An intelligent power stealing judgment method and system based on power grid characteristic information for an intelligent fusion terminal

By deploying intelligent fusion terminal nodes in the power distribution network and constructing a collaborative monitoring node group, the problem of distinguishing between electricity theft and internal faults was solved by using multi-dimensional traveling wave characteristic spectrum analysis and physical consistency discrimination model. This enabled efficient and accurate electricity theft identification and location, and improved the system's protection capabilities.

CN122109608APending Publication Date: 2026-05-29FUJIAN RUIST TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
FUJIAN RUIST TECH CO LTD
Filing Date
2026-02-13
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing anti-electricity theft technologies are unable to accurately distinguish between electricity theft and internal electrical faults, leading to false alarms and inefficient inspections, and are unable to effectively identify high-tech deceptive electricity theft attacks.

Method used

By deploying traveling wave sensors in intelligent fusion terminal nodes in the distribution network, a collaborative monitoring node group is constructed. Using multi-dimensional traveling wave characteristic spectrum analysis and physical consistency discrimination model, combined with power grid topology information, the accurate location and nature determination of abnormal events can be achieved.

Benefits of technology

It improves the accuracy of electricity theft detection, reduces false positives, identifies deceptive attacks, enhances the system's robustness and auditing efficiency, and provides precise coordinates of abnormal event locations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122109608A_ABST
    Figure CN122109608A_ABST
Patent Text Reader

Abstract

The application discloses a kind of intelligent fusion terminal intelligent electricity stealing judgment method and system based on power grid characteristic information, comprising: abnormal traveling wave signal is detected by the intelligent fusion terminal deployed in distribution network node, and initial event area is determined accordingly and power grid topology;Select other terminal located in the area electric upstream and downstream, jointly constitute collaborative monitoring node group;Obtain the broadband traveling wave data recorded in the event time window of the node group;Extract the wave head polarity and arrival time of data, obtain the first verification result for judging whether event occurs in the target user metering point upstream or downstream by comparison and calculation;While time-frequency analysis is carried out on data, generate multi-dimensional traveling wave characteristic spectrum, and obtain the second verification result for judging whether data has natural physical event spectrum attribute;Finally, according to the first and second verification results, it is judged that the abnormal event belongs to internal fault or electricity stealing behavior.The method realizes the accurate distinction of electricity stealing and user internal fault.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power systems, and in particular to a smart electricity theft detection method and system based on smart fusion terminal intelligent power grid characteristic information. Background Technology

[0002] The construction and development of smart grids have placed higher demands on the safety, reliability, and economical operation of power systems. Anti-theft technology, as a key means of protecting the legitimate rights and interests of power supply companies and maintaining a fair electricity consumption order, has always been a focus in the field of electricity metering and inspection. With the large-scale deployment of smart meters, remote monitoring based on electricity consumption information collection systems has become the mainstream method for preventing electricity theft. Existing technologies mainly detect suspected electricity theft by analyzing anomalies in steady-state electrical quantities such as current, voltage, and power (e.g., neutral current exceeding phase current, abnormal three-phase imbalance, sudden drop in daily electricity consumption, etc.), and then confirm this through on-site inspections.

[0003] However, these anti-theft methods based on steady-state electrical quantity analysis reveal a fundamental technical flaw when faced with increasingly complex and sophisticated electricity theft techniques: the difficulty in accurately and reliably distinguishing between anomalies caused by electricity theft and those caused by genuine electrical faults within the user's system (such as insulation aging, equipment leakage, and poor contact). These two fundamentally different events often exhibit highly similar characteristics in steady-state electrical quantities, leading to numerous false alarms and forcing inspectors to conduct extensive and inefficient on-site investigations. This not only wastes human resources but also reduces the accuracy and timeliness of anti-theft operations.

[0004] Therefore, there is an urgent need for an intelligent method to prevent electricity theft that can fundamentally solve the problem of confusing electricity theft with internal faults. Summary of the Invention

[0005] In view of the aforementioned deficiencies of the prior art, the technical problem to be solved by the present invention is to provide an intelligent electricity theft detection method based on power grid characteristic information for intelligent fusion terminals, aiming to avoid erroneous identification of faults and electricity theft, and improve the accuracy of electricity theft detection.

[0006] To achieve the above objectives, this invention discloses an intelligent electricity theft detection method based on power grid characteristic information using an intelligent fusion terminal. The method includes: Step S1: Detect abnormal traveling wave signals using traveling wave sensors deployed on smart converged terminal nodes of the distribution network; In response to any of the traveling wave sensors detecting an abnormal initial traveling wave signal, obtain the initial event region based on the initial traveling wave signal and the power grid topology information of the distribution network; Step S2: Based on the initial event region and the power grid topology information, select at least one other smart fusion terminal node located electrical upstream and downstream of the initial event region, and together with the smart fusion terminal node that detected the initial traveling wave signal, form a collaborative monitoring node group; Step S3: Obtain broadband traveling wave data recorded by each traveling wave sensor in the collaborative monitoring node group within a predetermined time window based on the arrival time of the initial traveling wave signal; Step S4: Extract the initial wavefront polarity and arrival time of the broadband traveling wave data corresponding to each traveling wave sensor. By comparing the polarity and calculating the time difference, obtain a first verification result for determining whether the abnormal event occurred upstream or downstream of the target user metering point corresponding to the initial event region. Perform time-frequency analysis on each broadband traveling wave data to generate a multi-dimensional traveling wave feature spectrum. Based on the multi-dimensional traveling wave feature spectrum, obtain a second verification result for determining whether the broadband traveling wave data has the spectral attributes of a natural physical event. Step S5: Based on the first verification result and the second verification result, determine the abnormal event corresponding to the initial traveling wave signal; wherein, the determination result of the abnormal event includes at least internal faults and electricity theft.

[0007] Optionally, step S5 includes: If the first verification result indicates that the fault occurred downstream, and the second verification result indicates that the fault has the spectral properties of a natural physical event, then it is determined to be an internal fault. If the first verification result indicates that the incident occurred upstream, and the second verification result indicates that the incident has spectral attributes of a natural physical event, then it is determined to be an act of electricity theft. If the second verification result determines that it does not have the spectral attributes of a natural physical event, then regardless of the first verification result, it is determined to be a deceptive attack.

[0008] Optionally, obtaining the first verification result through polarity comparison and time difference calculation in step S4 includes: If, in the collaborative monitoring node group, the initial wavefront polarity detected by the node downstream of the target user metering point is opposite to that of the upstream node, it is determined that the abnormal event occurred upstream of the target user metering point; if the initial wavefront polarity of all nodes is the same, and the arrival time increases sequentially from the downstream node to the upstream node, it is determined that the abnormal event occurred downstream of the target user metering point; wherein, the determination rule for electrical upstream and electrical downstream among the intelligent fusion terminal nodes is: in the power grid topology, the direction closer to the power source side is electrical upstream, and the direction closer to the user load side is electrical downstream.

[0009] Optionally, the frequency range covered by the broadband traveling wave data is from 10 kHz to 5 MHz; the multi-dimensional traveling wave characteristic spectrum includes at least: the distribution ratio of event energy in the 10-100 kHz, 100-500 kHz and 0.5-2 MHz sub-bands, and the cross-band coherence parameters between different frequency components.

[0010] Optionally, obtaining the second verification result based on the multidimensional traveling wave characteristic spectrum in step S4 includes: The multi-dimensional traveling wave feature spectrum is input into a pre-trained physical consistency discrimination model, and the physical consistency discrimination model outputs a judgment result on whether the broadband traveling wave data has the spectral attributes of a natural physical event; wherein, the physical consistency discrimination model is trained based on a large number of samples of real fault events and simulated deception signals.

[0011] Optionally, the physical consistency discrimination model is configured as follows: if the multi-dimensional traveling wave characteristic spectrum exhibits characteristics of wide-band continuity, energy attenuation conforming to theoretical laws, and high cross-band coherence, it is judged to have the spectral attributes of a natural physical event; if it exhibits characteristics of concentrated energy in a narrow band, abrupt spectral shape, or weak cross-band coherence, it is judged to not have the spectral attributes of a natural physical event.

[0012] Optionally, in step S2, selecting at least one other smart fusion terminal node located electrically upstream and downstream of the initial event region based on the initial event region and the power grid topology information includes: Based on the power grid topology information, the smart fusion terminal node that has the shortest electrical distance to the selected initial event region in the power grid topology, and / or whose signal correlation is higher than a preset threshold according to historical traveling wave signal propagation attenuation data.

[0013] Optionally, when step S5 determines that the act is electricity theft or a deceptive attack, the method further includes step S6: Based on the arrival time difference and the known traveling wave propagation speed, calculate and output the physical location coordinates of the abnormal event source relative to the nearest intelligent fusion terminal node.

[0014] Optionally, the method further includes: During the judgment process in step S5, the load transient characteristics of the target user's metering point are acquired simultaneously; when the judgment result is electricity theft, if the load transient characteristics match the pre-stored electricity theft device feature library or are unknown features, the confidence level of the judgment result is increased.

[0015] The present invention also discloses an intelligent fusion terminal intelligent electricity theft detection system based on power grid characteristic information. The system includes: an initial event area acquisition module, a collaborative monitoring node group construction module, a traveling wave data acquisition module, a verification module, and an anomaly detection module. The initial event region acquisition module is used to detect abnormal traveling wave signals by traveling wave sensors deployed on smart converged terminal nodes of the distribution network; in response to any of the traveling wave sensors detecting an abnormal initial traveling wave signal, the module obtains the initial event region based on the initial traveling wave signal and the power grid topology information of the distribution network. The collaborative monitoring node group construction module is used to select at least one other smart fusion terminal node located electrical upstream and downstream of the initial event area according to the initial event area and the power grid topology information, and to form a collaborative monitoring node group together with the smart fusion terminal node that detected the initial traveling wave signal. The traveling wave data acquisition module is used to acquire broadband traveling wave data recorded by each of the traveling wave sensors in the collaborative monitoring node group within a predetermined time window based on the arrival time of the initial traveling wave signal. The verification module is used to extract the initial wavefront polarity and arrival time of the broadband traveling wave data corresponding to each traveling wave sensor, and obtain a first verification result for determining whether the abnormal event occurs upstream or downstream of the target user metering point corresponding to the initial event region by comparing the polarity and calculating the time difference; perform time-frequency analysis on each broadband traveling wave data to generate a multi-dimensional traveling wave feature spectrum, and obtain a second verification result for determining whether the broadband traveling wave data has the spectral attributes of a natural physical event based on the multi-dimensional traveling wave feature spectrum; The anomaly detection module is used to detect anomalies corresponding to the initial traveling wave signal based on the first verification result and the second verification result; wherein the detection result of the anomaly event includes at least internal faults and electricity theft.

[0016] The beneficial effects of this invention are as follows: 1. Through the first layer of verification (multi-node traveling wave polarity comparison and time difference calculation), this invention, for the first time, directly and clearly determines whether an abnormal event occurs upstream (grid side) or downstream (user side) of the user's metering point. This provides a decisive criterion from a physical topology perspective to distinguish between "external electricity theft access" and "internal equipment failure," turning speculation into confirmation and greatly reducing misjudgments and ineffective audits. 2. Through the second layer of verification (wideband traveling wave characteristic spectrum analysis and physical consistency discrimination), this invention not only verifies the authenticity of the event but also effectively identifies artificially injected deceptive signals designed to mimic fault waveforms and evade monitoring. This enables the system to detect and determine "deceptive attacks," achieving a dimensional upgrade from preventing "electricity theft" to preventing "attacks," and improving the overall robustness and security of the system. 3. This invention, based on intelligent fusion terminals, establishes a dynamic "collaborative monitoring node group," changing the limitations of traditional single-point monitoring. This method utilizes grid topology to achieve multi-perspective data collaboration, realizing a leap from isolated signal analysis to networked event diagnosis, significantly improving the reliability of monitoring and early warning capabilities. 4. While completing the qualitative judgment (fault, electricity theft, deception), the method of this invention can simultaneously output the precise physical location coordinates of the abnormal event (based on the time difference of arrival of traveling waves), providing clear guidance for on-site inspections. This greatly improves the efficiency and deterrent effect of anti-electricity theft work.

[0017] In summary, this invention advances anti-electricity theft technology from passive analysis relying on experience and steady-state quantities to a new stage of proactive intelligent diagnosis based on transient physical characteristics and networked collaboration, thereby improving the accuracy of electricity theft identification. Attached Figure Description

[0018] Figure 1 This is a flowchart illustrating a smart electricity theft detection method based on power grid feature information provided in a specific embodiment of the present invention. Figure 2 This is a schematic diagram of the principle structure of an intelligent fusion terminal intelligent electricity theft detection method based on power grid feature information provided in a specific embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of an intelligent fusion terminal intelligent electricity theft detection system based on power grid feature information provided in a specific embodiment of the present invention. Detailed Implementation

[0019] This invention discloses an intelligent fusion terminal method and system for detecting electricity theft based on power grid characteristic information. Those skilled in the art can refer to the content of this document and appropriately improve the technical details for implementation. It should be particularly noted that all similar substitutions and modifications are obvious to those skilled in the art and are considered to be included in this invention. The methods and applications of this invention have been described through preferred embodiments. Those skilled in the art can obviously modify or appropriately change and combine the methods and applications described herein without departing from the content, spirit, and scope of this invention to implement and apply the technology of this invention.

[0020] The applicant's research revealed the following key shortcomings in existing technical solutions that lead to the aforementioned confusion: First, their judgment relies on a single data source at the metering point, lacking the ability to conduct multi-node collaborative observation at the distribution network topology level, and thus cannot accurately trace the "location" of abnormal events (i.e., it cannot clearly distinguish whether the event occurred on the grid side upstream of the metering point or the user side downstream). Second, existing methods mainly focus on power frequency electrical quantities, lacking effective monitoring and analysis methods for high-frequency traveling wave signals that can characterize the transient physical characteristics of events, and therefore cannot identify "deceptive" electricity theft attacks that are generated by special equipment and intended to simulate fault waveforms.

[0021] Therefore, embodiments of the present invention provide a smart electricity theft detection method based on power grid characteristic information using a smart fusion terminal, such as... Figure 1 As shown, the method includes: Step S1: Detect abnormal traveling wave signals using traveling wave sensors deployed on the smart converged terminal nodes of the distribution network; in response to any traveling wave sensor detecting an abnormal initial traveling wave signal, obtain the initial event region based on the initial traveling wave signal and the power grid topology information of the distribution network.

[0022] It should be noted that step S1 is the initiation stage. Intelligent fusion terminals deployed at various nodes of the distribution network continuously monitor high-frequency transient signals on the lines through their built-in broadband traveling wave sensors. When any sensor captures an "abnormal initial traveling wave signal" whose amplitude, frequency, or waveform characteristics significantly deviate from the background noise, a suspicious event is considered to have occurred. The system then combines this with a pre-stored digital power grid topology map and, based on the signal's strength, direction, and other characteristics, preliminarily estimates a possible event range, i.e., the "initial event area." Step S1 realizes the transformation from "continuous monitoring" to "event triggering." Its core lies in rapid response and initial focus, transforming the indiscriminate collection of massive amounts of data from the entire network into targeted analysis of specific areas and time windows, greatly improving subsequent processing efficiency.

[0023] Step S2: Based on the initial event region and power grid topology information, select at least one other smart fusion terminal node located electrical upstream and downstream of the initial event region, and together with the smart fusion terminal node that detected the initial traveling wave signal, form a collaborative monitoring node group.

[0024] It should be noted that step S2 demonstrates the collaborative and intelligent characteristics of the method. The system does not rely on a single trigger node as the sole information source; instead, based on topological relationships, it actively "summons" adjacent intelligent fusion terminal nodes located upstream and downstream of the initially identified abnormal area. These selected nodes, together with the trigger node, form a temporary "collaborative monitoring node group" for this specific event. Step S2 overcomes the limitations of single-point monitoring. By constructing a sensor array containing upstream and downstream observation points, the system can acquire observation data of the same event from multiple spatial locations, providing a multi-dimensional data foundation for subsequent analysis of the event propagation direction (determining upstream and downstream) and signal consistency. This is a prerequisite for achieving accurate positioning and differentiation.

[0025] In this specific embodiment, step S2, based on the initial event region and power grid topology information, selects at least one other smart fusion terminal node located electrically upstream and downstream of the initial event region, including: Based on the power grid topology information, the smart fusion terminal node is the one with the shortest electrical distance to the selected initial event area in the power grid topology, and / or whose signal correlation is higher than a preset threshold according to historical traveling wave signal propagation attenuation data.

[0026] It should be noted that this intelligent selection mechanism ensures that the signals collected by the summoned nodes are highly correlated with the initial events, which can effectively improve the accuracy and reliability of subsequent collaborative analysis and avoid the introduction of invalid data.

[0027] Step S3: Obtain broadband traveling wave data recorded by each traveling wave sensor in the collaborative monitoring node group within a predetermined time window based on the arrival time of the initial traveling wave signal; It should be noted that, under a unified and precise time reference, the system commands all terminals in the "coordinated monitoring node group" to retrieve the raw waveform data recorded within a specific time window (e.g., a few milliseconds before and after) around the arrival time of the initial traveling wave signal from their internal caches. This data is "wideband traveling wave data" containing rich high-frequency components. Step S3 ensures the completeness and synchronization of the analysis. The "predetermined time window" guarantees the capture of the complete transient process of the event; and the precise time synchronization of the data from each node is crucial for subsequent calculation of the wavefront arrival time difference, accurate positioning, and polarity comparison.

[0028] Step S4: Extract the initial wavefront polarity and arrival time of the broadband traveling wave data corresponding to each traveling wave sensor. By comparing the polarity and calculating the time difference, obtain the first verification result for determining whether the abnormal event occurred upstream or downstream of the target user metering point corresponding to the initial event area. Perform time-frequency analysis on each broadband traveling wave data to generate a multi-dimensional traveling wave feature spectrum. Based on the multi-dimensional traveling wave feature spectrum, obtain the second verification result for determining whether the broadband traveling wave data has the spectral attributes of a natural physical event.

[0029] It should be noted that step S4 performs in-depth analysis of the synchronously acquired data in two dimensions: First verification (topology verification): Accurately identify the first wavefront of the traveling wave signal from the broadband data of each node, and record its polarity (positive or negative) and precise arrival time. By comparing the polarity relationship (same or opposite) and arrival time difference of the wavefronts between upstream and downstream nodes, the relative location of the event (upstream or downstream of the user's metering point) is calculated using traveling wave propagation theory.

[0030] The second verification (attribute verification) involves performing time-frequency analysis (such as wavelet transform) on the broadband data to convert the time-domain waveform into a "multi-dimensional traveling wave characteristic spectrum" that simultaneously reflects the changes in frequency components and energy over time. By analyzing the morphology of this characteristic spectrum (such as the distribution of energy in different frequency bands, spectral continuity, harmonic correlation, etc.), it can be determined whether the signal originates from natural physical events such as short circuits or switching operations, or from an unnatural and potentially deceptive signal generated by electronic devices.

[0031] The purpose and function of step S4 is to provide mutually corroborating and multi-dimensional criteria. The first verification answers "where the event occurred" from a spatial topological perspective, providing direct evidence to distinguish between internal and external events. The second verification answers "whether the event itself is real and natural" from the physical nature of the signal, serving as a firewall to identify high-tech deception methods. The combination of the two forms the basis for highly reliable judgments.

[0032] It is worth noting that the upstream lines from the distribution transformer to the user's electricity metering point are usually constructed and maintained in a standardized manner by the power supply company, and the operating environment is relatively controlled, making the probability of natural faults such as insulation aging and short circuits extremely low. However, the user-side lines downstream of the metering point are often subject to unknown loads, unauthorized connections, and inconsistent equipment quality, making them a high-risk area for electrical faults. Therefore, when an abnormal event is precisely located upstream of the metering point, it is highly likely to be a deliberate and illegal act of electricity theft; while when located downstream, it is more likely to be a natural fault within the user's premises. This invention utilizes this objective physical and statistical law, using the "upstream / downstream" location information as the primary and reliable criterion for distinguishing between electricity theft and faults.

[0033] In this specific embodiment, step S4, obtaining the first verification result through polarity comparison and time difference calculation, includes: If, in the collaborative monitoring node group, the initial wavefront polarity detected by the node downstream of the target user's metering point is opposite to that of the node upstream, then the abnormal event is determined to occur upstream of the target user's metering point; if the initial wavefront polarity of all nodes is the same, and the arrival time increases sequentially from the downstream node to the upstream node, then the abnormal event is determined to occur downstream of the target user's metering point; the rule for determining electrical upstream and electrical downstream between intelligent fusion terminal nodes is as follows: in the power grid topology, the direction closer to the power source side is electrical upstream, and the direction closer to the user load side is electrical downstream.

[0034] It should be noted that this embodiment specifically illustrates how to determine whether an event occurred upstream or downstream by comparing the initial wavefront polarity (opposite or the same) and arrival time sequence detected by upstream and downstream nodes in the "cooperative monitoring node group".

[0035] This embodiment is based on the physical laws of traveling wave propagation in power lines: when an abnormal event (such as a short circuit or load switching) occurs, the resulting traveling wave pulse propagates to both ends of the line at near the speed of light. If the event occurs downstream of the user's metering point (user side), the traveling wave will first reach the downstream monitoring point and then propagate to the upstream point. Therefore, all monitoring points capture the same initial wavefront polarity, and the arrival time increases sequentially from downstream to upstream. If the event occurs upstream (grid side, such as a theft connection point), then this point is equivalent to a new "source," and the traveling wave it generates will propagate in the opposite direction to both the user side and the power supply side, resulting in opposite initial wavefront polarities captured by the monitoring points on the user side and the power supply side. By comparing the wavefront polarity relationship and timing of each node in the collaborative monitoring node group, the topological location of the event source relative to the metering point can be directly determined, thus providing conclusive physical evidence for distinguishing between internal faults and external theft.

[0036] Furthermore, the broadband traveling wave data covers a frequency range of 10kHz to 5MHz; the multi-dimensional traveling wave characteristic spectrum includes at least the distribution ratio of event energy in the 10-100kHz, 100-500kHz and 0.5-2MHz sub-bands, as well as the cross-band coherence parameters between different frequency components.

[0037] It should be noted that the frequency range of "wideband traveling wave data" needs to cover 10kHz to 5MHz, which ensures that the complete signal characteristics from power frequency harmonics to high frequency transients can be captured.

[0038] In this specific embodiment, step S4, obtaining the second verification result based on the multi-dimensional traveling wave characteristic spectrum, includes: The multi-dimensional traveling wave feature spectrum is input into a pre-trained physical consistency discrimination model, which outputs a judgment result on whether the broadband traveling wave data has the spectral attributes of a natural physical event. The physical consistency discrimination model is trained based on a large number of samples of real fault events and simulated deception signals.

[0039] Furthermore, the physical consistency discrimination model is configured as follows: if the multi-dimensional traveling wave characteristic spectrum exhibits characteristics of wide-band continuity, energy attenuation conforming to theoretical laws, and high cross-band coherence, it is judged to have the spectral attributes of a natural physical event; if it exhibits characteristics of concentrated energy in a narrow band, abrupt spectral shape, or weak cross-band coherence, it is judged not to have the spectral attributes of a natural physical event.

[0040] It should be noted that this embodiment further specifies the specific process for obtaining the second verification result, ensuring the reliability of the second verification result.

[0041] In this specific embodiment, the principle structure diagram corresponding to the embodiment of the present invention can be as follows: Figure 2 As shown, Figure 2 In the diagram, 201 is the transformer, 202 is the upstream intelligent fusion terminal node, 203 is the target user metering point, 204 is the downstream intelligent fusion terminal node, and 205 is the traveling wave sensor. 202 and 204 can form a collaborative monitoring node group.

[0042] Step S5: Based on the first verification result and the second verification result, judge the abnormal events corresponding to the initial traveling wave signal; wherein, the judgment result of the abnormal events includes at least internal faults and electricity theft.

[0043] It should be noted that this step inputs the results of the first and second verifications into a preset decision logic for comprehensive decision-making. This dual verification improves the accuracy of electricity theft detection and avoids the impact of false identifications.

[0044] In this specific embodiment, step S5 includes: If the first verification result indicates that the fault occurred downstream, and the second verification result indicates that the fault has the spectral properties of a natural physical event, then it is determined to be an internal fault. If the first verification result indicates that the incident occurred upstream, and the second verification result indicates that the incident has spectral attributes of a natural physical event, then it is determined to be an act of electricity theft. If the second verification result determines that it does not have the spectral attributes of a natural physical event, then regardless of the first verification result, it is determined to be a deceptive attack.

[0045] It should be noted that the specific judgment logic of step S5 in this embodiment is the core of the entire solution's decision-making. It clearly stipulates that: if the event occurs downstream of the user and the signal is natural, it is judged as an internal fault; if it occurs upstream and the signal is natural, it is judged as electricity theft; if the signal is determined to be of non-natural attributes, it is directly identified as a deceptive attack regardless of the event's location. These three rules constitute a complete and unambiguous classification system for abnormal events, transforming the physical results of double verification into clear business conclusions.

[0046] Furthermore, when step S5 determines that the act is electricity theft or a deceptive attack, the method also includes step S6: Based on the time difference of arrival and the known propagation speed of the traveling wave, calculate and output the physical location coordinates of the abnormal event source relative to the nearest intelligent fusion terminal node.

[0047] It should be noted that this embodiment adds an important derivative function—precise positioning. When the system determines that there is electricity theft or a deception attack, the method can use the "time difference" of the traveling wave arriving at each node calculated in step S4 and the known propagation speed of the traveling wave to calculate the physical location coordinates of the abnormal event source (such as the electricity theft connection point or the installation point of the attacking device), thereby providing precise navigation for on-site inspection and greatly improving the efficiency of the operation.

[0048] In this specific embodiment, the method further includes: During the judgment process in step S5, the load transient characteristics of the target user's metering point are acquired synchronously. When the judgment result is electricity theft, if the load transient characteristics match the pre-stored electricity theft device feature library or are unknown features, the confidence level of the judgment result is increased.

[0049] It should be noted that when the main system has determined that an act of electricity theft has occurred, if this load characteristic matches a known database of electricity theft devices or is completely unknown, it can serve as strong circumstantial evidence, further increasing the confidence of the final judgment and forming a reinforced judgment system in which primary and secondary evidence corroborate each other.

[0050] This invention also provides an intelligent fusion terminal system for determining electricity theft based on power grid characteristic information, such as... Figure 3 As shown, the system includes: an initial event region acquisition module 301, a collaborative monitoring node group construction module 302, a traveling wave data acquisition module 303, a verification module 304, and an anomaly judgment module 305; The initial event region acquisition module 301 is used to detect abnormal traveling wave signals by traveling wave sensors deployed on smart converged terminal nodes of the distribution network; in response to any traveling wave sensor detecting an abnormal initial traveling wave signal, the initial event region is obtained based on the initial traveling wave signal and the power grid topology information of the distribution network. The collaborative monitoring node group construction module 302 is used to select at least one other smart fusion terminal node located electrical upstream and downstream of the initial event area based on the initial event area and power grid topology information, and to form a collaborative monitoring node group together with the smart fusion terminal node that detected the initial traveling wave signal. The traveling wave data acquisition module 303 is used to acquire broadband traveling wave data recorded by each traveling wave sensor in the collaborative monitoring node group within a predetermined time window based on the arrival time of the initial traveling wave signal. The verification module 304 is used to extract the initial wavefront polarity and arrival time of the broadband traveling wave data corresponding to each traveling wave sensor. By comparing the polarity and calculating the time difference, a first verification result is obtained to determine whether the abnormal event occurred upstream or downstream of the target user metering point corresponding to the initial event area. Time-frequency analysis is performed on each broadband traveling wave data to generate a multi-dimensional traveling wave feature spectrum. Based on the multi-dimensional traveling wave feature spectrum, a second verification result is obtained to determine whether the broadband traveling wave data has the spectral attributes of a natural physical event. The anomaly judgment module 305 is used to judge the abnormal events corresponding to the initial traveling wave signal based on the first verification result and the second verification result; wherein the judgment result of the abnormal event includes at least internal faults and electricity theft.

[0051] This invention, through a first-level verification (multi-node traveling wave polarity comparison and time difference calculation), directly and clearly determines for the first time in terms of methodology whether an abnormal event occurs upstream (grid side) or downstream (user side) of the user's metering point. This provides a decisive criterion from a physical topology perspective to distinguish between "external electricity theft" and "internal equipment failure," turning speculation into confirmation and greatly reducing misjudgments and ineffective investigations.

[0052] This invention, through a second layer of verification (wideband traveling wave characteristic spectrum analysis and physical consistency discrimination), not only verifies the authenticity of events but also effectively identifies artificially injected deceptive signals designed to mimic fault waveforms and evade monitoring. This enables the system to detect and determine "deceptive attacks," achieving a dimensional upgrade from preventing "electricity theft" to preventing "attacks," thus improving the overall robustness and security of the system.

[0053] This invention, based on intelligent fusion terminals, establishes a dynamic "collaborative monitoring node group," overcoming the limitations of traditional single-point monitoring. This method utilizes power grid topology to achieve multi-perspective data collaboration, enabling a leap from isolated signal analysis to networked event diagnosis, significantly improving monitoring reliability and early warning capabilities.

[0054] The method described in this invention, while performing qualitative judgments (fault, electricity theft, deception), can simultaneously output the precise physical location coordinates of the abnormal event (based on the time difference of arrival of traveling waves), providing clear guidance for on-site inspections. This greatly improves the efficiency and deterrent effect of anti-electricity theft work.

[0055] In summary, the embodiments of the present invention advance anti-electricity theft technology from passive analysis relying on experience and steady-state quantities to a new stage of proactive intelligent diagnosis based on transient physical characteristics and networked collaboration, thereby improving the accuracy of electricity theft identification.

[0056] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes the element.

[0057] The various embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0058] The above are merely preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention are included within the scope of protection of the present invention.

Claims

1. A smart electricity theft detection method based on power grid characteristic information using a smart fusion terminal, characterized in that, The method includes: Step S1: Detect abnormal traveling wave signals using traveling wave sensors deployed on smart converged terminal nodes of the distribution network; In response to any of the traveling wave sensors detecting an abnormal initial traveling wave signal, obtain the initial event region based on the initial traveling wave signal and the power grid topology information of the distribution network; Step S2: Based on the initial event region and the power grid topology information, select at least one other smart fusion terminal node located electrical upstream and downstream of the initial event region, and together with the smart fusion terminal node that detected the initial traveling wave signal, form a collaborative monitoring node group; Step S3: Obtain broadband traveling wave data recorded by each traveling wave sensor in the collaborative monitoring node group within a predetermined time window based on the arrival time of the initial traveling wave signal; Step S4: Extract the initial wavefront polarity and arrival time of the broadband traveling wave data corresponding to each traveling wave sensor. By comparing the polarity and calculating the time difference, obtain a first verification result for determining whether the abnormal event occurred upstream or downstream of the target user metering point corresponding to the initial event region. Perform time-frequency analysis on each broadband traveling wave data to generate a multi-dimensional traveling wave feature spectrum. Based on the multi-dimensional traveling wave feature spectrum, obtain a second verification result for determining whether the broadband traveling wave data has the spectral attributes of a natural physical event. Step S5: Based on the first verification result and the second verification result, determine the abnormal event corresponding to the initial traveling wave signal; wherein, the determination result of the abnormal event includes at least internal faults and electricity theft.

2. The intelligent electricity theft detection method based on power grid characteristic information using an intelligent fusion terminal according to claim 1, characterized in that, Step S5 includes: If the first verification result indicates that the fault occurred downstream, and the second verification result indicates that the fault has the spectral properties of a natural physical event, then it is determined to be an internal fault. If the first verification result indicates that the incident occurred upstream, and the second verification result indicates that the incident has spectral attributes of a natural physical event, then it is determined to be an act of electricity theft. If the second verification result determines that it does not have the spectral attributes of a natural physical event, then regardless of the first verification result, it is determined to be a deceptive attack.

3. The intelligent electricity theft detection method based on power grid characteristic information using an intelligent fusion terminal according to claim 1, characterized in that, The step S4, which involves obtaining the first verification result through polarity comparison and time difference calculation, includes: If, in the collaborative monitoring node group, the initial wavefront polarity detected by the node downstream of the target user metering point is opposite to that of the upstream node, it is determined that the abnormal event occurred upstream of the target user metering point; if the initial wavefront polarity of all nodes is the same, and the arrival time increases sequentially from the downstream node to the upstream node, it is determined that the abnormal event occurred downstream of the target user metering point; wherein, the determination rule for electrical upstream and electrical downstream among the intelligent fusion terminal nodes is: in the power grid topology, the direction closer to the power source side is electrical upstream, and the direction closer to the user load side is electrical downstream.

4. The intelligent electricity theft detection method based on power grid characteristic information using an intelligent fusion terminal according to claim 1 or 3, characterized in that, The broadband traveling wave data covers a frequency range of 10kHz to 5MHz; the multi-dimensional traveling wave characteristic spectrum includes at least the distribution ratio of event energy in the 10-100kHz, 100-500kHz and 0.5-2MHz sub-bands, and the cross-band coherence parameters between different frequency components.

5. The intelligent electricity theft detection method based on power grid characteristic information using an intelligent fusion terminal according to claim 1, characterized in that, The step S4, obtaining the second verification result based on the multi-dimensional traveling wave characteristic spectrum, includes: The multi-dimensional traveling wave feature spectrum is input into a pre-trained physical consistency discrimination model, and the physical consistency discrimination model outputs a judgment result on whether the broadband traveling wave data has the spectral attributes of a natural physical event; wherein, the physical consistency discrimination model is trained based on a large number of samples of real fault events and simulated deception signals.

6. The intelligent electricity theft detection method based on power grid characteristic information using an intelligent fusion terminal according to claim 5, characterized in that, The physical consistency discrimination model is configured such that: if the multi-dimensional traveling wave characteristic spectrum exhibits wide-band continuity, energy attenuation conforms to theoretical laws, and high cross-band coherence, it is judged to have the spectral attributes of a natural physical event; if it exhibits concentrated energy in a narrow band, abrupt spectral shape, or weak cross-band coherence, it is judged not to have the spectral attributes of a natural physical event.

7. The intelligent electricity theft detection method based on power grid characteristic information using an intelligent fusion terminal according to claim 1, characterized in that, In step S2, selecting at least one other smart fusion terminal node located electrically upstream and downstream of the initial event region based on the initial event region and the power grid topology information includes: Based on the power grid topology information, the smart fusion terminal node that has the shortest electrical distance to the selected initial event region in the power grid topology, and / or whose signal correlation is higher than a preset threshold according to historical traveling wave signal propagation attenuation data.

8. The intelligent electricity theft detection method based on power grid characteristic information using an intelligent fusion terminal according to claim 2, characterized in that, When step S5 determines that the act is electricity theft or a deceptive attack, the method further includes step S6: Based on the arrival time difference and the known traveling wave propagation speed, calculate and output the physical location coordinates of the abnormal event source relative to the nearest intelligent fusion terminal node.

9. The intelligent electricity theft detection method based on power grid characteristic information using an intelligent fusion terminal according to claim 1, characterized in that, The method further includes: During the judgment process in step S5, the load transient characteristics of the target user's metering point are acquired simultaneously; when the judgment result is electricity theft, if the load transient characteristics match the pre-stored electricity theft device feature library or are unknown features, the confidence level of the judgment result is increased.

10. A smart electricity theft detection system based on power grid characteristic information using an intelligent fusion terminal, characterized in that, The system includes: an initial event region acquisition module, a collaborative monitoring node group construction module, a traveling wave data acquisition module, a verification module, and an anomaly judgment module; The initial event region acquisition module is used to detect abnormal traveling wave signals by traveling wave sensors deployed on smart converged terminal nodes of the distribution network; in response to any of the traveling wave sensors detecting an abnormal initial traveling wave signal, the module obtains the initial event region based on the initial traveling wave signal and the power grid topology information of the distribution network. The collaborative monitoring node group construction module is used to select at least one other smart fusion terminal node located electrical upstream and downstream of the initial event area according to the initial event area and the power grid topology information, and to form a collaborative monitoring node group together with the smart fusion terminal node that detected the initial traveling wave signal. The traveling wave data acquisition module is used to acquire broadband traveling wave data recorded by each of the traveling wave sensors in the collaborative monitoring node group within a predetermined time window based on the arrival time of the initial traveling wave signal. The verification module is used to extract the initial wavefront polarity and arrival time of the broadband traveling wave data corresponding to each traveling wave sensor, and obtain a first verification result for determining whether the abnormal event occurs upstream or downstream of the target user metering point corresponding to the initial event region by comparing the polarity and calculating the time difference; perform time-frequency analysis on each broadband traveling wave data to generate a multi-dimensional traveling wave feature spectrum, and obtain a second verification result for determining whether the broadband traveling wave data has the spectral attributes of a natural physical event based on the multi-dimensional traveling wave feature spectrum; The anomaly detection module is used to detect anomalies corresponding to the initial traveling wave signal based on the first verification result and the second verification result; wherein the detection result of the anomaly event includes at least internal faults and electricity theft.