Electricity stealing user positioning method and system based on intelligent power grid line toolbox

By generating a baseline curve for line loss rate, identifying unplanned destructive power outages and obtaining key data, and calculating comprehensive suspicion indicators, the problem of unstable electricity theft location results was solved, achieving efficient and reliable location of electricity theft users.

CN121978379APending Publication Date: 2026-05-05STATE GRID ZHEJIANG ELECTRIC POWER CO MARKETING SERVICE CENT
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
STATE GRID ZHEJIANG ELECTRIC POWER CO MARKETING SERVICE CENT
Filing Date
2026-01-30
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

Existing methods for identifying and locating electricity theft are unstable in terms of event judgment and data reporting during abnormal power outages, resulting in unreliable location results, a high risk of misjudgment, and low location efficiency.

Method used

By collecting line electrical parameters and power data from the line toolbox, a line loss rate benchmark curve is generated to determine real-time fluctuation characteristics, identify unplanned destructive power outages, activate backup batteries to enter anti-theft collaborative positioning mode, report geographical location, and obtain line electrical parameter snapshots and associated user load data within key time windows. Instantaneous behavior deviation and line loss contribution suspicion intensity are calculated to generate comprehensive suspicion indexes. Data packets are intermittently reported during low power consumption phases to ensure data integrity.

Benefits of technology

It improves the sensitivity and stability of abnormal line loss identification, avoids false triggers, maintains the continuity of location and evidence collection, enhances the accuracy of suspect identification and data credibility, and ensures the continuity and closed-loop analysis capability of anti-electricity theft handling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121978379A_ABST
    Figure CN121978379A_ABST
Patent Text Reader

Abstract

The invention relates to an electricity stealing user positioning method and system based on a smart grid line toolbox, and the method comprises the steps: collecting the line electrical parameters and electric quantity data of the line toolbox, generating a line loss rate reference curve, and extracting the real-time fluctuation characteristics; when the main power is in power failure, unplanned destructive power failure is judged by combining the real-time fluctuation characteristics and the original waveform of the load current before power failure, and a timestamp is recorded; starting a standby battery to enter an anti-theft cooperative positioning mode, reporting a geographic position, and obtaining line electrical parameter snapshots and associated user load data in a key time window; calculating an instantaneous behavior deviation degree and line loss contribution suspicion intensity, and fusing the instantaneous behavior deviation degree and the line loss contribution suspicion intensity to generate a comprehensive suspicion index to form a suspicion user sorting list; and encrypting and binding the sorting list, the geographic position and the timestamp to generate a to-be-reported data packet and a tamper-proof verification code, periodically reporting the position and intermittently reporting the data packet and the verification code in a low power consumption stage, and uploading an event analysis report after the main power is recovered. The method has the effect of improving the positioning accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the technical field of smart grid electricity consumption monitoring, and in particular relates to a method and system for locating electricity theft users based on a smart grid line toolbox. Background Technology

[0002] Currently, in the power distribution sector, there are a large number of users and their electricity consumption behavior is highly volatile. The operating status of the line side is significantly affected by factors such as load changes, maintenance operations, and external disturbances. Monitoring equipment such as line toolboxes need to continuously acquire line electrical parameters and power data under complex power supply conditions and maintain data time consistency. At the same time, in the event of a sudden power outage, it is still necessary to ensure the traceability of event information and the availability of location information.

[0003] Existing methods for identifying and locating electricity theft typically rely on monitoring abnormal features and reporting events on the line side. When faced with abnormal scenarios such as power outages or external damage, issues such as inaccurate event determination, interruption of available data links, and unstable location results can easily arise, leading to low efficiency in locating electricity theft users and an increased risk of misjudgment. Summary of the Invention

[0004] The purpose of this invention is to provide a method and system for locating electricity theft users based on a smart grid line toolbox, so as to solve the technical problem that the location results are unreliable due to the instability of event judgment and data reporting in the existing method under abnormal power outage scenarios.

[0005] To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a method for locating electricity theft users based on a smart grid line toolbox, the method comprising: The electrical parameters and power data of the branch lines installed in the line toolbox are collected, a line loss rate benchmark curve is generated, and the real-time fluctuation characteristics are determined based on the line loss rate benchmark curve. When a main power failure is detected, the system determines whether an unplanned destructive power failure has occurred based on the real-time fluctuation characteristics and the original waveform of the load current before the power failure, and records the corresponding power failure timestamp. In the event of an unplanned destructive power outage, the backup battery is activated to enter the anti-theft collaborative positioning mode, the geographical location of the line toolbox is reported, and snapshots of line electrical parameters and associated user load data are obtained within the critical time window. In the anti-theft collaborative positioning mode, the instantaneous behavior deviation and the suspected strength of line loss contribution are calculated based on the line electrical parameter snapshot and the associated user load data, and the instantaneous behavior deviation and the suspected strength of line loss contribution are weighted and fused to generate a comprehensive suspected index; A priority list of suspected households is generated based on the comprehensive suspicion indicators. The priority list of suspected households is encrypted and bound with the geographical location and the power outage timestamp to obtain the data packet to be reported. An anti-tampering verification code is generated for the data packet to be reported. The geographical location is reported during the low-power reporting phase according to a preset time period, and the data packet to be reported and the corresponding anti-tampering verification code are reported intermittently. After the main power is restored, a power failure event analysis report is generated and uploaded to the main station.

[0006] By adopting the above technical solutions, and through collecting line electrical parameters and power data to generate a line loss rate benchmark curve and determine real-time fluctuation characteristics, a comparable line loss reference benchmark can be formed and the degree of line loss anomaly can be quantified, thereby improving the sensitivity and stability of line loss anomaly identification. By identifying unplanned destructive power outages based on real-time fluctuation characteristics and the original waveform of the load current before the power outage, and recording the power outage timestamp, it is possible to distinguish between destructive and non-destructive events when a power outage occurs, thereby avoiding false triggering and providing a unified time anchor for subsequent event tracing. By activating the backup battery to enter the anti-theft collaborative positioning mode and reporting the geographical location, obtaining snapshots of line electrical parameters within key time windows and associated user load data, it is possible to maintain the continuity of positioning and evidence collection under main power interruption conditions, thereby improving… The system ensures complete retention of on-site information. By calculating the intensity of suspected contribution of instantaneous behavioral deviation and line loss and weighting and fusing them to generate a comprehensive suspected index, it can simultaneously characterize the correlation contribution of short-term abnormal user behavior and historical line loss, thereby improving the accuracy and interpretability of suspected identification. By generating a priority list of suspected users and encrypting and binding it with geographical location and power outage timestamp to obtain the data packet to be reported, it can consistently correlate the suspected results with the spatiotemporal information of the event, thereby improving the directionality of investigation and location and the credibility of data. By generating tamper-proof verification codes and intermittently reporting data packets during the low-power reporting phase, and generating analysis reports and uploading them to the main station after the main power is restored, it can continuously transmit key clues and ensure data integrity under limited battery life, thereby improving the continuity and closed-loop analysis capabilities of anti-electricity theft handling.

[0007] In one example, the present invention can be further configured as follows: the electrical parameters and power data of the branch lines installed in the acquisition line toolbox are used to generate a line loss rate benchmark curve, and the real-time fluctuation characteristics are determined based on the line loss rate benchmark curve, including: Obtain the dynamic line loss rate sequence corresponding to the line electrical parameters and the power data; The dynamic line loss rate sequence is decomposed into a time series to obtain a trend term and a period term. The trend term and the period term are then fitted to generate the line loss rate benchmark curve. The actual line loss rate is obtained under a unified time reference, and the deviation between the actual line loss rate and the line loss rate reference curve is calculated to obtain the relative deviation of the line loss rate. The relative deviation of the line loss rate is standardized to obtain the real-time fluctuation characteristics.

[0008] By adopting the above technical solution, by acquiring the dynamic line loss rate sequence and performing time series decomposition to obtain trend and periodic terms, and fitting to generate a line loss rate benchmark curve, the influence of long-term changes and periodic fluctuations on line loss can be separated, thus obtaining a benchmark reference that is more in line with the operating rules. By calculating the relative deviation based on the actual line loss rate and the line loss rate benchmark curve and performing standardization processing, the deviation scale under different time periods and different load levels can be unified, thereby improving the consistency of the real-time fluctuation characteristics in representing abnormal line loss.

[0009] In one example, the present invention can be further configured such that: the standardization process performed on the relative deviation of the line loss rate to obtain the real-time fluctuation characteristics includes: Within a preset time window, the mean and standard deviation of the relative deviation of the line loss rate are statistically analyzed. The relative deviation of the line loss rate is normalized based on the mean deviation and the standard deviation of the deviation to obtain a standardized deviation sequence; The standardized deviation sequence is output as the real-time fluctuation feature.

[0010] By adopting the above technical solution, and by statistically analyzing the mean and standard deviation of the relative deviation of the line loss rate and then normalizing them to output a standardized deviation sequence, the differences in the dimensions and fluctuation amplitude of the deviation sequence can be eliminated, thereby improving the sensitivity and comparability of real-time fluctuation characteristics to sudden anomalies.

[0011] In one example, the present invention can be further configured as follows: when a main power failure is detected, determining whether an unplanned destructive power failure has occurred based on the real-time fluctuation characteristics and the original waveform of the load current before the power failure includes: Extract the line loss rate fluctuation sequence corresponding to the real-time fluctuation characteristics within a preset time period before the main power failure trigger time; The approximate entropy is calculated for the line loss rate fluctuation sequence to obtain the line loss complexity characteristics; Perform wavelet packet transform on the original waveform of the load current before the power outage, extract at least one characteristic frequency band energy and calculate the corresponding energy change rate to obtain waveform distortion characteristics; If the line loss complexity characteristic and the waveform distortion characteristic meet the preset judgment conditions, it is determined that the unplanned destructive power outage has occurred.

[0012] By adopting the above technical solutions, the line loss complexity features are obtained by extracting the line loss rate fluctuation sequence before the power outage and calculating the approximate entropy. This allows for the quantification of the disorder and abrupt change of line loss fluctuations, thereby enhancing the ability to identify abnormal disturbances. By performing wavelet packet transform on the original waveform of the load current before the power outage and extracting the energy change rate of the characteristic frequency band to obtain waveform distortion features, abnormal current disturbances before the power outage can be captured at the time-frequency level, thereby improving the reliability of destructive power outage identification. By determining unplanned destructive power outages when the complexity features and distortion features meet the judgment conditions, multi-source evidence joint constraints can be achieved, avoiding misjudgment by a single indicator, thereby improving the accuracy of triggering the anti-theft collaborative positioning process.

[0013] In one example, the present invention can be further configured as follows: upon determining that the unplanned destructive power outage has occurred, reporting the geographical location of the line toolbox and obtaining a snapshot of the line electrical parameters and associated user load data within a critical time window includes: Based on the power outage timestamp, a key time window is determined, including a first time window before the power outage and a second time window after the power outage. Within the critical time window, collect line electrical parameters and generate a snapshot of the line electrical parameters; Within the key time window, retrieve the associated user load data and perform time alignment processing to obtain the associated user load data.

[0014] By adopting the above technical solutions, and by determining key time windows based on power outage timestamps, including a first time window before the power outage and a second time window after the power outage, the analysis scope can be aligned to the critical stages of the event, thereby improving the targeting of abnormal evidence capture. By collecting line electrical parameters within the key time windows and generating line electrical parameter snapshots, the line state characteristics before and after the power outage can be solidified, thereby strengthening the data foundation for subsequent suspect determination. By retrieving and time-aligning related user load data, the comparability of line-side and user-side data on the same time axis can be achieved, thereby improving the synchronization and accuracy of suspect location analysis.

[0015] In one example, the present invention can be further configured as follows: calculating the instantaneous behavior deviation and the suspected strength of line loss contribution based on the line electrical parameter snapshot and the associated user load data, and weighting and fusing the instantaneous behavior deviation and the suspected strength of line loss contribution to generate a comprehensive suspected index, including: Obtain the user power curve from the associated user load data and extract the historical same-period baseline curve. Calculate the deviation distance based on the user power curve and the historical same-period baseline curve, and generate the instantaneous behavior deviation by combining the abrupt correlation degree. Obtain historical electricity consumption data and branch line loss rate data of associated users, calculate influence score based on the historical electricity consumption data and the branch line loss rate data, and generate the line loss contribution suspicion intensity based on the influence score and the consistency of the change direction within the key time window; The instantaneous behavioral deviation and the suspected strength of line loss contribution are normalized and then weighted and fused based on preset dynamic weights to obtain the comprehensive suspected index.

[0016] By employing the aforementioned technical solutions, and by extracting user power curves and combining them with historical benchmark curves to calculate deviation distances and fusing abrupt change correlations to generate instantaneous behavioral deviations, the abnormality of users' behavior relative to their normal behavior within key time windows can be characterized, thereby improving the ability to detect short-term electricity theft. By combining historical electricity consumption data and branch line loss rate data to calculate influence scores and combining the consistency of change direction to generate line loss contribution suspicion intensity, the historical correlation contribution of users to line loss anomalies and event synchronicity can be characterized, thereby improving the ability to identify high-risk users. By normalizing instantaneous behavioral deviations and line loss contribution suspicion intensity and obtaining a comprehensive suspicion index based on dynamic weighted fusion, multi-dimensional suspicion evidence can be integrated under the same dimension, thereby improving the stability and ranking effectiveness of suspicion evaluation results.

[0017] In one example, the present invention can be further configured as follows: the step of calculating the deviation distance based on the user power curve and the historical concurrent baseline curve and generating the instantaneous behavior deviation by combining the mutation correlation degree includes: The Mahalanobis distance is calculated based on the user power curve and the historical reference curve for the same period to obtain the first deviation. Extract the power abrupt change times of the user power curve and the abrupt change times of the total branch power, and calculate the mutual information between the power abrupt change times to obtain the second deviation. The first deviation and the second deviation are weighted and fused to obtain the instantaneous behavior deviation.

[0018] By adopting the above technical solution, the first deviation is obtained by calculating the Mahalanobis distance between the user power curve and the historical benchmark curve of the same period. This can measure the overall degree of deviation while considering data correlation, thereby enhancing the identification effect of abnormal behavior in complex fluctuation scenarios. The second deviation is obtained by extracting the user power mutation time and the branch total power mutation time and calculating mutual information. This can characterize the temporal correlation strength between user mutation and branch mutation, thereby improving the directionality of key disturbance sources. The instantaneous behavior deviation is obtained by weighted fusion of the first and second deviations. This can take into account both amplitude deviation and temporal correlation features, thereby improving the comprehensiveness and robustness of instantaneous anomaly judgment.

[0019] In one example, the present invention can be further configured as follows: calculating an influence score based on the historical electricity consumption data and the branch line loss rate data, and generating the suspected strength of line loss contribution based on the consistency of the influence score and the direction of change within the key time window, includes: A vector autoregression model is constructed based on the historical electricity consumption data and the branch line loss rate data, and the influence score is obtained by calculating the Granger causality statistic based on the vector autoregression model. The symbolic consistency coefficient is calculated based on the direction of change of user power and the direction of change of line loss rate within the key time window, and the influence score and the symbolic consistency coefficient are combined to obtain the suspected strength of line loss contribution. The dynamic weights are determined based on the analytic hierarchy process (AHP), and the normalized instantaneous behavior deviation and the suspected strength of line loss contribution are weighted and fused based on the dynamic weights to obtain the comprehensive suspicion index.

[0020] By adopting the above technical solutions, and by constructing a vector autoregression model and calculating Granger causality statistics to obtain an influence score, the statistical correlation strength between historical changes in user electricity consumption and changes in branch line losses can be quantified, thereby improving the ability to identify long-term suspicious users. By calculating and combining the sign consistency coefficients of the direction of user power change and the direction of line loss rate change within a key time window to obtain the suspected strength of line loss contribution, the synchronous change relationship of the event stage can be incorporated into the evaluation, thereby improving the relevance of the suspected strength to the current power outage event. By determining dynamic weights based on the analytic hierarchy process and fusing them to obtain a comprehensive suspected index, the evidence contribution ratio can be adaptively adjusted according to event characteristics, thereby improving the applicability and stability of the comprehensive score in different scenarios.

[0021] In one example, the present invention can be further configured as follows: The step of reporting the geographical location and intermittently reporting the data packet to be reported during the low-power reporting phase according to a preset time period, generating an anti-tampering verification code for the data packet to be reported, and generating a power failure event analysis report and uploading it to the main station after the main power is restored includes: Extract a preset number of suspect entries from the suspect priority sorting list to generate a suspect list summary, and combine the suspect list summary with the device unique identifier and the power failure timestamp to obtain summary data; The summary data and the geographical location are symmetrically encrypted to obtain ciphertext data, and the ciphertext data is used as the data packet to be reported. A message authentication code is generated based on the data packet to be reported as an anti-tampering verification code, and the anti-tampering verification code is intermittently reported together with the data packet to be reported. It enters a deep sleep state between adjacent intermittent reporting and monitors the status of the backup battery during the low power reporting phase. If the status of the backup battery meets the alarm conditions, it reports the corresponding alarm flag. After the main power is restored, a power outage event analysis report is generated and uploaded to the main station. The power outage event analysis report includes at least the determination result of the unplanned destructive power outage, the snapshot of the line electrical parameters, the comprehensive suspected index and the priority ranking list of suspected users, and the low power consumption reporting log.

[0022] By adopting the above technical solutions, and combining the summary of the suspect list with the device's unique identifier and power-off timestamp to obtain summary data, key suspect clues and event index information can be preserved under limited communication resources, thereby improving the information transmission efficiency during low-power phases. By symmetrically encrypting the summary data and geographical location to obtain ciphertext data, which is then used as the data packet to be reported, the risk of data leakage during transmission can be reduced, thereby improving the security of sensitive positioning and suspect information. By generating a message authentication code based on the data packet to be reported as an anti-tampering verification code and reporting it intermittently, the integrity verification capability of the reported content can be provided, thereby improving the credibility of the data received by the main station. By entering deep sleep during intermittent reporting and monitoring the status of the backup battery, and reporting alarm flags when alarm conditions are met, the effective reporting time can be extended under limited battery life conditions, and operational risks can be promptly alerted, thereby improving the reliability of the collaborative positioning process. By generating a power-off event analysis report after the main power is restored, which includes the judgment results, snapshot, comprehensive suspect indicators, sorting list, and reporting logs and uploading it to the main station, a traceable evidence chain and analysis closed loop can be formed, thereby improving the review efficiency and management consistency of anti-electricity theft handling.

[0023] In a second aspect, the present invention provides a power theft user location system based on a smart grid line toolbox, the system comprising: The line loss acquisition module is used to collect the electrical parameters and power data of the branch lines installed in the line toolbox, generate a line loss rate benchmark curve, and determine the real-time fluctuation characteristics based on the line loss rate benchmark curve. The power failure detection module is used to determine whether an unplanned destructive power failure has occurred based on the real-time fluctuation characteristics and the original waveform of the load current before the power failure when a main power failure is detected, and to record the corresponding power failure timestamp. The collaborative positioning module is used to activate the backup battery to enter the anti-theft collaborative positioning mode when it is determined that the unplanned destructive power outage has occurred, report the geographical location of the line toolbox, and obtain a snapshot of the line electrical parameters and associated user load data within a key time window; The suspicion calculation module is used to calculate the instantaneous behavior deviation and the suspected strength of line loss contribution based on the line electrical parameter snapshot and the associated user load data in the anti-theft collaborative positioning mode, and to generate a comprehensive suspicion index by weighted fusion of the instantaneous behavior deviation and the suspected strength of line loss contribution. The sorting and binding module is used to generate a priority sorting list of suspect households based on the comprehensive suspicion index, and to encrypt and bind the priority sorting list of suspect households with the geographical location and the power outage timestamp to obtain the data packet to be reported. The low-power reporting module is used to generate an anti-tampering verification code for the data packet to be reported, report the geographical location during the low-power reporting phase according to a preset time period, and intermittently report the data packet to be reported and the corresponding anti-tampering verification code. After the main power is restored, it generates a power failure event analysis report and uploads it to the main station.

[0024] By adopting the above technical solutions, and through collecting line electrical parameters and power data to generate a line loss rate benchmark curve and determine real-time fluctuation characteristics, a comparable line loss reference benchmark can be formed and the degree of line loss anomaly can be quantified, thereby improving the sensitivity and stability of line loss anomaly identification. By identifying unplanned destructive power outages based on real-time fluctuation characteristics and the original waveform of the load current before the power outage, and recording the power outage timestamp, it is possible to distinguish between destructive and non-destructive events when a power outage occurs, thereby avoiding false triggering and providing a unified time anchor for subsequent event tracing. By activating the backup battery to enter the anti-theft collaborative positioning mode and reporting the geographical location, obtaining snapshots of line electrical parameters within key time windows and associated user load data, it is possible to maintain the continuity of positioning and evidence collection under main power interruption conditions, thereby improving… The system ensures complete retention of on-site information. By calculating the intensity of suspected contribution of instantaneous behavioral deviation and line loss and weighting and fusing them to generate a comprehensive suspected index, it can simultaneously characterize the correlation contribution of short-term abnormal user behavior and historical line loss, thereby improving the accuracy and interpretability of suspected identification. By generating a priority list of suspected users and encrypting and binding it with geographical location and power outage timestamp to obtain the data packet to be reported, it can consistently correlate the suspected results with the spatiotemporal information of the event, thereby improving the directionality of investigation and location and the credibility of data. By generating tamper-proof verification codes and intermittently reporting data packets during the low-power reporting phase, and generating analysis reports and uploading them to the main station after the main power is restored, it can continuously transmit key clues and ensure data integrity under limited battery life, thereby improving the continuity and closed-loop analysis capabilities of anti-electricity theft handling. Attached Figure Description

[0025] The accompanying drawings, which form part of this specification, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an undue limitation of the invention. In the drawings: Figure 1This is a flowchart of a method for locating electricity theft users based on a smart grid line toolbox in an embodiment of the present invention; Figure 2 This is a structural block diagram of an electricity theft user location system based on a smart grid line toolbox, according to an embodiment of the present invention. Detailed Implementation

[0026] The present invention will now be described in detail with reference to the accompanying drawings and embodiments. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.

[0027] The following detailed description is exemplary and intended to provide further detailed explanation of the invention. Unless otherwise specified, all technical terms used in this invention have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in this invention is for describing particular embodiments only and is not intended to limit the scope of exemplary embodiments according to the invention.

[0028] Example 1 like Figure 1 As shown, this invention discloses a method for locating electricity theft users based on a smart grid line toolbox, specifically including the following steps: S10: Collect the electrical parameters and power data of the branch lines installed in the line toolbox, generate the line loss rate benchmark curve, and determine the real-time fluctuation characteristics based on the line loss rate benchmark curve.

[0029] Specifically, the metering unit inside the line toolbox continuously collects the total three-phase voltage and total three-phase current at the outlet of the installed branch and calculates active power, reactive power, and energy data to form total energy data. At the same time, it collects the frozen time-of-use positive active energy of the associated user's smart meter at a preset cycle through power line carrier or low-power wireless communication to form time-of-use energy data. The total energy data and time-of-use energy data are stored in non-volatile memory to form a long-term dataset with multiple typical daily cycles. Combined with the transformer area topology, a dynamic line loss rate benchmark value sequence for each time period is generated. Then, the dynamic line loss rate benchmark value sequence is fitted with trends and cycles to obtain the line loss rate benchmark curve. Subsequently, the real-time statistical line loss rate is compared with the predicted value of the line loss rate benchmark curve in the same time period to obtain the relative deviation, which is then standardized. The relative deviation and the result of the standardization process are used as real-time fluctuation features for subsequent power outage detection.

[0030] S20: When a main power failure is detected, determine whether an unplanned destructive power failure has occurred based on real-time fluctuation characteristics and the original waveform of the load current before the power failure, and record the corresponding power failure timestamp.

[0031] Specifically, when the main power monitoring circuit detects that the AC input voltage is continuously lower than the rated voltage by a certain percentage and exceeds a very short delay, a power failure event is triggered and the power failure timestamp T0 is locked, where T0 is the time identifier of this main power failure. Then, the line loss rate fluctuation sequence corresponding to the real-time fluctuation characteristics is extracted from the first time window before the power failure and its complexity mutation degree is calculated. At the same time, the original waveform of the load current is extracted from the second time window before the power failure and time-frequency energy analysis is performed to obtain the waveform distortion characteristics. When the line loss mutation characteristics and the waveform distortion characteristics meet the preset judgment conditions, the power failure is judged as an unplanned destructive power failure and the judgment result is output.

[0032] S30: In the event of an unplanned destructive power outage, activate the backup battery to enter the anti-theft collaborative positioning mode, report the geographical location of the line toolbox, and obtain a snapshot of the line electrical parameters and associated user load data within the critical time window.

[0033] Specifically, after the determination of unplanned destructive power outage is established, the system switches to backup battery power and enters the anti-theft collaborative positioning mode. The geographical location of the line toolbox is reported for the first time to form a spatial anchor point at the power outage site. Then, based on the power outage timestamp T0, a key time window covering the evidence collection needs before and after the power outage is determined, and continuous line monitoring data within the key time window is read from the cache to form a snapshot of the line electrical parameters. At the same time, the associated user load data within the key time window is retrieved from the electricity information collection system or the smart meter side that communicates with the line toolbox and time alignment is completed. The snapshot of the line electrical parameters and the associated user load data serve as inputs for subsequent suspicion assessment.

[0034] S40: In the anti-theft collaborative positioning mode, the instantaneous behavior deviation and the suspected strength of line loss contribution are calculated based on the line electrical parameter snapshot and the associated user load data. The instantaneous behavior deviation and the suspected strength of line loss contribution are weighted and fused to generate a comprehensive suspected index.

[0035] Specifically, in the anti-theft collaborative positioning mode that maintains backup battery power, the instantaneous behavior deviation and line loss contribution suspicion intensity are calculated for each associated user. The instantaneous behavior deviation is used to measure the abnormal deviation of the user's power curve relative to its historical benchmark within the critical time window and the correlation between its sudden change and the total change of the branch. The line loss contribution suspicion intensity is used to measure the statistical influence of the user's historical electricity consumption behavior on the fluctuation of the branch line loss rate and the consistency of its change direction within the critical time window. Then, the two are normalized and weighted according to dynamic weights to obtain a comprehensive suspicion index to characterize the suspicion level under this power outage event.

[0036] S50: Generate a priority list of suspected households based on comprehensive suspicion indicators, encrypt and bind the priority list of suspected households with geographical location and power outage timestamp to obtain the data packet to be reported.

[0037] Specifically, a unified dimensional mapping is performed on the comprehensive suspicion indicators of all associated users, and a priority ranking list of suspected electricity thieves is generated in descending order. The priority ranking list of suspected electricity thieves includes at least the user identifier, the corresponding comprehensive suspicion indicators, and the main anomaly tags. The key information in the first predetermined ranking of the suspected electricity thieves, along with the device's geographical location and power outage timestamp T0, are structured and assembled, and then symmetric encryption is performed to obtain the data packet to be reported. The data packet to be reported is used to continuously transmit evidence of electricity theft location during the low-power reporting phase.

[0038] S60: Generates anti-tampering verification codes for data packets to be reported. During the low-power reporting phase, it reports the geographical location and intermittently reports the data packets to be reported and the corresponding anti-tampering verification codes according to the preset time period. After the main power is restored, it generates a power failure event analysis report and uploads it to the main station.

[0039] Specifically, after entering the low-power reporting phase, the device is woken up periodically in the first cycle to report the updated geographical location of the device, and intermittently woken up in the second cycle to report the summary of the priority list of suspected electricity thieves. The second cycle is longer than the first cycle to reduce communication power consumption. At the same time, before each report, the current summary information, the device's unique identifier, and the reporting timestamp are input into the message authentication code generation algorithm to generate an anti-tampering verification code, which is sent with the packet. The device enters deep sleep during the interval between adjacent reports to further reduce power consumption. The device continuously monitors the backup battery output voltage and ambient temperature to report with an alarm flag when alarm conditions are met. When the main power is detected to be restored, the device exits the anti-theft collaborative positioning mode and generates an analysis report of this power outage event, which is synchronized to the main station to support subsequent joint investigations.

[0040] In one embodiment, step S10 involves collecting the electrical parameters and power data of the branch lines installed in the line toolbox, generating a line loss rate benchmark curve, and determining the real-time fluctuation characteristics based on the line loss rate benchmark curve, including: S11: Obtain the dynamic line loss rate sequence corresponding to the line electrical parameters and power data.

[0041] Specifically, the total power consumption data of the installed branches and the time-of-use power consumption data of each associated user are collected under multiple typical daily cycles. Based on the transformer area topology, the branch head is regarded as the root node and the connection point of each user's electricity meter is regarded as the user node. Combined with the line parameters and load distribution, forward and backward power flow calculations are performed to obtain the theoretical line loss power consumption corresponding to each calculation period. The dynamic line loss rate benchmark value is further converted into a dynamic line loss rate benchmark value. The dynamic line loss rate benchmark value is arranged in time order to form a dynamic line loss rate benchmark value sequence and is output as a dynamic line loss rate sequence. The total power consumption data is the power consumption data obtained by metering at the branch outlet, and the time-of-use power consumption data is the time-of-use positive active power consumption data of the associated users, and the corresponding load can be obtained from the difference between adjacent frozen values.

[0042] S12: Perform time series decomposition on the dynamic line loss rate sequence to obtain the trend term and periodic term, and perform fitting processing on the trend term and periodic term to generate the line loss rate benchmark curve.

[0043] Specifically, the dynamic line loss rate benchmark value sequence is used as input to perform time series decomposition to obtain long-term trend component, periodic fluctuation component and residual component. The long-term trend component is used to characterize the slow effects of line aging, seasonal changes and other factors, the periodic fluctuation component is used to characterize the load change pattern with a daily cycle, and the residual component is used to characterize random noise. Then, the long-term trend component and periodic fluctuation component are extracted by moving average or Loess local regression and the two are superimposed and fitted to generate the line loss rate benchmark curve. The line loss rate benchmark curve is used to predict the line loss rate benchmark value for any future period of the same time.

[0044] S13: Obtain the actual line loss rate under a unified time reference, and calculate the deviation between the actual line loss rate and the line loss rate reference curve to obtain the relative deviation of the line loss rate.

[0045] Specifically, under a unified time reference, the actual line loss rate is calculated by summing the total electricity change and the electricity change of all individual households within the current monitoring period. The predicted line loss rate for the corresponding date and time is read from the line loss rate benchmark curve as the predicted value. The relative deviation δ of the line loss rate is calculated based on the two. The relative deviation δ of the line loss rate is calculated as δ = (actual value - predicted value) / predicted value, where the actual value is the actual line loss rate and the predicted value is the predicted line loss rate for the corresponding period of the line loss rate benchmark curve. The relative deviation of the line loss rate is used to characterize the degree of deviation of the line loss and serves as the input for subsequent standardization processing.

[0046] S14: Standardize the relative deviation of the line loss rate to obtain real-time fluctuation characteristics.

[0047] Specifically, the relative deviation sequence of line loss rate within a recent time range is continuously maintained, and its mean deviation μ and standard deviation σ are statistically analyzed. The latest relative deviation of line loss rate δ is standardized to obtain a standardized value Z, which is then used as the real-time fluctuation feature output. The standardized value Z is calculated as Z=(δ-μ) / σ, where δ is the latest relative deviation of line loss rate, μ is the mean of the recent relative deviation sequence of line loss rate, and σ is the standard deviation of the recent relative deviation sequence of line loss rate. The real-time fluctuation feature is the standardized value, and its sign and amplitude are used to quantify the degree of line loss anomaly.

[0048] In one embodiment, step S14, namely, performing standardization on the relative deviation of the line loss rate to obtain real-time fluctuation characteristics, includes: S141: Within a preset time window, calculate the mean and standard deviation of the relative deviation of the line loss rate.

[0049] Specifically, the relative deviation values ​​of line loss rate obtained at each sampling time within the preset time window are used to form a deviation sequence, and the mean deviation μ and the standard deviation deviation σ are statistically calculated on the sequence. The preset time window is used to limit the recent statistical range to reflect the latest line loss deviation distribution. The mean deviation μ is used to characterize the average level of deviation within the window, and the standard deviation deviation σ is used to characterize the dispersion of deviation within the window and to provide a scale benchmark for subsequent normalization.

[0050] S142: Normalize the relative deviation of the line loss rate based on the mean and standard deviation of the deviation to obtain a standardized deviation sequence.

[0051] Specifically, for each relative deviation value δk of the line loss rate within the preset time window, the (δk-μ) / σ transformation is performed to obtain the corresponding standardized deviation value Zk, and a standardized deviation sequence is formed in chronological order. Here, δk is the relative deviation of the line loss rate at the k-th sampling time within the window, μ is the mean deviation of the corresponding deviation for the window, and σ is the standard deviation of the corresponding deviation for the window. The standardized deviation sequence is used to unify the measurement scale of the deviation in different time periods for subsequent power outage detection.

[0052] S143: Output the standardized deviation sequence as a real-time fluctuation feature.

[0053] Specifically, the latest standardized deviation value Z in the standardized deviation sequence is output as a real-time fluctuation feature and bound to the corresponding sampling time for storage. This allows the real-time fluctuation feature sequence before the power outage to be directly traced back for complexity analysis when a power outage is triggered. The real-time fluctuation feature is the standardized value Z and its amplitude is used to characterize the abnormal intensity of the line loss deviation.

[0054] In one embodiment, in step S20, i.e., when a main power failure is detected, determining whether an unplanned destructive power failure has occurred based on real-time fluctuation characteristics and the original waveform of the load current before the power failure includes: S21: Extract the line loss rate fluctuation sequence corresponding to the real-time fluctuation characteristics within a preset time period before the main power failure trigger time.

[0055] Specifically, the time series of real-time fluctuation characteristics within the first time window before the power outage timestamp T0 is taken as the baseline and used as the line loss rate fluctuation series. The first time window is used to cover the abnormal evolution process of line loss before the power outage. The line loss rate fluctuation series reflects the change of the degree of recent line loss anomaly over time and is used as the input sequence for approximate entropy calculation.

[0056] S22: Calculate the approximate entropy of the line loss rate fluctuation sequence to obtain the line loss complexity characteristics.

[0057] Specifically, for the line loss rate fluctuation sequence, an embedding dimension m and a similarity tolerance threshold r are set, and a set of comparison vectors of length m is constructed. Here, m is used to define the dimensional length of the comparison vectors, and r is used to define the distance radius between two similar vectors. Then, for each m-dimensional vector, the similarity ratio of its distance to r among all vectors is calculated, and the natural logarithm is taken and averaged to obtain Φ(m). Then, the embedding dimension is increased to m+1 and the above process is repeated to obtain Φ(m+1). Finally, the approximate entropy ApEn is defined as ApEn=Φ(m)-Φ(m+1) and is used as the line loss complexity feature output. Here, Φ(m) and Φ(m+1) represent the average self-similarity of the sequence at scale m and scale m+1, respectively. The distance is Chebyshev distance, and the maximum value of the difference between corresponding components is taken as the distance between vectors. The line loss complexity feature is used to quantify the unpredictability of line loss fluctuations, and the larger the ApEn, the more complex the fluctuations.

[0058] S23: Perform wavelet packet transform on the original waveform of the load current before power failure, extract at least one characteristic frequency band energy and calculate the corresponding energy change rate to obtain waveform distortion characteristics.

[0059] Specifically, the original waveform sampling data of the load current within the second time window before the power outage timestamp T0 is extracted from the high-speed sampling buffer, and wavelet packet transform is performed to achieve fine-grained frequency band division. The frequency band energy Ek is calculated for the preset characteristic frequency band that is strongly correlated with the electricity theft and damage behavior, and the energy change rate Gk is further calculated. The energy change rate Gk can be calculated as Gk=(Eafter,k-Ebefore,k) / Ebefore,k, where Ebefore,k is the average energy of the kth characteristic frequency band in the first half of the second time window, and Eafter,k is the average energy of the kth characteristic frequency band in the second half of the second time window. The waveform distortion feature is characterized by the energy change rate of at least one characteristic frequency band and is used to reflect the degree of abnormal energy injection or distortion of the load current in a specific frequency band.

[0060] S24: If the characteristics of line loss complexity and waveform distortion meet the preset judgment conditions, it is determined that an unplanned destructive power outage has occurred.

[0061] Specifically, the line loss complexity feature ApEn is compared with a preset complexity mutation threshold, and the characteristic frequency band energy change rate Gk is compared with a preset energy mutation threshold. When ApEn exceeds the complexity mutation threshold and at least one characteristic frequency band satisfies that |Gk| exceeds the energy mutation threshold, it is determined to be an unplanned destructive power outage; otherwise, it is determined to be a planned power outage, a power grid fault, or a power outage caused by other non-destructive reasons. The complexity mutation threshold is used to determine whether the line loss fluctuation complexity is abnormal, and the energy mutation threshold is used to determine whether the load current energy change in a specific frequency band is abnormal. The determination result serves as the sole condition for triggering the anti-theft collaborative positioning mode.

[0062] In one embodiment, step S30, i.e., upon determining that an unplanned destructive power outage has occurred, involves reporting the geographical location of the line toolbox and obtaining a snapshot of the line electrical parameters and associated user load data within a critical time window, including: S31: Determine the key time windows, including the first time window before the power outage and the second time window after the power outage, based on the power outage timestamp.

[0063] Specifically, the first time window and the second time window are aligned on the time axis, and the overlapping part of the two or the extended time window covering the two is taken as the key time window. The key time window can be defined as [T0-ΔT,T0] to cover the abnormal evolution before the power failure and the evidence of the sudden change at the moment of power failure. T0 is the power failure timestamp, and ΔT is a fixed time length window value that extends forward and is used to limit the coverage of the key time window, so that subsequent snapshot extraction can quickly lock the evidence collection interval under the condition of backup battery power supply.

[0064] S32: Collect line electrical parameters within a critical time window and generate a snapshot of the line electrical parameters.

[0065] Specifically, the original line data of each sampling point within the key time window [T0-ΔT,T0] is read from the circular cache and structured to form a line electrical parameter snapshot. The line electrical parameter snapshot includes at least the three-phase voltage imbalance sequence, the zero-sequence current RMS value sequence, and the first-order differential sequence of total active power. The three-phase voltage imbalance sequence can be obtained by calculating the percentage ratio of negative-sequence voltage to positive-sequence voltage in each power frequency cycle. The zero-sequence current RMS value sequence can be obtained by calculating the RMS value of the three-phase current vector sum in each sampling cycle. The first-order differential sequence of total active power can be calculated by the difference in total active power between adjacent sampling points. The line electrical parameter snapshot is copied to a secure storage area to avoid loss of evidence due to cache overwriting after power failure.

[0066] S33: Retrieve associated user load data within the critical time window and perform time alignment processing to obtain associated user load data.

[0067] Specifically, after a power outage, the system seizes the available communication window and initiates an emergency data request to the concentrator or each smart meter to obtain the load data of all associated users within the critical time window [T0-ΔT,T0]. Time alignment processing is then performed to form an associated user load dataset. The associated user load dataset includes at least the active power time-series data and the current waveform distortion rate time-series data of each user. The active power time-series data can be reported at a higher density, and the current waveform distortion rate time-series data can be obtained by reporting the total harmonic distortion rate of the current for each power frequency cycle. The time alignment processing is used to align data from different sources and with different reporting granularities to a unified time axis to meet the needs of subsequent deviation and suspicion strength calculations.

[0068] In one embodiment, step S40 involves calculating the instantaneous behavior deviation and the suspected strength of line loss contribution based on the line electrical parameter snapshot and associated user load data, and then weighting and fusing the instantaneous behavior deviation and the suspected strength of line loss contribution to generate a comprehensive suspicion index, including: S41: Obtain the user power curve from the associated user load data and extract the historical same-period benchmark curve. Calculate the deviation distance based on the user power curve and the historical same-period benchmark curve, and generate the instantaneous behavior deviation by combining the mutation correlation degree.

[0069] Specifically, for each associated user i, active power time-series data Pi(t) within its key time window is extracted from the associated user load dataset, where i is the user index and t is the time variable. Simultaneously, the historical average power curve of that user in the same week type and time period as the key time window is retrieved from the historical database as the historical baseline curve Bi(t). Pi(t) and Bi(t) are treated as multi-dimensional vectors, and the covariance matrix X is calculated based on the user's historical power data. Then, the Mahalanobis distance DMi is calculated to measure the overall deviation of Pi(t) from Bi(t). The Mahalanobis distance DMi satisfies DMi² = [Pi(t) - Bi(t)]T × X⁻¹ × [Pi(t) - Bi(t)], where X⁻¹ is the inverse of the covariance matrix. Simultaneously, the user's power... The power mutation time point Hi of the rate curve Pi(t) is identified, and the total power mutation time point Ha of the branch is identified from the first-order difference sequence of the total active power in the line electrical parameter snapshot. The mutual information I(Hi;Ha) between Hi and Ha is calculated to characterize the correlation of the mutation time. The mutual information I(Hi;Ha) is estimated according to I(Hi;Ha)=∑p(hi,ha)×log(p(hi,ha) / (p(hi)×p(ha))), where p(hi,ha) is the joint probability distribution of Hi and Ha on the discrete time grid, and p(hi) and p(ha) are the corresponding marginal probability distributions. Finally, DMi and I(Hi;Ha) are normalized and weighted and fused according to preset weights to obtain the instantaneous behavior deviation Di as the quantitative result of the instantaneous abnormal behavior of user i.

[0070] S42: Obtain historical electricity consumption data and branch line loss rate data of related users, calculate the influence score based on the historical electricity consumption data and branch line loss rate data, and generate the suspected strength of line loss contribution based on the influence score and the consistency of the change direction within the key time window.

[0071] Specifically, for each associated user i, historical electricity consumption data over a relatively long period of time is retrieved, and historical line loss rate data of the branch is retrieved simultaneously to form historical data. Based on the historical data, a vector autoregression model is constructed with the electricity consumption of each user as the input variable and the line loss rate of the branch as the output variable. Granger causality test is performed to obtain the basic influence score Fi of user i. The basic influence score Fi is used to characterize the statistical explanatory power of the change in user i's electricity consumption on the subsequent fluctuation of the line loss rate and can be normalized to the [0,1] interval according to the test statistic. At the same time, the direction of change of active power of user i is calculated within the key time window, and the instantaneous change direction of the branch line loss rate is inferred by combining the line electrical parameter snapshot to obtain the consistency of the change direction and define the sign consistency coefficient Ci. When the two directions are consistent, Ci is +1 and when the two directions are opposite, Ci is -1. Finally, the line loss contribution suspicion intensity Si is generated by Si=Fi×Ci to reflect the degree of suspicion of user i's contribution to the line loss anomaly and its directionality.

[0072] S43: Normalize the instantaneous behavior deviation and the suspected strength of line loss contribution, and perform weighted fusion based on preset dynamic weights to obtain a comprehensive suspected index.

[0073] Specifically, the instantaneous behavioral deviation set {Di} and the suspected line loss contribution intensity set {Si} of all associated users are mapped to a unified suspected metric interval to form normalized Din and Sin. Then, the analytic hierarchy process is used to assign dynamic weights W1 and W2 to Din and Sin to calculate the comprehensive suspected index Sc. The comprehensive suspected index Sc satisfies Sc = W1 × Din + W2 × Sin and W1 + W2 = 1, where Din is the normalized instantaneous behavioral deviation, Sin is the normalized suspected line loss contribution intensity, W1 and W2 are the dynamic weights corresponding to this event, and the comprehensive suspected index Sc serves as the core scoring basis for subsequent ranking and summary reporting.

[0074] In one embodiment, step S41, which involves calculating the deviation distance based on the user power curve and the historical baseline curve for the same period and generating an instantaneous behavioral deviation by combining the abrupt change correlation, includes: S411: Calculate the Mahalanobis distance based on the user power curve and the historical benchmark curve for the same period to obtain the first deviation.

[0075] Specifically, a difference vector [Pi(t)-Bi(t)] is constructed between the user power curve Pi(t) of user i within the key time window and the historical reference curve Bi(t) of the same period. Based on the user's historical power data, the covariance matrix X is calculated. The squared Mahalanobis distance is obtained by calculating [Pi(t)-Bi(t)]T×X-1×[Pi(t)-Bi(t)] and taking the square root to obtain the Mahalanobis distance DMi as the first deviation. Here, Pi(t) represents the active power sequence of user i within the key time window as a function of time t, Bi(t) represents the average power reference sequence of user i in the corresponding period of the same period in history, X represents the covariance matrix of power values ​​between each sampling time, and DMi is used to measure the overall deviation of the power curve and can take into account the correlation between different time points.

[0076] S412: Extract the power mutation time of the user power curve and the mutation time of the total power of the branch, and calculate the mutual information between the power mutation times to obtain the second deviation.

[0077] Specifically, the power mutation moment point Hi is identified from the user power curve Pi(t), and the branch total power mutation moment point Ha is identified from the line electrical parameter snapshot based on the first-order difference sequence of total active power. The time axis is discretized into multiple time grids, and the joint probability distribution p(hi,ha) of Hi and Ha appearing in the time grids and their respective marginal probability distributions p(hi) and p(ha) are statistically analyzed. The mutual information is calculated by I(Hi;Ha)=∑p(hi,ha)×log(p(hi,ha) / (p(hi)×p(ha))) to obtain the second deviation, where the mutual information is used to characterize the correlation strength between the user mutation and the branch total mutation in the time of occurrence, and the larger the mutual information, the stronger the correlation.

[0078] S413: Weighted fusion of the first deviation and the second deviation to obtain the instantaneous behavior deviation.

[0079] Specifically, the first deviation amount, Mahalanobis distance DMi, and the second deviation amount, mutual information I (Hi;Ha), are normalized to eliminate dimensional differences. The two are then weighted and summed according to preset weighting coefficients to obtain the instantaneous behavior deviation degree Di. Di is used to comprehensively characterize the degree to which the user power curve deviates from the historical synchronous pattern and the degree of synchronous correlation between its mutation and the total mutation of the branch, and serves as the input for the subsequent calculation of the comprehensive suspicion index.

[0080] In one embodiment, step S42, which involves calculating an influence score based on historical electricity consumption data and branch line loss rate data, and generating a suspected line loss contribution intensity based on the consistency of the influence score and the direction of change within a key time window, includes: S421: Construct a vector autoregression model based on historical electricity consumption data and branch line loss rate data, and calculate the influence score based on the Granger causality statistic.

[0081] Specifically, a vector autoregression model is constructed based on the historical daily electricity consumption data of user i and other relevant users, as well as the historical daily statistical line loss rate data of the branch. This model is able to characterize the statistical explanatory relationship between changes in user electricity consumption and changes in line loss rate. The test statistic corresponding to user i is obtained through Granger causality test as the basic influence score Fi. Fi is used to quantify the guiding effect of the dynamic changes in user i's electricity consumption on the subsequent fluctuations of line loss rate and can be normalized and mapped according to the statistic to fall into the [0,1] interval.

[0082] S422: Calculate the sign consistency coefficient based on the direction of change of user power and the direction of change of line loss rate within the key time window, and combine the influence score and the sign consistency coefficient to obtain the suspected strength of line loss contribution.

[0083] Specifically, within the critical time window, the direction of change of active power of user i is calculated, and the instantaneous change direction of branch line loss rate is estimated or reconstructed by combining the line electrical parameter snapshot. The sign consistency coefficient Ci is defined by judging whether the two directions are consistent. When the directions are consistent, Ci = +1; when the directions are opposite, Ci = -1. The basic influence score Fi is multiplied by the sign consistency coefficient Ci to obtain the line loss contribution suspicion intensity Si. The line loss contribution suspicion intensity Si can be positive or negative, with a positive value indicating increased suspicion and a negative value indicating decreased suspicion. Fi reflects historical statistical influence, and Ci reflects the evidence of directional consistency in this event.

[0084] S423: Based on the analytic hierarchy process, dynamic weights are determined, and based on the dynamic weights, the normalized instantaneous behavior deviation and the suspected strength of line loss contribution are weighted and fused to obtain a comprehensive suspected index.

[0085] Specifically, the Analytic Hierarchy Process (AHP) was used to construct a judgment matrix by comparing the importance of instantaneous behavioral deviation and line loss contribution suspicion intensity in this electricity theft suspicion assessment. The initial weights were obtained by calculating the eigenvectors of the judgment matrix, and then the weights were fine-tuned in combination with the characteristics of this power outage event to determine the dynamic weights W1 and W2, satisfying W1 + W2 = 1. Subsequently, the normalized Din and Sin were calculated according to Sc = W1 × Din + W2 × Sin to obtain the comprehensive suspicion index Sc, where W1 corresponds to the instantaneous behavioral deviation weight, W2 corresponds to the line loss contribution suspicion intensity weight, Din is the normalized value of instantaneous behavioral deviation, Sin is the normalized value of line loss contribution suspicion intensity, and Sc is used for subsequent ranking and summary reporting.

[0086] In one embodiment, step S60 involves reporting the geographical location and intermittently reporting data packets to be reported during the low-power reporting phase according to a preset time period, generating an anti-tampering verification code for the data packets to be reported, and generating a power failure event analysis report and uploading it to the main station after the main power is restored. This includes: S61: Extract a preset number of suspect entries from the suspect priority sorting list to generate a suspect list summary, and combine the suspect list summary with the device unique identifier and power failure timestamp to obtain summary data.

[0087] Specifically, during the low-power reporting phase, the system wakes up in the second cycle to read the most recently generated priority list of suspected electricity thieves and extracts the top-ranked users to form a summary of the suspected list. The summary of the suspected list includes at least the anonymized user code, the weighted comprehensive suspected index, and the feature code converted from the main abnormal index type. The summary of the suspected list is then combined with the device's unique identifier and the power outage timestamp T0 in a predefined format to obtain the summary data. The second cycle is longer than the first cycle to reduce the frequency of summary reporting and control the consumption of the backup battery.

[0088] S62: Perform symmetric encryption on the summary data and geographical location to obtain ciphertext data, and use the ciphertext data as the data packet to be reported.

[0089] Specifically, the summary data and the latitude and longitude information of the device's geographical location reported for the first time or the latest time are encapsulated in a structured manner, and then a symmetric encryption is performed by calling a preset encryption key to obtain ciphertext data. The ciphertext data is then used as a data packet to be reported for intermittent reporting. The symmetric encryption can use a data block encryption method under a preset key to ensure the confidentiality of the power failure scene evidence during transmission and to avoid leakage of sensitive user information.

[0090] S63: Generate a message authentication code based on the data packet to be reported as an anti-tampering verification code, and intermittently report the anti-tampering verification code together with the data packet to be reported.

[0091] Specifically, before each second-cycle wake-up is prepared to send, the encrypted data, the device's unique identifier, and the current wake-up time timestamp in the data packet to be reported are concatenated into a message string and input into the message authentication code generation algorithm to obtain an anti-tampering verification code. The anti-tampering verification code can be calculated by using a cryptographic hash function based on a shared key to the message string, so that any tampering with the encrypted data or key fields will cause the main station to fail the verification, thereby realizing the integrity verification and anti-tampering protection of the intermittently reported data packets.

[0092] S64: Enters deep sleep state between adjacent intermittent reports, and monitors the status of the backup battery during the low power reporting phase. If the status of the backup battery meets the alarm conditions, the corresponding alarm flag is reported.

[0093] Specifically, after each location or summary report is completed, the communication module's power supply is cut off and it enters deep sleep to reduce power consumption. At the same time, the backup battery output voltage and the ambient temperature inside the device package are sampled in a low-frequency wake-up mode to form health status monitoring data. The battery output voltage is compared with a preset voltage safety threshold and the ambient temperature is compared with a preset normal operating temperature range [Mu, Mo], where Mu is the lower limit of the operating temperature and Mo is the upper limit of the operating temperature. When the battery output voltage is continuously lower than the voltage safety threshold or the ambient temperature exceeds Mo or is lower than Mu, the corresponding alarm flag is set and the alarm code is embedded in the next first or second cycle of the reporting data packet. This allows the master station to know the device's health status while receiving the location or suspected summary and to arrange recovery and maintenance accordingly.

[0094] S65: After the main power is restored, generate a power outage event analysis report and upload it to the main station. The power outage event analysis report shall include at least the judgment result of unplanned destructive power outage, a snapshot of line electrical parameters, a comprehensive list of suspected indicators and a priority list of suspected users, and a low power consumption reporting log.

[0095] Specifically, the system continuously monitors the main power status and exits the anti-theft collaborative positioning mode and resumes the regular monitoring process after detecting the restoration of main power. It then structurally summarizes the evidence chain for determining this incident, the line electrical parameter snapshots and related user load data snapshots within the key time window, the intermediate calculation results of the instantaneous behavior deviation of each user and the suspected strength of line loss contribution, the priority ranking list and final summary information of suspected electricity thieves, all reporting records and communication status logs during the low power phase, and the line status calibration data of the first complete monitoring cycle after the main power is restored. This data is then used to generate a power outage event analysis report and uploaded to the main station. After receiving the power outage event analysis report, the main station can perform spatiotemporal correlation analysis with related event reports reported by other line toolboxes in the same transformer area. When multiple reports are found to point to the same geographical area and the suspected user identifiers overlap, a high-confidence joint anti-theft on-site inspection work order is generated. The power outage event analysis report is stored in the main station database to update the transformer area line loss anomaly pattern library and user behavior risk profile.

[0096] Example 2 like Figure 2 As shown, based on the same inventive concept as the above embodiments, the present invention also provides a power theft user location system based on a smart grid line toolbox, comprising: The line loss acquisition module is used to collect the electrical parameters and power data of the branch lines installed in the line toolbox, generate a line loss rate benchmark curve, and determine the real-time fluctuation characteristics based on the line loss rate benchmark curve. The power failure detection module is used to determine whether an unplanned destructive power failure has occurred when a main power failure is detected, based on real-time fluctuation characteristics and the original waveform of the load current before the power failure, and to record the corresponding power failure timestamp. The collaborative positioning module is used to activate the backup battery and enter the anti-theft collaborative positioning mode when an unplanned destructive power outage is detected, report the geographical location of the line toolbox, and obtain a snapshot of the line electrical parameters and associated user load data within a key time window; The suspicion calculation module is used to calculate the instantaneous behavior deviation and the suspected strength of line loss contribution based on the line electrical parameter snapshot and associated user load data in the anti-theft collaborative positioning mode, and to generate a comprehensive suspicion index by weighted fusion of the instantaneous behavior deviation and the suspected strength of line loss contribution. The sorting and binding module is used to generate a priority list of suspect households based on comprehensive suspicion indicators, and to encrypt and bind the priority list of suspect households with geographical location and power outage timestamp to obtain the data packet to be reported. The low-power reporting module is used to generate anti-tampering verification codes for data packets to be reported. It reports the geographical location and intermittently reports the data packets to be reported and the corresponding anti-tampering verification codes during the low-power reporting phase according to a preset time period. After the main power is restored, it generates a power failure event analysis report and uploads it to the main station.

[0097] Optional, the line loss acquisition module includes: The line loss sequence submodule is used to obtain the dynamic line loss rate sequence corresponding to the line electrical parameters and power data; The decomposition and fitting submodule is used to decompose the dynamic line loss rate sequence into a time series to obtain the trend term and the period term, and to perform fitting processing on the trend term and the period term to generate the line loss rate benchmark curve. The deviation calculation submodule is used to obtain the actual line loss rate under a unified time base, and to calculate the deviation based on the actual line loss rate and the line loss rate benchmark curve to obtain the relative deviation of the line loss rate. The deviation standard submodule is used to perform standardization processing on the relative deviation of the line loss rate to obtain real-time fluctuation characteristics.

[0098] Optional, the deviation criteria submodule includes: The mean value statistics unit is used to calculate the mean and standard deviation of the relative deviation of the line loss rate within a preset time window. The normalization processing unit is used to normalize the relative deviation of the line loss rate based on the mean deviation and the standard deviation of the deviation, so as to obtain the standardized deviation sequence. The feature output unit is used to output the standardized deviation sequence as a real-time fluctuation feature.

[0099] Optional, the power failure detection module includes: The fluctuation extraction submodule is used to extract the line loss rate fluctuation sequence corresponding to the real-time fluctuation characteristics within a preset time period before the main power failure trigger time. The entropy calculation submodule is used to calculate the approximate entropy of the line loss rate fluctuation sequence to obtain the line loss complexity characteristics. The distortion extraction submodule is used to perform wavelet packet transform on the original waveform of the load current before power failure, extract at least one characteristic frequency band energy and calculate the corresponding energy change rate to obtain waveform distortion features. The comprehensive judgment submodule is used to determine whether an unplanned destructive power outage has occurred when the characteristics of line loss complexity and waveform distortion meet the preset judgment conditions.

[0100] Optionally, the cooperative positioning module includes: The time window determination submodule is used to determine key time windows, including the first time window before the power outage and the second time window after the power outage, based on the power outage timestamp. The snapshot acquisition submodule is used to acquire line electrical parameters within a key time window and generate a snapshot of the line electrical parameters. The load alignment submodule is used to retrieve associated user load data within a critical time window and perform time alignment processing to obtain associated user load data.

[0101] Optionally, the suspect calculation module includes: The deviation generation submodule is used to obtain the user power curve in the associated user load data and extract the historical same-period benchmark curve. Based on the user power curve and the historical same-period benchmark curve, the deviation distance is calculated and the instantaneous behavior deviation is generated by combining the abrupt correlation degree. The contribution generation submodule is used to obtain historical electricity consumption data and branch line loss rate data of associated users, calculate the influence score based on the historical electricity consumption data and branch line loss rate data, and generate the line loss contribution suspicion intensity based on the influence score and the consistency of the change direction within the key time window. The fusion scoring submodule is used to normalize the instantaneous behavioral deviation and the suspected intensity of line loss contribution, and perform weighted fusion based on preset dynamic weights to obtain a comprehensive suspected index.

[0102] Optional, the deviation generation submodule includes: The Mahalanobis calculation unit is used to calculate the Mahalanobis distance based on the user's power curve and the historical benchmark curve for the same period, and to obtain the first deviation. The mutual information unit is used to extract the power change time of the user power curve and the change time of the total power of the branch, and calculate the mutual information between the power change times to obtain the second deviation. The deviation fusion unit is used to perform weighted fusion of the first deviation and the second deviation to obtain the instantaneous behavior deviation.

[0103] Optionally, the contribution generation submodule includes: The VAR modeling unit is used to construct a vector autoregression model based on historical electricity consumption data and branch line loss rate data, and to calculate the influence score based on the Granger causality statistic of the vector autoregression model. The symbol consistency unit is used to calculate the symbol consistency coefficient based on the direction of change of user power and the direction of change of line loss rate within the key time window, and to combine the influence score and the symbol consistency coefficient to obtain the suspected strength of line loss contribution. The weighted fusion unit is used to determine dynamic weights based on the analytic hierarchy process (AHP), and then to perform weighted fusion of the normalized instantaneous behavior deviation and the suspected strength of line loss contribution based on the dynamic weights to obtain a comprehensive suspected index.

[0104] Optional, the low-power reporting module includes: The summary extraction submodule is used to extract a preset number of suspect entries from the suspect priority sorting list to generate a suspect list summary, and combine the suspect list summary with the device unique identifier and power failure timestamp to obtain summary data; The symmetric encryption submodule is used to perform symmetric encryption on the digest data and the geographic location to obtain ciphertext data, and then use the ciphertext data as the data packet to be reported. The authentication generation submodule is used to generate a message authentication code as an anti-tampering verification code based on the data packet to be reported, and intermittently report the anti-tampering verification code together with the data packet to be reported. The hibernation monitoring submodule is used to enter a deep hibernation state between adjacent intermittent reporting, and to monitor the status of the backup battery during the low power reporting phase. When the status of the backup battery meets the alarm conditions, the corresponding alarm flag is reported. The report generation submodule is used to generate a power outage event analysis report and upload it to the main station after the main power is restored. The power outage event analysis report includes at least the determination result of unplanned destructive power outage, a snapshot of line electrical parameters, a comprehensive list of suspected indicators and a priority list of suspected users, and low power consumption reporting logs.

[0105] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0106] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A method for locating electricity theft users based on a smart grid line toolbox, characterized in that, The method includes: The electrical parameters and power data of the branch lines installed in the line toolbox are collected, a line loss rate benchmark curve is generated, and the real-time fluctuation characteristics are determined based on the line loss rate benchmark curve. When a main power failure is detected, the system determines whether an unplanned destructive power failure has occurred based on the real-time fluctuation characteristics and the original waveform of the load current before the power failure, and records the corresponding power failure timestamp. In the event of an unplanned destructive power outage, the backup battery is activated to enter the anti-theft collaborative positioning mode, the geographical location of the line toolbox is reported, and snapshots of line electrical parameters and associated user load data are obtained within the critical time window. In the anti-theft collaborative positioning mode, the instantaneous behavior deviation and the suspected strength of line loss contribution are calculated based on the line electrical parameter snapshot and the associated user load data, and the instantaneous behavior deviation and the suspected strength of line loss contribution are weighted and fused to generate a comprehensive suspected index; A priority list of suspected households is generated based on the comprehensive suspicion indicators. The priority list of suspected households is encrypted and bound with the geographical location and the power outage timestamp to obtain the data packet to be reported. An anti-tampering verification code is generated for the data packet to be reported. The geographical location is reported during the low-power reporting phase according to a preset time period, and the data packet to be reported and the corresponding anti-tampering verification code are reported intermittently. After the main power is restored, a power failure event analysis report is generated and uploaded to the main station.

2. The method for locating electricity theft users based on a smart grid line toolbox according to claim 1, characterized in that, The data acquisition toolbox is used to collect the electrical parameters and power data of the branch lines, generate a line loss rate benchmark curve, and determine the real-time fluctuation characteristics based on the line loss rate benchmark curve, including: Obtain the dynamic line loss rate sequence corresponding to the line electrical parameters and the power data; The dynamic line loss rate sequence is decomposed into a time series to obtain a trend term and a period term. The trend term and the period term are then fitted to generate the line loss rate benchmark curve. The actual line loss rate is obtained under a unified time reference, and the deviation between the actual line loss rate and the line loss rate reference curve is calculated to obtain the relative deviation of the line loss rate. The relative deviation of the line loss rate is standardized to obtain the real-time fluctuation characteristics.

3. The method for locating electricity theft users based on a smart grid line toolbox according to claim 2, characterized in that, The standardization process performed on the relative deviation of the line loss rate to obtain the real-time fluctuation characteristics includes: Within a preset time window, the mean and standard deviation of the relative deviation of the line loss rate are statistically analyzed. The relative deviation of the line loss rate is normalized based on the mean deviation and the standard deviation of the deviation to obtain a standardized deviation sequence; The standardized deviation sequence is output as the real-time fluctuation feature.

4. The method for locating electricity theft users based on a smart grid line toolbox according to claim 1, characterized in that, The process of determining whether an unplanned destructive power outage has occurred based on the real-time fluctuation characteristics and the original waveform of the load current before the power outage when a main power failure is detected includes: Extract the line loss rate fluctuation sequence corresponding to the real-time fluctuation characteristics within a preset time period before the main power failure trigger moment; The approximate entropy is calculated for the line loss rate fluctuation sequence to obtain the line loss complexity characteristics; Perform wavelet packet transform on the original waveform of the load current before the power outage, extract at least one characteristic frequency band energy and calculate the corresponding energy change rate to obtain waveform distortion characteristics; If the line loss complexity characteristic and the waveform distortion characteristic meet the preset judgment conditions, it is determined that the unplanned destructive power outage has occurred.

5. The method for locating electricity theft users based on a smart grid line toolbox according to claim 1, characterized in that, The step of reporting the geographical location of the line toolbox and obtaining a snapshot of the line electrical parameters and associated user load data within a key time window, upon determining that an unplanned destructive power outage has occurred, includes: Based on the power outage timestamp, a key time window is determined, including a first time window before the power outage and a second time window after the power outage. Within the critical time window, collect line electrical parameters and generate a snapshot of the line electrical parameters; Within the key time window, retrieve the associated user load data and perform time alignment processing to obtain the associated user load data.

6. The method for locating electricity theft users based on a smart grid line toolbox according to claim 1, characterized in that, The calculation of instantaneous behavioral deviation and suspected line loss contribution intensity based on the line electrical parameter snapshot and the associated user load data, and the weighted fusion of the instantaneous behavioral deviation and suspected line loss contribution intensity to generate a comprehensive suspicion index, includes: Obtain the user power curve from the associated user load data and extract the historical same-period baseline curve. Calculate the deviation distance based on the user power curve and the historical same-period baseline curve, and generate the instantaneous behavior deviation by combining the abrupt correlation degree. Obtain historical electricity consumption data and branch line loss rate data of associated users, calculate influence score based on the historical electricity consumption data and the branch line loss rate data, and generate the line loss contribution suspicion intensity based on the influence score and the consistency of the change direction within the key time window; The instantaneous behavioral deviation and the suspected strength of line loss contribution are normalized and then weighted and fused based on preset dynamic weights to obtain the comprehensive suspected index.

7. The method for locating electricity theft users based on a smart grid line toolbox according to claim 6, characterized in that, The step of calculating the deviation distance based on the user power curve and the historical benchmark curve, and generating the instantaneous behavior deviation by combining the abrupt change correlation, includes: The Mahalanobis distance is calculated based on the user power curve and the historical reference curve for the same period to obtain the first deviation. Extract the power mutation time of the user power curve and the mutation time of the total branch power, and calculate the mutual information between the power mutation times to obtain the second deviation. The first deviation and the second deviation are weighted and fused to obtain the instantaneous behavior deviation.

8. The method for locating electricity theft users based on a smart grid line toolbox according to claim 6, characterized in that, The process of calculating an influence score based on the historical electricity consumption data and the branch line loss rate data, and generating the suspected strength of line loss contribution based on the consistency of the influence score and the direction of change within the key time window, includes: A vector autoregression model is constructed based on the historical electricity consumption data and the branch line loss rate data, and the influence score is obtained by calculating the Granger causality statistic based on the vector autoregression model. The symbolic consistency coefficient is calculated based on the direction of change of user power and the direction of change of line loss rate within the key time window, and the influence score and the symbolic consistency coefficient are combined to obtain the suspected strength of line loss contribution. The dynamic weights are determined based on the analytic hierarchy process (AHP), and the normalized instantaneous behavior deviation and the suspected strength of line loss contribution are weighted and fused based on the dynamic weights to obtain the comprehensive suspicion index.

9. The method for locating electricity theft users based on a smart grid line toolbox according to claim 1, characterized in that, The process of reporting the geographical location during the low-power reporting phase according to a preset time period and intermittently reporting the data packets to be reported, generating anti-tampering verification codes for the data packets to be reported, and generating a power failure event analysis report and uploading it to the main station after the main power is restored includes: Extract a preset number of suspect entries from the suspect priority sorting list to generate a suspect list summary, and combine the suspect list summary with the device unique identifier and the power failure timestamp to obtain summary data; The summary data and the geographical location are symmetrically encrypted to obtain ciphertext data, and the ciphertext data is used as the data packet to be reported. A message authentication code is generated based on the data packet to be reported as an anti-tampering verification code, and the anti-tampering verification code is intermittently reported together with the data packet to be reported. It enters a deep sleep state between adjacent intermittent reporting and monitors the status of the backup battery during the low power reporting phase. If the status of the backup battery meets the alarm conditions, it reports the corresponding alarm flag. After the main power is restored, a power outage event analysis report is generated and uploaded to the main station. The power outage event analysis report includes at least the determination result of the unplanned destructive power outage, the snapshot of the line electrical parameters, the comprehensive suspected index and the priority ranking list of suspected users, and the low power consumption reporting log.

10. A user location system for electricity theft based on a smart grid line toolbox, characterized in that, The system includes: The line loss acquisition module is used to collect the electrical parameters and power data of the branch lines installed in the line toolbox, generate a line loss rate benchmark curve, and determine the real-time fluctuation characteristics based on the line loss rate benchmark curve. The power failure detection module is used to determine whether an unplanned destructive power failure has occurred based on the real-time fluctuation characteristics and the original waveform of the load current before the power failure when a main power failure is detected, and to record the corresponding power failure timestamp. The collaborative positioning module is used to activate the backup battery to enter the anti-theft collaborative positioning mode when it is determined that the unplanned destructive power outage has occurred, report the geographical location of the line toolbox, and obtain a snapshot of the line electrical parameters and associated user load data within a key time window; The suspicion calculation module is used to calculate the instantaneous behavior deviation and the suspected strength of line loss contribution based on the line electrical parameter snapshot and the associated user load data in the anti-theft collaborative positioning mode, and to generate a comprehensive suspicion index by weighted fusion of the instantaneous behavior deviation and the suspected strength of line loss contribution. The sorting and binding module is used to generate a priority sorting list of suspect households based on the comprehensive suspicion index, and to encrypt and bind the priority sorting list of suspect households with the geographical location and the power outage timestamp to obtain the data packet to be reported. The low-power reporting module is used to generate an anti-tampering verification code for the data packet to be reported, report the geographical location during the low-power reporting phase according to a preset time period, and intermittently report the data packet to be reported and the corresponding anti-tampering verification code. After the main power is restored, it generates a power failure event analysis report and uploads it to the main station.