A power grid operation site dangerous area intelligent identification and early warning method

By collecting and processing multi-source heterogeneous data, and utilizing three-dimensional digital twin scenarios and safety momentum assessment models, hidden risks at power grid operation sites can be identified and warned. This solves the problem of insufficient perception of dynamic risks in existing technologies, realizes the transformation from post-event alarm to pre-event warning, and improves the preventive capabilities of power grid operation safety management.

CN122435752APending Publication Date: 2026-07-21SICHUAN RES INST OF SHANGHAI JIAOTONG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SICHUAN RES INST OF SHANGHAI JIAOTONG UNIV
Filing Date
2026-03-03
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing technologies lack the ability to proactively perceive the dynamic and hidden risk accumulation trends at power grid operation sites, and the rule base cannot learn and evolve autonomously from historical data, resulting in insufficient adaptability to complex scenarios.

Method used

Collect multi-source heterogeneous data and perform timestamp alignment and spatial coordinate system transformation to generate a spatiotemporally synchronized multi-dimensional perception data stream. Utilize a three-dimensional digital twin scene for calculation and logical judgment, calculate the risk momentum vector through a safety momentum assessment model, perform counterfactual reasoning analysis and optimize safety rules, and generate the final early warning instruction.

Benefits of technology

It enables early warning of risk trends at power grid operation sites, providing trend warnings during the incubation stage of potential accidents, improving the prevention level of safety management, and transforming from passive alarm after the fact to proactive early warning during and before the event.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122435752A_ABST
    Figure CN122435752A_ABST
Patent Text Reader

Abstract

The application discloses a kind of power grid operation site dangerous area intelligent identification and early warning method, it is related to electric power system safety technical field, including, acquisition multi-source heterogeneous data, and carry out time stamp alignment and spatial coordinate system conversion, generate time-space synchronous multidimensional perception data flow;Real-time driving three-dimensional digital twin scene using multidimensional perception data flow, based on the initial safety rule library of preset in three-dimensional digital twin scene calculation and logic judgment, output dynamic digital twin scene and basic risk event record;Basic risk event record is input to safety momentum assessment model.The present application realizes the fundamental change from after-the-fact passive alarm to in-process, before the event active early warning, so that safety management personnel can obtain trend warning in the incubation stage of potential accident (i.e.before phase change occurs), so there is a more sufficient time window to take preventive intervention measures, greatly improve the prevention level of power grid operation safety.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power system safety technology, and in particular to a method for intelligent identification and early warning of dangerous areas at power grid operation sites. Background Technology

[0002] With the development of smart grids and the Industrial Internet, on-site safety management in power grid operations is gradually shifting from traditional methods to technology-based prevention and control. Current mainstream technologies utilize IoT sensing devices such as video surveillance, UWB positioning, and RFID to build on-site monitoring networks. This enables the identification of personnel wearing safety equipment and the monitoring of static electronic fence areas, triggering alarms when boundary violations or improper equipment wearing is detected. This approach automates the monitoring of some overt violations, improving regulatory coverage and response speed, and represents a transition in on-site safety from manual inspection to automated monitoring.

[0003] Existing technologies have limitations in the foresight and adaptability of risk identification. They respond to immediate and explicit states based on preset static rules, and the safety rule base is fixed. While they can effectively handle known and clearly located typical risks, they lack the ability to perceive and warn of the non-immediate accumulation trends of risks caused by the dynamic interaction of multiple factors such as personnel behavior, environment, and equipment during operations. For example, minor anomalies that occur continuously on-site without triggering alarms may not violate rules individually, but their aggregation over time may indicate significant risks. Existing technologies lack correlation analysis and dynamic modeling of risk events over time, cannot quantify the risk accumulation process, and struggle to provide trend warnings before a qualitative change in the situation. The fixed rule base cannot learn autonomously from massive amounts of daily data and cannot discover complex risk coupling patterns not covered by the rules, resulting in the system's identification capabilities being difficult to continuously evolve and insufficient adaptability to new or complex scenarios. Summary of the Invention

[0004] In view of the aforementioned existing problems, the present invention is proposed.

[0005] Therefore, this invention provides an intelligent identification and early warning method for dangerous areas at power grid operation sites to solve the problems of existing technologies lacking forward-looking perception of dynamic and hidden risk accumulation trends, and the rule base being unable to autonomously learn and evolve from historical data.

[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution:

[0007] In a first aspect, the present invention provides a method for intelligent identification and early warning of dangerous areas at power grid operation sites, which includes collecting multi-source heterogeneous data, performing timestamp alignment and spatial coordinate system-unified transformation, and generating a spatiotemporally synchronized multidimensional sensing data stream;

[0008] The system utilizes multi-dimensional perception data streams to drive a 3D digital twin scene in real time. Based on a pre-set initial security rule base, it performs calculations and logical judgments within the 3D digital twin scene, outputting a dynamic digital twin scene and basic risk event records.

[0009] The basic risk event records are input into the safety momentum assessment model. The risk momentum vector is calculated based on the event type weight and time decay factor. Based on the magnitude and direction of the risk momentum vector, a risk trend early warning signal is generated.

[0010] Perform counterfactual reasoning analysis on near-miss events in the basic risk event record, construct and deduce counterfactual virtual scenarios in the digital twin environment, test the boundaries of the initial security rule base, generate a security rule iteration optimization suggestion report, and output the optimized security rules;

[0011] By integrating basic risk event records, risk trend warning signals, and optimized security rules, a multi-level warning decision engine is used to generate the final warning instruction.

[0012] As a preferred embodiment of the intelligent identification and early warning method for hazardous areas in power grid operation sites described in this invention, the method involves: collecting multi-source heterogeneous data, performing timestamp alignment and spatial coordinate system-unified transformation, and generating a spatiotemporally synchronized multidimensional sensing data stream, including the following steps:

[0013] Acquire multi-source heterogeneous data, and attach a high-precision timestamp to each data packet in the multi-source heterogeneous data to form multi-source heterogeneous data with timestamps;

[0014] All spatial coordinate data in the multi-source heterogeneous data with timestamps are transformed to the same preset spatial coordinate system, forming multi-source heterogeneous data that has undergone timestamp alignment and spatial coordinate system unification transformation.

[0015] Multi-source heterogeneous data that has been timestamped and transformed by a unified spatial coordinate system are integrated according to time series and spatial relationships to generate a spatiotemporally synchronized multidimensional sensing data stream.

[0016] As a preferred embodiment of the intelligent identification and early warning method for hazardous areas in power grid operation sites described in this invention, the method includes: using multi-dimensional sensing data streams to drive a three-dimensional digital twin scene in real time; performing calculations and logical judgments within the three-dimensional digital twin scene based on a preset initial safety rule base; and outputting a dynamic digital twin scene and basic risk event records, comprising the following steps:

[0017] The state and spatial coordinates of personnel, equipment and environmental elements in the three-dimensional digital twin scene are updated using the multi-dimensional sensing data stream to form a dynamic digital twin scene that reflects changes in the physical scene in real time.

[0018] In dynamic digital twin scenarios, spatial relationship calculations and security logic judgments are performed based on a pre-set initial security rule base.

[0019] The expression for calculating spatial relationships is:

[0020] ;

[0021] in, This is a violation of spatial relationship rules. For the twin's spatial position vector - object 1, For the twin's spatial position vector - object 2, Geometric relation rules;

[0022] The security logic judgment expression is:

[0023] ;

[0024] in, For the result of the security logic judgment, For security logic rules, This is a dynamic threshold parameter;

[0025] Based on the results of spatial relationship calculations and security logic judgments performed on a pre-set initial security rule base, specific events that violate the entries of the initial security rule base are identified.

[0026] Specific events that violate the initial security rule base entries are encapsulated into structured logs to generate basic risk event records.

[0027] As a preferred embodiment of the intelligent identification and early warning method for hazardous areas at power grid operation sites described in this invention, the method includes the following steps: inputting basic risk event records into a safety momentum assessment model, and calculating the risk momentum vector based on event type weights and time decay factors:

[0028] Extract the event type, risk intensity value, and event timestamp from the basic risk event records;

[0029] The event type is queried from the preset event type-weight mapping table to obtain the corresponding event type weight coefficient.

[0030] Calculate the time decay factor using the event timestamp and the current time, employing a decay function.

[0031] The expression for the time decay factor is:

[0032] ;

[0033] in, The time decay factor, For the current time, The timestamp of the event. The attenuation coefficient;

[0034] The risk intensity value is obtained from the basic risk event record. The event type weight coefficient and time decay factor are multiplied by the risk intensity value to calculate the momentum contribution value of a single event.

[0035] The expression for the momentum contribution of a single event is:

[0036] ;

[0037] in, The momentum contribution value for a single event. This refers to the event type weighting coefficient. This represents the risk intensity value.

[0038] The risk momentum vector is calculated by vector superimposing the momentum contribution values ​​of all individual events according to the directional components corresponding to their event types.

[0039] The expression for the risk momentum vector is:

[0040] ;

[0041] in, For risk momentum vector, The total number of basic risk events recorded. Index of basic risk event records, For a single event, the vector component in a specific type of direction;

[0042] As a preferred embodiment of the intelligent identification and early warning method for hazardous areas in power grid operation sites described in this invention, the method includes the following steps: generating a risk trend early warning signal based on the magnitude and direction of the risk momentum vector.

[0043] The magnitude of the risk momentum vector is calculated based on the risk momentum vector, and the magnitude of the risk momentum vector is compared with several preset thresholds.

[0044] The expression for the magnitude of the risk momentum vector is:

[0045] ;

[0046] in, The magnitude of the risk momentum vector. For the spatial coordinate axes The momentum component in the direction, For the spatial coordinate axes The momentum component in the direction, For the spatial coordinate axes The momentum component in the direction;

[0047] Based on the comparison of the magnitude of the risk momentum vector with multiple preset thresholds, the preliminary warning level is determined, the direction of the risk momentum vector is obtained, the direction of the risk momentum vector is mapped to a preset direction-risk type lookup table, and the dominant risk type is determined.

[0048] By combining the initial warning level with the dominant risk type, a structured risk trend warning signal is generated.

[0049] As a preferred embodiment of the intelligent identification and early warning method for hazardous areas at power grid operation sites described in this invention, the method includes the following steps: performing counterfactual reasoning analysis on near-missed events in the basic risk event record.

[0050] Filter through the basic risk event records to identify basic risk event records whose event type is marked as "nearly missed";

[0051] By leveraging historical multidimensional perception data streams associated with near-miss basic risk event records, the complete scene sequence before and after an event can be accurately reproduced in a digital twin environment;

[0052] Based on the recreated complete scene sequence, multiple counterfactual assumptions are constructed. The counterfactual assumptions are then substituted into the recreated complete scene sequence to generate multiple corresponding counterfactual virtual scenes.

[0053] In each counterfactual virtual scenario, the safety momentum assessment model and the initial safety rule base are used to recalculate risks and make safety logic judgments.

[0054] Collect and analyze the results of risk calculation and safety logic judgment based on the application of the safety momentum assessment model and the preset initial safety rule base, and obtain counterfactual reasoning analysis of near-miss events in the basic risk event record.

[0055] As a preferred embodiment of the intelligent identification and early warning method for hazardous areas at power grid operation sites described in this invention, the method includes the following steps: constructing and simulating a counterfactual virtual scenario in a digital twin environment, testing the boundaries of the initial safety rule base, generating a safety rule iterative optimization suggestion report, and outputting the optimized safety rules.

[0056] In a digital twin environment, a counterfactual virtual scenario is constructed based on counterfactual assumptions, and the result of the counterfactual virtual scenario is derived.

[0057] The boundaries of the initial security rule base are tested using the results of counterfactual virtual scenario simulations. Based on the results of testing the boundaries of the initial security rule base, a security rule iterative optimization suggestion report is generated.

[0058] Based on the security rule iterative optimization suggestion report, the optimized security rules are output.

[0059] As a preferred embodiment of the intelligent identification and early warning method for hazardous areas at power grid operation sites described in this invention, the method integrates basic risk event records, risk trend early warning signals, and optimized safety rules, and generates a final early warning instruction through a multi-level early warning decision engine, including the following steps:

[0060] Based on a multi-level early warning decision engine, it receives basic risk event records, risk trend early warning signals, and optimized security rules;

[0061] The multi-level early warning decision engine integrates basic risk event records, risk trend early warning signals, and optimized security rules to generate a fusion decision basis.

[0062] The multi-level early warning decision engine uses a fusion decision foundation to generate the final early warning command.

[0063] In a second aspect, the present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, wherein when the computer program is executed by the processor, it implements any step of the intelligent identification and early warning method for dangerous areas at power grid operation sites as described in the first aspect of the present invention.

[0064] Thirdly, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, it implements any step of the intelligent identification and early warning method for dangerous areas at power grid operation sites as described in the first aspect of the present invention.

[0065] The beneficial effects of this invention are as follows: It records discrete, instantaneous basic risk events, introduces event type weights to distinguish the importance of different risks, and uses a time decay factor to simulate the continuous decay of risk impact, calculating a comprehensive risk momentum vector. The magnitude of this vector reflects the overall intensity of risk accumulation, and its direction indicates the dominant risk type, generating risk trend early warning signals. This overcomes the limitation of existing technologies that can only respond to single, immediate, and explicit risk events. Its function is to expand the perspective of safety monitoring from a point to a field, enabling the system to perceive the non-immediate risk accumulation trend caused by the superposition of multiple minor violations or abnormal states over time. This achieves a fundamental shift from reactive post-event alarms to proactive in-event and pre-event warnings, allowing safety managers to receive trend warnings during the gestation stage of potential accidents (i.e., before qualitative changes occur), thus providing a more sufficient time window for preventative intervention measures and greatly improving the prevention level of power grid operation safety. Attached Figure Description

[0066] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0067] Figure 1 A flowchart for a method for intelligent identification and early warning of hazardous areas at power grid operation sites. Detailed Implementation

[0068] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0069] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.

[0070] Secondly, the term "one embodiment" or "example" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the invention. The appearance of an embodiment in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that mutually excludes other embodiments.

[0071] Reference Figure 1 As one embodiment of the present invention, this embodiment provides a method for intelligent identification and early warning of hazardous areas at power grid operation sites, comprising the following steps:

[0072] S1. Collect multi-source heterogeneous data, perform timestamp alignment and spatial coordinate system transformation to generate a spatiotemporally synchronized multidimensional sensing data stream.

[0073] S1.1. Obtain multi-source heterogeneous data, and attach a high-precision timestamp to each data packet in the multi-source heterogeneous data to form multi-source heterogeneous data with timestamps.

[0074] Furthermore, multi-source heterogeneous data is acquired from multiple sources, including video surveillance equipment deployed at power grid operation sites, ultra-wideband positioning base stations, wearable sensors, environmental parameter monitoring units, and power grid monitoring interfaces. These data differ in their generation time, format, and transmission delay. To establish a unified time reference for subsequent analysis, a high-precision timestamp from a unified time source must be appended to each independently arriving multi-source heterogeneous data packet at the receiving entry point. The accuracy of the high-precision timestamp is typically at the millisecond or microsecond level to ensure that rapidly occurring events can be distinguished. After this operation, the original, time-ambiguous multi-source heterogeneous data is transformed into structured, timestamped multi-source heterogeneous data, laying a precise time alignment foundation for all subsequent processing steps.

[0075] S1.2. All spatial coordinate data in the multi-source heterogeneous data with timestamps are converted to the same preset spatial coordinate system to form multi-source heterogeneous data that has been timestamp aligned and spatial coordinate system unified.

[0076] Furthermore, processing the spatial information in multi-source heterogeneous data with timestamps is crucial. Since different sensing devices have their own independent spatial reference systems—for example, video surveillance uses an image pixel coordinate system, global navigation satellite system equipment uses a geodetic coordinate system, and on-site local positioning networks may use a custom Cartesian coordinate system—all these diverse spatial coordinate data are transformed into the same preset, globally unified spatial coordinate system. This preset unified spatial coordinate system is usually a three-dimensional Cartesian coordinate system with a fixed point at the work site as the origin. Through pre-calibrated coordinate transformation matrices or parameters, each set of spatial coordinate data in the multi-source heterogeneous data with timestamps is transformed, resulting in the result that all spatial coordinate data has been transformed into the same preset spatial coordinate system. This process forms the key multi-source heterogeneous data that has undergone timestamp alignment and unified spatial coordinate system transformation, eliminating ambiguity in spatial dimensions.

[0077] S1.3 Integrate the multi-source heterogeneous data that has been timestamped and transformed by a unified spatial coordinate system according to time series and spatial relationships to generate a spatiotemporally synchronized multidimensional sensing data stream.

[0078] Furthermore, the multi-source heterogeneous data, after being timestamped and transformed by a unified spatial coordinate system, is deeply fused. This fusion is not a simple accumulation, but rather a strict alignment of all data streams on the timeline based on high-precision timestamps, and slicing and synchronizing them according to nanosecond or millisecond time windows. At the same time, using the unified spatial coordinates, data from different sources describing the same spatial location or the same physical entity are spatially correlated and integrated. For example, the location coordinates of a person at the same moment, the video frame from their helmet camera, and the environmental wind speed data at that location are bound together. Through this integration operation based on time sequence and spatial relationship, a spatiotemporally synchronized multi-dimensional sensing data stream that can accurately reflect the comprehensive state of the physical scene at every moment and at every location is ultimately generated.

[0079] S2. Utilize multi-dimensional perception data streams to drive the three-dimensional digital twin scene in real time. Based on a preset initial security rule base, perform calculations and logical judgments in the three-dimensional digital twin scene, and output dynamic digital twin scene and basic risk event records.

[0080] S2.1. Utilize the multidimensional sensing data stream to update the status and spatial coordinates of personnel, equipment, and environmental elements in the three-dimensional digital twin scene, forming a dynamic digital twin scene that reflects changes in the physical scene in real time.

[0081] Furthermore, multidimensional sensing data streams are used to drive and update pre-constructed 3D digital twin scenes in real time. A 3D digital twin scene is a virtualized representation that includes power grid equipment models, worker models, engineering machinery models, and terrain environment models. When multidimensional sensing data streams are continuously input, the data is parsed, and based on the object types and unique identifiers in the data, the corresponding personnel models, equipment models, and environmental element models are found in the 3D digital twin scene. The real-time position coordinates, attitude angles, equipment switching status, environmental parameter values, and other state information contained in the multidimensional sensing data streams are directly assigned to these 3D models. This allows the position, attitude, and state of the virtual models in the 3D digital twin scene to keep pace with the real-time state of the real objects in the physical scene, forming a dynamic digital twin scene that can mirror the dynamics of the real world with millisecond-level latency.

[0082] S2.2 In dynamic digital twin scenarios, spatial relationship calculations and security logic judgments are performed based on a preset initial security rule base.

[0083] Furthermore, risk detection is performed based on the formed dynamic digital twin scenario. The preset initial security rule base contains a series of formalized geometric relationship rules and security logic rules. The spatial relationship calculation function CheckSpatialRelation is called. The input parameters of this function include the three-dimensional coordinates of the two objects that need to be judged in real time from the dynamic digital twin scenario, namely the twin spatial position vector - object 1 and the twin spatial position vector - object 2, as well as the geometric relationship rules specified from the preset initial security rule base that are applicable to these two object types. The geometric relationship rules define the type of spatial relationship to be judged, such as minimum Euclidean distance, spatial containment relationship or line-of-sight occlusion relationship, and specify the corresponding thresholds. The spatial relationship calculation function CheckSpatialRelation calculates the geometric relationship between the two twin spatial position vectors and compares it with the threshold in the geometric relationship rules. It outputs a Boolean value or enumeration value as the spatial relationship violation status, indicating whether the spatial relationship violates the rules. Subsequently, the safety logic judgment function EvaluateRule is called. This function takes the spatial relationship violation status as one of its inputs, and combines it with safety logic rules related to the current scenario obtained from the preset initial safety rule base, as well as dynamic threshold parameters that may be determined by the environment or device status. The safety logic rules define more complex conditional logic. For example, a high-risk event is only determined when the spatial relationship violation status is true and the object's movement speed exceeds the dynamic threshold parameter. The safety logic judgment function EvaluateRule executes these logical judgments and finally outputs a safety logic judgment result, which may be a risk level or a specific alarm type identifier.

[0084] The expression for calculating spatial relationships is:

[0085] ;

[0086] in, This is a violation of spatial relationship rules. For the twin's spatial position vector - object 1, For the twin's spatial position vector - object 2, These are geometric relationship rules.

[0087] The security logic judgment expression is:

[0088] ;

[0089] in, For the result of the security logic judgment, For security logic rules, This is a dynamic threshold parameter.

[0090] S2.3. Based on the results of spatial relationship calculation and security logic judgment performed on the preset initial security rule base, identify specific events that violate the entries of the initial security rule base.

[0091] Furthermore, the security logic judgment results are analyzed. When the security logic judgment result indicates that a rule has been violated, that is, the output is an unsafe state or a specific alarm indicator, then a specific event that violates the initial security rule base entry is identified. This specific event includes core information such as the time of the event, the virtual object involved, the violated rule entry, and the calculated risk level.

[0092] S2.4 Encapsulate the specific events that violate the initial security rule base entries into structured logs to generate basic risk event records.

[0093] Furthermore, the specific events that violate the initial security rule base entries are encapsulated into structured logs. The structured logs adopt a predefined format, such as JSON or XML, which includes a fixed event timestamp, event unique identifier, event type code, list of associated object identifiers, the violated rule ID, calculated risk intensity value, and the three-dimensional spatial coordinate field of the event occurrence. Through this standardized encapsulation, discrete and instantaneous events are transformed into data units that can be uniformly processed, stored, and analyzed by subsequent processes, thereby generating basic risk event records.

[0094] S3. Input the basic risk event records into the safety momentum assessment model, and calculate the risk momentum vector based on the event type weight and time decay factor.

[0095] S3.1 Extract the event type, risk intensity value, and event occurrence timestamp from the basic risk event records.

[0096] Furthermore, the input basic risk event records are parsed. Based on a predefined structured log format, the event type field, risk intensity value field, and event occurrence timestamp field are read and separated from each basic risk event record. The event type field is usually a code used to identify the specific category of the event, such as safe distance intrusion or failure to wear security equipment. The risk intensity value field is a numerical value that quantifies the immediate severity of the event. The event occurrence timestamp field is a high-precision time value that records the moment the event occurred. This completes the extraction of event type, risk intensity value, and event occurrence timestamp from the basic risk event records.

[0097] S3.2 Query the preset event type-weight mapping table according to the event type to obtain the corresponding event type weight coefficient.

[0098] Furthermore, using the event type extracted from the basic risk event records as the query key, a preset event type-weight mapping table is accessed. This event type-weight mapping table is a statically configured set of mapping relationships, in which a corresponding event type weight coefficient is predefined for each possible event type. The event type weight coefficient is a real number greater than zero, reflecting the differences in importance and influence of different types of events in risk accumulation. For example, event types involving high-voltage electric shock risks may be assigned a higher event type weight coefficient, while event types involving improper wearing of personal protective equipment are assigned a lower event type weight coefficient. By looking up the table, the corresponding event type weight coefficient that precisely matches the current event type is obtained, thus completing the query of the preset event type-weight mapping table based on the event type and obtaining the corresponding event type weight coefficient.

[0099] S3.3 Calculate the time decay factor using the event timestamp and the current time through the decay function.

[0100] Furthermore, using the event timestamp extracted from the basic risk event records and the current time at the time of calculation (provided by a unified clock source to ensure consistency), the time interval since the event occurred is obtained by subtracting the event timestamp from the current time. This time interval is then substituted into the decay function along with a preset decay coefficient greater than zero. The decay function is an exponential decay function, which ensures that the value of the time decay factor monotonically decreases from 1 to 0 as time passes after the event. The decay coefficient controls the decay rate; the larger the decay coefficient, the faster the event's influence weakens over time. Through this calculation, the time decay factor D, which characterizes the current remaining influence of the event, is obtained, thus completing the calculation of the time decay factor using the event timestamp and the current time and the decay function.

[0101] The expression for the time decay factor is:

[0102] ;

[0103] in, The time decay factor, For the current time, The timestamp of the event. This is the attenuation coefficient.

[0104] S3.4 Obtain the risk intensity value from the basic risk event record, multiply the event type weight coefficient and time decay factor by the risk intensity value, and calculate the momentum contribution value of a single event.

[0105] Furthermore, a scalar multiplication operation is performed on the event type weighting coefficient, the time decay factor, and the risk intensity value obtained from the basic risk event records. This calculation comprehensively considers the inherent severity of the event, the importance of the event type, and the time decay effect after the event occurs, thereby outputting a momentum contribution value of a single event after time and type adjustment that can represent the contribution of the event to the current overall risk status. This completes the process of obtaining the risk intensity value from the basic risk event records and multiplying the event type weighting coefficient, the time decay factor, and the risk intensity value to calculate the momentum contribution value of a single event.

[0106] The expression for the momentum contribution of a single event is:

[0107] ;

[0108] in, The momentum contribution value for a single event. This refers to the event type weighting coefficient. This represents the risk intensity value.

[0109] S3.5. The momentum contribution values ​​of all individual events are vector-superimposed according to the directional components corresponding to their event types to calculate the risk momentum vector.

[0110] Furthermore, a normalized direction vector is defined for each event type in a predefined abstract risk space. This direction vector is the direction component corresponding to the event type. For example, mechanical risk, electrical risk, and fall from height risk can be mapped to the X-axis, Y-axis, and Z-axis directions of a spatial rectangular coordinate system, respectively. Then, the momentum contribution value of each individual event is multiplied by the unit vector of the direction component corresponding to its event type to obtain the vector component of the individual event in a specific type direction. This operation converts the scalar contribution value into a vector with directional attributes. Finally, the vector components of the individual events corresponding to all basic risk events in a specific type direction are summed according to the vector addition rule to gather the directional contributions of all events into a comprehensive vector, namely the risk momentum vector M. The magnitude of this risk momentum vector M represents the intensity of the overall risk accumulation, and its direction indicates the currently dominant risk type combination. This completes the vector superposition of the momentum contribution values ​​of all individual events according to the direction components corresponding to their event types and calculates the risk momentum vector.

[0111] The expression for the risk momentum vector is:

[0112] ;

[0113] in, For risk momentum vector, The total number of basic risk events recorded. Index of basic risk event records, For a single event, the vector component in a specific type direction.

[0114] S4. Generate a risk trend warning signal based on the magnitude and direction of the risk momentum vector.

[0115] S4.1 Calculate the magnitude of the risk momentum vector based on the risk momentum vector, and compare the magnitude of the risk momentum vector with multiple preset thresholds.

[0116] Furthermore, using the calculated risk momentum vector as input, the magnitude of the risk momentum vector is first calculated. The risk momentum vector is a vector in a predefined multidimensional risk space, and its components can be understood as projection values ​​on different abstract risk dimensions. Under the common setting of a three-dimensional risk space, the risk momentum vector can be expressed as having... , , The form of three components, in which Let be the momentum component along the x-axis in space. Let be the momentum component along the y-axis in space. Let M be the momentum component along the z-axis of the spatial coordinate system. These three components correspond to the accumulated amounts of different types of risks. To obtain a scalar value that measures the overall intensity of risk accumulation, the magnitude of the risk momentum vector needs to be calculated using the Euclidean norm formula. The calculated magnitude M of the risk momentum vector is a non-negative real number; the larger the value, the more severe the overall risk accumulation situation. After obtaining the magnitude of the risk momentum vector, it is compared with several preset thresholds. These preset thresholds are a predefined set of increasing values, such as a first threshold and a second threshold, used to divide different risk accumulation stages. The comparison operation is a process of sequentially judging whether the magnitude M of the risk momentum vector is greater than or equal to these thresholds, thereby determining which threshold interval the magnitude M falls into. This completes the calculation of the magnitude of the risk momentum vector based on the risk momentum vector and the comparison of the magnitude of the risk momentum vector with the preset thresholds.

[0117] The expression for the magnitude of the risk momentum vector is:

[0118] ;

[0119] in, The magnitude of the risk momentum vector. For the spatial coordinate axes The momentum component in the direction, For the spatial coordinate axes The momentum component in the direction, For the spatial coordinate axes The momentum component in the direction;

[0120] S4.2. Based on the comparison of the magnitude of the risk momentum vector with multiple preset thresholds, determine the preliminary warning level, obtain the direction of the risk momentum vector, map the direction of the risk momentum vector to the preset direction-risk type comparison table, and determine the dominant risk type.

[0121] Furthermore, based on simple interval mapping logic, for example, if the magnitude of the risk momentum vector is less than a first threshold, the initial warning level is no warning; if the magnitude of the risk momentum vector is greater than or equal to the first threshold but less than a second threshold, the initial warning level is attention; and if the magnitude of the risk momentum vector is greater than or equal to the second threshold, the initial warning level is a warning. This initial warning level reflects the overall intensity level of risk accumulation. Simultaneously, it is necessary to obtain the directional information from the risk momentum vector. The direction of the risk momentum vector is determined by the ratio of its components, representing the relative proportion of different types of risks. To understand the specific risk meaning represented by the direction, it is necessary to analyze the risk momentum... The direction of a vector is mapped to a pre-defined direction-risk type lookup table. This table defines the interpretation of the dominant risk type corresponding to unit vectors in different directions in a multi-dimensional risk space. For example, if the direction of the risk momentum vector mainly points to the positive X-axis, its dominant risk type can be determined by looking up the table as mechanical collision risk. If the direction mainly points to a certain angle in the plane formed by the Y-axis and Z-axis, it may correspond to a combined risk of electrical and fall from height. Through this mapping process, the abstract vector direction is transformed into a concrete and understandable description of the dominant risk type, thus completing the determination of the preliminary warning level based on the comparison results and obtaining the direction mapping to determine the dominant risk type.

[0122] S4.3. Combine the preliminary warning level with the dominant risk type to generate a structured risk trend warning signal.

[0123] Furthermore, by combining the initial warning level and the dominant risk type, the initial warning level provides information on the severity of the risk, while the dominant risk type provides information on the nature of the risk. Generating a structured risk trend warning signal involves creating a standard data structure. This data structure contains at least two core fields: one field records the initial warning level, and the other field records the dominant risk type. By encapsulating these two types of information within a unified signal structure, a structured risk trend warning signal is formed. This signal can clearly and unambiguously convey the intensity level of accumulated risk and the main risk components at the current work site, providing direct quantitative input for subsequent warning decisions. This completes the generation of a structured risk trend warning signal by combining the initial warning level and the dominant risk type.

[0124] S5. Perform counterfactual reasoning analysis on near-miss events in the basic risk event record.

[0125] S5.1 Filter out basic risk event record items from the basic risk event records whose event type is marked as nearly missed.

[0126] Furthermore, the basic risk event record set is traversed and filtered based on conditions. Each basic risk event record has a dedicated field for identifying event types. A specific event type is predefined as "nearly missed," meaning that although the event was recorded, it did not immediately lead to an accident or trigger a high-level alarm. The filtering operation involves examining the event type field of each basic risk event record, selecting all basic risk event records whose event type field values ​​are equal to "nearly missed," forming a subset. This subset contains all potentially dangerous events that require in-depth analysis to learn lessons. This completes the filtering process for basic risk event records whose event type is marked as "nearly missed."

[0127] S5.2 Utilize historical multidimensional perception data streams associated with near-miss basic risk event record items to accurately reproduce the complete scene sequence before and after the event in a digital twin environment.

[0128] Furthermore, for each near-miss basic risk event record that has been selected, it is necessary to trace back the history to reconstruct the specific context of the event. Each near-miss basic risk event record contains a unique event identifier and a precise event timestamp. Using this event timestamp, the historical multidimensional perception data stream matching the time period can be retrieved from the persistently stored historical database. The historical multidimensional perception data stream is a sequence of perception data containing complete spatiotemporal synchronization information generated and stored in the previous steps. The retrieved historical multidimensional perception data stream surrounding the time before and after the near-miss event is used as input and re-injected into the data-driven interface of the digital twin environment. Based on this historical data, the digital twin environment gradually drives the movement and state changes of models such as personnel and equipment in the 3D virtual scene, starting from a point in time before the event, accurately and frame by frame reproducing the entire process of the event from occurrence to development to end, forming a complete scene sequence that is accurately reproduced in the digital world. This completes the accurate reproduction of the complete scene sequence before and after the event in the digital twin environment using the historical multidimensional perception data stream associated with the near-miss basic risk event record.

[0129] S5.3 Based on the reproduced complete scene sequence, construct multiple counterfactual assumptions, substitute the counterfactual assumptions into the reproduced complete scene sequence, and generate multiple corresponding counterfactual virtual scenes.

[0130] Furthermore, counterfactual deduction is conceived based on the recreated complete scene sequence. Counterfactual assumptions are purposeful and controllable modifications to historical facts. They are constructed based on the analysis of the causes of near-miss events or the enumeration of potential aggravating factors. For example, it can be assumed that the wind speed at the time was one level higher than the actual recorded value, or that a worker's movement path was offset to the left by half a meter, or that the response of a safety interlock device was delayed by several milliseconds. These counterfactual assumptions are defined in the form of parameter modification instructions. Each constructed counterfactual assumption is independently substituted into the previously recreated complete scene sequence. Specifically, the corresponding parameters driving the scene reproduction in the digital twin environment are modified, and then the scene evolution calculation is rerun to generate a new version of the scene that occurs in the virtual world. This new version of the scene reflects what would have happened if a certain condition had been different, that is, a corresponding counterfactual virtual scene is generated. By constructing multiple different counterfactual assumptions and substituting them into the recreated complete scene sequence, multiple different counterfactual virtual scenes can be generated in parallel. This completes the process of constructing multiple counterfactual assumptions based on the recreated complete scene sequence and substituting the counterfactual assumptions into the recreated complete scene sequence to generate multiple corresponding counterfactual virtual scenes.

[0131] S5.4 In each counterfactual virtual scenario, apply the security momentum assessment model and recalculate the risk and make security logic judgments based on the preset initial security rule base.

[0132] Furthermore, a security risk reassessment is performed on each generated counterfactual virtual scenario. Applying the security momentum assessment model means treating the counterfactual virtual scenario as a real-time scenario flow that is currently unfolding. Following the same defined process, the risk momentum vector of the basic risk event records simulated in this virtual scenario flow is calculated. At the same time, risk calculation and security logic judgment are re-performed based on a preset initial security rule base. This means that at every moment of the evolution of the counterfactual virtual scenario, functions such as CheckSpatialRelation and EvaluateRule are called to perform real-time calculation and logical judgment on the object relationships and states in the virtual scenario based on the preset initial security rule base. Thus, in this hypothetical virtual scenario, new basic risk event records that may differ from the historical ones and calculated risk momentum may also be generated. This completes the application of the security momentum assessment model and the re-performation of risk calculation and security logic judgment based on the preset initial security rule base in each counterfactual virtual scenario.

[0133] S5.5 Collect and analyze the results of recalculating risks and making safety logic judgments using the applied safety momentum assessment model and based on the preset initial safety rule base, and obtain counterfactual reasoning analysis of near-miss events in the basic risk event record.

[0134] Furthermore, in the analysis of each counterfactual virtual scenario, key result data is extracted. For example, under a certain counterfactual assumption, did a higher level of risk warning occur? Did a new type of risk event that had not occurred in history appear? Or did the magnitude of the risk momentum vector exceed a higher threshold? The analysis operation involves summarizing and comparing these collected results. The aim is to answer key questions such as under what assumptions the original near miss event will deteriorate into a real accident, under what boundary conditions the existing preset initial safety rule base will fail, and under what small changes in risk factors will lead to significantly different consequences. By answering these questions, a profound insight into the vulnerability and rule blind spots behind the original near miss event is formed. This insight is the counterfactual reasoning analysis of near miss events in the basic risk event record. The results of collecting and analyzing the application of the safety momentum assessment model and recalculating risk and making safety logic judgments based on the preset initial safety rule base are used to obtain the counterfactual reasoning analysis of near miss events.

[0135] S6. Construct and simulate counterfactual virtual scenarios in a digital twin environment, test the boundaries of the initial security rule base, generate a security rule iteration and optimization suggestion report, and output the optimized security rules.

[0136] S6.1 Construct counterfactual virtual scenarios based on counterfactual assumptions in a digital twin environment, and deduce the counterfactual virtual scenarios to obtain the deduction results of the counterfactual virtual scenarios.

[0137] Furthermore, the constructed counterfactual virtual scenario is simulated and the results are obtained. Simulating the counterfactual virtual scenario means activating the simulation engine of the digital twin environment. Starting from the initial state and modified parameters of the counterfactual virtual scenario, the virtual objects in the scenario are driven to evolve forward on the timeline according to predefined physical laws and behavioral models, simulating the entire possible development process of events under counterfactual conditions. The simulation result of the counterfactual virtual scenario is a collection of all state and event data generated at the end of this simulation process. This collection includes at least all basic risk event records recalculated under counterfactual conditions, the calculated final risk momentum vector, and all warning information triggered during the process. These data fully record the hypothetical consequences if the conditions were different. The simulation of the counterfactual virtual scenario is completed to obtain the simulation results of the counterfactual virtual scenario.

[0138] S6.2. Test the boundaries of the initial security rule base using the results of the counterfactual virtual scenario. Based on the results of testing the boundaries of the initial security rule base, generate a security rule iterative optimization suggestion report.

[0139] Furthermore, the results of the counterfactual scenario deduction are structurally analyzed to extract key risk judgment outputs. These outputs include the safety logic judgment results obtained by reapplying the initial safety rule base for risk calculation and safety logic judgment under counterfactual conditions, and the magnitude of the risk momentum vector calculated by reapplying the safety momentum assessment model. These data represent the existing rule framework's perception and assessment of the risk situation under the modified assumptions. Testing the boundaries of the initial safety rule base involves comparing these assessment results under counterfactual conditions with a pre-set, recognized safety baseline or a more stringent judgment standard. For example, a principle can be set: under any reasonable or foreseeable counterfactual conditions, the magnitude of the risk momentum vector should not exceed a certain absolute safety upper limit, or certain high-risk types of safety logic judgment results should not be triggered. By comparing, it is found that the results of the counterfactual scenario deduction violate this principle, such as the magnitude of the risk momentum vector exceeding the absolute safety upper limit. This clearly indicates that the initial safety rule base has insufficient assessment or missing coverage under the scenario category represented by the counterfactual assumption. This process of discovering the boundaries is essentially an exploratory stress test of the rule's effective domain. Based on the test results, a safety rule iteration optimization suggestion report is generated. Report generation is a logical process of summarizing and writing. For each identified rule boundary failure case, the report must clearly record three elements: the specific counterfactual assumptions that led to the failure, the specific risk indicators triggered at the time of failure such as the safety logic judgment result exceeding the threshold or the magnitude of the risk momentum vector, and the index or description of the relevant rule entries in the initial safety rule base involved. Based on these records, the report further generates specific optimization suggestions. The suggestions directly target the modification of the rule clauses. For example, it may point out that the Xth Rlogic safety logic rule in the initial safety rule base is not sensitive enough to Y-type environmental parameters, and suggest adding a judgment branch for Y-type parameters in the rule conditions. Or, it may point out that the fixed threshold Tthreshold used by the Zth Rgeo geometric relationship rule in the initial safety rule base is not conservative under condition A, and suggest modifying it to a dynamic function related to factor B. The generated safety rule iteration optimization suggestion report is a detailed and traceable document of rule defect diagnosis and repair scheme. It completes the testing of the boundaries of the initial safety rule base using the deduction results of the counterfactual virtual scenario and generates a safety rule iteration optimization suggestion report based on the test results.

[0140] S6.3, Based on the security rule iterative optimization suggestion report, output the optimized security rules.

[0141] Furthermore, the textualized patching scheme is transformed into a directly deployable rule knowledge base update. Based on the security rule iterative optimization suggestion report, optimized security rules are output. This process involves precisely editing and reconstructing the initial security rule base according to the suggestion report. For each modification suggestion in the report, the operation involves locating the corresponding rule entry in the initial security rule base and modifying its logical expression or parameters according to the suggestion. For example, an Rlogic security logic rule can be modified from a simple IF A THEN Alarm to IF A AND NOT B THEN. To eliminate false alarms, for supplementary suggestions in the report, the process involves writing entirely new rule entries and adding them to the initial safety rule base according to its syntax. For example, a new Rgeo geometric relationship rule might be added to define a previously unconsidered method for calculating the danger envelope of a specific device during rotation. All modifications and additions ensure that the newly generated rules are logically compatible with and conflict-free with other existing rules in the base. The new set of rules obtained after editing and restructuring is the optimized safety rule set. The optimized safety rule set maintains the same form as the initial safety rule base, but its content includes lessons learned from counterfactual analysis of near-miss events, enhancing its ability to identify and assess complex, boundary, or rare risks. The optimized safety rule set is then output as a report based on iterative optimization suggestions for safety rules.

[0142] S7 integrates basic risk event records, risk trend warning signals, and optimized security rules, and generates the final warning instruction through a multi-level warning decision engine.

[0143] S7.1 Receives basic risk event records, risk trend warning signals, and optimized security rules based on a multi-level early warning decision engine.

[0144] Furthermore, the multi-level early warning decision engine's reception of basic risk event records, risk trend warning signals, and optimized security rules implies the establishment of three independent and continuous data input channels. The first channel continuously receives a stream of basic risk event records, each representing an instance of an immediate risk event that violates current security rules and is detected in real time. The second channel receives risk trend warning signals, which are periodically or event-triggered updates that provide a macro-level assessment of the overall risk accumulation situation and dominant type. The third channel receives optimized security rules, which are the latest versions and include a set of formal rules enhanced by historical learning. The multi-level early warning decision engine needs to simultaneously monitor and capture input from these three channels to ensure that the latest and most comprehensive relevant information is available when a decision needs to be made. This completes the multi-level early warning decision engine's reception of basic risk event records, risk trend warning signals, and optimized security rules.

[0145] S7.2 The multi-level early warning decision engine integrates basic risk event records, risk trend early warning signals, and optimized security rules to generate a fusion decision basis.

[0146] Furthermore, the multi-level early warning decision engine integrates basic risk event records, risk trend early warning signals, and optimized safety rules to generate a fusion decision basis. This integration process involves logical association and information enhancement. First, based on time windows and spatial location, the multi-level early warning decision engine correlates newly arriving basic risk event records with currently active risk trend early warning signals to determine whether the immediate event occurred under a high-risk accumulation situation or a relatively stable background. Simultaneously, the multi-level early warning decision engine analyzes optimized safety rules, particularly those clauses related to the current event type and situation, to understand how to interpret the current risk input under the latest knowledge framework. For example, a basic risk event record regarding personnel approaching equipment, when compared with a… Once a risk trend warning signal, primarily indicating electrical risk, is associated with another risk, its importance is amplified. Optimized safety rules may include dynamic adjustments to the safe distance of the equipment under specific operating conditions, providing a more precise benchmark for assessing the event. Through this association, retrieval, and context construction, the multi-level warning decision engine transforms raw, discrete input information into a unified, semantically rich snapshot of the decision-making context. This snapshot is the fusion decision foundation, integrating information on what immediate event occurred, the overall risk trend on-site, and how to make a judgment based on the latest knowledge. This completes the integration of basic risk event records, risk trend warning signals, and optimized safety rules by the multi-level warning decision engine to generate the fusion decision foundation.

[0147] S7.3, the multi-level early warning decision engine uses a fusion decision foundation to generate the final early warning command.

[0148] Furthermore, the multi-level early warning decision engine uses a fusion decision foundation to generate a final early warning instruction. This step involves a pre-defined, hierarchical decision logic. The multi-level early warning decision engine analyzes the information contained in the fusion decision foundation, assesses the overall urgency, scope of impact, and potential evolution path of the current risk, and, based on a predefined decision matrix or strategy tree, determines what level, type, and target of the early warning to issue. For example, the fusion decision foundation may show that a high-risk basic risk event is currently occurring in a high-risk accumulation situation area, and optimized safety rules indicate that such a complex situation requires immediate evacuation. In this case, the multi-level early warning decision engine will generate a final early warning instruction of the highest level. This instruction has a clear structure and typically includes an early warning level code, a list of target objects or areas, recommended or mandatory actions, and the validity period of the early warning. The generated final early warning instruction will be formatted and prepared for distribution to designated terminal devices or personnel via a communication network, thus completing the closed loop from risk perception to the triggering of protective actions, and completing the generation of the final early warning instruction by the multi-level early warning decision engine using the fusion decision foundation.

[0149] This embodiment also provides a computer device applicable to the intelligent identification and early warning method for dangerous areas at power grid operation sites, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to realize the intelligent identification and early warning method for dangerous areas at power grid operation sites as proposed in the above embodiment.

[0150] The computer device can be a terminal, comprising a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, carrier networks, NFC (Near Field Communication), or other technologies. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the computer device's casing, or an external keyboard, touchpad, or mouse.

[0151] This embodiment also provides a storage medium storing a computer program. When executed by a processor, the program implements the intelligent identification and early warning method for hazardous areas at power grid operation sites as proposed in the above embodiments. The storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Red-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0152] In summary, this invention records discrete, instantaneous basic risk events, introduces event type weights to distinguish the importance of different risks, and utilizes a time decay factor to simulate the continuous decay of risk impact, calculating a comprehensive risk momentum vector. The magnitude of this vector reflects the overall intensity of risk accumulation, while its direction indicates the dominant risk type, generating risk trend early warning signals. This overcomes the limitation of existing technologies that can only respond to single, immediate, and explicit risk events. Its function is to expand the perspective of safety monitoring from a point to a field, enabling the system to perceive the non-immediate risk accumulation trend caused by the superposition of multiple minor violations or abnormal states over time. This achieves a fundamental shift from reactive post-event alarms to proactive in-event and pre-event warnings, allowing safety managers to receive trend warnings during the gestation stage of potential accidents (i.e., before qualitative changes occur), thus providing a more sufficient time window for preventative intervention measures and significantly improving the prevention level of power grid operation safety.

[0153] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for intelligent identification and early warning of hazardous areas at power grid operation sites, characterized in that: This includes collecting multi-source heterogeneous data, performing timestamp alignment and spatial coordinate system transformation, and generating a spatiotemporally synchronized multidimensional sensing data stream; The system utilizes multi-dimensional perception data streams to drive a 3D digital twin scene in real time. Based on a pre-set initial security rule base, it performs calculations and logical judgments within the 3D digital twin scene, outputting a dynamic digital twin scene and basic risk event records. The basic risk event records are input into the safety momentum assessment model. The risk momentum vector is calculated based on the event type weight and time decay factor. Based on the magnitude and direction of the risk momentum vector, a risk trend early warning signal is generated. Perform counterfactual reasoning analysis on near-miss events in the basic risk event record, construct and deduce counterfactual virtual scenarios in the digital twin environment, test the boundaries of the initial security rule base, generate a security rule iteration optimization suggestion report, and output the optimized security rules; By integrating basic risk event records, risk trend warning signals, and optimized security rules, a multi-level warning decision engine is used to generate the final warning instruction.

2. The intelligent identification and early warning method for hazardous areas at power grid operation sites as described in claim 1, characterized in that: Collecting heterogeneous data from multiple sources, performing timestamp alignment and spatial coordinate system-unified transformation, and generating a spatiotemporally synchronized multidimensional sensing data stream includes the following steps: Acquire multi-source heterogeneous data, and attach a high-precision timestamp to each data packet in the multi-source heterogeneous data to form multi-source heterogeneous data with timestamps; All spatial coordinate data in the multi-source heterogeneous data with timestamps are transformed to the same preset spatial coordinate system, forming multi-source heterogeneous data that has undergone timestamp alignment and spatial coordinate system unification transformation. Multi-source heterogeneous data that has been timestamped and transformed by a unified spatial coordinate system are integrated according to time series and spatial relationships to generate a spatiotemporally synchronized multidimensional sensing data stream.

3. The intelligent identification and early warning method for hazardous areas at power grid operation sites as described in claim 2, characterized in that: The system utilizes multi-dimensional sensing data streams to drive a 3D digital twin scene in real time. Based on a pre-set initial security rule base, it performs calculations and logical judgments within the 3D digital twin scene, outputting a dynamic digital twin scene and basic risk event records. This includes the following steps: The state and spatial coordinates of personnel, equipment and environmental elements in the three-dimensional digital twin scene are updated using the multi-dimensional sensing data stream to form a dynamic digital twin scene that reflects changes in the physical scene in real time. In dynamic digital twin scenarios, spatial relationship calculations and security logic judgments are performed based on a pre-set initial security rule base. The expression for calculating spatial relationships is: ; in, This is a violation of spatial relationship rules. For the twin's spatial position vector - object 1, For the twin's spatial position vector - object 2, Geometric relation rules; The security logic judgment expression is: ; in, For the result of the security logic judgment, For security logic rules, This is a dynamic threshold parameter; Based on the results of spatial relationship calculations and security logic judgments performed on a pre-set initial security rule base, specific events that violate the entries of the initial security rule base are identified. Specific events that violate the initial security rule base entries are encapsulated into structured logs to generate basic risk event records.

4. The intelligent identification and early warning method for hazardous areas at power grid operation sites as described in claim 3, characterized in that: Inputting basic risk event records into the safety momentum assessment model, and calculating the risk momentum vector based on event type weights and time decay factors, includes the following steps: Extract the event type, risk intensity value, and event timestamp from the basic risk event records; The event type is queried from the preset event type-weight mapping table to obtain the corresponding event type weight coefficient. Calculate the time decay factor using the event timestamp and the current time, employing a decay function. The expression for the time decay factor is: ; in, The time decay factor, For the current time, The timestamp of the event. The attenuation coefficient; The risk intensity value is obtained from the basic risk event record. The event type weight coefficient and time decay factor are multiplied by the risk intensity value to calculate the momentum contribution value of a single event. The expression for the momentum contribution of a single event is: ; in, The momentum contribution value for a single event. This refers to the event type weighting coefficient. This represents the risk intensity value. The risk momentum vector is calculated by vector superimposing the momentum contribution values ​​of all individual events according to the directional components corresponding to their event types. The expression for the risk momentum vector is: ; in, For risk momentum vector, The total number of basic risk events recorded. Index of basic risk event records, For a single event, the vector component in a specific type direction.

5. The intelligent identification and early warning method for hazardous areas at power grid operation sites as described in claim 4, characterized in that: Based on the magnitude and direction of the risk momentum vector, a risk trend early warning signal is generated, including the following steps: The magnitude of the risk momentum vector is calculated based on the risk momentum vector, and the magnitude of the risk momentum vector is compared with several preset thresholds. The expression for the magnitude of the risk momentum vector is: ; in, The magnitude of the risk momentum vector. For the spatial coordinate axes The momentum component in the direction, For the spatial coordinate axes The momentum component in the direction, For the spatial coordinate axes The momentum component in the direction; Based on the comparison of the magnitude of the risk momentum vector with multiple preset thresholds, the preliminary warning level is determined, the direction of the risk momentum vector is obtained, the direction of the risk momentum vector is mapped to a preset direction-risk type lookup table, and the dominant risk type is determined. By combining the initial warning level with the dominant risk type, a structured risk trend warning signal is generated.

6. The intelligent identification and early warning method for hazardous areas at power grid operation sites as described in claim 5, characterized in that: Counterfactual analysis of nearly missed events in the basic risk event record includes the following steps: Filter through the basic risk event records to identify basic risk event records whose event type is marked as "nearly missed"; By leveraging historical multidimensional perception data streams associated with near-miss basic risk event records, the complete scene sequence before and after an event can be accurately reproduced in a digital twin environment; Based on the recreated complete scene sequence, multiple counterfactual assumptions are constructed. The counterfactual assumptions are then substituted into the recreated complete scene sequence to generate multiple corresponding counterfactual virtual scenes. In each counterfactual virtual scenario, the safety momentum assessment model and the initial safety rule base are used to recalculate risks and make safety logic judgments. Collect and analyze the results of risk calculation and safety logic judgment based on the application of the safety momentum assessment model and the preset initial safety rule base, and obtain counterfactual reasoning analysis of near-miss events in the basic risk event record.

7. The intelligent identification and early warning method for hazardous areas at power grid operation sites as described in claim 6, characterized in that: Constructing and simulating counterfactual virtual scenarios within a digital twin environment, testing the boundaries of the initial security rule base, generating a security rule iterative optimization suggestion report, and outputting optimized security rules, includes the following steps: In a digital twin environment, a counterfactual virtual scenario is constructed based on counterfactual assumptions, and the result of the counterfactual virtual scenario is derived. The boundaries of the initial security rule base are tested using the results of counterfactual virtual scenario simulations. Based on the results of testing the boundaries of the initial security rule base, a security rule iterative optimization suggestion report is generated. Based on the security rule iterative optimization suggestion report, the optimized security rules are output.

8. The intelligent identification and early warning method for hazardous areas at power grid operation sites as described in claim 7, characterized in that, By integrating basic risk event records, risk trend early warning signals, and optimized security rules, a multi-level early warning decision engine generates the final early warning instruction, including the following steps: Based on a multi-level early warning decision engine, it receives basic risk event records, risk trend early warning signals, and optimized security rules; The multi-level early warning decision engine integrates basic risk event records, risk trend early warning signals, and optimized security rules to generate a fusion decision basis. The multi-level early warning decision engine uses a fusion decision foundation to generate the final early warning command.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the intelligent identification and early warning method for dangerous areas at power grid operation sites as described in any one of claims 1 to 8.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the intelligent identification and early warning method for dangerous areas at power grid operation sites as described in any one of claims 1 to 8.