Anhydrous hydrogen fluoride automatic sampling control method and system
By introducing antifragile control logic and fault identification technology, the problem of task interruption caused by sensor failure in automated sampling systems was solved, enabling safe switching and task completion when critical components fail, thus improving the resilience and security of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHEJIANG STARRY PHARMA
- Filing Date
- 2026-04-07
- Publication Date
- 2026-05-05
AI Technical Summary
Existing automated sampling systems have been unable to effectively resolve the contradiction between high reliability requirements and the inherent failure rate of components due to the failure of critical sensors, which has led to mission interruptions or safety risks.
Antifragile control logic is introduced, and through fault identification and mode switching, the system can still safely complete the sampling task when some components fail. It adopts a central control unit, process actuator module, multi-source sensing module and antifragile control and fault response module to switch to a safe degradation sub-mode.
It improves the system's operational resilience and mission success rate in high-risk environments, enhances the safety and robustness of unattended sampling tasks, and avoids the vulnerabilities of traditional systems.
Smart Images

Figure CN121979089A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of automation control technology, and in particular to an automatic sampling control method and system for hazardous chemicals, specifically an automatic sampling control method and system for anhydrous hydrogen fluoride. Background Technology
[0002] In the production of high-purity chemicals, periodic sampling of hazardous media such as anhydrous hydrogen fluoride to analyze their purity and impurity content is a crucial step in ensuring product quality. Current technologies largely rely on manual operation, which is not only labor-intensive and inefficient but also exposes operators directly to highly toxic and corrosive environments, posing significant safety risks. While automated sampling systems can isolate personnel, their design logic often replicates a linear process under ideal operating conditions, making such systems inherently fragile. Their stable operation heavily depends on the perfect functioning of all sensors. If a critical sensor (such as a level gauge) malfunctions, the system lacks resilience; the only safety strategy is a complete shutdown, leading to sampling failure and impacting the entire production schedule. Essentially, this transforms safety risks into task failure risks, failing to address the fundamental contradiction between high reliability requirements and the inherent failure rate of components. Summary of the Invention
[0003] In the first aspect, this application provides an automatic sampling control method for anhydrous hydrogen fluoride, which aims to solve the technical problem that the automatic sampling system in the prior art is interrupted or causes safety risks due to the failure of key sensors.
[0004] The method includes: in response to a sampling command, controlling a circulation pump and a circulation valve to open to establish fluid circulation within a main pipeline; after the fluid circulation is established, controlling a micro-inline delivery pump to open to replace a bypass line connected to the main pipeline; after the bypass line replacement is completed, controlling a bypass valve to open to execute a main sampling mode based on a real-time signal from a first sensor used to monitor the liquid level in the sampling bottle; during the execution of the main sampling mode, continuously monitoring the real-time signal from the first sensor to identify a preset fault fingerprint; and, upon identification of the fault fingerprint, switching the sampling mode from the main sampling mode to a safety degradation sub-mode to complete the sampling.
[0005] Optionally, the step of identifying a preset fault fingerprint includes: acquiring multiple consecutive sampled values of the first sensor within a preset time window; and determining, based on the statistical characteristics of the multiple consecutive sampled values, whether the real-time signal of the first sensor has signal freeze or signal jump, as the fault fingerprint.
[0006] Optionally, the step of determining whether the real-time signal of the first sensor is frozen based on the statistical characteristics of the plurality of continuous sampled values includes: calculating the difference between the maximum and minimum values of the plurality of continuous sampled values within the time window; and if the difference is less than a first preset threshold and the duration of the state exceeds a preset duration, then it is determined that the real-time signal is frozen.
[0007] Optionally, the safety degradation sub-mode is a time-based quantitative sampling mode, and the step of switching to a safety degradation sub-mode includes: starting a timer, the duration of which is a preset safety timed sampling duration; and controlling the bypass valve to close when the timer ends.
[0008] Optionally, the method further includes a calibration step performed before the sampling command response, the calibration step including: performing at least one standard sampling procedure under manual monitoring, recording the time required from the opening of the bypass valve to the first sensor detecting that the liquid level has reached a preset target liquid level, to obtain an average sampling time; and recording the stable pressure reading in the main pipeline monitored by a second sensor during the standard sampling procedure, to obtain a reference pressure; and determining the safe timed sampling duration based on the average sampling time and a safety factor.
[0009] Optionally, the step of switching to a safety degradation sub-mode further includes, before starting the timer: acquiring the real-time pressure in the main pipeline currently monitored by the second sensor; comparing the real-time pressure with the reference pressure; and starting the timer only when the deviation between the real-time pressure and the reference pressure is less than a second preset threshold.
[0010] Optionally, after responding to the sampling command and before controlling the circulation pump and the circulation valve to open, the method further includes: performing a pre-start sensor self-test, the self-test including acquiring static signals from the first sensor and at least one pressure sensor; and continuing to perform subsequent steps only if the static signals are within their respective reasonable standby ranges.
[0011] Optionally, the fault fingerprint further includes a process noise missing fingerprint; the step of identifying the fault fingerprint further includes: performing a sliding window fast Fourier transform on the real-time signal of the first sensor to generate a series of frequency domain spectra; identifying whether there is a characteristic spectral peak corresponding to a preset operating frequency of the micro-pipeline pump in the frequency domain spectra; and if the characteristic spectral peak is missing or its amplitude is lower than a noise floor threshold, determining that the first sensor has lost its dynamic response capability to the physical process, and generating the fault fingerprint.
[0012] Optionally, before controlling the bypass valve to open to execute the main sampling mode, the method further includes a valve health adaptive maintenance step, which includes: obtaining the action response time of the bypass valve from receiving a drive command to its valve position feedback device returning a position signal in the previous one or more historical operations; comparing the action response time with a dynamically updated viscous threshold; and, if the action response time exceeds the viscous threshold, determining that the bypass valve has a viscous risk, and controlling the bypass valve to execute at least one high-frequency pulse switching sequence before performing a full-open action, so as to use fluid impact force to remove potential viscous substances from the valve core.
[0013] Secondly, this application also provides an automatic sampling control system for anhydrous hydrogen fluoride, the system comprising: a process actuator module including a circulation pump, a circulation valve, a micro-pipeline delivery pump, and a bypass valve; a multi-source sensing module including a first sensor for monitoring the liquid level in the sampling bottle; and a central control unit configured to: in response to a sampling command, control the circulation pump and the circulation valve to open to establish fluid circulation in a main pipeline; after the fluid circulation is established, control the micro-pipeline delivery pump to open to replace a bypass pipeline connected to the main pipeline; after the bypass pipeline replacement is completed, control the bypass valve to open based on the real-time signal of the first sensor to execute a main sampling mode; during the execution of the main sampling mode, continuously monitor the real-time signal of the first sensor to identify a preset fault fingerprint; and when the fault fingerprint is identified, switch the sampling mode from the main sampling mode to a safety degradation sub-mode to complete the sampling.
[0014] Optionally, the central control unit also incorporates an antifragile control and fault response module, which is configured to: acquire multiple consecutive sampled values of the first sensor within a preset time window; and, based on the statistical characteristics of the multiple consecutive sampled values, determine whether the real-time signal of the first sensor has signal freezing or signal jump, so as to serve as the fault fingerprint, and generate a fault flag bit for the central control unit to call.
[0015] Optionally, the safety degradation sub-mode is a time-based quantitative sampling mode, and the central control unit is configured to: start an internal timer when switching to the safety degradation sub-mode, the duration of which is a preset safety timed sampling duration; and control the bypass valve to close when the timer ends.
[0016] The beneficial effects of this application are as follows: By introducing an antifragile control logic based on fault identification and mode switching, this application provides an automatic sampling system that can still safely and successfully complete core tasks even when some components fail. This application transforms the failure downtime events in traditional automated systems into a controllable and effective information input that guides the system into a backup safety process, thereby qualitatively improving the system's operational resilience, task success rate, and inherent safety in high-risk environments without human intervention, and overcoming the inherent vulnerability of traditional automated systems. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is a schematic diagram of the overall technical architecture of an anhydrous hydrogen fluoride automatic sampling control system provided in one embodiment of this application.
[0019] Figure 2 This is a flowchart illustrating the main process and preparation stage of an anhydrous hydrogen fluoride automatic sampling and control method provided in one embodiment of this application.
[0020] Figure 3 for Figure 2 The process shown is a continuation of the sampling, fault handling, and termination phases.
[0021] Figure 4 This is a schematic diagram of a fault fingerprint recognition logic provided in one embodiment of this application. Detailed Implementation
[0022] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with the accompanying drawings and specific embodiments. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0023] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, "multiple" means two or more, unless otherwise explicitly specified.
[0024] System Implementation Examples This application provides an automatic sampling and control system 1000 for anhydrous hydrogen fluoride. This system is constructed as a control entity with an inherent anti-fragile mechanism. It is configured to autonomously switch its operating mode from a high-precision main mode to a preset safety degradation sub-mode when faced with failure events of critical sensing components within the system, ensuring the final completion of sampling tasks in high-risk environments. In a specific implementation, the system integrates a central control unit M100, a process actuator module M200, a multi-source sensing module M300, and an anti-fragile control and fault response module M400 embedded in the central control unit M100, thereby achieving continuous monitoring of the system's own operating status. In response to the identified specific sensor fault fingerprint, the system seamlessly switches the sampling process from a closed-loop control mode relying on real-time sensor feedback to an open-loop control safety mode based on a precise time reference. This system, through its design, solves the technical dilemma of traditional automation solutions having no choice but to shut down the system in the event of a single point of failure in the sensor, which leads to task interruption. Thus, it improves the success rate of unattended high-risk sampling tasks and the overall robustness of the system while ensuring absolute operational safety.
[0025] Reference Figure 1 This is a schematic diagram of the overall technical architecture of an embodiment of the anhydrous hydrogen fluoride automatic sampling control system 1000. The system 1000 includes a central control unit M100, a process actuator module M200, a multi-source sensing module M300, and an antifragile control and fault response module M400.
[0026] The central control unit M100 is configured to execute all decision-making and control logic. In a specific physical implementation, the central control unit M100 is an industrial-grade programmable logic controller (PLC) deployed in an explosion-proof control cabinet in the field, such as, but not limited to, a Siemens S7-1500 series or equivalent controller. This PLC is equipped with hardware resources to meet the complex interface requirements of this system, specifically including: at least 32 opto-isolated 24V DC digital input (DI) channels for receiving discrete status signals from the valve position feedback switches in the process actuator module M200 without interference; at least 16 relay-type digital output (DO) channels with contact capacity sufficient to drive the solenoid coils of the pumps and valves in the process actuator module M200; and at least 8 differential analog input (AI) channels with 16-bit resolution for accurately converting the 4-20mA standard current loop signals output from the pressure and level sensors in the multi-source sensing module M300 into internal digital quantities. To enable communication with the upper-level monitoring system, the PLC also integrates an industrial Ethernet port supporting Profinet or Modbus TCP / IP protocols. Through this port, the central control unit M100 responds to operation commands from the human-machine interface (HMI) and pushes system status, process data, and alarm information to the monitoring center in real-time in the form of structured data packets. Its internally embedded control program is based on a set of stepper state machine logic written in Sequential Function Chart (SFC) language to ensure the strict timing of the sampling process. Furthermore, the PLC's memory space is divided into multiple functional data blocks (DBs). One critical data block is configured for power-down retention, used to persistently store key parameters determined through the S000 calibration process, such as the safe sampling duration Tsafe and the reference pressure Pbase, to ensure the system maintains the correct configuration after a power cycle. Another global data block defines a core 32-bit system status word, where each bit is mapped to a specific system status flag; for example, Bit 8 is hard-coded as the LS1 level sensor fault flag. At each critical decision node in the scan cycle, the main program reads the status word through bit manipulation instructions, thereby driving the process branch.
[0027] The process actuator module M200, serving as the physical actuator of the system 1000, comprises all equipment that directly contacts and operates the anhydrous hydrogen fluoride medium. To cope with the strong corrosiveness of the medium, all flow-through components within this module are made of chemically inert materials. Specifically, the module includes a circulation pump P1 and a micro-pipeline transfer pump P2. The circulation pump P1 is implemented as a magnetically driven centrifugal pump, with its pump casing and impeller made of integrally sintered polytetrafluoroethylene (PTFE). The magnetic coupling transmission eliminates traditional dynamic sealing points, thus achieving zero leakage. The micro-pipeline transfer pump P2 is implemented as a high-precision micro diaphragm pump, with its diaphragm also made of PTFE. Driven by a stepper motor, it provides stable and precisely adjustable micro-flow and pressure for the displacement and sampling stages. The module also includes a series of pneumatic diaphragm valves, including a circulation pipeline valve V1, a bypass sampling valve V2, and a tail gas vacuum valve V3. These valves all feature full PTFE bodies and are driven by clean compressed air controlled by external solenoid valves, completely isolating the electrical components from the process fluids. Each pneumatic valve is equipped with a valve position feedback device, whose internal open (ZSO) and closed (ZSC) mechanical limit switches transmit the valve's physical stroke state as a binary signal via hard-wired connection to the DI channel of the central control unit M100, thus forming a closed-loop feedback link for confirming command execution status. Furthermore, normally closed emergency shut-off valves V4 and V5 are installed at critical isolation points in the system; these valves automatically close the pipelines using spring return force in the event of a power failure or upon receiving an emergency stop signal. All these actuators are driven via relay contacts of the DO module of the central control unit M100.
[0028] The multi-source sensing module M300, serving as the sensing system of the system 1000, is configured to measure key physical parameters during system operation in real time. The performance of this module directly determines the accuracy and safety of system control. In a specific implementation, this module includes multiple pressure transmitters and at least one level transmitter. Specifically, the circulation pipeline pressure sensor PT1 and the sampling pipeline pressure sensor PT2 are implemented as diaphragm-type pressure transmitters specifically designed for highly corrosive media. Their pressure-sensing diaphragms, which are in direct contact with the media, are made of Hastelloy C-276 alloy or tantalum metal to ensure long-term chemical stability. These sensors linearly convert the measured gauge pressure values into a 4-20mA standard current signal, which is then connected to the AI module of the central control unit M100 via a shielded cable.
[0029] The first sensor, LS1, is used for non-contact monitoring of the liquid level in the sampling bottle. Optionally, LS1 can be implemented as an external clamp-on ultrasonic level gauge, with its probe fixed to the outer wall of the sampling bottle. It calculates the liquid level by emitting ultrasonic pulses and analyzing the time-of-flight (TOF) of the echo signal at the liquid-gas interface after the pulses penetrate the bottle wall. As a higher-performance alternative, LS1 can also be implemented as a guided wave radar level gauge, with its probe section fully protected by a PFA (fusible polytetrafluoroethylene) coating. The liquid level is determined by measuring the time it takes for the gigahertz-level microwave pulse propagating along the probe to reflect back from the liquid surface. This method is more robust to interference such as foaming of the medium or liquid residue on the bottle wall. Regardless of the technology used, the output of LS1 is a 4-20mA standard signal, serving as the core feedback signal for accurate quantitative control in the main sampling mode.
[0030] The antifragile control and fault response module M400 is configured to implement the system's immune monitoring and emergency response functions. In a preferred embodiment, M400 is implemented as a pure software function block, whose code runs in the firmware environment of the central control unit M100 and is synchronously called within the same PLC scan cycle as the main control program. This embedded design allows it to access internal system data with extremely low latency without requiring additional hardware. The internal logic structure of M400 consists of two core sub-components. The first is the fault fingerprint recognition algorithm subroutine, which is the logical core for identifying faults. Its implementation details will be described in detail in subsequent method embodiments. Its core task is to continuously receive the data stream from the LS1 level sensor forwarded in real time by M100 and apply an algorithm based on sliding window statistics and physical model constraints to determine whether the data stream exhibits a predefined fault mode. The second is the fault flag manager subroutine, which is responsible for processing and arbitrating the raw output of the fault fingerprint recognition algorithm. For example, a simple counter can be used to implement debouncing logic, requiring a fault state to occur consecutively for N (e.g., 3) scan cycles to be confirmed as a valid fault. Once confirmed, a latching operation is performed, writing the fault state into a specific flag bit (e.g., Bit 8) of the aforementioned system status word, and holding this bit until the entire sampling process ends or a manual reset command is received. In the private data area of the M400, a data structure, a sensor data circular buffer, is maintained. This is a fixed-length (e.g., 50 floating-point numbers) one-dimensional array, using pointer operations to implement a first-in-first-out (FIFO) function, used to cache the most recent 5 seconds of LS1 historical data. This buffer provides the data foundation required for the fault fingerprinting algorithm to perform time-series pattern analysis. Through this architecture, the M400 module, as an independent and parallel monitoring task, does not directly interfere with the physical actuators. Instead, it proposes a strategic mode switch to the main control program by modifying a shared status flag, thereby decoupling the monitoring and control logic.
[0031] This application provides an automatic sampling and control method for anhydrous hydrogen fluoride, which is executed by the aforementioned automatic sampling and control system 1000 for anhydrous hydrogen fluoride. The following will refer to... Figure 2 , Figure 3 The flowchart shown provides an in-depth explanation of the execution details of this method.
[0032] S000: Perform system initialization and calibration.
[0033] Upon initial deployment of the System 1000 or after replacement of sampling vials with different geometries, a mandatory initialization and calibration procedure is triggered. The purpose of this procedure is to calibrate an accurate, critical control parameter relevant to the current physical system state for any subsequent potential safety degradation sub-modes. This procedure is initiated by an authorized engineer via the HMI interface and executed under their continuous local or remote monitoring.
[0034] In a specific example, suppose a new 500mL sampling bottle is installed in the system, with the target sampling level set at 66.7% of the bottle's total height. The engineer correctly installs an empty, nitrogen-purged sampling bottle onto the quick-connect fitting of the bypass line and confirms it is securely in place. Subsequently, a calibration start command is issued via the HMI. In response to this command, the central control unit M100 executes a complete standard sampling procedure according to the main mode control logic from S100 to S400. During this procedure, an internal hardware timer with millisecond-level resolution is synchronously triggered and begins timing the moment the solenoid coil controlling the bypass valve V2 is energized in step S310.
[0035] Meanwhile, the central control unit M100 continuously polls the analog input channel of the circulating pipeline pressure sensor PT1 at a high frequency (e.g., 10Hz), and after the main pipeline circulation reaches a stable state (e.g., when S130 is completed), it acquires and records the pressure reading at that moment, assumed to be 1.02 kg / cm². When the sampling process reaches step S340, that is, when the liquid level reading of the first sensor LS1, after noise filtering, first reaches and exceeds the threshold of 66.7%, a hardware interrupt is triggered. The interrupt service routine immediately stops the aforementioned timer and locks its count value. Assume the duration of the first calibration run is 48.35 seconds. To ensure the statistical reliability of the calibration results and smooth out the random error of a single measurement, the calibration process can be programmed to be executed automatically three times consecutively. Assume the durations of the second and third measurements are 47.92 seconds and 48.51 seconds, respectively. After all three runs are completed, the solidified algorithm inside the central control unit M100 automatically calculates the arithmetic mean of these three duration values, resulting in Tavg = (48.35 + 47.92 + 48.51) / 3 = 48.26 seconds. Simultaneously, the average pressure of the three stable cycles is also calculated to determine the reference pressure Pbase: Pbase = (1.02 + 1.01 + 1.03) / 3 = 1.02 kg / cm².
[0036] Next, the system calculates the core safe timed sampling duration Tsafe based on Tavg. This calculation introduces a key safety factor K, whose value is in the range (0, 1). The purpose of introducing this factor is to reserve a certain safety volume margin in the open-loop timed sampling mode by actively shortening the sampling time, in order to cope with potential small fluctuations in process pressure and ensure that the sampling volume does not exceed the safety limit. The value of this factor K can be derived from the risk assessment strategy, for example, using the formula K = 1 - (Vmargin / Vtarget). Where Vtarget is the target sampling volume (corresponding to 66.7% of the bottle height), and Vmargin is the safety space volume that must be reserved in the process safety procedure (for example, requiring that at least 10% of the total bottle volume should be left empty at the top of the sampling bottle). In this example, the ratio of Vmargin to Vtarget is 10% / 66.7% ≈ 15%. Therefore, the safety factor K is set to 1 - 0.15 = 0.85. Based on this, the central control unit M100 calculates Tsafe = Tavg×K = 48.26×0.85 = 41.021 seconds. Finally, the two measured and calibrated parameters, Tsafe = 41.021 seconds and Pbase = 1.02 kg / cm², are written into the PLC's power-down retention data block, completing the configuration of the safety degradation sub-mode.
[0037] S100: Responds to sampling command.
[0038] In the system's normal operating mode, when the operator in the central control room needs to perform a sampling according to the production plan, they issue a start sampling command through the HMI interface. This command is encapsulated as a data packet with a specific function code and sent to the central control unit M100 via industrial Ethernet. In response to this command, the M100 does not immediately activate any actuators, but first enters a pre-emptive safety and status check sequence. By polling its digital input (DI) channels, it sequentially checks the signal levels of the closed-position feedback switches (ZSCs) associated with the critical valves (V1, V2, V3). A preset logical requirement is that all these signals must be simultaneously high (or low, depending on the hardware wiring), indicating that all valves are in the initial fully closed state. Additionally, the system can be configured with a mechanical limit switch mounted on the sampling bottle holder, whose signal is also connected to the DI channel. The M100 checks the signal of this switch to verify that a physical sampling bottle has indeed been correctly installed. Only when all these precondition checks return true does the M100 transition its internal state machine from idle to standby, preparing to proceed to the next self-test step. This initial state confirmation step constitutes the first logic gate to prevent the process from starting unexpectedly due to improper device reset or incorrect consumable installation.
[0039] S115: Perform sensor self-test before startup.
[0040] After the internal state of the system 1000 transitions to standby, a mandatory pre-start sensor self-test subroutine is automatically invoked. The purpose of this step is to perform a static check on the electrical viability and physical plausibility of the readings of all critical sensors before starting any potentially hazardous power equipment (such as pumps). The central control unit M100 is configured to sequentially read the current values of all its analog and digital input channels during this step. For the first sensor LS1 (level gauge), since the sampling bottle should be empty at this time, its physical level is zero. Taking into account the sensor's inherent zero-point drift and electrical noise, the system compares its current reading to a predefined zero-point tolerance window, such as [-0.5%, +0.5%]. Readings falling within this window are considered normal. If the reading deviates significantly, such as returning to 15.8% (potentially indicating residual liquid from a previous cleaning) or a negative value indicating over-range (e.g., -10.0%, typically indicating sensor failure or a broken 4-20mA signal loop), the system determines its status to be abnormal. For pressure sensors PT1 and PT2, under static conditions where the pipeline is not pressurized, their readings should reflect the current ambient pressure or a slight positive pressure maintained by the system's nitrogen protection system. The system checks whether their readings fall within a preset standby pressure window, such as [0.05 kg / cm², 0.2 kg / cm²]. Only when the static readings of all polled sensors pass their respective rationality checks will the M100 determine that the self-test has passed and transition the system status from standby to ready, thereby authorizing the execution of subsequent procedures. Conversely, if any sensor reading is determined to be abnormal, the M100 will immediately abort the startup sequence, keeping all actuators in a disabled state. Simultaneously, a high-priority alarm flag will be set on its communication interface with the HMI, and a diagnostic message containing the faulty sensor ID and abnormal reading value will be pushed to the HMI, such as: Pre-start self-test failed: Level sensor LS1 reading abnormal, current value 55.2%. This design ensures that the system will not blindly initiate a high-risk operation sequence when critical sensing capabilities are impaired.
[0041] S120: Controls the opening of a circulation pump and a circulation valve to establish fluid circulation in a main pipeline.
[0042] After the self-test of S115 is successfully completed and the system state transitions to ready, the central control unit M100 begins executing the first physical operation sequence of the sampling process. Through a relay contact of its digital output (DO) module, M100 outputs a 24V DC excitation signal to the coil of the motor starter controlling the circulation pump P1, thereby starting the circulation pump P1. Almost simultaneously, M100 outputs a drive signal through another DO channel to the solenoid valve coupled to the pneumatic actuator controlling the circulation pipeline valve V1, causing V1 to open. In response to the opening action of valve V1, the open-to-position (ZSO) limit switch on its valve position feedback device closes, sending an acknowledgment signal to a digital input (DI) channel of M100. The control logic of M100 includes a watchdog timer that waits for the return of the ZSO signal after issuing the valve opening command. If the signal is not received within a preset time window (e.g., 2 seconds), the system will determine that the valve execution is faulty and trigger a shutdown alarm. After P1 is started and V1 is opened and confirmed, the anhydrous hydrogen fluoride medium in the storage tank is pumped into the main pipeline and begins to circulate.
[0043] S130: After the fluid circulation is established.
[0044] After the execution of S120, the system enters a waiting and confirmation phase to ensure that the fluid circulation in the main pipeline has reached a stable state. The central control unit M100 continuously acquires the analog input signal from the circulation pipeline pressure sensor PT1 at a fixed high frequency (e.g., a scan cycle of 100 milliseconds). During the transient process of P1 activation, the PT1 reading experiences a rapid rise and possible overshoot. The control logic of M100 is configured to monitor this pressure value until it first enters a preset target stability range, e.g., [0.9 kg / cm², 1.1 kg / cm²]. To ensure true stability of the circulation, rather than instantaneous stability, M100 further requires the PT1 reading to remain continuously within this range for a preset period, e.g., 10 seconds. Within this 10-second stability window, the fluctuation range of the reading must be constrained within a narrower tolerance band (e.g., ±0.02 kg / cm²). Only when both conditions—entering the stable range and maintaining stability—are met, will M100 determine that the fluid circulation in the main pipeline has been fully established, thus providing a stable pressure and flow source for subsequent replacement and sampling steps.
[0045] S200: Control a miniature pipeline delivery pump to start, thereby replacing a bypass line connected to the main pipeline. This stage is a pretreatment to ensure sample representativeness and includes S210 to S240.
[0046] S210: In response to the internal event in S130 confirming that the main pipeline circulation has been stably established, the central control unit M100 issues a command via its DO module to start the micro-inline delivery pump P2. P2 is configured to draw a small stream of anhydrous hydrogen fluoride from the circulating main pipeline and force it through the bypass line connected to the sampling bottle. The purpose of this operation is to thoroughly remove dead volume fluid in the bypass line that may have stratified due to prolonged settling or contain residual impurities, using a new, homogeneous fluid, thereby ensuring that the final sample accurately reflects the real-time chemical state of the fluid in the main pipeline.
[0047] S220: After P2 is initiated, the monitoring focus of M100 switches to the reading of the sampling line pressure sensor PT2. The pressure value of PT2 should rise rapidly after P2 is initiated and eventually stabilize in a displacement pressure target range set slightly higher than the main line pressure, for example [1.7 kg / cm², 1.9 kg / cm²]. Simultaneously, the antifragile control and fault response module M400 begins to apply its fault fingerprinting algorithm to the real-time signal stream of PT2, marking the first activation of the system's antifragile mechanism in the process.
[0048] S230: Once M100 determines that the pressure reading of PT2 has stabilized within the target range, an internal displacement timer is activated. According to the process specifications, the duration of this timer is set sufficient to ensure that the bypass line is thoroughly flushed with several times its volume of fresh fluid, for example, 120 seconds (2 minutes) or 180 seconds (3 minutes). During this timer cycle, P2 continues to run, continuously flushing the bypass line with fresh anhydrous hydrogen fluoride. The displaced fluid returns to the main line or a dedicated waste collection system via the end of the line.
[0049] S240: This step is executed asynchronously in parallel with S220 and S230, demonstrating the system's real-time anti-fragility check capability.
[0050] Throughout the replacement phase, the M400 module continuously receives the real-time data stream from PT2. Its internal fault fingerprint matching algorithm is configured to perform a specific start-up response check: if, within a short time window after the P2 start command is issued in S210, for example, within 5 seconds, the PT2 reading increment is less than a preset minimum response threshold (e.g., 0.1 kg / cm²), the M400 identifies this event as a clear purge blockage or sensor failure fault fingerprint. This fingerprint may correspond to various physical faults, such as bypass line blockage, P2 pump mechanical failure, or PT2 sensor failure itself. In response to this identification, the M400 immediately sets a specific internal fault flag (e.g., FAULTPT2NO_RESPONSE) in the global data block of the M100. The M100's main program checks this flag every scan cycle within its loop logic while waiting for the PT2 pressure to stabilize. Once the flag is detected to be set, the M100 will immediately interrupt the normal waiting process and jump to a preset emergency safety shutdown sequence: immediately stop the motors of micro pump P2 and circulation pump P1, close all open valves (such as V1), trigger a high-priority alarm on the HMI with the content of purge pressure establishment failure, and put the entire sampling process into a suspended state, waiting for manual intervention.
[0051] S300: After the bypass line is replaced, based on the real-time signal from a first sensor used to monitor the liquid level in the sampling bottle, a bypass valve is controlled to open to execute a main sampling mode. This stage includes S310 to S340.
[0052] Before executing the S310 instruction to open the bypass valve V2, to prevent valve core sticking due to potential trace crystallization or polymerization of anhydrous hydrogen fluoride medium, which could affect sampling accuracy and even cause valve jamming, the central control unit M100 is configured to first call a valve health adaptive maintenance subroutine. The core of this subroutine relies on a valve health history database implemented as a circular buffer within the PLC power-off retention data area. This database is configured to store complete timing records of the most recent N (e.g., N=50) bypass valve V2 operations.
[0053] Specifically, during each V2 action (whether it's on or off), the high-precision timer inside the M100 records its action response time Δt. resp This time is defined as the time interval between the rising edge of the drive signal output by the DO module of M100 and the rising edge of the position signal returned by its DI module from the corresponding valve position feedback device (ZSO or ZSC). Before executing S310, the subroutine reads N Δtresp samples from the historical database and calculates their moving average μ and standard deviation σ. A dynamic viscosity threshold Threshold.sticky It is set to μ + 3σ. This subroutine will take the Δt from the previous operation. resp Compare with this dynamic threshold.
[0054] If the response time of the previous action exceeded the viscosity threshold, for example, if the normal opening time is 200ms and the previous record was 500ms, the system determines that the surface of the V2 valve core is highly likely to have viscosity caused by polymer crystallization. In response to this determination, M100 will not immediately execute the full-open command of S310, but will first trigger a micro-cavitation cleaning sequence. This sequence is programmed to drive the V2 solenoid valve with 3 to 5 consecutive pulses at a preset high frequency (e.g., 5Hz) with a duty cycle of 25% (e.g., 50ms for coil excitation, followed by 150ms of de-energization). This high-frequency vibration is designed to utilize the micro-cavitation effect caused by the sudden drop in local pressure in the fluid due to the rapid reciprocating motion of the valve core, and the subsequent micro-jet impact force generated by the collapse of cavitation bubbles, to break down and peel off the potential crystalline layer attached to the sealing surfaces of the valve core and valve seat. Only after this cleaning sequence is completed will the system continue to execute the formal opening command of S310. By integrating this adaptive maintenance mechanism, the system is endowed with the ability to self-heal against incremental failures at the physical level of the actuator, ensuring the long-term reliability of the sampling process.
[0055] S310: After the replacement timer in S230 finishes timing, the system determines that the bypass pipeline is ready for sampling. The central control unit M100 issues a command through its DO module to activate the solenoid valve of the bypass sampling valve V2, causing V2 to open. The opening of V2 establishes a fluid channel from the bypass pipeline to the sampling bottle below. Fresh anhydrous hydrogen fluoride, after being replaced, begins to flow into the bottle under the drive of the pressure difference, marking the formal start of the closed-loop control main sampling mode.
[0056] S320: From the moment V2 is activated, M100 allocates its primary control resources to real-time signal processing of the first sensor LS1 (level gauge). It acquires the analog input signal of LS1 at a frequency much higher than the system's main scan cycle (e.g., every 50 milliseconds via a timer interrupt service routine) and converts it into a level value in percentage (%) through a calibrated linear transformation. This level value is compared in real-time with a target level value (e.g., 66.7%) stored in the parameter area. As long as the current level value is less than the target level value, M100 maintains the valve-opening command to V2, allowing sampling to continue.
[0057] S330: This step is executed in parallel with S320. Throughout the duration of the main sampling mode, the antifragile control and fault response module M400 continuously applies its core fault fingerprinting algorithm to the real-time data stream of LS1. Figure 4 As shown, the algorithm continuously verifies whether the signal dynamics of LS1 conform to the physical model that the liquid level should rise monotonically and smoothly during continuous injection. If the algorithm identifies a predefined fault fingerprint, such as the signal not changing significantly within a few seconds (signal freeze) or the signal experiencing a large jump between adjacent sampling points that does not conform to hydrodynamics (signal jump), M400 will immediately set the critical fault flag FAULTLS1FAILURE to 1 in the global data block of M100. The main program of M100 is designed to perform a quick bit check on the FAULTLS1FAILURE flag bit before each comparison operation in its control loop for comparing liquid levels. Under normal circumstances, this bit is 0, and the process executes according to the predetermined logic. However, once M100 detects that this bit has been set to 1 by M400, it will immediately and unconditionally abort the current main sampling mode control loop and execute a program jump instruction, directly transferring execution privileges to the entry point of the safety degradation sub-mode defined by S350.
[0058] S340: Under normal circumstances, the LS1 level reading will rise steadily and continuously as sampling proceeds. When M100 detects that the current value of LS1level is greater than or equal to the target level (Targetlevel, 66.7%) for the first time, it determines that the sampling has reached the predetermined amount, and the main sampling mode task is completed. M100 interrupts the control loop of this mode and jumps the program execution authority to S410 to begin the sampling end and safety processing sequence.
[0059] This section elaborates on the core algorithm running in the antifragile control and fault response module M400 in S330.
[0060] This algorithm was developed to address a specific technical problem: how to distinguish between normal signal fluctuations and anomalous patterns indicating physical faults in sensors within an automated, unattended process, solely by analyzing the sensor's output data stream, thereby providing deterministic input for the system's antifragile decision-making. Its working principle is as follows: in a continuous liquid injection process driven by constant or slowly varying pressure, the change in liquid level within the container over time should be a continuously monotonically increasing function. Its rate of change (i.e., the speed of liquid level rise) is constrained by the laws of fluid dynamics and the container geometry, and should be relatively stable on a macroscopic time scale. Any signal behavior that significantly deviates from this physical model can be considered a high-probability fault event. The algorithm captures and analyzes the short-term dynamic characteristics of the signal in real time by maintaining a sliding time window and is configured with two parallel logical branches specifically for identifying the two most common sensor fault modes: signal freeze and signal jump.
[0061] In a specific implementation, the algorithm's operating parameters are set as follows: the system sampling frequency is set to 10Hz, meaning the central control unit M100 acquires an LS1 reading from the AI channel every 100 milliseconds (ms). The data window size, WINDOWSIZE, as a dimensionless integer, is set to 10, meaning each statistical analysis of the algorithm is based on data from the most recent second (10 sampling points). The signal freeze threshold, FREEZETHRESHOLD, as a floating-point number, is set to a minimum value matching the sensor resolution, for example, 0.01% (dimensionless) relative to the total height of the sampling bottle. The physical meaning of this threshold is that if the maximum change in liquid level is less than one ten-thousandth of the bottle height within a continuous second, then the liquid surface can be considered static on a macroscopic scale. The signal freeze duration, STABLEDURATION, as a floating-point number in seconds (s), is set to 3 seconds. This parameter is introduced to establish a time hysteresis, preventing momentary stillness caused by accidental signal transmission delays or minor system fluctuations from being misjudged as a fault. The stillness must persist for a sufficiently long time before being definitively identified as a fault. The signal jump threshold, JUMPTHRESHOLD, is a floating-point number expressed as a percentage (%), set to a large value far exceeding the probability of a normal physical process, such as 5.0% of the bottle height. Physically, this threshold means that a drastic change in liquid level exceeding 5% of its total height between two consecutive sampling points (i.e., within 0.1 seconds) is physically impossible and therefore can be definitively attributed to a signal anomaly.
[0062] The algorithm's execution flow is embedded in a periodically called function. The M400 module internally maintains a 10-bit First-In-First-Out (FIFO) queue, implemented as a circular buffer, serving as a sliding data window. Whenever a new LS1 reading, `currentvalue`, is passed to this function, the value is pushed onto the position pointed to by the queue's write pointer, while the write pointer moves forward one position (and handles the loop boundary), thus enabling the data window to slide over time.
[0063] The first logical branch of the algorithm is signal jump detection. Before storing new data into the window, the algorithm calculates the absolute difference ∆ between the new value currentvalue and the old value lastvalue recorded in the previous sampling period. Subsequently, ∆ is compared with JUMPTHRESHOLD (5.0%). If ∆ is greater than 5.0%, the algorithm immediately determines that a signal jump fault has occurred and directly returns a predefined fault status code, such as FAULTJUMP. This status code is then captured by the fault flag manager and used to set the FAULTS1FAILURE flag.
[0064] For example, suppose that at system timestamp t=135.0 seconds, lastvalue is 32.1%. At the next sampling point t=135.1 seconds, currentvalue suddenly changes to 40.5% due to interference or fault. The algorithm calculates ∆= |40.5% - 32.1%| = 8.4%. Since 8.4% is greater than the preset JUMP_THRESHOLD (5.0%), the algorithm immediately triggers fault detection.
[0065] If no signal jump is detected, the algorithm's execution flow enters the second logical branch: signal freeze detection. This branch is only activated after the data window (datawindow) is completely filled (i.e., the system has collected at least 10 data points). The algorithm traverses the 10 data points within the window, finding the maximum value (maxinwindow) and minimum value (mininwindow) through a linear scan. Then, it calculates their difference, i.e., the signal range (range = maxinwindow - mininwindow). This range value is compared to FREEZETHRESHOLD (0.01%). If the range is less than 0.01%, it means that the peak-to-peak fluctuation of the signal has been extremely small in the past second, and can be judged as being in a frozen state. At this point, the algorithm checks the status of an internal freeze timer. If this is the first time a freeze state is detected, the algorithm records the current system timestamp and starts the timer. In subsequent sampling periods, if the range remains less than 0.01%, the timer continues to accumulate. Once the timer records a continuous freeze time exceeding STABLEDURATION (3 seconds), the algorithm finally confirms a signal freeze fault and returns the FAULTFROZEN status code. If, during the continuous freezing process, the calculated range exceeds 0.01%, it indicates that the signal has resumed normal activity. The algorithm will immediately reset the timer to avoid misjudging a normal phase where the liquid level rises extremely slowly as a fault.
[0066] For example, suppose sampling proceeds normally until t=135.0 seconds, at which point the LS1 reading is 32.1%, and then the sensor malfunctions, locking its output at that value.
[0067] Within the time window [135.1s, 136.0s], the values of the 10 newly acquired sampling points are all 32.1%. At t=136.0s, the datawindow is filled. The algorithm calculates maxinwindow = 32.1% and mininwindow = 32.1%. Therefore, range = 0, which is less than FREEZETHRESHOLD (0.01%). The algorithm then starts the freeze timer at t=136.0s, setting the internal variable freezestarttime to 136.0.
[0068] Within the time window [136.1s, 137.0s], the new 10 sampling points are still all 32.1%. At t=137.0s, the algorithm recalculates the range, which is still 0, and checks the timer. The difference between the current time 137.0 and freezestarttime is 1 second, which is less than STABLE_DURATION (3 seconds), so no fault is triggered, and monitoring continues.
[0069] Within the time window [137.1s, 138.0s], the situation is the same. At t=138.0s, the difference between the current time and freezestarttime is 2 seconds, which is still less than 3 seconds.
[0070] Within the time window [138.1s, 139.0s], the situation is the same. At t=139.0s, the difference between the current time and freezestarttime is 3 seconds, which equals STABLEDURATION. At this point, the fault confirmation condition is met. The algorithm immediately returns the FAULTFROZEN status code, triggers the FAULTLS1FAILURE flag to be set, thereby guiding the main program to jump to S350 at the precise moment t=139.0s.
[0071] Through these two parallel detection logics based on explicit physical assumptions and quantified parameters, the M400 module can efficiently and accurately perform its immune surveillance function.
[0072] To further enhance the coverage of fault identification and identify zombie sensor faults (i.e., sensor circuitry jammed but outputting a constant, non-zero effective current, or internal filter circuit breakdown causing excessive signal smoothing) that traditional time-domain analysis methods cannot detect, the M400 module is also equipped with a spectrum integrity analyzer. The analyzer operates based on an inherent physical characteristic of the system: when the micro-pipeline pump P2 (as a diaphragm pump) is running, the periodic reciprocating motion of its diaphragm inevitably introduces a tiny pressure and level pulsation in the fluid corresponding to the pump stroke frequency. This pulsation signal, i.e., process noise, is the heartbeat of a healthy system operation. A properly functioning level sensor LS1 must be able to capture this weak but definitely present physical disturbance.
[0073] In one specific implementation, the spectral integrity analyzer is configured to perform a sliding window Fast Fourier Transform (FFT) on the data in the sensor data ring buffer. For example, the analyzer can be configured with a sliding window of 128 sampling points (corresponding to 12.8 seconds of data at a 10Hz sampling rate) and apply a Hamming window function to preprocess the data within the window to suppress spectral leakage. Based on this window data, the analyzer calculates a frequency domain spectrum. Assuming the operating frequency of the micro-pipeline pump P2 is calibrated to 2Hz, the core task of the analyzer is to search for an energy band centered at 2Hz (e.g., 1.8Hz to 2.2Hz) in each generated frequency domain spectrum.
[0074] The analyzer's decision logic is set as follows: it calculates the spectral energy integral within the 2Hz energy band and compares it with a preset noise floor threshold, Threshold_noise_floor. This noise floor threshold is not a fixed value but is dynamically determined during the S000 calibration step by recording the baseline noise spectrum statistics of the system under healthy operating conditions. If the calculated energy integral, Energy(f_pump), remains below this noise floor threshold, it indicates that the pump's pulsating characteristics have been completely lost in the LS1 signal, and the signal becomes abnormally "clean" or "flat." Based on this, the M400 module determines that although the first sensor LS1 is still outputting an electrical signal within the effective range, it has lost its dynamic response capability to the actual physical process. In response to this determination, the M400 sets a specific fault flag, such as FAULT_LS1_ZOMBIE, in the global data block of the central control unit M100. This flag has the same effect as FAULT_LS1_FAILURE, triggering the system to switch to the S350 safety degradation sub-mode. By introducing this spectral integrity analysis mechanism, this system is able to identify deep sensor faults that cannot be detected by traditional time-domain thresholding methods, significantly improving the completeness of fault identification and the triggering accuracy of antifragile logic.
[0075] S350: Upon detecting the faulty fingerprint, the sampling mode is switched from the primary sampling mode to a security degradation sub-mode to complete the sampling. This stage includes S350a to S353.
[0076] S350a: In response to the detection of the FAULTLS1FAILURE flag in S332, the system does not immediately enter open-loop timed sampling. Instead, it first performs a critical operating pressure verification. The purpose of this step is to verify whether the current macroscopic operating condition of the system is consistent with the operating condition during the timing parameter calibration, thereby ensuring the accuracy of the timed sampling. The central control unit M100 immediately reads the current real-time pressure PT1current of the circulating pipeline pressure sensor PT1. Subsequently, it reads the reference pressure Pbase stored in the calibration step S010 from its power-off retained data block. Based on these two values, the relative deviation Deviation = |PT1current - Pbase| / Pbase is calculated. The system presets a pressure stability window threshold, for example, 5%. If the calculated Deviation is less than 5%, the system determines that the current operating condition is stable and comparable to that during calibration, and therefore suitable for accurate timed sampling. The process continues to execute S351. However, if the deviation is greater than or equal to 5%, for example, Pbase is 1.02 kg / cm², while PT1_current is 1.10 kg / cm², the deviation reaches 7.8%. This means that the upstream pressure is significantly higher than the calibration condition. If sampling continues at the original time interval, it will lead to unacceptable oversampling. In this case, M100 will determine that the preconditions for performing timed sampling are not met. It will immediately stop the sampling process and jump directly to the S410 safety shutdown sequence, shutting down all valves and pumps. At the same time, it will push a specific, diagnostic alarm message to the HMI: Timed sampling mode aborted: Upstream pressure fluctuation exceeds limits, current pressure 1.10 kg / cm², reference pressure 1.02 kg / cm².
[0077] S351: After the pressure calibration of S350a is successfully passed, M100 officially initiates the safety degradation sub-mode, sending a clear warning message to the HMI via the communication interface, informing the operator that the level sensor LS1 has malfunctioned and the system has automatically switched to timed sampling mode. At the same time, M100 immediately starts an internal high-precision hardware timer and sets the preset value of the timer to the safe timed sampling duration Tsafe calculated and stored in the S010 calibration step.
[0078] S352: After the timer is triggered, hardware subtraction counting begins, starting from the value of Tsafe. During this period, M100 maintains the opening command to the bypass valve V2, allowing anhydrous hydrogen fluoride to continue flowing into the sampling bottle. At this point, the system's control logic is completely independent of the LS1 sensor, and the sampling process is entirely controlled by this precise time base.
[0079] S353: A hardware interrupt is generated when the internal timer count reaches 0. In response to this interrupt, M100 determines that the timing sampling process has ended. It immediately interrupts the mode and jumps the program's execution privileges to S410 to begin the final safety processing.
[0080] S400: End and safety procedures phase.
[0081] This phase, comprising S410 to S440, is the final safety sequence that must be executed for each sampling process, whether it is successfully completed in main mode or degraded mode.
[0082] S410: In response to a program jump from S340 (Main Mode Complete) or S353 (Degradation Mode Complete), this step is executed to shut off all power sources. M100 immediately closes the solenoid coil of the bypass valve V2 via the DO module de-energize, thereby cutting off the flow of liquid into the sampling bottle. Then, following a preset safety sequence, commands are issued sequentially to stop the operation of the micro-inline transfer pump P2, and then to stop the operation of the circulation pump P1.
[0083] S420: After M100 confirms via motor feedback or a delay that all pumps have stopped operating, a pipeline purging sequence is initiated. Its purpose is to remove residual anhydrous hydrogen fluoride liquid and gas from the sampling vial connection point to valve V2, preventing any potential chemical exposure during operator disassembly of the sampling vial. M100 instructs the opening of exhaust gas vacuum valve V3. V3 is connected to a system with a stable negative pressure; its opening draws the residue in this section of pipeline back into a safe chemical treatment system. This process is controlled by an internal timer set for 30 seconds to ensure complete evacuation.
[0084] S430: After the vacuum back suction timer ends, M100 issues a command to close valve V3. To ensure the system returns to its safest initial state, a status check is also performed to confirm and close all other valves that may be open, such as recirculation valve V1.
[0085] S440: At this point, all physical operations in the entire automated sampling process are complete. The M100 sends a final status message, such as "sampling complete," to the HMI in the central control room via industrial Ethernet. If the process switched to degraded mode during the process, this message will include a corresponding event log, such as "sampling complete (LS1 fault in timed mode)." At this time, a clear green indicator light or information box will be displayed on the HMI interface, authorizing the field operator to safely proceed to the operating area to disassemble and remove the sample vials that have completed sampling.
[0086] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit described above can be implemented in hardware.
[0087] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. An automatic sampling and control method for anhydrous hydrogen fluoride, characterized in that, The method includes: In response to a sampling command, a circulation pump and a circulation valve are opened to establish fluid circulation within a main pipeline; After the fluid circulation is established, a miniature pipeline delivery pump is turned on to replace a bypass pipeline connected to the main pipeline. After the bypass line is replaced, a bypass valve is opened based on the real-time signal from a first sensor used to monitor the liquid level in the sampling bottle to execute a main sampling mode. During the execution of the main sampling mode, the real-time signal of the first sensor is continuously monitored to identify a preset fault fingerprint; Furthermore, upon identifying the faulty fingerprint, the sampling mode is switched from the main sampling mode to a security degradation sub-mode to complete the sampling.
2. The method according to claim 1, characterized in that, The step of identifying a preset fault fingerprint includes: Acquire multiple consecutive sampled values of the first sensor within a preset time window; Furthermore, based on the statistical characteristics of the multiple consecutive sampled values, it is determined whether the real-time signal of the first sensor has signal freeze or signal jump, as a fault fingerprint.
3. The method according to claim 2, characterized in that, The step of determining whether there is signal freeze in the real-time signal of the first sensor based on the statistical characteristics of the multiple consecutive sampled values includes: Calculate the difference between the maximum and minimum values of the plurality of consecutive sampled values within the time window; Furthermore, if the difference is less than a first preset threshold and the duration of the state exceeds a preset duration, then it is determined that the real-time signal is frozen.
4. The method according to claim 1, characterized in that, The security degradation sub-mode is a time-based quantitative sampling mode, and the steps of switching to a security degradation sub-mode include: Start a timer, the duration of which is a preset safe timed sampling duration; And, when the timer ends, the bypass valve is controlled to close.
5. The method according to claim 4, characterized in that, The method further includes a calibration step performed prior to the sampling command response, the calibration step comprising: Perform at least one standard sampling procedure under manual monitoring, and record the time required from the opening of the bypass valve to the first sensor detecting that the liquid level has reached the preset target liquid level, so as to obtain an average sampling time. And record the stable pressure reading in the main pipeline monitored by a second sensor during the standard sampling process to obtain a reference pressure; Furthermore, the safe timed sampling duration is determined based on the average sampling time and a safety factor.
6. The method according to claim 5, characterized in that, The step of switching to a security degradation sub-mode, before starting the timer, further includes: Obtain the real-time pressure in the main pipeline currently monitored by the second sensor; Compare the real-time pressure with the reference pressure; Furthermore, the timer is activated only when the deviation between the real-time pressure and the reference pressure is less than a second preset threshold.
7. The method according to claim 1, characterized in that, The method further includes, after responding to the sampling command and before controlling the circulation pump and the circulation valve to open: Perform a pre-start sensor self-test, which includes acquiring static signals from the first sensor and at least one pressure sensor. Furthermore, subsequent steps will only be executed if the static signals are within their respective reasonable standby ranges.
8. An automatic sampling and control system for anhydrous hydrogen fluoride, characterized in that, The system includes: A process actuator module includes a circulating pump, a circulating valve, a micro pipeline pump, and a bypass valve; A multi-source sensing module, including a first sensor for monitoring the liquid level in a sampling bottle; And, a central control unit, the central control unit being configured as follows: In response to a sampling command, the circulation pump and the circulation valve are controlled to open to establish fluid circulation within a main pipeline; After the fluid circulation is established, the micro pipeline delivery pump is turned on to replace a bypass pipeline connected to the main pipeline. After the bypass pipeline is replaced, based on the real-time signal from the first sensor, the bypass valve is controlled to open to execute a main sampling mode. During the execution of the main sampling mode, the real-time signal of the first sensor is continuously monitored to identify a preset fault fingerprint; Furthermore, upon identifying the faulty fingerprint, the sampling mode is switched from the main sampling mode to a security degradation sub-mode to complete the sampling.
9. The system according to claim 8, characterized in that, The central control unit also incorporates an antifragile control and fault response module, which is configured as follows: Acquire multiple consecutive sampled values of the first sensor within a preset time window; Furthermore, based on the statistical characteristics of the multiple consecutive sampled values, it is determined whether the real-time signal of the first sensor has signal freeze or signal jump, so as to serve as the fault fingerprint, and a fault flag bit is generated for the central control unit to call.
10. The system according to claim 8 or 9, characterized in that, The security degradation sub-mode is a time-based quantitative sampling mode, and the central control unit is configured to, when switching to the security degradation sub-mode: Start an internal timer, the duration of which is a preset safe timed sampling duration; And, when the timer ends, the bypass valve is controlled to close.
Citation Information
Patent Citations
Surface water sampling port position-adjustable sampling device and control method
CN119198191A
Dust collecting bag breaking detection device and control method
CN120801125A
Cheese filling flow real-time calibration control method and system
CN121106874A
Automatic sealed sampler of chemical pipeline
CN205138811U
Panel mount socket locking apparutus
KR102162087B1