Electric quantity theft detection method and system based on ultrasonic vibration spectrum

By constructing a three-dimensional correlation model of power grid topology, user profiles, and ultrasonic features, and combining ultrasonic sensors and data fusion technology, electricity theft behavior can be accurately screened and verified, achieving real-time and efficient identification of electricity theft detection, thus improving power grid security and economic benefits.

CN121933780APending Publication Date: 2026-04-28STATE GRID HEBEI ELECTRIC POWER CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
STATE GRID HEBEI ELECTRIC POWER CO LTD
Filing Date
2025-11-27
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing electricity theft detection technologies rely on manual inspections and offline analysis, which have problems such as limited coverage, slow response, and insufficient real-time performance, making it difficult to meet the power system's needs for detecting electricity theft.

Method used

A three-dimensional correlation model based on power grid topology, user profiles, and ultrasonic features is constructed. Power equipment signals are captured by ultrasonic sensors. Combined with power load and equipment status data, time calibration and data fusion are performed to screen out dual-abnormal targets with abnormal ultrasonic features and abnormal behavioral trajectories. Consistency cross-comparison is performed to output targeted handling instructions for electricity theft type, location, and evidence, and feature thresholds are dynamically updated.

Benefits of technology

It achieves precise, real-time, and efficient detection of electricity theft, solving the problems of poor adaptability and insufficient real-time performance of traditional detection technologies, ensuring the safe and stable operation of the power grid and minimizing losses for power companies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121933780A_ABST
    Figure CN121933780A_ABST
Patent Text Reader

Abstract

The invention provides an electric quantity theft detection method and system based on an ultrasonic vibration spectrum, and belongs to the technical field of electric quantity detection, and the method comprises the steps: constructing a correlation model, analyzing a target region feature and a user portrait, and presetting a feature threshold value of an electricity theft type and an abnormal triggering condition; capturing an ultrasonic signal, calling electricity load of an electricity meter and running state data of equipment, and carrying out time calibration and data fusion; converting the ultrasonic signal into a frequency spectrum feature vector, and screening out double abnormal targets with an ultrasonic feature anomaly and a behavior track anomaly; signal enhanced acquisition, power utilization data time sequence reconstruction and equipment state remote diagnosis are started for the double abnormal targets, and the electricity stealing behavior is confirmed; and outputting a targeted treatment instruction, and updating the feature threshold value and the abnormal triggering condition. According to the electric quantity theft detection method based on the ultrasonic vibration spectrum provided by the invention, the accuracy, real-time performance and high efficiency of electric quantity theft detection are realized through an active identification mode of accurate screening, multi-dimensional verification, targeted treatment and dynamic optimization.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of power detection technology, and more specifically, relates to a power theft detection method and system based on ultrasonic vibration spectrum. Background Technology

[0002] As power systems evolve towards intelligence and distributed computing, electricity theft has become a critical issue hindering the safe operation of the power grid and the economic benefits of power companies. Such activities not only result in the loss of hundreds of millions of kilowatt-hours of electricity annually but also disrupt the grid load balance, leading to localized line overloads, equipment overheating, and even fires. For example, cable burnouts caused by "meter bypassing" in rural transformer substations, or power outages in commercial complexes caused by "concealed bypass" electricity theft, directly impact the stability of residential electricity use and industrial production. Currently, existing electricity theft detection technologies largely rely on regular manual inspections, resulting in limited coverage and delayed response times. While intelligent algorithm-based identification technologies are employed, their offline analysis mode lacks real-time capability, failing to meet the demands of distribution networks for detecting electricity theft. Summary of the Invention

[0003] The purpose of this application is to provide a method and system for detecting electricity theft based on ultrasonic vibration spectrum, so as to solve the technical problem that the existing technology has insufficient electricity theft detection performance and cannot meet the needs of power system.

[0004] To achieve the above objectives, the technical solution adopted in this application is as follows: A method for detecting electricity theft based on ultrasonic vibration spectrum is provided, comprising: S1: Constructing a correlation model with power grid topology, user profile, and ultrasonic features as dimensions; analyzing the power grid topology features and user electricity consumption behavior profile of the target area; combining the ultrasonic vibration spectrum and partial discharge signal patterns; and presetting ultrasonic feature thresholds for the type of electricity theft and abnormal user behavior triggering conditions; S2: Capturing ultrasonic signals from power equipment using ultrasonic sensors; retrieving data on meter load and equipment operating status; forming a three-source data stream and performing time calibration and data fusion; S3: Converting the ultrasonic signal into a spectral feature vector; comparing it with the thresholds in the correlation model; and filtering out dual-abnormal targets with abnormal ultrasonic features and abnormal behavioral trajectories; S4: Initiating ultrasonic signal enhancement acquisition, electricity data time-series reconstruction, and remote equipment status diagnosis for dual-abnormal targets; and performing a consistency cross-comparison with the three-source data streams in S2 to confirm the electricity theft behavior; S5: Outputting targeted handling instructions for the type, location, and evidence of electricity theft, and updating the ultrasonic feature thresholds and abnormal user behavior triggering conditions.

[0005] In one possible implementation, in S1, when constructing the association model, the power grid topology parameters are first decomposed into a grid to extract core topology features such as line node correlation, impedance distribution, and load carrying threshold. Then, user electricity consumption data is grouped using a clustering algorithm to generate a baseline electricity consumption behavior profile for users of the same type. Finally, ultrasonic signal samples of different types of electricity theft are associated with topology features and user profiles for training, and feature weights are optimized using a gradient boosting tree algorithm to form a strong correlation mapping relationship between the three dimensions of power grid topology, user profile, and ultrasonic features.

[0006] In one possible implementation, the user's electricity consumption behavior profile includes collecting the user's electricity consumption time-series data for the past 12 months, extracting peak electricity consumption periods, load fluctuation amplitude, and seasonal variation coefficient features through a sliding window algorithm, and combining the user's industry type, list of electrical equipment, and historical repair records to construct a dynamically updated user profile. When the user's electricity consumption behavior deviates from its own historical profile by more than 30% or deviates from the profile of similar users by more than 40%, an abnormal behavior marker is triggered.

[0007] In one possible implementation, in S2, the ultrasonic sensors are arranged in an array and deployed according to a two-layer architecture of core nodes and edge terminals; the core node deploys a 16-unit ultrasonic sensor array to cover line branch nodes; the edge terminal deploys an 8-unit ultrasonic sensor array to cover end-user electrical equipment; during the deployment of the ultrasonic sensors, the sensor installation angle is calculated using the power grid topology diagram to ensure that the monitoring range overlap rate of adjacent sensors is ≥15%; the three-source data streams adopt a timestamp alignment mechanism, using the ultrasonic signal acquisition time as a reference to perform time calibration on the power consumption data and equipment status data, with the synchronization error controlled within 5ms.

[0008] In one possible implementation, in S3, the ultrasonic signal is first decomposed into 4-6 layers of detail coefficients through wavelet packet transform, and the main frequency offset, harmonic distortion rate, and spectral entropy features are extracted to construct a spectral feature vector. Then, the cosine similarity algorithm is used to calculate the matching degree between the spectral feature vector and various electricity theft feature thresholds in the three-dimensional association model. When the matching degree is ≥80%, the equipment operation record and user electricity consumption trajectory are retrieved. When the ultrasonic feature matching degree is ≥80% and any of the following abnormal user behavior triggering conditions are met, it is marked as a double abnormal target. The abnormal user behavior triggering conditions include a sudden change in electricity load of ≥30% without explanation from power grid dispatch or equipment maintenance, continuous low load operation for more than 12 hours during non-peak electricity consumption periods, and a difference of ≥40% in electricity consumption compared with similar users during the same period, or the equipment wiring status change record and electricity consumption data are not synchronized, and the electricity load drops by more than 25% after the change.

[0009] In one possible implementation, when screening for dual-abnormal targets, an initial screening is first completed based on the matching degree of ultrasonic features. Then, behavioral trajectory cross-validation is initiated on the initial screening results. During the validation, electricity consumption data of similar users in the same period are automatically retrieved to build a temporary benchmark. By comparing the electricity consumption differences between the target user and the temporary benchmark, misjudgments caused by changes in the user's own electricity consumption habits are eliminated, and the dual-abnormal targets are finally locked.

[0010] In one possible implementation, in S4, the ultrasonic signal enhancement acquisition includes automatically adjusting the beam direction of the sensors corresponding to the dual anomaly targets, focusing on the target device, and narrowing the beamwidth to 15°-30°; increasing the acquisition frequency from 100ms / time to 20ms / time, increasing the signal gain by 5-8dB; expanding the spectrum acquisition band to 10kHz-2MHz to ensure the capture of weak partial discharge signals; and simultaneously initiating collaborative acquisition of the sensor array, enhancing the target signal strength through multi-unit signal superposition; the power consumption data time-series reconstruction includes using a sliding window algorithm to segment the power consumption data of the dual anomaly targets, reconstructing... The system constructs a time-series curve of electrical load; analyzes the abrupt change points and stable segment characteristics of the curve using a trend fitting algorithm, and calculates the abrupt change slope and duration; when the abrupt change slope is ≥0.8 and the duration is ≥10 minutes, and there are no external factors, the electrical load abrupt change verification is deemed successful; the remote equipment status diagnosis includes retrieving infrared imaging data, wiring standard diagrams, and historical maintenance records of the power equipment corresponding to the dual abnormal targets; identifying abnormal statuses such as loose wiring terminals, abnormal wire connections, and damaged seals using an image comparison algorithm; combining the partial discharge characteristics in the ultrasonic signal, and when the equipment status abnormality identification rate is ≥85%, the equipment wiring status consistency verification is deemed successful.

[0011] In one possible implementation, in S5, the targeted handling instruction is pushed to the operation and maintenance system and triggers the on-site verification process. When updating the ultrasonic feature threshold and the abnormal user behavior triggering conditions, an incremental learning algorithm is used to supplement the confirmed electricity theft case data into the model training set. Only the newly added data is used for local model training, and the feature threshold and behavior triggering conditions of the corresponding electricity theft type are adjusted without retraining the entire model.

[0012] In one possible implementation, S6 is also included: transmitting ultrasonic stimulation signals to the power equipment corresponding to the dual abnormal targets, collecting the response signals and power load change data after stimulation, and verifying them; at the same time, calling the cross-regional electricity theft feature database for collaborative comparison, and if there are unmatched features, triggering cross-regional parameter sharing update.

[0013] The beneficial effects of the ultrasonic vibration spectrum-based power theft detection method provided in this application are as follows: Compared with the prior art, the ultrasonic vibration spectrum-based power theft detection method of this application first constructs a three-dimensional correlation model based on power grid topology, user profile, and ultrasonic features. Through in-depth analysis of the power grid wiring structure and historical electricity consumption behavior patterns of the target area, combined with the ultrasonic vibration spectrum distortion characteristics and partial discharge signal patterns corresponding to different types of power theft (such as meter bypassing, concealed bypass, etc.), it presets differentiated ultrasonic feature threshold ranges and abnormal user behavior triggering conditions, establishing accurate and adaptable judgment criteria for subsequent detection. This solves the problems of fixed thresholds and inapplicability to different scenarios in traditional detection techniques. The problem of poor compatibility with different types of electricity theft was addressed; subsequently, multi-source data synchronous acquisition was initiated. Ultrasonic sensors were used to capture in real time abnormal vibration signals (such as mechanical vibrations caused by current distortion) and partial discharge signals (such as electric field breakdown discharges caused by abnormal wiring) caused by electricity theft during the operation of power equipment. Simultaneously, real-time power load data from smart meters and power equipment operating status data were retrieved. After time calibration and data fusion processing, a three-source data stream of ultrasonic signals, power consumption data, and equipment status was formed. This broke through the limitations of traditional technologies that relied solely on single electrical data or physical signals, providing complete data support for accurate detection. Then, by converting the real-time ultrasonic signals into standardized spectral feature vectors, and... The first step compares the data against the preset threshold range for electricity theft characteristics, while tracing the corresponding power equipment operation records and user electricity consumption trajectories. This filters out dual-anomaly targets with both ultrasonic feature anomalies and behavioral trajectory anomalies, initially identifying suspected electricity theft targets and avoiding misjudgments caused by single-dimensional anomalies, thus improving the accuracy of the initial screening. Further verification is then conducted on dual-anomaly targets by activating ultrasonic signal enhancement to improve the ability to capture weak anomaly signals, reconstructing the time series of electricity consumption data to clearly present load change characteristics, and performing remote equipment status diagnosis to identify physical modifications such as wiring anomalies. This data is then cross-checked with the three-source data streams formed in the second step to determine the physical anomalies (ultrasonic features and behavioral trajectory anomalies). The system verifies the authenticity of electricity theft from three dimensions: sound signals, electricity consumption behavior (load data), and equipment status (operation data). It thoroughly distinguishes electricity theft from false anomalies such as environmental interference and occasional equipment failures, solving the problem that traditional passive detection cannot accurately identify false alarms. Finally, it outputs targeted handling instructions containing the type of electricity theft, precise location, and complete evidence chain (ultrasound spectrum comparison chart, abnormal electricity trajectory report, and equipment status diagnosis results). This eliminates the need for maintenance personnel to conduct blind investigations, significantly shortening response time. At the same time, by dynamically updating the ultrasonic feature thresholds and abnormal user behavior triggering conditions, the model continuously adapts to new electricity theft methods, avoiding the shortcomings of traditional algorithms that rely on samples and have weak ability to identify new types of electricity theft.

[0014] This approach upgrades passive detection to an active identification mode that involves precise screening, multi-dimensional verification, targeted processing, and dynamic optimization. It solves the problems of limited coverage and delayed response of manual inspections, and overcomes the shortcomings of traditional intelligent algorithms, such as offline analysis and insufficient real-time performance. This achieves precision, real-time performance, and high efficiency in electricity theft detection, ensuring the safe and stable operation of the power grid and minimizing economic losses to power companies caused by electricity theft. It has strong practical application value.

[0015] Another objective of this application is to provide a power theft detection system based on ultrasonic vibration spectrum, including any of the above-mentioned power theft detection methods based on ultrasonic vibration spectrum.

[0016] The electricity theft detection system based on ultrasonic vibration spectrum provided in this application adopts an ultrasonic vibration spectrum-based electricity theft detection method, upgrading passive detection to an active identification mode that has undergone precise screening, multi-dimensional verification, targeted handling, and dynamic optimization. It not only solves the problems of limited coverage and slow response of manual inspection, but also overcomes the shortcomings of traditional intelligent algorithms in offline analysis and insufficient real-time performance. It achieves accurate, real-time, and efficient electricity theft detection, ensuring the safe and stable operation of the power grid and minimizing the economic losses caused by electricity theft to power companies. It has extremely strong practical application value. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 This is a front view of the power theft detection method based on ultrasonic vibration spectrum provided in the embodiments of this application. Detailed Implementation

[0019] To make the technical problems, technical solutions, and beneficial effects to be solved by this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and are not intended to limit the scope of this application.

[0020] It should be noted that when a component is referred to as being "fixed to" or "set on" another component, it can be directly on or indirectly on that other component. When a component is referred to as being "connected to" another component, it can be directly connected to or indirectly connected to that other component.

[0021] It should be understood that the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application.

[0022] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, "multiple" means two or more, unless otherwise explicitly specified.

[0023] Please see Figure 1 This application describes a method for detecting electricity theft based on ultrasonic vibration spectrum. The method includes: S1: Constructing a correlation model with power grid topology, user profile, and ultrasonic features as dimensions; analyzing the power grid topology features and user electricity consumption behavior profiles of the target area; combining ultrasonic vibration spectrum and partial discharge signal patterns; and presetting ultrasonic feature thresholds for the type of electricity theft and abnormal user behavior triggering conditions; S2: Capturing ultrasonic signals from power equipment using ultrasonic sensors; retrieving data on meter load and equipment operating status; forming a three-source data stream and performing time calibration and data fusion; S3: Converting the ultrasonic signal into a spectral feature vector; comparing it with the thresholds in the correlation model; and filtering out dual-abnormal targets with abnormal ultrasonic features and abnormal behavioral trajectories; S4: Initiating ultrasonic signal enhancement acquisition, electricity data time-series reconstruction, and remote equipment status diagnosis for the dual-abnormal targets; performing a consistency cross-comparison with the three-source data streams in S2 to confirm the electricity theft behavior; S5: Outputting targeted handling instructions for the type, location, and evidence of electricity theft; and updating the ultrasonic feature thresholds and abnormal user behavior triggering conditions.

[0024] The electricity theft detection method based on ultrasonic vibration spectrum provided in this application, compared with existing technologies, firstly constructs a three-dimensional correlation model based on power grid topology, user profile, and ultrasonic features. Through in-depth analysis of the power grid wiring structure and historical electricity consumption patterns of users in the target area, and combining the ultrasonic vibration spectrum distortion characteristics and partial discharge signal patterns corresponding to different types of electricity theft (such as meter bypassing, concealed bypass, etc.), it presets differentiated ultrasonic feature threshold ranges and abnormal user behavior triggering conditions, establishing accurate and adaptable judgment criteria for subsequent detection. This solves the problems of fixed thresholds and poor adaptability to different scenarios and types of electricity theft in traditional detection technologies. Subsequently, it initiates multi-source data synchronization... The first step involves data acquisition. Ultrasonic sensors capture real-time vibration signals (such as mechanical vibrations caused by current distortion) and partial discharge signals (such as electric field breakdown discharges caused by wiring abnormalities) from electrical equipment during operation, indicating potential electricity theft. Simultaneously, real-time power load data from smart meters and operational status data from electrical equipment are retrieved. After time calibration and data fusion processing, a three-source data stream—ultrasonic signal, power consumption data, and equipment status—is formed. This overcomes the limitations of traditional technologies that rely solely on single electrical data or physical signals, providing comprehensive data support for accurate detection. Next, the real-time ultrasonic signal is converted into a standardized spectral feature vector and compared with the preset electricity theft characteristic threshold range from the first step. By comparing the data and tracing the corresponding power equipment operation records and user electricity consumption trajectories, dual-anomaly targets with both ultrasonic feature anomalies and behavioral trajectory anomalies were identified, initially pinpointing suspected electricity theft targets and avoiding misjudgments caused by single-dimensional anomalies, thus improving the accuracy of the initial screening. Further verification was conducted on the dual-anomaly targets by enhancing ultrasonic signal acquisition to improve the capture of weak anomaly signals, reconstructing the time series of electricity consumption data to clearly present load change characteristics, and performing physical modifications such as remote equipment status diagnosis to identify wiring anomalies. These modifications were then cross-checked with the three-source data streams formed in the second step to determine the consistency of the data. This system verifies the authenticity of electricity theft across three dimensions: load data, equipment status (operational data), and thoroughly distinguishes between electricity theft and pseudo-anomaly scenarios such as environmental interference and occasional equipment malfunctions. This solves the problem of traditional passive detection's inability to accurately identify false alarms. Finally, it outputs targeted handling instructions containing the type of electricity theft, precise location, and a complete chain of evidence (ultrasonic spectrum comparison chart, abnormal power consumption trajectory report, and equipment status diagnosis results). This eliminates the need for maintenance personnel to conduct blind investigations, significantly shortening response time. Furthermore, by dynamically updating ultrasonic feature thresholds and abnormal user behavior triggering conditions, the model continuously adapts to new electricity theft methods, avoiding the shortcomings of traditional algorithms that rely on sample data and have weak ability to identify new types of electricity theft.

[0025] This approach upgrades passive detection to an active identification mode that involves precise screening, multi-dimensional verification, targeted processing, and dynamic optimization. It solves the problems of limited coverage and delayed response of manual inspections, and overcomes the shortcomings of traditional intelligent algorithms, such as offline analysis and insufficient real-time performance. This achieves precision, real-time performance, and high efficiency in electricity theft detection, ensuring the safe and stable operation of the power grid and minimizing economic losses to power companies caused by electricity theft. It has strong practical application value.

[0026] Please see Figure 1 As a specific implementation of the electricity theft detection method based on ultrasonic vibration spectrum provided in this application, in S1, when constructing the association model, the power grid topology parameters are first decomposed into a grid to extract the core topology features such as line node correlation, impedance distribution, and load carrying threshold; then, the user electricity consumption data is grouped by a clustering algorithm to generate a benchmark electricity consumption behavior profile of similar users; finally, ultrasonic signal samples of different types of electricity theft are associated with topology features and user profiles for training, and the feature weights are optimized by gradient boosting tree algorithm to form a strong correlation mapping relationship between the three dimensions of power grid topology, user profile, and ultrasonic features. First, in the power grid topology feature processing stage, a grid-based decomposition method is adopted. The power grid is divided into several independent grid units according to the line distribution and voltage level of the target power supply area. Three core topology features are accurately extracted: line node correlation (reflecting the tightness of the connection between nodes, such as the correlation strength between transformers and user meters), impedance distribution (characterizing the power transmission loss characteristics of lines), and load carrying threshold (the upper limit of safe power load for each line / node). This avoids the scenario adaptation deviation caused by the generalized processing of the power grid topology in traditional models, allowing the model to accurately locate abnormal correlation nodes in a way that fits the specific power grid structure. Subsequently, for user electricity consumption data, a clustering algorithm is used to group users according to dimensions such as industry type, electricity consumption scale, and load fluctuation patterns. Users with similar electricity consumption behaviors are grouped together to generate a benchmark electricity consumption behavior profile for the same type of user (such as peak electricity consumption periods for residential users and load fluctuation standards for commercial users). This eliminates the limitations of using historical data of a single user as a benchmark and effectively removes the interference of differences in individual user electricity consumption habits on anomaly detection. Finally, a massive amount of ultrasonic signal samples (including vibration spectrum features and partial discharge signal features) of different types of electricity theft (such as meter bypass and concealed bypass) are fused with the aforementioned extracted power grid topology features and benchmark profiles of similar users, and correlation training is carried out through gradient boosting tree algorithm.

[0027] This algorithm automatically learns the correlation between three types of features and electricity theft. It assigns higher weights to highly correlated features (such as the correlation between node correlation and short-circuit theft, and the correlation between pulse cluster density ultrasonic features and conductor damage theft), while reducing the weights of low-correlation interference features (such as occasional short-term load fluctuations). This ultimately forms a strong correlation mapping relationship between the power grid topology, user profile, and ultrasonic features. The entire implementation process, through hierarchical decomposition, precise extraction, and intelligent correlation, allows the correlation model to break free from the rigid mode of traditional fixed thresholds and general templates: gridded decomposition ensures the model adapts to different power grid structures; clustering and grouping make user profiles more representative and comparable; and the gradient boosting tree algorithm's weight optimization strengthens the judgment role of key features. The synergy of these three elements gives the constructed correlation model advantages such as strong scenario adaptability, accurate judgment benchmarks, and outstanding anti-interference capabilities, providing a reliable judgment basis for the subsequent third step of feature reverse matching and dual-anomaly target screening.

[0028] Please see Figure 1As a specific implementation of the electricity theft detection method based on ultrasonic vibration spectrum provided in this application, the user electricity behavior profile includes collecting the user's electricity consumption time-series data for the past 12 months, extracting peak electricity consumption periods, load fluctuation amplitude, and seasonal variation coefficient features through a sliding window algorithm, and combining these with the user's industry type, list of electrical equipment, and historical repair records to construct a dynamically updated user profile. When a user's electricity consumption behavior deviates from its own historical profile by more than 30% or from the profile of similar users by more than 40%, an abnormal behavior marker is triggered. Operationally, the focus is first on the user's electricity consumption time-series data for the past 12 months. The selection of 12 months is to fully cover the seasonal changes in electricity consumption (such as residential air conditioning in summer). The system uses load data (including winter commercial heating load) to avoid baseline bias caused by short-term data (1-2 months) failing to reflect seasonal patterns. Then, a sliding window algorithm (e.g., setting the window length to 1 day and sliding through the time series) is used to extract core features: peak electricity consumption periods (e.g., residential users mostly consume electricity between 18:00-22:00, and commercial users mostly consume electricity between 9:00-21:00) to anchor users' regular electricity consumption habits; load fluctuation amplitude (calculating the ratio of the daily maximum and minimum load values ​​to the average value) to measure electricity consumption stability; and seasonal variation coefficient (the ratio of the average load in different seasons to the annual average value) to quantify the impact of seasons on electricity consumption. These three features outline a complete electricity consumption pattern from the dimensions of time period, stability, and season. Subsequently, the user profile is not solely based on electricity consumption data. Instead, it integrates user industry type (differentiating between residential, commercial, and industrial electricity consumption attributes), a list of electrical equipment (including users with high-power equipment such as central air conditioning, whose peak load is significantly higher), and historical repair records (such as excluding load anomalies during equipment failure repairs to avoid misjudging electricity theft). A dynamic update mechanism is also implemented: new electricity consumption data is added every 1-2 months, and the oldest data is removed to ensure the profile aligns with current user habits and avoids outdated baselines. Finally, anomaly triggers employ a dual deviation threshold: a deviation exceeding 30% from the user's own historical profile (allowing reasonable fluctuations such as temporary equipment additions to capture significant anomalies), or a deviation exceeding 40% from similar user profiles (groups of users in the same industry and with similar equipment size, segmented by clustering algorithms) (excluding individual differences and focusing on prominent anomalies within the group), is flagged as an abnormal behavior.

[0029] This approach combines full-cycle data with multi-dimensional features to avoid the one-sidedness of single data and make the profile more realistic. Furthermore, dynamic updates solve the problem that traditional static benchmarks cannot keep up with changes in user habits, reducing false alarms. At the same time, the dual bias trigger takes into account both individual history and comparison with similar groups, which not only accurately captures abnormal changes in the user but also eliminates misjudgments caused by industry characteristics and device differences.

[0030] Please see Figure 1As a specific implementation of the power theft detection method based on ultrasonic vibration spectrum provided in this application, in S2, the ultrasonic sensors are arranged in an array and deployed according to a two-layer architecture of core nodes and edge terminals; the core node deploys a 16-unit ultrasonic sensor array to cover the line branch nodes; the edge terminal deploys an 8-unit ultrasonic sensor array to cover the end-user equipment; during the deployment of the ultrasonic sensors, the sensor installation angle is calculated through the power grid topology diagram to ensure that the monitoring range overlap rate of adjacent sensors is ≥15%; the three-source data streams adopt a timestamp alignment mechanism, using the acquisition time of the ultrasonic signal as a reference to perform time calibration on the power consumption data and equipment status data, and the synchronization error is controlled within 5ms; firstly, focusing on the two-layer architecture deployment of the ultrasonic sensors, the first step is to clarify the deployment location and array configuration, and the core node is selected as a key line branch node of the power grid. (For example, at the outgoing line of a substation or the connection point of a transformer in a distribution area), a 16-unit ultrasonic sensor array is deployed. These nodes have intersecting lines and complex signals; the 16-unit array can enhance the capture capability of weak signals (such as abnormal vibrations of long-distance conductors) through multi-unit collaboration, achieving wide-area coverage. For edge terminals corresponding to end-user electrical equipment (such as user meter boxes or in-home cable joints), an 8-unit ultrasonic sensor array is deployed. Since the signals from end-user equipment are relatively concentrated, the 8-unit array can reduce deployment costs while ensuring monitoring accuracy, forming full-link coverage from core control branches to edge control terminals. The second step calculates the installation angle, combining it with the target area's power grid topology (including line routing, equipment spacing, building obstructions, etc.), and simulates the monitoring range of each sensor using a spatial geometric projection algorithm to determine the optimal pitch and azimuth angles, ensuring that the monitoring range overlap rate of adjacent sensors is ≥15%. In distributed lines, the sensor angles are adjusted to ensure overlapping coverage of adjacent equipment's monitoring ranges, avoiding monitoring blind spots due to dispersed lines. In densely populated distribution areas, overlapping coverage enhances signal redundancy and improves the reliability of signal acquisition in complex environments. The process then proceeds to synchronize the three data streams. The first step is to establish a synchronization benchmark, using the acquisition time of the ultrasonic signal as the reference. Since the ultrasonic signal is the direct physical feedback of electricity theft, using this benchmark ensures the temporal correlation between physical anomalies and electrical parameters and equipment status. The second step is to perform timestamp alignment. The timestamps of the smart meter's power load data and equipment status data (such as wiring detection records and start / stop logs) are supplemented or calibrated using the Network Time Protocol (NTP). For data with time deviations (such as delayed upload of meter data), a linear interpolation algorithm is used to correct them. Ultimately, the synchronization error of the three data sources is strictly controlled within 5ms. The third step is to preprocess the synchronized data to remove abnormal pulse values ​​caused by transmission delays, ensuring the continuity and integrity of the data stream.

[0031] Please see Figure 1As a specific implementation of the power theft detection method based on ultrasonic vibration spectrum provided in this application, in S3, the ultrasonic signal is first decomposed into 4-6 layers of detail coefficients through wavelet packet transform, and the main frequency offset, harmonic distortion rate, and spectral entropy features are extracted to construct a spectral feature vector; then, the cosine similarity algorithm is used to calculate the matching degree between the spectral feature vector and various power theft feature thresholds in the three-dimensional association model. When the matching degree is ≥80%, the equipment operation record and user power consumption trajectory are retrieved; when the ultrasonic feature matching degree is ≥80% and any of the following abnormal user behavior triggering conditions are met, it is marked as a double abnormal target. The abnormal user behavior triggering conditions include a sudden change in power load of ≥30% without explanation of grid dispatch or equipment maintenance, continuous low load operation for more than 12 hours during non-peak power consumption periods, and a power consumption difference of ≥40% compared with similar users in the same period, or the equipment wiring status change record and power consumption data change are not synchronized, and the power load decreases by more than 25% after the change. For the ultrasonic signals (including vibration anomalies and partial discharge signals) collected in the second step, wavelet packet transform technology is used to decompose them into 4-6 layers of detail coefficients. The choice of 4-6 layers is because this number of layers can accurately capture the characteristic frequency bands corresponding to different types of electricity theft (e.g., 500kHz-800kHz signals from meter short circuits correspond to 3-4 layers, and 800kHz-1.2MHz signals from wire damage correspond to 5-6 layers), while avoiding feature redundancy caused by too many layers. From the decomposed detail coefficients, three core features are extracted: main frequency offset (reflecting the degree to which the main frequency of the vibration signal caused by current distortion deviates from the normal range), harmonic distortion rate (measuring the proportion of harmonic components in the signal; electricity theft will cause a surge in harmonics), and spectral entropy (characterizing signal complexity; the spectral entropy of normal electricity signals is stable, while it will increase significantly due to abnormal discharge during electricity theft). Through standardized processing, a spectral feature vector with unified dimensions and comprehensive information is constructed to ensure that the features can accurately map the physical anomalies caused by electricity theft. Next, the feature quantization and matching stage is entered: the cosine similarity algorithm is used to calculate the similarity between the real-time spectrum feature vector and the feature threshold range of various types of electricity theft (such as meter bypass and concealed bypass) in the three-dimensional association model of the first step. This algorithm can quantify the matching degree by the vector angle, avoiding the rigid judgment defect of traditional threshold comparison. When the matching degree is ≥80%, it is initially determined that there is an ultrasonic feature anomaly. At this time, the operation records of the corresponding power equipment for the past 72 hours (such as start and stop status, wiring detection log) and the user's electricity consumption trajectory (such as load change curve and electricity consumption period distribution) are retrieved simultaneously to collect data support for the judgment of behavioral anomalies.

[0032] Finally, a dual-abnormal target screening is performed. The ultrasonic feature matching degree of ≥80% serves as the basic threshold. The target is further identified by combining three specific user behavior abnormality trigger conditions. The first is that the power load change amplitude is ≥30% and there is no reasonable explanation such as power grid dispatch or equipment maintenance (corresponding to the electricity theft scenario of sudden load drop caused by meter bypass, etc.). The second is that the power load is continuously low for more than 12 hours during non-peak power consumption periods (such as 00:00-06:00 for residential and 22:00-08:00 for commercial) and the power consumption is ≥40% different from that of similar users during the same period (corresponding to long-term electricity theft scenario such as concealed bypass). The third is that the equipment wiring status change record is not synchronized with the power consumption data change, and the power load drops by more than 25% after the change (corresponding to the electricity theft scenario of human-made wiring modification). If any one of the abnormal behavior conditions is met, it can be marked as a dual-abnormal target with abnormal ultrasonic features and abnormal behavior trajectory.

[0033] Please see Figure 1 As a specific implementation of the power theft detection method based on ultrasonic vibration spectrum provided in this application, when screening for dual abnormal targets, an initial screening is first completed based on the ultrasonic feature matching degree, and then the behavioral trajectory cross-verification is initiated on the initial screening results. During the verification, the electricity consumption data of similar users in the same period are automatically retrieved to construct a temporary benchmark. By comparing the electricity consumption difference between the target user and the temporary benchmark, misjudgments caused by changes in the user's own electricity consumption habits are eliminated, and finally dual abnormal targets are locked. In terms of operation steps, the initial screening of ultrasonic features is first performed. The matching degree between the spectrum feature vector calculated in the third step and the three-dimensional association model is used as the judgment basis. Only targets with a matching degree ≥80% (i.e., users / equipment with physical anomalies related to power theft) are retained. The core purpose of the initial screening is to quickly filter out normal targets without physical anomalies through the hard indicator of ultrasonic signal, and reduce the subsequent verification scope from all users to dozens to hundreds of suspected objects, which greatly reduces the workload of subsequent data processing and verification and improves the screening efficiency.

[0034] Then, cross-validation of behavioral trajectories is initiated: The first step is to construct a temporary baseline. The system automatically retrieves the electricity consumption data of 30-50 similar users with the same attributes and in the same area based on the user attributes of the initially screened target (the same period specifically refers to the time period that is completely aligned with the abnormal period of the initially screened target; for example, if the target's abnormality occurs on Wednesday from 18:00 to 20:00, then the electricity load data of similar users from Wednesday from 18:00 to 20:00 in the past 3 weeks is retrieved). By averaging and removing extreme values, a temporary baseline curve for the electricity consumption of similar users in this period is generated. The second step is to conduct a difference comparison, comparing the electricity consumption trajectory of the initially screened target (such as load changes, electricity consumption...). The process involves comparing the target load (duration) with a temporary baseline curve for each time period to calculate the deviation rate (e.g., the target load is 45% lower than the baseline). The third step eliminates reasonable interference, focusing on scenarios where users' electricity usage habits have changed. If a target user has recently added high-power equipment (e.g., a residential user adding an air conditioner) or adjusted production shifts (e.g., a factory switching to night shifts), and there are traceable and reasonable electricity usage change records (retrieved from user installation and maintenance records), even if their electricity usage trajectory deviates from the temporary baseline, it is determined to be a non-theft anomaly and excluded. Only targets with no reasonable explanation and a deviation rate exceeding a preset threshold (≥40% difference from similar users) are retained. Finally, the final locking is performed: targets that pass the initial ultrasonic screening and are confirmed by behavioral verification to have no reasonable explanation for their electricity usage anomalies are marked as dual-abnormal targets with both ultrasonic feature anomalies and behavioral trajectory anomalies, completing the screening process. In this way, the initial screening process uses ultrasonic features for pre-screening, avoiding the inefficiency caused by full-scale user behavior verification and significantly shortening the screening time. Compared with traditional fixed historical benchmarks, it is more adaptable to different scenarios and can avoid benchmark distortion caused by seasonal changes and differences in regional electricity consumption characteristics (such as the increase in overall residential load in summer, the temporary benchmark can reflect this change in a synchronous manner, avoiding misjudging normal high load as abnormal). At the same time, by excluding reasonable scenarios of changes in one's own electricity consumption habits, it accurately eliminates false abnormal targets (such as load fluctuations caused by users adding new equipment), reducing the misjudgment rate by more than 30%.

[0035] Please see Figure 1As a specific implementation of the power theft detection method based on ultrasonic vibration spectrum provided in this application, in S4, for the ultrasonic sensor corresponding to the dual abnormal targets, the first step is to automatically adjust the beam direction and accurately focus the beam on the target device (such as the user's meter box or cable joint) through the phase control algorithm of the sensor array. At the same time, the beam width is narrowed to 15°-30°. The narrow beam design can significantly reduce environmental interference in non-target areas (such as vibration of surrounding equipment and electromagnetic noise) and ensure the targeted nature of signal acquisition. The second step optimizes the acquisition parameters, increasing the acquisition frequency from the conventional 100ms / time to 20ms / time, achieving a 5-fold increase in signal sampling density. This avoids missing brief abnormal pulses caused by electricity theft. Simultaneously, the signal gain is increased by 5-8dB to enhance the intensity of weak partial discharge signals (such as microvolt-level discharge signals generated by slight wire damage). The spectrum acquisition band is further expanded to 10kHz-2MHz, fully covering the characteristic frequency bands of different electricity theft types, including meter short circuits (500kHz-800kHz), strong magnetic interference (10kHz-50kHz), and wire damage (800kHz-1.2MHz). The third step initiates array collaborative acquisition. Through signal time alignment and superposition fusion algorithms of the core and auxiliary sensor units, the target signals acquired by multiple units are superimposed, further improving the signal-to-noise ratio (SNR improvement ≥15dB after superposition), ensuring accurate capture of abnormal signals even in complex environments.

[0036] Next, the electricity consumption data time series reconstruction was carried out. The first step was to use a sliding window algorithm (window length set to 5 minutes, step size 2 minutes) to segment the electricity load data of the dual anomaly targets, transforming the discrete electricity consumption data into continuous time series segments, which facilitates the analysis of load change trends. The second step was to use a cubic polynomial trend fitting algorithm to reconstruct the segmented data into a curve, generating a smooth electricity load time series curve that clearly shows the rise and fall of the load. The third step was to identify key features, determine the load mutation point by calculating the first derivative of the curve (the larger the absolute value of the derivative, the more significant the mutation), and record the duration of the mutation. When the mutation slope is ≥0.8 (indicating a significant drop in load in a short period of time) and the duration is ≥10 minutes (excluding accidental fluctuations), and the system automatically retrieves the power grid dispatch log and equipment maintenance records to confirm that there are no reasonable external factors (such as power outages or power restrictions), the electricity load mutation verification is deemed to have passed.

[0037] Finally, remote equipment status diagnosis is performed: The first step is multi-source data retrieval, simultaneously acquiring infrared imaging data (reflecting equipment temperature distribution; loose wiring can lead to localized overheating), standard wiring diagrams (standard templates for normal equipment wiring), and historical maintenance records (records of maintenance and replacement in the past 3 months) of the power equipment corresponding to the dual abnormal targets; the second step is image comparison and analysis, using deep learning-based image segmentation and feature matching algorithms to compare real-time infrared imaging with standard temperature distribution and real-time wiring images with standard diagrams to identify abnormal statuses such as loose wiring terminals (temperature exceeding the normal range by more than 10°C), abnormal wire connections (wire connections outside the standard diagram), and damaged seals (seal integrity less than 90%); the third step is cross-dimensional correlation verification, combining the presence of partial discharge characteristics in the ultrasonic signals acquired by S4 enhancement (such as pulsed discharge signals often accompanying abnormal wiring). When the equipment status abnormality identification rate is ≥85% (i.e., the matching degree between the identified abnormal features and electricity theft-related abnormalities), the equipment wiring status consistency verification is deemed passed.

[0038] In this approach, ultrasonic signal enhancement acquisition, through focusing, high-density sampling, and collaborative superposition, solves the problems of weak signals, strong interference, and narrow frequency bands of traditional sensors, increasing the capture rate of weak electricity theft signals to over 95% and providing reliable data for physical dimension verification. Furthermore, the time-series reconstruction of electricity consumption data, through segmentation, fitting, and feature recognition, transforms messy electricity consumption data into a quantifiable trend curve, accurately distinguishing between random fluctuations and load mutations caused by electricity theft, reducing the false judgment rate by 40%. Moreover, remote equipment status diagnosis, through multi-source image comparison and ultrasonic feature correlation, can verify the physical status of equipment without manual on-site unpacking inspection, avoiding the lag of manual inspection and ensuring the accuracy of status determination through cross-dimensional verification (images and ultrasound).

[0039] Please see Figure 1As a specific implementation of the electricity theft detection method based on ultrasonic vibration spectrum provided in this application, in S5, the targeted handling instruction is pushed to the operation and maintenance system and triggers the on-site verification process. When updating the ultrasonic feature threshold and the abnormal user behavior triggering conditions, the confirmed electricity theft case data is supplemented to the model training set using an incremental learning algorithm. Only the newly added data is used for local model training, and the feature threshold and behavior triggering conditions of the corresponding electricity theft type are adjusted without retraining the entire model. The targeted handling instructions generated in step five are not simple anomaly alarms, but standardized work orders that include the type of electricity theft (such as meter bypassing or wire damage and diversion), precise physical location (specifically to a certain user's meter box / a certain section of cable in a certain area, with a positioning error ≤ 0.8 meters), and a complete chain of evidence (ultrasonic spectrum comparison chart, electricity load change curve, screenshot of abnormal equipment status, and the evidence chain is stored on the blockchain to ensure it is tamper-proof). This work order is automatically pushed to the corresponding maintenance terminal (such as a mobile APP or computer client) through the API interface of the power operation and maintenance system. At the same time, the on-site verification process is triggered according to the confidence level of electricity theft. For emergency work orders with a confidence level ≥ 90%, the system automatically marks them as priority processing, and the system completes the assignment of maintenance personnel within 10 minutes, requiring them to arrive on site within 1 hour. For regular work orders with a confidence level of 60%-90%, the system completes the verification within 24 hours after assignment, and the verification results (such as confirmation of electricity theft / removal of anomalies, on-site evidence photos) must be sent back to the system in real time, forming a closed-loop operational link of instruction push, personnel response, and result feedback.

[0040] Subsequently, dynamic model updates were implemented. The first step involved collecting confirmed electricity theft case data. Information on verified cases was extracted from the system, including the corresponding ultrasonic feature vectors (such as dominant frequency offset and harmonic distortion rate), user electricity consumption behavior data (such as load fluctuation amplitude and abnormal duration), and the final determined type of electricity theft. This cleaned data was then added to the training set of the 3D correlation model. The second step employed incremental learning algorithms (such as gradient descent-based local parameter update algorithms) for model training. Unlike traditional full-scale training, which requires iterating over all historical data, this algorithm only targets the electricity theft type corresponding to newly added case data. Local parameter adjustments are made. For example, when adding a new case of pulsed strong magnetic interference electricity theft, only the ultrasonic feature threshold corresponding to this type in the model is optimized (e.g., the original 50kHz-80kHz feature frequency band is finely adjusted to 45kHz-85kHz) and the abnormal user behavior triggering conditions (e.g., the load change amplitude threshold is adjusted from 30% to 28% to adapt to the load change characteristics of this type of electricity theft). There is no need to modify the model parameters of other types of electricity theft such as meter short-circuiting and wire damage. After the parameter update is completed in the third step, the system automatically synchronizes the new feature threshold and behavior triggering conditions to the detection module and immediately applies them to subsequent real-time detection.

[0041] In this way, the standardization and hierarchical delivery of targeted disposal instructions solves the problem of blind operation and maintenance in traditional operations and maintenance, improves the efficiency of on-site verification by more than 60%, and shortens the response time for handling emergency electricity theft from several hours to within 1 hour, minimizing power loss; and the lightweight update mode of incremental learning greatly reduces the resource consumption and time consumption of model optimization.

[0042] Please see Figure 1 As a specific implementation of the electricity theft detection method based on ultrasonic vibration spectrum provided in this application, it also includes S6: transmitting ultrasonic stimulation signals to the power equipment corresponding to the dual abnormal targets, collecting the response signals and power load change data after stimulation, and verifying them; at the same time, calling the cross-regional electricity theft feature library for collaborative comparison, and if there are unmatched features, triggering cross-regional parameter sharing update. For power equipment (such as user meters and incoming cables) corresponding to the dual abnormal targets locked by S3, the system adaptively generates ultrasonic stimulation signals with specific parameters based on the suspected electricity theft type initially determined by S4 (such as short circuit around the meter or wire damage). For short circuit-related electricity theft, a continuous wave signal of 500kHz-800kHz is emitted, and for damage-related theft, a pulse wave signal of 800kHz-1.2MHz is emitted. The signal amplitude is set to 1.5-2 times that of the normal acquisition signal, and the signal is emitted continuously for 30-60 seconds. At the same time, the ultrasonic response signal after stimulation is collected simultaneously (to observe whether the abnormal features are enhanced or stabilized) and the power load change data (to determine whether the load fluctuates unreasonably with stimulation). If the increase of electricity theft-related features (such as pulse cluster density) in the response signal is ≥10% and the power load fluctuation is ≤5% (excluding normal equipment response), then the abnormality is verified as a real electricity theft feature. Otherwise, it is determined to be environmental interference or occasional equipment failure, avoiding accidental triggering of the handling process.

[0043] Subsequently, cross-regional collaborative operations are initiated. The system uses a consortium blockchain architecture to call a cross-regional electricity theft feature database of the same voltage level and user type. It employs a feature hash comparison algorithm to quickly match the currently verified electricity theft features (or unmatched new features) with the data in the database. If a similar feature is matched, the corresponding electricity theft handling experience is synchronously added to the targeted handling instructions. If there are unmatched new electricity theft features (such as unique ultrasonic signals caused by new chip tampering), a horizontal federated learning mechanism is triggered. Only the model parameters (not the original electricity consumption data) are transmitted to the cross-regional collaborative nodes to complete the sharing and updating of model parameters. This ensures that other regions can quickly identify similar new types of electricity theft in the future without having to repeat the feature accumulation and model training process.

[0044] By manually triggering device responses, the system accurately distinguishes between genuine electricity theft anomalies and environmental interference or occasional equipment malfunctions, reducing the false alarm rate by more than 25% and minimizing ineffective maintenance dispatches. Furthermore, cross-regional feature collaboration and federated learning not only break down data silos between regional detection systems (preventing new types of electricity theft from recurring in different regions) but also protect user electricity data privacy through parameter sharing (eliminating the need to transmit sensitive raw data), reducing the response time for identifying new types of electricity theft from months to hours. This step also upgrades the entire detection method from a single-region closed loop to global collaborative optimization, not only improving the accuracy of current detection but also strengthening the defense against future new types of electricity theft.

[0045] Not shown in the figure, this application embodiment also provides a power theft detection system based on ultrasonic vibration spectrum, which includes any of the above-mentioned power theft detection methods based on ultrasonic vibration spectrum.

[0046] The electricity theft detection system based on ultrasonic vibration spectrum includes a control module and a computer connected to the control module. The control module is connected to sensors, and sensor data is uploaded to the control module, which then uploads the data to the computer. Related models and other data are processed and calculated on the computer.

[0047] The electricity theft detection system based on ultrasonic vibration spectrum provided in this application adopts the aforementioned electricity theft detection method based on ultrasonic vibration spectrum. It upgrades passive detection to an active identification mode that has undergone precise screening, multi-dimensional verification, targeted processing, and dynamic optimization. It not only solves the problems of limited coverage and slow response of manual inspection, but also overcomes the shortcomings of offline analysis and insufficient real-time performance of traditional intelligent algorithms. It achieves accurate, real-time, and efficient electricity theft detection, which not only ensures the safe and stable operation of the power grid, but also maximizes the recovery of economic losses caused by electricity theft to power companies, and has extremely strong practical application value.

[0048] The above are merely preferred embodiments of this application and are not intended to limit this application. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the protection scope of this application.

Claims

1. A method for detecting electricity theft based on ultrasonic vibration spectrum, characterized in that, The process includes: S1: Constructing a correlation model based on power grid topology, user profiles, and ultrasonic features; analyzing the power grid topology features and user electricity consumption behavior profiles in the target area; combining ultrasonic vibration spectrum and partial discharge signal patterns; and presetting ultrasonic feature thresholds for electricity theft types and abnormal user behavior triggering conditions; S2: Capturing ultrasonic signals from power equipment using ultrasonic sensors; retrieving electricity load data from meters and equipment operating status data; forming a three-source data stream and performing time calibration and data fusion; S3: Converting ultrasonic signals into spectral feature vectors; comparing them with thresholds in the correlation model; and filtering out dual-abnormal targets with both ultrasonic feature anomalies and behavioral trajectory anomalies; S4: Initiating ultrasonic signal enhancement acquisition, electricity data time-series reconstruction, and remote equipment status diagnosis for dual-abnormal targets; and performing consistency cross-comparison with the three-source data streams in S2 to confirm electricity theft behavior; and S5: Outputting targeted handling instructions based on electricity theft type, location, and evidence, and updating ultrasonic feature thresholds and abnormal user behavior triggering conditions.

2. The method for detecting electricity theft based on ultrasonic vibration spectrum as described in claim 1, characterized in that, In S1, when constructing the correlation model, the power grid topology parameters are first decomposed into a grid to extract the core topology features such as line node correlation, impedance distribution, and load carrying threshold. Then, the user electricity consumption data is grouped by clustering algorithm to generate a baseline electricity consumption behavior profile of users of the same type; finally, the ultrasonic signal samples of different types of electricity theft are associated with topological features and user profiles for training, and the feature weights are optimized by gradient boosting tree algorithm to form a strong correlation mapping relationship between the three dimensions of power grid topology, user profile and ultrasonic features.

3. The method for detecting electricity theft based on ultrasonic vibration spectrum as described in claim 2, characterized in that, The user electricity consumption behavior profile includes collecting electricity consumption time-series data from the past 12 months, extracting peak electricity consumption periods, load fluctuation amplitude, and seasonal variation coefficient features through a sliding window algorithm, and combining user industry type, electrical equipment list, and historical repair records to construct a dynamically updated user profile. When a user's electricity consumption behavior deviates from its own historical profile by more than 30% or from the profile of similar users by more than 40%, an abnormal behavior marker is triggered.

4. The method for detecting electricity theft based on ultrasonic vibration spectrum as described in claim 1, characterized in that, In S2, ultrasonic sensors are arranged in an array and deployed according to a two-layer architecture of core nodes and edge terminals. The core node deploys a 16-unit ultrasonic sensor array to cover line branch nodes. The edge terminal deploys an 8-unit ultrasonic sensor array to cover end-user electrical equipment. During the deployment of ultrasonic sensors, the installation angle of the sensors is calculated using the power grid topology diagram to ensure that the monitoring range overlap rate of adjacent sensors is ≥15%. The three-source data streams adopt a timestamp alignment mechanism, using the acquisition time of the ultrasonic signal as a reference to perform time calibration on the power consumption data and equipment status data, with the synchronization error controlled within 5ms.

5. The method for detecting electricity theft based on ultrasonic vibration spectrum as described in claim 1, characterized in that, In S3, the ultrasonic signal is first decomposed into 4-6 layers of detail coefficients through wavelet packet transform, and the main frequency offset, harmonic distortion rate, and spectral entropy features are extracted to construct a spectral feature vector. Then, the cosine similarity algorithm is used to calculate the matching degree between the spectral feature vector and various electricity theft feature thresholds in the three-dimensional association model. When the matching degree is ≥80%, the equipment operation record and user electricity consumption trajectory are retrieved. When the ultrasonic feature matching degree is ≥80% and any of the following abnormal user behavior triggering conditions are met, it is marked as a double abnormal target. The abnormal user behavior triggering conditions include a sudden change in electricity load of ≥30% without explanation from power grid dispatch or equipment maintenance, continuous low load operation for more than 12 hours during non-peak electricity consumption periods, and a difference of ≥40% in electricity consumption compared with similar users during the same period, or the change record of equipment wiring status is not synchronized with the change in electricity consumption data, and the electricity load drops by more than 25% after the change.

6. The method for detecting electricity theft based on ultrasonic vibration spectrum as described in claim 5, characterized in that, When screening for dual-abnormal targets, an initial screening is first completed based on the matching degree of ultrasonic features. Then, behavioral trajectory cross-validation is initiated on the initial screening results. During the validation, electricity consumption data of similar users in the same period are automatically retrieved to build a temporary benchmark. By comparing the electricity consumption differences between the target user and the temporary benchmark, misjudgments caused by changes in the user's own electricity consumption habits are eliminated, and the dual-abnormal targets are finally identified.

7. The method for detecting electricity theft based on ultrasonic vibration spectrum as described in claim 1, characterized in that, In S4, the ultrasonic signal enhancement acquisition includes automatically adjusting the beam direction of the sensors corresponding to the dual abnormal targets, focusing on the target device, and narrowing the beam width to 15°-30°; increasing the acquisition frequency from 100ms / time to 20ms / time, and improving the signal gain by 5-8dB; expanding the spectrum acquisition band to 10kHz-2MHz to ensure the capture of weak partial discharge signals; and simultaneously initiating collaborative acquisition of the sensor array to enhance the target signal strength through multi-unit signal superposition. The power consumption data time series reconstruction includes using a sliding window algorithm to segment the power consumption data of the dual abnormal targets and reconstructing the power load time series curve; and using a trend fitting algorithm to analyze the abrupt change points and stable segment characteristics of the curve, and calculating the abrupt change slope and duration. When the abrupt change slope is ≥0.8 and the duration is ≥10 minutes, and there are no external factors, the power load abrupt change verification is deemed successful; the remote equipment status diagnosis includes retrieving infrared imaging data, wiring standard diagrams, and historical maintenance records of the power equipment corresponding to the dual abnormal targets; identifying abnormal statuses such as loose wiring terminals, abnormal wire connections, and damaged seals through image comparison algorithms; and combining the partial discharge characteristics in the ultrasonic signal, when the equipment status abnormality identification rate is ≥85%, the equipment wiring status consistency verification is deemed successful.

8. The method for detecting electricity theft based on ultrasonic vibration spectrum as described in claim 1, characterized in that, In S5, the targeted handling instruction is pushed to the operation and maintenance system and triggers the on-site verification process. When updating the ultrasonic feature threshold and the abnormal user behavior triggering conditions, the incremental learning algorithm is used to supplement the confirmed electricity theft case data into the model training set. Only the newly added data is used for local model training, and the feature threshold and behavior triggering conditions of the corresponding electricity theft type are adjusted without retraining the entire model.

9. The method for detecting electricity theft based on ultrasonic vibration spectrum as described in claim 1, characterized in that, It also includes S6: transmitting ultrasonic stimulation signals to the power equipment corresponding to the dual abnormal targets, collecting the response signals and power load change data after stimulation, and verifying them; at the same time, calling the cross-regional electricity theft feature database for collaborative comparison, and if there are unmatched features, triggering cross-regional parameter sharing update.

10. A power theft detection system based on ultrasonic vibration spectrum, characterized in that, Including the power theft detection method based on ultrasonic vibration spectrum as described in any one of claims 1-9.