Water industry control risk prediction system based on intelligent management

By acquiring the underlying physical operation data of the water pump unit, using energy conservation to calculate the virtual flow benchmark and acoustic high-frequency characteristics to generate the cavitation index, cross-domain joint reasoning identifies data tampering and physically induced cavitation risks in the water industry control system, solving the problem that existing technologies cannot identify deep-seated covert attacks, and achieving system security and stability.

CN122018414AInactive Publication Date: 2026-05-12TSG (SHENZHEN) INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
TSG (SHENZHEN) INTELLIGENT TECH CO LTD
Filing Date
2026-04-10
Publication Date
2026-05-12
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing industrial control security systems are unable to identify physical operation commands and sensor feedback data tampered with by hackers under deep, covert attacks, leading to equipment damage or water quality exceeding standards in water industrial control systems even when the data message logic is normal.

Method used

By acquiring the underlying physical operation data of the water pump unit, the virtual flow benchmark is calculated using the energy conservation relationship, and the cavitation index is generated by combining the effective net positive suction head (NPSH) of the device with the acoustic high-frequency characteristics. Cross-domain joint reasoning identifies the risks of data tampering and physically induced cavitation, and a physical verification channel independent of the industrial control network is established.

Benefits of technology

Effectively identify maliciously concealed physical and biochemical risks, avoid equipment damage or water quality exceeding standards, and ensure system safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122018414A_ABST
    Figure CN122018414A_ABST
Patent Text Reader

Abstract

The invention discloses a water affair industrial control risk prediction system based on intelligent management, and relates to the technical field of industrial control system safety, and the system comprises a data collection module which obtains bottom layer physical operation data and process monitoring data; the virtual flow back calculation module is used for carrying out back calculation on a virtual flow reference based on the motor electric power; the trust residual analysis module is used for calculating a dynamic residual and a change rate between the network flow and the virtual flow reference; the cavitation state diagnosis module is used for generating an acoustic-electromechanical coupling cavitation index by combining the inlet pressure, the virtual flow and the volute acoustic characteristics; the cross-domain joint reasoning module is used for judging a data tampering risk and triggering a first response when the residual change rate is in positive correlation with the dosing frequency, and judging a physical induced cavitation risk and triggering a second response when the cavitation index is out of limit and a water inlet reducing instruction exists or the flow is suddenly reduced; according to the invention, industrial control network data credibility verification and physical security threat cooperative detection are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial control system security technology, and in particular to a water industry control risk prediction system based on intelligent management. Background Technology

[0002] The water industry control risk prediction system based on intelligent management is mainly applied to key infrastructure fields such as urban water supply and sewage treatment. By integrating sensor monitoring, automatic control and data analysis technologies, it realizes remote scheduling and safety monitoring of core process equipment such as water pump units, dosing systems and pipeline gates.

[0003] Existing industrial control system security protection systems typically employ network-side firewalls or anomaly detection based on information protocols. Their design relies on the integrity of network layer traffic packets to determine system status. However, in specific scenarios subjected to deep, covert attacks, hackers can simultaneously tamper with physical operation commands issued by the host computer (such as slightly closing a water inlet gate to induce cavitation) and false monitoring data fed back by sensors (such as fabricating large flow rates to induce excessive dosing). This synchronous deception of "command-feedback" means that existing technologies, lacking cross-verification of underlying physical authenticity, cannot identify maliciously concealed physical damage and biochemical risks. This can lead to equipment damage or water quality exceeding standards even when the data packet logic appears normal.

[0004] Therefore, a water industry control risk prediction system based on intelligent management is proposed. Summary of the Invention

[0005] To address the shortcomings of existing technologies, this invention provides a smart management system for predicting water industry control risks.

[0006] To achieve the above objectives, the technical solution of the present invention is as follows: According to one aspect of this application, a water industry control risk prediction system based on intelligent management is provided, comprising: The data acquisition module is used to acquire the underlying physical operation data of the pump unit as well as the process monitoring data and control commands in the industrial control network. The underlying physical operation data includes the motor input power, pump inlet pressure and volute acoustic emission signal, and the process monitoring data includes the flow count value read from the network. The virtual flow inverse calculation module is used to inversely calculate the physical flow rate through the water pump based on the energy conservation relationship, according to the input power of the motor and the preset water pump characteristic curve, and use it as the virtual flow rate benchmark. The Trust Residual Analysis module is used to calculate the dynamic residual between the traffic count value read by the network and the virtual traffic baseline, and to extract the rate of change of the dynamic residual over time. The cavitation status diagnosis module is used to calculate the effective net positive suction head (NPSH) of the device based on the pump inlet pressure and virtual flow reference, and couple the effective NPSH of the device with the high-frequency energy characteristics of the acoustic emission signal of the volute to generate an acoustic-electromechanical coupling cavitation index that characterizes the severity of cavitation. The cross-domain joint inference module is used to perform joint inference based on the rate of change of dynamic residuals, the dosing frequency in process monitoring data, the acoustic-mechanical coupling cavitation index, and control commands. If the rate of change of the dynamic residual meets the preset mutation threshold condition and the dosing frequency is positively correlated with the flow count value, then it is determined that there is a risk of data tampering and the first security response is triggered. If the acoustic-mechanical coupling cavitation index exceeds the preset safety threshold and there is a control command to reduce the water pump inlet flow or a sudden drop in the virtual flow benchmark, then it is determined that there is a risk of physical induced cavitation and a second safety response is triggered.

[0007] According to another aspect of this application, a method for predicting control risks in the water industry based on intelligent management is provided, including: The system acquires the underlying physical operation data of the pump unit, as well as the process monitoring data and control commands from the industrial control network. The underlying physical operation data includes the motor input power, pump inlet pressure, and volute acoustic emission signal, while the process monitoring data includes the flow count value read from the network. Based on the input power of the motor and the preset pump characteristic curve, the actual physical flow rate through the pump is calculated based on the energy conservation relationship, and used as a virtual flow rate benchmark. Calculate the dynamic residual between the traffic count value read by the network and the virtual traffic baseline, and extract the rate of change of the dynamic residual over time; The effective net positive suction head (NPSH) of the device is calculated based on the pump inlet pressure and virtual flow reference. The effective NPSH of the device is then coupled with the high-frequency energy characteristics of the acoustic emission signal from the volute to generate an acoustic-electromechanical coupling cavitation index that characterizes the severity of cavitation. Based on the rate of change of dynamic residuals, the dosing frequency in process monitoring data, the acoustic-mechanical coupling cavitation index, and joint inference of control command execution: If the rate of change of the dynamic residual meets the preset mutation threshold condition and the dosing frequency is positively correlated with the flow count value, then it is determined that there is a risk of data tampering and the first security response is triggered. If the acoustic-mechanical coupling cavitation index exceeds the preset safety threshold and there is a control command to reduce the water pump inlet flow or a sudden drop in the virtual flow benchmark, then it is determined that there is a risk of physical induced cavitation and a second safety response is triggered.

[0008] Compared with the prior art, the beneficial effects of the present invention are as follows: By acquiring tamper-proof underlying physical operation data (motor input power, pump inlet pressure, and acoustic emission signals), a virtual flow benchmark is calculated based on the energy conservation relationship. Furthermore, the effective net positive suction head (NPSH) of the device and high-frequency acoustic characteristics are combined to generate the cavitation index. Cross-domain joint reasoning is then performed with process monitoring data and control commands on the network side, establishing a physical verification channel independent of the industrial control network. This enables the system to effectively identify maliciously concealed physical damage (such as cavitation induced by slightly closing the inlet gate) and biochemical risks (such as excessive dosing induced by falsifying large flow rates) even when the data message logic appears normal. This fundamentally avoids equipment damage or water quality exceeding standards. Attached Figure Description

[0009] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0010] Figure 1 This is an overall block diagram of the system according to Embodiment 1 of the present invention.

[0011] Figure 2 This is an overall block diagram of the method in Embodiment 2 of the present invention. Detailed Implementation

[0012] Hereinafter, exemplary embodiments according to this application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this application, and not all embodiments of this application. It should be understood that this application is not limited to the exemplary embodiments described herein.

[0013] Example 1: As Figure 1 As shown, the water industry control risk prediction system based on intelligent management includes: To facilitate understanding, we will use a secondary booster pumping station of a city's waterworks as an example. Assume the station is equipped with a 75kW centrifugal pump to lift raw water from the primary storage tank to the secondary treatment plant. The pump's design flow rate is 200 m³ / h, head is 32m, impeller diameter is 280mm, and rotation speed is 1450 rpm. The station's control system monitors the upstream inlet gate opening, electromagnetic flowmeter readings, and the operating frequency of the downstream coagulant dosing pump via a SCADA network. Under normal operating conditions, the flowmeter displays a real-time flow rate of approximately 180 m³ / h. The coagulant dosing pump automatically adjusts the dosage proportionally based on this flow rate, with the dosage set at 15mg of polyaluminum chloride per cubic meter of raw water.

[0014] The data acquisition module is used to acquire the underlying physical operating data of the pump unit, as well as process monitoring data and control commands from the industrial control network. The underlying physical operating data includes the motor input power, pump inlet pressure, and volute acoustic emission signals, while the process monitoring data includes flow rate counts read from the network.

[0015] Specifically, when the data acquisition module obtains the underlying physical operating data of the pump unit, it acquires the motor input power through an out-of-band hardwired high-frequency current transformer. Here, "out-of-band" means that the acquisition channel is independent of the industrial control network, directly acquiring analog signals from the three-phase current transformers and voltage transformers of the motor power supply circuit. The instantaneous active power is then calculated by the power transmitter. The sampling frequency was set to 100Hz, far exceeding the typical scan cycle of industrial control networks (usually 1-10 seconds), ensuring the ability to capture power spikes caused by attacks. Because this acquisition channel does not pass through a programmable logic controller (PLC) or host computer software, malicious code cannot tamper with its readings. This constitutes the first unforgeable physical anchor point.

[0016] Using the aforementioned pump station example, under normal operating conditions, the current transformer measures the three-phase currents as follows: , , With a line voltage of 380V and a power factor of 0.88, the calculated input power of the motor is... kW.

[0017] Simultaneously, the pump inlet pressure is acquired via a pressure transmitter installed at the pump inlet. This pressure transmitter is installed approximately 0.5 meters before the pump suction flange, with a measurement range of -0.1 to 0.5 MPa (gauge pressure), and outputs a 4-20 mA standard signal. It should be noted that the pump inlet pressure... It is a key parameter for assessing cavitation risk. When the upstream intake gate is maliciously partially closed, the local drag coefficient increases sharply. According to Bernoulli's equation, the increased flow velocity leads to an increase in dynamic pressure, while the static pressure decreases accordingly. Decline. If Reduced to near or below the saturated vapor pressure at the current water temperature Water vaporizes at the impeller inlet, forming bubbles that then collapse in the high-pressure zone, causing cavitation.

[0018] Using the aforementioned pump station example, under normal operating conditions, the pressure transmitter measures an inlet gauge pressure of 0.02 MPa, which, when converted to absolute pressure... MPa. Assuming the current water temperature is 20℃, refer to the table for the saturated vapor pressure. If the inlet pressure is at kPa, then the inlet pressure is much higher than the saturated vapor pressure, and there is no risk of cavitation.

[0019] Furthermore, acoustic emission signals from the pump casing are acquired using an acoustic sensor attached to its surface. Acoustic emission (AE) refers to transient elastic waves generated by the rapid release of energy from a material or structure under stress. During pump cavitation, the microjet generated when bubbles collapse impacts the metal surface, exciting high-frequency sound waves ranging from tens of kHz to several MHz. This application uses a piezoelectric ceramic sensor with a resonant frequency of 150 kHz, attached to the outer wall of the casing via a magnetic base. The signal is amplified by a preamplifier and acquired by a high-speed data acquisition card at a sampling rate of 500 kHz. To extract cavitation characteristics, the original AE signal is bandpass filtered (100-200 kHz), and then the root mean square energy within a sliding time window (1 second) is calculated. This energy value can effectively characterize the severity of bubble bursting.

[0020] Using the aforementioned pump station example, under normal operating conditions, the high-frequency root-mean-square energy output by the acoustic sensor... Approximately 12mV, this value is used as the baseline energy for cavitation-free operation. When cavitation occurs, It can jump to several times or even dozens of times the baseline value within seconds.

[0021] While acquiring underlying physical operation data, the data acquisition module also obtains process monitoring data and control commands from the industrial control network. Process monitoring data includes flow count values ​​read from the network. This data is uploaded to the SCADA system via Modbus TCP protocol from an electromagnetic flow meter installed on the pump outlet pipe. Control commands include the opening command of the upstream inlet gate and the frequency setpoint of the downstream coagulant dosing pump. It is important to emphasize that this data transmitted through the industrial control network is at risk of tampering: attackers could forge flow meter readings by infiltrating the PLC or using a man-in-the-middle attack, or hijack gate control commands. Therefore, industrial control network data cannot be used as a reliable physical anchor and must be cross-verified with the underlying physical operation data.

[0022] Using the aforementioned pump station example, the SCADA system displays the flow meter readings. The coagulant dosing pump automatically adjusts its frequency based on this reading, currently operating at 36Hz (corresponding to a dosing flow rate of approximately 2.7kg / h). Simultaneously, the system record shows the inlet gate opening is 85%, and no abnormal gate closure command has been received.

[0023] Through the above scheme, the data acquisition module achieves synchronous acquisition of multi-source heterogeneous data from the water pump system, including tamper-proof underlying physical signals. , , It also includes potentially contaminated industrial control network data. (Control commands). This dual-channel acquisition architecture of "physical anchor point + network data" lays the data foundation for subsequent cross-domain verification, enabling the system to identify data tampering and control command anomalies in the network layer through the self-consistency of physical laws.

[0024] The virtual flow inverse calculation module is used to inversely calculate the actual physical flow rate through the water pump based on the motor input power and a preset water pump characteristic curve, using the energy conservation relationship as a virtual flow benchmark. This is one of the core innovations of this application. Traditional flow monitoring relies entirely on networked instruments such as electromagnetic flow meters. Once an attacker forges flow readings by tampering with Modbus messages or hijacking PLC logic, the downstream dosing control system will make decisions based on incorrect flow information, leading to the risk of poisoning. This application establishes the first physical anchor point by constructing a physical verification channel independent of the industrial control network and utilizing the inherent characteristics of the water pump as an energy conversion device to inversely calculate the actual flow rate from the unalterable electrical power.

[0025] This module operates based on the law of conservation of energy in centrifugal pumps. The electrical energy input from the power grid... After the energy is converted into mechanical energy by the motor, the effective mechanical power transmitted to the pump shaft after deducting the losses of the motor body and transmission device is called shaft power. This portion of mechanical energy is converted into pressure energy and kinetic energy of the fluid by doing work on it through the impeller. At a constant speed, the shaft power of the water pump... With the flow rate through the water pump There exists a strict physical mapping relationship between them, which is determined by the hydraulic characteristic curve of the water pump and can usually be expressed by a quadratic polynomial. Therefore, as long as the input electrical power of the motor is measured... And the motor transmission efficiency is known. By combining the pump characteristic curve parameters, the flow rate can be calculated inversely by solving algebraic equations. .this Bypassing potentially tampered flow meters It is derived directly from the physical law of energy conservation and is therefore unforgeable.

[0026] Specifically, the virtual flow inversion module calculates the actual physical flow rate through the pump based on the motor input power and the preset pump characteristic curve, according to the energy conservation relationship. This includes the following steps: First, the input electrical power of the motor is converted into the power of the water pump shaft according to the preset motor transmission efficiency. Motor transmission efficiency. This refers to the proportion of electrical power input to a motor that is converted into mechanical power output, with the remainder dissipated as iron losses, copper losses, mechanical friction, etc. For common three-phase asynchronous motors... The value is typically between 0.85 and 0.95; specific values ​​can be obtained from the motor nameplate or factory test report. In this application, The parameters are stored in the system as presets and can also be updated through periodic motor efficiency tests. Pump shaft power. The calculation formula is: ; It should be noted that the motor transmission efficiency The efficiency will vary at different load rates, but the variation is small near the rated load (typically 75%-100% of rated power). For higher accuracy, a load rate-dependent efficiency curve can be used. However, in practical engineering, the constant efficiency under rated operating conditions is sufficient to meet the accuracy requirements of attack detection, because the flow deviation caused by the attack is usually much greater than the error caused by efficiency fluctuations.

[0027] Using the aforementioned pump station example, under normal operating conditions, the motor input power... kW. Referring to the motor's manufacturer's specifications, the rated efficiency is... Therefore, the pump shaft power kW.

[0028] Then, obtain a pre-calibrated polynomial characteristic curve model of the relationship between pump shaft power and flow rate. (Centrifugal pump shaft power-flow rate characteristic curve) The curve reflects the relationship between shaft power and flow rate at a constant rotational speed. According to fluid mechanics theory, this curve typically exhibits an upward-opening parabolic shape and can be fitted using a quadratic polynomial: ; in, , , The polynomial coefficients of the characteristic curve are respectively, with units of . , and These coefficients can be obtained in the following ways: One method is to extract multiple operating points from the performance curves provided by the water pump manufacturer. The data pairs are fitted using the least squares method to obtain polynomial coefficients. For example, data such as the rated operating point (flow rate 200 m³ / h, shaft power 45 kW), maximum flow point (flow rate 280 m³ / h, shaft power 62 kW), and valve closing point (flow rate 0 m³ / h, shaft power 28 kW) are extracted from the factory test report, and determined through three-point or more-point fitting. , , .

[0029] Secondly, during the pump installation and commissioning phase, data is obtained through on-site calibration experiments. The specific procedure is as follows: Under conditions of known accurate flow rate (e.g., calibration using an ultrasonic flow meter or volumetric method), the valve opening is adjusted to allow the pump to operate under different flow conditions, and the motor power and flow rate are recorded simultaneously, plotting the measured values. The curve is fitted with a polynomial. This method can take into account factors such as on-site pipeline resistance and installation deviations to obtain characteristic curves that better reflect actual operating conditions.

[0030] Third, for water pumps that have been running for a period of time, online identification can be performed using historical operating data. This can be achieved by collecting data from pumps operating under normal conditions. The data pair (assuming the flow meter has not been tampered with) is combined with... The polynomial coefficients are dynamically updated using methods such as recursive least squares or Kalman filtering to adapt to the slow drift of the characteristic curve caused by impeller wear, scaling, etc.

[0031] It is important to emphasize that the calibration accuracy of the characteristic curve directly affects the accuracy of virtual traffic inversion. In this application, it is assumed that the characteristic curve remains stable in the short term (e.g., several months), the curve drift caused by mechanical wear is extremely slow (months / years), while the traffic deviation caused by an attack is abrupt or sudden (seconds / minutes). Therefore, even if the characteristic curve has a certain static error, as long as the attack detection depends on the time derivative of the traffic deviation (i.e., the mutation rate), it can effectively distinguish between attacks and equipment aging.

[0032] Continuing with the previous pump station example, assuming the pump's performance curve is provided at the factory, we fit the data by extracting three typical operating points: valve-closing point (0 m³ / h, 28 kW), rated point (200 m³ / h, 45 kW), and maximum flow point (280 m³ / h, 62 kW). Converting the flow rate to m³ / s (200 m³ / h = 0.0556 m³ / s, 280 m³ / h = 0.0778 m³ / s) and the power to W (45 kW = 45000 W), we use the least squares method to fit the polynomial coefficients. W·s² / m 6 , W·s / m³, W. This characteristic curve model is stored in the virtual traffic inverse calculation module as a benchmark for subsequent calculations.

[0033] Finally, the pump shaft power is substituted into the polynomial characteristic curve model, and the physically valid real roots are obtained by solving the polynomial equations, serving as a virtual flow reference. The values ​​calculated in the preceding steps are then used... Substituting into the characteristic curve equation, we obtain information about virtual traffic. The quadratic equation of : ; Organize into standard format: ; According to the quadratic formula, the solution to this equation is: ; Since physical flow rates must be non-negative real numbers, the solution results need to be filtered. First, the discriminant The value must be non-negative; otherwise, the equation has no real solutions, indicating that the measured value is... This exceeds the effective range of the water pump characteristic curve, which may be due to sensor malfunction or abnormal data. Under normal circumstances, It should fall within the operating range of the water pump, and the discriminant should always be positive.

[0034] Secondly, the equation has two real roots, but only one root has physical meaning. This is because of the coefficients... (The parabola opens upwards). The values ​​are usually positive, so one of the two roots is positive and the other is negative or a smaller positive value. In practical engineering, the larger positive root is chosen as the virtual flow. : ; It should be noted that if the water pump is operating at extremely low flow rates (close to valve closure), both roots may be positive. In this case, the root closer to the current operating state should be selected. However, under typical water supply conditions, the water pump usually operates near its rated flow rate, and the positive root given by the above formula is the only reasonable solution.

[0035] Using the aforementioned pumping station example, Substitute W into the characteristic curve equation: ; Summarized as follows: ; Calculate the discriminant: ; Solving for the given information, we get: ; Converted to m³ / h: m³ / h.

[0036] Compare the traffic count values ​​read from the industrial control network. m³ / h, virtual traffic There is approximately a 9% deviation from the target flow rate (m³ / h). This deviation may originate from flow meter measurement errors, characteristic curve fitting errors, or motor efficiency estimation errors. Under normal operating conditions, this deviation should remain stable and within a reasonable range (e.g., ±10%). A sudden increase in deviation or a time derivative exceeding a threshold indicates potential flow meter data tampering.

[0037] Through the above scheme, the virtual traffic inverse calculation module realizes the physical reverse calculation from electrical power to traffic flow, constructing a traffic verification channel independent of the industrial control network. The core advantage of this design is: First, virtual traffic The calculations are based entirely on physical laws (energy conservation) and immutable underlying signals (electric power), making it impossible for attackers to forge them through network layer methods. Unless the current transformer is physically damaged or the characteristic curve parameters are tampered with, such physical intrusions are far more difficult and risky than cyberattacks.

[0038] Second, virtual traffic and network traffic meter readings. residual This becomes a key indicator for detecting flow meter tampering. If an attacker forges a large flow rate to induce excessive addition of coagulant, then... It will be significantly larger than residual The number of cases increased rapidly, triggering a poisoning attack alert.

[0039] Third, the virtual flow inverse calculation module has low computational complexity, involving only solving first and second quadratic equations, and can run in real time on an embedded controller, meeting the real-time requirements of industrial sites.

[0040] Fourth, this method is robust to slow drifts in the pump characteristic curve. Because attack detection relies on the time derivative of the flow deviation rather than its absolute value, even if the characteristic curve drifts slowly due to impeller wear (leading to...), it is still effective against such slow drifts. (Static bias exists), meaning that as long as the traffic surge caused by the attack is much faster than the drift rate, it can be effectively identified. Furthermore, the accuracy of long-term operation can be further improved by dynamically correcting the characteristic curve coefficients through periodic online calibration or adaptive parameter update mechanisms.

[0041] It should be noted that the effectiveness of the virtual flow inverse calculation module depends on the following assumptions: the water pump operates in a quasi-steady state during the sampling period, and the fluid inertial force during the transient start-up process is ignored; the processing medium is room temperature water with a density of... These assumptions are considered constant; the pump characteristic curve remains stable in the short term, and the drift rate caused by mechanical wear is much slower than the abrupt change rate caused by an attack. These assumptions are reasonable in typical urban water supply scenarios, but under special operating conditions (such as variable frequency speed control, changes in medium density, and severe pump aging), correction mechanisms may need to be introduced, such as performing similar conversions of the characteristic curve based on the rotational speed, or adjusting the shaft power calculation formula based on the medium density.

[0042] Specifically, the time derivative processing of the dynamic residuals to obtain the time derivative sequence of the dynamic residuals includes: Differential operations are performed on the dynamic residuals at adjacent time points within a time window to calculate the sequence of residual change rates over time. The core idea of ​​time derivative calculation is to capture the instantaneous trend of residual change. Physically, under normal operating conditions, the flowmeter measurement error and characteristic curve fitting error are relatively stable, causing the dynamic residual to fluctuate slowly within a normal range, with its time derivative close to zero. However, flowmeter tampering caused by network attacks is a transient disturbance that causes the residual to change drastically in a very short time, and its time derivative will deviate significantly from the normal baseline. Therefore, by detecting abrupt changes in the residual time derivative, poisoning attacks at the network layer can be effectively identified.

[0043] Specifically, the discrete formula for calculating the time derivative is: ; in, The sampling period is and These are the dynamic residuals at the current time and the previous time, respectively.

[0044] Using the previous pump station example, suppose that at the 50th second, an attacker compromises the SCADA system and alters the value in the flow meter's Modbus register from 180 m³ / h to 280 m³ / h (faking a large flow rate to induce excessive dosing). Due to the virtual flow... Calculated independently of the physical signal, it does not change with tampering, therefore the dynamic residual... The residual will jump from the normal value of -0.0044 m³ / s to 0.0233 m³ / s, with a jump of 0.0277 m³ / s. If the sampling period... If the time derivative of the residual jumps instantaneously to approximately 2.77 m³ / s², it far exceeds the derivative threshold under normal operating conditions. (For example, 0.1 m³ / s²). This drastic change in the residual derivative clearly indicates anomalies in the network traffic data, triggering a poisoning attack alert.

[0045] It should be noted that the time derivative detection in this application targets the abrupt change rate of the residuals, rather than the absolute value of the residuals. This design has significant engineering implications: on the one hand, the pump characteristic curve may drift due to slowly changing factors such as impeller wear and scaling, leading to virtual flow... There is a certain static deviation between the actual traffic and the actual traffic. The existence of the static deviation will affect the residual. While a deviation from zero is possible, as long as the deviation is slow, its time derivative remains close to zero and will not trigger a false alarm. On the other hand, flow meter tampering caused by a network attack is a step or abrupt change, and its residual time derivative is much larger than normal fluctuations, making it easily identifiable.

[0046] Smoothing filtering is applied to the time derivative sequence, and the filtered result is used as the rate of change of the dynamic residual over time. Specifically, this includes: A low-pass filter is applied to the calculated residual time derivative sequence to eliminate high-frequency noise interference, outputting a smoothed rate of change signal. Various electromagnetic interference sources exist in industrial environments (such as frequency converters and the start / stop of high-power motors). These interferences may superimpose on the power measurement signal, affecting the accuracy of virtual flow calculation and causing the residual time derivative sequence to contain high-frequency noise. Directly using the original derivative sequence for threshold judgment can easily lead to false alarms. Therefore, a filtering algorithm is needed to extract the main trend components of the derivative sequence to improve the reliability of detection.

[0047] The specific filtering method can be any of the following: One method is moving average filtering. Within a preset filtering window (e.g., taking 5 to 10 sampling points), the time derivative sequence is arithmetically averaged, and the average value is used as the filtered output for the current time step. This method is simple to implement, has low computational latency, and is suitable for real-time processing scenarios.

[0048] Second, there is the exponentially weighted moving average filtering. This method applies exponentially decaying weights to historical derivative values, with larger weights for recent data and smaller weights for older data, recursively calculating the smoothed rate of change. This approach effectively suppresses high-frequency noise while preserving the ability to respond quickly to changes in signal trends.

[0049] Thirdly, Kalman filtering. If the system's state-space model and noise statistics are known, a Kalman filter can be used to optimally estimate the residual derivative, further improving filtering accuracy and anti-interference capability. However, this method has high computational complexity and is suitable for scenarios with high detection accuracy requirements.

[0050] Continuing with the previous pump station example, assume the original residual time derivative sequence is [2.65, 2.78, 2.77, 2.82, 2.71, 2.79] m³ / s² (units have been simplified), containing high-frequency fluctuations of approximately ±0.07 m³ / s². After applying a moving average filter with a window size of 5, the output is approximately 2.75 m³ / s², effectively suppressing noise. This smoothed rate of change signal is compared with a preset threshold. When comparing m³ / s², since 2.75 is much greater than 0.1, the system determines that there is significant network data tampering and triggers a poisoning attack alarm.

[0051] Through the above three steps, the trust residual analysis module outputs two key indicators: one is the dynamic residual. It has two functions: firstly, to monitor the absolute level of flow deviation; and secondly, the rate of change of dynamic residual over time. These two indicators are used to monitor instantaneous changes in flow rate deviation. Together, they constitute the core criteria for detecting flow meter tampering attacks.

[0052] Specifically, when only the dynamic residual is detected to exceed a preset first threshold (For example, 0.02 m³ / s², corresponding to approximately 10% flow deviation) may indicate a slow drift in the characteristic curve or a gradual measurement deviation in the flow meter. In this case, the system will only generate a deviation alert, and maintenance personnel are advised to check the equipment status. When both the dynamic residual and its rate of change exceed the first threshold, a deviation will occur. When this occurs, it indicates that the flow meter reading has undergone a non-physical change in a short period of time. At this point, the system determines that there is a flow meter tampering attack, triggers a poisoning risk alarm, and links the downstream dosing control system to execute a safety interlock action.

[0053] This decision mechanism based on dual thresholds and time-series derivatives effectively solves the problem of false alarms caused by static bias in traditional methods, and achieves robust attack detection in equipment aging scenarios.

[0054] The cavitation status diagnosis module calculates the effective net positive suction head (NPSH) of the device based on the pump inlet pressure and virtual flow reference. It then couples this NPSH with the high-frequency energy characteristics of the volute acoustic emission signal to generate an acousto-electromechanical (AE) cavitation index characterizing the severity of cavitation. This module is a key component in this application for identifying "micro-gate-induced cavitation" attacks. Unlike traditional methods that rely solely on pressure alarms or vibration thresholds, this application utilizes both fluid dynamic boundary conditions and the high-frequency acoustic response induced by bubble collapse to construct a consistent criterion across physical domains. This design is based on the fact that a decrease in inlet pressure alone cannot completely rule out normal disturbances such as operating condition switching and short-term water level fluctuations; and an increase in AE high-frequency energy alone may be affected by mechanical friction, external impacts, or electromagnetic interference. Only when the inlet vaporization conditions deteriorate simultaneously and the acoustic evidence of bubble collapse strengthens can cavitation be confidently identified as occurring, and its connection to malicious gate operation further inferred.

[0055] Using the aforementioned pump station example, under normal operating conditions, the virtual flow inverse calculation module has obtained... m³ / h, that is m / s, the absolute pressure at the pump inlet is MPa, current water temperature is 20℃, corresponding saturated vapor pressure kPa. Root-mean-square energy of high-frequency acoustic emission signal from the volute. It is approximately 12mV, and this value has been used as the baseline energy for acoustic emission under the aforementioned normal operating conditions. The data is then stored. The following section, using this specific operating condition as an example, explains the implementation process of the cavitation condition diagnosis module.

[0056] The cavitation condition diagnosis module calculates the effective net positive suction head (NPSH) of the device based on the pump inlet pressure and virtual flow reference, including: Obtain the saturated vapor pressure, the density of the treated medium, and the inlet cross-sectional area of ​​the water pump at the current water temperature; In this step, the saturated vapor pressure The critical pressure boundary used to characterize the vaporization of a liquid is directly related to water temperature. For ambient temperature raw water in urban water supply scenarios, the water temperature is typically between 5°C and 35°C. The pressure can be obtained by looking up a table, or it can be calculated in real time using a temperature sensor and a preset saturated vapor pressure mapping table. For example, at 20°C, the saturated vapor pressure of water is approximately... Pa; at 30°C, the saturated vapor pressure rises to approximately Pa; Pa. The reason why it is necessary to introduce... This is because cavitation is not determined by absolute low pressure itself, but by whether the local pressure is below the vaporization threshold at that temperature. The higher the temperature, the easier it is for the liquid to vaporize; therefore, the same inlet pressure corresponds to a higher risk of cavitation at high temperatures.

[0057] Processing medium density In this embodiment, the density is that of water at room temperature. Based on the aforementioned assumption that fluids are incompressible, It can be considered a constant, with a typical range of values. kg / m to kg / m To facilitate project implementation, it can be directly taken. kg / m The calculated value is based on a 20℃ operating condition. Gravitational acceleration. Usually taken m / s .

[0058] Water pump inlet cross-sectional area The dimensions are determined by the geometry of the suction pipe or pump inlet flange. If the inlet has a circular cross-section, then: ; in, The inlet pipe inner diameter is expressed in meters (m). This parameter can be obtained from equipment drawings, on-site measurements, or factory specifications. In this embodiment, assuming the centrifugal pump's inlet pipe inner diameter is 0.20 m, the inlet cross-sectional area is: ; The purpose of this area design is to establish a mapping relationship between flow rate and average inlet velocity, thereby representing the virtual flow rate. This is further converted into fluid kinetic energy. The smaller the inlet cross-sectional area, the higher the inlet velocity and the greater the kinetic head at the same flow rate. At the same time, the local pressure drop and cavitation sensitivity are also higher.

[0059] Calculate the pressure difference between the pump inlet pressure and the saturated vapor pressure, and convert this pressure difference into pressure head based on the density of the treated medium and the acceleration due to gravity. This step measures the static pressure margin that the liquid retains relative to its critical vaporization state when it reaches the pump inlet. Its physical meaning is: if... Much higher This indicates that there is still a considerable margin before the liquid vaporizes; if Approaching If this happens, the liquid enters a dangerous zone where vaporization is likely to occur. The formula for calculating pressure head is:

[0060] in, This refers to pressure head, measured in meters (m). This represents the absolute pressure at the pump inlet, in Pa. This is the saturated vapor pressure at the current water temperature, in Pa. The density of the medium is expressed in kg / m³. ; This is the acceleration due to gravity, measured in m / s². .

[0061] Using the aforementioned pumping station example, substitute... Pa、 Pa、 kg / m , m / s ,get:

[0062] This indicates that under normal operating conditions, the pump inlet liquid still has a hydrostatic head margin of approximately 12.12m relative to the vaporization boundary, which is a relatively safe condition.

[0063] The inlet velocity is calculated based on the virtual flow rate benchmark and the cross-sectional area of ​​the pump inlet, and then converted into kinetic head. This step is used to characterize the velocity energy level of the fluid entering the pump. According to the continuity equation, the inlet average velocity... Virtual traffic benchmark with entrance cross-sectional area The calculation yielded: Furthermore, the kinetic head corresponding to the inlet flow velocity for: in, The unit is m / s. The unit is meters (m). This item is included because the effective net positive suction head (NPSH) of the device depends not only on the static pressure conditions but also on the velocity energy carried by the liquid at the inlet. By unifying the pressure head and kinetic head into the form of "meter head," a directly comparable and cumulative fluid energy index can be formed.

[0064] Using the aforementioned pumping station example, m / s, m The inlet velocity is: The corresponding kinetic head is: It can be seen that under normal operating conditions, the kinetic head is relatively small compared to the pressure head. However, in scenarios with high flow rates or small-diameter suction pipes, this factor will increase significantly, so it still needs to be included in the unified calculation.

[0065] The effective net positive suction head (NPSH) of the device is obtained by adding the pressure head and the kinetic head.

[0066] Effective Net Positive Suction Head (NPSH) of the Equipment The formula for calculating the total residual energy head of a liquid at the pump inlet relative to vaporization conditions is as follows:

[0067] in, The unit is meters (m). The first term in the formula is the anti-vaporization capability provided by static pressure, and the second term is the energy conversion corresponding to the fluid velocity term. Dimensional analysis shows that both terms are in the dimension of length, so they can be directly added. The larger the index, the farther the liquid is from vaporization; the smaller the index, the closer the system is to the cavitation boundary.

[0068] Using the aforementioned pumping station example, substitute the aforementioned calculation results... m、 m, we get:

[0069] If the manufacturer of this type of centrifugal pump provides the required net positive suction head (NPSH) If it is 3.5m, then under the current working conditions Significantly higher than This indicates that there is no risk of cavitation during normal operation.

[0070] It should be noted that a virtual traffic benchmark is used in this application. Flow meter readings in non-industrial control networks participate Computational calculations are of significant security importance. If an attacker tampers with them... To create a false high traffic volume, if the system directly uses... Calculating inlet flow velocity and kinetic head can introduce incorrect judgments in some scenarios, weakening the reliability of cavitation diagnosis. It is derived from the underlying electrical power calculation and is independent of network traffic packets, thus providing an immutable traffic anchor point for cavitation diagnosis.

[0071] Following the description of normal operating conditions, let's consider an attack scenario. Assume an attacker uses the industrial control network to partially close the upstream inlet gate from 85% to 60%. Superficially, the gate doesn't appear completely closed, making it difficult for operators to immediately detect, but the resulting local resistance loss has significantly increased. At this point, the inlet pressure drops within seconds, and the pressure transmitter measures the inlet gauge pressure from 0.02 MPa to... MPa, corresponding to absolute pressure becomes MPa. Meanwhile, due to obstructed intake, the virtual flow inversion module outputs... Descending to approximately 150m / h, that is m / s. Calculated with the same inlet cross-sectional area, the inlet velocity becomes:

[0072] At this time, the pressure head is:

[0073] The kinetic head is:

[0074] Therefore, the effective net positive suction head (NPSH) of the unit decreases to:

[0075] Although this value is still higher in this example The height is m, but it has decreased significantly compared to the normal operating condition of 12.272m. In actual engineering, if there are local geometrical abrupt changes, additional losses in the suction pipe, transient disturbances, or further unfavorable installation heights, then... It will continue to approach or even fall below More importantly, this application does not rely on a single [source / method / element]. Instead of using an absolute threshold, it couples it with high-frequency AE energy to improve sensitivity to early and localized cavitation.

[0076] The cavitation condition diagnosis module couples the effective net positive suction head (NPSH) of the device with the high-frequency energy characteristics of the acoustic emission signal from the volute to generate an acoustic-electromechanical coupled cavitation index characterizing the severity of cavitation, including: Obtain the acoustic emission baseline energy under normal non-cavitation conditions, and calculate the logarithmic ratio of the high-frequency energy characteristics of the volute acoustic emission signal to the acoustic emission baseline energy as the acoustic abrupt change characteristic. This step is used to quantitatively characterize the enhancement level of the AE high-frequency signal relative to normal background noise. Because different pump mounting methods, sensor coupling quality, preamplifier gain, and ambient noise levels may vary, [the following is used directly]. Absolute values ​​are not robust enough as a uniform threshold. Therefore, this application uses energy relative to the baseline. The normalized logarithmic ratio is used to weaken individual differences and highlight mutation features. Acoustic mutation features. It can be represented as:

[0077] in, This represents the root mean square energy of the current volute acoustic emission signal in the high-frequency band, expressed in mV. Baseline energy of the same measurement link under normal, cavitation-free operating conditions, in units of... Consistent. Using the natural logarithm has two advantages: first, it can compress large energy changes, avoiding individual maxima dominating the judgment result; second, when… When the logarithmic ratio is 0, it is convenient to interpret the data using "0" as the normal baseline. If ,but It is positive, and increases with increasing energy; if ,but A value close to 0 or negative indicates that no obvious abnormal acoustic enhancement has occurred.

[0078] Using the aforementioned pumping station example, under normal operating conditions mV, then: Following a micro-closing gate attack, assuming that due to localized bubble formation and collapse at the impeller inlet, the root mean square energy in the high-frequency band of AE jumps from 12mV to 60mV within seconds, then:

[0079] The results indicate that the current acoustic energy has reached five times that of the cavitation-free baseline, and there is a significant high-frequency impact enhancement phenomenon.

[0080] Obtain the required net positive suction head (NPSH) of the water pump, calculate the difference between the required NPSH and the effective NPSH of the device, and extract the non-negative part of the difference as the fluid dynamic boundary feature. This step quantifies the degree to which the current operating conditions exceed the manufacturer's cavitation margin. Required NPSH (Net Positive Hypothesis). Provided by the pump manufacturer through testing under specific speed and flow conditions, it represents the minimum net positive suction head (NPSH) required to avoid significant performance degradation or damage. This information can typically be obtained from sample curves, nameplate data, or factory test reports. In this embodiment, it is assumed that the pump... m.

[0081] Fluid dynamic boundary characteristics Defined as:

[0082] in, This indicates that the non-negative part of the difference is extracted. The reason for using this form is that: when... When this condition is met, it indicates that the system has not yet exceeded the manufacturer's specified cavitation boundary from a macroscopic fluid condition perspective. Therefore, a negative risk value should not be generated due to "sufficient margin," and this item should be set to zero. When the difference is large, it indicates that the system has entered or is approaching the cavitation danger zone. The larger the difference, the more serious the boundary violation.

[0083] Using the previous example of normal operating conditions, m, therefore:

[0084] In a more severe scenario of malicious gate contraction, assuming the absolute pressure at the inlet further decreases to... MPa, and virtual traffic decreased to m / s, then: thereby:

[0085] At this point, the fluid dynamic boundary characteristics are:

[0086] This positive value indicates that the effective net positive suction head (NPSH) of the device has fallen below the required NPSH of the pump, and the system has entered a clear cavitation risk zone from a fluid dynamics perspective.

[0087] Based on preset weighting coefficients, a weighted fusion process is performed on acoustic abrupt change characteristics and hydrodynamic boundary characteristics to obtain the acoustic-mechanical-electric coupling cavitation index.

[0088] This step is used to unify microscopic acoustic evidence with macroscopic fluid boundary evidence into a comprehensive index that can be used for real-time determination. Acousto-mechanical-electrical coupling cavitation index. The calculation formula is: in, The acoustic-mechanical coupling cavitation index; and These are preset weighting coefficients, all of which are dimensionless parameters; The high-frequency energy characteristics of the current volute acoustic emission signal; The baseline energy of acoustic emission under normal, cavitation-free operating conditions; The required net positive suction head (NPSH) for water pumps; This represents the effective net positive suction head (NPSH) of the device.

[0089] Weighting coefficient , The setting principle is to make the two types of features comparable on a numerical scale and to highlight more reliable evidence sources based on field experience. Generally speaking, in scenarios where the acoustic sensors are stably installed and well coupled, the [specific value] can be appropriately increased. High accuracy in inlet pressure measurement, pump type In scenarios with complete data, the efficiency can be appropriately increased. In engineering, and Offline calibration can be performed using historical normal data and known cavitation samples, or it can be preset based on operational experience. For ease of explanation, this embodiment uses... , The reason why Slightly larger It is because once Below This indicates that the system has reached the danger boundary defined by the pump manufacturer and needs to be given higher weight.

[0090] Using the previous example of normal operating conditions, mV, and m, then:

[0091] This indicates that the cavitation index is close to zero under normal operating conditions, which is consistent with physical intuition.

[0092] Continuing with the severe risk scenario following malicious micro-closing of the gate, let's assume the current... mV, mV, m, m, then:

[0093] Substituting the values, we get:

[0094] If the system has a preset cavitation detection threshold If it is 1.0, then because This indicates that a significant risk of cavitation already exists. By further combining the gate closing command or virtual flow drop information obtained from the preceding modules, a coordinated attack of "maliciously induced cavitation" can be identified in subsequent joint reasoning.

[0095] It should be noted that this application employs a weighted fusion of "acoustic abrupt change features + hydrodynamic boundary features," rather than solely relying on... Or only The determination is that it has the following technical effects: First, improve the sensitivity of early diagnosis. In some early stages of cavitation, although... Not yet significantly lower However, small bubbles have already formed in the local flow field, causing an increase in the high-frequency energy of the acoustic phase. At this point, the acoustic phase rises first, which can issue an early risk warning.

[0096] Second, improve diagnostic specificity. If sporadic high-frequency noise not caused by cavitation sources exists at the scene, observe it separately. It may be a false alarm; but if at the same time If no deterioration is observed, the hydrodynamic boundary characteristics remain zero, and the comprehensive index... It will not amplify indefinitely, thus suppressing misjudgments.

[0097] Third, improve resistance to tampering. External sensors derived from the surface of the volute. Then it depends on the inlet pressure and virtual traffic It was calculated that, It also comes from the inverse calculation of electrical power. This means The generation of this signal relies on three different physical domain signals: electrical power, pressure, and high-frequency acoustics. For an attacker to simultaneously forge these three out-of-band physical quantities is far more difficult than tampering with a single network packet; therefore, this indicator possesses inherent resistance to network attacks.

[0098] Fourth, it facilitates engineering deployment and threshold setting. Once uniformly mapped to a single risk index, it can be directly compared with the threshold. The comparison outputs alarm, interlock, or tiered response results. For example, settings can be configured... This is a slightly abnormal observation area. As a warning zone, This is a high-risk area. Of course, the above threshold range is only an example; in actual applications, it can be adjusted based on pump type, operating conditions, and field sample data.

[0099] Furthermore, to avoid fluctuations in the cavitation index caused by transient noise, the acoustic-mechanical-electrical coupling cavitation index can be continuously calculated using a time window method consistent with the aforementioned dynamic residual, and updated once every 1-second sliding window. If multiple consecutive windows satisfy... If the cavitation event exceeds the limit within a single window and then recovers quickly, it can be recorded as a short-term anomaly without immediately triggering a strong interlock. This time continuity constraint can further improve the reliability and interpretability of field operations.

[0100] Through the above scheme, the cavitation condition diagnosis module can not only calculate the effective net positive suction head (NPSH) of the device from a fluid dynamics perspective, but also capture the microscopic physical evidence of bubble collapse using the high-frequency AE signal from the volute casing, ultimately forming a unified acoustic-mechanical-electrical coupled cavitation index. This index provides a high-confidence cavitation state input for subsequent cross-domain risk joint inference, enabling the system to promptly identify and trigger security protection actions when attackers cause covert damage through micro-closing gates.

[0101] The cross-domain joint inference module performs joint inference based on the rate of change of dynamic residuals, the dosing frequency in process monitoring data, the acoustic-mechanical-electrical coupling cavitation index, and control commands. This module is the decision-making core of the defense framework of this application. Its design concept is that: abnormal signals in a single physical domain may originate from normal operating condition switching, sensor drift, or occasional interference, but when the evidence chains of multiple independent physical domains simultaneously point to a consistent attack pattern, the false alarm probability will decrease exponentially, thereby achieving high-confidence attack identification and response. Specifically, this module implements two parallel inference paths: one is the flow trust chain pollution → poisoning risk path, which identifies biochemical poisoning attacks induced by attackers to induce excessive dosing by detecting abrupt residual changes between the virtual flow benchmark and the network flow meter reading, combined with the abnormal positive correlation between the downstream dosing pump frequency and the flow count value; the other is the fluid boundary deterioration → physical damage path, which identifies physical damage attacks induced by attackers to induce cavitation by slightly closing the upstream gate by detecting the exceeding of the limit of the acoustic-mechanical-electrical coupling cavitation index, combined with the upstream gate closing command or the sudden drop in virtual flow. These two paths are logically independent and may physically cover each other, but through cross-domain cross-verification, the system can simultaneously capture both types of covert attacks.

[0102] If the rate of change of the dynamic residual meets the preset mutation threshold and the dosing frequency is positively correlated with the flow count value, the cross-domain joint inference module determines that there is a risk of data tampering and triggers the first security response. This judgment logic is aimed at a biochemical poisoning attack scenario. A typical attacker's method is to tamper with the Modbus messages of the electromagnetic flowmeter by intruding into the SCADA system or using a man-in-the-middle attack, thus altering the actual flow rate. Fake high traffic This can induce downstream coagulant or chlorine dosing pumps to add coagulants or chlorine at incorrect flow rates, leading to water quality exceeding standards and even the production of toxic byproducts. Because dosing pumps typically use cascade control (flowmeter reading → dosing ratio setting → pump frequency), when… When maliciously amplified, the frequency of the dosing pump will increase accordingly, forming a positive correlation of "flow rate count ↑ → dosing frequency ↑". However, under normal operating conditions, if the actual flow rate does increase, the virtual flow rate baseline will be affected. The dynamic residual will also increase synchronously. For a condition that remains stable or changes slowly, its time derivative is... Approaching zero. Only when... altered When the values ​​remain unchanged, a step jump will occur in the residuals, leading to... This exceeds the normal fluctuation range. Therefore, this application achieves accurate identification of poisoning attacks by jointly detecting two conditions: residual mutation and positive correlation between the two conditions.

[0103] Specifically, the rate of change of the dynamic residual satisfying the preset abrupt change threshold condition means that, within a preset time window, the time derivative of the dynamic residual... The absolute value exceeds the preset mutation threshold. The threshold The configuration needs to comprehensively consider the flow meter's measurement accuracy, the fitting error of its characteristic curve, and the flow fluctuation range under normal operating conditions. In engineering practice, this can be achieved by collecting historical normal operating data and statistically analyzing it. The mean and standard deviation will The value is set to the mean plus three standard deviations, thus excluding normal fluctuations with a 99.7% confidence level. In this embodiment, it is assumed that the data is obtained through historical data analysis. m / s .

[0104] Using the aforementioned pump station example, under normal operating conditions, the virtual flow rate... m / h, flow meter reading m / h, dynamic residual m / s, its time derivative is within ±0.01m / s Fluctuations within a range, much smaller At this time, the coagulant dosing pump... At 15mg / m The ratio is automatically adjusted, the operating frequency is 36Hz, corresponding to a dosing flow rate of approximately 2.7 kg / h. Assuming that at the 50th second, the attacker tampers with the Modbus register... From 180m / h is faked as 280m / h. Due to Calculated independently by electrical power, unaffected by network tampering, it remains at 196m. / h, therefore the dynamic residual jumps instantaneously to m / s, the residual jump variable reaches 0.0277m / s. If the sampling period If the time derivative of the residual jumps instantaneously to approximately 2.77m, then the time derivative of the residual will increase to approximately 2.77m. / s Far exceeding the threshold m / s It meets the mutation threshold condition.

[0105] Meanwhile, the positive correlation between dosing frequency and flow meter reading means that within the same time window when a residual abrupt change is detected, the operating frequency of the coagulant dosing pump increases with the flow meter reading. The correlation coefficient between the two increases with the increase of the flow rate, and exceeds a preset positive correlation threshold. This condition is introduced to eliminate false alarms caused by flow meter malfunctions. If the flow meter experiences random fluctuations due to sensor failure or signal line faults, then... There is no stable causal relationship between the changes and the frequency of drug administration; the correlation coefficient is low or negative. Furthermore, the attacker tampered with... The purpose is precisely to induce excessive dosage, therefore There is a strong positive correlation between the frequency of chemical application and the amount of chemical added. In engineering, this can be calculated within a time window. The Pearson correlation coefficient between the frequency of drug administration and the frequency of drug administration is considered positive if the coefficient is greater than 0.8.

[0106] Using the aforementioned attack example, when It was altered to 280m After / h, the cascade controller of the dosing pump recalculates the dosing ratio based on the new flow rate benchmark, increasing the frequency from 36Hz to approximately 56Hz, corresponding to an increase in the dosing flow rate to approximately 4.2kg / h. Within a 10-second time window, the system records... The value jumped from 180 to 280, and the dosing frequency jumped from 36 to 56. The correlation coefficient between the two was close to 1.0, significantly exceeding the positive correlation threshold of 0.8. At this point, the cross-domain joint inference module comprehensively determined: dynamic residual mutation ( m / s Furthermore, the dosing frequency and the flow count value are strongly positively correlated (correlation coefficient ≈ 1.0 > 0.8), which meets the dual conditions for data tampering risk and triggers the first safety response.

[0107] The first safety response comprises three linked actions designed to immediately sever the causal chain of a poisoning attack and preserve evidence of the attack. First, a dosing interlock cutoff command is generated and sent to the corresponding dosing pump control unit. This command, via hardwired connection or a separate safety PLC channel, directly acts on the inverter enable terminal or contactor coil of the dosing pump, forcibly reducing the pump frequency to zero or switching to manual mode, preventing automatic dosing based on an incorrect flow rate reference. It should be noted that this interlock action bypasses the potentially vulnerable SCADA host computer, executing directly at the lower level to ensure the reliability and real-time nature of the response. Using the previous example, when the system determines a poisoning risk, it sends an interlock cutoff command to the coagulant dosing pump within 0.1 seconds, causing the pump frequency to drop urgently from 56Hz to 0Hz, and the dosing flow rate to zero, preventing excessive dosing that could lead to water quality exceeding standards.

[0108] Secondly, record and report data tampering attack logs containing the correlation between dynamic residual change rate and dosing frequency. These logs include the timestamp of the attack, the numerical sequence before and after the residual jump, the residual time derivative, and the flow meter reading. Virtual traffic benchmark Key information such as dosing frequency, correlation coefficient, and trigger threshold provides a complete data chain for subsequent attack tracing, forensic analysis, and security auditing. Logs are reported to an independent security monitoring platform or operations center via an encrypted channel to prevent attackers from tampering with or deleting them. Using the previous example, the system-generated attack log records the attack time as the 50th second. From 180m / h jumps to 280m / h, Maintain 196m / h, residual time derivative 2.77m / s The frequency of drug addition increased from 36Hz to 56Hz, with a correlation coefficient of 1.0, which was determined to be a flow meter tampering-induced poisoning attack.

[0109] Finally, the system's flow control baseline is forcibly switched from the flow count value read from the network to a virtual flow baseline. This action is one of the key innovations of this application. After detecting that the flow meter data is unreliable, the system no longer relies on it. Instead of making any control decisions, As a new flow benchmark, control parameters such as dosing ratio and pump scheduling are recalculated. Because Derived from power inversion and independent of the industrial control network, it can withstand continuous tampering by attackers. It also cannot affect the basis The control logic. This flow reference switching mechanism enables the system to maintain basic process control capabilities even after a cyberattack, preventing water supply interruptions due to complete shutdown. Continuing with the previous example, after triggering the first safety response, the system switches the flow control reference from... m / h switches to m / h, and according to Recalculate the dosage ratio. If it is necessary to resume dosage at this time, then... mg / m The pump frequency is set proportionally to ensure that the dosage matches the actual flow rate, avoiding over- or under-dosing.

[0110] If the acoustic-mechanical-electrical coupling cavitation index exceeds a preset safety threshold and there is a control command to reduce the water pump inlet flow or a sudden drop in the virtual flow benchmark, the cross-domain joint inference module determines that there is a risk of physically induced cavitation and triggers a second safety response. This judgment logic targets physical damage attack scenarios. A typical attacker's method is to hijack the control command of the upstream inlet gate, slightly closing the gate opening from the normal value to a smaller value. On the surface, the gate is not completely closed, which is not easily detected by the on-duty personnel, but the resulting local resistance loss has increased significantly, leading to a drop in the water pump inlet pressure and inducing cavitation. The collapse shock wave generated by cavitation bubbles will erode the impeller surface, and long-term operation will lead to impeller perforation, efficiency reduction, and even pump scrapping. Since cavitation damage is a cumulative process, it will not trigger traditional low pressure alarms or high vibration alarms in a short period of time, thus having strong concealment. This application uses the acoustic-mechanical-electrical coupling cavitation index... By capturing early microscopic evidence of cavitation and combining it with macroscopic evidence of gate commands or sudden drops in flow, accurate identification of physically induced cavitation attacks can be achieved.

[0111] Specifically, the acoustic-electromechanical coupling cavitation index exceeding the preset safety threshold refers to the following: the output of the cavitation state diagnosis module... The value exceeds the preset safety threshold. The threshold The setup needs to comprehensively consider the pump's cavitation sensitivity, the acoustic sensor's sensitivity, and the acceptable level of cavitation risk on-site. In engineering practice, this can be achieved by collecting sample data under known cavitation conditions and statistically analyzing the data. The distribution characteristics will The value is set to the normal operating mean plus two standard deviations, thus excluding normal fluctuations at a 95% confidence level. In this embodiment, it is assumed that the value is obtained through historical data analysis and cavitation test calibration. .

[0112] Using the aforementioned pumping station example, under normal operating conditions, far below Suppose that at the 100th second, an attacker, through the industrial control network, slightly closes the upstream intake gate from 85% to 60%, and the gate-closing command is recorded by the system. Due to the obstructed suction, the inlet pressure drops from 0.121 MPa to 0.091 MPa within seconds, and the virtual flow rate decreases from 196 m³ / s. / h plummeted to 150m / h, the effective net positive suction head (NPSH) of the device decreased from 12.272m to 9.15m. Simultaneously, bubble formation and collapse began locally at the impeller inlet, and the high-frequency energy of the acoustic emission signal from the volute jumped from 12mV to 60mV. According to the aforementioned formula, at this time... If the attacker further closes the gate to 40%, the inlet pressure drops to 0.030 MPa, and the virtual flow drops to 108 mV. / h, the effective net positive suction head (NPSH) of the device decreases to 2.877m, and the acoustic energy rises to 80mV. Significantly exceeding This meets the cavitation risk conditions.

[0113] Meanwhile, a sudden drop in the control command to reduce the water pump inlet flow or the virtual flow reference refers to the following: within the same time window when the cavitation index exceeds the limit, the system records a decrease in the opening command of the upstream inlet gate or a drop in the virtual flow reference. The time derivative is negative and its absolute value exceeds the preset drop threshold. This condition is introduced to distinguish the causes of cavitation: if cavitation is caused by normal operating condition switching (such as pump start-up / shutdown, valve adjustment), then the gate command and flow rate change are the result of active operation by maintenance personnel, and the system can eliminate this through operation logs or manual confirmation; if cavitation is caused by malicious operation by an attacker, then the time of issuing the gate command closely matches the time when the cavitation index exceeds the limit, and there is no corresponding maintenance operation record, forming a clear chain of attack evidence. In engineering, the drop threshold can be set to... m / s That is, when m / s The time was determined to be a sudden drop in traffic.

[0114] Using the previous attack example, when the gate is slightly closed from 85% to 60%, the virtual traffic increases from 196Mbps within 5 seconds. / h(0.0544m / s) dropped to 150m / h(0.0417m / s), the change in flow rate is m / s, the time derivative is approximately m / s The absolute value exceeds the sudden drop threshold of 0.01m. / s Simultaneously, the system captured a Modbus write command from the industrial control network mirror indicating a change in gate opening from 85% to 60%. The command was issued at the 100th second, only 5 seconds after the cavitation index exceeded the limit (105th second), and there were no login records or operation ticket approval records for maintenance personnel during this period. At this point, the cross-domain joint inference module comprehensively determined that the acoustic-mechanical-electric coupling cavitation index exceeded the limit (…). Furthermore, there are gate closing instructions (85% → 60%) and a sudden drop in virtual traffic. m / s This satisfies the dual conditions for physical induced cavitation risk, triggering the second safety response.

[0115] The second safety response comprises three coordinated actions designed to immediately eliminate cavitation inducing factors, protect the pump unit, and preserve evidence of an attack. First, a gate safety reset command is generated and sent to the intake gate control unit to increase the pump's inlet flow rate. This command, via hardwired connection or a separate safety PLC channel, directly acts on the gate's electric actuator or hydraulic cylinder, forcibly restoring the gate opening to a preset safe opening (e.g., 90% or fully open), eliminating local resistance loss and restoring the inlet pressure to its normal range. It should be noted that this reset action also bypasses the potentially attacker-controlled SCADA host computer, executing directly at the lower level to ensure the reliability of the response. Using the previous example, when the system determines there is a risk of cavitation, a safety reset command is sent to the intake gate within 0.2 seconds. The gate opening is forcibly restored from 60% to 90%, the inlet pressure recovers from 0.030 MPa to 0.110 MPa within 10 seconds, the effective net positive suction head (NPSH) recovers from 2.877 m to approximately 11 m, and the cavitation index... As it drops below 0.5, the cavitation phenomenon disappears.

[0116] Secondly, a physical induced attack log containing the acoustic-mechanical-electrical coupling cavitation index and control command sequence is recorded and reported. This log includes the timestamp of the attack occurrence and the cavitation index. Time series, device effective net positive suction head Acoustic emission energy Inlet pressure Virtual traffic The logs contain key information such as their time derivative, gate opening command sequence, trigger threshold, and gate reset action, providing a complete data chain for subsequent attack tracing, equipment damage assessment, and security auditing. The logs are reported to an independent security monitoring platform or operations center via an encrypted channel to prevent attackers from tampering with or deleting them. Using the previous example, the system-generated attack log records: the attack occurred at the 100th second, and the gate opening changed from 85% to 60%. From 196m / h dropped to 150m / h, the inlet pressure decreased from 0.121MPa to 0.091MPa. The elevation decreased from 12.272m to 9.15m. From 12mV to 60mV, It rose from 0 to 0.965 at the 105th second. The value further increased to 1.886, exceeding the threshold of 1.0, and was determined to be a malicious micro-closing gate-induced cavitation attack. At 105.2 seconds, the gate was safely reset to 90%.

[0117] Finally, the emergency frequency reduction and load reduction operation mode of the pump unit is triggered. This action is to further reduce the risk of cavitation and mechanical stress during the gate reset process. By sending a frequency reduction command to the pump inverter, the motor speed is reduced from the rated 1450 rpm to approximately 1200 rpm, causing the pump operating point to move along the characteristic curve towards the low flow and low head region, reducing the impeller inlet velocity and dynamic pressure, increasing the effective cavitation margin of the device, and buying time for gate reset. At the same time, frequency reduction operation can also reduce the impact intensity of bubble collapse and mitigate erosion damage to the impeller. After the gate reset is completed, the inlet pressure returns to normal, and the cavitation index remains below the threshold, the system gradually restores the speed to the rated value and resumes normal water supply. Continuing with the previous example, after triggering the second safety response, the system sends a frequency reduction command to the pump inverter within 0.3 seconds, reducing the speed from 1450 rpm to 1200 rpm and the virtual flow rate from 150 m³ / h. / h further decreased to approximately 125m The inlet flow velocity decreased from 1.33 m / s to approximately 1.1 m / s, the kinetic head decreased from 0.090 m to approximately 0.062 m, and the effective net positive suction head (NPSH) increased from 9.15 m to approximately 9.19 m, providing additional safety margin for gate reset. After the gate was reset to 90%, the inlet pressure recovered to 0.110 MPa, and the cavitation index remained below 0.5 for 30 seconds, the system gradually restored the rotational speed to 1450 rpm and the virtual flow rate to approximately 190 m³ / h. / h, normal water supply restored.

[0118] The dynamic threshold update module adaptively updates preset mutation threshold conditions and preset safety thresholds based on the statistical characteristics of historical normal operation data cycles to compensate for baseline drift caused by long-term mechanical wear of the pump unit. This module is the adaptive mechanism of the defense framework of this application. Its design concept is that during long-term operation of the pump unit, the impeller surface will slowly degrade in performance due to factors such as wear, scaling, and cavitation, resulting in a gradual decrease in the actual flow rate under the same electrical power and a drift in the characteristic curve. If the threshold... and If the baseline is kept constant, the dynamic residual and cavitation index under normal operating conditions may gradually approach or even exceed the threshold as baseline drift accumulates, leading to an increase in the false alarm rate. To address this, this application introduces a dynamic threshold update mechanism. By periodically analyzing the statistical characteristics of historical normal operating data, the threshold is adaptively adjusted to ensure it always matches the current equipment status, thus suppressing false alarms while maintaining attack detection sensitivity.

[0119] Specifically, the dynamic threshold update module adaptively updates the preset mutation threshold conditions and preset safety thresholds based on the statistical characteristics of historical normal operation data cycles, including the following steps: First, historical operational data that did not trigger any safety responses is collected within a preset update cycle, forming the normal operation dataset. This update cycle can be set weekly, monthly, or quarterly, depending on the equipment's operational intensity and wear rate. The normal operation dataset includes dynamic residuals. Residual time derivative Acousto-electromechanical coupling cavitation index Effective net positive suction head (NPSH) of the device Acoustic emission energy Time series of key indicators. It should be noted that only data collected during periods when no security response was triggered was included in the normal dataset to avoid attack samples contaminating the baseline statistics.

[0120] Using the pump station example mentioned earlier, assuming the system has accumulated 720 hours of operation over the past 30 days, including one triggering of the first safety response (lasting 10 minutes) and two triggering of the second safety response (each lasting 5 minutes), then the normal operating time is approximately 719.67 hours. During these 719.67 hours, the system collected approximately 2.59 million data points at a sampling period of 1 second, constituting the normal operating data set.

[0121] Then, the mean and standard deviation of the residual time derivative and cavitation index in the normal operation dataset are calculated respectively. The mean reflects the central trend of the index under the current equipment condition, and the standard deviation reflects the fluctuation range of the index. For the residual time derivative... Calculate the mean of their absolute values. and standard deviation For the cavitation index Calculate its mean and standard deviation .

[0122] Continuing with the previous example, suppose that in the normal operation dataset of the past 30 days, the mean of the absolute value of the residual time derivative is... m / s Standard deviation m / s Mean value of cavitation index Standard deviation The mean has increased slightly compared to the statistical characteristics at the time of initial system deployment, reflecting the characteristic curve drift caused by impeller wear and the slow increase in acoustic baseline energy.

[0123] Finally, the mutation threshold is updated based on the mean and standard deviation. and safety threshold The updated formula is:

[0124] in, and This is a preset multiplier used to control the leniency of the threshold. and The larger the threshold, the more lenient the threshold, resulting in a lower false alarm rate, but the false negative rate may increase. and The smaller the threshold, the stricter the threshold and the lower the false negative rate, but the false positive rate may increase. In engineering practice, the optimal threshold can be determined through ROC curve analysis based on the distribution characteristics of historical attack samples and normal samples. and In this embodiment, it is assumed that... , This corresponds to confidence levels of 99.7% and 95%.

[0125] Using the previous example, the result calculated according to the updated formula is:

[0126] With the initial threshold m / s and Compared to the updated The decrease reflects a reduction in the normal fluctuation range of the residual time derivative, making the system more sensitive to abrupt changes; the updated The significant reduction reflects the rise in the baseline of the cavitation index, indicating that the system is more stringent in its assessment of cavitation risk and avoids false alarms caused by baseline drift.

[0127] In summary, the system acquires underlying physical operating data such as motor input power, pump inlet pressure, and volute acoustic emission signals. Based on the energy conservation principle, it calculates a virtual flow baseline and generates an acousto-electromechanical coupling cavitation index by combining the device's effective net positive suction head (NPSH) and high-frequency acoustic characteristics. This index is then used to perform cross-domain joint inference with process monitoring data and control commands acquired from the network layer. This cross-domain verification mechanism establishes a physical verification channel independent of the industrial control network data. In specific scenarios where deep-cover attacks are occurring, it can accurately identify physical damage and biochemical risks that attackers attempt to conceal by synchronously tampering with control commands and monitoring feedback. By promptly triggering corresponding security response mechanisms after risk assessment, the system fundamentally enhances the underlying defense capabilities of water infrastructure and effectively prevents equipment damage or water quality exceeding standards caused by malicious attacks.

[0128] Example 2: Figure 2 As shown, the water industry control risk prediction method based on intelligent management includes: The system acquires the underlying physical operation data of the pump unit, as well as the process monitoring data and control commands from the industrial control network. The underlying physical operation data includes the motor input power, pump inlet pressure, and volute acoustic emission signal, while the process monitoring data includes the flow count value read from the network. Based on the input power of the motor and the preset pump characteristic curve, the actual physical flow rate through the pump is calculated based on the energy conservation relationship, and used as a virtual flow rate benchmark. Calculate the dynamic residual between the traffic count value read by the network and the virtual traffic baseline, and extract the rate of change of the dynamic residual over time; The effective net positive suction head (NPSH) of the device is calculated based on the pump inlet pressure and virtual flow reference. The effective NPSH of the device is then coupled with the high-frequency energy characteristics of the acoustic emission signal from the volute to generate an acoustic-electromechanical coupling cavitation index that characterizes the severity of cavitation. Based on the rate of change of dynamic residuals, the dosing frequency in process monitoring data, the acoustic-mechanical coupling cavitation index, and joint inference of control command execution: If the rate of change of the dynamic residual meets the preset mutation threshold condition and the dosing frequency is positively correlated with the flow count value, then it is determined that there is a risk of data tampering and the first security response is triggered. If the acoustic-mechanical coupling cavitation index exceeds the preset safety threshold and there is a control command to reduce the water pump inlet flow or a sudden drop in the virtual flow benchmark, then it is determined that there is a risk of physical induced cavitation and a second safety response is triggered.

[0129] The above description is merely an example and illustration of the structure of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described, or use similar methods to replace them, as long as they do not deviate from the structure of the invention or exceed the scope defined in the claims, all of which should fall within the protection scope of the present invention.

[0130] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0131] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to any specific implementation. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.

Claims

1. A water industry control risk prediction system based on intelligent management, characterized in that, include: The data acquisition module is used to acquire the underlying physical operation data of the pump unit as well as the process monitoring data and control commands in the industrial control network. The underlying physical operation data includes the motor input power, pump inlet pressure and volute acoustic emission signal, and the process monitoring data includes the flow count value read from the network. The virtual flow inverse calculation module is used to calculate the actual physical flow rate through the water pump based on the energy conservation relationship, according to the input electrical power of the motor and the preset water pump characteristic curve, and use it as the virtual flow rate benchmark. The trust residual analysis module is used to calculate the dynamic residual between the traffic count value read by the network and the virtual traffic baseline, and to extract the rate of change of the dynamic residual over time. The cavitation condition diagnosis module is used to calculate the effective net positive suction head (NPSH) of the device based on the pump inlet pressure and the virtual flow reference, and to couple the effective NPSH of the device with the high-frequency energy characteristics of the acoustic emission signal of the volute to generate an acoustic-electromechanical coupling cavitation index characterizing the severity of cavitation. The cross-domain joint inference module is used to perform joint inference based on the rate of change of the dynamic residual, the dosing frequency in the process monitoring data, the acoustic-mechanical-electrical coupling cavitation index, and the control commands. If the rate of change of the dynamic residual meets the preset mutation threshold condition and the dosing frequency is positively correlated with the flow count value, then it is determined that there is a risk of data tampering and the first security response is triggered. If the acoustic-mechanical coupling cavitation index exceeds the preset safety threshold and there is a control command to reduce the water pump inlet flow or the virtual flow benchmark drops sharply, then it is determined that there is a risk of physical induced cavitation and a second safety response is triggered.

2. The water industry control risk prediction system based on intelligent management according to claim 1, characterized in that, The virtual flow inversion module calculates the actual physical flow rate through the pump based on the motor input power and a preset pump characteristic curve, according to the energy conservation relationship. This includes: The input electrical power of the motor is converted into the power of the water pump shaft according to the preset motor transmission efficiency; Obtain a pre-calibrated polynomial characteristic curve model of the relationship between pump shaft power and flow rate; The pump shaft power is substituted into the polynomial characteristic curve model, and the real roots that are physically compliant are obtained by solving the polynomial equation, which are then used as the virtual flow reference.

3. The water industry control risk prediction system based on intelligent management according to claim 1, characterized in that, The trust residual analysis module calculates the dynamic residual between the traffic count value read by the network and the virtual traffic baseline, and extracts the rate of change of the dynamic residual over time, including: Within a preset time window, the difference between the traffic count value and the virtual traffic baseline is calculated as a dynamic residual. The dynamic residual is subjected to time derivative processing to obtain the time derivative sequence of the dynamic residual; The time derivative sequence is smoothed and filtered, and the filtered result is used as the rate of change of the dynamic residual over time.

4. The water industry control risk prediction system based on intelligent management according to claim 1, characterized in that, The cavitation condition diagnosis module calculates the effective net positive suction head (NPSH) based on the pump inlet pressure and the virtual flow reference, including: Obtain the saturated vapor pressure, the density of the treated medium, and the inlet cross-sectional area of ​​the water pump at the current water temperature; Calculate the pressure difference between the pump inlet pressure and the saturated vapor pressure, and convert the pressure difference into a pressure head based on the density of the processing medium and the gravitational acceleration. The inlet velocity is calculated based on the virtual flow rate reference and the cross-sectional area of ​​the pump inlet, and the inlet velocity is converted into kinetic head. The effective net positive suction head (NPSH) of the device is obtained by adding the pressure head and the kinetic head.

5. The water industry control risk prediction system based on intelligent management according to claim 4, characterized in that, The cavitation condition diagnosis module couples the effective net positive suction head (NPSH) of the device with the high-frequency energy characteristics of the acoustic emission signal from the volute to generate an acoustic-electromechanical coupled cavitation index characterizing the severity of cavitation, including: Obtain the acoustic emission baseline energy under normal non-cavitation conditions, and calculate the logarithmic ratio of the high-frequency energy characteristics of the volute acoustic emission signal to the acoustic emission baseline energy as an acoustic abrupt change feature. Obtain the required net positive suction head (NPSH) of the water pump, calculate the difference between the required NPSH and the effective NPSH of the device, and extract the non-negative part of the difference as a fluid dynamic boundary feature. Based on preset weighting coefficients, the acoustic abrupt change features and the hydrodynamic boundary features are subjected to weighted fusion processing to obtain the acoustic-mechanical-electric coupling cavitation index.

6. The water industry control risk prediction system based on intelligent management according to claim 1, characterized in that, The first security response includes: Generate and send a dosing interlock cutoff command to the corresponding dosing pump control unit; Record and report data tampering attack logs that include the correlation between dynamic residual change rate and dosing frequency; The system's traffic control baseline is forcibly switched from the traffic count value read from the network to the virtual traffic baseline.

7. The water industry control risk prediction system based on intelligent management according to claim 1, characterized in that, The second security response includes: Generate and send a gate safety reset command to the inlet gate control unit to increase the water pump inlet flow rate; Record and report physical induced attack logs containing the acoustic-electromechanical coupling cavitation index and control command sequences; This triggers the emergency frequency and load reduction operation mode of the water pump unit.

8. The water industry control risk prediction system based on intelligent management according to claim 1, characterized in that, The data acquisition module obtains the underlying physical operating data of the water pump unit, including: The input power of the motor is acquired by a high-frequency current transformer with external hardwire. The water pump inlet pressure is acquired by a pressure transmitter installed at the water pump inlet. Acoustic emission signals from the volute are collected by an acoustic sensor attached to the surface of the water pump volute.

9. The water industry control risk prediction system based on intelligent management according to claim 1, characterized in that, Also includes: The dynamic threshold update module is used to adaptively update the preset mutation threshold condition and the preset safety threshold based on the statistical characteristics of historical normal operation data cycles, so as to compensate for the baseline drift of the water pump unit caused by long-term mechanical wear.

10. A water industry control risk prediction method based on intelligent management, characterized in that, Based on any one of claims 1-9, the water industry control risk prediction system based on intelligent management shall perform the following steps: The system acquires the underlying physical operation data of the pump unit, as well as the process monitoring data and control commands from the industrial control network. The underlying physical operation data includes the motor input power, pump inlet pressure, and volute acoustic emission signal, while the process monitoring data includes the flow count value read from the network. Based on the input power of the motor and the preset water pump characteristic curve, the actual physical flow rate through the water pump is calculated based on the energy conservation relationship, and used as a virtual flow rate benchmark. Calculate the dynamic residual between the traffic count value read by the network and the virtual traffic baseline, and extract the rate of change of the dynamic residual over time; Based on the pump inlet pressure and the effective net positive suction head (NPSH) of the virtual flow reference calculation device, and by coupling the effective NPSH of the device with the high-frequency energy characteristics of the acoustic emission signal of the volute, an acoustic-electromechanical coupling cavitation index characterizing the severity of cavitation is generated. Based on the rate of change of the dynamic residual, the dosing frequency in the process monitoring data, the acoustic-mechanical-electrical coupling cavitation index, and the control commands, joint inference is performed: If the rate of change of the dynamic residual meets the preset mutation threshold condition and the dosing frequency is positively correlated with the flow count value, then it is determined that there is a risk of data tampering and the first security response is triggered. If the acoustic-mechanical coupling cavitation index exceeds the preset safety threshold and there is a control command to reduce the water pump inlet flow or the virtual flow benchmark drops sharply, then it is determined that there is a risk of physical induced cavitation and a second safety response is triggered.