Intelligent interaction method and system for energy internet based on cognitive computing

CN122412846BActive Publication Date: 2026-09-29BEIJING SMART CHINA ENERGY INTERNET RES INST CO
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610578901.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-04-29
Publication Date
2026-09-29
Estimated Expiration
2046-04-29

AI Technical Summary

Technical Problem

但是通常假设数据特征之间或节点关系是静态或预先定义的,未能充分考虑运行数据中复杂的时序因果关系,以及超越直接连接的多跳、高阶节点间动态依赖

Benefits of technology

[0017]本发明中,通过构建融合因果推断与高阶依赖关系的动态状态图谱,能够深入解析能源互联网的运行机理。时间窗口分解与多跳聚合技术,不仅捕捉了节点运行的时序动态,更揭示了网络深层的拓扑依赖,基于认知表征的因果路径发现,有效过滤了无关时序噪声,明确了关键影响因素间的因果关系,为精准干预奠定了可靠的状态认知基础,通过计算关联强度锁定关键响应节点集,并基于认知表征对节点的多步演化轨迹进行前瞻性推演与筛选,从而确定符合用户期望的目标演化路径,将用户的主观意愿有机地嵌入到客观系统的状态演化预测中,确保了响应策略不仅技术上可行,更与用户意图高度契合。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122412846B_ABST
    Figure CN122412846B_ABST
Patent Text Reader

Abstract

The application provides an energy internet intelligent interaction method and system based on cognitive computing, relates to the technical field of energy internet, and comprises the following steps: analyzing user input to generate cognitive representation, constructing a state graph based on energy node data, performing semantic alignment and determining a response node set, deducing a target evolution track, and finally generating and issuing an optimal scheduling scheme. The application realizes deep understanding of user intention and accurate coupling of the state of the energy system, and improves the intelligence of interaction and scheduling efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of energy internet technology, and in particular to an intelligent interaction method and system for energy internet based on cognitive computing. Background Technology

[0002] In the field of energy internet, achieving efficient and intelligent interaction between users and complex energy systems is key to improving system operating efficiency and user experience. Mainstream intelligent interaction methods usually rely on predefined rules or statistical learning-based models to process user commands and generate system responses.

[0003] Conventional methods typically handle user input and system status through separate processes. On the user side, common practices include parsing explicit user commands (such as natural language queries) and recording their operation logs separately. However, these are often treated as isolated information sources, performing only simple intent classification or behavioral pattern statistics, lacking a unified modeling of the intrinsic relationship between users' deep cognitive intent and behavioral habits. This results in the system's understanding of users' true needs remaining superficial, failing to capture their dynamically changing comprehensive intents, and limiting the accuracy and personalization of interactions.

[0004] In terms of system state awareness, existing technologies mostly focus on time-series analysis of energy node operating data or the mining of correlations based on fixed topologies. For example, they analyze node load through time-series prediction models or use graph neural networks to learn the impact of nodes under known connections. However, these technologies typically assume that the relationships between data features or nodes are static or predefined, failing to fully consider the complex temporal causal relationships in the operating data, as well as the dynamic dependencies between multi-hop and higher-order nodes that go beyond direct connections. This results in system state models that are not accurate and comprehensive enough to support accurate predictions of system evolution under complex interventions.

[0005] In summary, existing intelligent interaction methods for the energy internet have limitations in terms of unified representation of user cognition and in-depth modeling of system states, which affect the level of intelligence of interaction and the overall system efficiency. Summary of the Invention

[0006] This invention provides an intelligent interaction method and system for the energy internet based on cognitive computing, which can at least solve some of the problems existing in the prior art.

[0007] A first aspect of this invention provides an intelligent interaction method for the energy internet based on cognitive computing, comprising: The system receives natural language input and operation behavior input from users, performs semantic parsing on the natural language input to extract intent features, performs temporal encoding on the operation behavior input to extract behavior features, and concatenates these with the intent features to obtain a cognitive representation. The system acquires operational data and topology data of energy nodes, decomposes the operational data into time windows to extract temporal features, performs multi-hop aggregation on each energy node based on the topology data to obtain higher-order dependencies, filters the temporal features and performs conditional independence tests based on the cognitive representation to determine causal paths, marks the causal paths as directed edges and encodes them with the higher-order dependencies to generate a state graph. The cognitive representation and the state graph are projected onto the semantic space for semantic alignment to obtain a semantic alignment result. Based on the semantic alignment result, the association strength of each feature in the cognitive representation to the nodes in the state graph is calculated and a response node set is determined. The current state of each node in the response node set is forward extrapolated to generate multiple evolution trajectories, and the target evolution trajectory is obtained by filtering based on the cognitive representation. Based on the target evolution trajectory and preset scheduling constraints, a set of candidate solutions is generated. The execution effect and resource consumption of each solution in the set of candidate solutions are evaluated, the optimal solution is determined, and the solution is issued for execution.

[0008] In one alternative implementation, Receiving natural language input and operational behavior input from a user, performing semantic parsing on the natural language input to extract intent features, and performing temporal encoding on the operational behavior input to extract behavioral features, concatenating these with the intent features to obtain a cognitive representation, including: The system receives natural language input and operation behavior input from users through an interactive interface. It preprocesses the natural language input to remove invalid characters and obtains the text content. It records and parses the operation behavior input to obtain the operation type and operation timestamp. The text content is segmented and part-of-speech tagging is performed to obtain a word sequence. Semantic embedding is performed on each word in the word sequence to obtain a word vector. The word vector is then context-associated encoded based on an attention mechanism to obtain a semantic representation sequence. Key semantic components in the semantic representation sequence are identified and the importance weight corresponding to each key semantic component is calculated. The semantic representation sequence is then weighted and pooled based on the importance weight to obtain the intent feature. The operation types are sorted by time according to the operation timestamp to obtain an operation sequence. Each operation type in the operation sequence is encoded and mapped to obtain an operation vector sequence. The operation vector sequence is temporally encoded and temporal dependencies are modeled to obtain the behavioral features. The cognitive representation is obtained by concatenating the intention feature and the behavioral feature along the feature dimension and normalizing them.

[0009] In one alternative implementation, The process involves acquiring operational and topological data of energy nodes, extracting temporal features from the operational data through time window decomposition, and performing multi-hop aggregation on each energy node based on the topological data to obtain higher-order dependencies, including: The system acquires the operational data and topology data of each energy node, performs anomaly detection on the operational data and marks abnormal time periods, extracts the connection relationships and energy flow directions between energy nodes from the topology data, and constructs a directed topology graph. The abnormal time period is divided into multiple time window data blocks by sliding segmentation according to a preset time window. Wavelet multi-scale decomposition is performed on each time window data block to obtain sub-signals of different frequency bands. The trend component and residual component corresponding to each frequency band sub-signal are extracted. Autocorrelation analysis is performed on the trend component to extract the periodic pattern. Higher-order moment statistics are performed on the residual component to extract the fluctuation pattern. The periodic pattern and the fluctuation pattern are fused to obtain the time series feature. The directed topological graph is converted into a Laplacian matrix and spectral decomposition is performed to obtain the graph feature basis. The graph feature basis is truncated to select and retain the dominant feature patterns. A graph convolution operator is constructed based on the dominant feature patterns. The graph convolution operator is applied to the initial feature vector corresponding to each energy node to perform multi-layer propagation and residual connection to obtain the propagation features of each layer. The attention score corresponding to the propagation features is calculated and cross-layer feature aggregation is performed based on the attention score. Graph pooling is performed on the aggregated features to obtain the higher-order dependencies between nodes.

[0010] In one alternative implementation, Based on the cognitive representation, the temporal features are screened and conditional independence tests are performed to determine causal paths. These causal paths are then marked as directed edges and encoded with the higher-order dependencies to generate a state graph, including: Calculate the cosine similarity between the cognitive representation and each temporal feature in the temporal features, filter the temporal features based on a preset similarity threshold, and retain the temporal features with a cosine similarity greater than the similarity threshold to obtain a filtered temporal feature set; The time series features in the filtered time series feature set are paired up to obtain a feature pair set. A set of control variables is introduced into each feature pair in the feature pair set and the influence of the control variable set on the feature pair is calculated. Based on the influence, partial correlation analysis is performed on the feature pair to obtain a conditional independence index. The causal direction and causal strength between feature pairs are determined according to the conditional independence index. Significant causal relationships are screened based on the causal strength and the causal direction is recorded to obtain the causal path. The causal relationships in the causal path are mapped to directed edges, and the causal strength is used as the edge weight. A node set is constructed based on the energy nodes corresponding to the time-series features and the energy nodes corresponding to the higher-order dependencies. The directed edges and the connection relationships in the higher-order dependencies are merged into an edge set. The feature vector of each energy node in the node set is encoded and weighted by combining the edge weights to obtain the state graph.

[0011] In one alternative implementation, The cognitive representation and the state graph are projected onto a semantic space for semantic alignment to obtain a semantic alignment result. Based on the semantic alignment result, the association strength of each feature in the cognitive representation to the nodes in the state graph is calculated, and the set of response nodes is determined, including: A linear transformation is performed on the cognitive representation to obtain a cognitive representation projection vector. A linear transformation is performed on the feature vector encoding of each node in the state graph to obtain a set of node projection vectors. The cognitive representation projection vector and the node projection vectors in the set of node projection vectors are performed in a unified semantic space to obtain an initial alignment score. A softmax transformation is performed on the initial alignment score to obtain an alignment probability distribution. The set of node projection vectors is then weighted and summed to obtain an alignment vector. The Euclidean distance between the cognitive representation projection vector and the alignment vector is calculated to obtain the alignment error. The semantic alignment result is determined based on the alignment error and the alignment probability distribution. The intention feature component and the behavior feature component are separated from the cognitive representation. The intention feature component is decomposed to obtain an intention sub-feature set, and the behavior feature component is decomposed to obtain a behavior sub-feature set. Based on the semantic alignment result, the association strength between each sub-feature in the intention sub-feature set and the behavior sub-feature set and each node in the state graph is calculated. The association strengths corresponding to the intention sub-feature set and the behavior sub-feature set are fused to obtain a comprehensive association strength. The nodes in the state graph are then filtered to obtain the response node set.

[0012] In one alternative implementation, The current state of each node in the response node set is forward-engineered to generate multiple evolutionary trajectories, and the target evolutionary trajectory is obtained by filtering based on the cognitive representation, including: Extract the current state features and historical state sequence of each node in the response node set, perform time series analysis on the historical state sequence to obtain a state transition probability matrix, sample the current state features based on the state transition probability matrix to obtain multiple candidate successor states, recursively deduce each candidate successor state based on the edge weights and connection relationships in the state graph and record the deduction path to obtain multiple evolution trajectories, and calculate the trajectory length and state change amplitude corresponding to each evolution trajectory to obtain a trajectory feature set; Based on the cognitive representation, time preference features are determined and analyzed to obtain time span expectation and state stability preference. The time span expectation is matched with the trajectory length of each evolutionary trajectory in the trajectory feature set to obtain a matching score. Based on the state stability preference, the stability of the state change amplitude of each evolutionary trajectory is evaluated to obtain a stability score. The matching score and the stability score are weighted and summed to obtain a comprehensive trajectory score. The evolutionary trajectory with the highest comprehensive trajectory score is extracted as the target evolutionary trajectory. The state sequence of each node on the inference path is extracted from the target evolutionary trajectory and timestamped to obtain the time-series state sequence.

[0013] In one alternative implementation, Based on the target evolution trajectory and preset scheduling constraints, a candidate solution set is generated. The execution effect and resource consumption of each solution in the candidate solution set are evaluated, and the optimal solution is determined and executed. This includes: Extract the temporal state sequence and the state transition relationship of each node on the deduction path from the target evolution trajectory, generate multiple sets of node scheduling order based on the state transition relationship, and perform resource allocation planning for each set of node scheduling order. Verify the feasibility of the resource allocation plan based on the preset scheduling constraints, retain the verified resource allocation plan and record it as a candidate scheme, and construct a candidate scheme set. Extract the node scheduling order and resource allocation plan corresponding to each candidate scheme in the candidate scheme set. Calculate the state arrival time and state stability corresponding to the node scheduling order based on the time-series state sequence. Quantify the execution effect based on the state arrival time and state stability to obtain an effect score. Statistically calculate the occupancy and scheduling cost of various resources in the resource allocation plan. Normalize the occupancy and perform a weighted sum with the scheduling cost to obtain a resource consumption score. Perform multi-objective optimization on the effect score and resource consumption score to obtain a comprehensive evaluation index. The candidate scheme with the best comprehensive evaluation index is selected as the optimal scheme. The node scheduling order and resource allocation plan are extracted from the optimal scheme to generate an execution instruction sequence. The execution instruction sequence is encapsulated into a scheduling command and sent to the corresponding node for execution.

[0014] A second aspect of this invention provides an intelligent interactive system for the energy internet based on cognitive computing, comprising: The input parsing unit is used to receive the user's natural language input and operation behavior input, perform semantic parsing on the natural language input to extract intent features, perform temporal encoding on the operation behavior input to extract behavior features, and concatenate them with the intent features to obtain a cognitive representation; The graph generation unit is used to acquire the operating data and topology data of energy nodes, decompose the operating data into time windows to extract temporal features, perform multi-hop aggregation on each energy node based on the topology data to obtain higher-order dependencies, filter the temporal features and perform conditional independence tests based on the cognitive representation to determine causal paths, mark the causal paths as directed edges and encode them with the higher-order dependencies to generate a state graph. The trajectory extrapolation unit is used to project the cognitive representation and the state graph onto the semantic space for semantic alignment to obtain a semantic alignment result, calculate the association strength of each feature in the cognitive representation to the nodes in the state graph based on the semantic alignment result and determine the response node set, perform forward extrapolation on the current state of each node in the response node set to generate multiple evolution trajectories, and filter them based on the cognitive representation to obtain the target evolution trajectory. The scheme decision unit is used to generate a set of candidate schemes based on the target evolution trajectory and preset scheduling constraints, evaluate the execution effect and resource consumption of each scheme in the set of candidate schemes, determine the optimal scheme and issue it for execution.

[0015] A third aspect of the present invention provides an electronic device, comprising: A processor and a memory for storing processor-executable instructions, wherein the processor is configured to invoke instructions stored in the memory to perform the aforementioned method.

[0016] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.

[0017] This invention constructs a dynamic state graph that integrates causal inference and higher-order dependencies, enabling in-depth analysis of the operational mechanism of the energy internet. Time window decomposition and multi-hop aggregation techniques not only capture the temporal dynamics of node operation but also reveal deep topological dependencies within the network. Causal path discovery based on cognitive representation effectively filters irrelevant temporal noise, clarifies the causal relationships between key influencing factors, and lays a reliable state cognitive foundation for precise intervention. By calculating correlation strength, a set of key response nodes is identified, and the multi-step evolutionary trajectories of nodes are prospectively extrapolated and screened based on cognitive representation, thereby determining the target evolutionary path that meets user expectations. This organically embeds the user's subjective will into the state evolution prediction of the objective system, ensuring that the response strategy is not only technically feasible but also highly aligned with user intent. Attached Figure Description

[0018] Figure 1 This is a flowchart illustrating the intelligent interaction method for the energy internet based on cognitive computing, as described in an embodiment of the present invention. Figure 2 This is a flowchart illustrating the semantic alignment and filtering process of the intelligent interaction method for the energy internet based on cognitive computing, as described in an embodiment of the present invention. Detailed Implementation

[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0020] The technical solution of the present invention will be described in detail below with reference to specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0021] Figure 1 This is a flowchart illustrating the intelligent interaction method for the energy internet based on cognitive computing, as described in an embodiment of the present invention. Figure 1 As shown, the method includes: The system receives natural language input and operation behavior input from users, performs semantic parsing on the natural language input to extract intent features, performs temporal encoding on the operation behavior input to extract behavior features, and concatenates these with the intent features to obtain a cognitive representation. The system acquires operational data and topology data of energy nodes, decomposes the operational data into time windows to extract temporal features, performs multi-hop aggregation on each energy node based on the topology data to obtain higher-order dependencies, filters the temporal features and performs conditional independence tests based on the cognitive representation to determine causal paths, marks the causal paths as directed edges and encodes them with the higher-order dependencies to generate a state graph. The cognitive representation and the state graph are projected onto the semantic space for semantic alignment to obtain a semantic alignment result. Based on the semantic alignment result, the association strength of each feature in the cognitive representation to the nodes in the state graph is calculated and a response node set is determined. The current state of each node in the response node set is forward extrapolated to generate multiple evolution trajectories, and the target evolution trajectory is obtained by filtering based on the cognitive representation. Based on the target evolution trajectory and preset scheduling constraints, a set of candidate solutions is generated. The execution effect and resource consumption of each solution in the set of candidate solutions are evaluated, the optimal solution is determined, and the solution is issued for execution.

[0022] In one alternative implementation, Receiving natural language input and operational behavior input from a user, performing semantic parsing on the natural language input to extract intent features, and performing temporal encoding on the operational behavior input to extract behavioral features, concatenating these with the intent features to obtain a cognitive representation, including: The system receives natural language input and operation behavior input from users through an interactive interface. It preprocesses the natural language input to remove invalid characters and obtains the text content. It records and parses the operation behavior input to obtain the operation type and operation timestamp. The text content is segmented and part-of-speech tagging is performed to obtain a word sequence. Semantic embedding is performed on each word in the word sequence to obtain a word vector. The word vector is then context-associated encoded based on an attention mechanism to obtain a semantic representation sequence. Key semantic components in the semantic representation sequence are identified and the importance weight corresponding to each key semantic component is calculated. The semantic representation sequence is then weighted and pooled based on the importance weight to obtain the intent feature. The operation types are sorted by time according to the operation timestamp to obtain an operation sequence. Each operation type in the operation sequence is encoded and mapped to obtain an operation vector sequence. The operation vector sequence is temporally encoded and temporal dependencies are modeled to obtain the behavioral features. The cognitive representation is obtained by concatenating the intention feature and the behavioral feature along the feature dimension and normalizing them.

[0023] The interactive interface receives user input in natural language and input from user actions. This interface can be a command-line interface, a graphical user interface, or a network interface on an embedded real-time operating system terminal. Natural language input undergoes preprocessing to remove invalid characters, resulting in text content. Preprocessing uses regular expressions to identify and remove special symbols, extra spaces, tabs, and other interfering content. For example, when a user enters "Check network connection status!!", the preprocessing module uses a string replacement function to remove extra spaces and exclamation marks, resulting in the standardized text "Check network connection status". User action input is recorded and parsed by an event listener to obtain the action type and timestamp. Action types include keyboard input, mouse clicks, and screen swipes, with timestamps accurate to milliseconds. Specifically, the event listener continuously captures interactive events occurring on the user interface and converts each event into a standard-format operation record, including an action type identifier and a timestamp. For example, the operation "Click the network settings button" is recorded at 1649756830123 milliseconds.

[0024] The text processing begins with word segmentation and part-of-speech tagging to obtain a sequence of lexical units. Word segmentation relies on dictionary matching and statistical language models, using a maximum matching algorithm to divide continuous text into semantically meaningful lexical units. Part-of-speech tagging assigns a corresponding part-of-speech label to each lexical unit based on contextual relevance rules. In practical applications, "check network connection status" is segmented into "check / network / connection / status" and tagged with the parts of speech "check / verb", "network / noun", "connection / noun", and "status / noun". Each lexical unit in the sequence is further mapped to a word vector using semantic embedding technology. Semantic embedding employs a pre-trained word vector model, converting each lexical unit into a 128-dimensional real-valued vector, which captures semantic similarity and semantic association.

[0025] A sequence of word vectors is encoded using an attention mechanism to obtain a semantic representation sequence. The attention mechanism quantifies the semantic association strength between different word units by calculating the dot product similarity between word vectors, and then constructs an attention weight matrix. This attention weight matrix is ​​applied to the original word vector sequence to generate a semantic representation sequence that considers contextual information. For example, when processing "check network connection status," the attention weight between "check" and "status" is calculated to be 0.75, indicating that the two are semantically closely related. The generated semantic representation sequence maintains the same length as the original word unit sequence, but each representation vector incorporates global contextual information.

[0026] Key semantic component identification is achieved through semantic representation sequence analysis. It employs heuristic rules based on part-of-speech and position, combined with the norm of the semantic representation vectors, to identify the core components in a sentence. The importance weight calculation of key semantic components comprehensively considers word frequency statistics, part-of-speech importance, and positional information. Word frequency statistics utilize inverse document frequency (IVF) technology, part-of-speech importance is assigned according to preset rules, and positional information considers the relative position of the word in the sentence. In the aforementioned example, the verb "check" receives a weight of 0.35, the nouns "network" and "connection" receive weights of 0.25 and 0.20 respectively, and "state" receives a weight of 0.20. The weighted pooling process multiplies each vector in the semantic representation sequence by its corresponding importance weight and then sums them to generate a fixed-dimensional vector as the intent feature. In the specific implementation, the intent feature dimension is set to 256, and weighted summation and normalization ensure good numerical stability of the feature.

[0027] Operation behavior processing sorts operation types according to timestamps, forming a temporal operation sequence. The sorting uses a quicksort algorithm to ensure a log-linear time complexity. Each operation type in the sequence is mapped to an operation vector using a lookup table, which predefines standard vector representations for common operation types. For example, a "click" operation is mapped to a 64-dimensional vector, with the first few values ​​set to 0.9, 0.8, 0.7, etc., representing interactivity features; a "swipe" operation is mapped to a vector of the same dimension but with a different feature distribution. The operation vector sequence is further processed using temporal coding techniques to calculate the time intervals between operations and convert these time intervals into relative positional encoding information. Temporal dependency modeling uses a sliding window technique to analyze operation patterns within a fixed-size time window and extract correlation features between operations. For example, when a user sequentially performs operations such as "clicking the network settings button," "swiping the screen to view the network list," and "clicking the refresh button," the temporal dependency model can identify this combination of operation patterns. The operation behavior features are ultimately generated using a temporal aggregation function with a dimension of 128, containing the temporal information and behavioral pattern features of the user's operations.

[0028] Intent features and behavioral features are concatenated along their feature dimensions by aligning and joining the two vectors at their ends to form a higher-dimensional composite vector. Assuming the intent feature has a dimension of 256 and the behavioral feature has a dimension of 128, the concatenated vector has a dimension of 384. The concatenated vector is further normalized using a standardization formula with a mean of 0 and a variance of 1, ensuring that features from different sources have similar numerical distributions and preventing any one type of feature from dominating subsequent analysis due to excessively large values. The final cognitive representation is a 384-dimensional real-number vector that simultaneously contains the user's verbal input intent information and behavioral pattern information.

[0029] In one alternative implementation, The process involves acquiring operational and topological data of energy nodes, extracting temporal features from the operational data through time window decomposition, and performing multi-hop aggregation on each energy node based on the topological data to obtain higher-order dependencies, including: The system acquires the operational data and topology data of each energy node, performs anomaly detection on the operational data and marks abnormal time periods, extracts the connection relationships and energy flow directions between energy nodes from the topology data, and constructs a directed topology graph. The abnormal time period is divided into multiple time window data blocks by sliding segmentation according to a preset time window. Wavelet multi-scale decomposition is performed on each time window data block to obtain sub-signals of different frequency bands. The trend component and residual component corresponding to each frequency band sub-signal are extracted. Autocorrelation analysis is performed on the trend component to extract the periodic pattern. Higher-order moment statistics are performed on the residual component to extract the fluctuation pattern. The periodic pattern and the fluctuation pattern are fused to obtain the time series feature. The directed topological graph is converted into a Laplacian matrix and spectral decomposition is performed to obtain the graph feature basis. The graph feature basis is truncated to select and retain the dominant feature patterns. A graph convolution operator is constructed based on the dominant feature patterns. The graph convolution operator is applied to the initial feature vector corresponding to each energy node to perform multi-layer propagation and residual connection to obtain the propagation features of each layer. The attention score corresponding to the propagation features is calculated and cross-layer feature aggregation is performed based on the attention score. Graph pooling is performed on the aggregated features to obtain the higher-order dependencies between nodes.

[0030] Energy node operation data is collected from a distributed sensor network, including key parameters such as voltage, current, power, and temperature, with a sampling frequency of 100Hz, forming a continuous time-series data stream. Topology data describes the physical connections and energy flow between energy nodes, stored in the form of an adjacency list. The collected raw operation data is processed by an anomaly detection module, which uses a sliding window technique to calculate the mean and standard deviation of the data. When the data at a certain time point deviates from the mean by more than three times the standard deviation, it is marked as a potential anomaly. Consecutive anomalies constitute an abnormal time period; for example, in the voltage data monitored at a distribution node, an abnormal voltage fluctuation is detected between 12:30:15 and 12:45:20. During topology data processing, the connections and energy flow between energy nodes are extracted to construct a directed topology graph. In the directed topology graph, nodes represent energy devices, such as substations, distribution cabinets, and energy storage devices; edges represent energy transmission paths; the direction of the edges represents the energy flow; and the weight of the edges represents the energy transmission capacity. For example, the connection between two distribution nodes can be represented as a directed edge from node 1 to node 2, with a weight of 500 kilowatts, representing the maximum transmission capacity.

[0031] The abnormal time period is divided into multiple time window blocks using a 5-minute window size and a 1-minute sliding step. Each time window block contains 300 seconds of high-frequency sampling data, totaling 30,000 data points. Wavelet multi-scale decomposition is performed on each time window block using the Debyechin wavelet basis function, with a decomposition level of 4, yielding sub-signals in different frequency bands. After decomposition, four detail sub-signals and one approximate sub-signal are obtained. The detail sub-signals correspond to the 50-100Hz, 25-50Hz, 12.5-25Hz, and 6.25-12.5Hz frequency bands, respectively, while the approximate sub-signal corresponds to the 0-6.25Hz frequency band. The approximate sub-signal is considered the trend component, representing the main trend of the data; the set of detail sub-signals is considered the residual component, representing the fluctuation details of the data. Autocorrelation analysis is performed on the trend component, and periodic pattern features are extracted by calculating the autocorrelation coefficients under different time delays. Autocorrelation calculations use delay values ​​ranging from 1 to 300 to identify the delay time corresponding to the peak autocorrelation coefficient, thus recognizing periodicity in the data. For example, in the charging and discharging data of an energy storage device, a charging and discharging cycle of approximately 180 seconds was identified. Higher-order moment statistics are performed on the residual components to calculate the standard deviation, skewness, and kurtosis of each frequency band sub-signal, capturing the intensity and distribution characteristics of fluctuation patterns. During an anomaly, the high-frequency component skewness of a certain distribution node reached 2.3, and the kurtosis reached 8.5, significantly higher than normal values, indicating that the high-frequency disturbances during the anomaly exhibited asymmetrical and peaked distribution characteristics. Periodic and fluctuation patterns are fused through feature concatenation to form a comprehensive time-series feature vector with a dimension of 20, containing periodic indicators and statistical characteristics of each frequency band.

[0032] The conversion of a directed topological graph into a Laplacian matrix begins with the calculation of the in-degree matrix and the adjacency matrix. The in-degree matrix is ​​a diagonal matrix, with diagonal elements representing the in-degree of the corresponding node; the adjacency matrix elements represent the connection relationships and weights between nodes. The Laplacian matrix is ​​obtained by subtracting the adjacency matrix from the in-degree matrix, followed by spectral decomposition to calculate eigenvalues ​​and eigenvectors. In practical computation, a network with 50 energy nodes yields 50 eigenvalues ​​and corresponding eigenvectors in its Laplacian matrix through eigenvalue decomposition. These eigenvalues ​​are sorted in descending order, and the eigenvectors corresponding to the first 10 eigenvalues ​​are used as the graph feature basis, preserving approximately 85% of the information from the original topology. A graph convolution operator is constructed based on the dominant feature patterns. This operator combines the feature basis with Chebyshev polynomial approximation, avoiding the intensive computation of the full-graph Laplacian matrix. The parameter matrix of the graph convolution operator has the dimension of the input feature dimension multiplied by the output feature dimension, and the optimal parameter values ​​are determined through training.

[0033] Each energy node's initial feature vector contains the node's static attributes and dynamic operating parameters, with a dimension of 30. A three-layer graph convolutional network structure is designed using graph convolution operators for multi-layer propagation, with output feature dimensions of 64, 128, and 64 for each layer. Residual connections are added between layers, directly adding features from previous layers to the output of subsequent layers to enhance gradient propagation efficiency. For example, after propagation through the first layer, a node obtains a 64-dimensional feature vector, and after the second layer, it obtains a 128-dimensional feature vector, while retaining the 64-dimensional features from the first layer for residual connections. The attention score for propagated features is calculated using a self-attention mechanism, which uses the query vector, key vector, and value vector for similarity calculation and softening. In the specific implementation, the query vector is generated from the current node's features, and the key vector is generated from the features of neighboring nodes. Similarity is calculated through dot product, and then normalized using the softmax function to obtain the attention weights. The attention scores of a node to its three neighboring nodes are 0.5, 0.3, and 0.2, indicating that the first neighboring node has the greatest influence. Cross-layer feature aggregation is performed based on attention scores, which involves a weighted sum of propagation features from different layers, with the weights determined by the attention scores. The aggregated feature has a dimension of 64, encompassing multi-layer graph structure information.

[0034] Graph pooling is implemented through node clustering. A spectral clustering algorithm is used to group topologically similar nodes, and the features of each group are then subjected to max pooling or average pooling. In a 50-node energy network, pooling results in 10 supernodes, each representing a functionally similar energy subsystem. The pooled feature matrix has a dimension of 10×64, with rows representing supernodes and columns representing feature dimensions. This matrix is ​​further transformed into an adjacency matrix through matrix multiplication, representing higher-order dependencies between supernodes.

[0035] In one alternative implementation, Based on the cognitive representation, the temporal features are screened and conditional independence tests are performed to determine causal paths. These causal paths are then marked as directed edges and encoded with the higher-order dependencies to generate a state graph, including: Calculate the cosine similarity between the cognitive representation and each temporal feature in the temporal features, filter the temporal features based on a preset similarity threshold, and retain the temporal features with a cosine similarity greater than the similarity threshold to obtain a filtered temporal feature set; The time series features in the filtered time series feature set are paired up to obtain a feature pair set. A set of control variables is introduced into each feature pair in the feature pair set and the influence of the control variable set on the feature pair is calculated. Based on the influence, partial correlation analysis is performed on the feature pair to obtain a conditional independence index. The causal direction and causal strength between feature pairs are determined according to the conditional independence index. Significant causal relationships are screened based on the causal strength and the causal direction is recorded to obtain the causal path. The causal relationships in the causal path are mapped to directed edges, and the causal strength is used as the edge weight. A node set is constructed based on the energy nodes corresponding to the time-series features and the energy nodes corresponding to the higher-order dependencies. The directed edges and the connection relationships in the higher-order dependencies are merged into an edge set. The feature vector of each energy node in the node set is encoded and weighted by combining the edge weights to obtain the state graph.

[0036] The cosine similarity between cognitive representations and temporal features is calculated to construct a state graph. The cognitive representation is a 384-dimensional vector containing user interaction intent and behavioral characteristics; the temporal feature is a 20-dimensional vector containing the periodic and fluctuation patterns of energy node operation data. Cosine similarity is calculated by dividing the dot product of the two vectors by the product of their respective norms, with the result ranging from -1 to 1. A value closer to 1 indicates greater similarity in direction between the two vectors. In practical applications, for a network with 50 energy nodes, each node generates a temporal feature, requiring the calculation of the cosine similarity between the cognitive representation and each of the 50 temporal features. For example, the calculated similarity between the cognitive representation and the temporal feature of node 1 is 0.82, with node 2 it is 0.65, and with node 3 it is 0.42. Based on a preset similarity threshold of 0.6, temporal features with a cosine similarity greater than 0.6 are retained. In the aforementioned example, the temporal features of nodes 1 and 2 are retained, while the temporal feature of node 3 is filtered out. This filtering mechanism ensures that only temporal features highly relevant to the current cognitive representation are retained, reducing interfering information. After filtering, the original 50 temporal features may be reduced to 20, forming a filtered temporal feature set.

[0037] The time-series features in the filtered feature set are paired to generate a set of feature pairs. Assuming there are 20 time-series features after filtering, 190 feature pairs can be formed. A set of control variables is introduced for each feature pair, containing other time-series features besides the current feature pair. Conditional mutual information method is used to calculate the influence of the control variable set on the feature pair. This method quantifies the degree of interdependence between two variables given the control variable. During the calculation, the nearest neighbor search method is used to estimate the conditional probability distribution, with the search radius set to 0.1 times the average distance and the number of sample points set to 10% of the total sample size. For example, for feature pair 1 and 2, feature 3 is introduced as a control variable. The mutual information value between feature 1 and feature 2 given feature 3 is calculated to be 0.15, indicating that even after considering the influence of feature 3, there is still a certain degree of correlation between feature 1 and feature 2. Partial correlation analysis is performed on the feature pairs based on the influence value to obtain the conditional independence index. Partial correlation analysis calculates the degree of correlation between two variables after controlling for the influence of other variables. The conditional independence index ranges from 0 to 1; a value closer to 0 indicates that the two variables are more likely to be conditionally independent, while a value closer to 1 indicates that the two variables are more likely to have a direct causal relationship. In a network intrusion detection scenario, a conditional independence index of 0.85 for a certain feature pair indicates that even after controlling for all other variables, there is still a strong correlation between the two features, which may reflect an important causal path.

[0038] The causal direction and strength between feature pairs are determined using the conditional independence index. Causal direction is determined based on temporal sequence and the conditional independence test. If the change in feature 1 precedes the change in feature 2, and the conditional independence test supports that feature 1 influences feature 2 rather than the other way around, then the causal direction is determined to be feature 1 to feature 2. Causal strength is equivalent to the conditional independence index; a larger value indicates a more significant causal relationship. The causal relationships of all feature pairs are ranked, and relationships with a causal strength greater than 0.7 are selected as significant causal relationships, and their causal directions are recorded to form a set of causal paths. In a certain intrusion detection, a significant causal path was identified from "sudden increase in network traffic" to "increased CPU utilization" and then to "system response delay," with causal strengths of 0.92 and 0.85, respectively. This path reflects a typical denial-of-service attack pattern.

[0039] Causal relationships in causal paths are mapped to directed edges, with causal strength serving as edge weights. For example, the causal relationship from "sudden increase in network traffic" to "increased CPU utilization" is mapped to a directed edge with a weight of 0.92. A node set is constructed based on the energy nodes corresponding to time-series features and the energy nodes corresponding to higher-order dependencies. This set includes all nodes participating in causal analysis and nodes in higher-order dependencies. In practical applications, this might include network device nodes such as routers, firewalls, and critical servers. The directed edges and the connections in higher-order dependencies are merged into an edge set. The higher-order dependencies are derived from the previous multi-hop aggregation based on topological data. For example, there is a causal relationship between node A and node B, with an edge weight of 0.8; simultaneously, there is a connection between node A and node B in the higher-order dependencies, with an edge weight of 0.6; the larger value, 0.8, is taken as the final edge weight after merging.

[0040] Each energy node in the node set is encoded with a feature vector of 128 dimensions, containing information such as node type, functional attributes, and historical behavioral characteristics. For example, the first 32 bits of the core router node's encoding might represent its device type, the middle 32 bits its functional characteristics, and the last 64 bits its historical behavioral characteristics. When combining edge weights for weighted propagation, a graph attention network technique is used. The final representation of each node is obtained by weighted fusion of its own features and those of its neighboring nodes. The weights of neighboring nodes are jointly determined by edge weights and the attention mechanism. Edge weights reflect the strength of causality or the degree of dependency, while the attention mechanism adaptively learns the importance of different neighboring nodes. The propagation iteration count is set to 3, updating the node's feature representation in each iteration. For example, after three rounds of propagation, the initial feature vector of a server node incorporates information from upstream firewall nodes and downstream application service nodes, forming a more comprehensive state representation. The final state graph is a graph structure containing node representations and edge weights, with a node representation dimension of 128 and edge weights ranging from 0 to 1. This state graph comprehensively reflects the causal relationships and dependency structures between network devices and can be used for anomaly propagation analysis and critical node identification.

[0041] Figure 2 This is a flowchart illustrating the semantic alignment and filtering process of the intelligent interaction method for the energy internet based on cognitive computing, as described in an embodiment of the present invention.

[0042] In one alternative implementation, The cognitive representation and the state graph are projected onto a semantic space for semantic alignment to obtain a semantic alignment result. Based on the semantic alignment result, the association strength of each feature in the cognitive representation to the nodes in the state graph is calculated, and the set of response nodes is determined, including: A linear transformation is performed on the cognitive representation to obtain a cognitive representation projection vector. A linear transformation is performed on the feature vector encoding of each node in the state graph to obtain a set of node projection vectors. The cognitive representation projection vector and the node projection vectors in the set of node projection vectors are performed in a unified semantic space to obtain an initial alignment score. A softmax transformation is performed on the initial alignment score to obtain an alignment probability distribution. The set of node projection vectors is then weighted and summed to obtain an alignment vector. The Euclidean distance between the cognitive representation projection vector and the alignment vector is calculated to obtain the alignment error. The semantic alignment result is determined based on the alignment error and the alignment probability distribution. The intention feature component and the behavior feature component are separated from the cognitive representation. The intention feature component is decomposed to obtain an intention sub-feature set, and the behavior feature component is decomposed to obtain a behavior sub-feature set. Based on the semantic alignment result, the association strength between each sub-feature in the intention sub-feature set and the behavior sub-feature set and each node in the state graph is calculated. The association strengths corresponding to the intention sub-feature set and the behavior sub-feature set are fused to obtain a comprehensive association strength. The nodes in the state graph are then filtered to obtain the response node set.

[0043] A linear transformation of the cognitive representation using a projection matrix yields the cognitive representation projection vector. The cognitive representation is a 384-dimensional vector, which is transformed into a 256-dimensional semantic space by multiplying it by the projection matrix (384×256), whose elements are obtained through pre-training. The projected cognitive representation projection vector has a dimension of 256 and contains the main semantic information of the original cognitive representation. In practical applications, after a user's cognitive representation undergoes linear transformation, the projection vector shows a higher value for dimensions related to network security, indicating that the user's intent is closely related to network security defense. A similar linear transformation is performed on the feature vector encoding of each node in the state graph to obtain a set of node projection vectors. The node feature vector encoding in the state graph has a dimension of 128, which is transformed into the same 256-dimensional semantic space by multiplying it by a node projection matrix of dimension 128×256. For example, in a state graph containing 60 nodes, the 128-dimensional feature vector of each node is converted into a 256-dimensional node projection vector, forming a set of 60 node projection vectors.

[0044] The cognitive representation projection vector and the projection vectors of each node in the node projection vector set are multiplied in a unified semantic space to obtain an initial alignment score. The inner product operation essentially calculates the product of the cosine similarity of two vectors and their respective norms, reflecting the semantic similarity between the vectors. For a state graph of 60 nodes, 60 initial alignment scores are calculated. For example, the inner product of the cognitive representation projection vector and the firewall node projection vector is 7.2, the inner product with the router node is 5.8, and the inner product with the application server node is 3.1. A softmax transformation is applied to the initial alignment scores to convert them into a probability distribution. The softmax transformation uses an exponential function and normalization to ensure that all probability values ​​sum to 1 while maintaining the relative magnitudes of the original scores. In the aforementioned example, the alignment probabilities of the firewall node, router node, and application server node are 0.65, 0.28, and 0.07, respectively. Based on the alignment probability distribution, a weighted summation of the node projection vector set is performed to obtain the alignment vector. The projection vector of each node is multiplied by its corresponding alignment probability, and the summation yields the final alignment vector, which still has a dimension of 256. This weighted summation mechanism allows multiple related nodes to contribute to the final alignment result.

[0045] The alignment error is obtained by calculating the Euclidean distance between the cognitive representation projection vector and the alignment vector. The Euclidean distance is calculated by taking the square root of the sum of the squares of the differences between corresponding elements of the two vectors, reflecting the actual distance between them in the semantic space. Ideally, if the cognitive representation perfectly matches the node combinations in the state graph, the Euclidean distance is close to 0. In practical applications, the alignment error is typically between 0 and 10, with smaller values ​​indicating a higher degree of matching. In a certain defense operation, the calculated alignment error was 2.3, lower than the preset threshold of 3.5, indicating a good match between the cognitive representation and the nodes in the state graph. The semantic alignment result is determined based on the alignment error and the alignment probability distribution. When the alignment error is less than the preset threshold and the alignment probability of some nodes is significantly higher than that of other nodes, the semantic alignment is considered successful. The alignment result is output in the form of node index and corresponding probability value. For example, nodes 5, 12, and 28 are identified as the most relevant nodes to the current cognitive representation, with alignment probabilities of 0.65, 0.28, and 0.07, respectively.

[0046] When separating intention and behavioral feature components from cognitive representation, the structural characteristics of cognitive representation are utilized. In the 384-dimensional vector of cognitive representation, the first 256 dimensions represent intention feature components, and the last 128 dimensions represent behavioral feature components. Feature decomposition is performed on the intention feature components to obtain a set of intention sub-features. Principal component analysis (PCA) is used to extract the first eight principal components as intention sub-features. Each principal component is an orthogonal direction in the original feature space, representing an independent semantic pattern. For example, in a network intrusion prevention scenario, the first principal component might correspond to firewall configuration intent, and the second principal component might correspond to traffic monitoring intent. A similar feature decomposition is performed on the behavioral feature components, extracting the first six principal components as a set of behavioral sub-features. Behavioral sub-features may include mouse click patterns, command sequence patterns, etc.

[0047] Based on the semantic alignment results, the association strength between each sub-feature in the intent sub-feature set and the behavior sub-feature set and each node in the state graph is calculated. Each sub-feature vector is inner-producted with the node projection vector, and the result is then mapped to a value between 0 and 1 using the sigmoid function as the association strength. In the state graph with 60 nodes, 60 association strength values ​​are calculated for each intent sub-feature and behavior sub-feature. For example, the association strengths of the firewall configuration intent sub-feature with the firewall node, traffic filtering node, and rule base node are 0.92, 0.85, and 0.79, respectively, indicating that these three nodes are highly correlated with the intent. Meanwhile, the association strengths of the mouse click sequence behavior sub-feature with the configuration interface node and rule editing node are 0.88 and 0.76, respectively, indicating that these nodes are closely related to the user's current action.

[0048] The overall correlation strength is obtained by fusing the correlation strengths corresponding to the intent sub-feature set and the behavior sub-feature set. A weighted average method is used for fusion, with the intent correlation strength weight set to 0.6 and the behavior correlation strength weight set to 0.4. This weighting reflects that in network intrusion prevention, user intent is usually more indicative of the defense objective than specific operational behaviors. For each node, the weighted average of the correlation strengths of the eight intent sub-features and the six behavior sub-features is calculated, and then summed in a weighted ratio of 0.6:0.4 to obtain the final overall correlation strength. Nodes in the state graph are filtered, and the top 10 nodes with the overall correlation strength or a correlation strength greater than 0.7 are selected as the response node set. In a certain defense operation, firewall nodes, intrusion detection nodes, traffic analysis nodes, rule base nodes, and log service nodes are selected to form the response node set, with overall correlation strengths of 0.88, 0.82, 0.79, 0.75, and 0.71, respectively.

[0049] The response node set reflects the network components most relevant to the current user's cognitive representation, and these components need to respond collaboratively based on user intent and behavior. In actual defense, when the user intent is identified as strengthening the defense of a specific server, the response node set may include firewall nodes, access control nodes, and traffic monitoring nodes associated with that server. The defense system will then automatically adjust the operating parameters of these nodes, such as increasing the strictness of firewall rules, increasing the sensitivity of traffic detection, and enabling additional access verification mechanisms.

[0050] In one alternative implementation, The current state of each node in the response node set is forward-engineered to generate multiple evolutionary trajectories, and the target evolutionary trajectory is obtained by filtering based on the cognitive representation, including: Extract the current state features and historical state sequence of each node in the response node set, perform time series analysis on the historical state sequence to obtain a state transition probability matrix, sample the current state features based on the state transition probability matrix to obtain multiple candidate successor states, recursively deduce each candidate successor state based on the edge weights and connection relationships in the state graph and record the deduction path to obtain multiple evolution trajectories, and calculate the trajectory length and state change amplitude corresponding to each evolution trajectory to obtain a trajectory feature set; Based on the cognitive representation, time preference features are determined and analyzed to obtain time span expectation and state stability preference. The time span expectation is matched with the trajectory length of each evolutionary trajectory in the trajectory feature set to obtain a matching score. Based on the state stability preference, the stability of the state change amplitude of each evolutionary trajectory is evaluated to obtain a stability score. The matching score and the stability score are weighted and summed to obtain a comprehensive trajectory score. The evolutionary trajectory with the highest comprehensive trajectory score is extracted as the target evolutionary trajectory. The state sequence of each node on the inference path is extracted from the target evolutionary trajectory and timestamped to obtain the time-series state sequence.

[0051] Extracting the current state features and historical state sequences of each node in the response node set is fundamental to constructing the target evolution trajectory. The response node set contains several network device nodes, each maintaining a state vector that records its key operating parameters. The state vector has a 64-dimensional dimension and includes features such as resource utilization, traffic statistics, connection count, and abnormal event count. Current state features are directly obtained from the real-time monitoring system; for example, the current state features of a firewall node show a CPU utilization of 35%, 1250 active connections, and 12 abnormal connection attempts per minute. Historical state sequences are extracted from a historical database; each node stores the most recent 720 historical state records, corresponding to the state data of the last 24 hours, with a sampling frequency of once every 2 minutes. Temporal analysis of the historical state sequences yields a state transition probability matrix. Using Markov chain modeling, continuous state values ​​are discretized into 10 state intervals, and the transition frequency between states at adjacent time points is statistically analyzed to construct a 10×10 state transition probability matrix. For example, the probability of a firewall node's state transitioning from "low load range" to "medium load range" is 0.25, the probability of transitioning to "high load range" is 0.05, and the probability of remaining in "low load range" is 0.7.

[0052] Multiple candidate successor states are obtained by sampling the current state features based on the state transition probability matrix, using a Monte Carlo simulation method. Starting from the current state, the next state is randomly selected according to the transition probability, and this process is repeated to generate 20 different candidate successor states. Each candidate successor state is a point in the original 64-dimensional state vector space, representing the possible direction of node evolution. For example, the current firewall node state may evolve into different successor states such as "connection count increases but CPU load remains stable" and "connection count remains stable but abnormal connection attempts increase". Each candidate successor state is recursively deduced based on the edge weights and connection relationships in the state graph. The edge weights reflect the influence strength between nodes, and the connection relationships determine the influence propagation path. The recursive deduction process starts from the initial node, propagating the state change to connected nodes according to the edge weight ratio. After the connected nodes update their states, the change propagates to the next layer of nodes, with a recursion depth of 5 layers. The deduction process records the state propagation path, forming a complete evolution trajectory. In a network intrusion prevention scenario, the state change of a firewall node may propagate along the path "firewall → intrusion detection system → log server → alarm system → management console", forming a typical defense response trajectory. Each of the 20 candidate successor states was used to deduce 20 different evolutionary trajectories.

[0053] The trajectory feature set is obtained by calculating the trajectory length and state change amplitude for each evolutionary trajectory. The trajectory length is defined as the number of nodes involved in the trajectory, reflecting the breadth of state propagation; the state change amplitude is defined as the cumulative sum of the state changes of all nodes in the trajectory, reflecting the intensity of state propagation. The change amplitude is calculated using vector norms, by summing the norms of the state change vectors of each node to obtain the total change amplitude. For example, an evolutionary trajectory contains 5 nodes, has a trajectory length of 5, and the state changes of each node are 2.3, 1.7, 1.2, 0.8, and 0.5, respectively, with a total change amplitude of 6.5. The trajectory feature set contains the length and change amplitude data for 20 trajectories, used for subsequent evaluation and selection of the optimal trajectory.

[0054] Based on cognitive representations, time preference features are determined and analyzed to obtain expected time span and state stability preferences. Cognitive representations contain user intent and behavioral habits; time-related preference features are extracted using feature extraction algorithms. Expected time span reflects the user's desired duration of the defense response, inferred by analyzing time-related vocabulary and behavioral patterns in the cognitive representation. For example, a user input of "immediately block suspicious traffic" suggests a short time span expectation, while "continuously monitor network activity" suggests a longer time span expectation. Expected time span is quantified as the expected number of nodes, ranging from 3 to 10; a higher value indicates a greater expectation of node coverage. State stability preference reflects the user's acceptance of the severity of the defense response, inferred by analyzing degree words and behavioral decisiveness in the cognitive representation. For example, "mildly filter suspicious traffic" indicates a high stability preference, while "immediately disconnect all external connections" indicates a low stability preference. State stability preference is quantified as a value between 0 and 1, with higher values ​​indicating a greater preference for stable changes.

[0055] A matching score is obtained by matching the expected time span with the trajectory length of each evolutionary trajectory in the trajectory feature set, using a Gaussian similarity function. This function calculates the similarity based on the difference between the expected time span and the actual trajectory length; the smaller the difference, the higher the score. For an expected time span of 5, the evolutionary trajectory with a length of 5 receives the highest matching score of 1.0, trajectory lengths of 4 or 6 receive a score of 0.9, and trajectory lengths of 3 or 7 receive a score of 0.7. A stability score is obtained by evaluating the stability of the state change amplitude of each evolutionary trajectory based on state stability preference, considering the degree of matching between the change amplitude and the stability preference. When the stability preference value is 0.8, trajectories with smaller change amplitudes receive higher stability scores; when the stability preference value is 0.2, trajectories with larger change amplitudes receive higher scores. The score calculation uses an inverse proportional function, mapping the original change amplitude to a score range between 0 and 1.

[0056] A weighted sum of the matching score and the stability score yields a comprehensive trajectory score, with the weighting coefficients determined based on priority features in cognitive representation. Generally, the matching score has a weight of 0.6, and the stability score has a weight of 0.4, reflecting that time-span matching is usually more important than state stability. In specific scenarios, such as emergency response modes, the weights may be adjusted to 0.8 and 0.2, emphasizing more precise time-span matching. After calculating the comprehensive score for 20 evolutionary trajectories, the trajectory with the highest score is selected as the target evolutionary trajectory. For example, in a certain defense operation, trajectory 7 received the highest comprehensive score of 0.92, containing 5 nodes with a total change of 5.8, and was selected as the target evolutionary trajectory.

[0057] After extracting the evolutionary trajectory with the highest comprehensive trajectory score as the target evolutionary trajectory, the state sequence of each node on the inference path is extracted from this trajectory. The target evolutionary trajectory includes the node sequence and the state changes of each node, such as "firewall → intrusion detection system → log server → alarm system → management console", with each node having a corresponding state vector. When timestamp labeling, the state propagation delay between nodes is considered, and a delay model is established based on network topology and historical response data. Starting from the initial node, timestamps are assigned to each node according to the order of the inference path. For example, if the current time is 10:00:00, the firewall node state change is set to 10:00:00, and the intrusion detection system response delay is 30 seconds, then its timestamp is 10:00:30, and so on, timestamps are labeled for subsequent nodes. The final time-series state sequence is a triple sequence containing node identifier, state vector, and timestamp, which fully describes the evolution process of the defense response.

[0058] In one alternative implementation, Based on the target evolution trajectory and preset scheduling constraints, a candidate solution set is generated. The execution effect and resource consumption of each solution in the candidate solution set are evaluated, and the optimal solution is determined and executed. This includes: Extract the temporal state sequence and the state transition relationship of each node on the deduction path from the target evolution trajectory, generate multiple sets of node scheduling order based on the state transition relationship, and perform resource allocation planning for each set of node scheduling order. Verify the feasibility of the resource allocation plan based on the preset scheduling constraints, retain the verified resource allocation plan and record it as a candidate scheme, and construct a candidate scheme set. Extract the node scheduling order and resource allocation plan corresponding to each candidate scheme in the candidate scheme set. Calculate the state arrival time and state stability corresponding to the node scheduling order based on the time-series state sequence. Quantify the execution effect based on the state arrival time and state stability to obtain an effect score. Statistically calculate the occupancy and scheduling cost of various resources in the resource allocation plan. Normalize the occupancy and perform a weighted sum with the scheduling cost to obtain a resource consumption score. Perform multi-objective optimization on the effect score and resource consumption score to obtain a comprehensive evaluation index. The candidate scheme with the best comprehensive evaluation index is selected as the optimal scheme. The node scheduling order and resource allocation plan are extracted from the optimal scheme to generate an execution instruction sequence. The execution instruction sequence is encapsulated into a scheduling command and sent to the corresponding node for execution.

[0059] Extracting the temporal state sequence and state transition relationships of each node along the deduced path from the target evolution trajectory is a crucial step in implementing network intrusion prevention. The temporal state sequence contains the state vectors and timestamps of each node at different times. For example, the state vector of a firewall node at 10:00:00 records 64 parameters, including traffic filtering rules and connection limits. State transition relationships describe the process of a node changing from one state to another, including the magnitude, direction, and time required for the change. The extraction process calculates the difference vector by comparing the state vectors of adjacent time points. The direction of the difference vector indicates the trend of state change, and the magnitude indicates the magnitude of the change. For example, the difference vector of a firewall node from its initial state to its target state shows that 25 more filtering rules need to be added, the connection limit reduced by 500, and the packet detection depth increased by 2 layers. Based on these state transition relationships, multiple sets of node scheduling sequences are generated, and the scheduling order determines the implementation order of defense measures. The generation algorithm uses a topology sorting variant, considering the dependencies between nodes and the direction of influence propagation, while introducing random perturbations to generate diverse scheduling sequences. In a defense link containing 5 nodes, different scheduling sequences may be generated, such as "firewall → router → intrusion detection system → log server → alarm system" and "firewall → intrusion detection system → router → log server → alarm system".

[0060] Resource allocation planning is performed for each group of nodes, including CPU utilization, memory usage, bandwidth allocation, and storage space. Resource allocation employs a dynamic programming algorithm, allocating the necessary resources to each node based on its state transition requirements. For example, adding filtering rules to a firewall node requires an additional 15% CPU resource and 200MB of memory, while increasing the detection depth of an intrusion detection system requires an additional 30% CPU resource and 500MB of memory. The feasibility of the resource allocation plan is verified based on preset scheduling constraints, including total resource limits, single-node resource limits, priority requirements, and timing dependencies. The verification process checks for resource conflicts, whether priority requirements are met, and whether dependencies are violated. For example, an embedded terminal has a total CPU resource utilization of 400% (quad-core) and 4GB of memory; a single defense component can use a maximum of 150% CPU and 1.5GB of memory. If a resource allocation scheme requires 450% CPU resources at peak times, the verification fails and the scheme is discarded. Verified resource allocation plans are retained as candidate schemes, and a candidate scheme set is constructed. In a typical network intrusion prevention scenario, after resource constraint verification from 20 initial scheduling sequences, 8 candidate schemes that meet the constraints may be retained.

[0061] The node scheduling order and resource allocation plan corresponding to each candidate scheme in the candidate scheme set are extracted to further evaluate their performance characteristics. The state arrival time and state stability corresponding to the node scheduling order are calculated based on the time-series state sequence. State arrival time refers to the time required from defense initiation to each node reaching the target state. It is calculated by accumulating the state propagation delay between nodes and the state transition time within a node. For example, in a candidate scheme, the firewall node needs 20 seconds to complete the configuration update, followed by the router node needing 15 seconds to complete the routing table adjustment. Adding a 10-second propagation delay, the router's state arrival time is 45 seconds. State stability is quantified by the state jitter amplitude; the smaller the jitter amplitude, the higher the stability. The jitter amplitude is calculated as the average variance of multiple consecutive sampling points of the state vector, reflecting the severity of state fluctuations. An effectiveness score is obtained based on the quantified execution effect of state arrival time and state stability. The calculation formula is the weighted sum of the reciprocal of the state arrival time and the state stability, with the weights set according to the defense scenario. For example, for attacks requiring rapid response, the weight of state arrival time is set to 0.8, and the weight of state stability is set to 0.2; for persistent threats requiring fine-grained defense, the weights may be adjusted to 0.4 and 0.6, respectively.

[0062] In the statistical resource allocation planning, the occupancy and scheduling costs of various resources are calculated. Resource occupancy includes the time integral of CPU utilization, the time integral of memory utilization, and network bandwidth utilization. Scheduling costs consider factors such as node switching frequency, configuration changes, and state rollback risks, and are calculated by weighted summation to obtain the total scheduling cost. Occupancy is normalized by dividing the occupancy of each resource by the total system resource capacity, converting it into a relative occupancy rate between 0 and 1. For example, if the CPU occupancy time integral is 2400%·second and the system baseline is 4000%·second, the normalized rate is 0.6. The normalized resource occupancy rates are then weighted and summed with the scheduling costs to obtain a resource consumption score. In network defense scenarios, the weight of CPU resources is typically set to 0.4, memory to 0.3, bandwidth to 0.2, and scheduling cost to 0.1, reflecting the contribution of each factor to the overall resource consumption. A comprehensive evaluation index is obtained by multi-objective optimization of the effect score and resource consumption score, using Pareto front analysis and weighted summation as the optimization methods. There is a trade-off between the effectiveness score and the resource consumption score. Typically, the effectiveness score is weighted at 0.7, while the resource consumption score is weighted at 0.3, prioritizing defensive effectiveness. Among the eight candidate solutions, the highest comprehensive evaluation index may reach 0.85, while the lowest may only be 0.62.

[0063] The candidate solution with the best comprehensive evaluation index is selected as the optimal solution. From this optimal solution, the node scheduling order and resource allocation plan are extracted. The node scheduling order determines the activation order of the defense components, and the resource allocation plan determines the resource allocation strategy at each time point. Based on these two pieces of information, an execution instruction sequence is generated. The instruction sequence includes specific configuration parameters, timestamps, and execution priorities. For example, the execution instruction for a firewall node might include "Add 25 filtering rules at 10:00:00, allocate 15% additional CPU resources, high priority"; the execution instruction for an intrusion detection system might include "Increase the detection depth by 2 layers at 10:00:30, allocate 30% CPU resources and 500MB of memory, medium priority". The execution instruction sequence is encapsulated into scheduling commands. The scheduling commands adopt a standardized format, including a command header, parameter block, and verification information. The command header includes the target node identifier, execution time, and command type; the parameter block includes specific configuration parameters and resource allocation instructions; the verification information includes a digital signature and integrity check code to ensure the security and reliability of the command. The scheduling commands are sent to the corresponding nodes for execution through a secure channel using an encrypted transmission protocol to prevent commands from being tampered with or stolen. After receiving a scheduling command, the node first verifies its validity, then determines the execution time based on the timestamp, and finally adjusts its own configuration and resource allocation according to the instruction.

[0064] A second aspect of this invention provides an intelligent interactive system for the energy internet based on cognitive computing, comprising: The input parsing unit is used to receive the user's natural language input and operation behavior input, perform semantic parsing on the natural language input to extract intent features, perform temporal encoding on the operation behavior input to extract behavior features, and concatenate them with the intent features to obtain a cognitive representation; The graph generation unit is used to acquire the operating data and topology data of energy nodes, decompose the operating data into time windows to extract temporal features, perform multi-hop aggregation on each energy node based on the topology data to obtain higher-order dependencies, filter the temporal features and perform conditional independence tests based on the cognitive representation to determine causal paths, mark the causal paths as directed edges and encode them with the higher-order dependencies to generate a state graph. The trajectory extrapolation unit is used to project the cognitive representation and the state graph onto the semantic space for semantic alignment to obtain a semantic alignment result, calculate the association strength of each feature in the cognitive representation to the nodes in the state graph based on the semantic alignment result and determine the response node set, perform forward extrapolation on the current state of each node in the response node set to generate multiple evolution trajectories, and filter them based on the cognitive representation to obtain the target evolution trajectory. The scheme decision unit is used to generate a set of candidate schemes based on the target evolution trajectory and preset scheduling constraints, evaluate the execution effect and resource consumption of each scheme in the set of candidate schemes, determine the optimal scheme and issue it for execution.

[0065] A third aspect of the present invention provides an electronic device, comprising: A processor and a memory for storing processor-executable instructions, wherein the processor is configured to invoke instructions stored in the memory to perform the aforementioned method.

[0066] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.

[0067] This invention can be a method, apparatus, system, and / or computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for performing various aspects of the invention.

[0068] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for intelligent interaction in the energy internet based on cognitive computing, characterized in that: include: The system receives natural language input and operation behavior input from users, performs semantic parsing on the natural language input to extract intent features, performs temporal encoding on the operation behavior input to extract behavior features, and concatenates these with the intent features to obtain a cognitive representation. The system acquires operational data and topology data of energy nodes, decomposes the operational data into time windows to extract temporal features, performs multi-hop aggregation on each energy node based on the topology data to obtain higher-order dependencies, filters the temporal features and performs conditional independence tests based on the cognitive representation to determine causal paths, marks the causal paths as directed edges and encodes them with the higher-order dependencies to generate a state graph. The cognitive representation and the state graph are projected onto the semantic space for semantic alignment to obtain a semantic alignment result. Based on the semantic alignment result, the association strength of each feature in the cognitive representation to the nodes in the state graph is calculated and a response node set is determined. The current state of each node in the response node set is forward extrapolated to generate multiple evolution trajectories, and the target evolution trajectory is obtained by filtering based on the cognitive representation. Based on the target evolution trajectory and preset scheduling constraints, a set of candidate solutions is generated. The execution effect and resource consumption of each solution in the set of candidate solutions are evaluated, the optimal solution is determined, and the solution is issued for execution.

2. The method according to claim 1, characterized in that, Receiving natural language input and operational behavior input from a user, performing semantic parsing on the natural language input to extract intent features, and performing temporal encoding on the operational behavior input to extract behavioral features, concatenating these with the intent features to obtain a cognitive representation, including: The system receives natural language input and operation behavior input from users through an interactive interface. It preprocesses the natural language input to remove invalid characters and obtains the text content. It records and parses the operation behavior input to obtain the operation type and operation timestamp. The text content is segmented and part-of-speech tagging is performed to obtain a word sequence. Semantic embedding is performed on each word in the word sequence to obtain a word vector. The word vector is then context-associated encoded based on an attention mechanism to obtain a semantic representation sequence. Key semantic components in the semantic representation sequence are identified and the importance weight corresponding to each key semantic component is calculated. The semantic representation sequence is then weighted and pooled based on the importance weight to obtain the intent feature. The operation types are sorted by time according to the operation timestamp to obtain an operation sequence. Each operation type in the operation sequence is encoded and mapped to obtain an operation vector sequence. The operation vector sequence is temporally encoded and temporal dependencies are modeled to obtain the behavioral features. The cognitive representation is obtained by concatenating the intention feature and the behavioral feature along the feature dimension and normalizing them.

3. The method according to claim 1, characterized in that, The process involves acquiring operational and topological data of energy nodes, extracting temporal features from the operational data through time window decomposition, and performing multi-hop aggregation on each energy node based on the topological data to obtain higher-order dependencies, including: The system acquires the operational data and topology data of each energy node, performs anomaly detection on the operational data and marks abnormal time periods, extracts the connection relationships and energy flow directions between energy nodes from the topology data, and constructs a directed topology graph. The abnormal time period is divided into multiple time window data blocks by sliding segmentation according to a preset time window. Wavelet multi-scale decomposition is performed on each time window data block to obtain sub-signals of different frequency bands. The trend component and residual component corresponding to each frequency band sub-signal are extracted. Autocorrelation analysis is performed on the trend component to extract the periodic pattern. Higher-order moment statistics are performed on the residual component to extract the fluctuation pattern. The periodic pattern and the fluctuation pattern are fused to obtain the time series feature. The directed topological graph is converted into a Laplacian matrix and spectral decomposition is performed to obtain the graph feature basis. The graph feature basis is truncated to select and retain the dominant feature patterns. A graph convolution operator is constructed based on the dominant feature patterns. The graph convolution operator is applied to the initial feature vector corresponding to each energy node to perform multi-layer propagation and residual connection to obtain the propagation features of each layer. The attention score corresponding to the propagation features is calculated and cross-layer feature aggregation is performed based on the attention score. Graph pooling is performed on the aggregated features to obtain the higher-order dependencies between nodes.

4. The method according to claim 1, characterized in that, Based on the cognitive representation, the temporal features are screened and conditional independence tests are performed to determine causal paths. These causal paths are then marked as directed edges and encoded with the higher-order dependencies to generate a state graph, including: Calculate the cosine similarity between the cognitive representation and each temporal feature in the temporal features, filter the temporal features based on a preset similarity threshold, and retain the temporal features with a cosine similarity greater than the similarity threshold to obtain a filtered temporal feature set; The time series features in the filtered time series feature set are paired up to obtain a feature pair set. A set of control variables is introduced into each feature pair in the feature pair set and the influence of the control variable set on the feature pair is calculated. Based on the influence, partial correlation analysis is performed on the feature pair to obtain a conditional independence index. The causal direction and causal strength between feature pairs are determined according to the conditional independence index. Significant causal relationships are screened based on the causal strength and the causal direction is recorded to obtain the causal path. The causal relationships in the causal path are mapped to directed edges, and the causal strength is used as the edge weight. A node set is constructed based on the energy nodes corresponding to the time-series features and the energy nodes corresponding to the higher-order dependencies. The directed edges and the connection relationships in the higher-order dependencies are merged into an edge set. The feature vector of each energy node in the node set is encoded and weighted by combining the edge weights to obtain the state graph.

5. The method according to claim 1, characterized in that, The cognitive representation and the state graph are projected onto a semantic space for semantic alignment to obtain a semantic alignment result. Based on the semantic alignment result, the association strength of each feature in the cognitive representation to the nodes in the state graph is calculated, and the set of response nodes is determined, including: A linear transformation is performed on the cognitive representation to obtain a cognitive representation projection vector. A linear transformation is performed on the feature vector encoding of each node in the state graph to obtain a set of node projection vectors. The cognitive representation projection vector and the node projection vectors in the set of node projection vectors are performed in a unified semantic space to obtain an initial alignment score. A softmax transformation is performed on the initial alignment score to obtain an alignment probability distribution. The set of node projection vectors is then weighted and summed to obtain an alignment vector. The Euclidean distance between the cognitive representation projection vector and the alignment vector is calculated to obtain the alignment error. The semantic alignment result is determined based on the alignment error and the alignment probability distribution. The intention feature component and the behavior feature component are separated from the cognitive representation. The intention feature component is decomposed to obtain an intention sub-feature set, and the behavior feature component is decomposed to obtain a behavior sub-feature set. Based on the semantic alignment result, the association strength between each sub-feature in the intention sub-feature set and the behavior sub-feature set and each node in the state graph is calculated. The association strengths corresponding to the intention sub-feature set and the behavior sub-feature set are fused to obtain a comprehensive association strength. The nodes in the state graph are then filtered to obtain the response node set.

6. The method according to claim 1, characterized in that, The current state of each node in the response node set is forward-engineered to generate multiple evolutionary trajectories, and the target evolutionary trajectory is obtained by filtering based on the cognitive representation, including: Extract the current state features and historical state sequence of each node in the response node set, perform time series analysis on the historical state sequence to obtain a state transition probability matrix, sample the current state features based on the state transition probability matrix to obtain multiple candidate successor states, recursively deduce each candidate successor state based on the edge weights and connection relationships in the state graph and record the deduction path to obtain multiple evolution trajectories, and calculate the trajectory length and state change amplitude corresponding to each evolution trajectory to obtain a trajectory feature set; Based on the cognitive representation, time preference features are determined and analyzed to obtain time span expectation and state stability preference. The time span expectation is matched with the trajectory length of each evolutionary trajectory in the trajectory feature set to obtain a matching score. Based on the state stability preference, the stability of the state change amplitude of each evolutionary trajectory is evaluated to obtain a stability score. The matching score and the stability score are weighted and summed to obtain a comprehensive trajectory score. The evolutionary trajectory with the highest comprehensive trajectory score is extracted as the target evolutionary trajectory. The state sequence of each node on the inference path is extracted from the target evolutionary trajectory and timestamped to obtain the time-series state sequence.

7. The method according to claim 1, characterized in that, Based on the target evolution trajectory and preset scheduling constraints, a candidate solution set is generated. The execution effect and resource consumption of each solution in the candidate solution set are evaluated, and the optimal solution is determined and executed. This includes: Extract the temporal state sequence and the state transition relationship of each node on the deduction path from the target evolution trajectory, generate multiple sets of node scheduling order based on the state transition relationship, and perform resource allocation planning for each set of node scheduling order. Verify the feasibility of the resource allocation plan based on the preset scheduling constraints, retain the verified resource allocation plan and record it as a candidate scheme, and construct a candidate scheme set. Extract the node scheduling order and resource allocation plan corresponding to each candidate scheme in the candidate scheme set. Calculate the state arrival time and state stability corresponding to the node scheduling order based on the time-series state sequence. Quantify the execution effect based on the state arrival time and state stability to obtain an effect score. Statistically calculate the occupancy and scheduling cost of various resources in the resource allocation plan. Normalize the occupancy and perform a weighted sum with the scheduling cost to obtain a resource consumption score. Perform multi-objective optimization on the effect score and resource consumption score to obtain a comprehensive evaluation index. The candidate scheme with the best comprehensive evaluation index is selected as the optimal scheme. The node scheduling order and resource allocation plan are extracted from the optimal scheme to generate an execution instruction sequence. The execution instruction sequence is encapsulated into a scheduling command and sent to the corresponding node for execution.

8. An intelligent interactive system for the energy internet based on cognitive computing, used to implement the method of any one of claims 1-7, characterized in that, include: The input parsing unit is used to receive the user's natural language input and operation behavior input, perform semantic parsing on the natural language input to extract intent features, perform temporal encoding on the operation behavior input to extract behavior features, and concatenate them with the intent features to obtain a cognitive representation; The graph generation unit is used to acquire the operating data and topology data of energy nodes, decompose the operating data into time windows to extract temporal features, perform multi-hop aggregation on each energy node based on the topology data to obtain higher-order dependencies, filter the temporal features and perform conditional independence tests based on the cognitive representation to determine causal paths, mark the causal paths as directed edges and encode them with the higher-order dependencies to generate a state graph. The trajectory extrapolation unit is used to project the cognitive representation and the state graph onto the semantic space for semantic alignment to obtain a semantic alignment result, calculate the association strength of each feature in the cognitive representation to the nodes in the state graph based on the semantic alignment result and determine the response node set, perform forward extrapolation on the current state of each node in the response node set to generate multiple evolution trajectories, and filter them based on the cognitive representation to obtain the target evolution trajectory. The scheme decision unit is used to generate a set of candidate schemes based on the target evolution trajectory and preset scheduling constraints, evaluate the execution effect and resource consumption of each scheme in the set of candidate schemes, determine the optimal scheme and issue it for execution.

9. An electronic device, characterized in that, include: processor; Memory used to store processor-executable instructions; The processor is configured to invoke instructions stored in the memory to execute the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, they implement the method described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Industrial multi-modal data semantic alignment method based on vector space and topological constraint

    CN121543737A

  • Multi-source data input AI engine user demand analysis method

    CN121786775A