Hydrogen fuel cell safety staging response method and related products

By constructing a real-time digital twin of a hydrogen fuel cell system, combined with routine monitoring and diagnosis and proactive prediction, the shortcomings of safety monitoring in existing hydrogen fuel cell systems have been addressed, enabling precise early warning and intelligent response, and improving the system's safety and availability.

CN122432790APending Publication Date: 2026-07-21山东国创燃料电池技术创新中心有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
山东国创燃料电池技术创新中心有限公司
Filing Date
2026-06-18
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

The existing safety monitoring mode of hydrogen fuel cell system cannot achieve accurate prediction in advance and intelligent hierarchical response afterward, resulting in a high false alarm and false alarm rate and over-response, which cannot meet the requirements of high availability and high safety.

Method used

A digital twin synchronized with the hydrogen fuel cell system in real time is constructed. Through routine monitoring and diagnosis and proactive prediction, early warning and post-event response are carried out. By utilizing multi-source data fusion and AI intelligent diagnosis, the optimal response strategy is generated and verified through simulation.

Benefits of technology

It enables advanced prediction and precise handling of hydrogen safety risks, reduces false alarm and missed alarm rates, avoids unnecessary production interruptions, and improves the safety and availability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122432790A_ABST
    Figure CN122432790A_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of fuel cells. A hydrogen fuel cell safety grading response method and related products are proposed. The multi-source operation data of the hydrogen fuel cell system is obtained to drive the digital twin to be synchronously mapped with the hydrogen fuel cell system. Normal monitoring diagnosis and active deduction prediction are executed in parallel in the digital twin. The former detects abnormalities by comparing the deviation between measured and simulated data, and the latter predicts risk trends by fault injection simulation. Pre-warning or post-response is performed based on the diagnosis and prediction results. If post-response is performed, the risk level is evaluated according to the leakage concentration, the rising rate and the simulation conclusion, and the preset response strategy is simulated and verified in the digital twin, and then the optimized strategy is executed. The application realizes the transition from passive protection to active early warning, reduces the false positive and false negative rates, establishes a scientific grading response mechanism, and ensures the safe and continuous operation of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of fuel cell technology, specifically to a method for graded safety response of hydrogen fuel cells and related products. Background Technology

[0002] The statements in this section are merely background information related to the present invention and do not necessarily constitute prior art.

[0003] Stationary hydrogen fuel cell power generation systems, as an important carrier of clean energy technology, have been widely used in distributed energy, backup power, and other fields. With technological advancements, digital twin technology, with its ability to construct high-fidelity mappings of physical entities in virtual space, provides a new paradigm for the monitoring and management of complex industrial systems. By integrating multi-source sensor data, physical models, and artificial intelligence algorithms, this technology enables real-time synchronization, in-depth insights, and forward-looking predictions of system states, laying the technological foundation for addressing the inherent shortcomings of traditional security monitoring methods.

[0004] However, existing hydrogen safety technologies generally adopt a "sensing-alarm-action" model based on a single sensor threshold trigger. The core problem with this model is its inability to achieve an organic unity between accurate pre-event prediction and intelligent, tiered post-event response. This passive response mechanism is not only ineffective in providing early warnings before leaks occur, but also lacks a comprehensive assessment of the overall system status. After an incident, it can only adopt a crude "one-size-fits-all" approach, resulting in high false alarm and false alarm rates. Furthermore, it often causes unnecessary production interruptions due to over-response, failing to meet the demands of modern stationary hydrogen fuel cell power generation systems for both high availability and high safety. Summary of the Invention

[0005] To address the shortcomings of existing technologies, this invention provides a hydrogen fuel cell safety graded response method and related products. By constructing a digital twin and synchronously mapping it with the hydrogen fuel cell system in real time, this invention significantly improves the initiative and foresight of hydrogen safety monitoring.

[0006] To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a safety graded response method for hydrogen fuel cells.

[0007] A safety-graded response method for hydrogen fuel cells includes the following processes: Acquire multi-source operating data of the hydrogen fuel cell system, and perform synchronous data mapping between the digital twin and the hydrogen fuel cell system based on the multi-source operating data; Routine monitoring and diagnosis and proactive prediction are performed in parallel within the digital twin. Routine monitoring and diagnosis detects anomalies and analyzes root causes by comparing the deviations between measured data and simulation data. Proactive prediction injects faults into the digital twin to perform simulation and predict risk trends. Based on the results of routine monitoring and diagnosis and proactive simulation and prediction, early warning or post-event response is carried out. If post-event response is carried out, the risk level is jointly assessed based on the leakage concentration, the rate of increase in concentration and the simulation results of the digital twin. After the preset response strategy is verified by simulation in the digital twin, the optimized best response strategy is sent to the hydrogen fuel cell system for execution.

[0008] In one implementation of the first aspect of the present invention, the pre-warning process includes: When routine monitoring and diagnosis identify early abnormal characteristics, or when proactive deduction and prediction identify a clear fault development trend, an early warning is issued. Among these, early abnormal characteristics include abnormal control current characteristics of actuators, and fault development trends include performance degradation of key components leading to abnormal system status.

[0009] As a further limitation of the first aspect of the present invention, after providing early warning, the method further includes: displaying a visual warning sign of the corresponding level on the human-machine interface; generating a predictive maintenance work order; and controlling the hydrogen fuel cell system to enter a conservative operation mode to reduce output power based on the severity of the fault development trend.

[0010] In one implementation of the first aspect of the present invention, the actuator state of the hydrogen fuel cell includes the on / off state of the solenoid valve or regulating valve and the valve position feedback signal. The optimal response strategy includes: an action command for controlling the solenoid valve or regulating valve, and verification of the action execution result through the valve position feedback signal.

[0011] In one implementation of the first aspect of the present invention, after performing routine monitoring and diagnosis and proactive prediction in parallel in the digital twin, the method further includes: If routine monitoring and diagnosis detect abnormal deviations between measured data and simulation data, root cause analysis is initiated. Potential faults are located based on preset fault codes, and corresponding fault models are injected into the proactive inference and prediction based on the location information of potential faults.

[0012] As a further limitation of the first aspect of the present invention, feature data including stack voltage, total stack current, auxiliary machine current, output voltage, hydrogen pressure, coolant temperature and hydrogen leakage concentration are obtained as fault feature vectors, input to a pre-trained XGBoost classification model, and the corresponding fault codes are output.

[0013] In one implementation of the first aspect of the present invention, active deduction and prediction includes: Hydrogen leakage faults are injected into the geometric model of the digital twin. Computational fluid dynamics model is used to simulate hydrogen leakage and diffusion, predict the hydrogen concentration distribution at various points in the cabin in the future, and determine the range of flammable areas based on the hydrogen concentration distribution.

[0014] As a further limitation of the first aspect of the present invention, determining the flammable zone range based on the hydrogen concentration distribution includes: In the geometric model of the digital twin, virtual sensors are set up according to the actual sensor placement locations to monitor the time and rate of increase of hydrogen concentration at each virtual sensor when it reaches a preset threshold.

[0015] In one implementation of the first aspect of the present invention, the active inference and prediction further includes: Long Short-Term Memory (LSTM) networks are used to analyze time-series data from multi-source operational data to predict future trends of key parameters; the remaining useful life of key components is predicted based on survival analysis theory.

[0016] In one implementation of the first aspect of the present invention, the risk levels include Level 1 risk, Level 2 risk, and Level 3 risk. The optimized best response strategy is then distributed to the hydrogen fuel cell system for execution, including: If the risk level is Level 1, the ventilation system will be controlled to increase the ventilation volume, and the data logging module will be triggered to record data before and after the event at a high frequency. If it is a level 2 risk, then in addition to executing the level 1 risk response actions, control the fuel supply system to close the upstream solenoid valve on the leakage path and control the power generation system controller to reduce the output power; If the risk level is level three, in addition to the response actions for level one and level two risks, the fuel supply system will be controlled to shut down the main hydrogen valve, the emergency venting system will be activated, and an emergency shutdown command will be sent to the main controller of the power generation system.

[0017] In one implementation of the first aspect of the present invention, a preset response strategy is simulated and verified in a digital twin, including: Multiple candidate response strategies are generated based on a rule engine; the candidate response strategies are sent to a digital twin for rapid simulation; the effectiveness, negative impact, and economy of each candidate response strategy are evaluated; and the comprehensive optimal strategy is selected from the candidate response strategies as the best response strategy based on a multi-objective optimization algorithm.

[0018] Secondly, the present invention provides a hydrogen fuel cell safety graded response system.

[0019] A hydrogen fuel cell safety graded response system includes a physical layer, a data transmission layer, a cloud digital twin layer, and an application layer; The physical layer includes the stationary hydrogen fuel cell power generation system entity, sensor network, actuator array, and local controller; The data transmission layer is used to upload multi-source operational data collected by the sensor network to the cloud digital twin layer, and to send the response strategy generated by the cloud digital twin layer to the local controller, so that the local controller can control the operation of the stationary hydrogen fuel cell power generation system based on the actuator array; The cloud-based digital twin layer includes a data-driven and synchronization module for constructing a digital twin, which is used to execute the hydrogen fuel cell safety graded response method of the first aspect of the present invention. The application layer is used to provide the human-computer interaction interface.

[0020] In one implementation of the second aspect of the present invention, the digital twin includes a geometric model, a physical model, and behavioral rules; The geometric model is constructed based on the system's three-dimensional design drawings; The physical model integrates computational fluid dynamics, heat transfer, and electrochemical models. Behavioral rules are embedded in the control logic of all controllers, actuators, and sensors.

[0021] In one implementation of the second aspect of the present invention, the sensor network includes a hydrogen concentration sensor array, a temperature sensor, a pressure sensor, an electrical parameter sensor, a flow sensor, and a vibration sensor; the hydrogen concentration sensor array is arranged in the hydrogen storage tank area, the pressure reducing valve group, the fuel cell stack anode inlet, the fuel cell stack anode outlet, the vent, the top and bottom of the compartment; the actuator array includes a solenoid valve, a regulating valve, a ventilation fan, and an emergency venting device.

[0022] Thirdly, the present invention provides a hydrogen fuel cell safety graded response system.

[0023] A hydrogen fuel cell safety graded response system, comprising: The data synchronization unit is configured to: acquire multi-source operating data of the hydrogen fuel cell system, and perform synchronization data mapping between the digital twin and the hydrogen fuel cell system based on the multi-source operating data; The parallel diagnostic unit is configured to perform routine monitoring and diagnosis and proactive inference and prediction in parallel within the digital twin. Routine monitoring and diagnosis detects anomalies and performs root cause analysis by comparing the deviation between measured data and simulation data. Proactive inference and prediction predicts risk trends by injecting faults into the digital twin and performing simulation inference. The graded response unit is configured to: provide early warning or execute post-event response based on the results of routine monitoring and diagnosis and proactive inference and prediction; if a post-event response is executed, the risk level is jointly assessed based on the leakage concentration, the rate of increase in concentration and the simulation conclusions of the digital twin, and the preset response strategy is verified by simulation in the digital twin before the optimized best response strategy is sent to the hydrogen fuel cell system for execution.

[0024] Fourthly, the present invention provides a computer device, comprising: a processor and a computer-readable storage medium; A processor, adapted to execute computer programs; A computer-readable storage medium storing a computer program, which, when executed by a processor, implements the hydrogen fuel cell safety graded response method of the first aspect of the present invention.

[0025] Fifthly, the present invention provides a computer-readable storage medium storing a computer program adapted to be loaded by a processor and executed by the hydrogen fuel cell safety classification response method of the first aspect of the present invention.

[0026] In a sixth aspect, the present invention provides a computer program product, which includes a computer program that, when executed by a processor, implements the hydrogen fuel cell safety graded response method of the first aspect of the present invention.

[0027] Compared with the prior art, the beneficial effects of the present invention are: This invention effectively solves the core problem of the disconnect between prediction and response in traditional hydrogen safety technologies by constructing a digital twin that is synchronized in real time with the hydrogen fuel cell system and executing routine monitoring and diagnosis and proactive prediction in parallel within it. Routine monitoring and diagnosis achieves in-depth root cause analysis of system anomalies by continuously comparing the deviations between measured data and high-fidelity simulation data; proactive prediction, on the other hand, proactively predicts risk evolution trends by injecting faults into virtual space for simulation. The two work together, enabling the system to not only generate accurate early warnings before leaks occur, but also to scientifically assess risks after an event by comprehensively considering the leak concentration, the rate of concentration increase, and the simulation conclusions of the digital twin. More importantly, by simulating and optimizing the preset response strategy within the digital twin, it ensures that the execution commands ultimately issued to the hydrogen fuel cell system are the optimal solution that balances safety and economy, thereby significantly reducing false alarm and false negative rates and avoiding unnecessary production interruptions caused by "one-size-fits-all" over-response.

[0028] This invention achieves predictive maintenance and dynamic adjustment of system operation modes by refining early warning into a multi-level early warning mechanism based on early abnormal characteristics and clear fault development trends. When the system identifies early characteristics such as abnormal actuator current or development trends such as performance degradation of key components, it not only provides visual prompts through the human-machine interface but also automatically generates predictive maintenance work orders and intelligently controls the hydrogen fuel cell system to enter a conservative operation mode (such as reducing output power) according to the severity of the fault. This proactive intervention strategy significantly advances the safety defense line, ensuring the basic functions of the system while providing maintenance personnel with valuable response time windows, effectively preventing minor faults from escalating into major accidents.

[0029] This invention ensures the reliable execution of post-event graded response actions by establishing a closed-loop verification mechanism between actuator status (such as valve position feedback signals) and action commands in the response strategy. In the three-level response mechanism, for different risk levels (Level 1, Level 2, and Level 3), the system can accurately issue the optimal response strategy containing action commands for specific solenoid valves or regulating valves, and uses valve position feedback signals to verify the action results in real time. This precise linkage control based on actuator status feedback ensures that key safety measures such as air supply cutoff and power adjustment are accurately and reliably implemented, greatly improving the effectiveness of response measures and the overall safety level of the system.

[0030] This invention constructs a self-optimizing intelligent decision-making system by deeply integrating AI-powered intelligent diagnosis with multi-physics simulation. On one hand, it uses models such as XGBoost to analyze multi-source feature data, quickly locates potential faults, and feeds the diagnostic results back to the active simulation module to inject a more accurate fault model. On the other hand, it combines CFD simulation and LSTM time-series prediction to perform multi-dimensional simulations of hydrogen diffusion, key parameter trends, and component lifespan. Based on this, a rule engine generates candidate strategies, and multi-objective simulations evaluating effectiveness, negative impacts, and economic efficiency are conducted in a digital twin, ultimately selecting the comprehensive optimal strategy. This system transforms safety decision-making from static rule-driven to dynamic, adaptive intelligent optimization, continuously improving the system's prediction accuracy and response performance.

[0031] Advantages of additional aspects of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0032] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an improper limitation of the invention.

[0033] Figure 1A schematic diagram of the overall architecture of a hydrogen fuel cell safety graded response system provided as an exemplary embodiment of the present invention; Figure 2 A schematic flowchart of a hydrogen fuel cell safety graded response method provided as an exemplary embodiment of the present invention; Figure 3 A schematic diagram of health status detection results provided as an exemplary embodiment of the present invention; Figure 4 A schematic diagram illustrating the location of a pressure reducing valve leakage fault, provided as an exemplary embodiment of the present invention; Figure 5 A cloud map showing the hydrogen distribution changes at different times, provided as an exemplary embodiment of the present invention; Figure 6 A schematic diagram of a hydrogen fuel cell safety graded response system provided as another exemplary embodiment of the present invention; Figure 7 A schematic diagram of a computer device provided for an exemplary embodiment of the present invention. Detailed Implementation

[0034] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0035] It should be noted that the following detailed descriptions are exemplary and intended to provide further illustration of the invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.

[0036] The purpose of this invention is to overcome the shortcomings of existing technologies and provide a hydrogen safety prediction and graded response strategy based on cloud-based digital twins. This aims to achieve advanced prediction, in-depth diagnosis, and precise handling of hydrogen safety risks by constructing a digital twin synchronized in real time with the physical entity, integrating big data analysis, machine learning, and multiphysics simulation. Specifically, the objectives of this invention include: achieving a fundamental shift from passive protection to proactive early warning, identifying risks and taking measures before hydrogen leaks occur; significantly reducing false alarm and false negative rates through multi-source data fusion and digital twin technology; establishing a scientific graded response mechanism to avoid over-response and maximize system continuous operation while ensuring safety; providing predictive maintenance capabilities to reduce operation and maintenance costs and extend equipment lifespan; and ensuring the effectiveness and optimization of the response strategy through simulation verification.

[0037] To achieve the above objectives, the core technical solution of this invention is to construct a fully closed-loop intelligent safety system encompassing "perception-diagnosis-prediction-decision-verification-execution". For example... Figure 1As shown, at the system architecture level, the system of this invention adopts a layered design, consisting of a physical layer, a data transmission layer, a cloud-based digital twin layer, and an application layer from top to bottom. The physical layer includes the power generation system itself (such as hydrogen storage tanks, fuel cell stacks, pipelines, etc.), actuator arrays (such as solenoid valves, fans, pumps, etc.), and a local controller PLC. It collects equipment operating parameters through a sensor network and feeds back the equipment status. The PLC receives downlink commands and drives the execution of actions. The data transmission layer uses wired / wireless communication networks (industrial Ethernet / 4G / 5G) to realize the uplink of raw data and the downlink of verified control commands. The cloud-based digital twin layer first uses a data-driven and synchronization module to clean, transform, and align the uplink data to generate cleaned real-time data, and then constructs a high-fidelity digital twin (covering geometric, physical, and behavioral models) to support AI diagnostic and prediction models (risk prediction based on machine learning). At the same time, it responds to the strategy generation and simulation verification module to receive manual intervention / control commands or requests from the application layer, and outputs verified control commands based on the strategy optimization results. The application layer is a remote monitoring center (Web / App). The UI provides a human-computer interaction interface, forming a closed-loop intelligent control process of "perception-transmission-modeling-decision-execution".

[0038] In this implementation, the physical layer serves as the hardware foundation of the entire system and consists of the following components: (1) The physical structure of a stationary hydrogen fuel cell power generation system. This includes a hydrogen storage subsystem (hydrogen storage tank, pressure reducing valve assembly, pipeline), a power generation system (fuel cell stack, power converter), a thermal management subsystem (coolant circulation pump, radiator), and auxiliary subsystems.

[0039] (2) Sensor network. Includes: A) Hydrogen concentration sensor array: At least 12 high-precision hydrogen sensors are deployed in key locations such as the hydrogen storage tank area, pressure reducing valve group, fuel cell stack anode inlet, fuel cell stack anode outlet, ventilation openings, and the top and bottom of the compartment, with a measurement range of 0-100% LEL and an accuracy of ±2% FS; B) Temperature sensor: Monitors the surface temperature of the hydrogen pipeline (-40℃~+120℃), the fuel cell stack operating temperature (0℃~90℃), and the ambient temperature inside the compartment (-20℃~+60℃); C) Pressure sensor: Monitors the pressure of the high-pressure hydrogen storage tank (0-35MPa), the pressure before and after the pressure reducing valve (0-1MPa), and the fuel cell stack anode inlet pressure (0-500kPa); D) Electrical parameter sensor: Monitors the fuel cell stack voltage (0-500VDC), output current (0-300ADC), and single cell voltage; E) Flow sensor: Monitors the hydrogen circulation flow rate (0-200L / min) and coolant flow rate (0-50L / min); F) Vibration sensor: Monitors the vibration characteristics of the circulation pump and fan.

[0040] (3) Actuator array. Includes solenoid valves (response time < 2s), regulating valves, ventilation fans (explosion-proof type, air volume 2000-10000m³ / h), and emergency venting devices.

[0041] (4) Local controller. It adopts an industrial-grade PLC and is equipped with redundant CPU and communication module.

[0042] In this implementation, the data transmission layer acts as a bridge connecting the physical layer and the cloud, employing a hybrid wired and wireless network: the field layer uses PROFIBUS-DP or Modbus RTU protocols to connect sensors and actuators; the local controller communicates with the cloud via industrial Ethernet or 5G networks, supporting OPC UA and MQTT protocols; the communication network has a redundant design to ensure the reliability of data transmission.

[0043] In this implementation, the cloud-based digital twin layer is the core of the invention, comprising: A) a data-driven and synchronization module, responsible for receiving real-time data and performing data cleaning, format conversion, and time alignment; B) a high-fidelity digital twin, consisting of three parts: ① a geometric model: based on the system's 3D design drawings, using parametric modeling methods to accurately recreate the layout of all pipelines and equipment from the hydrogen storage tank to the fuel cell stack, achieving a modeling accuracy of LOD400 level; ② a physical model: integrating computational fluid dynamics (using the k-ε turbulence model and component transport model), heat transfer (conduction, convection, radiation), and electrochemical models (Bu The system includes: ① The Teller-Volmer equation and the Nernst equation, used to simulate hydrogen flow, diffusion, chemical reactions, and other processes; ② Behavioral rules: control logic embedded in all controllers, actuators, and sensors, including PID control algorithms, state machines, and safety interlock logic; ③ A multiphysics simulation engine based on the finite volume method, supporting transient and steady-state simulations; ④ AI diagnostic and prediction models, including LSTM time-series prediction networks, XGBoost classification models, and CNN feature extraction networks; ⑤ A response strategy generation and simulation verification module, generating candidate strategies based on a rule engine and optimization algorithms.

[0044] In this implementation, the application layer serves as the human-computer interaction interface, providing the remote monitoring center with a web graphical interface and a mobile app, supporting real-time data visualization, historical data query, early warning information management, and remote control functions.

[0045] In terms of methodology and process, such as Figure 2As shown, the process begins with real-time data acquisition. The acquired data is then uploaded, synchronized with the digital twin, and fed into the parallel computing and diagnostic stage of the digital twin. This stage consists of two parallel paths, branch A and branch B. Branch A first performs real-time anomaly detection and performance evaluation, then determines if any abnormal deviations are found. If an abnormal deviation is found, root cause analysis is initiated to locate potential faults. If no abnormal deviation is found, the system is continuously monitored. Branch B sequentially performs fault injection and simulation, then completes future risk trend prediction and AI predictive maintenance analysis. After both branches complete their operations, they enter a unified judgment stage to check if the pre-warning conditions are met. If the conditions are met, an enhanced pre-warning is generated and sent. If the conditions are not met, the process returns to the real-time data acquisition step. After the warning is issued, the process continues to determine if an actual emergency event has occurred. If no actual emergency event occurs, the process directly returns to the real-time data acquisition stage. If an actual emergency event occurs, a three-level post-event response mechanism is initiated, sequentially completing risk level assessment, simulation verification and optimization, and execution response. After all actions are completed, the system state is restored, and the process finally returns to the real-time data acquisition step, forming a closed-loop operation. The complete process includes the following steps: Step 1: The process begins with real-time data acquisition from the hydrogen fuel cell system.

[0046] More specifically, at the data level, the system collects the following multi-source operational data in real time: Direct safety parameters: (A) Hydrogen concentration: real-time concentration values ​​(%LEL) at multiple sampling points, with a sampling frequency of 1Hz; (B) Temperature: pipeline surface temperature, fuel cell stack operating temperature, and cabin ambient temperature, with a sampling frequency of 1Hz; (C) Pressure: hydrogen storage tank pressure, pressure before and after the pressure reducing valve, and fuel cell stack anode inlet pressure, with a sampling frequency of 10Hz; System operating parameters: Stack status: stack voltage, output current, single cell voltage uniformity, sampling frequency 10Hz; Fluid system parameters: hydrogen circulation pump / fan speed and current, coolant flow rate and pressure, anode-cathode pressure difference, sampling frequency 5Hz; Actuator status: the on / off status of each solenoid valve / control valve, valve position feedback signal, action time, and records when the status changes; Controller signal: The deviation between the control command and feedback signal of the key component, with a sampling frequency of 10Hz.

[0047] Environmental parameters: ambient temperature and humidity inside the cabin, sampling frequency 0.1Hz; operating status of ventilation equipment (start / stop), fan speed, recorded when status changes; external wind speed and direction, sampling frequency 0.1Hz.

[0048] The data processing flow includes three main steps: (A) Data cleaning: noise is removed by using a sliding window filtering algorithm and outliers are removed by using the Laida criterion; (B) Data fusion: sensor data of different frequencies and units are aligned and fused under a unified timestamp to form a system state vector with a dimension of 50+; (C) Feature engineering: time-domain features (mean, variance, peak value), frequency-domain features (FFT transform), and trend features (slope, curvature) are extracted.

[0049] Step 2: Data Upload and Synchronization with the Digital Twin. The collected multi-source operational data is uploaded to the cloud and drives the digital twin to achieve synchronous mapping with the physical entity.

[0050] Step 3: Parallel computation and diagnosis of the digital twin. This step is the core processing stage and is divided into two parallel branches.

[0051] Branch A (Routine Monitoring and Diagnosis): Performs real-time anomaly detection and performance evaluation; if an abnormal deviation is found between the measured data and the simulation data, root cause analysis is initiated to locate potential faults.

[0052] 1) Nonlinear PEM fuel cell system model, i.e.: (1); in, It is a system state variable. and These represent the system output and input signals, respectively. For the system matrix, Represents the real number field; It is a nonlinear continuous function; and It is a constant matrix, and and Full rank, For unknown disturbances, represent The derivative of .

[0053] Formula (1) constructs the state-space model of the nonlinear PEM fuel cell system, providing an accurate mathematical basis for subsequent fault diagnosis and system monitoring, and realizing an effective description of complex dynamic behavior.

[0054] Fault Its norm satisfies: (2); in, Representative fault The norm; Representative fault The norm of the derivative; and Boundary constraint values ​​representing the fault norm.

[0055] Formula (2) defines the norm constraint condition of system faults, providing a boundary basis for the quantitative analysis of faults and the subsequent design of observers, and ensuring the robustness of fault detection.

[0056] 2) Observer design model, namely: Assumption definition The observer design model is as follows: (3); in, , , and Representing state variables respectively The derivative of the estimated value; Representing state variables respectively The estimated value; , , , , These represent the observer model coefficient matrix; , , , These represent the nonlinear functions of the observer model, respectively. Represents the correlation coefficient of unknown disturbances; Represents unknown disturbance The estimated value; Represents the system output signal; Represents the system input signal; This represents the estimated value of the system output signal.

[0057] Formula (3) establishes an observer model for state estimation. By introducing an equivalent output error injection term, it achieves high-precision real-time reconstruction of the internal state of the system, laying the foundation for anomaly detection.

[0058] Injecting terms for equivalent output error: (4); in, Represents the error variable; and Represents the adaptive gain coefficient; Represents a symbolic function; Represents the error compensation term; Represents the gain self-update term; and The gain coefficient of the compensation term; Represents the observer's self-updating gain; Represents time; The derivative represents the error compensation term.

[0059] Formula (4) defines the key equivalent output error injection term in the observer and adopts an adaptive gain mechanism to effectively improve the tracking performance and stability of the observer under unknown disturbances.

[0060] in, Will be through gain Self-updating: (5); in, The derivative of the observer gain L(t) is represented.

[0061] Formula (5) describes the self-updating law of the observer gain, which can be dynamically adjusted according to the system error, thereby enhancing the observer's adaptability to model uncertainty and external disturbances.

[0062] For unknown disturbances Estimate: (6); in, For unknown disturbances The derivative of the estimate; This is the gain function for perturbation estimation.

[0063] Formula (6) provides an online estimation method for unknown disturbances in the system, which decouples the disturbances from the faults and significantly improves the accuracy and reliability of subsequent fault diagnosis.

[0064] Fault reconstruction algorithms, specifically, include: Define the estimation error as and Error formula: (7); in, This represents the estimation error of unknown disturbances; , , , This represents the estimation error of state variables x1 to x4; The derivative of the nonlinear function g3; and The derivatives of the nonlinear functions g1 and g2 are represented. and Represents the equivalent output error injection term; This indicates a system failure; The derivative of the nonlinear function g4; and All are coefficients.

[0065] Formula (7) defines the joint estimation error of state and fault. By constructing a composite error vector, it provides a unified analysis framework for achieving synchronized state and fault reconstruction.

[0066] (8); (9).

[0067] When the error reaches the decomposition surface ( When =0), we can obtain: (10); Formula (10) establishes the relationship between the state estimate and the true value when the error reaches the sliding surface. By utilizing the strong robustness of sliding mode control theory, the accuracy of the estimate is guaranteed.

[0068] because The fault is: (11); in, Fault The estimated value.

[0069] Formula (11) ultimately achieves accurate reconstruction of the fault signal, and can accurately estimate the size and shape of the fault within a limited time, providing a direct basis for accurate root cause analysis and graded response.

[0070] Within a finite time, the fault can be estimated using formula (11).

[0071] Branch B (Proactive Simulation and Prediction): Based on the current state, proactively inject faults and conduct simulation simulations to predict future risk trends; at the same time, the AI ​​model performs predictive maintenance analysis.

[0072] Step 4: Determine if an alert should be generated: Based on the analysis results of Step 3, determine whether the conditions for a pre-warning alert are met. If yes, generate and send an enhanced pre-warning alert to the monitoring center; if not, return to the data collection step and continue monitoring.

[0073] Step 5: Determine if an actual event has occurred: Based on direct detection by physical sensors or comprehensive judgment by the cloud, confirm whether an emergency event such as a hydrogen leak has occurred; if so, proceed with the three-level post-event response mechanism; if not, continue monitoring.

[0074] In this implementation, the three-level post-event response mechanism specifically includes: Risk level assessment: The risk level (Level 1, Level 2, or Level 3) is determined by combining the leakage concentration, the rate of increase, and the simulation results of the digital twin. Simulation verification and optimization: Before the final response action is executed, the preset response strategy is sent to the digital twin for simulation pre-run, and the best response strategy is selected based on the simulation results; Execution response: The optimized best response strategy is distributed to each sub-module of the hydrogen fuel cell system (such as ventilation system, fuel supply system, fire protection system, etc.) for execution; End / Return: After the response action is completed, the system status returns to normal, and the process returns to the initial data acquisition step, forming a continuously running intelligent safety closed loop; In this implementation, the digital twin performs the following core diagnostic and prediction tasks: (1) Real-time synchronization and state mapping.

[0075] The processed multi-source data is injected into the digital twin to drive it to keep synchronized with the hydrogen fuel cell system; the synchronization error is controlled within 1% to ensure that the digital twin can accurately reflect the status of the hydrogen fuel cell system.

[0076] (2) Anomaly detection and root cause analysis.

[0077] Twenty-dimensional feature data, including stack voltage, total stack current, auxiliary machine current, output voltage, hydrogen pressure, stack outlet hydrogen pressure, stack inlet hydrogen pressure, coolant inlet pressure, air inlet pressure, module inlet hydrogen pressure, coolant temperature, stack coolant outlet temperature, stack coolant inlet temperature, air compressor inlet air temperature, air outlet temperature, ambient temperature, intercooler temperature, module inlet coolant temperature, hydrogen leakage concentration, and coolant flow rate, are collected as fault feature vectors. A total of 800 sets of system operation data were collected, including 200 sets each of four health states: hydrogen leakage, low air pressure, excessively high stack inlet coolant temperature, and excessively low pressure. Fault codes F1 for hydrogen leakage, F2 for low air pressure, F3 for excessively high stack inlet coolant temperature, and F4 for excessively low pressure were defined after training. Measured and simulated values ​​were continuously compared. When the deviation exceeded a threshold, root cause analysis was triggered to locate potential faults based on the fault codes (e.g., ...). Figure 3 As shown), assuming the system identifies a hydrogen leak as the fault, it then compares the normal pressure at different valve assembly locations with the normal pressure threshold to pinpoint the leak location (e.g., ...). Figure 4 (As shown).

[0078] (3) Forward-looking simulation and deduction.

[0079] Hydrogen safety is primarily caused by hydrogen leaks, necessitating a focus on prevention. Based on the current system state, a hydrogen leak fault (pressure regulator leak) is proactively injected into the digital twin. The system's geometric model is simplified, and CFD calculations are used to simulate hydrogen leak diffusion. Figure 5As shown, the hydrogen concentration distribution at various points in the cabin can be predicted in the future. The flammable area range can be determined based on the fact that the flammable range of the gas after hydrogen and dry air are mixed at normal pressure is 4% to 74%.

[0080] Virtual sensors are set up in the simulation based on the actual sensor layout and number in the system. The sensors detect the hydrogen concentration at each point when it reaches the thresholds of 10% LEL, 25% LEL and 50% LEL, as well as the threshold of concentration rise rate of 1% LEL / minute. The system provides alarm time and leakage level to trigger different response mechanisms.

[0081] (4) AI intelligent diagnosis and prediction.

[0082] LSTM networks are used to analyze time series data and predict future trends of key parameters; XGBoost models are used for multi-class fault diagnosis to identify common fault modes; and the remaining useful life (RUL) of components is predicted based on survival analysis theory. Typical outputs may be: "The remaining useful life of the circulating pump is about 200 hours" or "The probability of leakage in the next 4 hours is 15%".

[0083] In this implementation, regarding the early warning mechanism, corresponding preventative measures are taken based on the prediction results: (1) Level 1 warning (early warning).

[0084] Triggering conditions: Early abnormal features are detected, such as "abnormal control current characteristics of the solenoid valve, suspected valve core jamming"; System response: A yellow warning indicator is displayed on the monitoring interface; a predictive maintenance work order is generated, suggesting "inspect / replace components during the next planned downtime"; the system continues to operate normally, but monitoring of relevant parameters is strengthened.

[0085] (2) Level II early warning (fault early warning).

[0086] Triggering conditions: Identify a clear fault development trend, such as "digital twin simulation shows that the performance degradation of the circulating water pump will lead to local overheating of the fuel cell stack"; System Response: Display an orange warning indicator on the monitoring interface and issue an audible alert; send a warning notification to the mobile phones of maintenance personnel; the system can automatically enter "conservative operation mode" and appropriately reduce the output power (e.g., reduce to 80% of the rated power); increase the sampling frequency of sensor data in relevant areas.

[0087] (3) Sensor health warning.

[0088] Triggering conditions: A sensor malfunction is diagnosed, such as "the hydrogen sensor reading is inconsistent with the surrounding sensors and simulation data"; System response: Reduce the weight of the sensor data in the control logic; rely more on the simulation data of the digital twin or other related sensors for judgment; prompt for sensor calibration or replacement.

[0089] When physical sensors confirm a leak or the digital twin determines that an emergency has been entered, the system initiates a three-level post-event response mechanism. Before executing the response action, the system can simulate and verify the response command in the digital twin to select the optimal strategy.

[0090] Level 1 Response (Low Risk / Early Warning Level) Triggering Conditions (meeting any one of the following is sufficient): Hydrogen concentration at a single monitoring point >10%LEL but <25%LEL; Concentration rise rate <1%LEL / minute; Digital twin simulation shows a small leakage amount and no risk of accumulation.

[0091] The linked submodules and actions under the first-level response include: Alarm module: Triggers a yellow visual warning on the local control room HMI and cloud monitoring center interface; emits a soft but continuous alert sound (volume < 60dB); warning information includes leak location, concentration value and trend prediction.

[0092] Ventilation system: Send instructions to the ventilation system controller to start or speed up the explosion-proof ventilation fan in the area where the leak point is located; increase the ventilation volume to 150%-200% of the rated air volume; continue to run until the concentration drops to a safe level (<5% LEL).

[0093] Data logging module: Triggers continuous event data recording function, recording all relevant operating parameters and sensor data at a frequency of 10Hz; recording time covers 30 minutes before and after the event; data is encrypted and stored for subsequent analysis.

[0094] More specifically, under a Level 1 response, power generation will not be interrupted; only early warning and auxiliary measures will be taken.

[0095] Level 2 response (medium risk / control level) triggering conditions (any one of the following needs to be met): hydrogen concentration at one or more monitoring points ≥25%LEL but <50%LEL; concentration rise rate ≥1%LEL / minute; digital twin confirms leak point and predicts risk escalation; obvious component failure is detected, such as solenoid valve jamming or pipeline rupture.

[0096] The linkage submodules and actions under the second-level response specifically include: Inherit Level 1 Response: Automatically execute all Level 1 response actions.

[0097] Alarm escalation: The warning is upgraded to a local audible and visual alarm (rotating lighthouse, high-frequency buzzer, volume > 80dB); an emergency alarm notification is sent to the mobile phones of maintenance personnel, including handling suggestions; the accident area is highlighted in orange on the monitoring interface.

[0098] Gas supply cut-off: Upon receiving the command, the fuel supply system immediately closes the upstream solenoid valve on the leak path; a regional isolation strategy is adopted to cut off the gas supply only in the fault area without affecting other parts; the valve position feedback signal is uploaded for verification in real time.

[0099] Power Management: Upon receiving a load reduction command, the power generation system controller smoothly reduces the output power within 30 seconds; depending on the severity of the leak, it reduces the power to 50% of the rated power or switches to no-load operation / standby mode; it stops hydrogen consumption to prevent the accident from escalating.

[0100] Safety interlock: prohibits unauthorized personnel from entering the accident area; activates continuous recording of area video surveillance.

[0101] More specifically, under a Level 2 response, the focus is on controlling the situation, preventing it from escalating, and, if necessary, implementing partial shutdowns.

[0102] Level 3 response (high risk / catastrophic level) trigger conditions (any one of the following is sufficient): hydrogen concentration at the monitoring point ≥ 50% LEL; concentration surges to more than 20% LEL within 1 minute; digital twin simulation predicts that it is about to reach the lower explosive limit; large-scale leakage is confirmed (such as pipeline rupture, storage tank leakage); ignition source is detected at the same time (such as open flame, high temperature surface).

[0103] The linked sub-modules and actions under the three-level response include: Inherit from Level 1 and Level 2 responses: Automatically execute the aforementioned related actions.

[0104] Highest level alarm: Triggers an emergency broadcast across the entire plant / site, playing preset evacuation instructions; automatically sends an alarm containing precise location, risk level, and on-site conditions to the safety manager and fire department via a dedicated communication interface; displays the alarm information in full red on the monitoring interface.

[0105] Hydrogen shut-off across the entire system: Send the highest priority command to the fuel supply system to urgently close the main hydrogen valve; simultaneously close all area valves to completely isolate the hydrogen source; monitor and confirm valve position status in real time.

[0106] Emergency venting: Immediately activate the emergency venting system and open the vent valve; safely guide the residual hydrogen in the system pipeline and fuel cell stack to the outdoor high-altitude combustion tower or dilution device through the dedicated vent pipe; the venting process should be completed within 2-5 minutes.

[0107] Forced shutdown: Sends an emergency shutdown command to the main controller of the power generation system; the system immediately stops all power generation processes, and the power output drops to zero within 10 seconds; executes electrical interlocking to prevent misoperation.

[0108] Fire alarm linkage: Send dry contact signals or standard protocol (such as Modbus TCP) commands to the fire protection system; activate the fire sprinkler system or inert gas (such as nitrogen) injection system in the accident area; ensure that the fire protection system pressure is normal and its operation is reliable.

[0109] Emergency power supply: Activate the backup power system to ensure power supply to the safety system; switch critical monitoring equipment to UPS power supply.

[0110] Data preservation: Back up all operational data and event logs to secure storage; prepare the basic data for incident analysis reports.

[0111] More specifically, under a Level 3 response, the focus is on ensuring the safety of personnel and equipment and preventing catastrophic accidents.

[0112] A key innovation of this invention is the simulation verification performed before executing the response action, specifically including the following steps: Strategy generation: Based on the rule engine and case library, generate 2 to 3 candidate response strategies; Digital twin simulation: Send candidate strategies to the digital twin for rapid simulation; Effectiveness evaluation assesses each strategy's: A) Effectiveness: Whether the risk concentration can be reduced to a safe level within the expected timeframe; B) Negative impacts: Whether it will cause system pressure shocks or lead to hydrogen accumulation in another location; C) Economics: Production losses and recovery costs incurred. Strategy selection: Select the comprehensive optimal strategy based on a multi-objective optimization algorithm; Execution and Feedback: Execute the optimal strategy and feed the actual results back to the system for model optimization.

[0113] Figure 6 A hydrogen fuel cell safety graded response system is shown, comprising: The data synchronization unit 601 is configured to: acquire multi-source operating data of the hydrogen fuel cell system, and perform synchronization data mapping between the digital twin and the hydrogen fuel cell system based on the multi-source operating data; The parallel diagnostic unit 602 is configured to perform routine monitoring and diagnosis and proactive prediction in parallel within the digital twin. Routine monitoring and diagnosis detects anomalies and performs root cause analysis by comparing the deviation between measured data and simulation data. Proactive prediction predicts risk trends by injecting faults into the digital twin and performing simulation. The graded response unit 603 is configured to: provide early warning or execute post-event response based on the results of routine monitoring and diagnosis and active inference and prediction; if post-event response is executed, the risk level is jointly assessed based on the leakage concentration, the rate of increase of concentration and the simulation conclusion of the digital twin, and after the preset response strategy is verified by simulation in the digital twin, the optimized best response strategy is sent to the hydrogen fuel cell system for execution.

[0114] It is understood that the aforementioned units can be individually or entirely merged into one or more other units, or some of the units can be further divided into multiple functionally smaller units. This achieves the same operation without affecting the technical effects of the embodiments of the present invention. The aforementioned units are based on logical functional division. In practical applications, the function of one unit can be implemented by multiple units, or the function of multiple units can be implemented by one unit. In other embodiments of the present invention, the system may also include other units. In practical applications, these functions can also be implemented with the assistance of other units, and can be implemented collaboratively by multiple units.

[0115] According to another embodiment of the present invention, the system of this embodiment can be constructed by running a computer program (including program code) capable of performing the steps involved in the corresponding method of the present invention on a general-purpose computing device, such as a computer, which includes processing elements and storage elements such as a central processing unit (CPU), random access memory (RAM), and read-only memory (ROM). The computer program can be recorded on, for example, a computer-readable recording medium, loaded into the aforementioned computing device through the computer-readable recording medium, and run therein.

[0116] Figure 7 A computer device is shown, which includes a processor 701, a communication interface 702, and a computer-readable storage medium 703. The processor 701, communication interface 702, and computer-readable storage medium 703 can be connected via a bus or other means.

[0117] The communication interface 702 is used to receive and send data. The computer-readable storage medium 703 can be stored in the memory of the electronic device. The computer-readable storage medium 703 is used to store computer programs, which include program instructions. The processor 701 is used to execute the program instructions stored in the computer-readable storage medium 703.

[0118] The processor 701 is the computing and control core of an electronic device. It is suitable for implementing one or more instructions, specifically for loading and executing one or more instructions to achieve the corresponding method flow or corresponding function.

[0119] Processor 701 is configured to perform the following procedure: Acquire multi-source operating data of the hydrogen fuel cell system, and perform synchronous data mapping between the digital twin and the hydrogen fuel cell system based on the multi-source operating data; Routine monitoring and diagnosis and proactive prediction are performed in parallel within the digital twin. Routine monitoring and diagnosis detects anomalies and analyzes root causes by comparing the deviations between measured data and simulation data. Proactive prediction injects faults into the digital twin to perform simulation and predict risk trends. Based on the results of routine monitoring and diagnosis and proactive simulation and prediction, early warning or post-event response is carried out. If post-event response is carried out, the risk level is jointly assessed based on the leakage concentration, the rate of increase in concentration and the simulation results of the digital twin. After the preset response strategy is verified by simulation in the digital twin, the optimized best response strategy is sent to the hydrogen fuel cell system for execution.

[0120] This invention also provides a computer-readable storage medium, which is a memory device in an electronic device for storing programs and data. It is understood that the computer-readable storage medium here may include both built-in storage media in the electronic device and extended storage media supported by the electronic device. The computer-readable storage medium provides storage space for storing the processing system of the electronic device.

[0121] Furthermore, this storage space also contains one or more instructions suitable for loading and execution by the processor. These instructions can be one or more computer programs (including program code). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory; alternatively, it can also be at least one computer-readable storage medium located remotely from the aforementioned processor.

[0122] In one embodiment, the computer-readable storage medium stores one or more instructions; the processor loads and executes the one or more instructions stored in the computer-readable storage medium to perform the following process: Acquire multi-source operating data of the hydrogen fuel cell system, and perform synchronous data mapping between the digital twin and the hydrogen fuel cell system based on the multi-source operating data; Routine monitoring and diagnosis and proactive prediction are performed in parallel within the digital twin. Routine monitoring and diagnosis detects anomalies and analyzes root causes by comparing the deviations between measured data and simulation data. Proactive prediction injects faults into the digital twin to perform simulation and predict risk trends. Based on the results of routine monitoring and diagnosis and proactive simulation and prediction, early warning or post-event response is carried out. If post-event response is carried out, the risk level is jointly assessed based on the leakage concentration, the rate of increase in concentration and the simulation results of the digital twin. After the preset response strategy is verified by simulation in the digital twin, the optimized best response strategy is sent to the hydrogen fuel cell system for execution.

[0123] The present invention also provides a computer program product or computer program comprising computer instructions stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the electronic device to perform the following process: Acquire multi-source operating data of the hydrogen fuel cell system, and perform synchronous data mapping between the digital twin and the hydrogen fuel cell system based on the multi-source operating data; Routine monitoring and diagnosis and proactive prediction are performed in parallel within the digital twin. Routine monitoring and diagnosis detects anomalies and analyzes root causes by comparing the deviations between measured data and simulation data. Proactive prediction injects faults into the digital twin to perform simulation and predict risk trends. Based on the results of routine monitoring and diagnosis and proactive simulation and prediction, early warning or post-event response is carried out. If post-event response is carried out, the risk level is jointly assessed based on the leakage concentration, the rate of increase in concentration and the simulation results of the digital twin. After the preset response strategy is verified by simulation in the digital twin, the optimized best response strategy is sent to the hydrogen fuel cell system for execution.

[0124] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this invention can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can implement the described functions using different methods for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0125] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of the present invention is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in or transmitted through a computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic cable, digital cable) or wireless (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data processing device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc.

[0126] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for graded safety response of hydrogen fuel cells, characterized in that, Includes the following processes: Acquire multi-source operating data of the hydrogen fuel cell system, and perform synchronous data mapping between the digital twin and the hydrogen fuel cell system based on the multi-source operating data; Routine monitoring and diagnosis and proactive prediction are performed in parallel within the digital twin. Routine monitoring and diagnosis detects anomalies and analyzes root causes by comparing the deviations between measured data and simulation data. Proactive prediction injects faults into the digital twin to perform simulation and predict risk trends. Based on the results of routine monitoring and diagnosis and proactive simulation and prediction, early warning or post-event response is carried out. If post-event response is carried out, the risk level is jointly assessed based on the leakage concentration, the rate of increase in concentration and the simulation results of the digital twin. After the preset response strategy is verified by simulation in the digital twin, the optimized best response strategy is sent to the hydrogen fuel cell system for execution.

2. The hydrogen fuel cell safety graded response method as described in claim 1, characterized in that, Providing early warnings, including: When routine monitoring and diagnosis identify early abnormal characteristics, or when proactive inference and prediction identify a clear fault development trend, an early warning is issued. Among these, early abnormal characteristics include abnormal control current characteristics of actuators in the hydrogen fuel cell system, and fault development trends include performance degradation of key components in the hydrogen fuel cell system leading to abnormal system status.

3. The hydrogen fuel cell safety graded response method as described in claim 2, characterized in that, After providing early warning, the process also includes: displaying visual warning signs of the corresponding level on the human-machine interface; generating predictive maintenance work orders; and controlling the hydrogen fuel cell system to enter a conservative operation mode to reduce output power based on the severity of the fault development trend.

4. The hydrogen fuel cell safety graded response method as described in claim 1, characterized in that, The actuator status of a hydrogen fuel cell includes the on / off status of a solenoid valve or regulating valve and valve position feedback signals. The optimal response strategy includes: action commands to control the solenoid valve or regulating valve, and verification of the action execution results through valve position feedback signals.

5. The hydrogen fuel cell safety graded response method as described in claim 1, characterized in that, After performing routine monitoring and diagnosis and proactive prediction in parallel within the digital twin, it also includes: If routine monitoring and diagnosis detect abnormal deviations between measured data and simulation data, root cause analysis is initiated. Potential faults are located based on preset fault codes, and corresponding fault models are injected into the proactive inference and prediction based on the location information of potential faults.

6. The hydrogen fuel cell safety graded response method as described in claim 5, characterized in that, The system acquires feature data including stack voltage, total stack current, auxiliary machine current, output voltage, hydrogen pressure, coolant temperature, and hydrogen leakage concentration as fault feature vectors, inputs them into a pre-trained XGBoost classification model, and outputs the corresponding fault codes.

7. The hydrogen fuel cell safety graded response method as described in claim 1, characterized in that, Active projection and prediction, including: Hydrogen leakage faults are injected into the geometric model of the digital twin. Computational fluid dynamics model is used to simulate hydrogen leakage and diffusion, predict the hydrogen concentration distribution at various points in the cabin in the future, and determine the range of flammable areas based on the hydrogen concentration distribution.

8. The hydrogen fuel cell safety graded response method as described in claim 7, characterized in that, The flammable zone is determined based on the hydrogen concentration distribution, including: In the geometric model of the digital twin, virtual sensors are set up according to the actual sensor placement locations to monitor the time and rate of increase of hydrogen concentration at each virtual sensor when it reaches a preset threshold.

9. The hydrogen fuel cell safety graded response method as described in claim 1, characterized in that, Active projection and prediction also include: Long Short-Term Memory (LSTM) networks are used to analyze time-series data from multi-source operational data to predict future trends of key parameters and predict the remaining useful life of key components based on survival analysis theory.

10. The hydrogen fuel cell safety graded response method as described in claim 1, characterized in that, Risk levels are categorized into Level 1, Level 2, and Level 3 risks. The optimized best response strategy will be deployed to the hydrogen fuel cell system for execution, including: If the risk level is Level 1, the ventilation system will be controlled to increase the ventilation volume, and the data logging module will be triggered to record data before and after the event at a high frequency. If it is a level 2 risk, then in addition to executing the level 1 risk response actions, control the fuel supply system to close the upstream solenoid valve on the leakage path and control the power generation system controller to reduce the output power; If the risk level is level three, in addition to the response actions for level one and level two risks, the fuel supply system will be controlled to shut down the main hydrogen valve, the emergency venting system will be activated, and an emergency shutdown command will be sent to the main controller of the power generation system.

11. The hydrogen fuel cell safety graded response method as described in claim 1, characterized in that, The pre-defined response strategy is simulated and verified in a digital twin, including: Multiple candidate response strategies are generated based on a rule engine. These strategies are then sent to a digital twin for rapid simulation to evaluate the effectiveness, negative impact, and cost-effectiveness of each strategy. Finally, a multi-objective optimization algorithm is used to select the optimal strategy from the candidate strategies as the best response strategy.

12. A hydrogen fuel cell safety graded response system, characterized in that, It includes the physical layer, data transmission layer, cloud digital twin layer, and application layer; The physical layer includes the stationary hydrogen fuel cell power generation system entity, sensor network, actuator array, and local controller; The data transmission layer is used to upload multi-source operational data collected by the sensor network to the cloud digital twin layer, and to send the response strategy generated by the cloud digital twin layer to the local controller, so that the local controller can control the operation of the stationary hydrogen fuel cell power generation system based on the actuator array; The cloud-based digital twin layer includes a data-driven and synchronization module for constructing a digital twin, which is used to execute the hydrogen fuel cell safety graded response method as described in any one of claims 1 to 11; The application layer is used to provide the human-computer interaction interface.

13. The hydrogen fuel cell safety graded response system as described in claim 12, characterized in that, A digital twin includes a geometric model, a physical model, and behavioral rules; The geometric model is constructed based on the system's three-dimensional design drawings; The physical model integrates computational fluid dynamics, heat transfer, and electrochemical models. Behavioral rules are embedded in the control logic of all controllers, actuators, and sensors.

14. The hydrogen fuel cell safety graded response system as described in claim 12, characterized in that, The sensor network includes a hydrogen concentration sensor array, temperature sensors, pressure sensors, electrical parameter sensors, flow sensors, and vibration sensors; the hydrogen concentration sensor array is arranged in the hydrogen storage tank area, pressure reducing valve group, fuel cell stack anode inlet, fuel cell stack anode outlet, vents, and the top and bottom of the compartment; the actuator array includes solenoid valves, regulating valves, ventilation fans, and emergency venting devices.

15. A hydrogen fuel cell safety graded response system, characterized in that, include: The data synchronization unit is configured to: acquire multi-source operating data of the hydrogen fuel cell system, and perform synchronization data mapping between the digital twin and the hydrogen fuel cell system based on the multi-source operating data; The parallel diagnostic unit is configured to perform routine monitoring and diagnosis and proactive inference and prediction in parallel within the digital twin. Routine monitoring and diagnosis detects anomalies and performs root cause analysis by comparing the deviation between measured data and simulation data. Proactive inference and prediction predicts risk trends by injecting faults into the digital twin and performing simulation inference. The graded response unit is configured to: provide early warning or execute post-event response based on the results of routine monitoring and diagnosis and proactive inference and prediction; if a post-event response is executed, the risk level is jointly assessed based on the leakage concentration, the rate of increase in concentration and the simulation conclusions of the digital twin, and the preset response strategy is verified by simulation in the digital twin before the optimized best response strategy is sent to the hydrogen fuel cell system for execution.

16. A computer device, characterized in that, include: Processor and computer-readable storage media; A processor, adapted to execute computer programs; A computer-readable storage medium storing a computer program that, when executed by the processor, implements the hydrogen fuel cell safety graded response method as described in any one of claims 1 to 11.

17. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program adapted to be loaded by a processor and executed as described in any one of claims 1 to 11.

18. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the hydrogen fuel cell safety graded response method as described in any one of claims 1 to 11.