Loading control system with multi-stage safety protection

The loading control system, with its multi-level safety protection, integrates data acquisition, digital twin synchronization, and intelligent decision-making, solving the problems of single-point failure and response delay in traditional systems and achieving comprehensive safety protection for structural tests.

CN121978990APending Publication Date: 2026-05-05BEIJING QTCREATE TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING QTCREATE TECH
Filing Date
2025-12-10
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

Traditional loading control systems fail when the central processing unit malfunctions, leading to a break in the safety protection logic and an inability to respond to emergencies in a timely manner, resulting in single-point failure risk and response delay issues.

Method used

The load control system, which employs multi-level security protection, includes a data acquisition and fusion unit, a digital twin synchronization unit, an intelligent decision-making unit, and a security execution and arbitration unit. Through distributed sensor networks, virtual model comparison, and intelligent decision generation, it ensures the independence and rapid response of hardware-level protection.

Benefits of technology

It enables rapid emergency protection in the event of software-level failures or delays, avoids system failures, provides comprehensive and highly reliable safety protection, and ensures the safety and stability of the testing process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121978990A_ABST
    Figure CN121978990A_ABST
Patent Text Reader

Abstract

The invention provides a loading control system with multi-level security protection, and a security control system with multi-level protection is constructed through a co-processing architecture integrating data acquisition and fusion, digital twin synchronization, intelligent decision and independent hardware security arbitration. According to the method, intelligent risk assessment and pre-judgment strategy generation can be performed based on multi-source data fusion and virtual model comparison, and a hardware-level security execution loop which directly monitors an original signal and is independent of main decision-making software is set, so that under the condition of any software layer fault or delay, the safety of the decision-making software is ensured to be improved. And the rapid emergency protection with the highest priority can be triggered when the structure test loading process is finished, so that the problems of single-point failure risk and response delay of the traditional centralized safety control system are fundamentally solved, and the omnibearing and high-reliability safety protection of the structure test loading process is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of structural engineering testing technology, and in particular to a loading control system with multi-level safety protection. Background Technology

[0002] Structural loading tests are a crucial means of evaluating the mechanical properties of large structures or components, such as civil engineering buildings and mechanical equipment. By applying static or dynamic loads simulating real-world working conditions to specimens, the entire process of stress, deformation, and eventual failure is observed. As test objects become increasingly complex and loading scales continue to expand, the safety control of the testing process becomes paramount.

[0003] Traditional load safety control systems often employ a centralized monitoring architecture based on a central processing unit (CPU). Their safety protection logic heavily relies on this single main control software to judge and make decisions based on the collected and processed status data. This architecture has a fundamental flaw: when the CPU fails due to software malfunctions, computational overload, or communication interruptions, the entire safety protection chain breaks, and the system loses its ability to respond to emergencies. Furthermore, there is an unavoidable time delay in the process from sensor signal acquisition and software algorithm processing to the final command issuance. Under extreme conditions of rapid uncontrolled load or deformation, this delay can lead to delayed protective actions, preventing timely intervention at the most critical moment, thereby causing sudden specimen failure, damage to the loading equipment, or even a safety accident. Summary of the Invention

[0004] In view of this, the present invention provides a loading control system with multi-level safety protection to solve the technical defects existing in the prior art.

[0005] Specifically, the present invention provides a loading control system with multi-level safety protection, comprising: The data acquisition and fusion unit is used to acquire, align and fuse the state signals of each loading actuator in the physical loading system to generate a multi-channel state vector that includes the load, the displacement measured by the displacement sensor and the instantaneous following error signal generated by the control feedback. The digital twin synchronization unit is used to receive multi-channel state vectors and drive a high-fidelity virtual model to calculate the real-time synchronization deviation between key monitoring points of the physical entity and corresponding points of the virtual model. The intelligent decision-making unit is used to perform multi-scale risk assessment based on multi-channel state vectors and real-time synchronization deviations, through preset rules and prediction models, and generate response strategies that include strategy types. The safety execution and arbitration unit is used to parse response strategies and generate coordinated control commands, while directly monitoring raw signals to execute hardware-level protection with the highest priority. The safety execution and arbitration unit includes an adaptive controller to adjust actuator control parameters. The safety execution and arbitration unit also includes a safety state management module, which is used to put the system into a safety lock state after triggering hardware-level protection, and can only be reset after authorized manual confirmation. The human-computer interaction and recording unit is used to provide a 3D visualization interface, parameter configuration interface, and record all system operation events.

[0006] In some implementations, the data acquisition and fusion unit includes a distributed sensor network and a real-time fusion processor; the distributed sensor network includes a strain sensor for measuring load, a grating ruler for measuring global displacement, and a dual-redundant magnetostrictive displacement sensor as one of the displacement sensors for acquiring the position of the actuator piston rod; the real-time fusion processor fuses multi-source signals based on Kalman filtering and dynamic time warping algorithms.

[0007] In some implementations, the high-fidelity virtual model includes a parametric geometric model and a real-time finite element simulation kernel; the digital twin synchronization unit performs spatial pose calibration using pre-scanned installation point cloud data and outputs the real-time synchronization deviation of each key monitoring point, which is the Euclidean distance between the physical point and the virtual point.

[0008] In some implementations, the intelligent decision-making unit includes a configurable multi-level rule base and a prediction engine based on a long short-term memory network; the types of response strategies include flexible adjustment, gradient unloading, and emergency braking; the intelligent decision-making unit triggers strategy generation by calculating a global comprehensive risk index; the configurable multi-level rule base stores protection thresholds for load, following error, and synchronization deviation.

[0009] In some implementations, the intelligent decision-making unit calculates the global comprehensive risk index through the following steps: The system acquires real-time load measurements, real-time tracking error assessments, and real-time synchronization deviation absolute values ​​from the monitoring nodes in parallel. It then performs benchmarking processing on each type of real-time data and its corresponding preset safety threshold value to generate a set of dimensionless relative deviation data. Nonlinear intensity mapping is performed on the load relative deviation data, the tracking error assessment value relative deviation data, and the synchronization deviation relative deviation data to obtain the load risk intensity, tracking risk intensity, and deviation risk intensity, respectively. The load risk intensity and tracking risk intensity of each channel are assigned first-class weights and aggregated within the channel to obtain the channel execution risk index; the deviation risk intensity of each monitoring node is introduced with a time risk factor and assigned second-class weights and then aggregated within the node to obtain the node model risk index; using a preset category balance coefficient, the statistical mean of the execution risk index of all channels and the statistical mean of the risk index of all node models are fused across categories to generate the median value of the global comprehensive risk index. The intermediate value of the global comprehensive risk index is normalized to output the final global comprehensive risk index.

[0010] In some implementations, the real-time tracking error assessment value is obtained through the following steps: The command position signal and actual feedback position signal of the loading actuator are acquired in real time, and the instantaneous following error signal is calculated; an evaluation time window related to the loading frequency is defined. Within the evaluation time window, a first feature characterizing its average energy, a second feature characterizing its extreme amplitude, and a third feature characterizing its fluctuation stability are extracted from the instantaneous follow error signal. The first feature, the second feature, and the third feature are fused according to a preset contribution ratio to generate a real-time tracking error evaluation value.

[0011] In some implementations, the time risk factor is obtained through the following steps: For the absolute value of the real-time synchronization deviation generated by the specified monitoring node, calculate its trend average level within the sliding time window.

[0012] By comparing the trend average level with the preset tolerance threshold value of the node, a benchmarked recent deviation level index is obtained.

[0013] A nonlinear saturation mapping is performed on the recent deviation level index to generate a time risk factor that is not less than the benchmark value. This factor is used to characterize the statistical severity of the recent model synchronization deviation at this node.

[0014] In some implementations, the safety execution and arbitration unit includes a policy parser, an adaptive controller, an independent safety logic processor, and a safety state management module; the policy parser converts the response policy into a sequence of control instructions with timing logic; the adaptive controller receives instantaneous follow-up error signals to perform calculations and output control quantities; the independent safety logic processor directly receives raw signals from the data acquisition and fusion unit, and when a hard protection threshold or emergency stop signal is triggered, it bypasses the intelligent decision-making unit and directly starts the emergency unloading loop.

[0015] In some implementations, the emergency unloading circuit includes a supercapacitor energy storage module and a mechanical locking mechanism; when the emergency unloading is triggered, the supercapacitor energy storage module provides independent power to drive all loading actuators to return to the mechanical zero point according to a preset exponential decay rate curve, and then the mechanical locking mechanism fixes the actuator piston rod.

[0016] In some implementations, the 3D visualization interface is based on a high-fidelity virtual model rendered by the WebGL engine, and the stress field cloud map is overlaid and displayed in a color mapping manner. The stress field cloud map is calculated by a real-time finite element simulation kernel. The parameter configuration interface supports modifying the protection threshold value through voice commands. The modification operation is authenticated through preset multiple permissions and a decision is made on whether to pass.

[0017] At least one embodiment of this invention constructs a multi-layered safety control system through a collaborative processing architecture integrating data acquisition and fusion, digital twin synchronization, intelligent decision-making, and independent hardware security arbitration. This system not only enables intelligent risk assessment and predictive strategy generation based on multi-source data fusion and virtual model comparison, but also ensures that a hardware-level safety execution loop, independent of the main decision-making software and directly monitoring the original signals, triggers the highest-priority rapid emergency protection in the event of any software-level failure or delay. This fundamentally overcomes the single-point failure risk and response delay problems of traditional centralized safety control systems, achieving comprehensive and highly reliable safety protection during structural testing and loading processes. Attached Figure Description

[0018] Figure 1 This is a structural block diagram of a loading control system with multi-level safety protection provided by the present invention. Detailed Implementation

[0019] Many specific details are set forth in the following description to provide a full understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar extensions without departing from the spirit of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.

[0020] The terminology used in one or more embodiments of this specification is for the purpose of describing particular embodiments only and is not intended to limit the scope of the one or more embodiments of this specification. The singular forms “a” and “the” as used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items. The modifications “a” and “a plurality” as used in this disclosure are illustrative and not restrictive, and those skilled in the art will understand that they should be understood as “one or more” unless the context clearly indicates otherwise.

[0021] It should be understood that although the terms first, second, etc., may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first may also be referred to as second without departing from the scope of one or more embodiments of this specification, and similarly, second may also be referred to as first. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."

[0022] See Figure 1 , Figure 1 This diagram illustrates a structural block diagram of a loading control system with multi-level safety protection according to some embodiments of this specification. The loading control system includes: a data acquisition and fusion unit for acquiring, aligning, and fusing state signals from each loading actuator in the physical loading system to generate a multi-channel state vector containing load, displacement measured by a displacement sensor, and instantaneous following error signal generated by control feedback; a digital twin synchronization unit for receiving the multi-channel state vector and driving a high-fidelity virtual model to calculate the real-time synchronization deviation between key monitoring points of the physical entity and corresponding points of the virtual model; and an intelligent decision-making unit for making decisions based on the multi-channel state vector and the real-time synchronization error signal generated by the physical entity and the virtual model. The system addresses time synchronization deviation by performing multi-scale risk assessments using pre-defined rules and prediction models, and generating response strategies that include strategy types. A safety execution and arbitration unit parses these strategies and generates coordinated control commands, while simultaneously monitoring raw signals to execute the highest-priority hardware-level protection. This unit includes an adaptive controller to adjust actuator control parameters. The safety execution and arbitration unit also includes a safety state management module, which places the system into a safety lock state after hardware-level protection is triggered, requiring authorized manual confirmation before resetting. Finally, a human-machine interaction and recording unit provides a 3D visualization interface, parameter configuration interface, and records all system operation events.

[0023] A data acquisition and fusion unit can refer to hardware and software components responsible for acquiring and fusing multi-source state signals. This could involve using distributed sensor networks and real-time fusion processors, applying algorithms such as Kalman filtering to generate accurate multi-channel state vectors, providing a data foundation for subsequent processing. A physical loading system can refer to the collection of hardware devices that actually load the structure, such as hydraulic or electric actuators and support structures, capable of applying controllable loads to the test structure. A loading actuator can refer to a single drive in the physical loading system that performs the loading action, such as a hydraulic cylinder or servo motor, receiving control commands and outputting force and displacement to directly apply mechanical loads to the test structure. State signals can refer to physical quantity electrical signals reflecting the operating state of the loading actuator. For example, sensors convert physical quantities such as load and displacement into analog or digital signals to monitor the actuator's behavior in real time. Load can refer to the force or torque applied to the test structure by the loading actuator. For example, it can be measured by strain sensors and converted into a voltage signal, quantifying the applied force, which is a key parameter for safety assessment. Displacement sensors can refer to devices that measure the displacement of an actuator piston rod or structure, such as optical encoders or magnetostrictive displacement sensors. They output position feedback signals to provide accurate position information for control feedback. Displacement can refer to the change in position of a measuring point on the actuator piston rod or test structure, such as that measured in real time by a displacement sensor, to assess structural deformation and actuator tracking accuracy. Control feedback refers to the feedback loop in a control system, used to compare commands and actual outputs. For example, by comparing the commanded position and the sensor feedback position, an error signal is generated for closed-loop control to ensure the actuator accurately tracks the command. Instantaneous tracking error signal refers to the real-time difference signal between the commanded position and the actual position in control feedback. For example, it is calculated by the controller's comparison unit and is usually a voltage or digital signal, reflecting the actuator's instantaneous tracking performance. Multi-channel state vectors can refer to a data structure composed of multiple state signals, with each channel corresponding to an actuator or measuring point. For example, a data acquisition unit aligns load, displacement, and error signals and encapsulates them into a vector for unified transmission and processing of multi-source state information.

[0024] A digital twin synchronization unit can refer to a software module that synchronizes a physical entity with a virtual model. For example, it might receive state vectors to drive a finite element model, calculate synchronization deviations, and provide combined virtual-real monitoring and early warning capabilities. A high-fidelity virtual model can refer to a computer model that accurately reflects the characteristics of a physical system. For example, it might be built based on parametric geometry and real-time finite element simulation, including material properties and boundary conditions, and simulate the behavior of the physical system for prediction and comparison. Key monitoring points of the physical entity can refer to selected locations on the physical loading system for focused monitoring. These can be determined through pre-scanning or design drawings, and sensors are installed to measure and obtain response data from the actual structure. Corresponding points in the virtual model can refer to the locations in the high-fidelity virtual model that correspond to the physical monitoring points. For example, spatial coordinate mapping ensures geometric consistency for direct comparison of virtual and real data. Real-time synchronization deviation can refer to the real-time difference between the positions of the physical monitoring point and its virtual counterpart. For example, it might calculate the Euclidean distance between the two points and update it over time to evaluate the synchronization accuracy and structural anomalies of the digital twin.

[0025] Intelligent decision-making units can refer to software modules that perform risk assessment and strategy generation based on data and models. For example, they can integrate rule bases and LSTM prediction engines to calculate risk indices and automatically generate response strategies to improve system security. Pre-defined rules can refer to a set of pre-set logical conditions used for risk judgment, such as those stored in a configurable rule base, including threshold values ​​for load and error, used to quickly trigger predefined safety responses. Predictive models can refer to machine learning or mathematical models used to predict the future state of a system. For example, models trained on Long Short-Term Memory (LSTM) networks can take historical data as input and output predictions to identify potential risks in advance and achieve preventative safety control. Multi-scale risk assessment can refer to the process of assessing system risks from different time or spatial scales. For example, combining instantaneous errors, short-term trends, and long-term statistics for comprehensive assessment can comprehensively capture system risks and avoid missed or false alarms. Strategy types can refer to the classification of response strategies, such as flexible adjustment, gradient unloading, and emergency braking. For example, in intelligent decision-making units, the appropriate type can be selected based on the risk level, enabling differentiated measures to be taken for different risk levels. A response strategy can refer to a set of specific control or protection instructions generated to address risks. These may include sequences of actions such as adjusting control parameters, changing loading rates, or triggering protection, to guide the safety execution unit to take action and mitigate risks.

[0026] The safety execution and arbitration unit can refer to the component responsible for executing strategies and monitoring raw signals to implement hardware protection. This could include a strategy resolver, adaptive controller, and independent safety logic processor, coordinating hardware and software responses to ensure the highest priority protection takes effect. Coordinated control commands can refer to a sequence of control commands that coordinate the actions of multiple actuators. For example, these commands are generated by the strategy resolver based on the response strategy and sent to each actuator controller to achieve coordinated loading or unloading of multiple actuators. Raw signals can refer to unprocessed electrical signals directly acquired from sensors, such as the analog voltage output of a strain gauge sensor or the pulse signal of a displacement sensor. These can be used for direct triggering of hardware-level protection, avoiding processing delays. Highest priority hardware-level protection can refer to emergency protection mechanisms that directly act on hardware circuits or independent processors. For example, an independent safety logic processor monitors raw signals and immediately cuts off power or triggers mechanical lockout upon exceeding limits, ensuring system safety and providing the fastest response in the event of software failure. An adaptive controller can refer to a controller that automatically adjusts control parameters according to the system state. For example, it can adjust PID (proportional-integral-derivative) parameters online based on instantaneous tracking error signals to improve tracking performance and reduce error accumulation. Actuator control parameters refer to parameters that control the behavior of the loaded actuator, such as gain and integral time. For example, in an adaptive controller, these parameters are dynamically adjusted based on errors and take effect through a control algorithm, optimizing actuator response and improving control accuracy. A safety status management module refers to software or hardware modules that manage the safety status of the system. For example, after hardware protection is triggered, the system is placed in a locked state and the event is recorded to prevent accidental operation and ensure manual confirmation is required for recovery after a safety incident. A safety lockout state refers to a state where automatic operation is prohibited after hardware protection is triggered. For example, the control output is disconnected, the actuator position is fixed, and only authorized resets are allowed to force a shutdown and prevent the danger from continuing. Authorized manual confirmation commands refer to reset or continue commands issued by authorized operators, such as those triggered on the HMI (Human Machine Interface) after password, biometric identification, or multi-factor authentication, to ensure that a manual safety check is performed before system recovery.

[0027] The human-computer interaction and recording unit can refer to hardware and software components that provide an operating interface and event logging functions. For example, it could be a 3D interface rendered using a WebGL engine, providing configuration interfaces and database records for operator monitoring, system configuration, and post-event analysis. The parameter configuration interface can refer to an input interface that allows users to modify system parameters (such as protection thresholds). This could include graphical sliders, input boxes, or natural language voice command parsing functions for customized safety strategies to adapt to different testing needs. System-wide operational events can refer to all important state changes and operation records that occur during system operation, such as those recorded in a timestampd log database. These events include data acquisition, decision-making, and protection triggering events to support fault diagnosis, performance analysis, and compliance auditing.

[0028] As a concrete example: In fatigue testing of bridge components, the physical loading system comprises four hydraulic actuators applying cyclic loads to the specimen. The data acquisition and fusion unit, through a distributed sensor network, collects the load, displacement, and instantaneous following error signals of each actuator at a sampling rate of 1000 times per second. After Kalman filtering and fusion, a multi-channel state vector with 12 components is generated. The digital twin synchronization unit receives this vector and drives a high-fidelity virtual model built based on parametric geometry and a real-time finite element simulation kernel to calculate the real-time synchronization deviation at four key monitoring points. The intelligent decision-making unit, based on the state vector and synchronization deviation, performs multi-scale risk assessment using preset rules and a long short-term memory network prediction model. When the risk exceeds the limit, it generates a response strategy including gradient unloading. The safety execution and arbitration unit parses the strategy and generates coordinated control commands. Simultaneously, its independent safety logic processor directly monitors the original strain signals, immediately triggering hardware-level protection once the load exceeds the hardware threshold. The adaptive controller adjusts the actuator control parameters according to the instantaneous following error. After triggering protection, the safety status management module puts the system into a safety lock state, which requires a manual confirmation command from an authorized engineer through multiple authentications on the 3D visualization interface to be reset. The human-computer interaction and recording unit renders stress field cloud maps using the WebGL engine and records all system operation events.

[0029] The beneficial effects of one of the embodiments in this specification include at least the following: By integrating a collaborative processing architecture that combines data acquisition and fusion, digital twin synchronization, intelligent decision-making, and independent hardware security arbitration, this invention constructs a multi-layered security control system. It not only enables intelligent risk assessment and predictive strategy generation based on multi-source data fusion and virtual model comparison, but also ensures that, by establishing a hardware-level security execution loop that directly monitors the original signals and is independent of the main decision-making software, the highest priority rapid emergency protection can be triggered in the event of any software-level failure or delay. This fundamentally overcomes the single-point failure risk and response delay problems of traditional centralized security control systems, achieving comprehensive and highly reliable safety protection during structural testing and loading.

[0030] In some implementations, the data acquisition and fusion unit includes a distributed sensor network and a real-time fusion processor; the distributed sensor network includes a strain sensor for measuring load, a grating ruler for measuring global displacement, and a dual-redundant magnetostrictive displacement sensor as one of the displacement sensors for acquiring the position of the actuator piston rod; the real-time fusion processor fuses multi-source signals based on Kalman filtering and dynamic time warping algorithms.

[0031] Distributed sensor networks refer to hardware networks composed of multiple sensor nodes used for collaborative data acquisition. For example, connecting strain sensors, linear encoders, and displacement sensors via fieldbus or Ethernet allows for the synchronous acquisition of state data from various points in a physical loading system, providing comprehensive and synchronized sensing information. Real-time fusion processors are dedicated computing units that perform real-time alignment and fusion processing of multi-source sensor data. These can be achieved using FPGAs (Field-Programmable Gate Arrays) or high-performance embedded systems, running specific fusion algorithms to generate consistent state vectors within millisecond delays. Strain sensors indirectly calculate loads by measuring material strain. For example, using resistance strain gauges to form a Wheatstone bridge, attached to an actuator force sensor or structure, its output voltage is proportional to the strain, converting mechanical strain into a measurable electrical signal to obtain the load value. Global displacement refers to the absolute displacement of the test structure in the global coordinate system or the displacement of a specific measuring point relative to a fixed reference. For example, using a long-distance linear encoder to measure the movement of a specific point on a loading frame or specimen reflects the overall rigid body displacement or large deformation of the structure, used to assess the overall motion state of the structure. A grating ruler can refer to a high-precision sensor that measures linear displacement based on the principle of grating interference. For example, it consists of a scale grating and a reading head, outputting a pulse signal proportional to the displacement. It can measure long-stroke linear displacement with micron-level accuracy, providing a reference measurement for global displacement. The actuator piston rod position can refer to the extension or retraction of the piston rod used to output force in a hydraulic or electro-actuated actuator. This can be obtained, for example, by measuring the position of the magnetic ring inside the rod using a magnetostrictive displacement sensor. It is the most direct position feedback for the actuator, used to precisely control the actuator's stroke and positioning.

[0032] Dual-redundant magnetostrictive displacement sensors refer to displacement sensors that employ the magnetostrictive principle and have two independent measurement circuits to improve reliability. For example, strain pulses are generated within the waveguide rod, and the magnetic ring position signal is processed by two independent electronic chambers, outputting two channels of position data. Cross-validation ensures high reliability and fault tolerance in displacement measurement. Dynamic time warping (DTW) algorithms are used to align time series of different lengths or rates. For instance, in a fusion processor, nonlinear time alignment is performed on sensor data from different sampling times to compensate for timing differences caused by sampling delays or clock asynchrony between sensors, ensuring consistency of multi-source signals on the time axis. Multi-source signals refer to raw electrical signals from different types or positions of sensors, such as analog voltage signals (strain), pulse signals (grating rulers), and digital signals (displacement sensors). These signals differ in amplitude, frequency, and timing, and are the objects of fusion processing. After alignment and fusion, a unified decision-making basis is formed.

[0033] As a concrete example: In a seismic test of a wall panel under coordinated multi-actuator loading, the data acquisition and fusion unit is responsible for integrating all sensor information. Its distributed sensor network includes: strain sensors attached to the actuator hinges to measure the applied axial load; a high-precision grating ruler mounted on the reaction wall to measure the global horizontal displacement at the top of the specimen; and dual-redundant magnetostrictive displacement sensors integrated within each actuator to accurately acquire the real-time position of the actuator piston rod. These sensor signals are transmitted to a real-time fusion processor via an Ethernet / CAT (Controller Area Network) bus. This processor, based on an extended Kalman filter algorithm, performs noise filtering and state estimation on the load and displacement signals; simultaneously, it employs a dynamic time warping algorithm to align the timing of data asynchrony caused by minor differences in physical wiring and sampling clocks between sensors. Finally, the processor outputs a multi-channel state vector with strictly aligned timestamps and higher data quality for use by the subsequent digital twin synchronization unit and intelligent decision-making unit.

[0034] By employing a distributed sensor network that includes strain sensors, grating rulers, and dual redundant magnetostrictive displacement sensors, comprehensive and reliable acquisition of multi-dimensional physical quantities such as load, global displacement, and actuator position is achieved. Through a real-time fusion processor based on Kalman filtering and dynamic time warping algorithms, the accuracy, synchronization, and consistency of multi-source heterogeneous sensor data are effectively improved, providing a high-quality data foundation for upper-level security decisions.

[0035] In some implementations, the high-fidelity virtual model includes a parametric geometric model and a real-time finite element simulation kernel; the digital twin synchronization unit performs spatial pose calibration using pre-scanned installation point cloud data and outputs the real-time synchronization deviation of each key monitoring point, which is the Euclidean distance between the physical point and the virtual point.

[0036] Parametric geometric models refer to computer models whose geometry can be altered by adjusting parameters. For example, they are defined in CAD software, where dimensions and constraints are driven by parameters. The model geometry is automatically updated when new parameter values ​​are input, allowing for the rapid construction and modification of virtual model geometry to adapt to different experimental structures. Real-time finite element simulation kernels refer to core solvers capable of real-time structural finite element analysis, such as those developed based on explicit integration algorithms and sparse matrix solvers. These solvers can complete stress, strain, and displacement field calculations within milliseconds, providing real-time structural mechanical response predictions for digital twins. Pre-scanned installation point cloud data refers to a set of points describing the spatial positions of physical entity surfaces, acquired through a 3D laser scanner. For example, scanning the loading frame and specimen installation area before the experiment generates a point cloud file containing millions of 3D coordinate points, providing a high-precision physical spatial reference for digital twins and achieving initial alignment between virtual and physical models. Spatial pose calibration refers to the process of adjusting a virtual model to align its position and orientation with that of a physical entity in space. For example, iterative closest point (ICP) algorithms can be used to match point cloud data with the surface of the virtual model, solving for the optimal rotation and translation matrices to ensure consistency between the spatial coordinate systems of the virtual model and the physical entity in a digital twin, thus reducing initial registration errors. Key monitoring points refer to locations jointly defined on both the physical entity and the virtual model for focused comparison and monitoring. These points are selected based on structural mechanical properties or sensor placement schemes, marking corresponding nodes in the virtual model and attaching targets or installing sensors on the physical entity. These serve as reference locations for calculating real-time synchronization deviations, focusing monitoring resources. Physical points refer to actual spatial locations at key monitoring points on the physical entity, such as three-dimensional coordinates measured by a laser tracker or photogrammetry system. These represent the real physical location and are used for comparison with virtual points, serving as one of the benchmarks for calculating synchronization deviations. A virtual point can refer to a spatial location point in a high-fidelity virtual model that corresponds to a physical point. For example, it can be defined using node coordinates in a parametric geometric model or finite element mesh nodes, representing the corresponding position in the virtual world. It is used for comparison with the physical point and serves as another benchmark for calculating synchronization deviation. Euclidean distance can refer to the straight-line distance between two points in three-dimensional space. For example, based on the three-dimensional coordinates of a physical point and a virtual point, it is used to quantify the real-time positional deviation between the physical entity and the virtual model at a specific monitoring point, providing an intuitive measure of spatial error.

[0037] As a concrete example: Before conducting a loading test on a node of a large spatial reticulated shell structure, operators used a 3D laser scanner to scan the installed specimen and loading fixture, obtaining high-precision pre-scanned installation point cloud data. The digital twin synchronous unit loaded a parametric geometric model derived from the BIM model and launched a real-time finite element simulation kernel. The unit invoked an iterative nearest-point algorithm to match the point cloud data with the virtual model, completing spatial pose calibration and ensuring precise alignment between the virtual coordinate system and the physical world. After the test began, the unit continuously received multi-channel state vectors from the data acquisition and fusion unit, driving the virtual model to perform real-time mechanical simulation at 100 steps per second. At six pre-set key monitoring points on the specimen, the unit synchronously acquired the physical point coordinates measured in real-time by a total station and read the corresponding virtual point coordinates from the virtual model. For each pair of points, the unit calculated their Euclidean distance as the real-time synchronization deviation for that point and continuously output it. When the deviation value of a certain monitoring point continued to increase, it provided the intelligent decision-making unit with an important early warning signal that the structural response might mismatch with the prediction model.

[0038] By constructing a high-fidelity virtual model that includes a parametric geometric model and a real-time finite element simulation kernel, real-time, high-precision digital mapping and mechanical simulation of the physical experiment process were achieved. Spatial pose calibration based on pre-scanned point cloud data ensured a high degree of consistency between the digital twin and the initial state of the physical entity. By calculating the Euclidean distance between the physical point and the virtual point at key monitoring points as the synchronization deviation, an intuitive and quantitative measure of virtual-real consistency was provided for the system, which is a key basis for early detection of structural anomalies or model errors.

[0039] In some implementations, the intelligent decision-making unit includes a configurable multi-level rule base and a prediction engine based on a long short-term memory network; the types of response strategies include flexible adjustment, gradient unloading, and emergency braking; the intelligent decision-making unit triggers strategy generation by calculating a global comprehensive risk index; the configurable multi-level rule base stores protection thresholds for load, following error, and synchronization deviation.

[0040] A configurable multi-level rule base can refer to a database that allows users to customize and organize logical judgment conditions at different levels (such as system-level, channel-level, and monitoring point-level). For example, it can be stored in a hierarchical XML or JSON format, containing parameters such as load thresholds, error thresholds, and deviation tolerances, along with their logical relationships, to provide flexible and structured judgment criteria for intelligent decision-making. A prediction engine can refer to the core software module that performs prediction model calculations. For example, it can be built based on a long short-term memory network, loading pre-trained model weights, inputting historical state sequences, and outputting risk probabilities or state predictions for multiple future steps, to achieve proactive risk perception and early warning. Flexible adjustment can refer to a type of response strategy that mitigates system states by fine-tuning control parameters. For example, when the risk is low, the intelligent decision-making unit instructs the adaptive controller to slightly reduce the proportional gain or introduce feedforward compensation to smooth the loading process and avoid abrupt changes. Gradient unloading can refer to a type of response strategy that reduces load in stages at a predetermined rate. For example, when the risk increases, the intelligent decision-making unit generates instructions requiring actuators to reduce the load to a safe level in multiple steps according to an exponential or linear curve, to orderly release structural stress and prevent shocks caused by sudden unloading. Emergency braking can refer to a response strategy that immediately terminates loading and activates the highest level of protection. For example, when the risk index exceeds the highest threshold, the intelligent decision-making unit directly triggers hardware-level protection commands, cutting off power and initiating mechanical locking to ensure system safety as quickly as possible in critical situations. The global comprehensive risk index can refer to a single numerical indicator that quantifies the overall risk level of the system. For example, it is calculated by the intelligent decision-making unit through multi-source data fusion and weighting, and its value continuously varies between 0 and 1 or a wider range, serving as a unified quantitative basis for triggering different levels of response strategies. Protection thresholds can refer to threshold parameters set in the software logic to trigger protection actions. For example, they are stored in a configurable multi-level rule base, including specific values ​​such as load limits, error limits, and synchronization tolerances. When real-time data exceeds these thresholds, the software will activate the corresponding protection strategy.

[0041] As a concrete example: In a quasi-static loading test of a cable-stayed bridge tower segment model, the intelligent decision-making unit operates continuously. Its configurable multi-level rule base sets different levels of protection thresholds: the system-level threshold is a total loading force not exceeding 5000kN; each channel-level threshold is set according to the actuator capacity; the following error threshold is 0.5mm; and the synchronization deviation tolerance is 2.0mm. Simultaneously, its prediction engine, based on a long short-term memory network, takes the multi-channel state vector sequence of the past 10 seconds as input and predicts the load and error trends for the next 2 seconds. When the system's calculated global comprehensive risk index R exceeds 0.7 due to the continuous increase in the following error assessment value of a certain actuator, the unit first generates a "flexible adjustment" type of response strategy, attempting to suppress the error by adjusting the controller parameters. If the index continues to rise to 0.85, it upgrades to a "gradient unloading" strategy, instructing the channel to unload at a rate of 5% reduction in maximum load per second. If the index suddenly jumps to 1.0 (for example, due to the prediction of instability), an "emergency braking" strategy is immediately generated, ordering the safety execution and arbitration unit to perform the highest priority protection.

[0042] By integrating a configurable multi-level rule base with a prediction engine based on long short-term memory networks, the system can respond quickly according to preset rules and make advance judgments on risks using prediction models. By defining different types of response strategies such as flexible adjustment, gradient unloading, and emergency braking, and linking them with the global comprehensive risk index, the system achieves refined and gradual handling of risks of different degrees, thereby improving the accuracy and robustness of safety control.

[0043] In some implementations, the intelligent decision-making unit calculates the global comprehensive risk index through the following steps: acquiring in parallel real-time load measurements, real-time follow-up error assessments, and the absolute values ​​of real-time synchronization deviations from monitoring nodes; benchmarking each type of real-time data against its corresponding preset safety threshold to generate a set of dimensionless relative deviation data; performing nonlinear intensity mapping on the load relative deviation data, follow-up error assessment relative deviation data, and synchronization deviation relative deviation data to obtain load risk intensity, tracking risk intensity, and deviation risk intensity, respectively; assigning first-class weights to the load risk intensity and tracking risk intensity of each channel and performing intra-channel aggregation to obtain channel execution risk indicators; introducing a time risk factor into the deviation risk intensity of each monitoring node and assigning second-class weights before intra-node aggregation to obtain node model risk indicators; using a preset category balance coefficient, performing cross-category fusion of the statistical mean of all channel execution risk indicators and the statistical mean of all node model risk indicators to generate an intermediate value of the global comprehensive risk index; and normalizing the intermediate value of the global comprehensive risk index to output the final global comprehensive risk index.

[0044] Real-time load measurements refer to the numerical values ​​of force or torque applied by the actuator, acquired in real time by sensors. For example, force values ​​measured by strain sensors and converted by a data acquisition unit are expressed in kN and serve as direct input for calculating load risk intensity, reflecting the current mechanical strength of the load. Real-time tracking error assessment values ​​refer to a quantified value that comprehensively reflects the accuracy of the actuator's tracking command, characterizing the transient and steady-state tracking performance of the control system. A larger value indicates poorer tracking performance. Real-time synchronization deviation absolute values ​​refer to the absolute value of the Euclidean distance between the physical monitoring point and its virtual counterpart, i.e., the magnitude without direction. For example, a scalar value that is always positive, calculated and output by the digital twin synchronization unit, used to quantify the degree of mismatch in the digital twin model at that point, ignoring the direction of the deviation. Monitoring nodes refer to locations structurally selected as key monitoring points, which have corresponding virtual points in the digital twin system. For example, sensors or optical markers are installed in stress concentration areas or displacement-sensitive points of the specimen, serving as specific location units for calculating and evaluating synchronization deviation. Preset safety thresholds refer to threshold parameters set in advance for various types of data to determine whether they are safe. These values ​​are stored in a rule base and serve as the denominator in benchmarking processes, used to standardize real-time data to a uniform scale. Dimensionless relative deviation data refers to unitless ratio data obtained by dividing real-time data by its safety threshold. It is used to eliminate the influence of dimensions and intuitively represent how close the current value is to the safety limit.

[0045] Nonlinear intensity mapping refers to the process of converting input values ​​into output intensity using nonlinear mathematical functions. For example, taking the cube of the relative deviation data causes the output intensity to increase sharply when the input value slightly exceeds the limit, emphasizing the rapid growth of risk represented by data exceeding the safety threshold. Load risk intensity refers to a quantitative value reflecting the magnitude of risk brought about by the current load level. Its value increases rapidly as the load approaches or exceeds the threshold, highlighting the danger of high load conditions in risk assessment. Tracking risk intensity refers to a quantitative value reflecting the magnitude of risk brought about by the current tracking error. Its value increases rapidly as tracking accuracy deteriorates, emphasizing the risk of control instability in risk assessment. Deviation risk intensity refers to a quantitative value reflecting the magnitude of risk brought about by the current synchronization deviation. Its value increases rapidly as model mismatch worsens, characterizing the risk implied by digital twin inconsistencies in risk assessment.

[0046] The first type of weight refers to the weighting coefficients assigned to the load risk intensity and tracking risk intensity within each loading channel. These coefficients satisfy the normalization condition that the sum of these two types of weights for all active channels equals 2M. They are used to adjust the contribution ratio of each channel's execution risk to the overall risk based on channel importance or reliability. Intra-channel aggregation refers to the process of weighted summation of the load risk intensity and tracking risk intensity within the same loading channel, used to obtain an index representing the comprehensive execution risk of that single channel. The channel execution risk index refers to the value characterizing the comprehensive risk of a single loading channel due to load anomalies and tracking errors. It is derived from the weighted aggregation of the channel's load risk intensity and tracking risk intensity, used to quantify the operational risk level of each independent loading unit. The time risk factor refers to a coefficient used to amplify the risk of recent persistent deviations. Its value is not less than 1, used to introduce a time dimension into the deviation risk intensity, giving persistent model mismatches a higher risk weight than instantaneous deviations. The second type of weight refers to the weight coefficients assigned to the deviation risk intensity of each monitoring node. These coefficients satisfy the normalization condition that the sum of the weights of all monitoring points equals N. They are used to adjust the contribution ratio of each node's model mismatch risk to the overall risk based on the structural importance of the monitoring point's location. Intra-node aggregation refers to the process of multiplying the deviation risk intensity, time risk factor, and second-type weights within the same monitoring node to obtain an index representing the comprehensive model risk of that single node. The node model risk index refers to the value characterizing the comprehensive risk generated by the digital twin synchronization deviation of a single monitoring node. It is derived from the node's deviation risk intensity, time risk factor, and weights through intra-node aggregation and is used to quantify the risk level of inconsistency between model prediction and physical reality at each key location. The category balance coefficient refers to the weight coefficients used to adjust the proportion of execution risk and model risk in the final risk index. It controls the relative importance of risks from the actuator execution level and risks from the digital twin model level in the global assessment. Cross-category fusion refers to the process of merging risk indicators of different natures (such as channel execution risk indicators and node model risk indicators) to integrate the risks of the execution layer and the model layer into a unified mathematical expression. The statistical mean can refer to the arithmetic average of a set of values. For example, summing the risk indicators of all M channels and dividing by M yields the statistical mean, which is used to summarize the overall risk level of a certain category (such as all channels), simplifying cross-category comparisons and fusions. The median value of the global comprehensive risk index can refer to the risk value after weighted aggregation and cross-category fusion, but before final normalization. For example, it can be the value calculated from the entire expression within the square root of the formula. It is the direct precursor to the final risk index and needs to be normalized to transform it into a standard range.

[0047] Normalization can refer to the processing method of transforming data to a specific range or conforming to a specific distribution. For example, taking the square root of the median value of the global comprehensive risk index can compress the impact of extreme large values, making the growth trend of the final index R relatively smooth, which is more suitable for the judgment of graded thresholds.

[0048] As a specific example, the formula for calculating the global comprehensive risk index can be:

[0049] Among them, the exponential coefficient , , The value of is 3; the global adjustment coefficient of the model risk term. The value ranges from 0.5 to 2.0; the global risk balance weight coefficient. , The value of each is 0.5; weighting coefficient , , The normalization condition is that the sum of the weights of the load and error terms for all active channels is equal to twice the number of active channels. Right now: ; The sum of the weights of the synchronization deviation terms for all monitoring points equals the number of monitoring points. Right now: ; The real-time load measurement value for the j-th loading actuator channel is derived from the load component in the multi-channel state vector; The software sets the ultimate load protection threshold for the corresponding channel, which is derived from a configurable multi-level rule base; This is the real-time tracking error evaluation value for the j-th loaded actuator channel; The software sets the following error limit protection threshold for the corresponding channel, which is derived from a configurable multi-level rule base; The absolute value of the real-time synchronization deviation of the k-th key monitoring point is derived from the digital twin synchronization unit; This is the synchronization tolerance threshold value for the corresponding monitoring point; , is the time risk factor, used to characterize the statistical severity of the recent model synchronization deviation at the k-th monitoring point; M is the total number of currently active loading actuator channels; N is the total number of critical monitoring points; This indicates that the risk contribution of all M active loading channels is summed. This indicates that the risk contribution of all N key monitoring points is summed up.

[0050] By structuring and standardizing the calculation process of the global comprehensive risk index, and by introducing nonlinear intensity mapping, time risk factors, and cross-category fusion, risk assessment can simultaneously capture instantaneous over-limits, persistent deviations, and risks from different sources than the model, significantly improving the comprehensiveness, dynamic sensitivity, and accuracy of comprehensive judgment in risk quantification.

[0051] In some implementations, the real-time follower error evaluation value is obtained through the following steps: acquiring the command position signal and the actual feedback position signal of the loading actuator in real time, and calculating the instantaneous follower error signal; defining an evaluation time window related to the loading main frequency; within the evaluation time window, extracting a first feature representing its average energy, a second feature representing its extreme amplitude, and a third feature representing its fluctuation stability from the instantaneous follower error signal; and fusing the first feature, the second feature, and the third feature according to a preset contribution ratio to generate the real-time follower error evaluation value.

[0052] Command position signal refers to the target position signal sent by the control system to the loaded actuator, which is expected to reach. For example, it is a digital quantity calculated in real time by the test controller based on the loading spectrum function. Its waveform may be a sine wave, triangular wave, or step wave, used as a setpoint in the control loop to drive the actuator's movement. Actual feedback position signal refers to the feedback signal of the current position of the loaded actuator's piston rod, actually measured by a displacement sensor. For example, it is a digital quantity collected by a dual-redundant magnetostrictive displacement sensor, conditioned, and then sent to the controller. It is used as a measured value in the control loop, reflecting the actuator's actual motion state. The first characteristic can refer to the characteristic quantity extracted from the instantaneous following error signal to characterize its average energy. For example, within the evaluation time window T, this value reflects the overall energy level of the error signal within the window, used to measure the average intensity of the tracking error. The second characteristic can refer to the characteristic quantity extracted from the instantaneous following error signal to characterize its extreme amplitude. For example, within the evaluation time window T, the maximum value of the absolute value of the instantaneous following error is found. This value reflects the magnitude of the peak value that the error signal may appear within the window, used to measure the worst-case instantaneous deviation of the tracking error. The third feature can refer to a characteristic quantity extracted from the instantaneous follow-up error signal to characterize its fluctuation stability. For example, within the evaluation time window T, the standard deviation of the instantaneous follow-up error is calculated. This value reflects the degree of dispersion of the error signal around its mean and is used to measure the stability or smoothness of the tracking process. The preset contribution ratio can refer to a pre-set combination of coefficients used to determine the weight of each feature in the final fusion result. For example, a three-dimensional weight vector is used to assign different weights to the first, second, and third features, with the sum of these weights being 1. This is set through a parameter configuration interface and is used to adjust the emphasis of the evaluation value according to different control performance concerns (such as focusing more on peak value or more on stability).

[0053] As a concrete example, the formula for calculating the real-time tracking error evaluation value can be:

[0054] in, For the j-th channel in The instantaneous tracking error at any given moment is defined as the difference between the commanded position of the loaded actuator and the actual position fed back by the dual redundant magnetostrictive displacement sensor; T is the length of the evaluation time window. The dimensionless maximum error mixing coefficient; Let e_j(t) be the standard deviation of the instantaneous following error within the time window T; This is a dimensionless fluctuation penalty coefficient.

[0055] By decomposing the calculation of real-time tracking error assessment values ​​into multiple sub-steps, the assessment process becomes clear, reproducible, and configurable. By extracting and fusing multi-dimensional features representing average energy, extreme amplitude, and fluctuation stability from the error signal, the dynamic tracking performance of the actuator can be assessed more comprehensively and reasonably. This overcomes the potential bias of relying solely on a single indicator (such as maximum error or average error) and provides a more reliable input for accurate risk assessment.

[0056] In some implementations, the time risk factor is obtained through the following steps: For the absolute value of real-time synchronization deviation generated by a specified monitoring node, calculate its trend average level within a sliding time window. Compare the trend average level with a preset tolerance threshold for that node to obtain a benchmarked recent deviation level index. Perform a nonlinear saturation mapping on the recent deviation level index to generate a time risk factor that is not less than the benchmark value. This factor is used to characterize the statistical severity of the recent model synchronization deviation at that node.

[0057] A sliding time window can refer to a fixed-length data buffer that slides continuously forward along a time axis, such as a 60-second first-in-first-out queue. It continuously stores the latest real-time synchronization deviation absolute value of the monitored nodes, providing a data sample within a defined time range for calculating recent statistics (such as averages). A trend average can refer to a central measure within the sliding time window, derived statistically to reflect the trend of data change. For example, it can be the fitted value of a straight line representing the trend at the center of the window, obtained through linear fitting, used to summarize the typical magnitude or direction of the node's synchronization deviation in the recent period. A recent deviation level index can refer to the ratio of the recent average mismatch of the monitored node to its tolerance, obtained after a statistical benchmarking step, used to quantify the persistent severity of the node's model mismatch. Nonlinear saturation mapping refers to a nonlinear function transformation where the output value increases with the input value, but the growth rate gradually slows down and tends to saturate. For example, using the natural logarithm function ln(1+x) to map the input is characterized by a slower output growth when the input value x is large, never exceeding a certain upper bound. This is used to prevent the time risk factor from increasing indefinitely due to persistent severe deviations at a single node, thus avoiding oversensitivity in risk assessment. Statistical severity refers to the statistical severity of recent model synchronization deviations at a monitoring node, quantified by the time risk factor. It is a composite measure combining the concepts of deviation magnitude and duration. For example, a time risk factor of 1.5 indicates that the recent average deviation of that node amplifies its risk contribution by a factor of 1.5, used to assign higher weight to persistent model mismatches in risk assessment.

[0058] As a specific example: the formula for calculating the real-time risk factor can be:

[0059] in, The absolute value of the real-time synchronization deviation at the k-th monitoring point The moving arithmetic mean over a recent statistical period is used to quantify the average mismatch level at that point in the recent period. It is the natural logarithm function.

[0060] By defining three steps—deviation statistics, benchmarking, and mapping—to calculate the time risk factor, the assessment of model synchronization deviation is extended from a simple instantaneous value to a time dimension. By introducing average level statistics based on a sliding window and logarithmic saturation mapping, the system can identify and penalize persistent model mismatch states that have not reached the instantaneous danger threshold but have deviated over a long period of time. This achieves a more forward-looking and stable risk assessment and avoids frequent strategy switching caused by instantaneous fluctuations.

[0061] In some implementations, the safety execution and arbitration unit includes a policy parser, an adaptive controller, an independent safety logic processor, and a safety state management module; the policy parser converts the response policy into a sequence of control instructions with timing logic; the adaptive controller receives instantaneous follow-up error signals to perform calculations and output control quantities; the independent safety logic processor directly receives raw signals from the data acquisition and fusion unit, and when a hard protection threshold or emergency stop signal is triggered, it bypasses the intelligent decision-making unit and directly starts the emergency unloading loop.

[0062] A strategy parser can refer to a software module within the safety execution and arbitration unit responsible for translating response strategies into specific control instructions. For example, it receives a JSON-formatted strategy description from the intelligent decision-making unit and generates a sequence of control instructions with timing logic based on the strategy type and parameters, such as "reduce the proportional gain of channel 1 by 20% at time t1, and initiate exponential unloading of channel 2 at time t2." This translates high-level strategies into precise action commands that the lower-level controllers can execute. A control instruction sequence can refer to a set of control commands arranged in chronological or logical order, such as a list of instructions containing timestamps, target channels, control modes (e.g., position control, force control), and setpoints (e.g., target position, unloading rate). This sequence is generated by the strategy parser and sent to each actuator controller to coordinate the collaborative actions of multiple actuators along the timeline. An independent safety logic processor can refer to a dedicated hardware circuit or programmable logic device within the safety execution and arbitration unit that processes raw signals directly to achieve hardware-level protection, independent of the main decision-making software. For example, an FPGA-based board can independently and in parallel monitor all raw sensor signals and emergency stop button status, triggering the highest-priority protection action with a microsecond-level response speed in the event of main control software failure or delay. A hard protection threshold can refer to an absolute threshold value embedded in or independently loaded into the independent safety logic processor hardware to trigger emergency protection. This threshold can be set via a DIP switch or EEPROM chip. When the load value corresponding to the raw strain signal voltage exceeds this threshold, the processor will unconditionally trigger protection, providing an absolutely reliable final safety line that does not rely on any software judgment. An emergency stop signal can refer to a digital signal generated by devices such as physical emergency stop buttons, pull-cord switches, or safety light curtains, indicating the need for immediate emergency shutdown. This is typically a dry contact signal, directly connected to the dedicated digital input channel of the independent safety logic processor, allowing operators to force the system into a safe state in the most direct and fastest way in an emergency.

[0063] As a concrete example: In a static load test of an aircraft wing with coordinated multi-actuator loading, the safety execution and arbitration unit operates continuously. Its strategy parser receives the "gradient unloading" response strategy from the intelligent decision-making unit in real time, deducing that actuators 3 and 4 need to reduce the load to 50% exponentially within 5 seconds, and immediately generates the corresponding control command sequence, sending it to the servo controllers of these two actuators. Simultaneously, the adaptive controller continuously receives the instantaneous following error signal from actuator 3, optimizing tracking performance by adjusting its PID parameters online. On the other side of the test, an independent safety logic processor (an FPGA board) directly samples the raw analog voltage signals from all actuator strain sensors at a rate of 100,000 times per second, comparing them in real time with the hard protection thresholds (e.g., the voltage value corresponding to 6000kN). When the test load reaches a dangerous level, although the intelligent decision-making unit may still be calculating the risk index, the independent safety logic processor, upon acquiring a raw load signal exceeding the hard protection threshold, immediately bypasses the intelligent decision-making unit and directly sends a hard-wired signal to the hydraulic power unit and actuators, activating the emergency unloading circuit. At the same time, the security status management module records the event and puts the system into a security lockout state.

[0064] By setting up a collaborative architecture that includes a policy parser, an adaptive controller, an independent security logic processor, and a security status management module, the system achieves an organic combination of policy execution, control optimization, and hardware-level security monitoring. In particular, by directly monitoring the raw signals and making independent judgments through the independent security logic processor, the system achieves the highest priority security protection path in parallel with the upper-level intelligent decision-making software. This ensures that the system can still respond extremely quickly based on the most raw and direct data in the event of any software delay or failure, greatly enhancing the overall security and reliability of the system.

[0065] In some implementations, the emergency unloading circuit includes a supercapacitor energy storage module and a mechanical locking mechanism; when the emergency unloading is triggered, the supercapacitor energy storage module provides independent power to drive all loading actuators to return to the mechanical zero point according to a preset exponential decay rate curve, and then the mechanical locking mechanism fixes the actuator piston rod.

[0066] An emergency unloading circuit can refer to a dedicated hardware circuit and actuator combination that operates independently of the main control system in an emergency for safe and rapid unloading. For example, it may be directly triggered by an independent safety logic processor and includes independent power supplies, drive circuits, and mechanical actuators. It provides a final physical safety net to ensure the actuator safely retracts and locks in the event of a main system failure. A supercapacitor energy storage module can refer to a device that stores electrical energy using supercapacitors (electrically double-layer capacitors). For example, it may consist of multiple supercapacitor cells connected in series to form a module with rapid charge and discharge characteristics. Its electrical energy is independent of the main test power network and is used to provide instantaneous, reliable, and independent power to the solenoid valves or motors that drive the actuators to retract when emergency unloading is triggered, in the event of a potential power failure in the main control system. A mechanical locking mechanism refers to a mechanical device that physically fixes the piston rod of an actuator after it reaches a designated position (such as mechanical zero point). For example, a pin or caliper driven by an electromagnet or independent cylinder extends and inserts into the locking hole of the actuator piston rod or locks the rod body when a locking command is received. This prevents the actuator from moving unexpectedly due to any reason (such as residual pressure in the pipeline) after unloading and retraction, providing the most reliable physical locking. A preset exponential decay rate curve refers to a preset trajectory describing the actuator's unloading and retraction speed decreasing exponentially over time. This is used to control the actuator to return to zero smoothly and without impact, avoiding secondary damage to the structure caused by sudden speed changes. Independent electrical energy refers to a self-sufficient power supply that does not rely on the main power grid or main control system power supply. Here, it specifically refers to the electrical energy released instantaneously by a supercapacitor energy storage module. For example, at the moment of triggering, a supercapacitor module can provide hundreds of amperes of drive current within hundreds of milliseconds to ensure that the execution of emergency unloading does not fail due to a main power outage, guaranteeing the absolute independence of the protection. Mechanical zero point can refer to a preset physical reference position of the loading actuator, usually corresponding to its fully retracted or initial installation position, such as a coordinate point defined by a mechanical limit switch or an absolute displacement sensor. It serves as the target endpoint for emergency unloading, providing a clear and safe termination position for unloading.

[0067] As a concrete example: During an ultimate load-bearing capacity test on a large-span spatial structure node, when the load approached the critical value, the independent safety logic processor detected that the original load signal from actuator No. 2 momentarily exceeded its hard protection threshold. The processor immediately triggered the emergency unloading circuit. First, the supercapacitor energy storage module was activated within 5 milliseconds, providing independent 24V DC power to the proportional servo valves of all actuators, driving each actuator to retract synchronously according to a preset exponential decay speed curve (initial speed 10mm / s, time constant 0.5 seconds). After approximately 3 seconds, all actuator piston rods had retracted to the mechanical zero-point position defined by mechanical limits. Subsequently, the electromagnets of the mechanical locking mechanism installed on each actuator cylinder were energized, driving high-strength alloy pins to pop out and precisely insert into the locking holes at the ends of the piston rods, physically fixing the piston rods. At this point, the system was completely in a hardware-forced locked safety state.

[0068] By specifying the emergency unloading circuit as being powered by a supercapacitor energy storage module and driving the actuator to retreat along an exponential curve, and then combining it with a mechanical locking mechanism for final fixation, a complete and independent hardware-level safety closed loop is constructed, from energy supply and motion control to final state maintenance. This design ensures that even in the worst-case scenario of complete failure of the main control system and interruption of the main power supply, the system can still automatically and smoothly perform unloading and reach a physically locked safety state, greatly improving the protection determinism and reliability under extreme operating conditions.

[0069] In some implementations, the 3D visualization interface is based on a high-fidelity virtual model rendered using a WebGL engine, and displays the stress field cloud map overlaid using a color mapping method. The stress field cloud map is calculated by a real-time finite element simulation kernel. The parameter configuration interface supports modifying protection threshold values ​​via voice commands; modification operations are authenticated through preset multi-level permissions to determine whether approval is granted.

[0070] A 3D visualization interface can refer to a human-computer interaction interface that displays the system status in a three-dimensional graphical format. For example, it can run in a web browser and use WebGL technology to render a 3D model of the experimental structure and loading equipment in real time, providing operators with an intuitive and immersive view of the experimental process. A WebGL engine can refer to a JavaScript API (Web Graphics Library) that renders interactive 3D graphics in a web browser without plugins. For example, it can call libraries such as Three.js or Babylon.js, using hardware acceleration for graphics computation, to efficiently and cross-platform render high-fidelity virtual models and complex stress field cloud maps. A high-fidelity virtual model can refer to a defined computer model that accurately reflects the characteristics of a physical system. For example, it can be driven by a digital twin synchronization unit, containing detailed geometry and finite element meshes, and used as the core object for graphics rendering and data analysis in a 3D visualization interface. Color mapping can refer to a method of mapping data values ​​(such as stress values) to specific colors for visualization. For example, it can use color charts such as "Jet" or "Viridis" to convert the calculated stress scalar values ​​into corresponding RGB color values, used to visually display the stress distribution on the surface of a 3D model as a color cloud map, facilitating the identification of high-stress areas. A real-time finite element simulation kernel can refer to a defined finite element solver capable of performing real-time mechanical calculations. For example, it calculates and outputs the stress and strain values ​​for each mesh node, providing real-time data for stress field contour maps in a 3D visualization interface. A stress field contour map can be a visual representation of the magnitude and distribution of stress on or within a structure's surface, displayed in a color-gradient contour map format. For instance, the von Mises equivalent stress results calculated by the real-time finite element simulation kernel can be rendered on the surface of a 3D model using color mapping, providing an intuitive and quantitative representation of the structure's mechanical response during testing.

[0071] Parameter configuration interfaces refer to interactive interfaces that allow users to view and modify various system parameters. For example, a graphical web page containing forms, sliders, and voice input boxes can be used to centrally manage experimental control parameters and safety rules. Natural Language Processing (NLP) refers to technologies that enable computers to understand, interpret, and manipulate human language. For example, integrating Automatic Speech Recognition (ASR) and Natural Language Understanding (NLU) modules can parse users' spoken commands, converting configuration requirements expressed in natural language into machine-executable parameter modification commands. Multi-factor authentication refers to user identity and permission verification consisting of multiple steps or conditions. For example, combining username and password, Dynamic Tokens (OTPs), and biometrics (such as fingerprints) for step-by-step verification ensures that modifications to critical security parameters (such as protection thresholds) can only be performed by strictly authorized personnel, preventing unauthorized or accidental operations.

[0072] As a concrete example: In a fatigue test involving multi-point loading of a high-speed train's body structure, the operator used a human-computer interaction and recording unit. A 3D visualization interface opened in a browser rendered in real-time a high-fidelity virtual model—a detailed finite element mesh of the train's skeleton—driven by a digital twin synchronization unit, based on a WebGL engine (using the Three.js library). Simultaneously, the interface obtained nodal stress data from the real-time finite element simulation kernel and displayed dynamically updated stress field cloud maps on the model surface using a color mapping method (employing a "Rainbow" color spectrum), with red areas clearly indicating stress concentration points. During the test, the engineer discovered a significant following error in a certain channel, requiring adjustment of the rules. Using the voice input function of the parameter configuration interface, he stated the command: "Adjust the following error limit threshold of loading channel number two from 0.5 mm to 0.8 mm." This voice command was parsed into a structured modification request by the integrated natural language processing service (e.g., calling Alibaba Cloud NLP services). The system then initiated a preset multi-level authentication process: first, requiring the user's account password, and then a secondary confirmation via a one-time dynamic verification code generated by the mobile app. After all authentications are successful, the system will write the new threshold values ​​to the corresponding locations in the configurable multi-level rule base. All state changes, commands, and events throughout the entire operation and experiment will be recorded as system-wide runtime events in the database.

[0073] By employing a WebGL-based 3D visualization interface combined with real-time stress field cloud map overlay, operators are provided with an intuitive, realistic, and information-rich monitoring view of the test process, greatly enhancing the spatial perception of structural response and potential risks. By supporting the modification of key parameters using voice commands based on natural language processing, and supplemented by a strict multi-level authentication process, the system improves the efficiency and flexibility of human-computer interaction while firmly guarding the authorization gate for safe parameter modification, effectively preventing accidental operation or unauthorized access, and balancing the convenience of operation with the security of the system.

[0074] The preferred embodiments disclosed above are merely illustrative of this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the content of this invention. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.

Claims

1. A loading control system with multi-level safety protection, characterized in that, include: The data acquisition and fusion unit is used to acquire, align and fuse the state signals of each loading actuator in the physical loading system to generate a multi-channel state vector that includes the load, the displacement measured by the displacement sensor and the instantaneous following error signal generated by the control feedback. The digital twin synchronization unit is used to receive the multi-channel state vector and drive the high-fidelity virtual model to calculate the real-time synchronization deviation between the key monitoring points of the physical entity and the corresponding points of the virtual model. The intelligent decision-making unit is used to perform multi-scale risk assessment based on the multi-channel state vector and the real-time synchronization deviation, through preset rules and prediction models, and generate response strategies including strategy types. The security execution and arbitration unit is used to parse the response strategy and generate coordinated control instructions, while directly monitoring the original signals to execute the highest priority hardware-level protection. The security execution and arbitration unit includes an adaptive controller to adjust the actuator control parameters. The security execution and arbitration unit also includes a security state management module, which is used to put the system into a security lock state after triggering hardware-level protection, and can only be reset after authorized manual confirmation instructions. The human-computer interaction and recording unit is used to provide a 3D visualization interface, parameter configuration interface, and record all system operation events.

2. The system according to claim 1, characterized in that, The data acquisition and fusion unit includes a distributed sensor network and a real-time fusion processor; The distributed sensing network includes a strain sensor for measuring load, a grating ruler for measuring global displacement, and a dual redundant magnetostrictive displacement sensor, which is one of the displacement sensors, for acquiring the position of the actuator piston rod. The real-time fusion processor fuses multi-source signals based on Kalman filtering and dynamic time warping algorithms.

3. The system according to claim 1, characterized in that, The high-fidelity virtual model includes a parametric geometric model and a real-time finite element simulation kernel; The digital twin synchronization unit performs spatial pose calibration using pre-scanned installation point cloud data and outputs the real-time synchronization deviation for each key monitoring point, whereby the real-time synchronization deviation is the Euclidean distance between the physical point and the virtual point.

4. The system according to claim 1, characterized in that, The intelligent decision-making unit includes a configurable multi-level rule base and a prediction engine based on a long short-term memory network; The types of response strategies include flexible adjustment, gradient unloading, and emergency braking; The intelligent decision-making unit triggers strategy generation by calculating a global comprehensive risk index; The configurable multi-level rule base stores protection thresholds for load, following error, and synchronization deviation.

5. The system according to claim 4, characterized in that, The intelligent decision-making unit calculates the global comprehensive risk index through the following steps: The system acquires real-time load measurements, real-time tracking error assessments, and real-time synchronization deviation absolute values ​​from the monitoring nodes in parallel. It then performs benchmarking processing on each type of real-time data and its corresponding preset safety threshold value to generate a set of dimensionless relative deviation data. Nonlinear intensity mapping is performed on the load relative deviation data, the tracking error evaluation value relative deviation data, and the synchronization deviation relative deviation data to obtain the load risk intensity, tracking risk intensity, and deviation risk intensity, respectively. The load risk intensity and tracking risk intensity of each channel are assigned first-class weights and aggregated within the channel to obtain the channel execution risk index; the deviation risk intensity of each monitoring node is introduced with a time risk factor and assigned second-class weights and then aggregated within the node to obtain the node model risk index; using a preset category balance coefficient, the statistical mean of the execution risk index of all channels and the statistical mean of the risk index of all node models are fused across categories to generate the median value of the global comprehensive risk index. The intermediate value of the global comprehensive risk index is normalized to output the final global comprehensive risk index.

6. The system according to claim 5, characterized in that, The real-time tracking error evaluation value is obtained through the following steps: The command position signal and actual feedback position signal of the loading actuator are acquired in real time, and the instantaneous following error signal is calculated; an evaluation time window related to the loading frequency is defined. Within the evaluation time window, a first feature characterizing its average energy, a second feature characterizing its extreme amplitude, and a third feature characterizing its fluctuation stability are extracted from the instantaneous following error signal. The first feature, the second feature, and the third feature are fused according to a preset contribution ratio to generate the real-time following error evaluation value.

7. The system according to claim 5, characterized in that, The time risk factor is obtained through the following steps: For the absolute value of the real-time synchronization deviation generated by the specified monitoring node, calculate its trend average level within a sliding time window; The trend average level is compared with the preset tolerance threshold value of the node to obtain a benchmarked recent deviation level index. The recent deviation level index is subjected to nonlinear saturation mapping to generate a time risk factor that is not less than the benchmark value. This factor is used to characterize the statistical severity of the recent model synchronization deviation at this node.

8. The system according to claim 1, characterized in that, The security execution and arbitration unit includes a policy parser, an adaptive controller, an independent security logic processor, and a security state management module; The strategy parser converts the response strategy into a sequence of control instructions with timing logic; the adaptive controller receives the instantaneous following error signal to perform calculations and outputs control quantities. The independent safety logic processor directly receives the raw signals from the data acquisition and fusion unit, and when a hard protection threshold or emergency stop signal is triggered, it bypasses the intelligent decision-making unit and directly starts the emergency unloading circuit.

9. The system according to claim 8, characterized in that, The emergency unloading circuit includes a supercapacitor energy storage module and a mechanical locking mechanism; When the emergency unloading is triggered, the supercapacitor energy storage module provides independent power to drive all loading actuators to return to the mechanical zero point according to the preset exponential decay rate curve, and then the mechanical locking mechanism fixes the actuator piston rod.

10. The system according to claim 1, characterized in that, The three-dimensional visualization interface is obtained by rendering the high-fidelity virtual model based on the WebGL engine, and the stress field cloud map is superimposed and displayed in a color mapping manner. The stress field cloud map is calculated by the real-time finite element simulation kernel. The parameter configuration interface supports modifying the protection threshold value via voice commands. The modification operation is authenticated through preset multiple permissions to determine whether it is approved.