A user-side metering data intelligent anomaly detection and efficient repair method and system

By constructing a knowledge graph for power metering and using tensor decomposition technology, anomalies in user-side metering data can be accurately located and collaboratively repaired, solving the problem of inconsistent data repair in existing technologies and improving the operating efficiency and service quality of the power system.

CN122432498APending Publication Date: 2026-07-21HANGZHOU RUIQI TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HANGZHOU RUIQI TECHNOLOGY CO LTD
Filing Date
2026-03-06
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing technologies, when detecting and repairing anomalies in user-side metering data, only repair isolated data nodes, leading to inconsistencies between related data nodes and the individually repaired data. This fails to guarantee the economical operation of the power system and the quality of power supply services.

Method used

By acquiring multi-source heterogeneous operational data, a power metering knowledge graph is constructed, static anomaly feature vectors and topology are extracted, time-series data features are fused, anomaly location nodes are accurately located, anomaly propagation paths are analyzed and tensor decomposition is performed, and multi-node collaborative repair is carried out.

Benefits of technology

It enables accurate identification and efficient repair of abnormal data, ensuring that the repaired data conforms to the operational correlation patterns between nodes, solving the problem of data inconsistency in traditional methods, and improving the economic operation of the power system and the quality of power supply services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122432498A_ABST
    Figure CN122432498A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of electric power metering, and particularly discloses a user-side metering data intelligent abnormality detection and efficient repair method and system. Structured electric energy metering data and time sequence operation data are acquired, an electric power metering knowledge graph is constructed based on the structured data, a static abnormality feature vector and a topological structure are extracted, dynamic features such as a frequency domain and a mode of time sequence data are fused, comprehensive abnormality pending feature values are formed, an abnormality position node is accurately positioned, a root cause is diagnosed by analyzing an abnormality propagation path and node operation data, core features are extracted by combining preset normal data for tensor decomposition, and multi-node collaborative repair is carried out based on topological correlation characteristics. In this way, the topological correlation characteristics between abnormality position nodes are considered, multi-node collaborative repair is carried out instead of isolated repair of a single node, and it is ensured that the repaired data can meet the operation correlation law between nodes, so that the problem that associated data nodes and individually repaired data are inconsistent can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power metering technology, and in particular to a method and system for intelligent anomaly detection and efficient repair of user-side metering data. Background Technology

[0002] User-side metering data serves as the core basis for electricity market settlement, grid operation and dispatch, and user electricity consumption analysis. Its accuracy and completeness directly impact the economic operation of the power system and the quality of power supply services. With the widespread deployment of smart meters, IoT sensors, and other devices, a multi-source heterogeneous data system has been formed on the user side, encompassing structured electricity metering data (such as equipment ledgers and user files) and time-series operational data (such as real-time electricity consumption and voltage-current time-series curves). This data not only provides fundamental support for the refined management of the power system but also brings new technological directions to anomaly detection and repair. By mining the correlations and time-series characteristics between data, accurate identification and efficient correction of metering anomalies can be achieved, ensuring the reliability of data applications. However, with the widespread deployment of smart meters, IoT sensors, and other devices on the user side, electricity metering data has formed a multi-source heterogeneous data system that includes structured electricity metering data (such as equipment ledgers and user files) and time-series operational data (such as real-time electricity consumption and voltage and current time-series curves). However, the expansion of data scale and the complexity of structure have also increased the probability of abnormal data occurrence. Currently, when repairing abnormal data, only the data of one node is repaired in isolation, resulting in inconsistencies between the related data nodes and the individually repaired data. Therefore, an intelligent anomaly detection and efficient repair method for user-side metering data is needed to solve the above problems. Summary of the Invention

[0003] The purpose of this invention is to provide an intelligent anomaly detection and efficient repair method for user-side metering data, comprising: A method for intelligent anomaly detection and efficient repair of user-side metering data includes: Acquire multi-source heterogeneous operation data from the target user side, wherein the multi-source heterogeneous operation data includes structured power metering data and time-series power metering operation data; Based on the structured data of electricity metering, an electricity metering knowledge graph is obtained, and static anomaly feature vectors and topological structures are obtained based on the electricity metering knowledge graph; Based on the topology and the power metering time-series operation data, multiple nodes are obtained as undetermined abnormal feature values, and multiple comprehensive undetermined abnormal feature values ​​are obtained based on the multiple undetermined abnormal feature values ​​and the static abnormal feature vector. Sequentially determine whether multiple comprehensive abnormal undetermined feature values ​​exceed the abnormal threshold, and take the position corresponding to the comprehensive abnormal feature value that exceeds the abnormal threshold as the abnormal position node; Multiple node root cause diagnostic data are obtained based on multiple abnormal location nodes, and the multiple node root cause diagnostic data and their corresponding associated node preset normal data are decomposed into tensor data to obtain multiple tensor decomposed data. The multiple tensor decomposition data are collaboratively repaired to obtain a collaborative repair result.

[0004] Preferably, the steps of obtaining a power metering knowledge graph based on the power metering structured data, and obtaining static anomaly feature vectors and topological structures based on the power metering knowledge graph, include: Based on the structured data of electricity metering, obtain equipment ledger data, network topology connection data, and equipment attribute file data; Based on the equipment ledger data and the equipment attribute file data, multiple metering equipment entities, user entities, and distribution transformer area entities are obtained; Based on the network topology connection data and the multiple metering device entities, multiple physical connection relationships between the multiple metering device entities are obtained; based on the multiple metering device entities and the user entity, multiple membership relationships between them are obtained; and based on the multiple metering device entities and the distribution transformer area entity, multiple access relationships are obtained. An initial power metering knowledge graph is constructed based on multiple physical connection relationships, multiple membership relationships, and multiple access relationships. The topological relationship structure of nodes and edges is obtained based on the initial power metering knowledge graph, and the topological relationship structure is used as the topological structure. Obtain the topological centrality and historical co-occurrence frequency of each metering device entity node in the initial power metering knowledge graph; Multiple static risk contribution degrees are calculated based on multiple topological centralities and multiple historical co-occurrence frequencies, and a static anomaly feature vector is constructed based on the multiple static risk contribution degrees.

[0005] Preferably, the step of obtaining multiple undetermined anomaly feature values ​​of multiple nodes based on the topology and the power metering time-series operation data, and obtaining multiple comprehensive undetermined anomaly feature values ​​based on the multiple undetermined anomaly feature values ​​and the static anomaly feature vector, includes: Based on the energy metering time sequence operation data, obtain the energy metering time sequence operation sequence under the preset continuous timestamps; The topological relationship chain is obtained according to the topological structure, and multiple first metering device entities in the topological relationship chain are obtained according to the topological relationship chain. The multi-dimensional operating characteristics of each first metering device entity within a preset time window are obtained, wherein the multi-dimensional operating characteristics include frequency domain characteristics and time-series morphological characteristics. Multiple operation feature vectors are obtained based on the power metering time series operation sequence, multiple frequency domain features, and multiple time series morphological features; The abnormal undetermined feature value of each node is obtained based on multiple described running feature vectors; Based on each of the aforementioned undetermined anomaly features, the cumulative anomaly deviation area and anomaly evolution trend feature value of each node within a preset time window are obtained; The topological neighborhood area corresponding to each node is obtained according to the topological structure, and the spatiotemporal anomaly diffusion intensity of each node is obtained according to the topological neighborhood area and the cumulative anomaly deviation area. The spatiotemporal anomaly intensity of each node is obtained based on the characteristic value of the anomaly evolution trend of each node and the spatiotemporal anomaly diffusion intensity. Obtain multiple historical health feature values ​​corresponding to each identical node within a historical normal period, and obtain the historical health benchmark of the corresponding node based on the multiple historical health feature values ​​of each node; The relative deviation of node anomaly is obtained based on the spatiotemporal anomaly intensity of each node and the historical health benchmark. The node dynamic anomaly comprehensive value of each node is obtained based on the relative deviation of the node anomaly and the spatiotemporal anomaly diffusion intensity, and multiple node dynamic anomaly comprehensive values ​​are used as multiple comprehensive anomaly undetermined feature values.

[0006] Preferably, the step of obtaining root cause diagnosis data for multiple nodes based on multiple abnormal location nodes includes: The topological association between the abnormal location nodes is obtained based on the multiple abnormal location nodes, wherein the topological association includes at least one abnormal propagation path of at least one of the abnormal location nodes; Obtain the time-series data of the running status of each node in each of the aforementioned abnormal propagation paths within a preset historical time period; The spatiotemporal impact intensity of the corresponding node is obtained based on the time-series data of the running status of each node and the anomaly propagation path; Obtain the duration and magnitude of the abnormal change for each of the abnormal location nodes; The node abnormality attribute value of each node is obtained based on the abnormal duration and the abnormal mutation magnitude of each abnormal location node. The node anomaly comprehensive weight is obtained based on the spatiotemporal influence intensity and the node anomaly attribute value of each anomaly location node. The root cause node of each path is obtained by taking the comprehensive weight of the node anomalies of all nodes on each path of anomaly propagation, and the identifier of each root cause node and its corresponding comprehensive weight of the node anomalies are used as the root cause diagnosis data.

[0007] Preferably, the step of performing tensor decomposition on the root cause diagnostic data of multiple nodes and the preset normal data of their corresponding associated nodes to obtain multiple tensor decomposed data includes: For each node root cause diagnosis data corresponding to the abnormal location node, obtain the dimension weights of multiple data dimensions in the node root cause diagnosis data; The node root cause diagnosis data is weighted according to the dimensional weights of the multiple data dimensions to obtain weighted node root cause diagnosis data. Obtain the preset normal data corresponding to the abnormal location node within the historical normal period; Multiple historical normal principal component features are extracted from the preset normal data, and the average value of the historical normal principal component features of the abnormal location node is obtained based on the multiple historical normal principal component features. Multiple abnormal principal component features are extracted from the weighted root cause diagnosis data of the nodes, and the mean value of the current abnormal principal component features of the nodes at the abnormal locations is obtained based on the multiple abnormal principal component features. Based on the historical normal principal component feature mean and the current abnormal principal component feature mean, the feature deviation of the abnormal location node is obtained; The weighted node root cause diagnosis data, the feature deviation, and the preset normal data are combined to construct a node repair feature tensor; The node repair feature tensor is decomposed into multiple core feature sub-tensors, and these multiple core feature sub-tensors are used as multiple tensor decomposition data.

[0008] Preferably, the step of collaboratively repairing multiple tensor decomposition data to obtain a collaborative repair result includes: For each of the abnormal location nodes, the tensor decomposition data is used to obtain the repair stability features in multiple core feature sub-tensors, and the node repair stability vector of the corresponding node is obtained based on the repair stability features of each core feature sub-tensor. The connection relationships between the nodes at the abnormal locations are obtained based on the topology, and the repair influence intensity between nodes is obtained based on the connection relationships and multiple node repair stability vectors. Based on the repair stability vectors of multiple nodes and the repair influence strength between nodes, a collaborative repair feature matrix is ​​constructed; Obtain the collaborative historical normal data corresponding to the abnormal location node within the historical normal period, and obtain the collaborative health benchmark based on the collaborative historical normal data; Based on the collaborative repair feature matrix and the collaborative health benchmark, the collaborative repair credibility is calculated, and the collaborative repair credibility is used as the collaborative repair result.

[0009] This application also provides an intelligent anomaly detection and efficient repair system for user-side metering data, including: The data acquisition module is used to acquire multi-source heterogeneous operation data from the target user side, wherein the multi-source heterogeneous operation data includes structured power metering data and time-series power metering operation data. The vector acquisition module is used to acquire the power metering knowledge graph and topology based on the power metering structured data, and to acquire static anomaly feature vectors based on the power metering knowledge graph. The feature acquisition module is used to acquire multiple undetermined abnormal feature values ​​of multiple nodes based on the topology and the power metering time series operation data, and to acquire multiple comprehensive undetermined abnormal feature values ​​based on the multiple undetermined abnormal feature values ​​and the static abnormal feature vector. The judgment module is used to sequentially judge whether multiple comprehensive abnormal undetermined feature values ​​exceed the abnormal threshold, and to take the position corresponding to the comprehensive abnormal feature value that exceeds the abnormal threshold as the abnormal position node. The tensor decomposition module is used to obtain multiple node root cause diagnostic data based on multiple abnormal location nodes, and to perform tensor decomposition on the multiple node root cause diagnostic data and the preset normal data of their corresponding associated nodes to obtain multiple tensor decomposition data. The collaborative repair module is used to collaboratively repair multiple tensor decomposition data to obtain a collaborative repair result.

[0010] Preferably, the vector acquisition module includes: The first acquisition unit is used to acquire equipment ledger data, network topology connection data and equipment attribute file data based on the structured power metering data; The second acquisition unit is used to acquire multiple metering equipment entities, user entities, and distribution transformer area entities based on the equipment ledger data and the equipment attribute file data. The topology relationship acquisition unit is used to acquire multiple physical connection relationships between multiple metering device entities based on the network topology connection data and multiple metering device entities, acquire multiple membership relationships between multiple metering device entities and user entities, and acquire multiple access relationships between multiple metering device entities and distribution transformer area entities. The knowledge graph construction unit is used to construct an initial power metering knowledge graph based on multiple physical connection relationships, multiple membership relationships, and multiple access relationships, and to obtain the node-edge topological relationship structure based on the initial power metering knowledge graph, and to use the topological relationship structure as the topological structure. The third acquisition unit is used to acquire the topological centrality and historical co-occurrence frequency of each metering device entity node in the initial power metering knowledge graph; The calculation unit is used to calculate multiple static risk contribution degrees based on multiple topological centralities and multiple historical co-occurrence frequencies, and to construct a static anomaly feature vector based on the multiple static risk contribution degrees.

[0011] This application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the above-described method.

[0012] This application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the above-described method.

[0013] The beneficial effects of this application are as follows: This invention comprehensively acquires structured electricity metering data and time-series operation data collected by power system equipment management systems, user file databases, and smart meters, etc., constructs an electricity metering knowledge graph based on the structured data, extracts static anomaly feature vectors and topological structures, integrates the frequency domain, morphological and other dynamic features of time-series data to form comprehensive anomaly undetermined feature values, accurately locates anomaly nodes, diagnoses root causes by analyzing anomaly propagation paths and node operation data, extracts core features by tensor decomposition combined with preset normal data, and carries out multi-node collaborative repair based on topological correlation characteristics. This approach considers the topological correlation characteristics between nodes at anomaly locations and performs multi-node collaborative repair rather than repairing a single node in isolation, ensuring that the repaired data conforms to the operational correlation rules between nodes, thereby solving the problem of inconsistency between data nodes that can be correlated and data repaired individually. Attached Figure Description

[0014] Fig. 1 This is a schematic diagram of a method flow according to an embodiment of this application.

[0015] Fig. 2 This is a schematic diagram of the system structure according to an embodiment of this application.

[0016] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0017] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0018] like Figs. 1-2 As shown, this application provides an intelligent anomaly detection and efficient repair method for user-side metering data, including: S1. Obtain multi-source heterogeneous operation data from the target user side, wherein the multi-source heterogeneous operation data includes structured power metering data and time-series power metering operation data; S2. Obtain a power metering knowledge graph based on the power metering structured data, and obtain static anomaly feature vectors and topology based on the power metering knowledge graph; S3. Obtain multiple undetermined abnormal feature values ​​of multiple nodes based on the topology and the power metering time-series operation data, and obtain multiple comprehensive undetermined abnormal feature values ​​based on the multiple undetermined abnormal feature values ​​and the static abnormal feature vector; S4. Sequentially determine whether the multiple comprehensive abnormal undetermined feature values ​​exceed the abnormal threshold, and take the position corresponding to the comprehensive abnormal feature value that exceeds the abnormal threshold as the abnormal position node. S5. Obtain multiple node root cause diagnostic data based on multiple abnormal location nodes, and perform tensor decomposition on the multiple node root cause diagnostic data and the preset normal data of their corresponding associated nodes to obtain multiple tensor decomposition data. S6. Perform collaborative repair on multiple tensor decomposition data to obtain collaborative repair results.

[0019] As described in steps S1-S6 above, with the widespread deployment of smart meters, IoT sensors, and other devices on the user side, power metering data has formed a multi-source heterogeneous data system that includes structured power metering data (such as equipment ledgers and user files) and time-series operational data (such as real-time power consumption and voltage-current time-series curves). These data are the core basis for the refined management of the power system. However, the expansion of data scale and the complexity of structure also increase the probability of abnormal data occurrence, and the types of abnormalities are becoming more diverse, which may involve various situations such as equipment failure, data transmission errors, and topology correlation anomalies. If they cannot be detected and repaired in a timely and accurate manner, they will directly affect the economic operation of the power system and the quality of power supply services. This invention first obtains multi-source heterogeneous operational data on the target user side, wherein the multi-source heterogeneous operational data includes structured power metering data and time-series power metering operational data. From a data source perspective, structured electricity metering data can be obtained from existing equipment management systems and user profile databases within the power system, covering fixed-format data such as equipment ledgers, user attributes, and distribution transformer area information. Time-series electricity metering data, on the other hand, comes from real-time data collected by smart meters, sensors, and other devices, including dynamic changes in electricity consumption, voltage, and current at different timestamps. The physical significance of this step lies in providing comprehensive and complete data source support for subsequent anomaly detection and repair. The identification and repair of abnormal data must be based on a comprehensive understanding of the equipment's basic information, topological relationships, and operating status. The lack of any type of data can lead to incomplete capture of anomaly characteristics. For example, if only time-series operational data is obtained without equipment ledger data, it will be impossible to determine static factors that may affect data anomalies, such as equipment model and service life. Without time-series data, it will be difficult to capture dynamic evolution anomalies in the data, such as sudden changes in electricity consumption. A power metering knowledge graph is obtained from structured power metering data, and static anomaly feature vectors and topology are derived from this knowledge graph. Specifically, equipment ledger data, network topology connection data, and equipment attribute file data are first extracted from the structured power metering data. Then, based on this data, metering equipment entities, user entities, and distribution transformer area entities are identified. Furthermore, the physical connection relationships between metering equipment, the affiliation relationships between metering equipment and users, and the access relationships between metering equipment and distribution transformer areas are identified. An initial power metering knowledge graph is constructed based on these entities and relationships. Subsequently, the node-edge topology structure is extracted from the graph as the topology, and the topological centrality and historical co-occurrence frequency of each metering equipment entity node are obtained. The static risk contribution is calculated, and a static anomaly feature vector is constructed. The physical significance of this step lies in transforming fragmented structured data into a knowledge graph with interconnected relationships, mining the static correlation features behind the data, and providing topological and static risk-level evidence for anomaly detection. For example, if a metering device occupies a central position in the topology (high topological centrality) and has historically exhibited a high frequency of co-occurrence with other devices (high historical co-occurrence frequency), then its static risk contribution is high, resulting in a larger dimensionality in the static anomaly feature vector. Subsequent detection should focus on the data anomalies of this device. This step transforms "isolated data" into "associative knowledge," solving the problem of traditional methods neglecting static topological relationships between data and providing more comprehensive feature dimensions for anomaly detection. Based on the topology and electricity metering time-series operation data, multiple nodes' undetermined anomaly feature values ​​are obtained. Then, multiple comprehensive undetermined anomaly feature values ​​are obtained based on these multiple undetermined anomaly feature values ​​and static anomaly feature vectors. Specifically, the time-series operation sequence under preset continuous timestamps is first extracted from the electricity metering time-series operation data. Then, a topological relationship chain is obtained based on the topology. The frequency domain features (such as frequency distribution features obtained through Fourier transform) and time-series morphological features (such as data upward trends, downward trends, and fluctuation amplitudes) of the metering equipment entities within the chain are extracted within a preset time window. An operation feature vector is constructed by combining the time-series operation sequence, thereby obtaining the undetermined anomaly feature value for each node. Subsequently, the cumulative anomaly deviation area and anomaly evolution trend feature value within the preset time window are calculated. The spatiotemporal anomaly diffusion intensity is obtained by combining the topological neighborhood area. Then, the relative deviation degree of node anomalies is calculated by combining the historical health benchmark within the historical normal cycle. Finally, the comprehensive dynamic anomaly value of the node is obtained as the comprehensive undetermined anomaly feature value. The physical significance of this step lies in integrating static anomaly features and dynamic temporal features to construct a multi-dimensional comprehensive anomaly judgment basis. This considers both the static risk attributes of the equipment and captures the dynamic evolution patterns of the data and the diffusion impact of anomalies. For example, if the time-series operation data of a node shows a significant fluctuation in electricity consumption within a short period (anomaly in temporal morphology), and multiple nodes in its topological neighborhood also exhibit similar fluctuations (high spatiotemporal anomaly diffusion intensity), and the node has a high static risk contribution (large numerical value corresponding to the dimension of the static anomaly feature vector), then its comprehensive anomaly pending feature value will increase significantly, comprehensively reflecting the degree of anomaly of the node. This step overcomes the limitations of traditional methods that rely solely on a single-dimensional feature for anomaly judgment. By integrating static and dynamic features, it improves the comprehensiveness and accuracy of anomaly feature capture. The process sequentially determines whether multiple comprehensive anomaly features exceed an anomaly threshold, and identifies the locations of these exceeding thresholds as anomaly node locations. The anomaly threshold can be determined based on statistical analysis of historical normal data, such as by calculating the maximum value or 95th percentile of comprehensive anomaly features across all nodes within a historical normal period, ensuring the threshold effectively distinguishes between normal and anomalous data. The physical significance of this step lies in quantifying the extracted comprehensive anomaly features to accurately pinpoint the specific node where the anomaly occurred, providing a clear target for subsequent root cause diagnosis and repair. For example, if a node has a comprehensive anomaly feature value of 8.5, and the anomaly threshold is set to 6.0, then this node is identified as an anomaly node, and subsequent root cause analysis and data repair will be conducted targeting this node. This step, through quantified threshold judgment, avoids errors caused by subjective judgment, improves the accuracy of anomaly location, and solves the problems of vague anomaly judgment standards and inaccurate location in traditional methods. Multiple node root cause diagnostic data are obtained from multiple abnormal location nodes, and tensor decomposition is performed on the multiple node root cause diagnostic data and their corresponding associated node preset normal data to obtain multiple tensor decomposed data. In the root cause diagnosis section, the topological relationships between nodes at abnormal locations are first analyzed through topological structure analysis to identify the anomaly propagation path. Then, the time-series data of the operational status of each node on each path within a preset historical time period are obtained. The spatiotemporal impact intensity, anomaly duration, and anomalous mutation amplitude of the nodes are calculated to obtain the comprehensive weight of the node anomaly. Finally, the root cause node on each path is determined, and the root cause node identifier and its comprehensive anomaly weight are used as the node root cause diagnosis data. In the tensor decomposition section, for the root cause diagnosis data of each node at an abnormal location, the weights of each data dimension are first obtained and weighted. Then, the historical normal principal component feature mean of the preset normal data (i.e., the operational data within the historical normal period of the node) and the current abnormal principal component feature mean of the weighted root cause diagnosis data are extracted. The feature deviation is calculated, and then the weighted root cause diagnosis data, feature deviation, and preset normal data are combined to construct a node repair feature tensor. This tensor is decomposed to obtain the core feature sub-tensor as tensor decomposition data. The physical significance of this step is to clarify the root cause of the anomaly and to fuse the root cause data with the normal data to extract core features, providing a precise basis for subsequent repair. For example, if the propagation paths of multiple abnormal location nodes all point to a certain metering device, and this device has the highest overall weight for node abnormalities, then this device is identified as the root cause node, and its abnormality may be due to measurement errors caused by equipment aging. Tensor decomposition can separate and extract abnormal features from the root cause data, healthy features from the normal data, and feature deviations, enabling subsequent repairs to specifically correct abnormal parts while preserving normal features. This step solves the problems of traditional methods lacking root cause diagnosis and having strong blind repair tendencies. Through root cause localization and tensor decomposition, the repair process becomes more targeted. Furthermore, the application of tensor decomposition technology can effectively extract the core features of the data, reduce data dimensionality, and improve the efficiency of subsequent repairs. The collaborative repair of multiple tensor decomposition data is performed to obtain the collaborative repair result. Specifically, repair stability features are first extracted from the tensor decomposition data of each anomalous node to construct a node repair stability vector. Then, the connection relationships between anomalous nodes are analyzed based on the topological structure, and the repair influence strength between nodes is calculated in conjunction with the node repair stability vector to construct a collaborative repair feature matrix. Subsequently, historical normal data (i.e., normally operating data with inter-node correlation) of anomalous nodes within historical normal cycles is obtained to establish a collaborative health benchmark. Finally, the collaborative repair credibility is calculated based on the collaborative repair feature matrix and the collaborative health benchmark, serving as the collaborative repair result. The physical significance of this step lies in considering the topological correlation characteristics between anomalous nodes, performing multi-node collaborative repair rather than isolated repair of a single node, ensuring that the repaired data conforms to the operational correlation rules between nodes, thereby resolving the inconsistency between correlated data nodes and individually repaired data. For example, two abnormal nodes within a distribution transformer area may be physically connected, and their operational data may exhibit a certain correlation (such as the matching relationship between total electricity consumption and individual electricity consumption). If only one node's data is repaired in isolation, it may lead to data mismatch between the two nodes. However, through collaborative repair, combining the repair stability characteristics and mutual influence strength of both nodes, the repaired data can conform to both the normal characteristics of a single node and the correlation patterns between nodes. This step solves the problem of inconsistent repair data caused by the traditional isolated single-node repair mode, ensuring the rationality and consistency of the data through collaborative repair.

[0020] In one embodiment, step S2, which involves obtaining a power metering knowledge graph based on the power metering structured data and obtaining static anomaly feature vectors and topological structures based on the power metering knowledge graph, includes: S21. Obtain equipment ledger data, network topology connection data, and equipment attribute file data based on the structured power metering data; S22. Obtain multiple metering equipment entities, user entities, and distribution transformer area entities based on the equipment ledger data and the equipment attribute file data; S23. Based on the network topology connection data and the multiple metering device entities, obtain multiple physical connection relationships between the multiple metering device entities, obtain multiple membership relationships between the multiple metering device entities and the user entity, and obtain multiple access relationships between the multiple metering device entities and the distribution transformer area entity. S24. Construct an initial power metering knowledge graph based on multiple physical connection relationships, multiple membership relationships, and multiple access relationships, and obtain the node-edge topology structure based on the initial power metering knowledge graph, and use the topology structure as the topology structure; S25. Obtain the topological centrality and historical co-occurrence frequency of each metering device entity node in the initial power metering knowledge graph; S26. Calculate multiple static risk contribution degrees based on multiple topological centralities and multiple historical co-occurrence frequencies, and construct a static anomaly feature vector based on multiple static risk contribution degrees.

[0021] As described in steps S21-S26 above, this invention obtains equipment ledger data, network topology connection data, and equipment attribute file data based on structured energy metering data. The structured energy metering data originates from existing databases such as the power system's equipment management platform and user information management system. This data, accumulated and stored in a standardized manner over a long period, possesses the characteristics of uniform format and complete information. Equipment ledger data includes basic information such as equipment model, installation location, service life, and maintenance records. Network topology connection data records topology information such as the physical connection methods and connection ports between various metering devices. Equipment attribute file data covers attribute information such as the equipment's accuracy level, rated parameters, and manufacturer. The physical significance of this step lies in filtering out core data directly related to topology construction and static risk analysis from massive amounts of structured data, laying the foundation for subsequent entity identification and relationship analysis. For example, if a batch of smart meters are added to a certain area, their equipment ledger data and attribute file data will be entered into the system. This step can extract this data to provide data support for the subsequent construction of the power metering knowledge graph of the area. If this data screening step is missing, the subsequent analysis will face the problems of data redundancy and the obscuring of core information, affecting the efficiency and accuracy of the graph construction. Multiple metering equipment entities, user entities, and distribution transformer area entities are obtained based on equipment ledger data and equipment attribute file data. The entity identification process employs a hybrid recognition algorithm based on rules and a dictionary. First, an entity dictionary for the power industry is constructed, including common metering equipment models, user identification formats, and distribution transformer area numbering rules. Then, through rule matching, entity information conforming to the dictionary rules and format requirements is extracted from the equipment ledger data and equipment attribute file data. For example, the metering equipment entity "smart meter with model number DTZY108-Z" is identified from the equipment ledger data; the user entity "residential user with user number 10001" is identified from the user file data; and the distribution transformer area entity "distribution transformer area with distribution area number TQ-023" is identified from the distribution transformer area information. The physical significance of this step lies in abstracting the core objects in the structured data into entities, providing specific analytical objects for subsequent analysis of the relationships between entities. Entities are the basic units for constructing a knowledge graph; only by clarifying each entity can the relationships between entities be further explored, effectively ensuring the pertinence and effectiveness of subsequent relationship analysis. Based on network topology connection data and multiple metering device entities, obtain multiple physical connection relationships between multiple metering device entities, obtain multiple affiliation relationships between multiple metering device entities and user entities, and obtain multiple access relationships between multiple metering device entities and distribution transformer area entities. The extraction of physical connection relationships is based on port connection records and line routing information in network topology connection data. By analyzing data such as device connection port numbers and line identifiers, the direct or indirect connection relationships between metering devices are determined, for example, "port 1 of smart meter A is directly connected to port 3 of concentrator B." The extraction of affiliation relationships involves matching the installation location of the metering device entity, user affiliation information, and user entity identification information to determine which user a particular metering device belongs to, for example, "smart meter C is installed in user 10001's residence and belongs to user 10001." The extraction of access relationships is based on the access point information of the metering device and the coverage data of the distribution transformer area to determine which distribution transformer area the metering device is connected to, for example, "the access point of smart meter D is the outgoing end of distribution transformer area TQ-023, and it is connected to distribution transformer area TQ-023." The physical significance of this step lies in sorting out the core relationships between entities. These relationships are the key links in constructing the power metering knowledge graph, reflecting the actual operating architecture of the power metering system. For example, by sorting out the connection relationship between distribution transformer areas and metering equipment, the power supply range and the number of metering equipment covered by the distribution transformer area can be clearly defined. If a fault occurs in a distribution transformer area, all the metering equipment covered by it can be quickly located, providing a basis for subsequent anomaly propagation path analysis. This step solves the problem of scattered entity relationships in structured data that are difficult to intuitively represent. An initial power metering knowledge graph is constructed based on multiple physical connections, membership relationships, and access relationships. The node-edge topological relationship structure is then obtained from this initial knowledge graph and used as the topological structure. The initial power metering knowledge graph is constructed using a graph database storage architecture. Metering equipment entities, user entities, and distribution transformer substations are used as nodes in the graph, and physical connections, membership relationships, and access relationships are used as edges between nodes. Through the associative storage function of the graph database, a visualized knowledge graph network is formed. For example, distribution transformer substation TQ-023 is used as the core node, and its edges connect to all metering equipment nodes connected to this substation. Each metering equipment node is then connected to its corresponding user node through edges, forming a complete "distribution transformer substation-metering equipment-user" association network. The extraction of the topological relationship structure involves traversing the nodes and edges in the graph database, recording information such as the connection method, number of connections, and hierarchical relationships of the nodes, forming structured topological relationship data. The physical significance of this step lies in transforming entities and relationships into a structured graph model and topology, intuitively presenting the interconnected architecture of the power metering system, and providing a topological foundation for subsequent static risk feature extraction and anomaly propagation path analysis. For example, the topological relationship structure clearly shows the position of a metering device in the entire system. If it is located at the connection hub of multiple devices, then the impact of its anomaly on the system will be greater. This step realizes the transformation from "entity-relationship" to "graph-topology," solving the problem that traditional methods are unable to intuitively represent the interconnected architecture of the system. The topological centrality and historical co-occurrence frequency of each metering device entity node in the initial power metering knowledge graph are obtained. Topological centrality is calculated using the degree centrality algorithm, counting the number of connecting edges for each metering device entity node in the graph. A higher number of connecting edges results in higher topological centrality; for example, a concentrator node connected to 20 smart meter nodes has a much higher topological centrality than a node connected to only one smart meter. Historical co-occurrence frequency is obtained by querying the power system's historical anomaly record database, counting the number of times each metering device entity and other device entities simultaneously exhibited anomalies within the same time period. For example, metering device E exhibited anomalies 3 times simultaneously with metering device F and 2 times simultaneously with metering device G in the past year, for a total historical co-occurrence frequency of 5 times. The physical significance of this step lies in extracting the static topological features and historical associated anomaly features of each metering device entity node. These features are crucial for assessing the static anomaly risk of the equipment. For example, devices with high topological centrality play important roles in the system, such as data transmission and signal forwarding. Their failures have a wider impact and are considered high-risk nodes. Devices with high historical co-occurrence frequency indicate that they have a strong correlation with the operating status of other devices and may have common causes of failure. They are also considered high-risk nodes that require special attention. This step provides core parameters for the subsequent calculation of static risk contribution. Multiple static risk contribution values ​​are calculated based on multiple topological centrality values ​​and multiple historical co-occurrence frequencies, and a static anomaly feature vector is constructed based on these static risk contribution values. The static risk contribution value is calculated using a weighted summation algorithm. First, the weight coefficients of topological centrality and historical co-occurrence frequency are determined using the analytic hierarchy process (AHP). Assuming the weight of topological centrality is 0.6 and the weight of historical co-occurrence frequency is 0.4, and the standardized value of the topological centrality of a certain metering equipment node is 0.8 and the standardized value of its historical co-occurrence frequency is 0.6, then its static risk contribution value is 0.8 × 0.6 + 0.6 × 0.4 = 0.72. The construction of the static anomaly feature vector involves arranging the static risk contribution values ​​of all metering equipment entity nodes in a preset order to form a one-dimensional vector. Each element of the vector corresponds to the static risk contribution value of a metering equipment node. The physical significance of this step is to quantify the static characteristics of each metering equipment node into a risk contribution value and integrate them into a unified feature vector, providing standardized static risk input for subsequent comprehensive anomaly feature judgment. For example, in subsequent anomaly detection, by combining dynamic operating characteristics, if a node has a high static risk contribution and abnormal dynamic operating characteristics, its comprehensive anomaly characteristic value will increase significantly, thereby improving the accuracy of anomaly detection. This step solves the problem of traditional methods lacking standardized static risk feature inputs and realizes the quantification and integration of static risk features.

[0022] In one embodiment, step S3, which involves obtaining multiple undetermined anomaly feature values ​​of multiple nodes based on the topology and the power metering time-series operation data, and obtaining multiple comprehensive undetermined anomaly feature values ​​based on the multiple undetermined anomaly feature values ​​and the static anomaly feature vector, includes: S31. Obtain the power metering time sequence operation sequence under a preset continuous timestamp based on the power metering time sequence operation data; S32. Obtain a topological relationship chain based on the topological structure, and obtain multiple first metering device entities in the topological relationship chain based on the topological relationship chain, and obtain the multi-dimensional operating characteristics of each first metering device entity within a preset time window, wherein the multi-dimensional operating characteristics include frequency domain characteristics and time-series morphological characteristics. S33. Obtain multiple operating feature vectors based on the power metering time-series operation sequence, multiple frequency domain features, and multiple time-series morphological features; S34. Obtain the abnormal undetermined feature value of each node based on the multiple running feature vectors; S35. Obtain the cumulative abnormal deviation area and abnormal evolution trend feature value of each node within a preset time window based on each of the aforementioned undetermined abnormal feature values; S36. Obtain the topological neighborhood area corresponding to each node according to the topological structure, and obtain the spatiotemporal anomaly diffusion intensity of each node according to the topological neighborhood area and the cumulative anomaly deviation area; S37. Obtain the spatiotemporal anomaly intensity of each node based on the anomaly evolution trend characteristic value and the spatiotemporal anomaly diffusion intensity of each node; S38. Obtain multiple historical health feature values ​​corresponding to each identical node within a historical normal period, and obtain the historical health benchmark of the corresponding node based on the multiple historical health feature values ​​of each node. S39. Obtain the relative deviation of the node anomaly of the corresponding node based on the spatiotemporal anomaly intensity of each node and the historical health benchmark. S310. Obtain the node dynamic anomaly comprehensive value of the corresponding node based on the relative deviation degree of the node anomaly and the spatiotemporal anomaly diffusion intensity of each node, and use multiple node dynamic anomaly comprehensive values ​​as multiple comprehensive anomaly undetermined feature values.

[0023] As described in steps S31-S310 above, this invention obtains the electricity metering time-series operation sequence under preset continuous timestamps based on the electricity metering time-series operation data. The electricity metering time-series operation data originates from real-time collection by devices such as smart meters and sensors, and is stored in the power system's time-series database in timestamp order. The preset continuous timestamps can be set according to actual monitoring needs, for example, one timestamp per minute, extracting continuous 24-hour time-series data. When obtaining the time-series operation sequence, data cleaning techniques are used to remove missing values ​​and obviously invalid data (such as negative electricity consumption data) caused by transmission interruptions during data acquisition, forming a complete, time-ordered one-dimensional data sequence. For example, the electricity consumption time-series operation sequence of a smart meter is [1.2, 1.3, 1.1, ..., 1.4] (unit: kWh). The physical significance of this step is to transform discrete time-series operation data into structured sequence data, providing a foundation for subsequent extraction of time-series features and analysis of data evolution patterns. For example, without a structured time-series sequence, it will be impossible to accurately calculate the dynamic characteristics of the data, such as fluctuation trends and abrupt changes, and it will be difficult to capture the time-series anomalies of the data. This step ensures the continuity and effectiveness of dynamic feature extraction. The topological relationship chain is obtained based on the topological structure, and multiple first metering device entities within the topological relationship chain are then identified. Simultaneously, the multi-dimensional operational characteristics of each first metering device entity within a preset time window are acquired. These multi-dimensional operational characteristics include frequency domain characteristics and time-series morphological characteristics. The topological relationship chain is obtained by traversing the previously constructed topological structure, identifying chain-like connections starting from the core device and connecting related devices as nodes. For example, starting from a distribution transformer area, all concentrators under it are connected, and then the smart meters under each concentrator are connected, forming a topological relationship chain of "distribution transformer area - concentrator - smart meter." The concentrators and smart meters in the chain are the first metering device entities. The preset time window can be set according to the data update frequency and the speed of anomaly evolution, for example, a 1-hour time window, to ensure that data change characteristics within a certain time period can be captured. Frequency domain feature extraction employs the Fast Fourier Transform (FFT) algorithm to transform time-series data from the time domain to the frequency domain, acquiring features such as frequency distribution and amplitude. For example, Fourier transform reveals that the power consumption data of a certain device exhibits fluctuations at a fixed frequency, potentially indicating a periodic fault. Time-series morphological features are obtained by calculating parameters such as the rise / fall slope, fluctuation amplitude, and number of peaks. For instance, if the voltage data shows a fall slope of 0.5 kV / h and a fluctuation amplitude of 0.8 kV over a certain period, these parameters directly reflect the morphological changes in the data. The physical significance of this step lies in combining topological correlation characteristics to selectively extract multi-dimensional dynamic features of key metering devices. This considers both the frequency regularity of the data and captures its morphological changes, providing rich dimensional support for subsequent anomaly feature quantification. For example, if a concentrator is a key node in the topological relationship chain, and its frequency domain features show abnormal frequency components while its time-series morphological features show data fluctuation amplitudes exceeding the normal range, it can be preliminarily determined that this node has an anomaly risk. This step overcomes the limitations of traditional methods that only extract single dynamic features, achieving comprehensive capture of multi-dimensional dynamic features. Multiple operational feature vectors are obtained based on the electricity metering time-series operation sequence, multiple frequency domain features, and multiple time-series morphological features. Specifically, the electricity metering time-series operation sequence, frequency domain features, and time-series morphological features are first standardized to eliminate the influence of different units. For example, electricity consumption data is converted to standardized values ​​in the [0,1] interval, and features such as frequency, amplitude, and slope are also standardized in the same way. Then, a feature concatenation method is used to combine the standardized time-series operation sequence, standardized frequency domain features, and standardized time-series morphological features of each first metering device entity in a preset order to form a one-dimensional operational feature vector. For example, the standardized time-series operation sequence of a smart meter is [0.2,0.3,...,0.25], the standardized frequency domain feature is [0.1,0.4], and the standardized time-series morphological feature is [0.3,0.2]. The resulting operational feature vector after concatenation is [0.2,0.3,...,0.25,0.1,0.4,0.3,0.2]. The physical significance of this step lies in integrating multi-dimensional and scattered feature data into a unified vector form, providing standardized input data for subsequent calculation of anomaly-determined feature values. Vector-form data facilitates mathematical operations and feature comparison, effectively integrating information from multiple aspects such as time series, frequency domain, and morphology, avoiding the limitations of single-feature analysis. For example, by running feature vectors, the differences in multi-dimensional features across different nodes can be intuitively compared, providing a more comprehensive basis for anomaly identification. The algorithm obtains the undetermined anomaly feature value for each node based on multiple operational feature vectors. The calculation of the undetermined anomaly feature value employs a distance-based anomaly detection algorithm. A normal feature vector library is constructed using the operational feature vectors of nodes of the same type within historical normal cycles. The Euclidean distance between the current node's operational feature vector and all vectors in the normal feature vector library is calculated, and the average of all Euclidean distances is used as the undetermined anomaly feature value for that node. For example, if the normal feature vector library contains operational feature vectors of 100 smart meters of the same type, and the average Euclidean distance between the current smart meter's operational feature vector and these 100 vectors is 0.6, then its undetermined anomaly feature value is 0.6. The larger this value, the greater the deviation of the current node from its normal state. The physical significance of this step lies in the preliminary quantification of the multi-dimensional features of each node, obtaining an initial index reflecting the degree of deviation of the node from its normal state, providing a foundation for subsequent more refined anomaly feature analysis. For example, the undetermined anomaly feature value can quickly filter out nodes that deviate significantly from their normal state, narrowing the scope of subsequent analysis and improving the efficiency of anomaly detection. This step achieves the initial transformation from multi-dimensional features to a single quantitative index. Based on each undetermined anomaly feature value, the cumulative anomaly deviation area and anomaly evolution trend feature value of each node within a preset time window are obtained. The cumulative anomaly deviation area is calculated by constructing a curve showing the change of the undetermined anomaly feature value over time, with the undetermined anomaly feature value at each moment within the preset time window as the vertical axis and time as the horizontal axis. The area between this curve and the normal threshold line (set based on historical data) is the cumulative anomaly deviation area. For example, within a 1-hour time window, the area enclosed by the undetermined anomaly feature value curve and the threshold line is 5.2. The larger this value, the higher the cumulative anomaly level of the node within that time window. The anomaly evolution trend feature value is calculated using a linear regression algorithm. A linear fit is performed on the undetermined anomaly feature values ​​within the preset time window to obtain the slope of the fitted line. A positive slope indicates an increasing anomaly level, while a negative slope indicates a decreasing anomaly level. The larger the absolute value of the slope, the more pronounced the trend. For example, a fitted slope of 0.3 indicates that the anomaly level of the node is continuously increasing. The physical significance of this step lies in capturing the cumulative effect and evolution trend of node anomalies over time, avoiding misjudgments caused by relying solely on the anomaly's undetermined feature value at a single moment. For example, if a node has a high anomaly's undetermined feature value at a certain moment, but the cumulative anomaly deviation area is small and the evolution trend slope is negative, it may be a temporary anomaly caused by instantaneous interference; while if a node's anomaly's undetermined feature value does not significantly exceed the threshold, but the cumulative anomaly deviation area continues to increase and the evolution trend slope is positive, it may be a potential, gradually aggravated anomaly. This step enriches the temporal dimension information of the anomaly features. The topological neighborhood area of ​​each node is obtained based on the topological structure, and the spatiotemporal anomaly diffusion intensity of each node is obtained based on the topological neighborhood area and the cumulative anomaly deviation area. The topological neighborhood area is obtained by determining the number of directly and indirectly associated nodes for each node through the topological structure. For example, if a concentrator directly connects to 20 smart meters, and each smart meter has no other associated nodes, then the topological neighborhood area of ​​this concentrator is 21 (including itself); if a smart meter is directly associated with 1 concentrator and 2 adjacent smart meters, then its topological neighborhood area is 4. The spatiotemporal anomaly diffusion intensity is calculated using a weighted product algorithm, multiplying the cumulative anomaly deviation area by the standardized value of the topological neighborhood area, i.e., spatiotemporal anomaly diffusion intensity = standardized value of cumulative anomaly deviation area × standardized value of topological neighborhood area. For example, if the standardized value of a node's cumulative anomaly deviation area is 0.7 and its standardized value of the topological neighborhood area is 0.8, then its spatiotemporal anomaly diffusion intensity is 0.56. The physical significance of this step lies in fusing the temporal cumulative characteristics and spatial diffusion potential of anomalies, quantifying the potential impact of anomalies on surrounding associated nodes. For example, core nodes with large topological neighborhood areas have a wider range of anomaly spread, and even if the current cumulative anomaly deviation area is not large, there may still be a significant risk; while edge nodes with small topological neighborhood areas have limited impact of anomaly spread. This step achieves spatiotemporal dimensional fusion of anomaly features and solves the problem of traditional methods ignoring spatial correlation characteristics. The spatiotemporal anomaly intensity of each node is obtained based on its anomaly evolution trend characteristic value and spatiotemporal anomaly diffusion intensity. The calculation of the node's spatiotemporal anomaly intensity employs a weighted summation algorithm. The weight coefficients for the anomaly evolution trend characteristic value and the spatiotemporal anomaly diffusion intensity are determined using the analytic hierarchy process (AHP). Assuming the weight of the anomaly evolution trend characteristic value is 0.4, the weight of the spatiotemporal anomaly diffusion intensity is 0.6, the standardized value of a node's anomaly evolution trend characteristic value is 0.6, and the standardized value of its spatiotemporal anomaly diffusion intensity is 0.5, then its node spatiotemporal anomaly intensity is 0.6 × 0.4 + 0.5 × 0.6 = 0.54. The physical significance of this step lies in integrating the anomaly's temporal evolution trend and spatiotemporal diffusion intensity into a comprehensive index, fully reflecting the comprehensive intensity of the node's anomaly in the spatiotemporal dimension. For example, if the abnormal evolution trend of a node is upward (with a positive characteristic value) and the spatiotemporal anomaly diffusion intensity is high, the spatiotemporal anomaly intensity of the node will increase significantly, indicating that the anomaly of the node is not only continuously aggravated, but may also affect surrounding nodes, which is a high-risk anomaly; while if the abnormal evolution trend of a node is downward and the spatiotemporal anomaly diffusion intensity is low, the spatiotemporal anomaly intensity of the node is small, and the risk is relatively low. This step realizes the comprehensive quantification of spatiotemporal dimension anomaly characteristics. Multiple historical health feature values ​​are obtained for each identical node within a historical normal cycle, and a historical health benchmark for the corresponding node is derived based on these values. The historical normal cycle can be determined according to user electricity consumption patterns and equipment operating cycles. For example, the historical normal cycle for residential users is set to the non-holiday period of the past 12 months, and for industrial users, it is set to the normal production period of the past 6 months. The historical health feature value refers to the spatiotemporal anomaly intensity of the node corresponding to that node within a historical normal cycle (this is a calculated value under normal conditions, typically at a low level). The spatiotemporal anomaly intensity of the node within multiple historical normal cycles is obtained by querying the historical data repository of the power system as the historical health feature value. The historical health benchmark is calculated using a statistical averaging method, taking the average of multiple historical health feature values ​​as the historical health benchmark for that node. For example, if the historical health feature values ​​of a residential user's smart meter within five historical normal cycles are 0.1, 0.12, 0.08, 0.11, and 0.09, then its historical health benchmark is 0.1. The physical significance of this step lies in establishing a personalized normal state benchmark for each node, taking into account the individual differences of different nodes, and avoiding misjudgments caused by using a uniform standard. For example, the electricity load of an industrial user fluctuates greatly, and its historical health benchmark may be higher than that of ordinary residential users. If a uniform benchmark is used for judgment, its normal fluctuations may be misjudged as abnormal. However, a personalized historical health benchmark can better reflect the actual normal operating state of the node and improve the accuracy of anomaly judgment. The relative deviation of a node's anomaly is obtained based on the spatiotemporal anomaly intensity and historical health benchmark of each node. The relative deviation is calculated using the relative deviation formula: Relative Deviation = (Spatiotemporal Anomaly Intensity - Historical Health Benchmark) / Historical Health Benchmark. For example, if a node's spatiotemporal anomaly intensity is 0.3 and its historical health benchmark is 0.1, its relative deviation is 2.0. A positive value indicates that the current anomaly intensity exceeds the historical health benchmark; a larger value indicates a greater deviation. A negative value indicates that the current state is better than the historical normal benchmark and falls within the normal range. The physical significance of this step lies in quantifying the degree of deviation of the current node's anomaly intensity relative to its own historical normal state, highlighting the impact of individual node differences on anomaly judgment. For example, if the spatiotemporal anomaly intensity of two nodes is 0.2, and the historical health baseline of one node is 0.1 with a relative deviation of 1.0, while the historical health baseline of the other node is 0.05 with a relative deviation of 3.0, it is clear that the latter has a more severe anomaly deviation. If a uniform standard is used, this difference cannot be distinguished. This step solves the problem of traditional methods ignoring individual differences of nodes, making anomaly judgment more targeted. The dynamic anomaly comprehensive value of each node is obtained based on its relative deviation from the node anomaly and its spatiotemporal anomaly propagation intensity. Multiple dynamic anomaly comprehensive values ​​are then used as multiple comprehensive anomaly undetermined feature values. The calculation of the node dynamic anomaly comprehensive value employs a weighted product algorithm, multiplying the standardized value of the relative deviation from the node anomaly by the standardized value of the spatiotemporal anomaly propagation intensity. For example, if a node's standardized relative deviation from the node anomaly is 0.8 and its standardized spatiotemporal anomaly propagation intensity is 0.7, then its dynamic anomaly comprehensive value is 0.56. The physical significance of this step lies in integrating the node's own relative deviation from the anomaly and the spatiotemporal propagation risk of the anomaly to form a final quantitative indicator that comprehensively reflects the degree of node anomaly. For example, if a node has a high relative deviation from the node anomaly but a low spatiotemporal anomaly propagation intensity, it indicates that its own anomaly is severe but its impact range is limited; while if a node has both a high relative deviation from the node anomaly and a high spatiotemporal anomaly propagation intensity, it indicates that it not only has its own severe anomaly but may also trigger large-scale anomaly propagation, making it a high-priority anomaly node. This step provides a comprehensive and scientific quantitative basis for the subsequent determination of anomaly location nodes.

[0024] In one embodiment, step S5, which involves obtaining root cause diagnostic data for multiple nodes based on multiple abnormal location nodes, includes: S51. Obtain the topological association relationship between the abnormal location nodes based on the multiple abnormal location nodes, wherein the topological association relationship includes at least one abnormal propagation path of at least one of the abnormal location nodes. S52. Obtain the time sequence data of the running status of each node in each of the abnormal propagation paths within a preset historical time period; S53. Obtain the spatiotemporal impact intensity of the corresponding node based on the time-series data of the running status of each node and the anomaly propagation path; S54. Obtain the abnormal duration and abnormal mutation magnitude of each abnormal location node; S55. Obtain the node abnormality attribute value of the corresponding node based on the abnormal duration and abnormal mutation amplitude of each abnormal location node. S56. Obtain the comprehensive weight of node anomalies for each node based on the spatiotemporal influence intensity and the node anomaly attribute value of each node at the anomaly location. S57. Obtain the root cause node of the corresponding path based on the comprehensive weight of the node anomalies of all nodes on each abnormal propagation path, and use the identifier of each root cause node and its corresponding comprehensive weight of the node anomalies as the root cause diagnosis data of the node.

[0025] As described in steps S51-S57 above, this invention obtains the topological relationships between multiple abnormal location nodes, wherein the topological relationships include at least one abnormal propagation path for at least one abnormal location node. An abnormal location node is the node whose comprehensive abnormal undetermined characteristic value exceeds the abnormal threshold in the preceding steps. Its topological relationships are obtained based on the topological structure constructed earlier. By traversing the connection relationships of abnormal location nodes in the topological structure, direct or indirect connection paths between nodes are identified. For example, if abnormal location node A (concentrator) has a direct physical connection with abnormal location nodes B, C, and D (smart meters), and abnormal location node D has an indirect connection with abnormal location node E (another smart meter), then the topological relationships include abnormal propagation paths such as "AB," "AC," and "ADE." The physical significance of this step is to clarify the propagation path of the abnormality in the topological structure, providing a path basis for subsequent root cause tracing. Without identifying the abnormal propagation paths, it is impossible to determine whether the abnormality is caused by a single node or multiple independent abnormalities superimposed, resulting in a lack of direction in root cause diagnosis. This step, through path identification, connects the scattered abnormal location nodes to form a logical abnormal propagation network. Acquire the operational status time-series data of each node in each anomaly propagation path within a preset historical time period. The preset historical time period can be set according to the duration of the anomaly and the data update frequency, for example, from 24 hours before the anomaly occurred to the current moment of the anomaly, ensuring that it can cover the complete state changes before and after the anomaly occurred. The operational status time-series data comes from the power system's time-series database and includes dynamic data such as the node's electricity consumption, voltage, current, and data transmission status. This data is collected and stored in real time by devices such as smart meters and sensors. For example, for the "ADE" path, it is necessary to acquire the voltage data time-series sequence and data transmission success rate time-series sequence of nodes A, D, and E every minute within the preset historical time period. The physical significance of this step is to acquire the state change data of each node during the anomaly propagation process, providing data support for analyzing the role of nodes in anomaly propagation. For example, if node A experiences a sudden change in voltage data before the anomaly occurs, and subsequently nodes D and E experience voltage anomalies, then node A is likely the source of the anomaly. This step provides a key time-series data foundation for subsequent quantitative analysis. The spatiotemporal impact intensity of each node is obtained based on the time-series data of its operational status and the anomaly propagation path. The calculation of spatiotemporal impact intensity combines characteristics of both time and space dimensions. In the time dimension, the temporal priority of a node in the propagation path is determined by analyzing the chronological order of anomaly occurrences; the node with the earliest anomaly occurrence has the highest temporal priority. In the spatial dimension, the influence range of a node is determined based on its position in the topology; for example, the influence range of the starting node covers the entire path, and the influence range of an intermediate node covers its subsequent nodes. The specific algorithm is: Spatiotemporal Impact Intensity = Temporal Priority Weight × Time Impact Factor + Spatial Impact Range Weight × Spatial Impact Factor. The temporal priority weight and spatial impact range weight are determined using the analytic hierarchy process (AHP), assumed to be 0.6 and 0.4 respectively. If a node has a time impact factor of 0.8 (earliest anomaly occurrence) and a spatial impact factor of 0.9 (influence range covers the entire path), then its spatiotemporal impact intensity = 0.6 × 0.8 + 0.4 × 0.9 = 0.84. The physical significance of this step lies in quantifying the spatiotemporal influence of a node on other nodes during anomaly propagation. The higher the spatiotemporal influence intensity, the more central and dominant the node is in the path, and the more likely it is to be the root cause node. For example, if the spatiotemporal influence intensity of node X in a certain path is 0.9, which is much higher than the 0.3-0.5 of other nodes, then node X plays a key role in promoting the anomaly propagation of the entire path. This step achieves a quantitative assessment of the node's influence. The process involves obtaining the duration and magnitude of anomalies at each node. The duration is determined by analyzing time-series data of the node's operational status, spanning from the first occurrence of an anomaly to the current time. For example, if node B experiences anomalies in electricity consumption data starting at 10:00 and the current time is 12:30, the duration is 2.5 hours. The magnitude of the anomalous change is calculated by selecting a baseline value (determined based on historical normal cycle data) for the node's normal operating conditions and calculating the relative deviation between the data at the time of the anomaly and the baseline value. The formula is: Anomalous Change Amplitude = |Initial Anomaly Value - Baseline Value| / Baseline Value. For example, if the normal baseline voltage value for node C is 220V and the initial anomaly value is 180V, then the anomalous change amplitude = |180 - 220| / 220 ≈ 0.18. The physical significance of this step lies in capturing the key attributes of node anomalies. The longer the duration and the greater the magnitude of the anomaly, the more severe the node's anomaly, and the higher its likelihood of being the root cause node. For example, if the anomaly duration of a certain node reaches 8 hours and the anomalous change amplitude is 0.3, which is much higher than the 1-2 hours and 0.05-0.1 of other nodes, then the degree of anomaly of this node is more serious and it is more likely to be the root cause of the chain of anomalies. This step provides the core parameters for the calculation of the subsequent node anomaly attribute values. The node anomaly attribute value is obtained based on the anomaly duration and anomalous mutation amplitude of each node at an anomaly location. The calculation of the node anomaly attribute value uses a weighted product algorithm. First, the anomaly duration and anomalous mutation amplitude are standardized (converted to values ​​within the [0,1] interval). Then, the weights of the two are determined using the analytic hierarchy process (AHP). Assuming the weight of the anomaly duration is 0.3 and the weight of the anomalous mutation amplitude is 0.7, and a node's standardized anomaly duration is 0.6 and its standardized anomalous mutation amplitude is 0.8, then its node anomaly attribute value = 0.6 × 0.3 × 0.8 × 0.7 + (0.6 × 0.3 + 0.8 × 0.7) × 0.5 (introducing a cross term to reflect the synergistic effect of the two) = 0.73. The physical significance of this step is to integrate the two single attributes of anomaly duration and mutation amplitude into a comprehensive indicator reflecting the severity of node anomalies, avoiding the one-sidedness of single-attribute analysis. For example, if a node has an abnormality that lasts for a long time but has a small mutation magnitude, it may be a minor but persistent abnormality; if another node has a large mutation magnitude but a short duration, it may be a severe but transient abnormality. By calculating the abnormality attribute values ​​of nodes, the severity of the abnormalities of the two can be comprehensively measured, providing a basis for subsequent weight calculations. The comprehensive weight of a node's anomaly is obtained based on the spatiotemporal influence intensity and the node's anomaly attribute value at each anomaly location. The calculation of the comprehensive weight uses a weighted summation algorithm, with weight coefficients determined using the entropy weight method. These coefficients are automatically assigned based on the inherent dispersion of the data, avoiding the influence of subjective factors. Assuming the weight of spatiotemporal influence intensity is 0.55 and the weight of node anomaly attribute value is 0.45, and a node has a spatiotemporal influence intensity of 0.8 and an anomaly attribute value of 0.7, then its comprehensive weight = 0.8 × 0.55 + 0.7 × 0.45 = 0.755. The physical significance of this step lies in integrating the node's influence intensity in anomaly propagation with its own anomaly severity to form a comprehensive indicator that fully reflects the node's importance in the anomaly event. For example, a node with high spatiotemporal influence intensity but low anomaly attribute value may be a "transfer station" in anomaly propagation rather than the root cause; a node with both high spatiotemporal influence intensity and high anomaly attribute value is highly likely to be the source of the anomaly. This step, through comprehensive weight calculation, achieves precise positioning of the node's role. The root cause node for each anomaly propagation path is determined by the comprehensive weight of all nodes' anomalies. The identifier of each root cause node and its corresponding comprehensive weight are used as the root cause diagnostic data. The root cause node is selected by choosing the node with the highest comprehensive weight on each path. If there are nodes with the same weight, the node with the earliest anomaly occurrence time is selected as the root cause node. For example, in the "ADE" path, node A has a comprehensive weight of 0.85, node D has 0.5, and node E has 0.3, so node A is the root cause node for that path. In the "FG" path, nodes F and G both have a weight of 0.6, but node F's anomaly occurred earlier, so node F is the root cause node. The identifier of the root cause node includes unique identification information such as the node's device number and installation location, which, together with the corresponding comprehensive weight, constitutes the root cause diagnostic data. The physical significance of this step is to ultimately pinpoint the root cause of the anomaly, providing a clear target for subsequent repair work and avoiding blind repair efforts. For example, if the root cause is diagnosed as a transmission module failure in a concentrator, the concentrator can be repaired specifically instead of all the meters connected to it one by one, which greatly improves the repair efficiency. This step realizes a closed loop from anomaly propagation analysis to root cause location.

[0026] In one embodiment, step S5, which involves performing tensor decomposition on the root cause diagnostic data of multiple nodes and their corresponding associated nodes to obtain multiple tensor decomposed data, includes: S58. For each node root cause diagnosis data corresponding to the abnormal location node, obtain the dimension weights of multiple data dimensions in the node root cause diagnosis data. S59. The node root cause diagnosis data is weighted according to the dimension weights of the multiple data dimensions to obtain weighted node root cause diagnosis data. S510. Obtain the preset normal data corresponding to the abnormal location node within the historical normal period; S511. Extract multiple historical normal principal component features from the preset normal data, and obtain the average value of the historical normal principal component features of the abnormal location node based on the multiple historical normal principal component features. S512. Extract multiple abnormal principal component features from the weighted root cause diagnosis data of the nodes, and obtain the mean value of the current abnormal principal component features of the nodes at the abnormal locations based on the multiple abnormal principal component features. S513. Based on the historical normal principal component feature mean and the current abnormal principal component feature mean, obtain the feature deviation of the abnormal position node; S514. The weighted node root cause diagnosis data, the feature deviation and the preset normal data are combined to construct a node repair feature tensor; S515. Perform tensor decomposition on the node repair feature tensor to obtain multiple core feature sub-tensors, and use the multiple core feature sub-tensors as multiple tensor decomposition data.

[0027] As described in steps S58-S515 above, this invention obtains the dimensional weights of multiple data dimensions in the root cause diagnosis data corresponding to each abnormal location node. The root cause diagnosis data is the data obtained in the preceding steps, containing the root cause node identifier and its corresponding node anomaly comprehensive weight. Its data dimensions include the root cause node identifier dimension, the node anomaly comprehensive weight dimension, and the anomaly propagation path dimension. The dimensional weights are obtained using the entropy weight method, which determines the weight by calculating the information entropy of each data dimension. The smaller the information entropy, the greater the data dispersion of that dimension and the more effective information it contains, resulting in a higher weight. For example, the node anomaly comprehensive weight dimension has a large data dispersion (significant differences in the anomaly comprehensive weights of nodes at different abnormal locations) and a small information entropy, so its dimensional weight might be set to 0.6; the root cause node identifier dimension has a small data dispersion and a large information entropy, so its dimensional weight might be set to 0.3; and the anomaly propagation path dimension has a weight of 0.1. The physical significance of this step is to highlight data dimensions that are more valuable for repair, reduce the impact of redundant dimensions, and improve the targeting of subsequent data processing. For example, the comprehensive weight of node anomalies directly reflects the degree of influence of the root cause node on the current abnormal location node. Giving it a higher weight can make subsequent repairs more focused on the core influencing factors. This step lays the foundation for the effective use of root cause diagnostic data. The root cause diagnosis data of nodes is weighted according to the dimensional weights of multiple data dimensions to obtain weighted root cause diagnosis data. The specific weighting method is as follows: the original data of each data dimension is multiplied by its corresponding dimensional weight, and then the weighted results of each dimension are combined in a preset order to form the weighted data. For example, in the root cause diagnosis data of a node at an abnormal location, the quantized value corresponding to the root cause node identifier is 5 (assuming the root cause node identifier is quantized according to preset rules), the dimensional weight is 0.3, the node anomaly comprehensive weight is 0.8, the dimensional weight is 0.6, and the quantized value corresponding to the anomaly propagation path is 3 (assuming the propagation path is quantized according to complexity), the dimensional weight is 0.1. Then the weighted root cause diagnosis data of the node is [5×0.3,0.8×0.6,3×0.1]=[1.5,0.48,0.3]. The physical significance of this step is to strengthen the influence of key dimensions and weaken the interference of secondary dimensions through weight allocation, so that the weighted data can better reflect the core information needed for repair. For example, through weighted processing, the impact of the key dimension of the comprehensive weight of node anomalies is highlighted, and subsequent analysis will focus more on the degree of anomaly of the root cause node on the current node, improving the targeting of the repair. This step realizes the optimized processing of root cause diagnosis data.

[0028] Obtain the preset normal data corresponding to the abnormal location node within the historical normal cycle. The setting of the historical normal cycle is consistent with the previous section and can be determined according to the node type and operating patterns. For example, the historical normal cycle for residential user nodes is set to the non-holiday period of the past 12 months, and the historical normal cycle for industrial user nodes is set to the normal production period of the past 6 months. The preset normal data refers to the operating data of the abnormal location node within the historical normal cycle, including historical electricity consumption, voltage, current, and other time-series operating data. This data comes from the historical data repository of the power system. By querying the equipment number of the abnormal location node, its relevant operating data within the historical normal cycle is extracted. The physical significance of this step is to obtain reference data under the normal operating state of the node, providing a benchmark for subsequent comparative analysis of abnormal characteristics. For example, without preset normal data, it is impossible to determine whether the characteristics of the current node are abnormal and to what extent, and subsequent calculation of characteristic deviation is also impossible. This step provides a necessary reference basis for the quantitative analysis of abnormal characteristics.

[0029] Multiple historical normal principal component features are extracted from preset normal data, and the mean of these features for nodes at anomaly locations is obtained. Principal component feature extraction employs Principal Component Analysis (PCA) algorithm. This involves dimensionality reduction of the preset normal data to extract a few principal components that reflect the main information of the data. Specifically, the preset normal data is first standardized to eliminate the influence of dimensions. Then, the covariance matrix of the data is calculated, and the eigenvalues ​​and eigenvectors of the covariance matrix are solved. Eigenvectors with eigenvalues ​​greater than a preset threshold (e.g., 1.0) are selected as principal component eigenvectors. The standardized preset normal data is multiplied by the principal component eigenvectors to obtain the historical normal principal component features. The mean of the historical normal principal component features is calculated by taking the arithmetic mean of the extracted features. For example, performing principal component analysis on preset normal electricity consumption data for a node at an abnormal location extracts two principal component features with values ​​of [2.1, 1.8, ..., 2.0] and [0.5, 0.6, ..., 0.4]. The corresponding historical normal principal component feature means are 1.97 and 0.5, respectively. The physical significance of this step lies in condensing the core features of the preset normal data, using a few principal component features to represent the main information of the node's normal operating status, reducing the complexity of subsequent calculations. Simultaneously, the historical normal principal component feature means provide a concise and accurate benchmark value for subsequent comparison with abnormal features. This step achieves effective extraction and condensation of normal data features.

[0030] Multiple anomalous principal component features are extracted from the weighted root cause diagnosis data, and the mean of the current anomalous principal component features for nodes at anomalous locations is obtained based on these features. The extraction of anomalous principal component features also employs principal component analysis (PCA) algorithms, consistent with the extraction process of historical normal principal component features. First, the weighted root cause diagnosis data is standardized. Then, the covariance matrix is ​​calculated, eigenvalues ​​and eigenvectors are solved, and principal component eigenvectors are selected to finally obtain the anomalous principal component features. The mean of the current anomalous principal component features is the arithmetic mean of these features. For example, performing PCA on the weighted root cause diagnosis data for a node at anomalous location yields two anomalous principal component features with values ​​[3.5, 3.3, ..., 3.4] and [1.2, 1.3, ..., 1.1], respectively. The corresponding mean values ​​of the current anomalous principal component features are 3.4 and 1.2. The physical significance of this step lies in condensing the core anomalous features in the weighted root cause diagnosis data, providing a basis for comparison with normal principal component features. Principal component analysis can extract the features that best reflect the nature of the abnormality from the weighted root cause diagnosis data, avoiding interference from redundant information. This step achieves effective extraction and condensation of abnormal data features.

[0031] The feature deviation of nodes at abnormal locations is obtained based on the historical mean of normal principal component features and the current mean of abnormal principal component features. The feature deviation is calculated using the Euclidean distance formula: Feature Deviation = √[(Historical mean of normal principal component features 1 - Current mean of abnormal principal component features 1)² + (Historical mean of normal principal component features 2 - Current mean of abnormal principal component features 2)² + ... + (Historical mean of normal principal component features n - Current mean of abnormal principal component features n)²], where n is the number of extracted principal component features. For example, if the historical mean of normal principal component features for a node at an abnormal location is [1.97, 0.5] and the current mean of abnormal principal component features is [3.4, 1.2], then its feature deviation = √[(1.97 - 3.4)² + (0.5 - 1.2)²] ≈ √[2.04 + 0.49] ≈ 1.59. The physical significance of this step lies in quantifying the degree of deviation between the abnormal principal component features and the normal principal component features. The greater the feature deviation, the more significant the difference between the abnormal features and normal features of the current node, and the greater the necessity and difficulty of repair. For example, a node with a feature deviation of 1.59 has obvious differences between its abnormal features and normal features and needs to be repaired in a focused manner; while a node with a smaller feature deviation may only have minor anomalies, and the repair scope can be appropriately reduced. This step provides a quantitative basis for deviation for subsequent repairs.

[0032] The weighted root cause diagnostic data, feature deviation, and preset normal data are combined to construct a node repair feature tensor. The combination method is as follows: the weighted root cause diagnostic data is used as the first dimension of the tensor, the feature deviation as the second dimension, and the preset normal data as the third dimension. These three are combined in dimensional order to form a three-dimensional tensor. For example, if the weighted root cause diagnostic data is a 1×m vector (m is the number of data dimensions), the feature deviation is a 1×1 numerical value, and the preset normal data is a t×k matrix (t is the time series length, k is the number of data types), then the constructed node repair feature tensor is an m×1×(t×k) three-dimensional tensor. The physical significance of this step is to fuse root cause diagnostic information, deviation information, and normal reference information into a structured tensor data, comprehensively integrating various key information required for repair. The tensor structure can preserve the multidimensional correlation characteristics of the data, avoid information loss, and provide a complete data foundation for subsequent tensor decomposition and extraction of core features. This step achieves deep fusion of repair-related information.

[0033] Tensor decomposition is performed on the node repair feature tensor to obtain multiple core feature sub-tensors, which are then used as multiple tensor decomposition data. The Tucker decomposition algorithm is employed to decompose the node repair feature tensor into a core tensor and three factor matrices. By adjusting the rank of the core tensor (set according to data complexity and repair accuracy requirements, e.g., 3), the core feature sub-tensors that represent the main information of the original tensor are extracted. For example, performing Tucker decomposition on an m×1×(t×k) node repair feature tensor yields a core tensor G (3×3×3) and factor matrices A (m×3), B (1×3), and C ((t×k)×3). The product of the core tensor G and factor matrices A, B, and C can approximately reconstruct the original tensor, where the core tensor G and the key sub-matrices in the factor matrices are the core feature sub-tensors. The physical significance of this step lies in separating the core features from redundant information in the original tensor and extracting the key features most valuable for repair. Tensor decomposition removes noise and redundancy from the data, focusing on the core information in root cause diagnosis, feature deviation, and normal reference. This allows subsequent repair to be precisely applied to the abnormal features while preserving normal features. This step achieves accurate extraction of core repair features.

[0034] In one embodiment, step S6, which involves collaboratively repairing multiple tensor decomposition data to obtain a collaborative repair result, includes: S61. For the tensor decomposition data corresponding to each abnormal location node, obtain the repair stability features in multiple core feature sub-tensors, and obtain the node repair stability vector of the corresponding node according to the repair stability features of each core feature sub-tensor. S62. Obtain the connection relationship between the nodes at the abnormal locations based on the topology, and obtain the repair influence intensity between nodes based on the connection relationship and multiple node repair stability vectors; S63. Construct a collaborative repair feature matrix based on the multiple node repair stability vectors and the repair influence intensity between the nodes; S64. Obtain the collaborative historical normal data corresponding to the abnormal location node within the historical normal period, and obtain the collaborative health benchmark based on the collaborative historical normal data; S65. Calculate the collaborative repair confidence level based on the collaborative repair feature matrix and the collaborative health benchmark, and use the collaborative repair confidence level as the collaborative repair result.

[0035] As described in steps S61-S65 above, this invention obtains the repair stability features from multiple core feature sub-tensors of the tensor decomposition data corresponding to each abnormal location node, and obtains the node repair stability vector of the corresponding node based on the repair stability features of each core feature sub-tensor. The tensor decomposition data refers to the core feature sub-tensors obtained by Tucker decomposition in the previous steps, which contain the core feature information required for node repair. The repair stability features are obtained by analyzing the fluctuation of the core feature sub-tensors in different repair iterations. The smaller the fluctuation, the more stable the repair result corresponding to the feature. For example, if the values ​​of a certain core feature sub-tensor in 5 repair iterations are [2.1, 2.08, 2.12, 2.09, 2.11], the fluctuation is small, and its repair stability feature value is high; if the value is [2.1, 1.8, 2.3, 1.9, 2.4], the fluctuation is large, and the repair stability feature value is low. The construction of the node repair stability vector involves arranging the repair stability feature values ​​corresponding to each core feature sub-tensor in a preset order to form a one-dimensional vector. For example, if a node has three core feature sub-tensors with repair stability feature values ​​of 0.85, 0.78, and 0.92, then the node repair stability vector is [0.85, 0.78, 0.92]. The physical significance of this step lies in quantifying the stability of the self-repair of each node at an anomaly location, providing a foundation for subsequent analysis of the repair impact between nodes. Nodes with high repair stability have more reliable repair schemes, and their repair impact on associated nodes is more valuable for reference. Nodes with low repair stability require careful consideration of the constraints of associated nodes in collaborative repair to avoid the chain reaction caused by their own repair fluctuations. This step achieves a precise characterization of the node's own repair characteristics. The connection relationships between nodes at abnormal locations are obtained based on the topology, and the strength of the repair impact between nodes is obtained based on the connection relationships and the repair stability vectors of multiple nodes. The connection relationships between nodes at abnormal locations are determined based on the topology constructed above, including direct physical connections and indirect associations. For example, if node A at an abnormal location is directly connected to nodes B and C, and node B is directly connected to node D, then node A and node D are indirectly connected. The calculation of the repair impact strength between nodes adopts a weighted algorithm based on connection relationships and repair stability. The closer the connection relationship (e.g., direct connection compared to indirect connection), the higher the weight. At the same time, the higher the mean of the node's own repair stability vector, the greater the impact strength on associated nodes. The specific formula is: Repair impact strength between nodes = Connection relationship weight × (mean of active node repair stability vector + mean of passive node repair stability vector) / 2, where the connection relationship weight is set according to the connection type, with the weight of direct connection set to 0.8 and the weight of indirect connection set to 0.3. For example, if node A and node B are directly connected, and the mean value of the repair stability vector for node A is 0.82 while the mean value for node B is 0.75, then the repair influence strength between them is 0.8 × (0.82 + 0.75) / 2 = 0.628. The physical significance of this step lies in quantifying the degree of mutual repair influence between nodes at abnormal locations and clarifying the mutual constraints in the node repair process. For instance, the repair influence strength of core nodes and multiple associated nodes is high, and adjustments to their repair schemes will significantly affect the repair results of surrounding nodes. Conversely, the repair influence of edge nodes on other nodes is relatively small. This step addresses the problem of traditional repair methods neglecting the mutual influence between nodes, providing a quantitative basis for collaborative repair. A collaborative repair feature matrix is ​​constructed based on the repair stability vectors of multiple nodes and the repair influence strength between nodes. The collaborative repair feature matrix is ​​constructed with anomalous node positions as rows and columns. Matrix elements contain two dimensions of information: the mean repair stability vector of the row nodes and the repair influence strength between the row node and the column node. For example, given three anomalous node positions A, B, and C, node A has a mean repair stability vector of 0.82, a repair influence strength between A and B of 0.628, and a repair influence strength between A and C of 0.512; node B has a mean repair stability vector of 0.75, a repair influence strength between B and A of 0.628, and a repair influence strength between B and C of 0.486; and node C has a mean repair stability vector of 0.79, a repair influence strength between C and A of 0.512, and a repair influence strength between C and B of 0.486. Therefore, the collaborative repair feature matrix is ​​a 3×3 matrix, where each element is a combination of (mean repair stability vector, repair influence strength). The physical significance of this step lies in integrating the self-repair characteristics of multiple nodes with the correlation and influence characteristics between nodes into structured matrix data, comprehensively presenting the core information of collaborative repair. The collaborative repair feature matrix can intuitively reflect the status and mutual constraints of each node in collaborative repair, providing a unified structured data foundation for subsequent comparison with health benchmarks. This step achieves the systematic integration of collaborative repair information.

[0036] S64 retrieves the historical normal data of the abnormal location nodes within the historical normal period and obtains the collaborative health benchmark based on this data. The historical normal period is defined as described above. The collaborative historical normal data refers to the interrelated operational data of the abnormal location nodes within the historical normal period. For example, it includes the electricity consumption and voltage data of multiple abnormal location nodes within the same distribution transformer area during the same historical normal period. This data originates from the power system's historical data repository. By querying the device number and corresponding topological relationships of the abnormal location nodes, their collaborative operational data within the historical normal period is extracted. The collaborative health benchmark is obtained using statistical analysis methods. The historical normal data is calculated for mean, variance, and covariance to obtain quantitative indicators that reflect the normal collaborative operational status between nodes. For example, for the coordinated historical normal electricity consumption data of nodes A, B, and C, the calculated mean vectors are [12.5kWh, 11.8kWh, 13.2kWh], and the covariance matrix is ​​[[1.2, 0.8, 0.9], [0.8, 1.1, 0.7], [0.9, 0.7, 1.3]]. These statistical indicators together constitute the coordinated health benchmark. The physical significance of this step is to establish a normal benchmark for coordinated operation between nodes, providing a reference for judging the rationality of the coordinated repair results. The coordinated health benchmark can quantify the normal coordinated relationship between nodes, such as the degree of data matching and fluctuation consistency, avoiding deviation of the repaired coordinated relationship from the historical normal pattern. This step provides a clear reference standard for coordinated repair.

[0037] S65 calculates the collaborative repair credibility based on the collaborative repair feature matrix and the collaborative health benchmark, and uses this credibility as the collaborative repair result. The calculation of collaborative repair credibility uses a similarity matching algorithm. First, the repair stability information and repair impact intensity information in the collaborative repair feature matrix are aligned dimensionally with the statistical indicators in the collaborative health benchmark. Then, the cosine similarity between the two is calculated. A higher similarity indicates that the collaborative repair features are closer to the historical normal collaborative state, and the higher the collaborative repair credibility. In specific implementation, the data in the collaborative repair feature matrix and the collaborative health benchmark are first standardized to eliminate the influence of dimensions. Then, the cosine similarity is calculated through matrix multiplication, with a value range of [0,1]. The closer to 1, the higher the repair credibility. For example, if the cosine similarity between the standardized collaborative repair feature matrix and the collaborative health benchmark is 0.92, then the collaborative repair credibility is 0.92, indicating that the collaborativeness of the repaired node data is highly consistent with the historical normal state. If the similarity is 0.65, it indicates that there is a certain deviation in the collaborativeness, and further adjustments to the repair scheme may be needed. The physical significance of this step lies in quantifying the reliability and rationality of the collaborative repair results, providing clear evaluation indicators for the repair effect. The credibility of collaborative repair not only reflects the accuracy of the repair of a single node, but also ensures the rationality of the collaborative relationship between nodes. For example, a highly credible repair result ensures that the data of each node conforms to its own historical normal characteristics, and also ensures that the data matching degree between nodes conforms to historical collaborative patterns. This step realizes the quantitative evaluation and verification of the collaborative repair effect.

[0038] This application also provides an intelligent anomaly detection and efficient repair system for user-side metering data, including: The data acquisition module is used to acquire multi-source heterogeneous operation data from the target user side, wherein the multi-source heterogeneous operation data includes structured power metering data and time-series power metering operation data. The vector acquisition module is used to acquire the power metering knowledge graph and topology based on the power metering structured data, and to acquire static anomaly feature vectors based on the power metering knowledge graph. The feature acquisition module is used to acquire multiple undetermined abnormal feature values ​​of multiple nodes based on the topology and the power metering time series operation data, and to acquire multiple comprehensive undetermined abnormal feature values ​​based on the multiple undetermined abnormal feature values ​​and the static abnormal feature vector. The judgment module is used to sequentially judge whether multiple comprehensive abnormal undetermined feature values ​​exceed the abnormal threshold, and to take the position corresponding to the comprehensive abnormal feature value that exceeds the abnormal threshold as the abnormal position node. The tensor decomposition module is used to obtain multiple node root cause diagnostic data based on multiple abnormal location nodes, and to perform tensor decomposition on the multiple node root cause diagnostic data and the preset normal data of their corresponding associated nodes to obtain multiple tensor decomposition data. The collaborative repair module is used to collaboratively repair multiple tensor decomposition data to obtain a collaborative repair result.

[0039] In one embodiment, the vector acquisition module includes: The first acquisition unit is used to acquire equipment ledger data, network topology connection data and equipment attribute file data based on the structured power metering data; The second acquisition unit is used to acquire multiple metering equipment entities, user entities, and distribution transformer area entities based on the equipment ledger data and the equipment attribute file data. The topology relationship acquisition unit is used to acquire multiple physical connection relationships between multiple metering device entities based on the network topology connection data and multiple metering device entities, acquire multiple membership relationships between multiple metering device entities and user entities, and acquire multiple access relationships between multiple metering device entities and distribution transformer area entities. The knowledge graph construction unit is used to construct an initial power metering knowledge graph based on multiple physical connection relationships, multiple membership relationships, and multiple access relationships, and to obtain the node-edge topological relationship structure based on the initial power metering knowledge graph, and to use the topological relationship structure as the topological structure. The third acquisition unit is used to acquire the topological centrality and historical co-occurrence frequency of each metering device entity node in the initial power metering knowledge graph; The calculation unit is used to calculate multiple static risk contribution degrees based on multiple topological centralities and multiple historical co-occurrence frequencies, and to construct a static anomaly feature vector based on the multiple static risk contribution degrees.

[0040] This application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the above-described method.

[0041] This application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the above-described method.

[0042] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the methods described above. Any references to memory, storage, databases, or other media used in this application and in the embodiments can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual-speed SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0043] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, apparatus, article, or method. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, apparatus, article, or method that includes that element.

[0044] The above description is merely a preferred embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.

Claims

1. A method for intelligent anomaly detection and efficient repair of user-side metering data, characterized in that, include: Acquire multi-source heterogeneous operation data from the target user side, wherein the multi-source heterogeneous operation data includes structured power metering data and time-series power metering operation data; Based on the structured data of electricity metering, an electricity metering knowledge graph is obtained, and static anomaly feature vectors and topological structures are obtained based on the electricity metering knowledge graph; Based on the topology and the power metering time-series operation data, multiple nodes are obtained as undetermined abnormal feature values, and multiple comprehensive undetermined abnormal feature values ​​are obtained based on the multiple undetermined abnormal feature values ​​and the static abnormal feature vector. Sequentially determine whether multiple comprehensive abnormal undetermined feature values ​​exceed the abnormal threshold, and take the position corresponding to the comprehensive abnormal feature value that exceeds the abnormal threshold as the abnormal position node; Multiple node root cause diagnostic data are obtained based on multiple abnormal location nodes, and the multiple node root cause diagnostic data and their corresponding associated node preset normal data are decomposed into tensor data to obtain multiple tensor decomposed data. The multiple tensor decomposition data are collaboratively repaired to obtain a collaborative repair result.

2. The intelligent anomaly detection and efficient repair method for user-side metering data according to claim 1, characterized in that, The steps of obtaining a power metering knowledge graph based on the power metering structured data, and obtaining static anomaly feature vectors and topological structures based on the power metering knowledge graph, include: Based on the structured data of electricity metering, obtain equipment ledger data, network topology connection data, and equipment attribute file data; Based on the equipment ledger data and the equipment attribute file data, multiple metering equipment entities, user entities, and distribution transformer area entities are obtained; Based on the network topology connection data and the multiple metering device entities, multiple physical connection relationships between the multiple metering device entities are obtained; based on the multiple metering device entities and the user entity, multiple membership relationships between them are obtained; and based on the multiple metering device entities and the distribution transformer area entity, multiple access relationships are obtained. An initial power metering knowledge graph is constructed based on multiple physical connection relationships, multiple membership relationships, and multiple access relationships. The topological relationship structure of nodes and edges is obtained based on the initial power metering knowledge graph, and the topological relationship structure is used as the topological structure. Obtain the topological centrality and historical co-occurrence frequency of each metering device entity node in the initial power metering knowledge graph; Multiple static risk contribution degrees are calculated based on multiple topological centralities and multiple historical co-occurrence frequencies, and a static anomaly feature vector is constructed based on the multiple static risk contribution degrees.

3. The intelligent anomaly detection and efficient repair method for user-side metering data according to claim 1, characterized in that, The step of obtaining multiple undetermined anomaly feature values ​​of multiple nodes based on the topology and the power metering time-series operation data, and obtaining multiple comprehensive undetermined anomaly feature values ​​based on the multiple undetermined anomaly feature values ​​and the static anomaly feature vector, includes: Based on the energy metering time sequence operation data, obtain the energy metering time sequence operation sequence under the preset continuous timestamps; The topological relationship chain is obtained according to the topological structure, and multiple first metering device entities in the topological relationship chain are obtained according to the topological relationship chain. The multi-dimensional operating characteristics of each first metering device entity within a preset time window are obtained, wherein the multi-dimensional operating characteristics include frequency domain characteristics and time-series morphological characteristics. Multiple operation feature vectors are obtained based on the power metering time series operation sequence, multiple frequency domain features, and multiple time series morphological features; The abnormal undetermined feature value of each node is obtained based on multiple described running feature vectors; Based on each of the aforementioned undetermined anomaly features, the cumulative anomaly deviation area and anomaly evolution trend feature value of each node within a preset time window are obtained; The topological neighborhood area corresponding to each node is obtained according to the topological structure, and the spatiotemporal anomaly diffusion intensity of each node is obtained according to the topological neighborhood area and the cumulative anomaly deviation area. The spatiotemporal anomaly intensity of each node is obtained based on the characteristic value of the anomaly evolution trend of each node and the spatiotemporal anomaly diffusion intensity. Obtain multiple historical health feature values ​​corresponding to each identical node within a historical normal period, and obtain the historical health benchmark of the corresponding node based on the multiple historical health feature values ​​of each node; The relative deviation of node anomaly is obtained based on the spatiotemporal anomaly intensity of each node and the historical health benchmark. The node dynamic anomaly comprehensive value of each node is obtained based on the relative deviation of the node anomaly and the spatiotemporal anomaly diffusion intensity, and multiple node dynamic anomaly comprehensive values ​​are used as multiple comprehensive anomaly undetermined feature values.

4. The intelligent anomaly detection and efficient repair method for user-side metering data according to claim 1, characterized in that, The step of obtaining root cause diagnostic data for multiple nodes based on multiple abnormal location nodes includes: The topological association between the abnormal location nodes is obtained based on the multiple abnormal location nodes, wherein the topological association includes at least one abnormal propagation path of at least one of the abnormal location nodes; Obtain the time-series data of the running status of each node in each of the aforementioned abnormal propagation paths within a preset historical time period; The spatiotemporal impact intensity of the corresponding node is obtained based on the time-series data of the running status of each node and the anomaly propagation path; Obtain the duration and magnitude of the abnormal change for each of the abnormal location nodes; The node abnormality attribute value of each node is obtained based on the abnormal duration and the abnormal mutation magnitude of each abnormal location node. The node anomaly comprehensive weight is obtained based on the spatiotemporal influence intensity and the node anomaly attribute value of each anomaly location node. The root cause node of each path is obtained by taking the comprehensive weight of the node anomalies of all nodes on each path of anomaly propagation, and the identifier of each root cause node and its corresponding comprehensive weight of the node anomalies are used as the root cause diagnosis data.

5. The intelligent anomaly detection and efficient repair method for user-side metering data according to claim 1, characterized in that, The step of performing tensor decomposition on the root cause diagnostic data of multiple nodes and the preset normal data of their corresponding associated nodes to obtain multiple tensor decomposed data includes: For each node root cause diagnosis data corresponding to the abnormal location node, obtain the dimension weights of multiple data dimensions in the node root cause diagnosis data; The node root cause diagnosis data is weighted according to the dimensional weights of the multiple data dimensions to obtain weighted node root cause diagnosis data. Obtain the preset normal data corresponding to the abnormal location node within the historical normal period; Multiple historical normal principal component features are extracted from the preset normal data, and the average value of the historical normal principal component features of the abnormal location node is obtained based on the multiple historical normal principal component features. Multiple abnormal principal component features are extracted from the weighted root cause diagnosis data of the nodes, and the mean value of the current abnormal principal component features of the nodes at the abnormal locations is obtained based on the multiple abnormal principal component features. Based on the historical normal principal component feature mean and the current abnormal principal component feature mean, the feature deviation of the abnormal location node is obtained; The weighted node root cause diagnosis data, the feature deviation, and the preset normal data are combined to construct a node repair feature tensor; The node repair feature tensor is decomposed into multiple core feature sub-tensors, and these multiple core feature sub-tensors are used as multiple tensor decomposition data.

6. The intelligent anomaly detection and efficient repair method for user-side metering data according to claim 1, characterized in that, The step of collaboratively repairing multiple tensor decomposition data to obtain a collaborative repair result includes: For each of the abnormal location nodes, the tensor decomposition data is used to obtain the repair stability features in multiple core feature sub-tensors, and the node repair stability vector of the corresponding node is obtained based on the repair stability features of each core feature sub-tensor. The connection relationships between the nodes at the abnormal locations are obtained based on the topology, and the repair influence intensity between nodes is obtained based on the connection relationships and multiple node repair stability vectors. Based on the repair stability vectors of multiple nodes and the repair influence strength between nodes, a collaborative repair feature matrix is ​​constructed; Obtain the collaborative historical normal data corresponding to the abnormal location node within the historical normal period, and obtain the collaborative health benchmark based on the collaborative historical normal data; Based on the collaborative repair feature matrix and the collaborative health benchmark, the collaborative repair credibility is calculated, and the collaborative repair credibility is used as the collaborative repair result.

7. A user-side metering data intelligent anomaly detection and efficient repair system, characterized in that, include: The data acquisition module is used to acquire multi-source heterogeneous operation data from the target user side, wherein the multi-source heterogeneous operation data includes structured power metering data and time-series power metering operation data. The vector acquisition module is used to acquire the power metering knowledge graph and topology based on the power metering structured data, and to acquire static anomaly feature vectors based on the power metering knowledge graph. The feature acquisition module is used to acquire multiple undetermined abnormal feature values ​​of multiple nodes based on the topology and the power metering time series operation data, and to acquire multiple comprehensive undetermined abnormal feature values ​​based on the multiple undetermined abnormal feature values ​​and the static abnormal feature vector. The judgment module is used to sequentially judge whether multiple comprehensive abnormal undetermined feature values ​​exceed the abnormal threshold, and to take the position corresponding to the comprehensive abnormal feature value that exceeds the abnormal threshold as the abnormal position node. The tensor decomposition module is used to obtain multiple node root cause diagnostic data based on multiple abnormal location nodes, and to perform tensor decomposition on the multiple node root cause diagnostic data and the preset normal data of their corresponding associated nodes to obtain multiple tensor decomposition data. The collaborative repair module is used to collaboratively repair multiple tensor decomposition data to obtain a collaborative repair result.

8. The intelligent anomaly detection and efficient repair system for user-side metering data according to claim 7, characterized in that, The vector acquisition module includes: The first acquisition unit is used to acquire equipment ledger data, network topology connection data and equipment attribute file data based on the structured power metering data; The second acquisition unit is used to acquire multiple metering equipment entities, user entities, and distribution transformer area entities based on the equipment ledger data and the equipment attribute file data. The topology relationship acquisition unit is used to acquire multiple physical connection relationships between multiple metering device entities based on the network topology connection data and multiple metering device entities, acquire multiple membership relationships between multiple metering device entities and user entities, and acquire multiple access relationships between multiple metering device entities and distribution transformer area entities. The knowledge graph construction unit is used to construct an initial power metering knowledge graph based on multiple physical connection relationships, multiple membership relationships, and multiple access relationships, and to obtain the node-edge topological relationship structure based on the initial power metering knowledge graph, and to use the topological relationship structure as the topological structure. The third acquisition unit is used to acquire the topological centrality and historical co-occurrence frequency of each metering device entity node in the initial power metering knowledge graph; The calculation unit is used to calculate multiple static risk contribution degrees based on multiple topological centralities and multiple historical co-occurrence frequencies, and to construct a static anomaly feature vector based on the multiple static risk contribution degrees.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.