Explosion-proof robot combination control system and robot facing complex working environment

By working together with the sensor acquisition module, state transition module, hazard identification module, and protection measures module, the system solves the problem of insufficient adaptability of existing safety shutdown protection systems in complex operating scenarios, realizes high-precision shutdown event identification and risk response, and improves the safety protection level and operational reliability of explosion-proof robots.

CN121928528BActive Publication Date: 2026-06-02HEFEI RUIBAO TECH DEV CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HEFEI RUIBAO TECH DEV CO LTD
Filing Date
2026-03-30
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing safety shutdown protection systems are not adaptable enough to complex operating scenarios and are difficult to adjust protection strategies flexibly, resulting in insufficient coverage of safety inspections and potential safety hazards, especially in the inability to identify mechanical hazards in a timely manner after an emergency shutdown.

Method used

The system employs a sensor acquisition module to perceive trigger signals and equipment status in real time, combined with a status transition module to perform multi-level mode switching, a hazard identification module to identify potential hazards, a path detection module to analyze the scope of impact, a protection measures module to generate targeted inspection procedures, and a feedback verification module to optimize control strategies, thus forming a closed-loop control system.

Benefits of technology

It achieves high-precision shutdown event identification and risk response in complex operating environments, improves the system's adaptability, ensures the integrity of protection logic and explosion-proof safety, and enhances the robot system's response speed and recovery capability in the event of an emergency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121928528B_ABST
    Figure CN121928528B_ABST
Patent Text Reader

Abstract

The application discloses a kind of complex job environment-oriented explosion-proof robot combination control system and robot, it is related to industrial automation and intelligent control technical field, including sensing acquisition module, trigger signal class and equipment state index in robot job environment are collected in real time by sensor network, combine environmental interference factor and signal intensity level, analyze abnormal fluctuation range, obtain the classification result of current shutdown event;State transition module, according to shutdown event classification result, adopt the state transition diagram of pre-setting, according to state node definition and transition condition rule, combine path priority ordering and mode hierarchical division, match multi-level shutdown mode, determine specific mode switching path;The complex job environment-oriented explosion-proof robot combination control system and robot of this application realize multi-mode collaborative control and adaptive optimization, significantly enhance the response speed and recovery ability of robot system under sudden event.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial automation and intelligent control technology, specifically to an explosion-proof robot combination control system and robot for complex working environments. Background Technology

[0002] In modern industry and automation, the design of safety protection systems is a core element in ensuring the safety of equipment and personnel, and its importance is self-evident. Especially in robotic operating environments, safety shutdown protection systems directly affect production efficiency and the stability of the working environment, and are an indispensable key technology for ensuring safe human-machine collaboration. Whether in factory production lines or intelligent warehousing, the reliability and completeness of safety shutdown systems have become important standards for measuring the level of equipment intelligence.

[0003] However, current safety shutdown protection methods often exhibit insufficient adaptability when dealing with complex operational scenarios. Many existing solutions lack comprehensive consideration of different shutdown modes in their design, making it difficult to flexibly adjust protection strategies according to actual conditions. This is especially true when facing changing working environments and emergencies, where the system's response mechanism appears incomplete. This not only increases potential safety risks but also limits the application scope of equipment in complex scenarios. A deeper technical challenge lies in how to coordinate the matching relationship between multi-level shutdown modes and corresponding safety inspection procedures. Different shutdown modes, such as normal shutdown, emergency shutdown, and fault shutdown, each have their specific triggering conditions and protection requirements, but existing technologies often experience problems with smooth process transitions during mode switching. This lack of smoothness further leads to insufficient coverage of safety inspections; for example, after an emergency shutdown, the system may fail to identify potential mechanical hazards in a timely manner, thus creating hidden safety risks. For a concrete example, in a high-speed robotic welding workshop, when the equipment enters an emergency shutdown state due to a sudden malfunction, if the safety inspection process fails to fully cover the immediate status of critical components, residual heat or unreleased mechanical pressure may threaten the surrounding environment and even affect subsequent recovery operations. Summary of the Invention

[0004] The purpose of this invention is to provide an explosion-proof robot combination control system and robot for complex working environments, thereby solving the problems existing in the prior art.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a combined control system for explosion-proof robots in complex operating environments, comprising a sensor acquisition module that collects trigger signal categories and equipment status indicators in the robot's operating environment in real time through a sensor network, analyzes the abnormal fluctuation range by combining environmental interference factors and signal strength levels, and obtains the classification result of the current shutdown event; a state transition module that, based on the shutdown event classification result, uses a preset state transition diagram, according to the state node definition and transition condition rules, combined with path priority sorting and mode hierarchy division, matches multi-level shutdown modes, and determines the specific mode switching path; and a hazard identification module. If the mode switching path involves an emergency shutdown scenario, the system queries the database for switching time constraints and abnormal status markers, combines them with historical path records, obtains the real-time status parameters of relevant mechanical components, and determines the distribution of potential hazards. The path detection module uses path conflict detection technology to analyze the shutdown time interval and fault frequency distribution, and compares it with historical data to determine the specific impact range and priority order of the hazards. The protection measures module obtains a predefined sequence of protection measures based on the impact range and priority order of the hazards, and generates a targeted inspection process list for mode transitions by combining environmental interference factors and signal strength levels.

[0006] On the other hand, the present invention also provides a robot that uses the above-mentioned explosion-proof robot combination control system for complex working environments to realize robot walking operations through the control system.

[0007] As can be seen from the above technical solution, the present invention has the following beneficial effects:

[0008] This invention utilizes a sensor acquisition module to achieve real-time perception of trigger signal categories, equipment status indicators, and environmental interference factors in the robot's operating environment, providing fundamental data support for the refined classification of downtime events. A state transition module, combined with a preset state transition diagram and priority path planning, enables intelligent matching and rapid switching between multi-level downtime modes, thereby improving the system's adaptability in different operating scenarios. Through the collaborative work of the hazard identification module and the path detection module, the system can automatically acquire the real-time status of mechanical components after an emergency shutdown, and analyze the distribution range and risk level of potential hazards using historical data, achieving comprehensive hazard identification and dynamic assessment. A protection measures module can generate targeted checklists based on hazard priority, ensuring the correspondence and accuracy of protective actions and control strategies. A process simulation module and a data fusion module further integrate the safety inspection process and recovery procedure logically, enabling the system to have self-verification and strategy adjustment capabilities. A feedback verification module and an adaptive optimization module form a closed-loop control, dynamically optimizing the mode level and time constraints according to the protection coverage, ensuring the integrity of the protection logic and improving explosion-proof safety.

[0009] Therefore, this system not only improves the safety protection level and operational reliability of explosion-proof robots in complex working environments, but also realizes multi-mode collaborative control and adaptive optimization, significantly enhancing the robot system's response speed and recovery capability under emergencies, and has good engineering application prospects and promotion value. Attached Figure Description

[0010] Figure 1 This invention relates to an explosion-proof robot combination control system for complex working environments.

[0011] Figure 2 This is a schematic diagram showing the connection between the explosion-proof robot and the robotic arm of the present invention.

[0012] Reference numerals: 1. Robot dog; 2. Robotic arm. Detailed Implementation

[0013] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0014] Example 1:

[0015] like Figures 1-2As shown, this invention provides a technical solution: a combined control system for explosion-proof robots in complex operating environments, comprising: a sensor acquisition module, which collects trigger signal categories and equipment status indicators in the robot's operating environment in real time through a sensor network, analyzes the abnormal fluctuation range based on environmental interference factors and signal strength levels, and obtains the classification result of the current shutdown event; a state transition module, which, based on the shutdown event classification result, uses a preset state transition diagram, according to the state node definition and transition condition rules, and combines path priority sorting and mode hierarchy division to match multi-level shutdown modes and determine the specific mode switching path; a hazard identification module, which, if the mode switching path involves an emergency shutdown scenario, queries the switching time constraint and abnormal state marker through an associated database, and combines historical path records to obtain the real-time status parameters of relevant mechanical components and determine the distribution of potential hazards; and a path detection module, which, based on the distribution of potential hazards, uses path conflict detection technology to analyze the shutdown time interval and fault frequency distribution, and compares with historical data to determine the specific impact range and priority order of the hazards. The system comprises the following modules: a protection measures module, a process simulation module, and a data fusion module. The protection measures module obtains a predefined sequence of protection measures based on the impact range and priority of potential hazards, and generates a targeted inspection process list with corresponding mode connections, taking into account environmental interference factors and signal strength levels. The process simulation module uses the inspection process list, historical path records and transition condition rules in the state transition diagram to simulate the process execution logic and determine the start conditions and execution order of the recovery procedure. The data fusion module integrates the inspection process list and the recovery procedure if the start conditions of the recovery procedure are met, combining the abnormal fluctuation range and equipment status indicators to obtain a complete protection strategy output for abnormal vibration of robot components. The feedback verification module verifies the effectiveness of the mode connection using a feedback loop mechanism, and determines the overall process coverage of abnormal component vibration by combining state node definitions and path priority sorting. The adaptive optimization module adjusts the mode hierarchy and switching time constraints based on the determined coverage completeness, obtains an optimized safety inspection framework, and determines the final protection logic for abnormal vibration of robot components.

[0016] In this embodiment, the core working principle of the explosion-proof robot combined control system is to achieve dynamic safety decision-making in complex operating environments through multi-level modular control logic. The system first uses a sensor acquisition module to perceive the operating environment in real time, identify trigger signals and equipment status indicators, and establish an abnormal fluctuation model based on signal strength and environmental noise to determine the type of shutdown event. The state transition module uses a preset state transition diagram as a decision framework, achieving intelligent transition from normal operating state to shutdown mode through path priority and hierarchical mode switching. The hazard identification module uses the time constraints and status marking mechanism of the database to identify potential mechanical hazards in shutdown mode, and then performs timing and conflict analysis through the path detection module to determine the impact range of the hazard on system operation. The protection measures module generates corresponding protection schemes based on risk levels and performs logical deduction through a process simulation module to ensure the timing correctness and logical coherence of the scheme execution. When various conditions are met, the data fusion module integrates multi-source sensing data and strategy models to form a dynamically adjusted protection strategy. Ultimately, the feedback verification module evaluates the integrity of the protection effect in real time, while the adaptive optimization module adjusts the control strategy and state parameters based on the feedback results, thereby constructing a closed-loop safety control system to achieve precise protection and self-learning optimization for explosion-proof robots in complex operating environments.

[0017] Furthermore, this system can achieve high-precision shutdown event identification and risk response in complex and ever-changing operating environments. Compared with traditional single-logic control systems, it has the following advantages: Enhanced real-time response capability: Multi-sensor data fusion and dynamic state recognition mechanisms enable the system to complete state switching decisions at the millisecond level. Through the linkage of hazard identification and path detection modules, potential mechanical fault areas can be located in advance, effectively avoiding safety accidents. The system can adjust the control logic in real time based on feedback verification results, continuously optimize safety strategies, and achieve self-learning and self-evolution. Each functional module can be deployed independently or run in conjunction, adapting to different models and scales of explosion-proof robot equipment. Through a two-layer control structure of state transition diagram and protection measure sequence, it ensures the safe switching of critical nodes under abnormal conditions.

[0018] Furthermore, the sensing and acquisition module collects trigger signal categories and equipment status indicators in the robot's operating environment in real time through a sensor network. Combining environmental interference factors and signal strength levels, it analyzes the abnormal fluctuation range and obtains the classification result of the current shutdown event. This includes: collecting trigger signal categories and equipment status indicators from the robot's operating environment through the sensor network to obtain an initial data set; obtaining environmental interference factors and signal strength levels based on the initial data set; determining the abnormal fluctuation range by calculating the weighted influence of interference factors on the signal and comparing the strength levels; if the abnormal fluctuation range exceeds a preset threshold, obtaining time-series changes, amplitude deviations, and frequency shifts as feature values ​​from the abnormal fluctuation range to obtain a fluctuation feature set; using a support vector machine algorithm with the fluctuation feature set as input and fusing interference and strength correlation data from environmental attributes to determine the type of the current shutdown event and obtain a preliminary classification label; and obtaining the correlation indicators of trigger signals, equipment status, and fluctuation range from the data fusion attributes based on the preliminary classification label to obtain a detailed classification result of the current shutdown event.

[0019] In this embodiment, the sensor acquisition module synchronously acquires trigger signal categories and device status indicators at a sampling rate of 1000 times per second under a unified time reference and records the timestamps. The sensing channels include vibration, sound pressure, temperature, air pressure, current, and voltage. The acquisition adopts a sliding window method with a window duration of 1 second and an adjacent window step size of 0.5 seconds. After installation, all channels undergo amplitude calibration and zero-point correction using a standard signal source. The initial data set enters the preprocessing flow. First, median filtering is performed to remove isolated glitches, with the median filtering window length set to 5 samples. Then, band-limited filtering is performed to suppress out-of-band components. The lower limit frequency of the band-limited filter is determined by frequency response testing. The frequency response test inputs a sinusoidal signal from low to high frequency in a sweeping manner and records the channel response amplitude. The lowest frequency corresponding to an energy percentage of 95% is taken as the lower limit frequency. The upper limit frequency of the band-limited filter is set to half of the sampling rate per second to meet the sampling constraints. After preprocessing, the mean, peak value, peak-to-peak value, RMS value, and dominant frequency position are calculated within each window. The dominant frequency position is obtained through spectrum analysis, which involves segmenting and windowing the signal within the window, calculating the energy distribution, and taking the frequency corresponding to the maximum energy as the dominant frequency position. The determination of environmental interference factors and signal strength levels is completed within the same window. The power frequency electromagnetic interference score is obtained by statistically analyzing the ratio of the narrow band energy centered on the power frequency to the total band energy. The mechanical resonance interference score is obtained by statistically analyzing the ratio of the peak amplitude of the spectral peak in the frequency neighborhood corresponding to the equipment rotation speed to the total band energy. The airflow disturbance interference score is obtained by jointly measuring the energy proportion of the air pressure signal in the low-frequency band and the low-frequency fluctuation. The ground impact interference score is obtained by jointly measuring the pulse rate and instantaneous peak rate of the vibration signal. The above four items are mapped to the range of zero and one after minimum and maximum value normalization. The weights of each interference factor were determined through orthogonal experiments on a historical dataset consisting of 30 consecutive days of normal operation data. The orthogonal experiments divided the four weights into four levels with values ​​of 0.2, 0.4, 0.6, and 0.8. The evaluation metric was the minimum sum of the false positive and false negative rates. The resulting weights were: power frequency electromagnetic interference 0.4, mechanical resonance interference 0.3, airflow disturbance interference 0.2, and ground impact interference 0.1. The four scores were summed according to these weights to obtain the comprehensive interference score. Signal strength levels were divided into five levels based on the statistical results of the same 30-day normal data, with the dividing points taken as the 20th, 40th, 60th, and 80th percentiles of amplitude. After mapping the peak-to-peak value and effective value before correction within the window to specific intensity levels, the comprehensive interference score was mapped to a fixed amplitude correction amount and subtracted from the two amplitude statistics to compensate for the impact of environmental interference.

[0020] It should be noted that the calculation of the abnormal fluctuation range adopts a dual threshold strategy. The amplitude threshold is determined by three times the steady-state baseline volatility. The steady-state baseline volatility is calculated within a sliding window of 30 days of normal data and converted by the median absolute deviation. The frequency offset threshold is determined by the 97.5th percentile of the steady-state dominant frequency position deviation. When the corrected peak value or effective value in any window exceeds the amplitude threshold of the corresponding intensity level, or the difference between the dominant frequency position and the steady-state dominant frequency position exceeds the frequency offset threshold, the window is marked as an abnormal window. Multiple abnormal windows with an interval of no more than one window between adjacent abnormal windows are merged, and the start and end times of the merged result are the abnormal fluctuation range. For each abnormal fluctuation range, three types of features are extracted from the fluctuation feature set to form a feature vector. The steps for obtaining the temporal variation feature are: calculating the difference sequence of the mean values ​​of adjacent abnormal windows in chronological order; calculating the rise time and fall time within each abnormal window and calculating their ratio; and combining these two items at a fixed ratio to synthesize the temporal variation feature. The steps for obtaining the amplitude deviation feature are: calculating the difference between the peak value of the abnormal window and the steady-state baseline and combining this with the peak value of the abnormal window at a fixed ratio to synthesize the amplitude deviation feature. The steps for obtaining the frequency shift feature are: calculating the difference between the dominant frequency position of the abnormal window and the dominant frequency position of the steady state and calculating the rate of change of this difference between adjacent abnormal windows; and combining these two items at a fixed ratio to synthesize the frequency shift feature. The steady-state baseline is obtained from 30 days of normal data under the same window parameters, and the fixed ratio is determined by the optimal performance combination during the training phase. To ensure that each feature has a consistent input scale to the classifier, the mean and volatility of the three types of features are calculated on the training set, then standardized and linearly scaled to between zero and one. The mean and volatility used for standardization are fixed as constants at the end of training.

[0021] Specifically, the classifier uses a support vector machine algorithm with a radial basis function kernel. The event types include four categories: emergency shutdown, system maintenance shutdown, overload protection shutdown, and sensor abnormal shutdown. The training data comes from labeled historical abnormal events. The classification penalty strength in the parameter search space is 1, 10, and 100, and the kernel scale is 0.001, 0.01, 0.1, and 1. Five-fold cross-validation is used for evaluation. Each set of parameters is considered feasible when the sum of the false positive and false negative rates across all folds is minimized and the recall rate is not less than 90%. Finally, the set of parameters with the smallest comprehensive index in the feasible set is selected as the fixed parameters and fixed. The resulting model is embedded into the sensor acquisition module in an inference manner. During online operation, the feature vector calculated for each abnormal fluctuation range is input into the classifier along with the environmental interference score and intensity level correlation data for the same window. The classifier outputs a preliminary classification label. Subsequently, based on the preliminary classification label, the data fusion attributes are accessed and four correlation indicators are calculated: trigger signal consistency, equipment status consistency, duration ratio, and time alignment deviation. The calculation steps for trigger signal consistency are to compare the occurrence order of trigger signals with the standard trigger order of this type of event according to the timestamp and to calculate the consistency ratio. The calculation steps for equipment status consistency are to read the changes in the status bits of each device within the window and compare them bit by bit with the standard status sequence of this type of event to obtain the consistency ratio. The calculation steps for duration ratio are to divide the total duration of the abnormal fluctuation by the total duration of the window to obtain the ratio. The calculation steps for time alignment deviation are to calculate the absolute time difference between the start of the abnormal fluctuation and the shutdown trigger time. Four indicators are used for judgment based on defined thresholds: trigger signal consistency no less than 80%, equipment status consistency no less than 80%, duration percentage no less than 50%, and time alignment deviation no more than 1 second. When all four indicators are met and consistent with the initial classification label, the detailed classification result is directly output as that type of event. When there are unmet criteria, a rollback judgment is performed according to priority order, from high to low: trigger signal consistency, equipment status consistency, time alignment deviation, and duration percentage. The rollback judgment process is as follows: first, the four indicators are re-weighted and scored in the candidate event set most similar to the initial classification label. The scoring weights are fixed based on the historical misjudgment attribution results: trigger signal consistency 0.4, equipment status consistency 0.3, time alignment deviation 0.2, and duration percentage 0.1. The event type with the highest score is taken as the final detailed classification result. If the scores are the same, the event type with the lower overall misjudgment rate in the past similar working conditions is selected as the final result.The sources and determination methods of the above parameters are all fixed before operation and are not automatically changed during the online phase; the number of samplings, window duration, and step size are determined based on the device's highest effective response frequency and shortest anomaly duration and are written into the factory configuration; the lower limit frequency of the band-limited filter is determined through frequency response testing and recorded in the device file; the interference scoring threshold is obtained and fixed through percentile statistics of 30 days of normal data; the amplitude threshold and frequency offset threshold are obtained and fixed through statistics of steady-state baseline fluctuation and steady-state dominant frequency position deviation, respectively; the feature standardization parameters and classifier parameters are determined and solidified through offline training and verification; the thresholds and weights of the four related indicators are determined through replay evaluation of historical events to minimize the sum of the false positive rate and false negative rate and ensure that the recall rate of each of the four types of events is not less than 90%.

[0022] In this embodiment, the state transition module, based on the shutdown event classification results, uses a preset state transition diagram, and according to the state node definitions and transition condition rules, combined with path priority sorting and mode hierarchy division, matches multi-level shutdown modes to determine the specific mode switching path. This includes obtaining the initial state node definitions and transition condition rules from the preset state transition diagram based on the shutdown event classification results, and obtaining a matching node sequence; determining a potential set of mode paths by combining the node sequence with path priority sorting and mode hierarchy division; for the set of mode paths, integrating event recovery strategies and real-time monitoring indicators, judging the temporal correlation of multi-level shutdown modes by comparing temporal change deviations, and obtaining path optimization indicators; using the path optimization indicators, obtaining historical data fusion and predicted state deviations, and matching specific mode switching paths by comparing deviation values; if the mode switching path meets the transition condition rules, extracting the final switching sequence from the path to determine the specific mode switching path.

[0023] Specifically, the first step is to call the corresponding starting node and the standard node sequence template for the event in the transition graph according to the event type. The template gives the entry conditions, the maximum allowed stay time, and the possible exit direction for each node. The module takes the template node sequence as the first matching node sequence and records its sequence number and the necessary conditions for each jump.

[0024] The second step is to perform a bounded path search based on the first matched node sequence. The upper limit of the search depth is set to 5 steps. Path branches are only taken from directed edges marked as allowed to transfer in the transition graph. The path priority is based on the safety priority of each directed edge, with the numerical label increasing from 1 to 9. The smaller the value, the higher the priority. The mode level is divided into 3 levels, where level 1 indicates controllable shutdown and recovery after the allowable conditions are met, level 2 indicates restricted shutdown and recovery after on-site confirmation, and level 3 indicates forced shutdown and only allows entry into the maintenance process. The module calculates the path priority value for each candidate path and takes the minimum priority of all edges on the path as the priority of the path. At the same time, it calculates the highest mode level of the path as the risk level of the path. All candidate paths that can reach the target node within 5 steps are combined into a mode path set, and the top 20 paths with higher priority values ​​and lower risk levels are retained to proceed to the next step.

[0025] The third step integrates event recovery strategies and real-time monitoring indicators for each path in the pattern path set. The event recovery strategy uses a standard process template for similar events to provide the standard trigger signal occurrence order, key equipment status bit flipping order, and standard duration range for each stage. Real-time monitoring indicators include the timestamp sequence of trigger signals and equipment status bits collected within the current cycle, as well as the duration and peak occurrence time of core monitoring quantities at each stage. The module performs timing alignment on each candidate path, calculates three deterministic deviation indicators, and obtains the timing change deviation. These three indicators are the number of trigger sequence misalignment steps, the number of status flipping misalignment steps, and the absolute time difference of each stage's duration. The allowable upper limit for trigger sequence and status flipping misalignment is set to 1 step, the upper limit for single-stage time error is set to 2 seconds, and the upper limit for the total error between any two adjacent stages is set to 3 seconds. If any one of these limits is exceeded, the timing association of the path is deemed invalid and discarded; otherwise, it proceeds to optimization scoring. The module calculates path optimization indicators for each valid path. Path optimization indicators consist of timing consistency score, risk... The score is calculated by adding the risk weight score, execution cost score, and other components in a fixed ratio: 50% for time series consistency, 30% for risk weight score, and 20% for execution cost score. The time series consistency score is given using a deterministic mapping table where lower deviations result in higher scores: 100 points for zero deviation, 60 points for reaching the upper limit, and 80 points for any interval between the two. The risk weight score is mapped according to the highest path mode level: 100 points for level 1, 70 points for level 2, and 40 points for level 3. 0 points. If any node on the path is an emergency shutdown node, 30 points will be deducted from the score, but not less than 0 points. The execution cost score is determined by the total expected downtime and the number of switches. The total expected downtime is less than or equal to 300 seconds and is worth 100 points, between 301 and 600 seconds and is worth 70 points, and greater than 600 seconds and is worth 40 points. If the number of switches exceeds 3, 10 points will be deducted from the execution cost score for each additional switch, but not less than 0 points. The sum of the three scores is the path optimization index and is recorded in the path table.

[0026] The fourth module performs deviation comparison and path matching based on path optimization indicators, historical data fusion, and predicted state deviation. Historical data fusion extracts baseline trajectories from samples within the last 30 days that match the event type and operating condition labels. The operating condition labels are fixed and include three levels of ambient temperature, three levels of load ratio, and three levels of shift. Each level is defined and fixed before going live. The baseline trajectory records the typical duration and key monitoring range of this type of path at each stage. The predicted state deviation is calculated by using real-time monitoring indicators from the last three control cycles in chronological order to determine the stage-level expected duration and key monitoring range, generating the predicted deviation interval for each stage. The module compares each candidate path item by item across the three categories. First, the duration of each stage of the candidate path and the range of key monitoring quantities are compared with the baseline trajectory. If the duration of any stage deviates from the baseline range by more than 20% or the key monitoring quantity deviates from the baseline range by more than 20%, the path is eliminated. Then, the expected duration of each stage of the candidate path and the expected range of key monitoring quantities are compared with the prediction deviation range. If any stage exceeds the prediction deviation range by more than 20%, the path is eliminated. Among the remaining paths, they are sorted from high to low according to the path optimization index. The one with the highest score is selected as the candidate specific mode switching path. If the scores are the same, the path with the higher priority value is retained first. If they are still the same, the path with fewer total switching times is retained first.

[0027] The fifth step module verifies the transfer condition rules hop-by-hop on the selected path. The verification content is determined item by item according to the rule list. The rule list is fixed and includes four items: the necessary trigger signal is met, the combination of critical equipment status bits is consistent, the core monitoring quantity falls within the safe range, and the mode level is permitted. The method for determining the necessary trigger signal is to compare the required trigger signal for that hop with the corresponding signal in real-time monitoring by timestamp, requiring a time difference of no more than 1 second. The method for determining the consistency of critical equipment status bit combinations is to compare each status bit value required for that hop with all of them, requiring them to be consistent. The method for determining whether the core monitoring quantity falls within the safe range... The method involves comparing the upper and lower limits of the monitoring quantity required for the jump with the current value and ensuring that all values ​​are within the range. The method for determining the permissible mode level is as follows: if any subsequent node in the current path contains a higher level than the current node, the level upgrade must be completed before the jump is entered; otherwise, the condition is not met. If all four conditions are met, the jump passes the verification and proceeds to the next jump. If any condition is not met, the path verification fails, and the next candidate is selected from high to low according to the path optimization indicators for repeated verification until a path that passes all verifications is found. If all candidates fail, a clear result of "no usable path" is output and the reason code is recorded.

[0028] In the above, the search depth of 5 steps is used to ensure that the finite number of steps from the starting point to the target is completed within a single operation; this value is determined by the security assessment report. The path priority values ​​of 1 to 9 are determined by the security demonstration meeting minutes and written into the edge attributes of the transition graph. The mode level of 3 is determined by the risk assessment report and written into the node attributes. The upper limit of 1 step for trigger and state misalignment, the upper limit of 2 seconds for single-stage time error, and the upper limit of 3 seconds for the combined error of two adjacent stages are determined by the playback statistics of the operation records of the past three months to ensure that alarm scenarios are captured in a timely manner without misjudgment. The proportion of path optimization indicators and the specific values ​​of each level are determined by historical data playback experiments to minimize the misjudgment rate and the missed judgment rate. The sum is minimized; the 30-day window for historical data fusion and the three-level division of operating condition labels are determined by the review of equipment operating environment and production line cycle time; the 20% threshold for baseline deviation and prediction deviation is determined by statistical analysis of the fluctuation range of stable samples in the past three months to ensure that the safety margin is not lower than the requirements of the common specifications for similar equipment; the time difference of 1 second, the consistency of all status bits, the requirement that the monitoring quantity must be within the upper and lower limits, and the judgment rules for hierarchical permission in the verification steps are all derived from the transfer condition rules and solidified in the form of numerical values ​​or enumeration items; the final output is the complete node sequence and switching order of the verified path, which is written to the audit log before the end of this cycle to ensure that the same output is produced under the same input.

[0029] In this embodiment, if the mode switching path involves an emergency shutdown scenario, the hazard identification module queries the associated database for switching time constraints and abnormal status markers, combines historical path records, obtains the real-time status parameters of relevant mechanical components, and determines the distribution of potential hazards. This includes obtaining the associated database under the emergency shutdown scenario through the mode switching path, querying the switching time constraints and abnormal status markers, and obtaining preliminary hazard indicators; for the preliminary hazard indicators, combining historical path records, extracting real-time status parameters from a preset mechanical component library, and determining the distribution of potential hazards; using the distribution of potential hazards, integrating real-time monitoring data, determining the correlation deviation between components, and obtaining an optimized path sequence; and matching multi-level shutdown modes according to the optimized path sequence to obtain the final mode switching path.

[0030] In this implementation, the first step is to query the database and audit information and generate preliminary indicators of potential risks. The module uses the starting node, ending node, and actual trigger time of each hop in the path as the joint search key to access the switching constraint data and abnormal status marker data in the associated database. Simultaneously, it accesses the corresponding audit entries in the historical path records using the same search key. The switching constraint data includes three items: minimum waiting time, maximum allowable delay, and mandatory safety interlock conditions. The abnormal status marker data includes three items: abnormal name, trigger source, and severity level. The module calculates the difference between the actual interval and the minimum waiting time for each hop and the difference between the actual interval and the maximum allowable delay. If the actual... If the interval is less than the minimum waiting time, the jump is recorded as a time advance violation. If the actual interval is greater than the maximum allowable delay, the jump is recorded as a time lag violation. At the same time, the abnormal status markers are checked item by item. If any abnormality is active, the abnormality and its severity level are recorded. The above three types of information are combined into preliminary indicators of hidden dangers and a specific flag bit and value record are generated for each jump. The second step is to extract real-time status parameters and judge the distribution of potential hidden dangers. The module expands the component list in the preset mechanical component library according to the nodes involved in the path and extracts the real-time status parameters of the corresponding channel in the time period of backtracking and look-ahead for a total of 5 seconds before and after the emergency stop is triggered through the one-to-one or one-to-many mapping relationship between the component and the sensing channel.

[0031] Specifically, within this time period, four indicators are calculated for each channel: instantaneous value, time average value, maximum value, and duration of continuous boundary violations. The mechanical component library has fixed three numerical boundaries for each component: normal range, alarm range, and shutdown range. These boundaries are determined and recorded as specific values ​​by the manufacturer's test report and on-site acceptance data before going live and do not change automatically during operation. Based on this, the module determines the level of each component. If the instantaneous value or time average value enters the shutdown range or the duration of continuous boundary violations exceeds 2 seconds, the component is determined to be a high-level hazard. If it enters the alarm range but does not meet the high-level conditions, it is determined to be a medium-level hazard; otherwise, it is determined to be a low-level hazard. A potential hazard distribution map is generated at the component level. The distribution map is a deterministic list of components along the path and their hazard level, boundary violation type, and time period. The third step is to integrate the potential hazard distribution with real-time monitoring data and determine the correlation deviation between components. The module reads the time series of all corresponding channels for all components in the distribution map from the real-time monitoring data and aligns them according to a unified timestamp. For predefined component pairs with mechanical coupling or energy transfer relationships in the library, the module calculates the average absolute difference of the two alignment sequences within the most recent 2-second window and slides in 1-second increments. To suppress the influence of occasional spike interference on the judgment, the module performs a 10% double-ended truncated average on the obtained average absolute difference sequence to obtain a stable difference degree. Then, the stable difference degree is compared with the baseline difference band of the component pair under the same operating conditions in the historical path records. The baseline difference band is obtained by statistical analysis of the most recent 30 days of normal operation data and is fixed as a specific numerical range of 5% to 95%. If the stable difference degree is higher than 20% of the upper boundary of the baseline difference band, the component is marked as having a correlation deviation and the correlation deviation count is accumulated on the corresponding bar of the path. Subsequently, the module aggregates three types of deterministic indicators—the time advance or lag violation flag and the abnormal activation flag for each hop, the highest hidden danger level of the component involved in the hop, and the correlation deviation count—into a path risk score for generating optimized path sequences. The highest hidden danger level of the component has a weight of 0.3, and the correlation deviation count has a weight of 0.2. The scoring rules for time violations and abnormal activations are as follows: both occur simultaneously, full marks are awarded; one occurs, a medium score (medium level score) is awarded; and neither occurs, a low score is awarded. The scoring rules for the highest hazard level of a component are: high level, full marks; medium level, medium score; and low level, low score. The scoring rules for associated deviation counts are: a count greater than or equal to 2, full marks; a count equal to 1, medium score; and a count equal to 0, low score. Based on this, the module calculates a risk score for each hop on the path and forms a risk sequence arranged in chronological order. Then, based on the risk score, an optimized path sequence is generated. The generation rule is to insert a buffer node allowed in the state transition diagram for high-risk hops with a risk score of not less than 80, or to directly upgrade the target mode of that hop to a higher level to quickly isolate the risk. For continuous segments with a risk score below 40 and adjacent hops being low-risk, they are merged into a single segment without violating switching time constraints and safety interlocks. To reduce the number of handovers, for medium-risk jumps between 40 and 80 points, the original path remains unchanged, but time margins are reserved before and after the jump to meet the minimum waiting time and maximum allowable delay. Insertion or merging operations are only performed within the set of allowed edges in the state transition diagram, and the minimum waiting time, maximum allowable delay, and safety interlock conditions in the handover constraints are checked item by item. The fourth step is multi-level shutdown mode matching and final path determination. The module maps the optimized path sequence jump by jump to a multi-level shutdown mode set, and selects the minimum level not lower than the requirement based on the risk score of each jump and the highest hidden danger level of the component. The mode level is fixed at 3 levels and is solidified by numerical enumeration before going live. If any jump has both time violation and abnormal activation, the level of that jump and its subsequent jumps is directly raised to the highest level. At the same time, the highest level in the entire path range is taken as the minimum allowed level for this path execution.

[0032] If the insertion or merging of any hop in the optimized path sequence causes any switching constraint to be violated, the process will fall back to the previous feasible optimization result and perform matching again. If the matching is successful, the final mode switching path will be output and a clear switching sequence and reason code will be generated according to the node order and the selected level and written into the audit log.

[0033] Example 2:

[0034] The difference between this embodiment and Embodiment 1 is that it also includes a path detection module. For the distribution of potential hazards, it employs path conflict detection technology to analyze downtime intervals and fault frequency distribution. By comparing historical data, it determines the specific impact range and priority order of the hazards. This includes assessing the hazard distribution, obtaining fault frequency statistics from downtime interval divisions, identifying hazard location associations through conflict path identification, and defining the impact range. Based on the impact range definition, it integrates historical data, compares fault frequency statistical deviations, determines the priority ranking mechanism, and establishes state parameter monitoring. Based on state parameter monitoring, it extracts the difference values ​​between components in the deviation correlation calculation to obtain path sequence adjustments. It then verifies the matching pattern from the path sequence adjustments and, combined with time constraints in downtime scenario simulations, determines the specific impact range and priority order of the hazards.

[0035] In this implementation, the first step involves establishing a frequency statistical sequence based on downtime intervals and potential hazard locations, and identifying conflict paths. The downtime interval is defined as the complete period from the triggering of a downtime event to reaching a stable state. The interval division uses a fixed combination of a 5-second window duration and a 2-second step. The module counts the number of occurrences of each potential hazard location within each window and divides the count by the window duration to obtain the unit time frequency. The results are then arranged in chronological order to form a fault frequency sequence. Simultaneously, two derived indicators are recorded: the cumulative number of occurrences across the entire interval and the maximum number of consecutive window occurrences. Path conflict detection is performed on the same time axis, and an impact group is generated. Time conflict determination is based on the transfer condition rule base for that specific action. The module uses two fixed values: minimum waiting time and maximum allowable delay. If the execution times of any two potential hazard points overlap on the timeline and the overlap length is greater than or equal to the minimum waiting time, it is considered a time conflict. If the actual interval of any jump is greater than the maximum allowable delay and its subsequent jump has already started execution, it is considered a sequence conflict. Logical conflict is determined based on the fixed mutual exclusion table in the rule base. If there are mutually exclusive entries for the corresponding states or corresponding transitions of two potential hazard points, it is considered a logical conflict. The module merges the points that have any type of conflict with their corresponding paths into the same impact group and uses the list of components and the list of states covered by this impact group to form a preliminary definition of the scope of impact.

[0036] The second step, based on the initial definition of the impact area, involves historical data fusion and frequency deviation comparison, and outputting a status parameter monitoring list. Historical data fusion extracts the baseline frequency sequence and the switch time distribution of the same status list from records within the most recent 30 days that match the current event type and operating condition label, corresponding to the same downtime interval. The module calculates the deviation ratio by matching the current frequency sequence with the baseline frequency sequence according to window positions and evaluates the continuity of the deviation. The deviation ratio is defined as the percentage difference between the current window frequency and the median frequency in the baseline window relative to the median frequency in the baseline window. When the deviation ratio is greater than or equal to 20% and persists for more than two consecutive windows, the location is marked as having a frequency anomaly, and the risk level is increased within its impact group. Level 1: Simultaneously, using the same window comparison method, the actual interval of each current jump is compared with the median interval of the baseline. When the difference ratio is greater than or equal to 20% and the jump is located in the affected group, it is marked as a time spread risk. Subsequently, the module establishes a state parameter monitoring list based on the response sequence and stability of each component within the affected area in historical samples. The list selects the 10 items most relevant to the event trigger from existing acquisition channels such as vibration, temperature, current, sound pressure, and displacement. The selection method is to calculate the absolute correlation score between each channel and the event trigger time under the same event type in the last 30 days and sort them from high to low, taking the top 10 items. If there is a tie, the deterministic rule of prioritizing the one with higher contribution in the historical misjudgment attribution statistics is adopted.

[0037] The third step, after the status parameter monitoring list is determined, is to perform deviation correlation calculation and generate a path sequence adjustment plan according to fixed rules. For any pair of components in the list, after alignment to a unified timestamp, the deviation correlation calculation calculates the average absolute difference with a window duration of 2 seconds and a step size of 1 second to obtain a difference value sequence. To suppress occasional spike interference, the module performs a 10% double-ended truncated average on the difference value sequence to obtain a stable difference value. This stable difference value is then compared with the baseline difference band obtained from the statistical analysis of the corresponding component's normal operation data over the past 30 days. The baseline difference band is defined as a value range of 5% to 95% and fixed with specific numerical intervals. When the stable difference value is higher than 20% of the upper boundary of the baseline difference band, it is determined that the component has a strong correlation deviation, and the deviation count is accumulated on its path. Based on this, the module performs two deterministic adjustments to the path sequence. Adjustment rules and generate adjustment suggestions. Rule 1 is a buffer insertion rule. When a hop meets the time conflict, the sequence conflict, or its strong correlation deviation count is greater than or equal to 2, a buffer hop allowed by the rule base is inserted before the hop to increase the minimum waiting time and postpone the planned start time of the downstream hop by no less than the minimum waiting time and no more than the maximum allowable delay. Rule 2 is a risk enhancement rule. When the impact group of a hop contains high-risk components and the hop has been marked as having frequency abnormality or time propagation risk, the shutdown mode level required by the hop is directly upgraded to a higher level, and adjacent low-risk hops in the same impact group are merged to reduce the number of switching operations. All insertion and merging operations are verified item by item within the transfer range allowed by the rule base, including minimum waiting time, maximum allowable delay, and safety interlock conditions, and a new path sequence is generated.

[0038] The fourth step is to perform pattern matching verification on the new path sequence and combine it with the time constraints in the shutdown scenario simulation to output the specific impact range and priority order of the hidden dangers. The pattern matching verification checks the consistency between the new path and the multi-level shutdown mode hop by hop. When the target mode of any hop is lower than the lowest permissible level of the impact group to which the hop belongs, it is directly promoted to that level and necessary merging is performed between adjacent hops to ensure the continuity of the mode. The time constraint verification confirms that the actual interval of all hops is not less than the minimum waiting time, not greater than the maximum permissible delay, and that all interlocks are released before entering the next hop and there is no time overlap caused by merging in the entire path.

[0039] Furthermore, this embodiment can also add a protection measures module. Based on the impact range and priority order of the hidden danger, a predefined sequence of protection measures is obtained. Combined with environmental interference factors and signal strength levels, a targeted inspection process list is generated. This includes extracting priority ranking from the definition of the hidden danger range, obtaining the predefined sequence of protection measures through the extraction results, and obtaining adjustment values ​​by combining environmental interference assessment and signal strength classification. By integrating the adjustment values ​​with the adjustment of influencing factors, the mode connection generation path is determined, and the targeted mode sequence is identified. The interference signal is matched according to the targeted mode sequence to generate an inspection list fusion framework and obtain the output of the process generation mechanism. The connection priority matching of the output of the process generation mechanism is used to extract the optimization parameters for the measures and determine the inspection process list.

[0040] In this implementation, priority extraction and basic measure positioning are first performed. The module reads the priority number of the affected group and its internal components from the hazard scope definition results and maps the priority number to a percentage score, where priority number 1 is mapped to 100 points, 2 to 80 points, 3 to 60 points, 4 to 40 points, and 5 to 20 points. At the same time, the module retrieves the basic measure list from the predefined protection measure sequence according to component type and hazard level. The basic measure list contains 10 fixed items, and each item has four parameters: execution order, maximum allowable duration, pass threshold, and failure handling branch. The 10 items are: maximum allowable duration of power isolation verification (120 seconds), maximum allowable duration of interlocking circuit continuity verification (90 seconds), etc. The maximum allowable time for verification of explosion-proof enclosure sealing and fastening is 180 seconds; the maximum allowable time for verification of pressure relief and unobstructed ventilation channels is 120 seconds; the maximum allowable time for verification of combustible and toxic gas detection is 150 seconds; the maximum allowable time for verification of temperature rise and hot spot is 180 seconds; the maximum allowable time for verification of grounding and equipotentiality is 120 seconds; the maximum allowable time for verification of the appearance and bending radius of power and control cables is 120 seconds; the maximum allowable time for verification of sensor self-test and calibration is 180 seconds; and the maximum allowable time for verification of safety confirmation before restoration is 60 seconds.

[0041] Next, the module calculates the adjustment value of the execution measures and forms the basis for generating targeted pattern sequences. The input of environmental interference factors is a comprehensive interference score between zero and one. The module converts this score into an environmental interference score between 0 and 100. The input of signal strength level is 1 to 5 and mapped to signal strengths of 20, 40, 60, 80, and 100 respectively. The two are combined with fixed weights to form the adjustment value of the execution measures, with the signal strength score accounting for 60% and the environmental interference score accounting for 40%. Subsequently, a connection score is calculated for each impact group. The connection score is the result of adding the hazard priority score and the adjustment value of the execution measures, each accounting for 50%. The connection score is used to determine the pattern connection generation path and the category of the targeted pattern sequence. A connection score greater than or equal to 80 is judged as an enhanced sequence. A value between 60 and 79 is considered a standard sequence, while a value below 60 is considered a simplified sequence. The module then performs targeted pattern sequence generation combined with interference signals. For each impact group, the module adjusts its position and configures time parameters within the basic measures list based on the sequence category. The enhanced sequence is pre-loaded with three checks: power isolation verification, interlocking circuit continuity verification, and combustible and toxic gas detection verification. A 10-second waiting time is set between any two adjacent checks to ensure result stability. The standard sequence executes according to the default order of the basic measures list, with a 5-second waiting time between adjacent checks. The simplified sequence, without changing the pass threshold and maximum allowable duration, merges the two lowest-risk and independent adjacent checks into one, setting a 5-second waiting time to reduce switching time. The module then binds interference signals and signal strength grading information to each item in the sequence and generates a checklist fusion framework. Each checklist item typically includes five fields: execution object, sampling window, pass threshold, timeout threshold, and retry count. The sampling window is set to 5 seconds by default; when the measure adjustment value is greater than or equal to 80, the sampling window is set to 10 seconds to improve judgment stability; when the measure adjustment value is less than 80, the sampling window remains at 5 seconds. The timeout threshold equals the maximum allowed duration for that item. The retry count is fixed at one, and failure immediately triggers the failure handling branch. After binding, the module generates a process generation mechanism, outputting an ordered sequence of checklist items, and sets two unique branches (pass and failure) and a reason code after each item. Subsequently, it executes a priority matching and... The measures target the extraction of optimized parameters to determine the final inspection process list, and prioritize the matching of each list item to calculate the execution priority score. The score is obtained by superimposing three parts: hazard priority score, environmental interference score, and signal strength score with fixed weights. The weights of the three parts are hazard priority score 50%, environmental interference score 30%, and signal strength score 20%. The score is used to determine the execution order within the same node. If the scores are the same, the one with the shorter maximum allowable time is given priority. If they are still the same, the one with the stricter pass threshold is given priority. If they are still the same, the one with the higher hazard level of the associated component of the list item is given priority. The measures target the optimization parameters including five items: execution order, waiting time, sampling window, timeout threshold, and number of retries. The execution order is determined by the above scores.

[0042] Furthermore, in this embodiment, a process simulation module can be added. By checking the process list and using historical path records and transition condition rules in the state transition diagram, the process execution logic is simulated to determine the start conditions and execution order of the recovery program. This includes obtaining historical path records from the process list, matching path nodes and fusing condition constraints on the historical path records using transition condition rules to obtain simulated execution paths; matching the simulated execution paths with the process execution logic, comparing path nodes to determine the recovery start conditions and the execution order; combining the execution order with a condition judgment mechanism to obtain order optimization adjustments, applying the adjusted values ​​to the path sequence to obtain a logic simulation framework; fusing the start threshold setting with the logic simulation framework, determining if the start threshold setting exceeds a preset threshold, and obtaining the recovery start conditions through threshold comparison; extracting transition condition rules from the recovery start conditions, applying the rules to the sequence path to determine the execution order.

[0043] In this implementation, the execution object, sampling window, pass threshold, timeout threshold, waiting time, and retry count are read one by one from the list items. The node order marked in the list items is compared with the historical path records in the state transition diagram. The historical path records include the node sequence, the planned interval between adjacent nodes, the actual interval, and the transition condition rules that were met at that time. The module calculates three indicators for each candidate path: node matching rate, time interval deviation, and rule satisfaction rate. The node matching rate is the percentage of the number of items in the list items that are matched by the candidate path nodes out of the total number of list items. The time interval deviation is the absolute difference between the planned interval of each hop in the candidate path and the median interval of the same hop in history, calculated as the arithmetic mean in seconds. The rule satisfaction rate is calculated by converting the satisfaction of each hop in the candidate path with four types of rules: essential signal, minimum waiting time, maximum allowable delay, and interlocking conditions. 100 points are awarded for satisfying all four rules, 70 points for missing one, 40 points for missing two, and 0 points for missing three or more. These three indicators are then combined into a path matching score with fixed weights: node matching rate (40%), time interval deviation (40%), and rule satisfaction rate (20%). The time interval deviation is first converted into a three-tiered score table with smaller deviations receiving higher scores: deviations no greater than 1 second score 100 points, deviations between 1 and 2 seconds score 80 points, and deviations greater than 2 seconds score 60 points. Candidates with a path matching score greater than or equal to 80 points and a rule satisfaction rate of 100% are marked as usable and used as simulated execution paths; other candidates are eliminated. The module checks whether the four types of rules for each hop are satisfied in the node sequence along the simulated execution path. Specifically, it checks whether the necessary signals required for the hop have appeared in the pass record of the check process list and whether the time is no earlier than the end time of the previous hop, and checks the waiting time. If the waiting time is not less than the minimum waiting time of the hop, check if the planned interval is not greater than the maximum allowable delay of the hop, and check if all interlock conditions have been released before entering the next hop. If all four conditions are met, the hop is marked as executable and counted in the pass count. If any condition is not met, it is marked as pending adjustment and the reason code is recorded. Then, calculate the pre-start satisfaction rate as a percentage of the number of executable hops to the total number of hops in the path. If the pre-start satisfaction rate is not less than 90%, enter the sequential optimization stage. Otherwise, select the path with the highest path matching score from the remaining available candidates and repeat the deduction until the condition is met or there are no available candidates.For each hop marked as needing adjustment, a sequence adjustment value is calculated. This value is obtained by adding the time margin score, interlock conflict score, and historical failure rate score with fixed weights. The time margin score is the difference between the planned interval for that hop and the minimum waiting time, mapped according to tiers: 100 points for a difference of 2 seconds or more, 80 points for a difference between 1 and 2 seconds, 60 points for a difference less than 1 second, and 40 points for a difference of 0 seconds or more. The interlock conflict score is 40 points if there is an unresolved interlock, and 100 points if there is no interlock. The historical failure rate score is calculated based on the hop's failure rate in the historical path: 100 points for a failure rate not exceeding 5%, 80 points for a failure rate between 6% and 15%, and 60 points for a failure rate exceeding 15%. The weights for these three factors are time. The remaining space accounts for 50%, interlocking conflicts account for 30%, and historical failure rate accounts for 20%. When the order adjustment value is less than 80 points, deterministic adjustment rules are applied sequentially. Rule 1 is to insert waiting time, increasing the waiting time before the jump to meet the minimum waiting time, but without making the actual interval of the jump exceed its maximum allowable delay. Rule 2 is to move the jump to the next feasible position and recheck the interval between adjacent jumps. Rule 3 is to merge execution segments. If the conditions are still not met, merge it with the previous executable jump into a single segment without changing the meaning of the node, and inherit the stricter condition of the two jumps. After all the jumps to be adjusted are processed, the entire path is expanded on the time axis with a step size of 1 second, and each jump is bound. The sampling window and timeout threshold are defined. The sampling window is given in the list and defaults to 5 seconds. If a list item is marked as an enhanced case, it will be 10 seconds. The timeout threshold is equal to the maximum allowed duration of the item and is directly provided by the list, thus forming a logical simulation framework that includes node order, time alignment, and threshold linkage. Three scores are calculated on the logical simulation framework: coverage score, stability score, and timing consistency score. The coverage score is the percentage of all rule items that have met the four rule categories multiplied by 100. The stability score is the percentage of list items that pass once within their respective sampling windows without triggering a retry multiplied by 100. The timing consistency score is the percentage of each hop... The deviation of the actual interval from the historical median interval is averaged after mapping the scores to the aforementioned 1-second and 2-second boundaries. The three scores are combined with fixed weights to set the start threshold: coverage score 50%, stability score 30%, and timing consistency score 20%. When the start threshold is not lower than 85 points, the recovery start condition is determined to be met, and the set of rules for the currently true and necessary transition conditions is extracted. When the score is lower than 85 points, the values ​​are adjusted sequentially from low to high to address the insufficient score using the aforementioned three rules. After each adjustment, the three scores are recalculated until the threshold is reached or there is no room for adjustment. If the threshold is still not reached, a clear reason code for non-compliance is output, and the current cycle is stopped.

[0044] Furthermore, after the recovery startup conditions are obtained, the extracted transfer condition rules are applied to the sequential path one by one. The order constraints in the rules are used as the sorting key, the minimum waiting time in the rules is used as the minimum interval between adjacent hops, the maximum allowed delay in the rules is used as the upper limit between adjacent hops, and the interlock release order in the rules is used as a mandatory precondition. When sorting conflicts occur, the three-key sorting method is used to adjudicate the final execution order arranged by time axis by rule strictness from high to low, list item timeout threshold from short to long, and historical failure rate from low to high.

[0045] Example 3:

[0046] The difference between this embodiment and Embodiments 1 and 2 is the addition of a data fusion module. If the startup conditions of the recovery program are met, the data fusion module integrates the inspection process list and the recovery program, combining the abnormal fluctuation range and equipment status indicators to obtain a complete protection strategy output for abnormal vibration of robot components. This includes obtaining vibration data from the abnormal fluctuation range, normalizing the vibration data, and then performing a weighted average integration with the equipment status indicators to obtain a preliminary fusion result; matching the preliminary fusion result with the inspection process list, and using the recovery program startup conditions to determine if they are met, then comparing and integrating the inspection process list through path nodes to determine the integration path; combining the integration path with the robot component monitoring attributes, applying threshold constraints to the fluctuation range to obtain a combined fluctuation range value, and obtaining a status indicator fusion sequence; extracting the protection strategy output from the status indicator fusion sequence, and generating a complete strategy for abnormal vibration detection through sequence node mapping.

[0047] In a specific implementation, the standardization and weighted integration of vibration and equipment status are first performed. The module reads the effective value of vibration, peak value and dominant frequency position, and seven raw quantities of equipment status indicators such as temperature, current, speed and status consistency from the abnormal fluctuation range window by window. For each item, extreme value clipping and interval mapping are first performed. The extreme value clipping uses the 1% and 99th percentiles of the historical distribution of the item under the same working conditions over the past 30 days as the upper and lower limits, and the excess is truncated as boundary values. Then, using the historical minimum and maximum values ​​of the item in the abnormal segment as the mapping endpoints, the current value is linearly mapped to the 0 to 100 interval to obtain seven normalized scores. After normalization, the following parameters are generated. The initial fusion is performed with the following weights: 60% for the three vibration-related items and 40% for the four state-related items. The three vibration-related items have equal weights, while the four state-related items are internally allocated as follows: temperature 35%, current 35%, rotational speed 20%, and state position consistency 10%. When the peak value exceeds the steady-state baseline fluctuation threshold by at least 50%, the total weight for the vibration-related items is increased to 70%, and the total weight for the state-related items is reduced to 30%. When the peak value is only within ±5% of the threshold and the number of consecutive abnormal windows is less than 2, the total weight for both categories is set to 50% each. The steady-state baseline fluctuation threshold is fixed at the corresponding component's performance in the past 30 days of normal samples. The absolute deviation of the number of bits is three times the value of the configuration list before going live; secondly, the path-level fusion of the inspection process list and the recovery program is performed. The module reads the sequence of inspection process list items related to the component, as well as their passing time, reason code, and timeout flag. At the same time, it reads the node sequence of the recovery program and the satisfied transfer condition rules, and aligns them item by item to obtain two indicators: node coverage and timing consistency. The node coverage is the number of list items successfully mapped to the recovery node divided by the total number of list items. The timing consistency is the average of the absolute difference between the passing time of the list item and the planned interval of the corresponding node, and then mapped to a threshold as a score. An absolute difference of less than or equal to 1 second is scored as 100 points. 1 second and 2 seconds are scored as 80 points, and more than 2 seconds are scored as 60 points. The path fusion score is calculated based on 70% node coverage and 30% timing consistency. When the path fusion score is greater than or equal to 80 and the recovery program status is "startable", the integration path is determined. Otherwise, the candidate paths are recalculated in descending order of node coverage until the requirement is met or the reason code for non-fusion is returned. Threshold constraints are then applied to the integration path in combination with the robot component monitoring attributes to generate a status index fusion sequence. The monitoring attributes are fixed and include four values: the number of axial vibration measurements, the upper limit of bearing temperature, the upper limit of operating current, and the allowable deviation of rotational speed. All of these values ​​are derived from the manufacturer's test report and on-site acceptance records.

[0048] The threshold constraint rule is as follows: when the normalized vibration score of any axis is greater than or equal to 80, or the deviation of the dominant frequency position from the steady-state dominant frequency exceeds the 97.5% quantile threshold of the historical distribution, the window is marked as high risk; when the normalized vibration score is between 60 and 79, or the dominant frequency deviation is between the 95% and 97.4% quantile thresholds, it is marked as medium risk; the rest are marked as low risk. After obtaining the risk labels, the "fluctuation range combined value" for each window is calculated. The combined ratio is fixed at 50% for the normalized vibration score, 20% for the normalized temperature score, 20% for the normalized current score, and 10% for the normalized rotational speed score, and is deterministically adjusted according to the risk level. High risk will be... After multiplying the vibration score by 1.2, the upper limit is truncated to 100. The vibration score for medium risk remains unchanged, while for low risk, it is multiplied by 0.8 to obtain a time-sorted fusion sequence of state indicators. Each element contains a value, the start and end time of the window, and the risk level. Subsequently, three global indicators required for the protection strategy are extracted from the fusion sequence of state indicators and mapped to the strategy level. The three indicators are the proportion of high risk, the length of the longest continuous segment of medium risk, and the composite mean. The proportion of high risk is the number of high-risk windows divided by the total number of windows multiplied by 100%. The length of the longest continuous segment of medium risk is the maximum number of continuous windows marked as medium risk. The composite mean is the arithmetic mean of the combined values ​​of the entire sequence.

[0049] Specifically, the strategy judgment thresholds are fixed as follows: If the high-risk percentage is greater than or equal to 30%, the composite mean is greater than or equal to 75, or the longest continuous segment length of medium-risk is greater than or equal to 3, the output is "Strong Protection," which involves maintaining shutdown, prioritizing power isolation verification and interlocking circuit continuity verification and gas detection retesting, performing hot spot retesting, delaying recovery, and triggering a secondary assessment after 10 seconds; if the high-risk percentage is between 10% and 29%, the composite mean is between 60 and 74, or the longest continuous segment length of medium-risk is equal to 2, the output is "Enhanced Monitoring," which involves maintaining degraded operation, performing gas detection and temperature rise retesting in a 5-second sampling window, and only recovering after the recovery start conditions are met again and the checklist is passed consecutively for 2 rounds; if the high-risk percentage is less than 10%, the composite mean is less than 60, and the longest continuous segment length of medium-risk is less than or equal to 1, the output is "Standard Recovery," which involves executing the recovery procedure in the predetermined order, maintaining the sampling window for 5 seconds, waiting for the checklist, and recovering after the checklist is completed; to ensure traceability... The traceability module generates an action list and execution sequence while outputting the strategy. The action names and order are strictly derived from the mapping relationship between the check process list items and the recovery program node names, and records the hit threshold, weight, and source reason code for each judgment. The combined weights of vibration and status are 60% and 40%, respectively, which are the benchmark combinations that minimize the sum of false positive and false negative rates in historical playback. The steady-state baseline is multiplied by 3 times the threshold to ensure that it is higher than the upper limit of noise and operating condition disturbance. The path fusion weights of 70% node coverage and 30% timing consistency are derived from the sensitivity assessment of the impact on alignment quality and execution stability. The path fusion threshold of 80 is used to ensure that the integrated path has sufficient consistency with the current list. The main frequency offset thresholds of 95% and 97.5% are used to distinguish between medium and high risk spectrum offsets. The risk boundary of 60 and 80 is used to divide the window into low, medium, and high levels and is consistent with the trade-off between on-site handling costs. The correction coefficients of 1.2 for high risk and 0.8 for low risk are used to improve the sensitivity to strong vibrations and suppress false alarms of low risk.

[0050] Furthermore, the feedback verification module, for the protection strategy output, employs a feedback loop mechanism to verify the effectiveness of the mode connection. Combining state node definitions and path priority ranking, it determines the overall process's coverage completeness of component vibration anomalies. Specifically, this includes acquiring vibration data from the abnormal fluctuation range, integrating the vibration data to obtain a preliminary fusion result; matching the preliminary fusion result with state node definitions and determining the integration path through path priority ranking; applying threshold constraints to the vibration anomaly coverage by integrating the integration path with equipment status, where the threshold constraint is achieved by comparing the abnormal fluctuation range with a preset standard value to obtain a coverage sequence value; extracting the recovery program start conditions from the coverage sequence value, where the extraction is achieved through sequence node filtering; and using a feedback loop mechanism to verify the effectiveness of the mode connection and determine the overall process completeness. If the overall process completeness meets the preset threshold, the complete strategy generates an output demonstrating the coverage completeness of component vibration anomalies.

[0051] In this implementation, the system first reads three raw quantities—vibration effective value, peak value, and dominant frequency position—window by window from the sampling window bound to the inspection process checklist within the abnormal fluctuation range. The sampling window is 5 seconds by default, or 10 seconds if the checklist item belongs to an enhanced sequence, with a fixed time step of 1 second. Each raw quantity is first pruned using the 1% and 99th percentiles of historical samples under the same working conditions over the past 30 days to eliminate extreme points. Then, the current value is linearly mapped to the 0-100 range using the historical minimum and maximum values ​​of the quantity in the abnormal segment as endpoints to obtain three normalized scores. The module calculates the preliminary fusion result of the three normalized scores with fixed weights: vibration effective value 40%, peak-to-peak value 40%, and dominant frequency position offset 20%. When the peak-to-peak value of the window exceeds the steady-state baseline fluctuation threshold by no less than 50%, the peak-to-peak value weight is increased to 50%, the vibration effective value weight is decreased to 30%, and the dominant frequency position offset weight remains at 20%. The steady-state baseline fluctuation threshold is fixed at the absolute value of the median of the normal samples over the past 30 days. The deviation is 3 times and written into the configuration list during deployment; then, state node matching and path priority selection are performed. The module aligns the timestamp of the preliminary fusion result with the node sequence template in the state node definition, and calculates two indicators: node coverage and node strictness. Node coverage is the ratio of the number of successfully mapped windows to the total number of windows multiplied by 100, and node strictness is the ratio of the number of adjacent mapped windows without holes multiplied by 100. At the same time, the priority value of each feasible path in the path priority sorting table is read and taken as 1 to 9. Priority scores are generated according to 1 corresponding to 100 points, 3 corresponding to 80 points, 5 corresponding to 60 points, 7 corresponding to 40 points, and 9 corresponding to 20 points. The three items are added with a weight of 40% for node coverage, 30% for node strictness, and 30% for priority score to obtain the path selection score. Candidates with a path selection score of not less than 80 points are marked as integration paths. If there are multiple paths that meet the criteria, the one with the highest score is selected. If the scores are the same, the one with the lower priority value is selected. If they are still the same, the one with the higher node coverage is selected.

[0052] After determining the integration path, the module performs device status integration and threshold constraint generation for each window to generate coverage sequence values. Device status integration reads three state variables bound to the component: temperature, current, and rotational speed. These are then cropped to the 1% and 99% quantiles using the same method as for vibration and mapped to the 0-100 range. The coverage base value is then calculated by combining this value with the vibration normalized score in the same window at a fixed ratio: 50% for vibration, 20% for temperature, 20% for current, and 10% for rotational speed. A threshold constraint rule is applied: when the vibration normalized score is not lower than 80 or the dominant frequency position is relatively close to the steady-state dominant frequency... When the deviation exceeds the 97.5th percentile threshold of the normal sample distribution over the past 30 days, the window is marked as high-risk, and the coverage base value is multiplied by 1.2, with the upper limit truncated to 100. When the vibration normalized score is between 60 and 79, or the dominant frequency deviation is between the 95th and 97.4th percentile thresholds, it is marked as medium-risk, with the coverage base value remaining unchanged. The rest are marked as low-risk, and the coverage base value is multiplied by 0.8. The above processing results are the coverage sequence values ​​arranged in chronological order. The module then extracts the recovery procedure initiation conditions from the coverage sequence values ​​in the integration path sequence. The extraction rule is to find the three most recent consecutive... The window coverage sequence value is not lower than 85, and the corresponding window temperature is not higher than the manufacturer's and site acceptance temperature limit, the current is not higher than the corresponding current limit, and the speed deviation is not higher than the speed allowable deviation. The starting point of this time period is used as the candidate time to start the recovery program. If the candidate exists, it is recorded as satisfied; otherwise, the feedback loop is entered. The feedback loop has a maximum of 3 rounds, and each round executes 3 actions in a fixed order: Action 1 is path replacement, selecting the path with the highest score of not less than 80 points, recalculating the node coverage rate and node severity, and updating the integrated path; Action 2 is weighting... The process involves fine-tuning the vibration component of the coverage base value. This is done only when the longest continuous segment of the medium-risk window is not less than two and the high-risk percentage is less than 10%. The vibration component is reduced from 50% to 45%, the temperature component and the current component are each increased to 22.5%, and the rotation speed component is kept at 10% to improve the coverage of the boundary states. The third action is window merging, which merges two adjacent medium-risk windows into a longer window without crossing the boundary of the state node and recalculates the coverage sequence value. After the three actions are completed, the start condition extraction is re-executed. If no candidate is obtained after three rounds, the unmet reason code is output and the cycle ends.

[0053] When a suitable startup candidate exists, the module further calculates the overall process integrity score and makes a final determination based on this score. The integrity score is obtained by weighted summation of three indicators: coverage achievement rate, node compliance rate, and connection efficiency. The coverage achievement rate has a weight of 60%, the node compliance rate has a weight of 30%, and the connection efficiency has a weight of 10%. The coverage achievement rate is calculated as follows: the proportion of windows with a coverage sequence value of at least 85 to the total number of windows is calculated, and then this proportion is converted into a percentage score. The node compliance rate is calculated as follows: the proportion of node transfers that meet the status node definition in the integration path to the total number of node transfers is calculated, and then this proportion is converted into a percentage score. The connection efficiency is calculated as follows: the proportion of adjacent nodes in the integration path that meet the transfer condition rules to the total number of adjacent node transfers is calculated, and then this proportion is converted into a percentage score. The module multiplies each of the three scores by its corresponding weight and then sums them to obtain the integrity score.

[0054] The integrity threshold is set to 90 points. When the integrity score is greater than or equal to 90 points, the module determines that the coverage integrity meets the standard and simultaneously outputs the integration path identifier, recovery start time, hit threshold, and reason code. When the integrity score is lower than 90 points, if there are still remaining feedback loop rounds, the module continues to perform verification according to the aforementioned process until the integrity score reaches 90 points or the feedback loop rounds reach the preset upper limit.

[0055] The adaptive optimization module adjusts the mode hierarchy and switching time constraints based on the determined coverage integrity, obtaining an optimized safety inspection framework. This framework determines the final protection logic for abnormal vibration of robot components, including obtaining adjustment parameters from the coverage integrity, matching these parameters to the mode hierarchy, and determining hierarchy boundaries through threshold comparison. The threshold comparison compares each adjustment parameter with a preset hierarchy standard value; if a parameter exceeds the standard value, it is assigned to a higher hierarchy, resulting in a hierarchy sequence. The module then integrates switching time constraints into the hierarchy sequence, using a preset threshold constraint time interval. If the interval exceeds the threshold, the constraint is reset, achieved by subtracting the threshold difference from the interval value. Constraint optimization values ​​are used to extract safety inspection framework elements. A framework structure is generated through an element fusion module, which sorts the extracted elements by priority and stacks them layer by layer to determine the internal verification logic. For the internal verification logic, component durability assessment is introduced, and assessment data is integrated into the framework. If the assessment data is abnormal, a response path is activated. Activation is triggered by matching abnormal data with a logic threshold, resulting in a draft protection logic. The draft protection logic is used to verify the abnormal vibration coverage of robot components. The draft parameters are adjusted through a sequence integration module, which performs an abnormal coverage sequence scan on the draft parameters and optimizes them to determine the final protection logic.

[0056] In this implementation, the coverage integrity score, coverage compliance rate, node compliance rate, and connection efficiency are first read, and the coverage gap score is obtained by subtracting the coverage integrity score from 100 as the core adjustment parameter. At the same time, the coverage compliance rate, node compliance rate, and connection efficiency are each converted into a correction coefficient with a weight of 1 / 33. If any of the three is lower than 80, the coverage gap score is increased by 5 to form a tightened gap score, so as to ensure that the strategy is tightened in the weak dimension. The module then performs threshold comparison to determine the mode level boundary and generates a level division sequence. The preset level standard value is fixed as the high-level boundary value of 15 and the mid-level boundary value of 5 before going online. The comparison rule is that when the tightened gap score is greater than or equal to 15, it is classified as high-level. Level 1: When the tightened gap score is between 5 and 14, it is classified as a mid-level; when the tightened gap score is less than 5, it is classified as a low-level. The level determination applies to the entire path in this cycle and is recorded as a level division sequence for subsequent constraint integration. Based on the level division, the module integrates the switching time constraints and generates constraint optimization values. The minimum waiting time and maximum allowable delay are based on the items fixed in the current configuration list. For high-level scenarios, the minimum waiting time is increased by 2 seconds and the maximum allowable delay is reduced by 10%. For mid-level scenarios, the minimum waiting time is increased by 1 second and the maximum allowable delay is reduced by 5%. Low-level scenarios remain unchanged. Subsequently, the threshold range is checked item by item for the planned interval of each hop in the path and re-execution is performed. Setting: When the planned interval is less than the minimum waiting time, a waiting segment is inserted before the jump, and the waiting time is equal to the minimum waiting time minus the planned interval and rounded up to 1 second. When the planned interval is greater than the maximum allowable delay, the jump planned interval is reset according to deterministic rules to the planned interval minus the excess difference, making it equal to the maximum allowable delay and rounded down to 1 second. If the reset or insertion causes overlap with the adjacent jump time, the overlap is extended forward, and the threshold of the extended adjacent jump is re-verified until there is no overlap in the entire path. The above processing results are summarized into a set of constraint optimization values ​​at the jump granularity. The module then extracts safety check framework elements from the constraint optimization values ​​and generates a framework structure through the element fusion module. The element set is fixed to include a set of state nodes and a set of transition conditions. The system consists of five items: a checklist of process items, a recovery trigger threshold set, and a rollback path set. These items are merged in order of safety priority and then layered on top of each other. The order is solidified before going online as follows: interlock verification priority, power isolation verification priority, gas detection verification priority, temperature rise and hot spot verification priority, interlock continuity verification priority, and pre-recovery safety confirmation priority. The stacking rule is to bind each element to its corresponding minimum waiting time, maximum allowable delay, and permission level in the constraint optimization value and form the internal verification logic of the framework. The verification logic is a strict four-stage sequence: first verify the interlock, then verify the time, then verify the signal, and finally verify the level. If any verification fails, the system will immediately roll back to the next higher level of shutdown mode according to the rollback path set and record the reason code and trigger time.After the internal verification logic is in place, the module introduces component durability assessment and integrates the assessment data into the framework. The durability assessment uses three fixed indicators: total operating time, cumulative over-temperature time, and cumulative vibration and shock counts. The upper limits of these three indicators are taken from the manufacturer's test report and on-site acceptance records and have been fixed. During the assessment, the three indicators are linearly mapped to 0 to 100 based on the minimum and maximum values ​​under the same operating conditions over the past 30 days to form a normalized score. Then, a durability health score is calculated according to the weights, which are fixed at 40% for total operating time, 40% for cumulative over-temperature time, and 40% for cumulative vibration and shock counts. The dynamic impact count is 20%. When the durability health score is less than 60 or any single item reaches its standard upper limit, it is judged as a durability anomaly, and a response path is activated in the framework. The response path is to directly elevate the current jump to a higher level, insert a 10-second waiting segment before the jump for secondary verification, and reduce the maximum allowable delay of the jump by 10% based on the constraint optimization value. When the durability health score is between 60 and 69, the original level is maintained, but a 5-second waiting segment is added before the jump, and interlocking continuity re-check is activated in the next two jumps. No adjustment is made when the durability health score is not lower than 70.

[0057] After durability injection is completed, the module generates a draft protection logic and hands it over to the sequence integration module for abnormal coverage sequence scanning and optimization of the draft parameters. The sequence integration module reads three global indicators of the coverage sequence value: the high-risk percentage, the longest continuous segment of medium risk, and the average combination value, and adjusts them according to fixed rules: when the high-risk percentage is greater than or equal to 20%, the sampling window of the relevant path segment is set to 10 seconds, the waiting time is set to 10 seconds, and the number of retries is set to 0 to avoid repeated triggering; when the longest continuous segment of medium risk is greater than or equal to 3 and the high-risk percentage is less than 20%, a 5-second waiting segment is added before and after the continuous segment, and the minimum waiting time of the segment is increased by 1 second based on the constraint optimization value; when the average combination value is not less than 70 and the high-risk percentage is less than 10%, the level remains unchanged, but the maximum allowable delay is increased within the constraint. The optimized value is increased by 5% to reduce false triggers. Any adjustment requires immediate re-verification of interlocks, levels, and time overlaps. If it fails, it will fall back to the most recent successful parameter set and stop further relaxation. After the sequence integration is completed, the module performs a one-time final check and produces the final protection logic. The final check list includes: the minimum waiting time of the whole path meets the standard; the maximum allowable latency of the whole path meets the standard; all interlocks are released before entering the next hop; the level does not decrease along the path or there is only a single decrease allowed by the fallback path set; after this parameter takes effect, the recalculated coverage integrity score is not less than 90 and the coverage gap score is less than or equal to 10. If all the above conditions are met, the final protection logic is generated and the final level division, final time constraint, final execution order and fallback path and corresponding reason code are output and written to the audit record.

[0058] On the other hand, the present invention also provides a robot that uses the above-mentioned explosion-proof robot combination control system for complex working environments, such as... Figure 2As shown, the robotic arm 2 is mounted on the robot dog 1, and the movement of the robotic arm 2 is controlled by the control system inside the robot dog 1.

[0059] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A combination control system for explosion-proof robots designed for complex working environments, characterized in that, include: The sensor acquisition module collects trigger signal categories and equipment status indicators in the robot's working environment in real time through a sensor network. Combined with environmental interference factors and signal strength levels, it analyzes the range of abnormal fluctuations and obtains the classification results of the current shutdown event. The state transition module, based on the shutdown event classification results, uses a preset state transition diagram, and according to the state node definition and transition condition rules, combined with path priority sorting and mode hierarchy division, matches multi-level shutdown modes to determine the specific mode switching path; The hazard identification module, if the mode switching path involves an emergency shutdown scenario, queries the database to determine the switching time constraints and abnormal status markers, and combines them with historical path records to obtain the real-time status parameters of relevant mechanical components and judge the distribution of potential hazards. The path detection module uses path conflict detection technology to analyze the distribution of potential hazards, analyze downtime intervals and fault frequency distribution, and compare with historical data to determine the specific impact range and priority order of the hazards. The protection measures module obtains a predefined sequence of protection measures based on the impact range and priority of potential hazards, and generates a targeted inspection process checklist by combining environmental interference factors and signal strength levels.

2. The explosion-proof robot combination control system for complex working environments according to claim 1, characterized in that: The sensor acquisition module collects trigger signal categories and equipment status indicators in the robot's operating environment in real time through a sensor network. Combining environmental interference factors and signal strength levels, it analyzes the range of abnormal fluctuations to obtain the classification results of the current shutdown event, including: By using a sensor network, trigger signal types and device status indicators are collected from the robot's operating environment to obtain an initial data set; Based on the initial dataset, environmental interference factors and signal strength levels are obtained. The range of abnormal fluctuations is determined by calculating the weighted impact of interference factors on the signal and comparing the strength levels. If the abnormal fluctuation range exceeds the preset threshold, then the time sequence change, amplitude deviation and frequency shift are obtained from the abnormal fluctuation range as feature values ​​to obtain the fluctuation feature set; The support vector machine algorithm is used to determine the type of the current shutdown event by taking the fluctuation feature set as input and fusing the interference and intensity correlation data in the environmental data attributes, and obtaining a preliminary classification label. Based on the preliminary classification labels, the correlation indicators of trigger signals, equipment status and fluctuation range in the environmental data attributes are obtained to obtain the detailed classification results of the current shutdown event.

3. The explosion-proof robot combination control system for complex working environments according to claim 1, characterized in that: The state transition module, based on the shutdown event classification results, uses a preset state transition diagram, and according to the state node definitions and transition condition rules, combined with path priority sorting and mode hierarchy division, matches multi-level shutdown modes to determine the specific mode switching path, including: Based on the shutdown event classification results, the initial state node definitions and transition condition rules are obtained from the preset state transition diagram to obtain the matching node sequence; By using node sequences, combined with path priority sorting and pattern hierarchy division, a potential set of pattern paths is determined. For the set of mode paths, the event recovery strategy and real-time monitoring indicators are integrated, and the timing correlation of multi-level shutdown modes is judged by comparing the timing change deviation, so as to obtain path optimization indicators. By using path optimization indicators, historical data fusion and predicted state deviation are obtained, and specific mode switching paths are matched by comparing deviation values. If the mode switching path meets the transition condition rules, the final switching sequence is extracted from the path to determine the specific mode switching path.

4. The explosion-proof robot combination control system for complex working environments according to claim 1, characterized in that: The hazard identification module, if the mode switching path involves an emergency shutdown scenario, queries the associated database for switching time constraints and abnormal state markers, and combines this with historical path records to obtain the real-time state parameters of relevant mechanical components, thereby determining the distribution of potential hazards, including: By using the mode switching path, we can obtain the associated database under the emergency shutdown scenario, query the switching time constraints and abnormal status markers, and obtain preliminary indicators of potential hazards. Based on the preliminary indicators of potential hazards and combined with historical path records, real-time status parameters are extracted from a pre-set mechanical parts library to determine the distribution of potential hazards. By analyzing the distribution of potential hazards and integrating real-time monitoring data, we can determine the correlation deviations between components and obtain an optimized path sequence. Based on the optimized path sequence, multi-level shutdown modes are matched to obtain the final mode switching path.

5. The explosion-proof robot combination control system for complex working environments according to claim 1, characterized in that: The path detection module, based on the distribution of potential hazards, employs path conflict detection technology to analyze downtime intervals and fault frequency distributions. By comparing this data with historical data, it determines the specific impact range and priority order of the hazards, including: For the assessment of hazard distribution, the failure frequency statistics are obtained from the division of shutdown areas, and the correlation of hazard points is determined by the identification of conflict paths to obtain the scope of impact. By defining the scope of impact, integrating historical data, comparing statistical deviations in failure frequency, determining the priority ranking mechanism, and identifying status parameter monitoring; Based on the monitoring of status parameters, the difference values ​​between components are extracted in the deviation correlation calculation to obtain the path sequence adjustment; By verifying the matching pattern through path sequence adjustment and combining it with the time constraints in the shutdown scenario simulation, the specific impact range and priority order of the hidden dangers can be determined.

6. The explosion-proof robot combination control system for complex working environments according to claim 1, characterized in that: The protection measures module, based on the impact range and priority order of the potential hazards, obtains a predefined sequence of protection measures, and, combined with environmental interference factors and signal strength levels, generates a targeted inspection process checklist that integrates different modes, including: Priority ranking is extracted from the definition of potential hazards, and a predefined sequence of protection measures is obtained from the extraction results. Adjustment values ​​are then obtained by combining environmental interference assessment and signal strength classification. By adjusting the influencing factors of value fusion, the generation path of pattern connection is determined, and a targeted pattern sequence is identified; Based on the targeted pattern sequence matching interference signal, a checklist fusion framework is generated to obtain the output of the process generation mechanism; The process generation mechanism prioritizes matching output connections, extracts measures to optimize parameters, and determines the inspection process list.

7. The explosion-proof robot combination control system for complex working environments according to claim 6, characterized in that, It also includes a process simulation module, which, by examining the process list and using historical path records and transition condition rules in the state transition diagram, simulates the process execution logic to determine the startup conditions and execution order of the recovery program. Specifically, it includes: Historical path records are obtained from the inspection process checklist. The historical path records are then matched with path nodes and fused with condition constraints using transfer condition rules to obtain the simulated execution path. The execution logic is simulated by matching the execution path. The recovery startup conditions are determined by comparing path nodes, and the execution order is determined. By combining the execution order with the conditional judgment mechanism, the order optimization adjustment is obtained, and the adjustment value is applied to the path sequence to obtain the logical simulation framework; By integrating the startup threshold setting through a logic simulation framework, if the startup threshold setting exceeds the preset threshold, the recovery startup conditions are obtained through threshold comparison. Extract transfer condition rules from the recovery startup conditions, apply the rules to the sequence path, and obtain the execution order determination.

8. The explosion-proof robot combination control system for complex working environments according to claim 1, characterized in that, It also includes a data fusion module. If the conditions for starting the recovery procedure are met, the data fusion module integrates the inspection process list with the recovery procedure, and combines the abnormal fluctuation range and equipment status indicators to obtain a complete protection strategy output for abnormal vibration of robot components, specifically including: Vibration data is obtained from the abnormal fluctuation range. After normalization, the vibration data is integrated with the equipment status indicators by weighted average to obtain preliminary fusion results. For the preliminary fusion results matching checklist, the recovery program start condition judgment is adopted. If the condition is met, the integration path is determined by comparing the path nodes with the fusion checklist. By integrating path and robot component monitoring attributes, and applying threshold constraints to the fluctuation range, the combined fluctuation range value is obtained, resulting in a fused sequence of state indicators. The protection strategy output is extracted from the fusion sequence of state indicators, and a complete strategy is generated by mapping sequence nodes for vibration anomaly detection.

9. A combination control system for explosion-proof robots in complex working environments according to claim 8, characterized in that, It also includes a feedback verification module, which verifies the effectiveness of mode connection using a feedback loop mechanism for the protection strategy output. Combining state node definitions and path priority sorting, it determines the overall process's complete coverage of component vibration anomalies. Specifically, this includes: Vibration data is obtained from the abnormal fluctuation range, and the vibration data is integrated to obtain preliminary fusion results; Based on the initial fusion results and the defined status nodes, the integration path is determined by prioritizing the paths. By integrating the path with the equipment status, a threshold constraint is applied to the vibration anomaly coverage. The threshold constraint is achieved by comparing the abnormal fluctuation range with a preset standard value to obtain the coverage sequence value. The recovery procedure start conditions are extracted from the covered sequence values. The extraction is achieved by filtering sequence nodes. A feedback loop mechanism is used to verify the effectiveness of the mode connection and to determine the completeness of the overall process. If the overall process integrity meets the preset threshold, the integrity of the output for component vibration anomalies will be generated through the integrity strategy.

10. The explosion-proof robot combination control system for complex working environments according to claim 1, characterized in that, It also includes an adaptive optimization module, which adjusts the mode hierarchy division and switching time constraints based on the determined coverage completeness, obtains the optimized safety inspection framework, and determines the final protection logic for abnormal vibration of robot components, specifically including: The adjustment parameters are obtained from the coverage completeness. The adjustment parameters are matched with the hierarchical division of the matching mode. The hierarchical boundary is determined by the threshold comparison. The threshold comparison compares the adjustment parameters with the preset hierarchical standard value one by one. If the parameter is higher than the standard value, it is classified into a higher level, thus obtaining the hierarchical division sequence. To address the time constraint for integrating and switching hierarchical partitioning sequences, a preset threshold constraint time interval is used. If the interval exceeds the threshold, the constraint is reset. The reset is achieved by subtracting the threshold difference from the interval value to obtain the constraint optimization value. The security check framework elements are extracted from the constraint optimization values, and the framework structure is generated through the element fusion module. The element fusion module sorts the extracted elements by priority and then stacks them layer by layer to determine the internal verification logic of the framework. To address the internal verification logic of the framework, component durability assessment is introduced. The assessment data is then integrated into the framework. If the assessment data is abnormal, the response path is activated. Activation is triggered by matching abnormal data with a logical threshold, resulting in a draft of the protection logic. The draft protection logic verifies the abnormal vibration coverage of robot components. The draft parameters are adjusted through the sequence integration module, which optimizes the draft parameters after scanning for abnormal coverage sequences to determine the final protection logic.

11. A robot that uses the explosion-proof robot combination control system for complex working environments as described in any one of claims 1-10 to realize robot walking operations through the control system.