Abnormality alarm method and device, electronic equipment, storage medium and program product
Patent Information
- Application Number
- CN202610620719.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-08
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2046-05-08
AI Technical Summary
然而,由于工业系统通常较为庞大,往往可能出现多个异常节点同时报警
[0038] Based on common knowledge in the field, the above-mentioned preferred conditions can be combined arbitrarily to obtain various preferred embodiments of this disclosure.
Smart Images

Figure CN122157462B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of alarm analysis, and in particular to an abnormal alarm method, device, electronic equipment, storage medium, and program product. Background Technology
[0002] With the development of modern industrial technology, industrial systems typically involve the coordinated operation of various industrial equipment and devices. When a node in an industrial system malfunctions, it can often trigger malfunctions in other nodes within the system.
[0003] When an abnormal node appears in an industrial system, the system will issue a corresponding alarm, enabling staff to quickly take corrective measures to ensure the safe operation and economic benefits of the industrial system. However, because industrial systems are usually quite large, multiple abnormal nodes may alarm simultaneously. When staff are dealing with multiple abnormal nodes, it is often difficult to maintain a global perspective, which may lead to staff delaying the handling of higher-priority alarms, potentially causing safety hazards. Summary of the Invention
[0004] The technical problem to be solved by this disclosure is to overcome the above-mentioned defects in the prior art and provide an abnormal alarm method, device, electronic device, storage medium and program product.
[0005] This disclosure solves the above-mentioned technical problems through the following technical solution:
[0006] In a first aspect, embodiments of this disclosure provide an anomaly alarm method, the method comprising:
[0007] Obtain at least one abnormal node in the system model of the industrial system and the causal path corresponding to each abnormal node;
[0008] Based on each abnormal node and its corresponding causal path, multiple abnormal node features are determined for each abnormal node; each abnormal node feature has a different priority.
[0009] According to the aforementioned priority, the sorting strategy corresponding to the characteristics of each abnormal node is used sequentially to perform multi-level sorting on all abnormal nodes in the at least one abnormal node, thereby obtaining the abnormal alarm result.
[0010] Optionally, the system model is established based on the operational data of the detection points in the industrial system; each node in the system model represents a detection point, and the connection relationship between nodes represents the data propagation relationship between the detection points.
[0011] Optionally, the system model is obtained by processing the operational data of the detection points of the industrial system using a multi-layer flow modeling method.
[0012] Optionally, the step of sequentially sorting all abnormal nodes in the at least one abnormal node according to the priority and using the sorting strategy corresponding to the features of each abnormal node to obtain the abnormal alarm result includes:
[0013] Sort all abnormal nodes in the at least one abnormal node according to the sorting strategy corresponding to the highest priority abnormal node feature;
[0014] For abnormal nodes with the same sorting, sort them sequentially according to the sorting strategy corresponding to the characteristics of the next lower priority abnormal node until the sorting stopping condition is met, and an abnormal alarm result is obtained; the sorting stopping condition includes determining different sorting among the abnormal nodes, or traversing all sorting strategies corresponding to the characteristics of all abnormal nodes.
[0015] Optionally, the abnormal node characteristics include an anomaly level; the sorting strategy corresponding to the anomaly level is that the abnormal nodes with higher anomaly levels are sorted in priority over the abnormal nodes with lower anomaly levels.
[0016] The step of determining multiple abnormal node features for each abnormal node based on each abnormal node and its corresponding causal path includes:
[0017] Determine the alarm events of the abnormal nodes;
[0018] Using the alarm event as an index, the abnormality level corresponding to the abnormal node is determined from the event level classification library; the alarm events in the event level classification library correspond to the abnormality levels.
[0019] Optionally, the abnormal node characteristics include causal type; the sorting strategy corresponding to the causal type is that the sorting of abnormal nodes with cause-type alarms takes precedence over the sorting of abnormal nodes with result-type alarms.
[0020] The step of determining multiple abnormal node features for each abnormal node based on each abnormal node and its corresponding causal path includes:
[0021] Based on the causal path, determine the number of upstream abnormal nodes of the abnormal node;
[0022] When the number of upstream abnormal nodes is less than one, the cause type of the abnormal node is determined to be a cause-based alarm;
[0023] When the number of upstream abnormal nodes is greater than or equal to one, the causal type of the abnormal node is determined to be a result-type alarm.
[0024] Optionally, the abnormal node features include the explanation ratio; the sorting strategy corresponding to the explanation ratio is that abnormal nodes with a larger explanation ratio are sorted before abnormal nodes with a smaller explanation ratio.
[0025] The step of determining multiple abnormal node features for each abnormal node based on each abnormal node and its corresponding causal path includes:
[0026] Identify the target causal path with the highest number of abnormal nodes in the causal path;
[0027] The ratio of the number of anomalous nodes in the target causal path to the total number of anomalous nodes is calculated to obtain the explanation ratio of the anomalous nodes.
[0028] Optionally, the abnormal node features include time nodes; the sorting strategy corresponding to the time nodes is that abnormal nodes with earlier time nodes are sorted in order of priority over abnormal nodes with later time nodes.
[0029] The step of determining multiple abnormal node features for each abnormal node based on each abnormal node and its corresponding causal path includes:
[0030] Determine the time point for each abnormal node.
[0031] Secondly, embodiments of this disclosure provide an anomaly alarm device, the device comprising:
[0032] The acquisition module is used to acquire at least one abnormal node in the system model of the industrial system and the causal path corresponding to each abnormal node.
[0033] The determination module is used to determine multiple abnormal node features for each abnormal node based on each abnormal node and its corresponding causal path; each abnormal node feature has a different priority.
[0034] The sorting module is used to sort all the abnormal nodes in the at least one abnormal node in a multi-level manner according to the priority and the sorting strategy corresponding to the characteristics of each abnormal node, so as to obtain the abnormal alarm result.
[0035] Thirdly, embodiments of this disclosure provide an electronic device, including a memory, a processor, and a computer program stored in the memory and used to run on the processor, wherein the processor executes the computer program to implement the abnormal alarm method as described in any one of the first aspects.
[0036] Fourthly, embodiments of this disclosure provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the abnormal alarm method as described in any one of the first aspects.
[0037] Fifthly, embodiments of this disclosure provide a computer program product, including a computer program that, when executed by a processor, implements the abnormal alarm method as described in any one of the first aspects.
[0038] Based on common knowledge in the field, the above-mentioned preferred conditions can be combined arbitrarily to obtain various preferred embodiments of this disclosure.
[0039] The positive and progressive effects of this disclosure are as follows: by obtaining abnormal nodes and their corresponding causal paths in the industrial system through a system model, and by sorting the abnormal nodes in a multi-level manner according to the sorting strategy corresponding to the multiple abnormal node features extracted from the abnormal nodes and their causal paths, the key information of abnormal nodes in the industrial system can be presented to the staff more comprehensively. This can reduce the number of abnormal nodes that the staff need to monitor under abnormal working conditions. At the same time, it can prompt the staff to handle the abnormal nodes that need to be prioritized according to their importance, thereby improving the staff's processing efficiency and optimizing the staff's response efficiency to abnormal nodes. Attached Figure Description
[0040] Figure 1 A flowchart of an anomaly alarm method provided as an exemplary embodiment of this disclosure;
[0041] Figure 2 A schematic diagram of the nodes of a system model of a dual-tank system provided as an exemplary embodiment of this disclosure;
[0042] Figure 3 A schematic diagram of a dual-tank system provided as an exemplary embodiment of this disclosure;
[0043] Figure 4 A schematic diagram of the causal path of energy flow S1 provided for an exemplary embodiment of this disclosure;
[0044] Figure 5 A flowchart for determining anomaly levels provided as an exemplary embodiment of this disclosure;
[0045] Figure 6 A schematic diagram of the causal path of energy flow S2 provided for an exemplary embodiment of this disclosure;
[0046] Figure 7 A schematic diagram illustrating an abnormal alarm result provided in an exemplary embodiment of this disclosure;
[0047] Figure 8 A block diagram of an abnormality alarm device provided as an exemplary embodiment of this disclosure;
[0048] Figure 9 This is a structural diagram of an electronic device provided as an exemplary embodiment of the present disclosure. Detailed Implementation
[0049] The present disclosure is further illustrated below by way of embodiments, but the present disclosure is not limited to the scope of the embodiments described herein.
[0050] The prefixes such as "first" and "second" used in this disclosure are merely for distinguishing different descriptive objects and do not limit the position, order, priority, quantity, or content of the described objects. The use of ordinal numbers and other prefixes used to distinguish descriptive objects in this disclosure does not constitute a limitation on the described objects. The description of the described objects is given in the claims or the context of the embodiments, and should not be construed as an unnecessary limitation. Furthermore, in the description of this embodiment, unless otherwise stated, "multiple" means two or more.
[0051] Industrial systems are typically equipped with alarm systems that operate based on sensor signals. These sensors monitor changes in equipment status in real time and issue alerts to personnel. This system can promptly detect any deviations from normal operating procedures, enabling personnel to take swift corrective action, thereby ensuring the safe operation and economic efficiency of the industrial system.
[0052] Modern large-scale industrial systems are typically equipped with tens of thousands of sensors. While many industrial systems have digitized their main control rooms (MCRs), overcoming spatial limitations in information display, this also significantly increases the workload for staff handling abnormal alarms. Furthermore, when processing alarms, staff often struggle to maintain a holistic view, potentially overlooking or omitting critical anomalies, or even responding inappropriately to incorrect anomalies. This not only poses safety hazards (such as accidentally entering high-risk work areas) but can also lead to economic losses. These challenges underscore the importance of managing abnormal alarm results.
[0053] In recent years, artificial intelligence (AI) technology has made significant progress, and industrial systems are closely monitoring cutting-edge technologies such as deep learning and large-scale language models to explore their potential applications throughout the entire lifecycle of industrial systems, including design, operation, maintenance, and decommissioning. These efforts aim to improve the safety, economic sustainability, and technological advancement of industrial systems.
[0054] Based on this, the embodiments of this disclosure aim to explore and screen advanced and engineering-feasible combinations of artificial intelligence technologies to improve the operational safety and efficiency of nuclear power plants. The anomaly alarm method of this embodiment mainly undertakes two core tasks: (1) reducing the number of anomaly nodes that staff need to handle and monitor under abnormal operating conditions; and (2) optimizing the response efficiency of staff to anomaly nodes. Specifically, an exemplary embodiment of this disclosure provides an anomaly alarm method, see [link to example]. Figure 1 The methods include:
[0055] S101. Obtain at least one abnormal node in the system model of the industrial system and the causal path corresponding to each abnormal node.
[0056] Specifically, industrial systems may include, but are not limited to, petrochemical systems, metallurgical systems, papermaking systems, and nuclear power systems. In this embodiment, nuclear power systems are preferred. The system model of the industrial system is a directed graph representing the causal relationships between the detection points of the industrial system. For details, please refer to... Figure 2 As shown, each node in the system model represents a detection point, and the connections between nodes represent the data propagation relationships between detection points. Data propagation relationships can be, but are not limited to, the propagation relationships of at least one of the following: material flow, energy flow, and information flow. The operational status data of the detection points are the operational status data of equipment in the industrial system, and / or the operational status data collected by detection equipment deployed on the industrial system. Operational status data can include, but is not limited to, at least one of the following parameters: temperature, pressure, displacement, and liquid level, etc. The parameters included in the operational status data can be obtained through the corresponding detection equipment. Each frame of operational status data can also include a detection point identifier to determine its corresponding detection point. It should be noted that in this embodiment, the system model can provide each node (including normal nodes and abnormal nodes) and its corresponding causal path; however, in abnormal alarm application scenarios, typically only abnormal nodes and their corresponding causal paths are referenced.
[0057] In existing industrial systems, parameters, signals, and alarm information are typically communicated to workers via piping and instrumentation diagrams (P&IDs). By associating these signals with the spatial relationships configured within the industrial system, workers can gradually develop conditioned reflex-like response capabilities through training and practical operation. This mechanism is generally suitable for diagnosing common and typical anomalies and can efficiently identify abnormal phenomena in system operation.
[0058] In contrast, the system model provided in this embodiment significantly enhances the ability of personnel to perform alarm analysis in complex and unfamiliar scenarios by providing abnormal nodes and their causal paths. The system model can decompose an industrial system into a multi-level structure where multiple nodes are interconnected through data propagation relationships, accurately depicting the processes and control of the industrial system. As a multi-level structure, the system model establishes causal paths based on the data propagation relationships between each node. Specifically, in the system model, lower-level nodes can serve as the means to implement higher-level nodes. An anomaly triggered by a lower-level node is essentially a warning indicator of an anomaly occurring at a higher-level node. In the system model, the failure of an abnormal node propagates along the data propagation relationships, potentially leading to multiple abnormal nodes upstream or downstream of that abnormal node. Connecting the upstream and downstream abnormal nodes based on the data propagation relationships yields the causal path of that abnormal node. For example, a high flow rate at an upstream flow node (such as a valve) may cause the liquid level in a downstream storage node (such as a storage tank) to rise, forming a causal path between the upstream flow node and the downstream storage node. Furthermore, each abnormal node typically has at least one causal path.
[0059] By tracing the causal path of each anomalous node, staff can quickly pinpoint the root cause of each anomalous node (i.e., the upstream anomalous node in the system model). This capability is particularly crucial in fault analysis involving multiple interconnected anomalous nodes. The system model not only helps infer the causal type of anomalous nodes but also connects their causal paths, highlighting the potential operational risks posed by each anomalous node.
[0060] The following is combined with Figure 2 and Figure 3 The system model is explained in detail using a two-tank system as an example: see [link to relevant documentation]. Figure 3 The system consists of two interconnected water tanks: tank L1 and tank L2. These tanks work together to optimize water heating and management, ensuring stable system operation. Tank L1 is filled with water from an external water source via a pump, and cold water flows from tank L1 to tank L2 through valve 1. In tank L2, the incoming cold water is heated by an electric heater to provide users with hot water at the desired temperature. The operation of the dual-tank system is regulated by two valves, valve 1 and valve 2, which control the outlet flow rates F1 and F2 of tanks L1 and L2, respectively. This flow control mechanism is crucial for maintaining the water level in tank L2, ensuring that the electric heater is submerged below a critical level during operation to prevent it from being exposed and losing its cooling effect. The primary goal of the dual-tank system is to consistently provide users with hot water at a stable temperature. To simplify the system modeling and reasoning process, the power regulation unit of the electric heater is excluded from this analysis. Figure 2The system model established for the two-tank system is shown, which focuses on analyzing three objectives (O1, O2, O3).
[0061] Objective O1 is to maintain the thermal energy of the water supplied to users. This objective is achieved through the energy flow (S1) of the dual-tank system. Specifically, the energy (F6) of the heater heats the cooling water (F1) in tank L2 (F3), and the heated water (F4) is supplied to users (F5) from the outlet of tank L2, meeting temperature maintenance requirements. Other nodes in S1, such as cooling capacity (F2) and the transfer of thermal energy in the water (F7), can affect the thermal energy of the water supplied to users. Since F4 directly delivers heated water to users, it is the key node for achieving O1.
[0062] The objective O2 is to maintain the water level in tank L2. This objective is achieved through mass flow (S2). Specifically, the mixing of cooling water and hot water in tank L2 (F12) is the key node for achieving O2, as it directly affects the water level in tank L2 and ensures that cooling water is adequately stored and mixed with hot water. Other nodes in S2, such as the source of cooling water (F8), cooling water injection into tank L1 (F9), cooling water storage in tank L1 (F10), cooling water transfer to tank L2 (F11), hot water consumption by users (F13), and wastewater discharge (F14), promote the flow and storage of cooling water, thereby contributing to F12 and providing the necessary environment for water level maintenance. Additionally, F3 is also a necessary node for achieving objective O2.
[0063] The objective O3 is to drive the cooling water. This objective is achieved through energy flow (S3). Specifically, the cooling water injection tank L1 (F17) is a major node in S3. Other nodes in S3, such as power supply (F15) and applying electricity to the pump (F16), which converts the electricity into mechanical energy (F17), can drive the cooling water into the system, providing the necessary mechanical force for the energy conversion process to facilitate the movement of the cooling water in the system.
[0064] This system model effectively maps the goals of an industrial system to each node. When an abnormal node appears in the industrial system, the system model can deduce the causal path of the abnormal node based on data propagation relationships, such as... Figure 4 As shown, the low water temperature in water tank L2 (the low state of F3) Figure 4 (As indicated by low temperature) will cause the water temperature at the outlet of tank L2 to drop (low state of F4). Figure 4 (characterized by low levels), and will also trigger an increase in the power of the electric heater (high state of F7). Figure 4By using a high-level characterization to compensate for the temperature drop in water tank L2, the causal paths corresponding to abnormal nodes such as F3 (low state), F4 (low state), and F7 (high state) can be determined. These paths include: F3 (low state) → F4 (low state), F3 (low state) → F7 (high state), F4 (low state) ← F3 (low state) → F7 (high state), F4 (low state), F3 (low state), F7 (high state), and so on. By following this causal relationship, the root cause of faults in industrial systems can be more accurately deduced, providing a solid foundation for maintenance decisions and system optimization.
[0065] The system model in this embodiment can intuitively present the causal path of abnormal nodes. This design stems from the observation during daily use that staff currently prefer a simple and clear presentation of abnormal alarms, thereby reducing the cognitive burden when interpreting complex intelligent technologies. As artificial intelligence technology becomes more deeply integrated into the operation of industrial systems and staff receive more training, more advanced human-computer interaction interfaces and methods can be gradually adopted in the system model in the future. This will not only present richer visualizations of causal paths but also provide more scientific basis for staff decision-making.
[0066] In one embodiment, the system model can also be obtained by processing the operational data of the detection points in the industrial system using a multilayer flow model (MFM) modeling method. The multilayer flow model reflects the relationships between targets and nodes in the industrial system, allowing for functional analysis (causal analysis) based on principles of mass or energy conservation or control theory.
[0067] S102. Based on each abnormal node and its corresponding causal path, determine multiple abnormal node characteristics for each abnormal node.
[0068] Each anomaly node feature has a different priority. These features include, but are not limited to, multiple dimensions such as anomaly level, causal type, explanatory power ratio, and time point. For example, the priority of anomaly level > causal type > explanatory power ratio > time point. Specific priorities can be adjusted as needed, and will not be elaborated upon in this embodiment. By determining multiple anomaly node features for each anomaly node, the event and time attributes of each anomaly node can be displayed more intuitively. When staff need to handle alarms from anomaly nodes, these multi-dimensional anomaly node features can help them gain a more comprehensive understanding of the relevant information. Furthermore, setting different priorities for each anomaly node feature allows for prioritizing anomaly nodes with a greater impact in the industrial system when generating anomaly alarm results, improving the efficiency of staff processing.
[0069] In one embodiment, the abnormal node characteristics include anomaly level, and the sorting strategy corresponding to the anomaly level is that abnormal nodes with higher anomaly levels are sorted before abnormal nodes with lower anomaly levels. Step S102 specifically includes:
[0070] Identify the alarm events for abnormal nodes. Using the alarm events as indexes, determine the abnormal level corresponding to the abnormal node from the event level classification library, where alarm events correspond to abnormal levels.
[0071] The event level classification library is typically constructed based on common alarm events encountered during the operation of industrial systems. Furthermore, the event level classification library can also be fitted to an artificial intelligence model. The AI model can learn the relationship between alarm events and anomaly levels in the event level classification library. Inputting the alarm events of identified anomaly nodes into the AI model can output the corresponding anomaly level. The specific implementation method is not particularly limited in this embodiment.
[0072] like Figure 5 As shown, in traditional industrial systems, anomaly levels are typically classified using a funnel-shaped hierarchy. Alarm events from anomaly nodes undergo a three-stage filtering process, categorized into four different anomaly levels based on severity and urgency. Red represents the first level, corresponding to critical situations requiring immediate human intervention. Yellow represents the second level, where the industrial system cannot handle the situation automatically but allows for a delayed response, providing leeway for handling. Green represents the third level, where the industrial system can handle the situation automatically, but human monitoring of the automated process is still required, with manual intervention only necessary if automation fails. Finally, white represents the fourth level, indicating that the industrial system can handle the situation automatically without further human intervention. From first to fourth level, the anomaly levels represent decreasing urgency and severity of the alarm events at the anomaly node. This anomaly level classification effectively improves alarm management efficiency, allowing staff to prioritize actions based on severity. The funnel-shaped hierarchy, by filtering lower-level anomalies, effectively reduces staff workload, allowing them to focus on higher-level anomalies.
[0073] In one embodiment, the abnormal node characteristics include causal type, and the sorting strategy corresponding to the causal type is that abnormal nodes with cause-type alarms are sorted before abnormal nodes with result-type alarms. Step S102 specifically includes:
[0074] Based on the causal path, determine the number of upstream abnormal nodes of the abnormal node. When the number of upstream abnormal nodes is less than one, the causal type of the abnormal node is determined to be a cause-based alarm; or when the number of upstream abnormal nodes is greater than or equal to one, the causal type of the abnormal node is determined to be a result-based alarm.
[0075] This classification method originates from the system model's inference of abnormal nodes. Cause-based alarms refer to abnormal nodes that have no upstream input events (i.e., upstream abnormal nodes) in any causal path, meaning their occurrence cannot be explained by other abnormal nodes. Conversely, result-based alarms refer to abnormal nodes that can be traced back to a certain upstream input event (i.e., upstream abnormal node) in any causal path as the cause of the abnormal node's occurrence.
[0076] by Figure 4 As an example, the above embodiments have illustrated multiple causal paths between abnormal nodes F3 (low state), F4 (low state), and F7 (high state), including F3 (low state) → F4 (low state), F3 (low state) → F7 (high state), F4 (low state) ← F3 (low state) → F7 (high state), F4 (low state), F3 (low state), and F7 (high state). Taking F3 (low state) as an example, it can be seen from the causal paths related to F3 (low state) that there are no upstream abnormal nodes for F3 (low state); therefore, F3 (low state) is a cause-based alarm. Taking F7 (high state) as an example, it can be seen from the causal paths related to F7 (high state) that the upstream abnormal node for F7 (high state) includes at least F3 (low state); therefore, F7 (high state) is a result-based alarm.
[0077] In one embodiment, the abnormal node characteristics include the explanation ratio, and the ranking strategy corresponding to the explanation ratio is that abnormal nodes with a larger explanation ratio are ranked before abnormal nodes with a smaller explanation ratio. Step S102 specifically includes:
[0078] Determine the target causal path for the abnormal nodes. The target causal path is the causal path containing the most abnormal nodes. Calculate the ratio between the number of abnormal nodes in the target causal path and the total number of abnormal nodes to obtain the explanation ratio of the abnormal nodes.
[0079] Combination Figure 2 and Figure 6 The abnormal nodes in energy flow S2 are described below. Based on the causal relationships in the system model, the target causal paths of the abnormal nodes are obtained as shown in the table below:
[0080]
[0081] The total number of anomalous nodes in energy flow S2 includes 8 nodes: F9 (high state), F9 (low state), F10 (high state), F11 (low state), F11 (low state), F12 (low state), and F13 (low state). When the anomalous node is F11 (low state), its corresponding target causal path is F9 (low state) ← F10 (high state) ← F11 (low state) → F12 (low state) → F13 (low state), which is 5. Based on the ratio of 5 anomalous nodes in the target causal path to the total number of 8 anomalous nodes, the explanation ratio of anomalous node F11 (low state) is calculated to be 62.5%. The explanation ratios of other anomalous nodes are calculated similarly and will not be elaborated further. The explanatory ratio is used to assess the probability that the anomaly can explain the occurrence of other anomalies in the causal path. The higher the explanatory ratio, the more effective the staff's handling of the anomaly is, highlighting the potential to correct or mitigate other unresolved anomalies by handling the anomaly. The characteristics of this anomaly provide an important reference for understanding the staff's response strategies and achieving comprehensive alarm management.
[0082] In one embodiment, the abnormal node features include time nodes, and the sorting strategy corresponding to the time nodes is that abnormal nodes with earlier time nodes are sorted before abnormal nodes with later time nodes. Step S102 specifically includes:
[0083] Determine the time point for each abnormal node.
[0084] Specifically, based on the assumption of "temporal causality," an abnormal node that triggers an alarm earlier is more likely to cause subsequent abnormal nodes to trigger alarms, and therefore needs to be handled first. However, due to the complexity of industrial systems and the specific threshold settings for abnormal nodes, this assumption does not always hold true. In this embodiment, the priority of the time node as an abnormal node feature is set low. Typically, when the ranking cannot be determined based on other abnormal node features, the time node will be used as the final judgment criterion. Therefore, abnormal nodes with earlier time nodes will be assigned a higher ranking to correspond to the handling requirements of potential cascading faults.
[0085] S103. According to priority, use the sorting strategy corresponding to the feature of each abnormal node in turn to sort all abnormal nodes in at least one abnormal node in a multi-level sorting to obtain the abnormal alarm result.
[0086] The abnormal alarm result includes all abnormal nodes in at least one abnormal node and their corresponding order, and may also include multiple abnormal node features corresponding to all abnormal nodes in at least one abnormal node.
[0087] Specifically, based on the abnormal node characteristics in the above example, the priority is: Abnormal level > Causal type > Explanation ratio > Time node. Specifically, the ranking strategy for abnormal levels is: higher-level abnormal nodes are ranked before lower-level abnormal nodes; the ranking strategy for causal types is: causal alarms are ranked before result-type alarms; the ranking strategy for explanation ratios is: larger-explanation-ratio abnormal nodes are ranked before smaller-explanation-ratio abnormal nodes; and the ranking strategy for time nodes is: earlier-time abnormal nodes are ranked before later-time abnormal nodes.
[0088] When an industrial system malfunctions, staff typically need to prioritize higher-level anomalies. However, when multiple anomalies of the same level trigger alarms simultaneously, conventional solutions rely solely on staff experience to determine which anomaly to handle first. In such situations, staff not only face multiple potentially urgent and equally important alarms but also need to make rapid decisions, undoubtedly placing immense psychological pressure and workload on them. This embodiment provides a multi-level sorting scheme, first dividing anomalies into multiple priority levels based on their characteristics, and then sorting the anomalies sequentially according to their priority order using a sorting strategy corresponding to each anomaly's characteristics. In one embodiment, step S103 includes:
[0089] First, sort all abnormal nodes within at least one abnormal node according to the sorting strategy corresponding to the highest priority abnormal node feature. Taking the abnormal node features in the example above as an example, first sort according to the sorting strategy corresponding to the abnormal level to obtain the sorting of all abnormal nodes. If all abnormal nodes obtain different sortings, the alarm result can be directly output. However, since there may be abnormal nodes with the same abnormal level within at least one abnormal node, after sorting according to the abnormal level sorting strategy, there may be abnormal nodes with the same sorting.
[0090] For anomaly nodes with the same ranking, they are sequentially sorted according to the ranking strategy corresponding to the anomaly node features of the next lower priority until the ranking stopping condition is met, resulting in an anomaly alarm. The ranking stopping condition includes either determining that the anomaly nodes have different rankings, or traversing all ranking strategies corresponding to the anomaly node features. Taking the anomaly node features in the example above as an example, they are sequentially sorted according to the ranking strategy corresponding to the causal type, the ranking strategy corresponding to the explanation ratio, and the ranking strategy corresponding to the time node. It should be noted that when applying the ranking strategy corresponding to the anomaly node features of the next lower priority, the objects processed are usually the anomaly nodes with the same ranking obtained from the ranking strategy corresponding to the anomaly node features of the previous priority, and it is not necessarily necessary to re-rank all anomaly nodes.
[0091] In one embodiment, step S103 is followed by:
[0092] Display the results of abnormal alarms.
[0093] Anomaly alarm results, as a standard monitoring tool in industrial systems, can comprehensively present the entire picture of abnormal nodes. For details, please refer to... Figure 7 This system allows the user interface to display all anomalous nodes from at least one anomaly node in a sorted order. It also includes key information such as anomaly level, ID number, description, cause-effect type, grouping information, and time period. Compared to existing alarm methods, displaying anomalous nodes in a sorted order helps staff respond promptly to the highest-ranking anomalous nodes. Furthermore, this method of displaying key information for each anomalous node provides staff with comprehensive information for analyzing the anomalies.
[0094] In an optional implementation, the anomaly alarm results also include intermediate variables. This is because the inference of anomaly nodes is typically based on intermediate variables introduced into the system model. These intermediate variables represent the operating status data of specific equipment in an industrial system, since real-world industrial systems often lack corresponding measurement equipment to detect the status. Therefore, intermediate variables are introduced as part of the causal path for establishing anomaly nodes; otherwise, it would be difficult to construct a direct causal path between anomaly nodes. Intermediate variables enable the establishment of causal paths for anomaly nodes when measurement equipment is missing or incomplete in traditional industrial systems. However, due to the inherent uncertainty of intermediate variables (i.e., the lack of direct measurement data), intermediate variables do not appear directly in the anomaly alarm results. The user interface hides intermediate variables by default to avoid interfering with the operator's view with uncertain information. However, when necessary, operators can choose to restore the display to help them better understand the propagation process and interpret the root causes of the anomaly nodes. This feature can provide a more comprehensive view of the industrial system's behavior when the operating status data of the measurement points is unavailable or incomplete.
[0095] In one optional implementation, another key feature of the abnormal alarm results is the alarm suppression function. This function allows staff to filter alarms based on preset criteria (such as anomaly level, causal type, time point, explanation ratio, etc.) to remove unwanted anomalies, such as result-based alarms or confirmed anomalies. The alarm suppression function can be triggered by double-clicking. Figure 7 The corresponding ID number triggers a pop-up window to configure preset standards. Suppressed abnormal nodes will be temporarily removed from the abnormal alarm results and stored in [the relevant database]. Figure 7The restored display is shown. Staff can also cancel the alarm suppression function at any time, allowing suppressed anomalies to be displayed normally in the anomaly alarm results. This mechanism ensures that suppressed anomalies are not forgotten while allowing staff to focus on the most urgent anomalies.
[0096] In one embodiment, step S103 is followed by:
[0097] The alarm results will be indicated by sound and / or light.
[0098] Specifically, when an abnormal alarm result occurs, staff can be alerted through sound and / or light. Upon noticing the abnormal alarm, staff should follow the alarm response procedure below:
[0099] The first step is to mute and stop the flashing lights so that staff can focus on assessing the situation without being distracted by the continuous alarms.
[0100] The second step is to confirm by pressing a button or key to indicate that staff have noticed the alarm.
[0101] The third step is cause identification. Staff members use the information in the abnormal alarm results to determine the root cause of the alarm.
[0102] The fourth step is to reset the alarm. After eliminating the cause of the alarm, the staff will trigger the alarm again, causing the indicator light to flash again, until the alarm is manually or automatically reset and the system returns to normal.
[0103] This structured response process ensures that staff can respond to alerts effectively and minimize risks.
[0104] In this embodiment, industrial systems often generate a large number of alarms under abnormal operating conditions, making it difficult for staff to analyze and respond appropriately in a timely manner. By analyzing abnormal nodes and their causal paths, multiple abnormal node characteristics are determined, and the abnormal nodes are ranked according to a ranking strategy corresponding to these characteristics. This ranking can construct abnormal alarm results based on the urgency and importance of the abnormal nodes. The higher the abnormal node is ranked, the more effective the handling of that abnormal node is. This allows staff to ensure the safety of the industrial system while maintaining its availability and reliability by handling the higher-ranked abnormal nodes.
[0105] In practical applications, verification was conducted using an industrial system within a nuclear power plant. Regarding the speed and accuracy of anomaly identification (especially cause-based alarms), the anomaly alarm method of this embodiment outperformed the identification speed of human operators. In verification across 10 typical operating conditions, encompassing single and multiple faults (each fault mode generating 8-10 anomaly nodes), the decision-making speed of personnel using the anomaly alarm method of this embodiment was 7%-32% faster than traditional methods. Furthermore, subjective feedback from personnel indicated a significant reduction in workload after using the anomaly alarm method of this embodiment.
[0106] Corresponding to the aforementioned embodiments of the abnormal alarm method, this disclosure also provides embodiments of the abnormal alarm device. Figure 8 A schematic diagram of an abnormality alarm device provided for an exemplary embodiment of this disclosure, the device comprising:
[0107] The acquisition module 81 is used to acquire at least one abnormal node in the system model of the industrial system and the causal path corresponding to each abnormal node.
[0108] The determination module 82 is used to determine multiple abnormal node features for each abnormal node based on each abnormal node and its corresponding causal path. Each abnormal node feature has a different priority.
[0109] The sorting module 83 is used to sort all abnormal nodes in at least one abnormal node in a multi-level manner according to priority and by using the sorting strategy corresponding to the characteristics of each abnormal node in turn, so as to obtain the abnormal alarm result.
[0110] In one embodiment, the system model is built based on operational data from the detection points of the industrial system. Each node in the system model represents a detection point, and the connections between nodes represent the data propagation relationships between the detection points.
[0111] In one embodiment, the system model is obtained by processing the operational data of the detection points of the industrial system using a multi-layer flow modeling method.
[0112] In one embodiment, the sorting module 83 is further configured to:
[0113] Sort all abnormal nodes in at least one abnormal node according to the sorting strategy corresponding to the highest priority abnormal node feature.
[0114] For abnormal nodes with the same ranking, sort them sequentially according to the ranking strategy corresponding to the characteristics of the next lower priority abnormal node, until the ranking stopping condition is met, and the abnormal alarm result is obtained. The ranking stopping condition includes determining that the abnormal nodes have different rankings, or traversing all the ranking strategies corresponding to the characteristics of all abnormal nodes.
[0115] In one embodiment, the abnormal node characteristics include anomaly level. The sorting strategy corresponding to the anomaly level is that abnormal nodes with higher anomaly levels are sorted before abnormal nodes with lower anomaly levels.
[0116] Module 82 is also used for:
[0117] Identify alarm events for abnormal nodes.
[0118] Using alarm events as indexes, the anomaly level corresponding to the abnormal node is determined from the event level classification library. Alarm events in the event level classification library correspond to anomaly levels.
[0119] In one embodiment, the abnormal node characteristics include causal type. The sorting strategy corresponding to the causal type is that abnormal nodes with cause-based alarms are sorted before abnormal nodes with result-based alarms.
[0120] Module 82 is also used for:
[0121] Based on the causal path, determine the number of upstream abnormal nodes of the abnormal node.
[0122] When the number of abnormal upstream nodes is less than one, the cause type of the abnormal node is determined to be a cause-based alarm.
[0123] When the number of abnormal upstream nodes is greater than or equal to one, the causal type of the abnormal nodes is determined to be a result-type alarm.
[0124] In one embodiment, the characteristics of anomalous nodes include the explanatory ratio. The ranking strategy corresponding to the explanatory ratio is to prioritize anomalous nodes with a larger explanatory ratio over anomalous nodes with a smaller explanatory ratio.
[0125] Module 82 is also used for:
[0126] Identify the target causal path with the most abnormal nodes in the causal path.
[0127] The ratio of the number of anomalous nodes in the target causal path to the total number of anomalous nodes is calculated to obtain the explanation ratio of anomalous nodes.
[0128] In one embodiment, the abnormal node characteristics include time nodes. The sorting strategy corresponding to the time nodes is that abnormal nodes with earlier time nodes are sorted before abnormal nodes with later time nodes.
[0129] Module 82 is also used for:
[0130] Determine the time point for each abnormal node.
[0131] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separate, and the components as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this disclosure according to actual needs.
[0132] This disclosure also provides an electronic device in one example embodiment. The electronic device includes a memory, a processor, and a computer program stored in the memory and used to run on the processor. When the processor executes the computer program, it implements the abnormal alarm method of any of the above embodiments. Figure 9 The electronic device 90 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments disclosed herein.
[0133] like Figure 9 As shown, the electronic device 90 can be manifested as a general-purpose computing device, such as a server device. The components of the electronic device 90 may include, but are not limited to: at least one processor 91, at least one memory 92, and a bus 93 connecting different device components (including memory 92 and processor 91).
[0134] Bus 93 includes a data bus, an address bus, and a control bus.
[0135] The memory 92 may include volatile memory, such as random access memory (RAM) 921 and / or cache memory 922, and may further include read-only memory (ROM) 923.
[0136] The memory 92 may also include a program tool 925 (or utility) having a set (at least one) program module 924, such program module 924 including but not limited to: operating device, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.
[0137] The processor 91 executes various functional applications and data processing by running computer programs stored in the memory 92, such as the abnormal alarm method provided in any of the above embodiments.
[0138] Electronic device 90 can also communicate with one or more external devices 94 (e.g., keyboard, pointing device, etc.). This communication can be performed through input / output (I / O) interface 95. Furthermore, electronic device 90 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public network, such as the Internet) via network adapter 96. As shown, network adapter 96 communicates with other modules of electronic device 90 via bus 93. It should be understood that, although... Figure 9 As not shown, other hardware and / or software modules may be used in conjunction with electronic device 90, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID (disk array) devices, tape drives, and data backup storage devices.
[0139] It should be noted that although several units / modules or sub-units / modules of the electronic device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more units / modules described above can be embodied in one unit / module. Conversely, the features and functions of one unit / module described above can be further divided and embodied by multiple units / modules.
[0140] An exemplary embodiment of this disclosure also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the abnormal alarm method provided in any of the above embodiments.
[0141] The readable storage medium may be more specifically adopted, including but not limited to: portable disk, hard disk, random access memory, read-only memory, erasable programmable read-only memory, optical storage device, magnetic storage device, or any suitable combination thereof.
[0142] An exemplary embodiment of this disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the abnormal alarm method described in any of the preceding claims.
[0143] The program code for executing the computer program product of this disclosure can be written in any combination of one or more programming languages, and the program code can be executed entirely on a user device, partially on a user device, as a stand-alone software package, partially on a user device and partially on a remote device, or entirely on a remote device.
[0144] While specific embodiments of this disclosure have been described above, those skilled in the art should understand that these are merely illustrative examples, and the scope of protection of this disclosure is defined by the appended claims. Those skilled in the art can make various changes or modifications to these embodiments without departing from the principles and essence of this disclosure, but all such changes and modifications fall within the scope of protection of this disclosure.
Claims
1. An abnormal alarm method, characterized in that, The method includes: Obtain at least one abnormal node in the system model of the industrial system and the causal path corresponding to each abnormal node; Based on each abnormal node and its corresponding causal path, multiple abnormal node features are determined for each abnormal node; each abnormal node feature has a different priority. The characteristics of the abnormal nodes include causal type and explanatory ratio; The sorting strategy corresponding to the cause-effect type is that the sorting of abnormal nodes of cause-type alarms takes precedence over the sorting of abnormal nodes of result-type alarms. The step of determining multiple abnormal node features for each abnormal node based on each abnormal node and its corresponding causal path includes: Based on the causal path, determine the number of upstream abnormal nodes of the abnormal node; When the number of upstream abnormal nodes is less than one, the cause type of the abnormal node is determined to be a cause-based alarm; When the number of upstream abnormal nodes is greater than or equal to one, the causal type of the abnormal node is determined to be a result-type alarm; The sorting strategy corresponding to the explanation ratio is that the sorting of abnormal nodes with a larger explanation ratio takes precedence over the sorting of abnormal nodes with a smaller explanation ratio. The step of determining multiple abnormal node features for each abnormal node based on each abnormal node and its corresponding causal path includes: Identify the target causal path with the highest number of abnormal nodes in the causal path; Calculate the ratio between the number of anomalous nodes in the target causal path and the total number of anomalous nodes to obtain the explanation ratio of the anomalous nodes; According to the priority, the sorting strategy corresponding to the feature of each abnormal node is used in turn to sort all the abnormal nodes in the at least one abnormal node in a multi-level sorting process to obtain the abnormal alarm result. The step involves sequentially sorting all abnormal nodes in the at least one abnormal node according to the priority, using the sorting strategy corresponding to the features of each abnormal node, to obtain an abnormal alarm result, including: Sort all abnormal nodes in the at least one abnormal node according to the sorting strategy corresponding to the highest priority abnormal node feature; For abnormal nodes with the same sorting, sort them sequentially according to the sorting strategy corresponding to the characteristics of the next lower priority abnormal node until the sorting stopping condition is met, and an abnormal alarm result is obtained; the sorting stopping condition includes determining different sorting among the abnormal nodes, or traversing all sorting strategies corresponding to the characteristics of all abnormal nodes.
2. The abnormal alarm method as described in claim 1, characterized in that, The system model is built based on the operational data of the detection points in the industrial system; each node in the system model represents a detection point, and the connection relationship between nodes represents the data propagation relationship between the detection points. And / or, the system model is obtained by processing the operational data of the detection points of the industrial system using a multi-layer flow modeling method.
3. The abnormal alarm method as described in claim 1, characterized in that, The abnormal node characteristics also include an abnormality level; the sorting strategy corresponding to the abnormality level is that abnormal nodes with higher abnormality levels are sorted in priority over abnormal nodes with lower abnormality levels. The step of determining multiple abnormal node features for each abnormal node based on each abnormal node and its corresponding causal path includes: Determine the alarm events of the abnormal nodes; Using the alarm event as an index, the abnormality level corresponding to the abnormal node is determined from the event level classification library; the alarm events in the event level classification library correspond to the abnormality levels.
4. The abnormal alarm method as described in claim 1, characterized in that, The abnormal node features also include time nodes; the sorting strategy corresponding to the time nodes is that abnormal nodes with earlier time nodes are sorted in order of priority over abnormal nodes with later time nodes. The step of determining multiple abnormal node features for each abnormal node based on each abnormal node and its corresponding causal path includes: Determine the time point for each abnormal node.
5. An abnormal alarm device, characterized in that, The device includes: The acquisition module is used to acquire at least one abnormal node in the system model of the industrial system and the causal path corresponding to each abnormal node. The determination module is used to determine multiple abnormal node features for each abnormal node based on each abnormal node and its corresponding causal path; each abnormal node feature has a different priority. The characteristics of the abnormal nodes include causal type and explanatory ratio; The sorting strategy corresponding to the cause-effect type is that the sorting of abnormal nodes of cause-type alarms takes precedence over the sorting of abnormal nodes of result-type alarms. The determining module is also used for: Based on the causal path, determine the number of upstream abnormal nodes of the abnormal node; When the number of upstream abnormal nodes is less than one, the cause type of the abnormal node is determined to be a cause-based alarm; When the number of upstream abnormal nodes is greater than or equal to one, the causal type of the abnormal node is determined to be a result-type alarm; The sorting strategy corresponding to the explanation ratio is that the sorting of abnormal nodes with a larger explanation ratio takes precedence over the sorting of abnormal nodes with a smaller explanation ratio. The determining module is also used for: Identify the target causal path with the highest number of abnormal nodes in the causal path; Calculate the ratio between the number of anomalous nodes in the target causal path and the total number of anomalous nodes to obtain the explanation ratio of the anomalous nodes; The sorting module is used to sort all the abnormal nodes in the at least one abnormal node according to the priority and the sorting strategy corresponding to the feature of each abnormal node in turn to obtain the abnormal alarm result. The sorting module is also used for: Sort all abnormal nodes in the at least one abnormal node according to the sorting strategy corresponding to the highest priority abnormal node feature; For abnormal nodes with the same sorting, sort them sequentially according to the sorting strategy corresponding to the characteristics of the next lower priority abnormal node until the sorting stopping condition is met, and an abnormal alarm result is obtained; the sorting stopping condition includes determining different sorting among the abnormal nodes, or traversing all sorting strategies corresponding to the characteristics of all abnormal nodes.
6. An electronic device comprising a memory, a processor, and a computer program stored in the memory and for running on the processor, characterized in that, When the processor executes the computer program, it implements the abnormal alarm method as described in any one of claims 1-4.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the abnormal alarm method as described in any one of claims 1-4.
8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the abnormal alarm method as described in any one of claims 1-4.
Citation Information
Patent Citations
Alarm analysis reasoning method and device, electronic equipment, medium and program product
CN118821946A
Power equipment anomaly detection method and device, equipment and storage medium
CN121116610A