A localized large model assisted research and judgment method and system for energy chemical industry work control warning
By using a localized large-scale model-assisted analysis method, the problems of false alarms, missed alarms, and data security risks in energy and chemical industrial control networks have been solved. This has enabled rapid and accurate interpretation and handling suggestions for industrial control alarms, improving analysis efficiency and data security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-09
- Publication Date
- 2026-07-17
AI Technical Summary
Existing industrial control network security systems suffer from false alarms, missed alarms, and low analysis efficiency in energy and chemical industry scenarios. Furthermore, the general large model lacks industrial control protocol semantics and industry knowledge, resulting in inaccurate outputs, data security risks, and an inability to meet production continuity constraints.
A localized large-scale model-assisted analysis method is adopted, including alarm data access and standardization, industrial control protocol semantic parsing, asset and production area context construction, enhanced analysis knowledge base retrieval, localized model reasoning, trusted verification and rule fallback, and closed-loop feedback optimization, to ensure local controllability of data and improve the accuracy and efficiency of analysis.
It significantly reduces the risk of false alarms, improves the completeness and efficiency of interpreting complex alarms, ensures data security and autonomous controllability, reduces the risk of inappropriate handling suggestions, and achieves rapid and accurate industrial control alarm analysis.
Smart Images

Figure CN122419975A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of industrial control system network security, industrial control security situation awareness, artificial intelligence-assisted analysis and emergency response, and specifically to a localized large-scale model-assisted analysis method and system for industrial control network alarms in the energy and chemical industry. Background Technology
[0002] Industrial control networks in energy and chemical enterprises typically include distributed control systems, programmable logic controllers (PLCs), monitoring and data acquisition systems, engineering workstations, operator workstations, industrial switches, industrial firewalls, and industrial intrusion detection systems. These networks communicate using industrial protocols such as Modbus TCP, OPC / OPCUA, Profinet, EtherNet / IP, S7, and IEC104. With the development of the Industrial Internet, remote operation and maintenance, and digital production management, energy and chemical industrial control networks generate a large amount of protocol traffic, equipment alarms, system logs, asset ledgers, vulnerability information, operation records, and threat intelligence data.
[0003] Existing industrial control system network security systems often focus on fixed rule detection, single-point alarm display, or manual experience analysis. Whether a single alarm represents a genuine risk often requires a comprehensive assessment considering the meaning of protocol instructions, asset importance, production location, business continuity requirements, vulnerability status, historical handling records, and external threat intelligence. Relying solely on the original alarm name or device alarm level is prone to false positives, false negatives, and low analysis efficiency.
[0004] In energy and chemical engineering scenarios, response actions are also strongly constrained by continuous production, safe production, and process flow. For example, isolating, blocking, restarting, or adjusting strategies for equipment in critical control loops or hazardous chemical production units may affect production stability. Therefore, safety systems not only need to determine the risk level, but also need to provide the reasons for the response, the chain of evidence, the conditions for verification, and the requirements for recovery confirmation.
[0005] In recent years, large language models have acquired the capabilities of natural language understanding, summary generation, and question-answering reasoning, and can be used for alarm interpretation, event summarization, and handling assistance. However, energy and chemical industrial control networks contain a large amount of sensitive asset information, network topology, production unit names, and handling records. Directly calling external public models poses risks of data leakage and security compliance. At the same time, general-purpose large models lack knowledge of industrial control protocol semantics, energy and chemical business constraints, and emergency response strategies, which can easily generate inaccurate, uncontrolled, or unexecutable suggestions.
[0006] Therefore, it is necessary to propose a localized large-scale model-assisted analysis method and system for energy and chemical industrial control alarms. This system should combine industrial control alarm standardization, protocol semantic parsing, asset context construction, enhanced knowledge base retrieval, localized model reasoning, reliability verification, rule fallback, and human feedback optimization to improve the ability to interpret complex alarms, conduct secondary analysis, and assist in handling, while ensuring local data controllability. Existing solutions struggle to simultaneously address data security, in-depth analysis of industrial control protocols, production process constraints, and the reliability of large-scale model outputs, and their industry adaptability remains insufficient. Summary of the Invention
[0007] The purpose of this invention is to provide a localized large-scale model-assisted analysis method and system for energy and chemical industrial control alarms, which can solve the problems of scattered alarm sources, large number of alarms, insufficient utilization of protocol semantics, reliance on human experience in the analysis process, lack of industry knowledge in general large-scale models, data security risks in calling external models, lack of production continuity constraints in handling suggestions, and difficulty in accumulating and reusing human experience in the safe operation of energy and chemical industrial control.
[0008] To achieve the above objectives, the system provided by this invention includes an alarm data access and standardization module, an industrial control protocol semantic parsing module, an asset and production area context construction module, an analysis knowledge base module, a retrieval enhancement module, a localized large model reasoning module, a trusted verification and rule fallback module, and a closed-loop feedback optimization module.
[0009] The alarm data access and standardization module is used to access industrial control protocol traffic, security alarms, log data, asset profiles, vulnerability information, threat intelligence and historical event records, and form alarm data with a unified field structure through time synchronization, source identification, field mapping, deduplication and standardization processing.
[0010] The industrial control protocol semantic parsing module is used to perform protocol identification, field extraction, instruction semantic annotation, and abnormal behavior identification on alarms related to the aforementioned mainstream industrial control protocols, converting the original protocol fields into interpretable semantic tags required for alarm analysis.
[0011] The Asset and Production Area Context Building Module is used to associate alarms with asset identifiers, asset importance, production area, business roles, communication relationships, vulnerability information, historical events, and production continuity requirements to form a structured analysis context.
[0012] The assessment knowledge base module includes a risk knowledge base, a handling strategy base, a protocol semantic base, and a historical case base. It is used to store protocol anomalies, command anomalies, access anomalies, misoperation anomalies, vulnerability vulnerabilities, attack characteristics, handling strategies, protocol semantic descriptions, historical events, and manual correction records.
[0013] The retrieval enhancement module is used to retrieve relevant knowledge fragments from the judgment knowledge base module based on the current alarm context, and sort them according to relevance, asset similarity, risk level consistency, knowledge update time and disposal success rate, providing evidence and constraints for localized large model reasoning.
[0014] The localized large model reasoning module is used to call the locally deployed large language model in the enterprise local area or security management area. It combines the current alarm context, retrieved knowledge fragments, industry domain knowledge, production continuity constraints and output format constraints into a prompt template, and generates alarm summary, risk cause, impact scope, evidence chain, handling suggestions and manual review prompts.
[0015] The trust verification and rule fallback module is used to perform fact consistency verification, protocol security constraint verification, action risk verification, and confidence score on the results generated by the large model. When the model is unavailable, the response times out, the output format does not meet the requirements, the verification fails, or the confidence score is lower than the threshold, the system outputs a fallback judgment result based on the rule base, the action strategy base, and the historical case base.
[0016] The localized large-scale model inference module and the trusted verification and rule fallback module are used to generate and output structured auxiliary judgment results. The structured auxiliary judgment results include alarm summary, protocol semantic explanation, related assets, production area, risk cause, risk level suggestion, evidence chain, scope of impact, similar historical cases, disposal suggestions, confidence level, and manual review prompts. Among them, the disposal suggestions are generated based on trusted verification results, disposal strategy library, production continuity constraints, asset importance, and historical disposal effects, and are used to determine disposal path, disposal priority, and review process.
[0017] The closed-loop feedback optimization module records the entire process of an event, from discovery, summary generation, risk interpretation, handling suggestions, manual review, work order processing, recovery confirmation to post-event evaluation, and feeds back the manual correction results to the knowledge base, prompt templates, trusted verification rules, and handling strategy library.
[0018] This invention also provides a localized large-scale model-assisted analysis method for energy and chemical industrial control alarms, including: accessing multi-source industrial control alarm data; performing standardization processing; parsing industrial control protocol fields and abnormal behaviors; constructing asset and production area contexts; retrieving risk knowledge, protocol semantics, handling strategies, and historical cases; calling a localized large-scale model to generate auxiliary analysis results; performing credibility verification and confidence scoring on the generated results; outputting structured analysis results or rule-based fallback results; receiving manual corrections and updating the knowledge base, prompt templates, rules, and strategies.
[0019] Compared with existing technologies, this invention has at least the following beneficial effects: First, by using localized large-scale model reasoning, it avoids the out-of-domain processing of original industrial control sensitive data, thereby improving data security and autonomous controllability in energy and chemical engineering scenarios. Second, it transforms industrial control protocol fields, asset profiles, production areas, vulnerability information, and historical handling experience into a structured judgment context, improving the completeness and efficiency of complex alarm interpretation. Third, by enhancing retrieval, it injects risk knowledge bases, handling strategy bases, protocol semantic bases, and historical case bases into the model reasoning process, improving the industry adaptability and judgment accuracy of the output content. Fourth, it reduces the risk of large-scale model illusions and inappropriate handling suggestions through trusted verification, rule fallback, and confidence scoring. Fifth, it continuously optimizes the knowledge base, prompt templates, rule base, and strategy base through manual correction feedback, achieving a closed-loop accumulation of alarm judgment and handling experience. Sixth, in a typical implementation scenario, this solution can shorten the average judgment time of a single complex industrial control alarm from more than ten minutes to tens of seconds, significantly reducing the risk of alarm misjudgment, while ensuring local storage and processing of original industrial control sensitive data. Attached Figure Description
[0020] Figure 1 This is a schematic diagram of the overall system structure of the present invention. Figure 2 This is a schematic diagram of the industrial control alarm context construction and retrieval enhancement process of the present invention. Figure 3 This is a schematic diagram of the localized large model-assisted judgment and credibility verification process of the present invention. Figure 4 This is a schematic diagram of an embodiment of the system deployment architecture of the present invention. Detailed Implementation
[0021] The present invention will be further described below with reference to specific embodiments. It should be understood that the following embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the scope of protection of the present invention. Equivalent substitutions, modifications, or combinations made by those skilled in the art without departing from the technical concept of the present invention should all fall within the scope of protection of the present invention. Example 1: A localized large-scale model-assisted judgment system for energy and chemical industrial control alarms
[0022] This system is deployed in the industrial control network security management area, enterprise intranet, or private cloud environment of energy and chemical enterprises. It can interface with industrial control firewalls, industrial intrusion detection systems, anomaly detection systems, log platforms, asset management systems, vulnerability management systems, work order systems, and situation display platforms. The system adopts a modular architecture, including an alarm data access and standardization module, an industrial control protocol semantic parsing module, an asset and production area context construction module, an analysis knowledge base module, a retrieval enhancement module, a localized large model inference module, a trusted verification and rule fallback module, and a closed-loop feedback optimization module. In a preferred embodiment, additional functional units such as a continuous session-assisted analysis module and an auditing and security isolation module can also be set up. These additional functional units do not affect the independent operation of the aforementioned core modules.
[0023] The alarm data access and standardization module collects data through mirroring ports, log interfaces, device interfaces, message queue interfaces, or API interfaces. For actively collected data, the system acquires incremental data according to the collection task cycle; for passively received data, the system receives alarms or logs pushed by external devices. The system performs time synchronization, source identification, field mapping, data deduplication, integrity verification, and task status recording on the accessed data, and forms a unified alarm field structure.
[0024] The unified alarm field structure can include alarm number, occurrence time, source device, protocol type, source address, destination address, port, function code, register address, read / write direction, operation command, asset identifier, production area, business role, asset importance, original alarm level, threat intelligence hit item, vulnerability label, historical similar event number, and original message summary.
[0025] The industrial control protocol semantic parsing module identifies and parses the aforementioned mainstream industrial control protocols. For example, for ModbusTCP alarms, the system parses the function code, register address, read / write direction, and access frequency, and converts "writing multiple registers," "abnormal write coil," and "high-frequency read of critical registers" into protocol semantic tags.
[0026] The asset and production area context construction module associates current alarms with specific assets and production business contexts based on asset ledgers, communication relationships, business roles, production areas, responsible persons, asset importance, vulnerability vulnerability, configuration baselines, patch status, and historical event records. For example, when an engineer station exhibits abnormal write behavior to a critical PLC, the system incorporates the engineer station's identity, the production area where the target PLC is located, the importance of the control loop, the current vulnerability status, and historical similar events into the analysis context.
[0027] The assessment knowledge base module includes a risk knowledge base, a protocol semantics base, a handling strategy base, and a historical case base. The risk knowledge base stores the relationships between protocol anomalies, access anomalies, command anomalies, misoperation anomalies, vulnerability vulnerabilities, attack stages, and business impacts. The protocol semantics base stores explanations of different industrial control protocol fields, function codes, operation commands, and abnormal behaviors. The handling strategy base stores handling actions, preconditions, review requirements, and recovery confirmation requirements under different risk levels, production areas, asset types, and event types. The historical case base stores assessment conclusions, handling effects, and manual correction records for handled events.
[0028] The retrieval enhancement module performs knowledge retrieval based on the protocol type, asset object, production area, abnormal behavior label, vulnerability label, event type, and time window of the current alarm. The retrieval results are then sorted according to relevance, historical handling success rate, asset similarity, risk level consistency, knowledge update time, and handling effectiveness. The retrieval results are input into the localized large-scale model inference module in the form of evidence fragments.
[0029] The localized large-scale model inference module is deployed on a local server or in a private model runtime environment to avoid sending raw industrial control sensitive data to external public model services. Before model invocation, the prompt template orchestration unit combines structured judgment context, retrieved evidence fragments, industry domain knowledge, production continuity constraints, unauthorized operation prohibition constraints, and output format constraints into a prompt template. Model output includes alarm summary, protocol semantic explanation, risk cause, scope of impact, handling suggestions, evidence chain, confidence level description, and manual review prompt.
[0030] The trust verification and rule fallback module verifies the model output. The fact consistency verification unit determines whether the assets, protocols, times, alarm sources, and risk levels output by the model are consistent with the current context and retrieved evidence; the protocol constraint verification unit determines whether the model's interpretation of protocol instructions conforms to the protocol semantic library; the action security verification unit determines whether actions such as isolation, blocking, policy adjustment, suspension of remote access, and recovery confirmation meet production continuity constraints and action permission requirements; and the confidence score unit calculates the confidence score based on evidence coverage, output consistency, rule hit count, historical case similarity, alarm source credibility, and asset vulnerability matching degree.
[0031] When the model output passes the verification and the confidence level is higher than the threshold, the trusted verification and rule fallback module will display the structured auxiliary judgment results to the security management personnel. When the model is unavailable, the response times out, the output format is incorrect, the facts are inconsistent, or the confidence level is insufficient, the rule fallback mechanism will generate basic judgment results based on the preset rules and the handling strategy library, and mark it as requiring manual review.
[0032] As a preferred additional functional unit, the continuous conversation-assisted analysis module saves the context state within the same event lifecycle, enabling safety managers to ask follow-up questions such as "Why was it judged as high-risk?", "Will it affect production equipment?", "How were similar events handled in the past?", and "Can we observe first?". The system archives user follow-up questions, model answers, supplementary evidence, handling confirmations, and review opinions along with the event number, providing a basis for subsequent review and strategy optimization.
[0033] As a preferred additional functional unit, the audit and security isolation module records model call logs, knowledge retrieval logs, user operation logs, output content versions, adoption status of handling suggestions, and manual review records. It also ensures data security through identity authentication, access control, transmission encryption, field anonymization, and model service isolation.
[0034] The closed-loop feedback optimization module receives manual correction results after the event handling is completed. Manual corrections can be made to the risk level, risk cause, evidence chain, handling recommendations, and handling effects. The system uses these corrections to update historical case tags, search indexes, prompt templates, trust verification rules, and handling strategy weights, thereby achieving continuous optimization of model reasoning, rule verification, and strategy matching. Example 2: A localized large-scale model-assisted judgment method for alarms in energy and chemical industrial control systems.
[0035] By accessing alarm data and standardizing modules, the system can access industrial control protocol traffic, security alarms, log data, asset profiles, vulnerability information, threat intelligence, and historical event records in the energy and chemical industrial control network.
[0036] The access data undergoes time synchronization, source identification, field mapping, data deduplication, integrity verification, and standardization to form a unified alarm field structure.
[0037] For alarms related to one or more of the aforementioned mainstream industrial control protocols, the protocol is identified, fields are extracted, operation instructions are identified, and abnormal behavior is labeled.
[0038] The current alarm is associated with asset identifiers, production areas, asset importance, business roles, communication relationships, vulnerability information, historical events, and production continuity requirements to build a structured analysis context.
[0039] Based on the structured analysis context, relevant knowledge fragments are retrieved from the risk knowledge base, protocol semantic base, disposal strategy base, and historical case base, and sorted according to relevance, historical disposal success rate, asset similarity, risk level consistency, and knowledge update time.
[0040] By inputting structured analysis context, retrieved knowledge fragments, production continuity constraints, and output format constraints into the localized large model, alarm summaries, protocol semantic explanations, risk causes, scope of impact, evidence chains, handling suggestions, and manual review prompts are generated.
[0041] The results generated by the large model are subjected to fact consistency verification, protocol security constraint verification, action risk verification, and confidence score.
[0042] When the verification passes and the confidence level is higher than the threshold, a structured auxiliary judgment result is output; when the model call fails, the response times out, the output does not meet the format requirements, the facts are inconsistent, or the confidence level is lower than the threshold, a rule-based fallback judgment result is output and marked as manual review.
[0043] It receives manual corrections on risk level, risk cause, evidence chain, handling suggestions, and handling effects, and feeds the correction results back to the knowledge base, prompt templates, trusted verification rules, and handling strategy library.
[0044] Through the above methods, the system can realize multi-source alarm access, protocol semantic parsing, asset context construction, knowledge retrieval enhancement, localized model reasoning, trusted verification, rule fallback, disposal suggestion generation, and manual feedback optimization in the energy and chemical industrial control network environment. This not only improves the efficiency of complex alarm analysis but also reduces the risks caused by data out-of-domain processing and untrusted output of large models. Example 3: Specific Implementation of Trust Verification and Confidence Scoring
[0045] In one specific implementation, the trusted verification and rule-based fallback module performs multi-dimensional verification on the output of the large model. Fact consistency verification includes verifying whether the asset name, IP address, protocol type, time window, alarm source, and risk level in the output are consistent with the structured context; protocol security constraint verification includes verifying whether the model's interpretation of function codes, read / write directions, register operations, and session behavior is consistent with the protocol semantic library; and action risk verification includes verifying whether the action meets production continuity requirements, approval authority, recovery confirmation requirements, and manual review requirements.
[0046] The confidence score can be obtained by weighting the following factors: retrieval evidence coverage, model output consistency with context, rule hit count, historical case similarity, alert source credibility, and asset vulnerability matching degree. If the confidence score is higher than the first threshold, the system outputs an acceptable assessment suggestion; if the confidence score is between the first and second thresholds, the system outputs a suggestion for manual review; if the confidence score is lower than the second threshold, the system activates a rule fallback and prohibits the automatic execution of high-risk handling actions that have not been manually reviewed and confirmed.
[0047] For example, the confidence score has a maximum score of 100 points, with a first confidence threshold of 85 points and a second confidence threshold of 60 points. When the confidence score is greater than or equal to 85 points and the factual consistency verification, protocol constraint verification, and action risk verification all pass, an acceptable assessment recommendation is output. When the confidence score is greater than or equal to 60 points but less than 85 points, a manual review recommendation is output. When the confidence score is less than 60 points, the model call fails, the response times out, or the verification fails, a rule-based fallback assessment is activated. The first and second thresholds are merely examples and can be flexibly configured according to the enterprise's security level, asset importance level, alarm type, and production scenario.
[0048] For events involving critical production facilities, hazardous chemical production areas, control loops, or safety instrumented systems, the system still forces manual verification even if the model output has a high confidence level. The system can output disposal suggestions such as isolation, blocking, restart, or strategy adjustment, but will not automatically execute high-risk disposal operations that have not been manually confirmed, in order to prevent disruption to continuous production. Example 4: Localized Deployment and Data Security Implementation
[0049] In one engineering deployment implementation, the system includes edge acquisition nodes, an alarm analysis server, a knowledge base server, a localized large-scale model server, a rule fallback server, a web analysis terminal, and an interface gateway. The edge acquisition nodes are deployed in the production control network security management area, collecting protocol traffic and security alarms through mirror ports, log interfaces, or device interfaces. The alarm analysis server performs data standardization, protocol semantic parsing, context construction, knowledge retrieval, and trust verification. The knowledge base server stores a risk knowledge base, a protocol semantic base, a handling strategy base, and a historical case base. The localized large-scale model server performs model inference. The rule fallback server provides basic rule analysis. The web analysis terminal provides an interface for event retrieval, analysis Q&A, handling suggestions, and review reports. The interface gateway exchanges data with the work order system, security management platform, group-level security operation platform, and regulatory interfaces.
[0050] The system defaults to a localized large-scale model priority strategy. Original alarms, asset ledgers, production area names, IP addresses, process unit names, disposal records, and personnel information are not sent to external public model services, and un-anonymized and unauthorized original sensitive industrial control data is not transmitted outside the enterprise network boundary. When it is necessary to call an external model, the system first anonymizes and replaces sensitive fields, and only sends authorized digest contexts. Audit logs are recorded throughout the model call and knowledge retrieval process to meet security management and traceability requirements. The entire system adheres to the security principles of energy and chemical industrial control network partitioning, data locality, and least privilege to adapt to industrial network security and data compliance requirements.
Claims
1. A localized large-scale model-assisted analysis system for energy and chemical industry control alarms, characterized in that, It includes an alarm data access and standardization module, an industrial control protocol semantic parsing module, an asset and production area context construction module, an analysis knowledge base module, a retrieval enhancement module, a localized large model reasoning module, a trusted verification and rule fallback module, and a closed-loop feedback optimization module; the alarm data access and standardization module is used to access protocol traffic, security alarms, log data, asset profiles, vulnerability information, threat intelligence, and historical event records in the energy and chemical industrial control network, and form standardized and unified alarm data; The industrial control protocol semantic parsing module is used to parse alarm fields related to industrial protocols and generate protocol semantic tags; the asset and production area context construction module is used to associate the current alarm with asset importance, production area, business role, communication relationship, vulnerability status and production continuity constraints to form a structured judgment context; the judgment knowledge base module includes a risk knowledge base, a protocol semantic base, a disposal strategy base and a historical case base; the retrieval enhancement module is used to retrieve knowledge fragments in the judgment knowledge base module based on the structured judgment context; The localized large-scale model inference module is deployed in the enterprise intranet, industrial control network security management area, or private cloud environment to perform local inference without transmitting original sensitive industrial control data outside the enterprise network boundary. The localized large-scale model inference module combines industrial domain knowledge base for retrieval-enhanced inference and superimposes production continuity security constraints. It generates structured auxiliary judgment results based on the structured judgment context and retrieved knowledge fragments. The trust verification and rule fallback module is used to perform fact consistency verification, protocol constraint verification, action risk verification, and confidence score on the structured auxiliary judgment results. When the verification fails or the model is unavailable, it outputs rule fallback judgment results. The closed-loop feedback optimization module is used to update the knowledge base, retrieval index, prompt template, trusted verification rules, and handling strategy weights based on the results of manual correction.
2. The system according to claim 1, characterized in that, The alarm data access and standardization module performs time synchronization, source identification, field mapping, deduplication, and integrity verification on the access data according to a unified alarm field structure. The unified alarm field structure includes one or more of the following: alarm time, alarm source, protocol type, communication object, operation command, asset identifier, production area, asset importance, vulnerability label, threat intelligence hit item, and original alarm summary.
3. The system according to claim 1, characterized in that, The industrial control protocol semantic parsing module extracts function codes, register addresses, read / write directions, session states, access frequencies, and cross-regional access relationships for one or more protocols among ModbusTCP, OPC / OPCUA, Profinet, EtherNet / IP, S7, and IEC104; and converts one or more behaviors among abnormal writes, unauthorized access, erroneous operations, abnormal logins, abnormal read / write frequencies, unauthorized command calls, and cross-regional access into protocol semantic tags.
4. The system according to claim 1, characterized in that, The asset and production area context construction module includes an asset association unit, a business impact labeling unit, a production continuity constraint unit, and a vulnerability association unit. The production continuity constraint unit is used to determine whether the target asset belongs to a continuous production unit, a critical control loop, a hazardous chemical production unit, or a safety instrumented area. It also marks one or more of the following actions as high-risk actions requiring manual review: isolation, blocking, restart, strategy adjustment, and recovery confirmation.
5. The system according to claim 1, characterized in that, The retrieval enhancement module uses keyword retrieval, vector similarity retrieval, or a combination of both to retrieve knowledge fragments from the risk knowledge base, protocol semantic base, disposal strategy base, and historical case base. After sorting the fragments according to one or more indicators such as relevance, asset similarity, event type similarity, risk level consistency, knowledge update time, and historical disposal success rate, the fragments are input into the localized large model inference module.
6. The system according to claim 1, characterized in that, The localized large-scale model inference module includes a prompt template arrangement unit, a context compression unit, a model invocation unit, and a structured generation unit. The model invocation unit invokes a large language model that has been locally deployed, quantized and compressed, fine-tuned in the domain, and / or adapted to prompt templates. The prompt template arrangement unit combines the current alarm context, retrieved knowledge fragments, constraints prohibiting the output of high-risk production handling actions without review, evidence citation constraints, and structured output format constraints as model input. The structured generation unit outputs alarm summaries, protocol semantic explanations, risk causes, risk level suggestions, evidence chains, scope of impact, similar historical cases, handling suggestions, and manual review prompts.
7. The system according to claim 1, characterized in that, The trusted verification and rule fallback module calculates the assessment confidence level based on the retrieval evidence coverage, consistency between the large model output and the context, the number of rule hits, the similarity of historical cases, the credibility of the alarm source, and the matching degree of asset vulnerability. When the assessment confidence level is higher than the first threshold and the trusted verification passes, an acceptable assessment result is output. When the assessment confidence level is between the first threshold and the second threshold, a manual review suggestion is output. When the confidence level is lower than the second threshold, the model call fails, the response times out, the output format is unqualified, or the credibility verification fails, the system outputs a fallback judgment result based on preset rules, the handling strategy library, and the historical case library. High-risk handling actions involving isolation, blocking, restarting, strategy adjustment, suspension of remote access, and recovery confirmation are marked for manual review. For the high-risk handling actions, the system only outputs handling suggestions and does not automatically execute operations that have not been manually reviewed and confirmed.
8. A localized large-scale model-assisted judgment method for energy and chemical industry control alarms using the system described in any one of claims 1 to 7, characterized in that, The process includes the following steps: S1, accessing industrial control protocol traffic, security alarms, log data, asset profiles, vulnerability information, threat intelligence, and historical event records from the energy and chemical industrial control network; S2, standardizing the accessed data to form standardized unified alarm data; S3, parsing fields, identifying instructions, and annotating abnormal behaviors for alarms related to industrial control protocols to generate protocol semantic tags; S4, associating current alarms with asset identifiers, production areas, asset importance, business roles, communication relationships, vulnerability information, historical events, and production continuity constraints to construct a structured assessment context; S5, based on the structured assessment context, retrieving and sorting knowledge fragments from the risk knowledge base, protocol semantic base, handling strategy base, and historical case base; S6, without transmitting raw sensitive industrial control data outside the enterprise network boundary, inputting the structured assessment context, retrieved knowledge fragments, industrial domain knowledge, and production continuity security constraints into a localized large model to generate structured auxiliary assessment results; S7 performs fact consistency verification, protocol constraint verification, action risk verification, and confidence score on the structured auxiliary analysis results; S8. When the verification passes and the confidence level meets the requirements, output the structured auxiliary judgment result; when the model call is abnormal, the verification fails, or the confidence level does not meet the requirements, output the rule-based fallback judgment result and mark it for manual review; S9. Receive the correction results of manual review on risk level, risk cause, evidence chain, handling suggestions, and handling effect, and update the knowledge base, retrieval index, prompt template, trusted verification rules, and handling strategy weights based on the correction results.
9. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, When the computer program or instructions are executed by a processor, they implement the method of claim 8.
10. A computer program product, characterized in that, It includes a computer program or instructions that, when executed by a processor, implement the method of claim 8.