Method and apparatus for activating rollback of structured editing package-based service bulletin
By generating scope certificates and core action graphs based on structured editing packages, the problem of inaccurate control over the effective scope of maintenance notices in existing technologies is solved. This enables multi-dimensional risk prevention and precise management of maintenance knowledge, ensuring the accuracy and reliability of maintenance notices.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- XIAMEN UNIV OF TECH
- Filing Date
- 2026-07-02
- Publication Date
- 2026-07-31
AI Technical Summary
Existing technologies cannot precisely control the scope of maintenance notices, lack a mechanism for proving the source of scope fields, cannot verify the integrity and reliability of equipment objects, component objects, fault contexts and version conditions, cannot reliably identify non-target disturbances in maintenance operations, lack a consistency submission mechanism for multiple knowledge carrying layers, and cannot accurately restore the correct answer path after the notice is revoked.
A structured package editing approach is adopted to generate scope certificates, perturbation coverage vectors, core action graph fields, lifecycle states, dependency ledger relationships, and rollback pointers. The accuracy and traceability of the package editing are ensured by verifying through a verification sandbox and performing shadow writes and transactional commits in multiple bearer layers.
It has achieved multi-dimensional risk prevention and control and precise management, improved the traceability of the scope field of maintenance notices, enhanced the integrity of local rule boundary control, strengthened the stability of pollution judgment, reduced the risk of abnormal answers, and ensured the computable recovery of answer paths.
Smart Images

Figure CN122489088A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial operation and maintenance technology, and more specifically, to a method, apparatus, and equipment for activating and rolling back maintenance announcements based on structured editing packages. Background Technology
[0002] Industrial equipment maintenance knowledge bases need continuous updates to adapt to maintenance bulletins, service notices, FAQ revisions, component replacement instructions, version errata, and safety tips constantly released by equipment manufacturers, service teams, and maintenance departments. These maintenance bulletins typically have clearly defined local applicability; the same fault phenomenon may correspond to completely different handling procedures under different equipment objects, different component objects, different fault contexts, or different version boundaries. Industrial equipment maintenance systems urgently need a technical solution that can precisely control the scope of maintenance bulletins, ensuring that newly added rules do not erroneously spread to inapplicable problem scenarios.
[0003] Currently, knowledge updates for industrial equipment primarily employ technical solutions such as manual rewriting of FAQs or rule tables, RAG document synchronization, rule engine or knowledge graph updates, parameter-level knowledge editing, and canary releases. Manual rewriting involves maintenance personnel converting announcement content into question-and-answer entries or rule rows. RAG synchronization directly writes announcements as new documents into the retrieval system. Rule engine methods write rule conditions into structured storage. Parameter-level editing updates knowledge by modifying model weights or external memory items. Canary releases gradually unlock new features through traffic ratios or configuration switches. These solutions have achieved certain results in terms of knowledge update speed and coverage.
[0004] Existing technical solutions have significant shortcomings and cannot meet the needs of accurate knowledge updates for industrial equipment maintenance. These solutions lack a mechanism for proving the source of scope fields, failing to verify the integrity and reliability of equipment objects, component objects, fault contexts, and version conditions. They lack quantitative gating for sufficient coverage of non-target disturbances, only checking whether new answers can be obtained for the target question without systematically verifying whether questions outside the boundary maintain their original answer paths. Existing solutions lack structured differential contamination determination for maintenance actions, relying solely on answer text similarity judgment, which cannot reliably identify undesirable changes to the maintenance operation itself. Furthermore, these solutions lack computationally achievable isolation between the sandbox and the production question-and-answer chain, lack a consistent submission mechanism for multiple knowledge-bearing layers, lack dependency management between edit packages, and cannot accurately restore the correct answer path after an announcement is revoked. Summary of the Invention
[0005] This invention provides a method, apparatus, and device for activating and rolling back maintenance notices based on structured editing packages, in order to improve at least one of the aforementioned technical problems.
[0006] In a first aspect, the present invention provides a method for activating and rolling back maintenance notices based on structured editing packages, which includes steps S1 to S7.
[0007] S1. Receive maintenance notice, and extract equipment object, component object, fault context, version conditions, old handling rules that have been replaced and new handling rules after replacement from the maintenance notice.
[0008] S2. Generate a structured edit package based on the extraction results. The structured edit package includes a scope certificate, a disturbance coverage vector representing the non-target disturbance coverage result, a core handling action graph field representing the maintenance action structure, a lifecycle state representing the edit package's flow status, a dependency ledger relationship representing the coverage, conflict, and recovery relationships between the edit package and the basic rules, and a rollback pointer representing the rollback record location.
[0009] S3. Verify the scope certificate based on the field source evidence, normalization basis, and field confidence level.
[0010] S4. When the scope certificate is valid, generate target samples and non-target disturbance samples outside the boundary in the verification sandbox based on the device object, the component object, the fault context and the version conditions, and compare the core processing action diagrams before and after the structured editing package takes effect.
[0011] S5. A joint verification access control is formed based on the validity of the scope certificate, the integrity of the disturbance coverage, the target sample hit result, the non-target contamination result, the conflict security result, and the production visibility pre-assessment result.
[0012] S6. When the joint verification access control passes, perform a shadow write to at least one of the knowledge carrier layers, namely the rule base, retrieval index, knowledge graph, or side memory layer, and commit it to a production visible state through transactions.
[0013] S7. When a submitted structured edit package is revoked, recalculate the recovery answer path based on the dependency ledger relationship and the rollback pointer.
[0014] As a preferred aspect of the present invention, S3 specifically includes:
[0015] .
[0016] In the formula, This indicates the result of the validity determination of the scope certificate for the edit package. This indicates a candidate edit package. This indicates the result of the source traceability verification. This indicates the result of the field normalization validation. This indicates the result of the integrity check of the scoped field. This represents the weighted average of the confidence levels of each field in the scope certificate. This indicates the scope certificate of the edit package. Indicates the validity threshold of the scope certificate. Represents the logical AND operation.
[0017] .
[0018] In the formula, Indicates editing package The scope of the certificate field collection. express An index of a certificate field. Indicates the first Weights of each certificate field. Indicates scope certificate The Middle The confidence level of each field. This indicates a normalization constraint on the certificate field weights.
[0019] when When the time comes, the structured editing package is written to a blocking state, and the structured editing package is prohibited from entering the production activation process.
[0020] As a preferred aspect of the present invention, S4, which generates target samples and non-target disturbance samples outside the boundary in the verification sandbox, specifically includes: Define the user problem as: In the formula, This represents a sample of user questions. Represents a device object. Represents a component object. Indicates the fault context. Indicates version conditions. This refers to the question text or its semantic representation.
[0021] .
[0022] In the formula, This indicates that the verification sandbox is a set of editable packages. This indicates a candidate edit package. This represents the set of candidate edit packages. This represents the function for determining whether an issue in the verification sandbox matches the edit package.
[0023] .
[0024] In the formula, This represents the set of editable packages visible in the production chain. This represents the function for determining whether a problem in the production pipeline matches an edit package.
[0025] Structured edit packages in the verification state are allowed to participate in answer calculation. Only structured edit packages that have completed transactional commits and are in a production-visible state are allowed to participate in answer calculation.
[0026] As a preferred aspect of the present invention, the disturbance coverage vector of S2 is determined by device disturbance samples, component disturbance samples, fault context disturbance samples, version lower bound disturbance samples, version upper bound disturbance samples, and combined disturbance samples: .
[0027] In the formula, This represents the perturbation coverage vector of the edit package. This indicates a candidate edit package. This indicates the coverage value for the device disturbance dimension. This indicates the coverage value of the component disturbance dimension. This indicates the coverage value of the fault context perturbation dimension. This indicates the coverage value of the lower bound perturbation dimension of the version. This indicates the coverage value of the upper bound perturbation dimension of the version. This indicates the coverage value of the combined perturbation dimension, which can be 0 or 1.
[0028] .
[0029] In the formula, This indicates the result of the disturbance covering the access control system. This indicates the label of the perturbation dimension currently being inspected. Dimension labels The corresponding overriding value. Dimension labels indicating device disturbances. Dimension labels indicating component disturbances. Dimension labels representing fault context perturbations. The dimension label representing the version lower bound perturbation. The dimension label representing the version upper bound perturbation. Dimension labels representing combined perturbations. This indicates a logical conjunction of multiple conditions.
[0030] when At that time, the structured editing package is kept in the candidate state or the verification state, and the uncovered perturbation dimensions are recorded.
[0031] As a preferred aspect of the present invention, S4 compares the core processing action diagrams before and after the structured editing package takes effect, specifically including: .
[0032] In the formula, This represents the general structure of the core processing action diagram. Represents a set of action nodes. This represents the set of ordered edges. Represents a set of conditions.
[0033] .
[0034] In the formula, Indicates the first Action graph differential labeling for non-target samples. Indicates the sequence number of the non-target perturbation sample. Indicates the first One non-target perturbation sample. This indicates an indicator function that takes the value 1 when the condition within the parentheses is true, and 0 otherwise. Indicates sample The diagram shows the basic core processing actions before the edit package takes effect. Indicates sample The diagram shows the core editing actions after the candidate edit package takes effect. This indicates that two core action graphs are not equivalent in terms of action type, target component, sequence edge, or conditional constraint.
[0035] .
[0036] In the formula, This indicates the non-target pollution rate. This represents the total number of non-target perturbation samples.
[0037] when When the time comes, the structured editing package is written to the blocking state, and the structured editing package is prohibited from entering the transactional activation process.
[0038] As a preferred aspect of the present invention, S5 specifically includes: .
[0039] In the formula, This indicates that the editing package jointly verifies the access control results. This indicates a candidate edit package. This indicates the result of the validity determination of the scope certificate for the edit package. This indicates the result of the disturbance covering the access control system. This indicates the target sample hit verification result. This indicates the non-target pollution rate. This indicates the result of the conflict security verification. This indicates the results of the preliminary assessment of production visibility. Represents the logical AND operation.
[0040] .
[0041] In the formula, This represents the target sample hit function. This indicates an equivalence checker.
[0042] .
[0043] In the formula, This represents the function of the number of unresolved conflict edges, and its value is a non-negative integer.
[0044] .
[0045] In the formula, Indicates editing package The set of bearer layers that actually participated in the writing this time. express One of the carrier layer indexes. Indicates the first Each layer is for editing packages The production visibility pre-assessment results. This indicates a logical conjunction of multiple conditions.
[0046] when At that time, the structured editing package is allowed to enter the pre-submission state.
[0047] when When this happens, the structured editing package is written to a blocked state or a paused state.
[0048] As a preferred aspect of the present invention, S6 specifically includes: When the joint verification access control is passed: Shadow write is performed on at least one knowledge-bearing layer that actually participates in the writing, including the rule base, retrieval index, knowledge graph, and side memory layer, to obtain the shadow write consistency check result and the dependent ledger write readiness status.
[0049] .
[0050] In the formula, This indicates the result of the transactional submission of the edit package. This indicates a candidate edit package. This indicates that the editing package jointly verifies the access control results. This indicates the result of the shadow write consistency check. This indicates that the dependency ledger is ready to be written. Represents the logical AND operation.
[0051] when At that time, the knowledge carrier layer that actually participated in the writing will be uniformly submitted as production visible, and the lifecycle state of the structured editing package will be written as the production visible state.
[0052] when At that time, the shadow writing content is cancelled, the lifecycle state of the structured editing package is written to the active terminated state, and the production question-and-answer link is kept from reading the structured editing package.
[0053] As a preferred aspect of the present invention, S7 specifically includes: When a submitted structured edit package is revoked: .
[0054] In the formula, Indicates user issues The path to producing the answer. This represents a sample of user questions. This represents the function for selecting the answer path. This represents the currently valid set of editable packages. This represents the set of basic rules. This represents the path-dependent ledger for the answer.
[0055] .
[0056] In the formula, This indicates the path to restore the answer after undoing the edit package. This indicates that the activated edit package has been revoked. This indicates that the edited package index has been revoked. This indicates the path-dependent ledger of the updated answer after reversal. This represents the set difference operation.
[0057] The answer path selection function determines the restored answer path in the following order: First, select the preceding valid edit package whose activation time is earlier than the revoked edit package, whose activation time is the latest, and whose scope covers the user's problem sample.
[0058] When there are multiple preceding valid edit packages, select the preceding valid edit package with the more precise scope.
[0059] When the scope precision is the same, the recovery answer path is selected based on the priority of the ledger edge type.
[0060] If all valid editing packages in the preceding sequence are unavailable or still conflicting, select the basic knowledge answer path from the basic rule set and record the routing conflict status.
[0061] Secondly, the present invention provides a maintenance announcement activation and rollback device based on a structured editing package, which includes an announcement input and preprocessing module, a structured editing package generation module, a scope certificate verification module, a verification sandbox module, a joint verification access control module, a transactional activation module, and a dependency ledger rollback module.
[0062] The announcement input and preprocessing module is used to receive maintenance announcements and extract equipment objects, component objects, fault contexts, version conditions, old handling rules that have been replaced, and new handling rules after replacement from the maintenance announcements.
[0063] The structured edit package generation module is used to generate structured edit packages based on the extraction results. The structured edit package includes a scope certificate, a perturbation coverage vector representing the non-target perturbation coverage result, a core handling action graph field representing the maintenance action structure, a lifecycle state representing the edit package's flow status, a dependency ledger relationship representing the coverage, conflict, and recovery relationships between the edit package and the basic rules, and a rollback pointer representing the rollback record location.
[0064] The scope certificate verification module is used to verify the scope certificate based on the field source evidence, normalization basis, and field confidence level.
[0065] The verification sandbox module is used to generate target samples and non-target disturbance samples outside the boundary in the verification sandbox based on the device object, the component object, the fault context and the version conditions when the scope certificate is valid, and to compare the core processing action diagrams before and after the structured editing package takes effect.
[0066] The joint verification access control module is used to generate joint verification access control based on the validity of the scope certificate, the integrity of the disturbance coverage, the target sample hit result, the non-target contamination result, the conflict security result, and the production visibility pre-assessment result.
[0067] The transactional activation module is used to perform shadow writes and transactional commits to at least one knowledge-bearing layer among the rule base, retrieval index, knowledge graph, or side memory layer when the federated verification access control passes, making it production visible.
[0068] The dependency ledger rollback module is used to recalculate the recovery answer path based on the dependency ledger relationship and the rollback pointer when a submitted structured edit package is revoked.
[0069] Thirdly, the present invention provides a maintenance notice activation rollback device based on a structured editing package, which includes a processor, a memory, and a computer program stored in the memory.
[0070] The computer program can be executed by the processor to implement a maintenance notice activation rollback method based on a structured editing package, as described above.
[0071] By adopting the above technical solution, the present invention can achieve the following technical effects: This invention constructs a full-link control system from maintenance notice input to dependency ledger rollback, achieving multi-dimensional risk prevention and precise management in scenarios where industrial equipment maintenance knowledge is continuously updated. Specifically, the scope certificate significantly improves the traceability of maintenance notice scope fields by storing evidence of field source, normalization basis, and confidence status, effectively blocking candidate updates with unknown sources or incomplete boundaries from entering the production chain. The design of minimum counterfactual perturbation samples and perturbation coverage vectors transforms the originally scattered non-target boundary verification into quantifiable dimensional coverage access control, greatly improving the integrity of local rule boundary control.
[0072] Meanwhile, the core action graph differential technology shifts the non-target contamination judgment from natural language text comparison to differential analysis of maintenance operation structures, enhancing the stability and interpretability of contamination judgment. The verification sandbox and production link matching function separation mechanism ensures that candidate edit packages are only tested in an isolated environment and cannot affect the official answer before passing verification. Transactional activation and shadow writing processes achieve consistent submission across multiple layers, including the rule base, retrieval index, and knowledge graph, reducing the risk of answer anomalies caused by inconsistent writing across multiple components. The answer path dependency ledger provides a calculable basis for the revocation and recovery of activated edit packages, avoiding answer blanks or excessive rollbacks caused by simple deletion or overall rollback. Furthermore, unified edit package lifecycle state management and dual-channel visibility constraints facilitate end-to-end auditing and traceability by operations personnel and prevent unstructured content such as side memory from bypassing state control and prematurely participating in production answer generation. Attached Figure Description
[0073] To more clearly illustrate the technical solution of the present invention, the accompanying drawings used in the specific embodiments of the present invention will be briefly introduced below. It should be understood that the following drawings only show some specific embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained from these drawings without creative effort.
[0074] Figure 1 This is a system module relationship diagram.
[0075] Figure 2 This is a state machine diagram of the lifecycle of a Structured Edit Packet (SEP). Detailed Implementation
[0076] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. The described embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the scope of protection of the present invention.
[0077] Example 1, please refer to Figures 1 to 2 This embodiment provides a method for activating and rolling back maintenance notices based on structured editing packages. This method does not directly append maintenance notices as plain text to the question-and-answer knowledge base, but first converts them into structured editing packages with lifecycle states. These structured editing packages define their local scope using device objects, component objects, fault contexts, and version conditions, and store evidence of field origin, normalization criteria, and field confidence for each scope field. Only when the field origin is clear, the boundaries are complete, and the scope certificate is valid, is the candidate editing package allowed to enter the subsequent verification process, thereby preventing notices with unclear origins or incomplete boundaries from directly affecting production question-and-answer answers.
[0078] During the verification phase, the system isolates candidate edit packages from the production Q&A link, only temporarily calculating the impact of candidate edit packages on the answer path in the verification sandbox. Verification checks both whether the new handling rules within the target scope take effect correctly and constructs samples of non-target disturbances outside the boundaries around equipment objects, component objects, fault contexts, and version conditions. The maintenance answers are then converted into core handling action graphs for differential comparison. This allows the system to determine whether candidate edit packages only change the handling rules within the target scope, without causing incorrect maintenance actions for unrelated equipment, components, faults, or issues that do not meet version conditions.
[0079] During the activation and recovery phases, the system aggregates results such as scope certificates, perturbation coverage, target verification, non-target contamination, conflict security, and production visibility into a joint verification gate. Only after the joint verification gate passes can the candidate edit package be written to the rule base, retrieval index, knowledge graph, or side memory layer in a transactional manner, and made visible to production Q&A after consistent submission across multiple layers. If an activated announcement is subsequently revoked, tightened, or confirmed as an error, the system recalculates recoverable answer paths based on the invalidation of relevant dependency edges in the answer path dependency ledger, rather than simply deleting the text or rolling back the entire knowledge base.
[0080] In this embodiment, the user question sample can be represented as: .
[0081] In the formula, This represents a sample of user questions. Represents a device object. Represents a component object. Indicates the fault context. Indicates version conditions. This refers to the question text or its semantic representation.
[0082] Candidate edit packages can be represented as: .
[0083] In the formula, This indicates a candidate edit package. This indicates the editor package identifier. This indicates the device to which the editing package applies. This indicates the component object to which the editing package applies. This indicates that the edit package is subject to a fault context. This indicates the version range to which the edit package applies. This indicates the old disposal rule that has been replaced. This indicates the new handling rules after the replacement. This indicates the scope certificate of the edit package. This represents the perturbation coverage vector of the edit package. Indicates editing package The core processing action graph field it carries. This indicates the lifecycle status of the edit package. This indicates the dependency ledger relationships of the edit package. This indicates the rollback pointer for the edit package.
[0084] To illustrate the complete process of candidate edit packages, from field extraction, certificateization, verification isolation, disturbance coverage, action graph differentiation, joint access control to submission and rollback recovery, the following will describe the process in sequence according to steps S1 to S7.
[0085] S1. Receive maintenance notice, and extract equipment object, component object, fault context, version conditions, old handling rules that have been replaced and new handling rules after replacement from the maintenance notice.
[0086] In this step, the system receives maintenance notice text or form records through the maintenance notice input and preprocessing module, and performs text cleaning, paragraph segmentation, and field candidate identification on the maintenance notice. Preprocessing can segment the notice content using sentence-end punctuation and paragraph blank lines, and identify candidate fields such as equipment objects, component objects, fault context, version conditions, old handling rules, and new handling rules according to a maintenance terminology keyword dictionary. Fields not identified can be recorded as "candidate fields" and proceed to subsequent normalization processing.
[0087] After extracting device objects, component objects, and fault contexts, the system can map them to a unified object representation within the system through an object normalization module. The normalization process can perform exact matching and longest prefix matching based on device synonym dictionaries, component synonym dictionaries, and fault synonym dictionaries. For fields that cannot be matched, they can be added to an "unresolved aliases" list, which can be manually updated or supplemented via subsequent announcements before retrying.
[0088] For version conditions, the system can use the version condition normalization module to convert natural language or semi-structured version expressions into comparable version boundary or version range expressions. For example, it can parse "2.1+" into... The phrase "below 2.3" is interpreted as... The "2.1 to 2.3.5" section is parsed as... If the version representation is not comparable, a "version error" status will be written, and the field will be prevented from directly entering the subsequent production activation process.
[0089] Through the above processing, the system can obtain the equipment object from the maintenance notice. Component objects Fault Context Version range The old disposal rules that were replaced and the new disposal rules after replacement This provides the field foundation for the subsequent generation of structured editing packages.
[0090] S2. Generate a structured edit package based on the extraction results. The structured edit package includes a scope certificate, a disturbance coverage vector representing the non-target disturbance coverage result, a core handling action graph field representing the maintenance action structure, a lifecycle state representing the edit package's flow status, a dependency ledger relationship representing the coverage, conflict, and recovery relationships between the edit package and the basic rules, and a rollback pointer representing the rollback record location.
[0091] In this step, the system generates an edit package object containing scope fields, old handling rules, new handling rules, status fields, and validation fields using the structured edit package generation module. The structured edit package can generate a JSON object according to preset field definitions and be validated using JSON Schema. Check if fields such as scope, rule, scope certificate, status, and ledger pointer are complete.
[0092] When the same maintenance notice involves multiple target objects, the system can split the notice into multiple independent candidate edit packages based on a combination of equipment objects, component objects, and fault contexts, ensuring that each candidate edit package has a clear local scope. After generation, the lifecycle status of the candidate edit packages... It can be initialized as a "candidate", rollback pointer Points to the newly allocated rollback record.
[0093] Scope certificate in the structured editing package Used to store source evidence, normalization basis, and confidence level of the scope field. Perturbation coverage vector. Used to record the coverage of non-target disturbance samples. Core action graph field. Used to record the maintenance and handling action structure corresponding to the candidate edit package. Lifecycle status. Used to record changes in candidate edit packages across states such as candidate, verification, pre-activated, activated, blocked, paused, aborted activation, and rolled back. Depends on ledger relationships. Used to record overriding, suppression, inheritance, conflict, and restoration candidate relationships between editing packages and between editing packages and base rules. Rollback pointer. Used to point to the rollback record that needs to be read when undoing or reverting.
[0094] The disturbance coverage vector is determined using device disturbance samples, component disturbance samples, fault context disturbance samples, version lower bound disturbance samples, version upper bound disturbance samples, and combined disturbance samples. .
[0095] In the formula, This represents the perturbation coverage vector of the edit package. This indicates the coverage value for the device disturbance dimension. This indicates the coverage value of the component disturbance dimension. This indicates the coverage value of the fault context perturbation dimension. This indicates the coverage value of the lower bound perturbation dimension of the version. This indicates the coverage value of the upper bound perturbation dimension of the version. This indicates the coverage value of the combined perturbation dimension, with each coverage value being 0 or 1.
[0096] Disturbance covering access control can be represented as: .
[0097] In the formula, This indicates the result of the disturbance covering the access control system. This indicates the label of the perturbation dimension currently being inspected. Dimension labels The corresponding overriding value. Dimension labels indicating device disturbances. Dimension labels indicating component disturbances. Dimension labels representing fault context perturbations. The dimension label representing the version lower bound perturbation. The dimension label representing the version upper bound perturbation. Dimension labels representing combined perturbations. This indicates a logical conjunction of multiple conditions.
[0098] when At that time, the structured editing package is kept in the candidate state or the verification state, and the uncovered perturbation dimensions are recorded.
[0099] S3. Verify the scope certificate based on the field source evidence, normalization basis, and field confidence level.
[0100] In this step, the system normalizes the announcement source, evidence fields, device aliases, component aliases, fault contexts, and version boundaries through the scope certificate generation and verification module, outputting a unified scope certificate. The field confidence of the scope certificate can be determined by a weighted average of the field evidence fragment length, source confidence, and normalized match degree. The validity of the scope certificate can be expressed as: .
[0101] In the formula, This indicates the result of the validity determination of the scope certificate for the edit package. This indicates a candidate edit package. This indicates the result of the source traceability verification. This indicates the result of the field normalization validation. This indicates the result of the integrity check of the scoped field. This represents the weighted average of the confidence levels of each field in the scope certificate. This indicates the scope certificate of the edit package. Indicates the validity threshold of the scope certificate. Represents the logical AND operation.
[0102] The weighted average of the confidence scores of each field in the scope certificate can be expressed as: .
[0103] In the formula, Indicates editing package The scope certificate field set, and express An index of a certificate field. Indicates the first Each certificate field has a weight, and Indicates scope certificate The Middle The confidence level of each field, and This indicates a normalization constraint on the certificate field weights.
[0104] Field-level threshold validation is carried out by a full-scope condition. If any required field is missing or the field's confidence level is lower than the minimum threshold for a single field, the certificate is deemed invalid. This condition is used to prevent low confidence levels in individual key fields from being masked by the overall weighted average.
[0105] As a supplementary criterion for minimum qualification at the field level, it can be expressed as: .
[0106] In the formula, Indicates editing package The minimum pass / fail validation result for the scope field. Represents a logical OR operation.
[0107] When any required field in the device object, component object, fault context, or version condition is missing, non-normalizable, or below the minimum confidence threshold for a single field, ,otherwise . It only represents the minimum pass / fail verification result of the scope field, and does not represent any system module.
[0108] when When the time comes, the structured editing package is written to a blocking state, and the structured editing package is prohibited from entering the production activation process.
[0109] Specifically, if the scope certificate is invalid, the system writes the lifecycle status of the candidate edit package to "blocked" and records the reason for the status through the status audit module, such as "invalid scope certificate". If the scope certificate is valid, the candidate edit package enters the verification sandbox process, but it cannot be read by the production Q&A link before the transactional commit is completed.
[0110] S4. When the scope certificate is valid, generate target samples and non-target disturbance samples outside the boundary in the verification sandbox based on the device object, the component object, the fault context and the version conditions, and compare the core processing action diagrams before and after the structured editing package takes effect.
[0111] In this step, the system uses the validation sandbox module to calculate the impact of candidate edit packages on both the target and non-target issues in a production isolation environment. The validation sandbox and the production question-and-answer link can share the same retrieval and generator; the difference lies in their matching functions: the validation sandbox reads candidate edit packages in the validation state, while the production question-and-answer link only reads edit packages that have completed transactional commits and are in a production-visible state.
[0112] User problem sample definition: In the formula, This represents a sample of user questions. Represents a device object. Represents a component object. Indicates the fault context. Indicates version conditions. This refers to the question text or its semantic representation.
[0113] The set of visible editable packages in the verification sandbox can be represented as: .
[0114] In the formula, This indicates that the verification sandbox is a set of editable packages. This represents the set of candidate edit packages. This represents the function for determining whether an issue in the verification sandbox matches the edit package.
[0115] Structured edit packages in the verification state are allowed to participate in answer computation in order to test whether candidate edit packages can be correctly effective within the target scope.
[0116] The set of editable packages visible in the production chain can be represented as: .
[0117] In the formula, This represents the set of editable packages visible in the production chain. This represents the function for determining whether a problem in the production pipeline matches an edit package.
[0118] Only structured edit packages that have completed transactional commits and are visible in production are allowed to participate in answer calculation, thus making candidate edit packages testable during the verification phase but not readable in advance during the production phase.
[0119] When generating samples, the system uses the minimum counterfactual perturbation sample generation module to generate samples around the scope of the edit package. Generate out-of-bounds samples. Target samples ensure that device objects, component objects, fault contexts, and version conditions all fall within the target scope. Out-of-bounds non-target disturbance samples include at least device disturbance samples, component disturbance samples, fault context disturbance samples, version lower bound disturbance samples, version upper bound disturbance samples, and combined disturbance samples. Each type of disturbance sample can be generated using a template: device disturbance samples will... Replace with adjacent devices from the dictionary while keeping other fields unchanged. Component disturbance samples will... Replace with adjacent components while keeping other fields unchanged. Fault context perturbation samples will... Replace with a similar but not identical fault context. The lower bound perturbation sample is selected from the nearest comparable version value that is less than the lower bound of the target version interval. The upper bound perturbation sample is selected from the nearest comparable version value that is greater than the upper bound of the target version interval. Combined perturbation samples change at least two boundary dimensions simultaneously. If there is no direct predecessor or successor version, it can be selected from the version dictionary, historical release sequence, or manually configured out-of-bounds representative values.
[0120] Specifically, the system can write the missing dimension into the "Missing Perturbation Dimension" field and prompt the sample generation module to supplement the corresponding type of sample before re-evaluating. Only after the perturbation coverage meets the minimum integrity requirements will the candidate edit package continue to enter the action graph difference and joint verification gate.
[0121] When comparing the core action graphs before and after the structured editing package takes effect, the system converts the question-and-answer answers into core action graphs through the core action graph extraction and difference module.
[0122] The core processing action diagram can be formally represented as: .
[0123] In the formula, This represents the general structure of the core processing action diagram. This represents a set of action nodes used to record action type, target component, and parameters. This represents the set of ordered edges. This represents a set of conditions used to record preconditions, version conditions, and security conditions.
[0124] The core action graph extraction and differential module can map the actions in the announcement to core action graph nodes. The current implementation covers four basic action categories: replacement, inspection, calibration, and tightening. These four categories are an extensible basic set, not a closed set. The action template library supports extensions such as cleaning, lubrication, reset, and firmware upgrade via plugins. New action types require corresponding parameter templates to take effect. Actions without configured templates must not be assumed to be covered and must be marked as coverage gaps in the verification report to prevent these samples from being missed in non-target contamination rate calculations.
[0125] The two core action graphs are equivalent in that the action nodes, sequence edges, and condition sets can all correspond. If the basic answer... Corresponding to "inspection" Sensor → Replacement "Edited" Corresponding to "inspection" Sensor → Replacement If the components are different, then the determination is made. .
[0126] For non-target samples The difference is labeled as follows: .
[0127] In the formula, Indicates the first Action graph differential labeling for non-target samples. Indicates the sequence number of the non-target perturbation sample. Indicates the first One non-target perturbation sample. This indicates an indicator function that takes the value 1 when the condition within the parentheses is true, and 0 otherwise. Indicates sample The diagram shows the basic core processing actions before the edit package takes effect. Indicates sample The diagram shows the core editing actions after the candidate edit package takes effect. This indicates that two core action graphs are not equivalent in terms of action type, target component, sequence edge, or conditional constraint.
[0128] Non-target pollution rate is expressed as: .
[0129] In the formula, This indicates the non-target pollution rate. This represents the total number of non-target perturbation samples, and .
[0130] when When the time comes, the structured editing package is written to the blocking state, and the structured editing package is prohibited from entering the transactional activation process.
[0131] Therefore, the system does not use complete consistency of answer wording as the sole criterion for judgment, but instead uses structured elements such as action type, target component, preconditions, version boundaries, security restrictions, and processing order as the main comparison objects, thereby improving the stability and interpretability of non-target contamination determination.
[0132] S5. A joint verification access control is formed based on the validity of the scope certificate, the integrity of the disturbance coverage, the target sample hit result, the non-target contamination result, the conflict security result, and the production visibility pre-assessment result.
[0133] In this step, the system calculates the joint verification access control result of the edit package through the joint verification access control module, and controls whether the candidate edit package enters the transactional activation process.
[0134] Joint authentication access control can be represented as: .
[0135] In the formula, This indicates that the editing package jointly verifies the access control results. This indicates the result of the validity determination of the scope certificate for the edit package. This indicates the result of the disturbance covering the access control system. This indicates the target sample hit verification result. This indicates the non-target pollution rate. This indicates the result of the conflict security verification. This indicates the results of the preliminary assessment of production visibility. Represents the logical AND operation.
[0136] The target sample hit verification result can be expressed as: .
[0137] In the formula, This represents the target sample hit function. This represents the equivalence criterion. The target sample hit function is used to determine whether the target sample's answer path hits the candidate editing package and whether to output a new handling rule. And whether to stop outputting the old disposal rules that have been replaced. .
[0138] The result of the conflict security verification can be expressed as: .
[0139] In the formula, This represents a function indicating the number of unresolved conflicting edges, and its value is a non-negative integer. If there are unresolved conflicting edges between the candidate edit package and the existing edit package or the base rules, then... Candidate edit packages must not enter transactional activation.
[0140] The results of the production visibility pre-assessment can be expressed as follows: .
[0141] In the formula, Indicates editing package The set of bearer layers that actually participated in the writing this time. express One of the carrier layer indexes. Indicates the first Each layer is for editing packages The production visibility pre-assessment results. This indicates a logical conjunction of multiple conditions. Bearer layers not involved in this write operation are not included in the conjunction condition.
[0142] For non-target contamination results, the joint verification access control adopts a zero-contamination constraint, namely: In the formula, This represents the non-target contamination rate. This constraint indicates that any non-target perturbation sample occurs... At that time, the activation of the candidate edit package is blocked.
[0143] when At that time, the structured editing package is allowed to enter the pre-submission state.
[0144] when When this happens, the structured editing package is written to a blocked state or a paused state.
[0145] Specifically, the joint verification access control module can calculate item by item. The system checks six conditions and writes the intermediate Boolean result and trigger reason for each condition into the "Activation Status" for auditing by the status audit module. If the target verification fails, the non-target action graph difference is abnormal, the conflict is unresolved, or the visibility pre-assessment fails, the candidate editing package enters the "Blocked" or "Paused" status, and the corresponding status reason is recorded. If the joint verification access control passes, the candidate editing package enters the "Pre-Activation" status.
[0146] S6. When the joint verification access control passes, perform a shadow write to at least one of the knowledge carrier layers, namely the rule base, retrieval index, knowledge graph, or side memory layer, and commit it to a production visible state through transactions.
[0147] In this step, the system maintains the edit package state machine through transactional activation and shadow write modules, and performs consistent commits across different knowledge carrier layers. Knowledge carrier layers can include at least one of a rule base, retrieval index, knowledge graph, and side-memory layer. Carrier layers within the same transaction domain that support synchronous locking and atomic commits can achieve strongly consistent activation results using a two-phase commit protocol. When dealing with heterogeneous carrier layers, long transactions, or situations requiring compensation and recovery, a Saga transaction model can be used, recording compensation actions and rollback handles for each sub-step.
[0148] When the joint verification access control passes, a shadow write is performed on at least one of the knowledge carrier layers that actually participate in the writing, including the rule base, retrieval index, knowledge graph, and side memory layer, to obtain the shadow write consistency check result and the dependent ledger write preparation status.
[0149] Shadow writing refers to writing the structured rules, retrieval fragments, graph edges or side memory records of the same candidate editing package into the pre-commit space and comparing whether the visible results of each carrier layer are consistent, rather than immediately opening them to the production question-and-answer link.
[0150] Submission conditions can be expressed as: .
[0151] In the formula, This indicates the result of the transactional submission of the edit package. This indicates that the editing package jointly verifies the access control results. This indicates the result of the shadow write consistency check. This indicates that the dependency ledger is ready to be written. Represents the logical AND operation.
[0152] when At that time, the knowledge carrier layer that actually participated in the writing will be uniformly submitted as production visible, and the lifecycle state of the structured editing package will be written as the production visible state.
[0153] when At that time, the shadow writing content is cancelled, the lifecycle state of the structured editing package is written to the active terminated state, and the production question-and-answer link is kept from reading the structured editing package.
[0154] Specifically, if the shadow write fails or the consistency comparison fails, the system executes "abort activation," revoking the pre-committed content and preventing the production Q&A link from reading the edit package. If the comparison passes, it is uniformly committed as activated. In the production Q&A link, the system uses the edit package visibility assessment module to determine whether rules, index fragments, graph edges, or side memories are allowed to be used by the current answer path. Only when the edit package is in an "active" state, the transaction commit is complete, the scope certificate is still valid, the four-dimensional scope matches, it is not in an unresolved conflict group, and it has not been rolled back, are its rules, index fragments, graph edges, or side memories allowed to enter the answer generation path. Edit packages that fail the visibility assessment do not enter the answer path generation, and "Visibility filtered = true" can be recorded in the answer path metadata.
[0155] Before and after transactional commits, the system can also record overriding, suppression, inheritance, conflict, and recovery relationships between edit packages and between edit packages and base rules through the answer path dependency ledger module. The answer path dependency ledger can be represented as: .
[0156] In the formula, This represents the path-dependent ledger for the answer. This represents the set of ledger nodes. This represents the ledger edge set. The node set can include edit package nodes, basic rule nodes, answer path nodes, and core action graph nodes. Edge elements in the edge set must contain at least the start, end, edge type, state, and timestamp fields. Edge types can include overriding, suppressing, inheriting, conflicting, and resuming candidates. Overriding edges can be established when a new action rule and an old action rule have a unique replacement relationship within the same four-dimensional scope. Inherited edges can be automatically derived from the parent-child relationship of the scope. Conflicting edges can be... Established at that time.
[0157] S7. When a submitted structured edit package is revoked, recalculate the recovery answer path based on the dependency ledger relationship and the rollback pointer.
[0158] In this step, the system uses the dependency ledger rollback module to recalculate the recoverable answer path in the current scope based on the answer path dependency ledger after the activated edit package is undone.
[0159] The production answer path can be viewed as the result of selections on the currently valid set of edit packages, the set of basic rules, and the answer path dependency ledger: .
[0160] In the formula, Indicates user issues The path to producing the answer. This represents the function for selecting the answer path. This represents the currently valid set of editable packages. This represents the set of basic rules. This represents the path-dependent ledger for the answer.
[0161] When a submitted structured edit package is revoked: .
[0162] In the formula, This indicates the path to restore the answer after undoing the edit package. This indicates that the activated edit package has been revoked. This indicates that the edited package index has been revoked. This indicates the path-dependent ledger of the updated answer after reversal. This represents the set difference operation.
[0163] When the edit package is activated When revoked, the system retrieves data from the ledger. Deleted or invalidated The relevant covering edges, suppressing edges, inherited edges, and conflicting edges are identified, and the updated ledger is obtained. Subsequently, the system... , and The answer path selection function is re-executed to determine the restored answer path after undoing.
[0164] The answer path selection function determines the recovery answer path in the following order: First, it selects the preceding valid edit package whose activation time is earlier than the revoked edit package and whose activation time is the latest, and whose scope covers the user question sample. If there are multiple preceding valid edit packages, it selects the preceding valid edit package with the more precise scope. When the scope precision is the same, it selects the recovery answer path according to the priority of ledger edge type. If none of the preceding valid edit packages are available or conflicts still exist, it selects the basic knowledge answer path from the basic rule set and records the routing conflict status.
[0165] Scope precision can be determined based on scope inclusion relationships and constraint narrowing: priority is given to those with more exact matching dimensions for device objects, component objects, and fault contexts. If the number of matching dimensions is the same, priority is given to those with a narrower version range and a scope that is a subset of another candidate. If they are still the same, then the ledger edge type is sorted. The priority of ledger edge type can be set to overriding edges over inherited edges, and inherited edges over recovery candidate edges. If all preceding edit packages are unavailable or conflicts still exist, the system selects the basic knowledge answer path from the basic rule set and records the "routing conflict" status in the lifecycle log.
[0166] To prevent side-memory or retrieval fragments from bypassing the structured editing package state control and prematurely participating in answer production, this embodiment can also set up a dual-channel routing module for the main path and side memory. The main path prioritizes returning structured rule answers, while side memory serves as an auxiliary path, returning relevant explanatory text. Both are filtered by production visibility assessment; only rules, index fragments, graph edges, or side memory records that meet the production visibility conditions are allowed to enter the final answer path.
[0167] This embodiment can also include a status audit module to record status changes and their reasons, such as candidate, verification in progress, pre-activation, activated, blocked, paused, aborted activation, and rolled back. The status audit module can use structured logs to record the "status reason," transition time, triggering conditions, and associated edit packages. Fields such as these facilitate audit playback and anomaly investigation.
[0168] Example 2 provides a maintenance notice activation and rollback device based on a structured edit package. This device corresponds to the method in Example 1 and includes a notice input and preprocessing module, a structured edit package generation module, a scope certificate verification module, a verification sandbox module, a joint verification access control module, a transactional activation module, and a dependency ledger rollback module.
[0169] The announcement input and preprocessing module is used to receive maintenance announcements and extract equipment objects, component objects, fault contexts, version conditions, old handling rules that have been replaced, and new handling rules after replacement from the maintenance announcements.
[0170] The structured edit package generation module is used to generate structured edit packages based on the extraction results. The structured edit package includes a scope certificate, a perturbation coverage vector representing the non-target perturbation coverage result, a core handling action graph field representing the maintenance action structure, a lifecycle state representing the edit package's flow status, a dependency ledger relationship representing the coverage, conflict, and recovery relationships between the edit package and the basic rules, and a rollback pointer representing the rollback record location.
[0171] The scope certificate verification module is used to verify the scope certificate based on the field source evidence, normalization basis, and field confidence level.
[0172] The verification sandbox module is used to generate target samples and non-target disturbance samples outside the boundary in the verification sandbox based on the device object, the component object, the fault context and the version conditions when the scope certificate is valid, and to compare the core processing action diagrams before and after the structured editing package takes effect.
[0173] The joint verification access control module is used to generate joint verification access control based on the validity of the scope certificate, the integrity of the disturbance coverage, the target sample hit result, the non-target contamination result, the conflict security result, and the production visibility pre-assessment result.
[0174] The transactional activation module is used to perform shadow writes and transactional commits to at least one knowledge-bearing layer among the rule base, retrieval index, knowledge graph, or side memory layer when the federated verification access control passes, making it production visible.
[0175] The dependency ledger rollback module is used to recalculate the recovery answer path based on the dependency ledger relationship and the rollback pointer when a submitted structured edit package is revoked.
[0176] Example 3 provides a maintenance bulletin activation and rollback device based on a structured editing package. The device includes a processor, a memory, and a computer program stored in the memory. The computer program can be executed by the processor to implement the maintenance bulletin activation and rollback method based on a structured editing package as described in Example 1. This device can be deployed in industrial equipment maintenance Q&A systems, industrial operation and maintenance knowledge base update systems, rule engine management systems, retrieval enhancement generation systems, or knowledge graph maintenance systems.
[0177] The following explanation uses the update control process after an industrial equipment maintenance notice enters the Q&A system as an example. This process is not dependent on a specific equipment model, a specific notice sample, or a specific deployment environment. It focuses on describing the handling methods of each module, field, status, and exception branch in the software system.
[0178] To facilitate understanding, consider the following typical scenario: Equipment manufacturers issue announcements requiring... equipment The component is in versions 2.1.0 to 2.3.5 and is faulty. At that time, the old disposal rules will be implemented. Replace with new handling rules If regular question-and-answer entries are directly replaced, or if the search enhancement generates recall announcements based solely on semantic similarity, equipment, Issues such as parts not meeting version requirements may also be received. This can lead to irrelevant devices executing incorrect handling procedures. If the verification report is separated from the knowledge activation status, announcements that have detected non-target contamination may still enter the production Q&A chain due to process oversights. If the announcement is subsequently confirmed as erroneous, the system should not simply revert to the initial basic knowledge, nor should it leave blank answers. Instead, it should recalculate the answer path based on the preceding valid edit packages in the same scope before the announcement was activated.
[0179] Specifically, the system may include the following modules: The M1 maintenance notice input and preprocessing module receives maintenance notice text or form records and performs text cleaning, paragraph segmentation, and field candidate identification. Specifically, preprocessing uses sentence-ending punctuation and paragraph blank lines for segmentation, and identifies field candidates according to a maintenance terminology keyword dictionary. Unidentified field records are recorded as candidate_field and will be further normalized by M2.
[0180] The M2 object normalization module maps device objects, component objects, and fault contexts to a unified object representation within the system. Normalization is based on a combination of exact matching and longest prefix matching using a dictionary of device / component / fault synonyms. When a match is not found, it is added to the "unresolved alias" list, which is then manually updated or updated via a subsequent announcement before retrying.
[0181] The M3 version conditional normalization module is used to convert natural language or semi-structured version expressions into comparable version boundary or range expressions. Normalization uses a semantic version parser: for example, "2.1+" is converted to $2.1.0,+∞), "below 2.3" is converted to \[0,2.3.0), and "2.1 to 2.3.5" is converted to \[2.1.0,2.3.5$. Incomparable version expressions are written to the version_error status.
[0182] The M4 structured edit package generation module generates edit package objects containing scope fields, old rules, new rules, status fields, and validation fields. It generates JSON objects based on the SEP field definitions, initializing s_e=candidate and rb_e to point to the newly assigned rollback record. When the same announcement involves multiple target objects, it is split into multiple independent edit packages based on the device-part-fault combination. Internally, the system verifies the completeness of fields such as id, scope, rule, scope certificate, status, and ledger pointer according to the JSON schema.
[0183] The M5 scope certificate generation and verification module. M5 normalizes the announcement source, evidence fields, device aliases, component aliases, and version boundaries, outputting a unified scope certificate. Confidence is calculated as a weighted average of field evidence fragment length, source confidence, and normalized match degree. Threshold. The system default configurable value is 0.7, which can be adjusted by the deployment environment. If any required field is incomplete, its source is untraceable, or its confidence level is below the threshold, The edit package must not enter the activation preparation stage. As a supplementary criterion for minimum field-level eligibility, this can be further expressed as: .
[0184] In the formula, This indicates the result of the validity determination of the scope certificate for the edit package. This indicates a candidate edit package. Indicates editing package The minimum pass / fail validation result for the scope field. This represents the weighted average of the confidence levels of each field in the scope certificate. This indicates the scope certificate of the edit package. This indicates the validity threshold for the scope certificate. It applies when any required field for the device object, component object, fault context, or version condition is missing, non-normalizable, or falls below the minimum confidence threshold for a single field. ,otherwise . It only indicates the minimum pass / fail result of the scope field, and does not represent any system module from M1 to M16.
[0185] The M6 Validation Sandbox module is used to calculate the impact of candidate edit packages on both the target and non-target problems in a production-isolated environment. The validation sandbox shares the same retriever and generator as the production pipeline; the only difference lies in the matching function: the sandbox uses... Read the status edit packet during verification for production use. Read-only activated edit package.
[0186] The M7 Minimal Counterfactual Perturbation Sample Generation Module generates out-of-bounds samples around device objects, component objects, fault contexts, and version conditions. The input is the edit package scope. The output is a set of non-target samples covering six types of perturbations. Each type of disturbance sample is generated using a template: for device disturbance samples, d_q is replaced with the adjacent device value from the dictionary, while other fields remain unchanged. For version lower bound disturbance samples, the nearest comparable version value is selected that is less than the target version interval lower bound. If no direct predecessor version exists, it is selected from the version dictionary, historical release sequence, or manually configured representative values outside the boundary. Similarly, for version upper bound disturbance samples, the nearest comparable version value is selected that is greater than the target version interval upper bound. Other types are similar.
[0187] The M8 perturbation coverage vector calculation module is used to form... And judge .according to Six-dimensional bitwise AND check, missing one bit means... Missing dimensions are recorded in the Missing Perturbation Dimension field, prompting M7 to re-evaluate after supplementing the corresponding type of samples.
[0188] The M9 core action graph extraction and differential module maps actions from the announcement to core action graph nodes, currently covering four basic actions: replacement, inspection, calibration, and tightening. These four categories form a currently implemented, scalable base set, not a closed set. The action template library supports extensions such as cleaning, lubrication, reset, and firmware upgrade via plugins. New action types require corresponding parameter templates to take effect. Actions without configured templates must not be assumed to be covered and must be marked as coverage gaps in the verification report to prevent samples from being missed. Beyond calculations.
[0189] .
[0190] in, This represents the general structure of the core processing action diagram. Represents a set of action nodes. This represents the set of ordered edges. Represents a set of conditions.
[0191] .
[0192] in, Indicates the first Action graph differential labeling for non-target samples. Indicates the sequence number of the non-target perturbation sample. Indicates the first One non-target perturbation sample. Indicates an indicator function. Indicates sample The diagram shows the basic core processing actions before the edit package takes effect. Indicates sample The diagram shows the core editing actions after the candidate edit package takes effect. This indicates that two core action graphs are not equivalent in terms of action type, target component, sequence edge, or conditional constraint.
[0193] The M10 joint verification access control module is used to calculate... It also controls whether candidate edit packages enter transactional activation. Calculation is performed item by item. The system sets six conditions and writes them to the active state. Each condition stores the intermediate Boolean result and the triggering reason for M16 auditing. If any condition is 0, it writes to the blocked or paused state.
[0194] The M11 transactional activation and shadow write module maintains the edit package state machine and performs consistent commits across different bearer layers. Bearer layers within the same transaction domain that support synchronous locking and atomic commits preferentially employ a two-phase commit protocol to achieve strongly consistent activation results. When crossing heterogeneous bearer layers, involving long transactions, or requiring compensation and recovery, the Saga transaction model is used, recording compensation actions and rollback handles for each sub-step. If a shadow write or consistency comparison fails, the edit package enters an aborted activation state, the system reverts the pre-committed content, and the production Q&A link does not read the edit package. If an edit package has completed production activation and needs to be revoked due to announcement revocation, certificate expiration, conflict confirmation, or tightening version conditions, it enters a rolled-back state, and the rollback recovery module recalculates the recoverable answer path based on the answer path dependency ledger.
[0195] The M12 edit package visibility assessment module is used to determine whether a production question-and-answer link reads rules, index fragments, graph edges, or side memories, and whether they are allowed to be used by the current answer path. (Click) Formula filtering is now active for edit packages. Edit packages that fail the filter will not be included in the answer path generation, and "Visibility filtered = true" will be recorded in the answer path metadata.
[0196] The M13 answer path dependency ledger module records the overriding, suppression, inheritance, conflict, and recovery relationships between edit packages and between edit packages and base rules. Inputs include hit edit packages, hit rules, and action graphs. Output is the ledger. The edge set includes candidates for covering, suppression, inheritance, conflict, and restoration. This represents the path-dependent ledger for the answer. This represents the set of ledger nodes. This represents the ledger edge set. The node set includes edit package nodes, basic rule nodes, answer path nodes, and core action graph nodes. Edge elements in the edge set must contain at least the start, end, edge type, state, and timestamp fields. Edge types are categorized into five types: overriding, suppressing, inheriting, conflicting, or restoring. Overriding edges are automatically identified by the rule: a new rule and an old rule within the same four-dimensional scope generate a unique rule, thus creating an overriding edge. Inherited edges are automatically derived from the parent-child relationship of the scope. Conflicting edges are detected in M10. Established at that time.
[0197] The M14 rollback and recovery module is used to recalculate the recoverable answer path in the current scope based on the ledger after an active edit package has been undone. M14 follows the selection rules of the aforementioned answer path selection function when the edit package is removed. And update the ledger to Then, a unique recovery path is determined as follows: First, prioritize the preceding valid edit package whose activation time is earlier than the revoked edit package, has the latest activation time, and whose scope can be covered. Second, if multiple candidates meet the conditions, prioritize the edit package with a more precise scope; if the scope precision is the same, sort them by ledger edge type priority (overriding edge > inherited edge > recovery candidate edge). Third, if all are unavailable or conflicts still exist, roll back the basic knowledge and record the routing conflicts.
[0198] The M15 dual-channel routing module, consisting of a main path and side memory, distinguishes between the structured rule main path and the side memory auxiliary path, ensuring both are subject to visibility evaluation constraints. The main path prioritizes returning the structured rule answer, while the side memory serves as an auxiliary, returning relevant explanatory text. Both are filtered through the M12 visibility evaluation to prevent the side memory from bypassing the edit package lifecycle control.
[0199] The M16 status audit module records status changes and their reasons, including candidate, verification in progress, pre-activated, activated, blocked, paused, aborted activation, and rolled back statuses. It uses structured logs to record fields such as "status reason," transition time, triggering conditions, and associated edit package ID, facilitating audit playback and anomaly investigation.
[0200] In one processing flow, the system first receives a maintenance notice and generates a structured edit package by M1 through M4. If the notice cannot form complete equipment objects, component objects, fault contexts, and version conditions, the system keeps the edit package in a candidate state and records the reason for the missing fields. If the fields are complete, a scope certificate is generated by M5.
[0201] If the scope certificate is invalid, the edit package enters a blocked state, and the production Q&A link becomes invisible. If the scope certificate is valid, the edit package enters the verification sandbox, where M7 generates the minimum counterfactual perturbation sample, and M8 forms the perturbation coverage vector. If the perturbation coverage does not meet the minimum integrity requirements, the edit package remains in the candidate or verification state and does not enter production activation.
[0202] After the perturbation coverage meets the requirements, M6 and M9 calculate the answer path and core action diagram for the target problem and non-target problems respectively. The target problem should reflect the new rules, while the core action diagram for non-target problems should not change. The system does not use complete consistency of answer wording as the sole criterion, but uses structured elements such as action type, target component, preconditions, version boundaries, security restrictions, and processing order as the main comparison objects.
[0203] M10 according to Perform joint verification access control. If target verification fails, non-target action graph difference is abnormal, conflict remains unresolved, or visibility pre-assessment fails, the candidate edit package enters a blocked or paused state, and the corresponding reason is recorded. If the access control passes, the edit package enters a pre-activated state.
[0204] M11 performs shadow writing in the pre-activated state, writing the structured rules, retrieval fragments, and graph edges or side memory records of the same editing package into the pre-commit space, and comparing the visible results of each carrier layer for consistency. If shadow writing fails or the consistency comparison fails, the system aborts activation, cancels the pre-commit content, and prevents the production Q&A link from reading the editing package. If the comparison passes, it is uniformly submitted as activated.
[0205] Once an edit package is activated, M12 performs a visibility assessment in the production question-and-answer chain. Rules, index fragments, graph edges, or side memories are only allowed into the answer generation path if the edit package is activated, the transaction has been committed, the scope certificate is still valid, the four-dimensional scope matches, it is not in an unresolved conflict group, and it has not been rolled back.
[0206] M13 records an answer path dependency ledger each time an answer is generated. The ledger stores at least the hit edit packages, basic rules, core action graphs, overridden preorder rules, suppressed edit packages, conflicting edges, inherited edges, and restoration candidate relationships. This ledger provides a computational basis for subsequent undoing and restoration.
[0207] When an activated edit package needs to be revoked, M14 marks the edit package as rolled back and removes the overriding edges, suppressing edges, and inherited edges associated with that edit package from the ledger. The system then recalculates the relationships based on the currently valid set of edit packages, the set of basic rules, and the updated ledger relationships. This restores the answer to the path where it should take effect in the current scope.
[0208] Case 1: Describe the end-to-end success processing path of typical announcement B-001.
[0209] The system received notification B-001, which states that the device... Components In the fault Furthermore, in versions 2.1.0 to 2.3.5, the old handling rules... Replace with new handling rules The announcement input and preprocessing module, object normalization module, and version condition normalization module complete the announcement cleaning, object normalization, and version normalization, parsing the natural language version expression into... The structured editing package generation module generates editing packages. initial state Rollback pointer .
[0210] The scope certificate verification module is for the device field. Component fields Fault context fields and version conditions Save the evidence fragments, normalization criteria, and field confidence levels separately, and determine... .
[0211] The verification sandbox module generates target samples. The sample includes six types of non-target disturbances: equipment disturbances, component disturbances, fault context disturbances, version lower bound disturbances, version upper bound disturbances, and combined disturbances. Indication and Fault The corresponding question text or question semantic representation. The perturbation coverage vector calculation module is formed. and obtain .
[0212] In the verification sandbox, the system uses Temporary read The target sample answer path includes the edit package identifier. Action coverage And no output ,therefore The core processing action graph extraction and difference module compares all non-target perturbation samples. and If the structures are identical, then When there are no unresolved conflicts and the visibility pre-assessment is passed, , Joint verification access control module calculation The edit package enters the "pre-activation" state.
[0213] The transactional activation and shadow write module performs shadow writes on the rule base, retrieval index, knowledge graph, and side memory layer, and compares the visibility consistency of each carrier layer. After passing the comparison, a unified commit is made, and the package status is edited. During production Q&A, user questions Through visibility assessment, and by Output User issues The visibility assessment failed due to a device object mismatch, and the basic knowledge answer path was output. The answer path depends on the ledger module writing the hit editing package, basic rules, core action graph, and recovery candidate relationship in the two answer generation processes, respectively.
[0214] Case 2: Describe the path for blocking error announcements and rolling back activated announcements.
[0215] The system received announcement B-002, the contents of which claim of The component is subject to a certain rule but the specific model is not specified, and key evidence fragments are missing. The object normalization module and the scope certificate verification module detected that the component field in announcement B-002 failed normalization, the version condition had no upper bound for comparison, and the confidence level of the field evidence was below the threshold. ,determination The status audit module will Write the "Blocked" status and log "State Reason = Invalid Scope Certificate". This candidate edit package does not enter the verification sandbox or participate in production Q&A, and therefore will not affect any answer path.
[0216] To illustrate path recovery, assume that a path recovery protocol already existed in the system. The preceding valid edit package of the fault The edit package has passed the full verification process and is in a "blocked" state, according to its rules. It took effect earlier than B-001. After some time, the manufacturer confirmed that the original scope of application for B-001 was too broad and should be narrowed down. Therefore, a modification to the original edit package was submitted. The revocation request. The tightened rules can be re-entered into the certificateization, perturbation coverage, and joint verification process as a new candidate edit package. Due to It is already in a "blocked" state, relying on the ledger rollback module to... Write it as "rollback completed" and from the ledger Failure and The related covering edges, suppressing edges, and inherited edges are used to obtain the updated ledger. The system presses Reselect answer path: The preceding valid rules in the current scope are... When under load, restore to Path. If If the path is also revoked or becomes unavailable, the system will revert to the basic knowledge answer path. The final restoration result is written to the answer path dependency ledger as input for subsequent auditing and reactivation controls.
[0217] If announcement B-003 only covers equipment disturbance samples and component disturbance samples, and lacks fault context disturbance samples, version lower bound disturbance samples, version upper bound disturbance samples, and combined disturbance samples, then the disturbance coverage vector calculation module will obtain... , The status audit module maintains... The status is set to "Candidate" or "Validating" and the reason for the status is recorded as "Insufficient Coverage". The status will be re-evaluated after the perturbation sample generation module supplements the samples.
[0218] If the target sample corresponding to announcement B-004 satisfies However, it is not the target sample. After participating in the candidate edit package, "Replace" appears "and Only includes "check" Then, the core processing action diagram extraction and differential module determination... This leads to The joint verification access control module was obtained. The status audit module writes it to the "blocked" status and records "status reason = non-target pollution". This edit package does not enter the transactional activation process.
[0219] The above embodiments collectively embody the end-to-end control chain of "maintenance notice input → scope certificate → disturbance coverage → joint verification → transactional activation → visibility assessment → dependency ledger rollback", and illustrate the present invention's ability to handle situations such as incomplete scope field evidence, insufficient disturbance coverage, non-target contamination, and revocation after activation.
[0220] By adopting the technical solution of this embodiment, the following technical effects can be achieved: By storing field evidence, normalization basis, and certificate status through scope certificates, the traceability of the source of maintenance announcement scope fields can be improved, reducing the risk of candidate updates with unknown field sources entering the production chain. Through minimum counterfactual perturbation samples and perturbation coverage vectors, non-target boundary verification can be transformed from sporadic sampling to access control judgment with computable coverage dimensions, improving the integrity of local rule boundary control. Through core action graph differential, contamination judgment can be transformed from natural language text comparison to maintenance operation structure comparison, improving the stability and interpretability of non-target contamination judgment. By separating the verification sandbox from the production matching function, candidate edit packages can be tested during the verification stage but cannot be read in advance during the production stage, reducing the risk of announcements that have not completed verification affecting the final answer. Through transactional activation and shadow writing, consistency comparison can be performed between the rule base, retrieval index, knowledge graph, and side memory layer, reducing answer path anomalies caused by partial writes or visibility inconsistencies in multiple bearer layers. By using the answer path dependency ledger, the recoverable path in the current scope can be recalculated after the active edit package is undone, which improves the accuracy of recovery after the error announcement is undone and avoids blank answers or excessive rollback caused by simple deletion or overall rollback.
[0221] By recording the lifecycle status and reasons for each edit package, states such as candidate, verification, pre-activation, activated, blocked, paused, aborted activation, and rolled back can be included in a unified audit. This facilitates operations personnel in tracing the complete status changes and reasons for each announcement from input to withdrawal. With both the main path and side memory routing channels subject to visibility assessment constraints, side memory or retrieval fragments can be prevented from bypassing structured edit package status control and prematurely participating in production answers.
[0222] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A method for activating and rolling back maintenance notices based on structured editing packages, characterized in that, include: S1. Receive maintenance notices and extract equipment objects, component objects, fault contexts, version conditions, old handling rules that have been replaced, and new handling rules after replacement from the maintenance notices. S2. Generate a structured editing package based on the extraction results; The structured editing package includes a scope certificate, a disturbance coverage vector representing the non-target disturbance coverage result, a core handling action graph field representing the maintenance action structure, a lifecycle state representing the editing package flow status, a dependency ledger relationship representing the coverage, conflict, and recovery relationship between the editing package and the basic rules, and a rollback pointer representing the rollback record location. S3. Verify the scope certificate based on the field source evidence, normalization basis, and field confidence level; S4. When the scope certificate is valid, generate target samples and non-target disturbance samples outside the boundary in the verification sandbox based on device objects, component objects, fault contexts and version conditions, and compare the core processing action diagrams before and after the structured editing package takes effect. S5. Based on the validity of the scope certificate, the integrity of the disturbance coverage, the target sample hit result, the non-target contamination result, the conflict security result, and the production visibility pre-assessment result, a joint verification access control is formed; S6. When the joint verification access control passes, perform shadow write and transactional commit to make it visible to production for at least one of the knowledge carrier layers, namely the rule base, retrieval index, knowledge graph or side memory layer; S7. When a submitted structured edit package is revoked, recalculate the recovery answer path based on dependency ledger relationships and rollback pointers.
2. The method for activating and rolling back maintenance notices based on structured editing packages according to claim 1, characterized in that, S3 specifically includes: ; In the formula, This indicates the result of the validity determination of the scope certificate for the edit package; Indicates candidate edit packages; This indicates the result of the source traceability verification. This indicates the result of the field normalization validation. This indicates the result of the scope field integrity check; This represents the weighted average of the confidence levels of each field in the scope certificate. Indicates the scope certificate of the edit package; Indicates the scope certificate validity threshold; This represents the logical AND operation; ; In the formula, Indicates editing package The scope certificate field set; express An index of a certificate field; Indicates the first Weight of each certificate field; Indicates scope certificate The Middle Confidence level of each field; This indicates a normalization constraint for the certificate field weights; when When the time comes, the structured editing package is written to a blocking state, and the structured editing package is prohibited from entering the production activation process.
3. The method for activating and rolling back maintenance notices based on structured editing packages according to claim 1, characterized in that, S4 generates target samples and non-target perturbation samples outside the boundary in the verification sandbox, specifically including: Define the user problem as: In the formula, This represents a sample of user questions; Represents a device object; Represents a component object; Indicates the fault context; Indicates version conditions; This refers to the question text or its semantic representation; ; In the formula, This indicates that the verification sandbox is a set of editable packages; Indicates candidate edit packages; Represents the set of candidate edit packages; This represents the function for determining whether an issue in the verification sandbox matches the edit package; ; In the formula, This represents the set of editable packages visible in the production chain; This represents the function for determining whether a problem in the production pipeline matches an edit package. Structured edit packages in the verification state are allowed to participate in answer calculation; Only structured edit packages that have completed transactional commits and are in a production-visible state are allowed to participate in answer calculation.
4. The method for activating and rolling back maintenance notices based on structured editing packages according to claim 1, characterized in that, The disturbance coverage vector of S2 is determined by device disturbance samples, component disturbance samples, fault context disturbance samples, version lower bound disturbance samples, version upper bound disturbance samples, and combined disturbance samples: ; In the formula, This represents the perturbation coverage vector of the edit package; Indicates candidate edit packages; This indicates the coverage value for the device disturbance dimension; This indicates the coverage value for the component disturbance dimension; Indicates the coverage value of the fault context perturbation dimension; This indicates the coverage value of the lower bound perturbation dimension of the version. This indicates the coverage value of the upper bound perturbation dimension of the version; This indicates the coverage value for the combined perturbation dimension, which can be either 0 or 1. ; In the formula, This indicates the result of the disturbance covering the access control system. Indicates the label of the disturbance dimension currently being inspected; Dimension labels The corresponding overlay value; Dimension labels indicating device disturbances; Dimension labels indicating component disturbances; Dimension labels representing fault context perturbations; Dimension labels indicating version lower bound perturbations; Dimension labels indicating version upper bound perturbations; Dimension labels representing combined perturbations; This indicates a logical conjunction of multiple conditions. when At that time, the structured editing package is kept in the candidate state or the verification state, and the uncovered perturbation dimensions are recorded.
5. The method for activating and rolling back maintenance notices based on structured editing packages according to claim 1, characterized in that, S4 compares the core processing action diagrams before and after the structured editing package takes effect, specifically including: ; In the formula, This represents the general structure of the core processing action diagram; Represents a set of action nodes; Represents the set of edges in order; Represents a set of conditions; ; In the formula, Indicates the first Action graph differential labeling for non-target samples; Indicates the sequence number of the non-target perturbation sample; Indicates the first One non-target perturbation sample; This indicates an indicator function that takes the value 1 when the condition inside the parentheses is true, and 0 otherwise. Indicates sample Diagram of basic core processing actions before the edit package takes effect; Indicates sample A diagram illustrating the core editing actions after a candidate edit package takes effect. This indicates that two core action graphs are not equivalent in terms of action type, target component, sequence edge, or conditional constraint. ; In the formula, Indicates the non-target pollution rate; This represents the total number of non-target disturbance samples; when When the time comes, the structured editing package is written to the blocking state, and the structured editing package is prohibited from entering the transactional activation process.
6. The method for activating and rolling back maintenance notices based on structured editing packages according to claim 1, characterized in that, S5 specifically includes: ; In the formula, This indicates that the editing package jointly verifies the access control results; Indicates candidate edit packages; This indicates the result of the validity determination of the scope certificate for the edit package; This indicates the result of the disturbance covering the access control system. This indicates the target sample hit verification result; Indicates the non-target pollution rate; Indicates the results of the conflict security verification; This indicates the results of the preliminary assessment of production visibility; This represents the logical AND operation; ; In the formula, Represents the target sample hit function; Indicates the equivalence determiner; ; In the formula, This represents a function indicating the number of unresolved conflicting edges, and its value is a non-negative integer. ; In the formula, Indicates editing package The set of bearer layers actually involved in this write operation; express A carrier layer index; Indicates the first Each layer is for editing packages The results of the production visibility pre-assessment; This indicates a logical conjunction of multiple conditions. when At that time, the structured editing package is allowed to enter the pre-submission state; when When this happens, the structured editing package is written to a blocked state or a paused state.
7. The method for activating and rolling back maintenance notices based on structured editing packages according to claim 1, characterized in that, S6 specifically includes: When the joint verification access control is passed: Shadow writing is performed on at least one knowledge-bearing layer that actually participates in writing, including the rule base, retrieval index, knowledge graph, and side memory layer, to obtain the shadow writing consistency check result and the dependent ledger writing preparation status; ; In the formula, This indicates the transactional submission result of the edit package; Indicates candidate edit packages; This indicates that the editing package jointly verifies the access control results; This indicates the result of the shadow write consistency check; This indicates that the dependency ledger is ready to be written. This represents the logical AND operation; when At that time, the knowledge carrier layer that actually participated in the writing will be uniformly submitted as production visible, and the lifecycle state of the structured editing package will be written as the production visible state; when At that time, the shadow writing content is cancelled, the lifecycle state of the structured editing package is written to the active terminated state, and the production question-and-answer link is kept from reading the structured editing package.
8. The method for activating and rolling back maintenance notices based on structured editing packages according to claim 1, characterized in that, S7 specifically includes: When a submitted structured edit package is revoked: ; In the formula, Indicates user issues The path to producing the answer; This represents a sample of user questions; This represents a function for selecting the answer path. This represents the currently valid set of editable packages; Represents the set of basic rules; The ledger represents the path-dependent answer; ; In the formula, This indicates the path to restore the answer after undoing the edit package; This indicates that the activated edit package has been revoked; This indicates that the edited package index has been revoked; This indicates the path-dependent ledger of the answer after reversal; This represents the set difference operation; The answer path selection function determines the restored answer path in the following order: First, select the preceding valid edit package whose activation time is earlier than the revoked edit package and whose activation time is the latest, and whose scope covers the user's problem sample; When there are multiple preceding valid edit packages, select the preceding valid edit package with the more precise scope. When the scope precision is the same, the path to restore the answer is selected based on the priority of the ledger edge type; If all valid editing packages in the preceding sequence are unavailable or still conflicting, select the basic knowledge answer path from the basic rule set and record the routing conflict status.
9. A maintenance bulletin activation rollback device based on a structured editing package, characterized in that, include: The announcement input and preprocessing module is used to receive maintenance announcements and extract equipment objects, component objects, fault contexts, version conditions, old handling rules that have been replaced, and new handling rules after replacement from the maintenance announcements. The structured editing package generation module is used to generate structured editing packages based on the extraction results; The structured editing package includes a scope certificate, a disturbance coverage vector representing the non-target disturbance coverage result, a core handling action graph field representing the maintenance action structure, a lifecycle state representing the editing package flow status, a dependency ledger relationship representing the coverage, conflict, and recovery relationship between the editing package and the basic rules, and a rollback pointer representing the rollback record location. The scope certificate verification module is used to verify the scope certificate based on the field source evidence, normalization basis, and field confidence level. The verification sandbox module is used to generate target samples and non-target disturbance samples outside the boundary in the verification sandbox based on the device object, the component object, the fault context and the version conditions when the scope certificate is valid, and to compare the core processing action diagrams before and after the structured editing package takes effect. The joint verification access control module is used to generate joint verification access control based on the validity of the scope certificate, the integrity of the disturbance coverage, the target sample hit result, the non-target contamination result, the conflict security result, and the production visibility pre-assessment result. The transactional activation module is used to perform shadow write and transactional commit to at least one of the knowledge carrier layers, namely the rule base, retrieval index, knowledge graph or side memory layer, when the joint verification access control passes, and make it visible to production. The dependency ledger rollback module is used to recalculate the recovery answer path based on the dependency ledger relationship and the rollback pointer when a submitted structured edit package is revoked.
10. A maintenance bulletin activation rollback device based on structured editing packages, characterized in that, Includes a processor, memory, and computer programs stored in the memory; The computer program can be executed by the processor to implement a maintenance notice activation rollback method based on a structured editing package as described in any one of claims 1 to 8.