Power grid monitoring signal processing method, system, device, medium and program product
By identifying suspected abnormal nodes and supplementary nodes in the power grid dispatch and monitoring system, and using protection information for diagnosis in conjunction with a deep learning model, the problem of anomaly determination under multi-source heterogeneous data was solved, and efficient and accurate fault response and location were achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- MEIZHOU POWER SUPPLY BUREAU OF GUANGDONG POWER GRID CORP
- Filing Date
- 2026-04-28
- Publication Date
- 2026-07-31
AI Technical Summary
Existing power grid dispatch and monitoring schemes struggle to balance the accuracy of anomaly detection and the timeliness of processing when faced with multi-source heterogeneous monitoring data, and protection information is not fully utilized, resulting in false alarms, missed alarms, and insufficient response timeliness.
By acquiring the OCS monitoring signals from the power grid dispatching and monitoring system, suspected abnormal nodes are identified, and supplementary suspected abnormal nodes are determined by combining them with a preset association table. Protection information from the protection information system is obtained, and anomaly diagnosis is performed using a deep learning model to establish a joint analysis of monitoring data and protection data.
It improves the accuracy of anomaly verification and the timeliness of fault response, enhances the reliability of anomaly localization, reduces false alarms and false negatives, and shortens the fault response chain.
Smart Images

Figure CN122495692A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of power system dispatching and monitoring and intelligent data processing, and in particular to a method, system, equipment, medium and program product for processing power grid monitoring signals. Background Technology
[0002] In the field of power grid dispatch and monitoring, equipment operating parameters and status signals are typically collected by the dispatch and monitoring system. The protection information management system (referred to as the protection information system) is specifically designed to collect, store, and analyze key data of power grid protection equipment (such as action records, fault messages, and protection settings), and is the core data source for fault root cause location.
[0003] Combining rule engines or machine learning methods to perform anomaly analysis on the above data is a diagnostic approach. However, this type of solution mainly relies on monitoring data and historical logs for judgment. When dealing with multi-source heterogeneous data such as protection information, it often requires complex standardization processing, resulting in insufficient feature utilization, increased computational overhead, and difficulty in simultaneously achieving anomaly verification, location accuracy, and fault response timeliness.
[0004] Therefore, how to improve the accuracy of anomaly detection of multi-source heterogeneous monitoring data in power grid dispatch scenarios, while taking into account both processing timeliness and location reliability, has become a technical problem that needs to be solved. Summary of the Invention
[0005] This application provides a method, system, device, medium, and program product for processing power grid monitoring signals. The method is designed for power grid dispatching and monitoring scenarios. It performs correlation expansion and joint analysis based on anomaly clues corresponding to monitoring signals, groups abnormal nodes on the monitoring side with related supplementary nodes for processing, and combines information from the information protection system to conduct comprehensive diagnosis of abnormal states. This improves the accuracy, timeliness, and reliability of anomaly determination in multi-source heterogeneous data scenarios.
[0006] In a first aspect, embodiments of this application provide a method for processing power grid monitoring signals, the method comprising:
[0007] Acquire monitoring signals from the power grid dispatching and monitoring system (OCS);
[0008] Based on the OCS monitoring signals, suspected abnormal nodes were identified;
[0009] Based on the devices and OCS monitoring signal types corresponding to suspected abnormal nodes, supplementary suspected abnormal nodes are determined based on a preset association table. The association table includes the association relationships of all devices, all types of OCS monitoring signals, and different time windows.
[0010] The suspected abnormal nodes and suspected abnormal supplementary nodes are treated as a suspected abnormal node package. Based on the time sequence window corresponding to each node in the suspected abnormal node package, the protection information in the information protection system is obtained.
[0011] Based on protection information and OCS monitoring signals, anomaly diagnosis is performed using a deep learning model.
[0012] In one possible embodiment, identifying suspected abnormal nodes based on OCS monitoring signals includes:
[0013] For each type of OCS monitoring signal from each device, extract time-series features window by window and obtain the preset threshold corresponding to the time-series feature type;
[0014] If the value of the time series feature is greater than the threshold, the time series window is determined to be a suspected abnormal node.
[0015] In one possible embodiment, based on the device and OCS monitoring signal type corresponding to the suspected abnormal node, and using a preset association table, a suspected abnormal supplementary node is determined, including:
[0016] From the association table, identify other devices that are associated with the device corresponding to the suspected abnormal node;
[0017] Obtain the timing window that is the same as the suspected abnormal node from other devices, and identify the timing window as a suspected abnormal supplementary node.
[0018] In one possible embodiment, the method further includes:
[0019] Obtain the extended timing windows of other devices before and after the timing window, and identify the extended timing windows as suspected abnormal supplementary nodes.
[0020] In one possible embodiment, the method further includes:
[0021] Using power grid equipment ledgers, historical data from OCS and the information protection system, and power grid operation specifications as data sources, we input equipment association relationships, association relationships of all types of OCS monitoring signals, and time sequence window association relationships. We call up historical abnormal case data of the power grid to verify the association relationships, eliminate invalid associations and correct deviation associations, and form an initial association table.
[0022] Acquire supplementary feedback data from suspected abnormal nodes, integrate and analyze feedback data, and collect power grid operation feedback data.
[0023] Based on feedback data, identify valid relationships that were not entered.
[0024] Add valid relationships to the initial association table to obtain the updated association table.
[0025] In one possible embodiment, before performing anomaly diagnosis based on a deep learning model according to the protection information and the OCS monitoring signal, the method further includes:
[0026] The structured data in the protected information is cleaned, its features are normalized, and its encoding is converted to generate standardized structured feature vectors.
[0027] Natural language processing technology is used to transform unstructured data in protected information into structured data through word segmentation, entity recognition, and text embedding.
[0028] The processed structured and unstructured data are integrated to generate a unified format credit guarantee data feature package.
[0029] Secondly, embodiments of this application provide a power grid monitoring signal processing system, which includes: a node acquisition module, a protection information pre-processing module, and an analysis module;
[0030] The node capture module is configured to capture suspected abnormal node packets in the OCS monitoring signal in real time;
[0031] The protection information preprocessing module is configured to receive suspected abnormal node packets and obtain protection information in the protection information system based on the timing window of each abnormal node in the suspected abnormal node packet.
[0032] The analysis module is configured to perform anomaly analysis on the OCS monitoring signal, and output an anomaly judgment command if the analysis result is abnormal.
[0033] Among them, the protection information preprocessing module, after receiving the anomaly judgment instruction, feeds the cached protection information to the analysis module as needed;
[0034] The analysis module integrates the received protection information with the OCS monitoring signals for analysis.
[0035] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor;
[0036] The memory stores the instructions that the computer executes;
[0037] The processor executes computer execution instructions stored in memory, causing the processor to perform the methods provided above.
[0038] Fourthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the method provided above.
[0039] Fifthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the method described above.
[0040] This application provides a method, system, device, medium, and program product for processing power grid monitoring signals. The method acquires OCS monitoring signals from the power grid dispatch monitoring system, identifies suspected abnormal nodes, and determines supplementary suspected abnormal nodes based on the devices corresponding to the suspected abnormal nodes, the type of OCS monitoring signals, and an association table containing the correlation relationships of all devices, all types of OCS monitoring signals, and different time-series window correlation relationships. The suspected abnormal nodes and supplementary suspected abnormal nodes are treated as a suspected abnormal node package. Based on the time-series window corresponding to each node in the suspected abnormal node package, protection information in the protection information system is obtained. Then, combined with the protection information and OCS monitoring signals, anomaly diagnosis is performed based on a deep learning model. This method can establish a correlation analysis range that matches the abnormal event among multi-source heterogeneous data, improve the sufficiency of anomaly verification and the accuracy of diagnostic judgment, and thus balance the reliability of anomaly location and the timeliness of fault response. Attached Figure Description
[0041] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0042] Figure 1 A flowchart illustrating the power grid monitoring signal processing method provided in this application;
[0043] Figure 2 This diagram illustrates the system architecture of OCS.
[0044] Figure 3 A schematic diagram of the power grid monitoring signal processing system according to one embodiment of this application is shown;
[0045] Figure 4 A schematic diagram of the analysis module in this embodiment is shown;
[0046] Figure 5 A schematic diagram of the structure of the protection information preprocessing module in this embodiment is shown;
[0047] Figure 6 A schematic diagram of the structure of the protection information preprocessing module in this embodiment is shown;
[0048] Figure 7 A schematic diagram of the structure of the electronic device provided in this application.
[0049] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0050] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0051] Power grid dispatching and monitoring technology is typically used for online operation status monitoring and fault early warning applications of power transmission and transformation equipment. In actual operation, the dispatching and monitoring system needs to continuously receive operating parameters and status signals uploaded from acquisition terminals such as sensors, RTUs, and IEDs, and aggregate information such as main transformer winding temperature, line current, bus voltage, circuit breaker opening and closing status, and protection device action records into a unified monitoring platform for display, alarming, and coordinated handling. This type of system generally consists of an acquisition layer, a transmission layer, and an application layer. The acquisition layer is responsible for real-time sampling of various power equipment, the transmission layer sends data to the monitoring platform through fiber optic communication networks or Ethernet, and the application layer completes signal parsing, status judgment, alarm generation, and dispatch interface presentation.
[0052] Due to the large number of power grid devices, rapid changes in their operating status, and complex types of monitored objects, the data on the monitoring side often exhibits characteristics of high frequency, strong time sequence, and strong heterogeneity. Therefore, in dispatch monitoring scenarios, how to identify equipment anomalies in a timely manner, how to accurately determine the authenticity of anomalies, and how to provide a reliable basis for subsequent handling have become the core issues that the monitoring system must solve.
[0053] Besides the monitoring system, the protection information management system also plays a crucial role in the same business scenario. It is responsible for collecting data such as action records, fault waveforms, setting parameters, and device self-test information from protection devices, typically used to assist in fault analysis, protection verification, and post-event traceability. Both systems jointly serve the safety of power grid operation; however, in existing application scenarios, they often operate separately with insufficient data linkage, making it difficult to form a unified closed loop between monitoring judgment and protection verification. This has created a clear demand in power grid dispatch scenarios for more efficient and accurate data collaborative processing capabilities.
[0054] Existing power grid dispatch and monitoring solutions typically rely primarily on monitoring-side data, combined with historical logs or preset rules for anomaly analysis. Specifically, after acquiring OCS monitoring signals, the system performs noise reduction, format correction, and basic standardization. Then, it uses a rule engine or traditional machine learning models to analyze features such as amplitude changes, slope abrupt changes, and state linkages to determine if a particular device or signal point exhibits anomalies. For example, if the main transformer temperature signal exceeds a set threshold, or if the line current experiences excessive fluctuations within a short period, the system will output an alarm message; if the circuit breaker status and the disconnector status are inconsistent, an anomaly warning will also be given based on linkage rules. While this type of solution can achieve basic alarm functions in general scenarios, its operating principle still mainly relies on single-source data from the monitoring side. Anomaly judgment is often based on limited temporal features and static rules, making it difficult to fully reflect the true state of power equipment under complex operating conditions.
[0055] On the one hand, protection information systems accumulate a large amount of data directly related to faults, such as protection action sequences, recorded waveforms, fault location results, soft messages, and device self-test information. This data can verify whether an anomaly has actually occurred from a perspective closer to the essence of the fault. However, existing solutions typically do not incorporate this data into the anomaly judgment chain, resulting in a lack of effective verification of alarms on the monitoring side, leading to prominent false alarms, missed alarms, and duplicate alarms. On the other hand, the data types in protection systems are complex, including both structured fields and a large amount of unstructured or semi-structured text. If this data is directly incorporated into the anomaly analysis process, additional processing steps such as standardization, word segmentation, entity recognition, and encoding mapping are often required. This results in long processing chains, high time consumption, and potential conflicts with the timeliness requirements of dispatch scenarios. At the same time, the scale of power grid equipment continues to expand, and the number of monitoring points and the amount of protection data are growing exponentially. If all data is processed synchronously, it will not only lead to significant computational consumption but also cause lengthy inference chains, making it difficult for the system to achieve rapid response in sudden fault scenarios.
[0056] Therefore, how to simultaneously ensure the accuracy of anomaly detection, the effective utilization of protection information, and the timeliness of fault response in power grid dispatch and monitoring scenarios has become an urgent technical problem to be solved. In view of this, this application provides a method for processing power grid monitoring signals. By acquiring the OCS monitoring signals of the power grid dispatch and monitoring system, suspected anomaly nodes are first identified based on the OCS monitoring signals. Then, based on the equipment corresponding to the suspected anomaly nodes and the type of OCS monitoring signals, supplementary suspected anomaly nodes are determined in conjunction with a preset association table. Subsequently, the suspected anomaly nodes and supplementary suspected anomaly nodes are combined into a suspected anomaly node package. Based on the time sequence window corresponding to each anomaly node in the node package, relevant protection information is obtained from the protection information system. Finally, based on the protection information and the OCS monitoring signals, anomaly diagnosis is performed using a deep learning model. This technical approach automatically introduces relevant supplementary nodes and corresponding protection information after anomaly attention is triggered by a signal on the monitoring side. This makes anomaly diagnosis no longer limited to a single monitoring signal but based on the joint analysis of monitoring data and protection data, thereby improving anomaly verification capabilities, shortening the fault response chain, and enhancing the reliability of locating abnormal equipment and anomaly time windows.
[0057] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0058] Example 1
[0059] Figure 1 This is a flowchart illustrating the power grid monitoring signal processing method provided in this application, as shown below. Figure 1 As shown, the method includes the following steps:
[0060] S101: Obtain monitoring signals from the power grid dispatching and monitoring system OCS.
[0061] In this embodiment, the executing entity can be a monitoring signal processing server, cluster computing node, edge analysis gateway, or data analysis platform that interfaces with the dispatch monitoring system, deployed on the dispatch master station side. OCS monitoring signals can be understood as a set of operation monitoring signals originating from the power grid dispatch monitoring system. These signals reflect the real-time status of transmission and transformation equipment, electrical circuits, and secondary devices during operation, and can include analog signals, status signals, and event signals. Analog signals include bus voltage, line current, active power, reactive power, main transformer winding temperature, and frequency; status signals include circuit breaker open / close position, disconnector position, protection on / off status, and pressure plate status; event signals include remote signaling changes, over-limit triggering, and SOE (Sequence of Events) sequential event records. The acquisition process is not merely about simply receiving data, but includes processing steps necessary for dispatch scenarios such as data access, time alignment, format unification, quality verification, and cache organization.
[0062] In one possible embodiment, OCS monitoring signals enter the signal processing platform via a scheduling data bus, IEC 60870-5-104 communication link, IEC 61850 message interface, message queue interface, or database subscription interface. For data from different plants, different acquisition terminals, and different subsystems, the platform first unifies the equipment identification of the original signals based on the equipment ledger and point mapping relationship, mapping the plant number, interval number, equipment code, signal point name, and signal type to internal standard identifiers to avoid duplicate or missed identification of the same equipment due to different naming habits. A unified timestamp is added to the acquired signals. The timestamp can be the signal source upload time, the master station reception time, or a standard time corrected by the time synchronization system. For multi-source signals with different sampling periods, resampling or interpolation alignment can be performed according to a preset time granularity. For example, 1-second telemetry, millisecond SOE events, and minute-level statistics can be uniformly mapped to a compatible time axis to facilitate subsequent anomaly analysis.
[0063] OCS monitoring signals can be understood as monitoring data objects that can be used for operational analysis in the system; signal type is used to distinguish the category of signals in a business sense, such as temperature, current, voltage, switch status, and protection status; time sequence data is used to represent data sequences with a time sequence; in this embodiment of the application, a node can be understood as an analysis unit jointly determined by device identifier, signal type, and corresponding time segment.
[0064] To ensure the reliability of subsequent identification of suspected abnormal nodes, the received OCS monitoring signals also need to undergo basic cleaning processing. Specifically, null values, illegal characters, obviously out-of-bounds values, duplicate reported values, and excessively jittery values can be removed, corrected, marked, or aggregated, respectively. For example, in cases where the circuit breaker position remote signaling experiences multiple round-trip transitions within a very short period, a minimum stable duration threshold can be set to filter out false changes caused by communication jitter. For analog signals, moving average filtering, median filtering, or Kalman filtering can be performed to eliminate spike noise while retaining actual operational disturbances. For signals related to sudden events, the original change sequence and occurrence time are retained, and the event sequence is not smoothed to avoid destroying accident process information. After the above processing, a structured monitoring signal data stream is generated. The data record includes at least the equipment identifier, plant information, signal point identifier, signal type, sampled value or status value, event attribute, and standard timestamp, and is written to the real-time buffer and time-series database to trigger the next step of suspected anomaly identification.
[0065] Based on the above processing, the scattered, heterogeneous, and time-inconsistent monitoring data are first transformed into standardized time-series objects that can be analyzed uniformly, thus providing a consistent data foundation for the accurate capture of subsequent anomalies. By completing standardization and time alignment during the acquisition phase, the uncertainty of subsequent model inputs can be effectively reduced, and a comparable basis can be established between monitoring signals and data from the information protection system in the time dimension.
[0066] S102: Identify suspected abnormal nodes based on OCS monitoring signals.
[0067] In this embodiment, a suspected anomaly node represents an analysis object that has exhibited abnormal symptoms at the monitoring signal level and requires further verification and expanded analysis. A suspected anomaly node is not directly equivalent to a final fault conclusion, but rather represents the initial screening result of the anomaly focus area. Each suspected anomaly node can be described by a device identifier, signal type, anomaly characteristics, start time, end time, anomaly score, and a corresponding timing window, where the timing window defines the temporal impact range of the anomaly. The timing window can be a fixed-length window or a dynamically generated window adaptively around the anomaly trigger point. For example, for a sudden event, the timing window can be set to 5 seconds before the trigger and 30 seconds after; for a gradually rising temperature anomaly, the timing window can be set to 30 minutes before the trigger and 2 hours after.
[0068] In one possible embodiment, the system reads standardized OCS monitoring signals from the real-time buffer and employs different anomaly identification strategies for different signal types. For analog signals, its absolute amplitude, rate of change, slope, fluctuation amplitude, local extrema, periodic deviation, and adjacent time window statistics can be calculated. If a temperature signal exceeds the rated temperature rise threshold of the equipment, or continues to rise within a preset time and the slope exceeds the change threshold, the equipment and time segment corresponding to the temperature signal are marked as suspected abnormal nodes. For operational quantities such as current and voltage, the statistical mean of the steady-state interval and dynamic deviation can be combined to identify over-limit, imbalance, sudden drop, sudden rise, and oscillation anomalies. For status signals, contradictory status anomalies can be identified based on the equipment linkage logic, such as circuit breaker being switched on but current continuing to flow, disconnector position inconsistent with operating mode, and protection activation / deactivation status not matching the maintenance plan. For event signals, SOE sequence and event density can be used to detect short-term concentrated clusters of abnormal events.
[0069] In some embodiments, to improve the adaptability of identification, rule analysis and data-driven analysis can be combined to generate suspected abnormal nodes. The rule analysis part is used to take into account existing scheduling operation procedures and equipment alarm thresholds, while the data-driven analysis part obtains a dynamic baseline through historical normal operating condition modeling. Specifically, a reference baseline can be constructed based on historical signals of similar equipment under similar loads, similar ambient temperatures, and similar operating modes. When the current signal deviates from the reference baseline by a preset deviation value, an anomaly score is generated. The anomaly score can be calculated by weighting multiple sub-scores, such as limit violation score, slope change score, linkage conflict score, and persistence score. For example, the formula "anomaly score = α × limit violation index + β × rate of change index + γ × linkage conflict index + δ × duration index" can be used, where α, β, γ, and δ are weight coefficients obtained from historical sample training or manual calibration, and each index takes a value between 0 and 1 after normalization. The purpose of this formula is to uniformly map different types of abnormal features into comparable quantitative results, enabling the system to select nodes that need in-depth analysis according to a unified threshold or sorting strategy. When the parameter value is in the range of 0 to 1, it is easy to keep the contribution of each indicator under control and avoid the excessive amplification of a single indicator to cover up other abnormal signs.
[0070] Suspected abnormal nodes can be understood as equipment signal analysis units that initially show abnormal signs; timing windows can be understood as time ranges established around the time of abnormal occurrence; abnormal scores can be understood as quantitative evaluations of the probability or severity of abnormalities; dynamic baselines can be understood as normal behavior reference models built based on historical similar operating conditions.
[0071] After identification, the system encapsulates each signal instance that triggers an anomaly as a node record and writes it to a pool of suspected anomaly nodes. For multiple anomaly records triggered by the same type of signal from the same device within adjacent timeframes, aggregation can be performed to merge them into a single persistent suspected anomaly node, avoiding redundant analysis. For cases where different signal types from the same device are simultaneously abnormal, each node is retained separately, and their potential correlations are recorded. The key function of this step is to quickly identify a limited number of key analysis objects from massive OCS monitoring signals, eliminating the need for a full retrieval of all security data in subsequent processing. Based on the above analysis, by first establishing suspected anomaly nodes on the monitoring side, initial anomaly screening can be completed with low latency, providing a clear device and time range for subsequent cross-system information linkage, thus balancing response speed and analysis accuracy in scheduling scenarios.
[0072] S103: Based on the device and OCS monitoring signal type corresponding to the suspected abnormal node, determine the suspected abnormal supplementary node based on the preset association table; wherein, the association table includes the association relationship of all devices, all types of OCS monitoring signals, and the association relationship of different time windows.
[0073] In this embodiment, the suspected anomaly supplementary node represents an extended analysis object that, although not directly triggered by the anomaly criterion in the initial screening stage, has a strong correlation with the suspected anomaly node based on device topology, primary and secondary correlations, signal linkage patterns, or time propagation characteristics. The correlation table is a knowledge-based mapping structure built for collaborative analysis of scheduling, monitoring, and protection. Its content covers not only the physical connection relationships between devices, but also the functional correlation relationships between different signal types within the same device, as well as the common temporal relationships across devices and signals during the accident evolution process.
[0074] In one possible embodiment, the association table is composed of a device association sub-table, a signal association sub-table, and a timing window association sub-table. The device association sub-table records the connection relationships between the main transformer and its high-voltage and low-voltage side switchgear, the attribution relationships between lines and adjacent busbars, switch bays, and protection devices, and the linkage relationships between capacitors, reactors, and their respective bays. The signal association sub-table records strong correlations between a certain signal type and other signal types, such as the correlation between circuit breaker tripping status and corresponding current drops, the correlation between protection action signals and switch position changes, and the correlation between temperature rise and persistently high load current. The timing window association sub-table records the typical temporal correspondences of different anomaly types. For example, protection actions typically occur within milliseconds to seconds after a sudden change in fault current; switch position signal changes may occur within several hundred milliseconds to several seconds after a protection trip; and equipment temperature rise may occur within minutes to hours after a prolonged load anomaly. By pre-storing these associations, the system can, after a suspected anomaly node appears, not only focus on the node itself but also on related nodes in its upstream and downstream time-series links.
[0075] In one specific implementation, the system reads the device identifier, signal type, and abnormal timing window of a suspected abnormal node, and retrieves the matching set of associated devices, the set of associated signal types, and the associated time offset rules from the association table. If the initial suspected abnormal node is a node with a sudden increase in current on a certain line, the association table can return the status signals of the circuit breakers to which the line belongs, the voltage signals of adjacent busbars, the protection action signals, the reclosing status signals, and the measurement point signals on both sides of the line, and give the time extension range of each associated object relative to the original abnormal window. Based on this, the system retrieves data segments of the corresponding device and signal type from the monitoring signal database. If these data segments are within the association window, they are constructed as suspected abnormal supplementary nodes. Objects that do not directly meet the abnormal threshold but show slight disturbances, status responses, or linkage changes within the association window can also be included in supplementary nodes to retain the contextual information in the accident chain.
[0076] The association table can be understood as a pre-established structured knowledge base used to represent device relationships, signal relationships, and time relationships; the association relationship can be understood as the physical, functional, or temporal correlation between two analysis objects; the suspected anomaly supplementary node can be understood as the related analysis node obtained by expanding the original suspected anomaly node; the association relationship of different time windows can be understood as the sequential offset and coverage relationship of different types of events in the time dimension.
[0077] This step can also introduce a correlation strength parameter to control the expansion range of supplementary nodes. Correlation strength can be obtained statistically from historical fault samples, such as the probability of a signal and target anomaly co-occurring in similar accidents, the time overlap rate, and the stability of causal sequence. For objects with correlation strength higher than a threshold, supplementary nodes are directly generated; for objects with correlation strength in the middle range, further judgment is made based on the current operating conditions; for objects with excessively low correlation strength, they are not included in the current node package to avoid an overly broad analysis scope. In this way, the system can achieve a balance between covering key contextual information and controlling computational complexity. Based on the above analysis, this step is a key link in solving the shortcomings of single-source analysis on the monitoring side. By introducing three types of correlations—device, signal, and time series—it expands the anomaly analysis object from a single point to a set of nodes with causal and linkage semantics, thereby laying the foundation for accurate retrieval of subsequent protection information and reducing the latency and computational consumption caused by indiscriminate full retrieval of the protection information system.
[0078] S104: Take the suspected abnormal nodes and suspected abnormal supplementary nodes as a suspected abnormal node packet, and obtain the protection information in the protection system based on the time sequence window corresponding to each node in the suspected abnormal node packet.
[0079] In this embodiment, a suspected anomaly node packet can be understood as a joint analysis container formed around the same abnormal event or the same device link. Each node packet includes at least one initial suspected anomaly node and one or more supplementary suspected anomaly nodes, and retains the device identifier, signal type, associated source, anomaly score, and timing window for each node. The establishment of node packets enables the system to perform cross-system searches based on event clusters rather than single signal points, thereby ensuring that the scope of protection information retrieval is consistent with the scope of anomalies on the monitoring side. The protection information in the protection information system can include protection action records, action sequence, alarm soft messages, fault waveform index, waveform summary, setting information, startup information, device self-test results, ranging results, pressure plate status, anomaly messages, and device communication status, etc. This information can be structured fields, text, logs, or semi-structured messages.
[0080] In practice, the system first performs time merging on the nodes within a node package. If the time windows of multiple nodes overlap or the interval is below a preset merging threshold, they are merged into a joint retrieval window; if the nodes belong to significantly different time periods, multiple sub-windows are retained within the same node package. Subsequently, based on the mapping relationship between device identifiers within the node package and device files in the protection information system, the system converts the monitoring-side device codes into protection-side device codes, interval codes, or waveform recording channel codes. After completing the code mapping, the system retrieves the protection information corresponding to each time window through the protection information system interface, data platform interface, log retrieval interface, or file index interface. For action record information, it can be queried directly based on device number and time range; for waveform recording information, it can first retrieve the waveform recording directory and trigger summary, and then load the corresponding waveform features or calculation results as needed; for text-based soft messages and self-test logs, it can filter out sentence fragments related to the node package based on keyword matching, rule templates, and time alignment.
[0081] The protection information management system is used to centrally manage information such as actions, waveforms, settings, and self-tests generated by relay protection devices. It is a data set that can characterize fault processes, protection behaviors, and device health status.
[0082] Considering the complexity and sheer volume of protection information data, this application embodiment employs targeted retrieval by node package, window, and associated device range, rather than uniformly parsing all protection information data. Specifically, the system only retrieves protection information corresponding to the device set in the node package and whose occurrence time falls within the target timing window, and different priorities can be set according to the protection information category. For example, for suspected fault-related anomalies, priority is given to obtaining protection actions and waveform summaries; for suspected long-term operation anomalies, priority is given to obtaining device self-test and status information. For text and semi-structured data, entity extraction and encoding standardization can be performed after retrieval to extract structured features such as device name, protection function number, action type, phase, and ranging result; for waveform data, summary features such as fault start time, peak current, voltage drop amplitude, zero-sequence component, and phase angle offset can be extracted, without loading all original waveforms in each diagnosis. This hierarchical acquisition method shortens the time for protection information to enter the diagnostic link.
[0083] The result of this step is the generation of a set of protection information matching the node packets, which, together with the original OCS monitoring signals, forms a multi-source joint sample. Based on the above analysis, by first constructing suspected abnormal node packets and then acquiring protection information based on the node packet timing window, the introduction of protection data can have clear device and time boundaries. This avoids the drag on system timeliness caused by complex protection information data and ensures that the protection information truly serves the verification of the authenticity of monitored anomalies and process supplementation, thereby improving the reliability of false alarm filtering, anomaly location, and subsequent diagnosis.
[0084] S105: Based on the protection information and OCS monitoring signals, perform anomaly diagnosis using a deep learning model and output the anomaly diagnosis results.
[0085] Deep learning models are used to fuse and analyze monitoring-side operational signals and protection-side verification information to output anomaly diagnosis results. These results can include whether an anomaly exists, the anomaly category, involved equipment, fault time range, associated signal links, confidence level, and a suggested remediation index. The deep learning model can employ a multi-input fusion structure, where one type of input corresponds to the temporal characteristics of the OCS monitoring signal, and another type corresponds to the structured features and textual semantic features of the protection information. If waveform summary features exist, they can also be used as a third type of input to participate in the diagnosis.
[0086] In one possible embodiment, the system first performs serialization encoding on the OCS monitoring signal. For analog time series, a fixed-time slice can be extracted by node packet window, and the original sequence, differential sequence, sliding statistics, and frequency domain features can be extracted. For state and event quantities, they can be converted into event sequences, displacement pulse sequences, or time interval features. On the protection information side, structured action records and setting information can be directly encoded into discrete and numerical features. For soft messages and log text, they can be encoded into semantic vectors through word segmentation, word vector mapping, or a dedicated power terminology vocabulary. For waveform summary features, they are input in the form of standard numerical vectors. Subsequently, each input is encoded through the corresponding feature extraction network, such as a temporal convolutional network, a long short-term memory network, a Transformer encoder, or a combination thereof, to obtain monitoring time series representation, protection behavior representation, and text semantic representation. Then, attention fusion layer, splicing layer, or gated fusion layer are used to jointly model features from different sources, outputting anomaly category probability and authenticity score.
[0087] Deep learning models are data analysis models with multi-layer nonlinear feature extraction capabilities; anomaly diagnosis can be understood as the process of judging whether an anomaly is real, its type, and its associated scope; confidence level can be understood as a quantitative representation of the reliability of the model's output conclusions.
[0088] To make the diagnostic results applicable to scheduling applications, embodiments of this application can integrate model outputs with business rules. For example, when the model gives a high fidelity score and the protection action record and monitoring change are highly consistent in time, the anomaly is marked as a verified anomaly; when the monitoring side signal exceeds the limit significantly but the protection side has no action, no start-up, and the device self-test is normal, the anomaly can be marked as requiring further manual verification or suspected false alarm; when multiple nodes point to the same equipment link and the waveform summary shows obvious fault electrical quantity characteristics, the fault type can be further output, such as instantaneous line fault, switch malfunction, measurement point anomaly, or device communication anomaly. During the model training phase, a supervised dataset can be constructed using historical accident samples, false alarm samples, and normal operation samples, and category identification and fidelity assessment can be optimized through cross-entropy loss, focus loss, or multi-task loss.
[0089] The core technological advantage of this step lies in moving away from relying solely on static rule-based judgments based on single-source signals from the monitoring side. Instead, it involves joint analysis of the external operational characteristics reflected in the monitoring signals and the fault essence and device behavior reflected in the protection information. This allows the model to identify seemingly abnormal events on the monitoring side, where the protection side lacks corresponding evidence, as communication jitter, measurement point anomalies, or transient disturbances. Furthermore, when the protection side has supporting actions and waveform recordings, but the monitoring side's characteristics are not obvious, the model can compensate for insufficient monitoring information, improving the detection rate of genuine anomalies. Based on the above analysis, this step achieves high-dimensional feature fusion of multi-source information through a deep learning model, solving the problem that traditional rule-based methods struggle to dynamically adapt to changes in equipment, operating conditions, and historical case accumulation. Simultaneously, it improves the accuracy of anomaly judgment, the specificity of fault location, and the interpretability of the output results.
[0090] In summary, this embodiment first captures suspected anomalies on the monitoring side, then expands associated nodes using an association table, and retrieves protection information based on the time-series window of the node packets. Finally, it utilizes a deep learning model for joint diagnosis, ensuring that anomaly determination is based on the collaboration between monitoring and protection data. This avoids the response delay caused by synchronously parsing all protection information and alleviates the problems of false alarms, missed alarms, and location errors caused by relying solely on monitoring-side rule judgments. Thus, it can balance the accuracy of anomaly identification, the efficiency of protection information utilization, and the timeliness of fault response in power grid dispatch and monitoring scenarios.
[0091] It should be understood that the above examples are merely illustrative and not limiting. In one possible embodiment, the monitoring signal access method, the association table construction method, the protection information extraction strategy, and the deep learning model structure can all be adjusted according to the specific deployment conditions of the scheduling system. As long as the technical concept of collaborative diagnosis of monitoring and protection information around suspected abnormal nodes can be realized, it can fall within the scope of the description of the embodiments of this application.
[0092] Example 2
[0093] Based on the aforementioned embodiments, further, in step S102, the suspected abnormal node is determined according to the OCS monitoring signal, specifically including: extracting time-series features for each type of OCS monitoring signal of each device in a time-series window, and obtaining the preset threshold corresponding to the time-series feature type; if the value of the time-series feature is greater than the threshold, then the time-series window is determined to be a suspected abnormal node.
[0094] In this embodiment, the OCS monitoring signal refers to the equipment operating parameters, status quantities, or alarm quantities received by the power grid dispatch monitoring system. The time sequence window is used to characterize a fixed-length interval of continuously sampled data, which can be divided by a set number of sampling points or time length. The time sequence feature can be one or more of the following: mean amplitude, peak value, rate of change, fluctuation amplitude, or trend deviation. Its threshold can be preset according to the equipment type, signal type, and historical normal operation data, and can be stored in a threshold table for direct retrieval when analyzing different signals from different equipment.
[0095] In practical implementation, for each type of OCS monitoring signal from each device, the system first performs time alignment and unit unification on the original sampling sequence, then segments it according to a set window length, and calculates the corresponding feature value within each time window. If the feature value extracted within a window exceeds the threshold matching that feature type, the window is marked as a suspected abnormal node, and its corresponding device identifier, signal type, and time interval are output. The threshold can be obtained through historical case statistics or configured directly according to specification limits. In practical applications, the threshold table can also be generated in other ways, which are not limited in this embodiment.
[0096] This method utilizes window-level feature exceedance to locate abnormal time periods, transforming anomaly identification from single-point judgment to time-series correlation judgment, and limiting the anomaly results to specific devices and specific time windows. After obtaining suspected abnormal nodes, the system can further provide input for subsequent supplementary node correlation, protection information acquisition, and anomaly diagnosis, thereby improving the accuracy and timeliness of anomaly localization.
[0097] By adopting the above method, abnormal windows can be identified in a timely manner when fluctuations occur in the monitoring signal, reducing the impact of instantaneous noise on the judgment results and minimizing invalid analysis of the full data. Since anomaly identification is based on preset thresholds and time-series windows, the overall calculation process is simple and can quickly output suspected abnormal nodes in power grid dispatching scenarios, providing a reliable basis for subsequent joint diagnosis.
[0098] Example 3
[0099] Based on the aforementioned embodiments, further, according to the device corresponding to the suspected abnormal node and the OCS monitoring signal type, and based on a preset association table, a suspected abnormal supplementary node is determined, including: from the association table, determining other devices that are associated with the device corresponding to the suspected abnormal node; obtaining the same timing window as the suspected abnormal node for the other devices, and determining the timing window as the suspected abnormal supplementary node.
[0100] Once a suspected anomalous node is identified, the system first matches it against the associated table based on the device identifier corresponding to that node, extracting other devices that are associated with it, and simultaneously searching the monitoring points corresponding to these devices. Subsequently, according to the time sequence window to which the suspected anomalous node belongs, the system extracts OCS monitoring signals within the same time period from the monitoring data of other devices. The time sequence window can be divided according to a fixed length or adaptively determined according to event trigger boundaries, thus ensuring that data from different devices are within the same analysis interval. To adapt to different substations and different signal types, the associated table can also record the association strength, association direction, and window offset between devices, allowing for window alignment correction when necessary. However, in this embodiment, the same time sequence window is still used as the basis for determining suspected anomalous supplementary nodes.
[0101] By employing the above method, the system incorporates monitoring signals from other devices linked to the malfunctioning device within the same time window into the anomaly analysis scope, forming a node set that complements the suspected malfunctioning node. This expands the device coverage for anomaly detection and provides a more complete data foundation for subsequent joint diagnosis using information from the power grid dispatching and monitoring system. This approach enhances the ability to identify cross-device linked anomalies, reduces the probability of misjudgment due to relying solely on signals from a single device, and improves the accuracy of anomaly time window location, making the anomaly diagnosis results more consistent with the actual operational characteristics in power grid dispatching and monitoring scenarios.
[0102] Example 4
[0103] Based on the above embodiment 3, in one possible implementation, when determining a suspected abnormal supplementary node, the following steps are also included: obtaining the extended timing windows of other devices before and after the timing window, and determining the extended timing windows as suspected abnormal supplementary nodes.
[0104] In this embodiment, "time sequence window" refers to a continuous time segment obtained by dividing the monitoring signal according to a preset sampling period, and "other devices" refers to similar or linked devices that are associated with the device corresponding to the suspected abnormal node. The extended time sequence window can be understood as one or more time windows adjacent to the current time sequence window before or after it. Its length can be set according to the sampling frequency, device action delay and protection coordination relationship to cover the precursors and delayed effects of abnormal propagation.
[0105] In its implementation, after identifying a device's timing window as a suspected anomalous node, the system retrieves other devices with electrical or logical connections to that device from the association table. Using the window containing the suspected anomalous node as a baseline, it extends forward and backward by a preset number of adjacent windows. The monitoring signals corresponding to the extended timing windows can continue to use the time alignment relationship from the original sampling sequence, thus maintaining timing comparability with the original anomalous node. The system then marks these extended timing windows as suspected anomalous supplementary nodes, which, together with the original suspected anomalous nodes, constitute a node package to be analyzed, enabling subsequent synchronous acquisition of corresponding protection information and joint diagnosis. If a symmetrical extension method is used, the extension range is one or more windows forward and backward; if an asymmetrical extension method is used, different extension lengths can be assigned to the forward or backward windows based on the device's response characteristics. In practical applications, the window width can be set to a fixed duration or adaptively adjusted based on the event trigger intensity; this embodiment does not limit this.
[0106] The working principle of this method is that when abnormal characteristics appear in the monitoring data within a certain time slice, the anomaly is often not limited to a single window, but will manifest as premature fluctuations, delayed recovery, or coordinated spread in adjacent time windows. By incorporating the extended time windows of other devices before and after the time window into supplementary nodes, the system can simultaneously cover the symptom information before the anomaly occurs and the response information after the anomaly occurs, making the anomaly node package more complete in the time dimension.
[0107] This specific implementation method expands the time-series range of anomaly associations, enhances the ability to capture anomaly propagation chains and linkage processes, reduces missed detections caused by observing only a single window, and improves the accuracy and stability of subsequent anomaly diagnosis based on protection information and monitoring signals. Since the acquisition of supplementary nodes relies on a preset association table and time-series neighborhood expansion rules, the overall processing has good controllability and real-time performance, meeting the requirements for rapid response and precise positioning in power grid dispatching and monitoring scenarios.
[0108] Example 5
[0109] In one possible implementation, the description list of any node in the suspected abnormal node package includes the node's unique identifier, device ID, abnormal timing window, abnormal feature description, and abnormal confidence level.
[0110] In this embodiment, a unique node identifier is used to uniquely number suspected abnormal nodes. It is typically generated by the system using a combination of device type, acquisition source identifier, timing window number, and random checksum. Hash encoding or an incremental sequence number can also be used to ensure the uniqueness of different abnormal nodes globally, facilitating subsequent retrieval, association, and tracing. The device ID identifies the specific power grid equipment or acquisition object corresponding to the abnormal node, such as a main transformer, line, circuit breaker, protection device, or busbar. Its encoding can be consistent with the monitoring system's asset ledger, enabling accurate mapping of abnormal nodes to physical devices. The abnormal timing window characterizes the time interval of the abnormal signal. Its window length can be set in seconds, minutes, or with a fixed number of sampling points to adapt to the changing characteristics of different types of OCS monitoring signals and provide a time anchor for the synchronous extraction of protection information. The abnormal feature description records the characterization information of the abnormal node, typically including descriptions such as exceeding limits, continuous increase, sudden change, jitter, abnormal slope, inconsistent state, or linkage mismatch. This field can be generated jointly by rule judgment results, statistical features, and model output labels. Anomaly confidence is used to quantify the credibility of an anomaly node. It is usually determined based on the threshold deviation, historical similar sample matching results, deep learning model output probability, and multi-factor fusion score. Its value range can be set between 0 and 1 to facilitate subsequent priority ranking of different anomaly nodes.
[0111] In practical implementation, after identifying suspected abnormal nodes, the system writes the above fields into a node list and encapsulates them into a suspected abnormal node package. The unique node identifier ensures data consistency between the monitoring and protection information sides for the same abnormal point. The device ID limits the retrieval range of protection information. The abnormal timing window limits the reading interval of protection waveforms, action records, and status variables. The abnormal feature description provides semantic input to subsequent diagnostic modules, and the abnormal confidence score is used to prioritize the analysis of highly reliable nodes when multiple suspected nodes coexist. By storing these fields in a unified structured manner, the system can form a stable data index relationship during abnormal supplementary node matching, protection information retrieval, and deep learning diagnostic processes.
[0112] The working principle of this node list is to transform the originally scattered anomaly observation results into information units with unique identities, device affiliations, time locations, characteristic descriptions, and reliable quantifications. This enables suspected anomaly node packages to not only carry data but also be searchable, fusionable, and sortable. Based on this structure, the system can quickly locate relevant devices and corresponding time-series windows, and map protection information in the protection information system to anomaly nodes one-to-one, providing accurate input for joint diagnosis.
[0113] With the above structure, the expression of suspected abnormal nodes is more complete, and the abnormal object, abnormal time, and abnormality can all be clearly identified. This reduces ambiguity in subsequent correlation analysis, improves the accuracy of protection information extraction, and enhances the interpretability and traceability of abnormal diagnosis results. At the same time, the introduction of anomaly confidence helps reduce the interference of low-confidence anomalies on diagnostic results, improving the system's alarm screening efficiency and handling accuracy in complex power grid scenarios.
[0114] Example 6
[0115] Based on any of the foregoing embodiments, the steps for creating the association table further include: using power grid equipment ledgers, historical data from the OCS and information protection system, and power grid operation specifications as data sources, inputting equipment association relationships, association relationships of all types of OCS monitoring signals, and time sequence window association relationships; calling historical anomaly case data of the power grid to verify the association relationships, eliminating invalid associations and correcting deviation associations to form an initial association table; obtaining supplementary feedback data from suspected anomaly nodes, fusion analysis feedback data, and power grid operation feedback data; identifying valid association relationships that have not been entered based on the feedback data; and adding valid association relationships to the initial association table to obtain an updated association table.
[0116] In this embodiment, the power grid equipment ledger provides equipment name, equipment number, commissioning information, assigned bay, and topological connection relationship. Historical data from the OCS and protection information system provides historical changes in monitoring signals, protection action records, fault waveform summaries, and alarm linkage records. Power grid operation specifications constrain the boundaries of possible associations between equipment and the effective range of time-series windows. The system maps the equipment topology in the ledger to equipment associations, maps the co-occurrence, linkage, or substitution relationships exhibited by monitoring signals in historical operation to all types of OCS monitoring signal associations, and maps the sequential, synchronous, or lagging relationships of different alarms, actions, and anomalies on the time axis to time-series window associations, thereby forming a set of associations to be verified.
[0117] When verifying the entered correlations by calling historical anomaly case data of the power grid, the system matches the faulty equipment, abnormal signals, protection actions, and time windows in the historical anomaly cases one by one with the current correlation set. If a correlation does not show a stable correspondence in multiple known cases, or if its time offset exceeds the limit of the operating specifications, it is judged as an invalid or biased correlation, and its correlation direction, correlation strength, and corresponding window range are removed from or corrected from the initial correlation table. For the corrected correlations, the system can re-record them as usable equipment correlations, signal correlations, and timing correlations to ensure that the initial correlation table can reflect relatively reliable power grid linkage relationships based on existing experience.
[0118] During operation, the system further receives supplementary feedback data from suspected anomaly nodes, fusion analysis feedback data, and power grid operation feedback data. The supplementary feedback data reflects newly discovered related equipment or signals after anomaly diagnosis; the fusion analysis feedback data reflects newly added correspondences obtained from joint analysis by the monitoring and information protection sides; and the power grid operation feedback data reflects the actual correlation results confirmed by dispatching, on-site verification, and fault review. Based on the above feedback data, the system identifies valid correlations that have not been entered and adds newly established correlations verified on-site or historically to the initial correlation table, resulting in an updated correlation table.
[0119] Through the above mechanism, the association table can continuously absorb online feedback information based on historical case verification, keeping device association, signal association, and timing window association dynamically updated. This updated association table can be directly called upon in subsequent anomaly node identification and supplementary node expansion, thereby improving the accuracy of hitting suspected anomaly supplementary nodes, reducing the probability of false positives caused by invalid associations, and enhancing the ability to characterize anomaly propagation relationships and protection response relationships under complex operating conditions.
[0120] Example 7
[0121] Based on any of the foregoing embodiments, the protected information further requires preprocessing before model analysis. The preprocessing steps include: cleaning, normalizing, and encoding the structured data in the protected information to generate standardized structured feature vectors; using natural language processing technology to transform the unstructured data in the protected information into structured data through word segmentation, entity recognition, and text embedding; and integrating the processed structured and unstructured data to generate a unified format of protected information data feature package.
[0122] In this embodiment, structured data may include fields such as protection device operation timestamps, input / output status, setting zone numbers, fault types, tripping flags, and waveform indexes. These fields typically have fixed data types and defined value ranges. Data cleaning is used to remove duplicate records, correct abnormal codes, complete missing fields, and standardize timestamp formats to ensure consistency of fields for the same protection event across different sources. Feature normalization is used to map amplitude, count, and duration fields to a unified scale, avoiding bias in subsequent fusion calculations due to different dimensions. Encoding conversion is used to convert discrete category fields into machine-computable vector representations. Encoding can employ one-hot encoding, binary encoding, or category mapping encoding to improve the model's ability to represent differences in protection states.
[0123] Unstructured data may include protection action reports, fault recording descriptions, device self-test text, soft message descriptions, and maintenance record text. After receiving the above text, the system first performs word segmentation, then combines part-of-speech and context rules to identify entity information such as device name, action element, protection type, action time, abnormal phenomenon, and fault location. Finally, it converts the semantic content into a fixed-length vector representation through text embedding, thereby making the original text computable and comparable. Text embedding can be based on word vectors, sentence vectors, or contextual semantic representation models to enhance the semantic recognition ability of synonyms, abbreviations, and complex sentence structures. In practical applications, other models can also be selected, and this application embodiment does not limit this choice.
[0124] When integrating structured and unstructured data, the system concatenates, aligns, or uniformly maps standardized structured feature vectors with text semantic vectors to form a data feature package with a fixed field order and unified dimensions. This feature package can further carry metadata such as device identifier, source time, data confidence level, and sample index, so that it can be fused and compared with OCS monitoring signals within the same time window. Through this processing method, the data security information completes format unification, semantic compression, and vectorization encapsulation before entering the fusion analysis model, thereby reducing parsing errors caused by direct input of heterogeneous data.
[0125] This data feature package can serve as an input source for the protection side during operation, and can be jointly modeled with the time-series features of the OCS monitoring signal in the same feature space. Since the structured fields have been scaled and the unstructured text has been semantically extracted, subsequent models can directly call this feature package for anomaly correlation judgment and fault consistency verification, without having to repeatedly perform format parsing and text cleaning, thereby improving the stability and real-time performance of the fusion analysis.
[0126] By adopting the above method, different data types in the protection information can be uniformly transformed into computable features, avoiding the information fragmentation problem that occurs when raw text and discrete fields directly participate in the fusion. Since data cleaning, normalization, and encoding conversion can improve the consistency of structured data, and word segmentation, entity recognition, and text embedding can improve the semantic usability of unstructured data, the resulting protection information data feature package is more conducive to improving the accuracy of fusion analysis, reducing the false judgment rate, and shortening the power grid fault diagnosis link.
[0127] Figure 2 The diagram illustrates the system architecture of OCS, including the acquisition layer, transmission layer, application layer, and data storage layer. Figure 2As shown, the acquisition layer employs a distributed deployment, with independent acquisition units deployed in each substation and distribution area to achieve full coverage. The acquisition layer includes various sensors, RTUs, IEDs, and acquisition gateways. Sensors are responsible for collecting operating parameters of the equipment (e.g., temperature, current, voltage), RTUs and IEDs are responsible for converting the collected data into standardized formats, and acquisition gateways are responsible for aggregating the collected data for their respective areas and pushing it to the transmission layer via power industry standard communication protocols such as IEC 61850 and IEC 104. The transmission layer is responsible for data transmission between the acquisition layer and the application layer. The transmission layer includes a fiber optic communication network, Ethernet switches, and a communication protocol adaptation module. The fiber optic communication network uses a primary fiber optic and wireless backup communication method to ensure high-speed and stable data transmission. The communication protocol adaptation module supports multiple power industry standard protocols such as IEC 61850 and IEC 104, enabling compatible data transmission from different manufacturers and types of acquisition equipment. It also incorporates a data encryption module to prevent tampering during data transmission and ensure data security. The application layer, as the core layer of the OCS, integrates various functional modules to realize data processing, analysis, monitoring, and linkage, such as... Figure 2 As shown, the application layer includes:
[0128] The data preprocessing module is used to perform noise reduction, completion, and standardization of the collected data;
[0129] The analysis module is used to perform anomaly analysis on OCS monitoring signals;
[0130] The monitoring and display module is used to present equipment operating status, alarm information, etc. to dispatchers.
[0131] The above are the typical application layer components of an OCS (Optical System for Applications). See [link / reference]. Figure 2 In this application, the application layer also includes a node capture module, which is used to capture suspected abnormal nodes in the OCS monitoring signal in real time and generate suspected abnormal node packets.
[0132] The linkage interface module is used to establish a data interaction channel with the protection information preprocessing module and the large model fusion analysis module.
[0133] Optionally, the application layer adopts a primary and backup dual-machine architecture to ensure that core functions are not interrupted, while supporting the expansion of functional modules to adapt to the needs of power grid expansion.
[0134] like Figure 2As shown, the data storage layer is responsible for storing all OCS process data, including a real-time database, a historical database, and a data backup unit. The real-time database stores real-time acquired OCS monitoring signals, analysis results, and information on suspected abnormal nodes, supporting millisecond-level read and write operations to ensure real-time analysis needs. The historical database stores historical acquired data, anomaly handling records, threshold calibration records, etc., providing data support for large model self-learning, threshold calibration, and fault tracing. The data backup unit adopts an off-site backup mechanism to prevent data loss and ensure data security and traceability.
[0135] Figure 3 The diagram shows a schematic of the power grid monitoring signal processing system in one embodiment of the present application, including a node capture module 100, a protection information preprocessing module 200, and an analysis module 300. The protection information preprocessing module 200 is used to receive suspected abnormal node packets, capture protection information in the protection information system based on the timing window in the suspected abnormal node list, and temporarily cache the protection information after preprocessing. After receiving an anomaly determination instruction, the cached protection information is fed to the analysis module 300 as needed. At this time, the analysis module 300 performs fusion analysis on the received protection information and OCS monitoring signals.
[0136] It should be noted that the analysis module 300 and the node capture module 100 in the application layer are independent and run in parallel, without any dependencies or functional conflicts. Both receive standardized data pushed by the data preprocessing module and perform their core tasks independently. That is, the node capture module 100 does not participate in the anomaly analysis process of the OCS monitoring signal; in other words, the analysis process of the analysis module 300 does not depend on the capture results of the node capture module 100. The interaction between the two only occurs when the analysis module 300 determines that the OCS monitoring signal is abnormal. At this time, the analysis module 300 extracts the protection information of the corresponding suspected abnormal node through the linkage interface module, providing data support for subsequent anomaly handling and fault tracing.
[0137] Figure 4 The diagram shows the structure of the analysis module in this embodiment. The analysis module 300 supports full coverage analysis of multiple types of OCS monitoring signals, can adapt to the operating conditions of different power grid equipment, has dynamic adaptive optimization capabilities, and can directly connect to the OCS data preprocessing module, linkage interface module, and monitoring display module to achieve seamless data flow and functional closed loop.
[0138] Optionally, the hardware deployment of the analysis module 300 uses industrial-grade servers, with identical primary and backup configurations. Server configuration requirements are: CPU (≥2 cores), ≥64GB DDR4 memory, ≥1TB SSD (for real-time data caching) + 4TB SATA (for local analysis log storage), and gigabit optical network cards (≥2 units, one for data access and one for data output). The operating system supports automatic recovery after power failure and restart. The analysis module 300 internally employs distributed computing power allocation, such as... Figure 4 As shown, it is divided into a data access unit, a feature extraction unit, an anomaly detection unit, an alarm generation unit, a log storage unit, and an interface adaptation unit. Each unit runs as an independent process and does not occupy computing resources. Data interaction is achieved through an internal message queue (RabbitMQ) to ensure that each unit operates in a coordinated and efficient manner. The data access unit and the anomaly detection unit are configured with the highest computing priority to ensure real-time analysis needs.
[0139] Optionally, the interface between the analysis module 300 and external modules adopts a standardized design. The data access interface adopts a publish-subscribe (Pub / Sub) mode and connects to the OCS data preprocessing module. The data output interface adopts a RESTful API interface and connects to the linkage interface module, monitoring and display module, and data storage layer respectively. The interface communication protocol adopts TCP / IP, and the data transmission encryption adopts the AES-256 encryption algorithm to ensure data transmission security.
[0140] In one embodiment, the data preprocessing module preprocesses three types of signals: basic operating parameter signals, equipment status signals, and raw alarm event signals. The raw alarm event signals are directly triggered by sensors and intelligent terminals (RTU / IED) in the acquisition layer. When the acquisition layer sensors detect instantaneous extreme anomalies in the equipment (such as current instantaneously exceeding physical limit thresholds or circuit breaker unexpectedly tripping), or when the intelligent terminal detects a fault in the actuator, a raw alarm event signal is immediately generated and pushed to the data preprocessing module via the transmission layer. The data preprocessing module filters out invalid alarms (such as false alarms caused by mis-collection or invalid alarms caused by transient interference) and standardizes the format before pushing it, along with the basic operating parameter signals and equipment status signals, to the analysis module 300.
[0141] The analysis module 300 performs comprehensive analysis and verification of these three types of signals. On the one hand, it determines the authenticity of the original alarm event signals, filters false alarms and confirms true alarms. On the other hand, it identifies hidden anomalies (such as signal trend deviations and periodic anomalies) that were not captured by the original alarms. Finally, it generates anomaly judgment instructions and generates anomaly alarm signals, which are pushed to the monitoring and display module for dispatchers to handle.
[0142] Data access employs a dual-mode approach: real-time subscription and batch tracing. The real-time subscription mode acquires real-time OCS monitoring signals pushed by the preprocessing module. The push frequency is consistent with the sampling frequency of the acquisition layer (default 100ms / time, dynamically adjustable based on device type; for core devices such as main transformers and circuit breakers, the sampling frequency is adjusted to 50ms / time). The data format is standardized JSON, containing seven core fields: device ID, timestamp, signal type, signal value, signal unit, operating condition identifier, and preprocessing status. The batch tracing mode is used for module startup initialization, anomaly tracing, or operating condition adaptation. It batch retrieves historical OCS monitoring signals from the historical database of the data storage layer. The tracing range is configurable (default 7 days, maximum 1 year), used for trend analysis, threshold calibration, and algorithm optimization. The data access unit has a built-in data verification mechanism that performs integrity checks (filling in missing fields), timeliness checks (discarding expired data), and format checks (rejecting non-standardized formats). Data that passes verification is pushed to the feature extraction unit; data that fails verification is logged and fed back to the data preprocessing module, ensuring high-quality analysis data.
[0143] As can be seen from the above scheme, the analysis objects of the analysis module 300 specifically include three categories: basic operating parameter signals, equipment status signals, and original alarm event signals. Among them, the basic operating parameter signals cover numerical signals such as main transformer winding temperature, line current, bus voltage, active power, reactive power, and frequency; the equipment status signals cover discrete signals such as circuit breaker open / close status, disconnector open / close status, protection device on / off status, and equipment operation / maintenance status; and the original alarm event signals cover structured event signals such as instantaneous alarms, fault alarms, and abnormal prompts triggered by the acquisition layer. The various analytical objects within the analysis module 300 are stored using a dual storage model of "time series + feature vector". Basic operating parameter signals (numerical) are stored as multi-dimensional time series sequences. The sequence elements include five core elements: timestamp, signal value, operating condition label, historical mean, and historical variance. The time series is stored in a circular buffer with a default cache duration of 10 minutes. Time series data exceeding the cache duration is automatically archived to the local log storage unit. Device status signals and raw alarm event signals are stored as structured status matrices. The matrix rows contain device IDs, the columns correspond to timestamps, and the matrix values are the signal status values or event details. All analytical objects are uniformly mapped to standardized feature vectors with a fixed 64-dimensional dimension. Numerical signals are extracted for features such as amplitude, rate of change, trend slope, and periodicity matching degree. Discrete signals are extracted for features such as state change frequency, logical matching degree, and number of state conflicts. The feature vectors are stored in an in-memory database (Redis) for quickly invoking anomaly detection algorithms, improving analysis efficiency. The log storage unit within the analysis module 300 adopts a circular overwrite mode to store analysis process logs, anomaly judgment logs, data verification logs, and alarm generation logs. The default log storage duration is 30 days. Log queries can be performed by device ID, timestamp, and anomaly type, providing support for subsequent fault tracing and module optimization.
[0144] Analysis module 300 first targets the basic operating parameter signals (numerical type), whose anomalies are mainly divided into four categories: transient mutation anomalies, trend deviation anomalies, periodic anomalies, and out-of-limit anomalies. The transient mutation anomaly analysis adopts the time-series window (i.e., sliding window) time-series difference method, with the time-series window size fixed at 5 sampling points (i.e., 500ms). The first-order difference of the signal within each window (ΔV=V) is calculated in real time. n -V n-1 ) and second-order difference (Δ²V=ΔV) n -ΔV n-1The system combines a large-scale model with self-learning optimized mutation thresholds (default current mutation threshold is 10% of rated current / 100ms, temperature mutation threshold is 5℃ / 100ms, which can be dynamically adjusted according to equipment type) to filter candidate mutation windows whose absolute difference exceeds the threshold. Neighborhood time-series verification is then performed on these candidate mutation windows, retaining only windows with mutations occurring at two or more consecutive sampling points. Reasonable mutation scenarios such as equipment operation and fault triggering are excluded, ultimately determining them as instantaneous mutation anomalies. The large-scale model, based on historical monitoring signal data from OCS (full time-series data for the past 1-3 years), employs a Transformer time-series model architecture. Through self-supervised learning, it autonomously learns the signal mutation characteristics under different equipment and operating conditions. The core logic involves feature labeling of historical mutation data (including normal and abnormal mutations), capturing the correlation between mutation signals and equipment operating conditions and the operating environment through an attention mechanism, autonomously training a mutation threshold optimization model, and dynamically adjusting the threshold in real time according to the current equipment operating conditions (such as peak load and summer high temperatures) to avoid misjudgments or omissions caused by fixed thresholds.
[0145] Trend deviation anomaly analysis first uses historical data and a combination of linear regression and exponential fitting algorithms to fit a normal trend model for each type of equipment and each operating condition (peak / off-peak / valley, summer / winter / spring / autumn). It then calculates the deviation rate between the current signal trend and the normal trend model in real time (deviation rate = |real-time trend value - model predicted value| / model predicted value × 100%). A preset trend deviation threshold of 5% and a sustained deviation time threshold of 1 second are used. When the deviation rate is ≥5% and the sustained deviation time is ≥1 second, it is determined to be a trend deviation anomaly. Simultaneously, it incorporates the current operating condition switching trend model to avoid misjudgments caused by mismatched operating conditions. Periodic anomaly analysis uses Fast Fourier Transform (FFT) and autocorrelation analysis to extract the main period, period amplitude, and period phase of the signal in real time, comparing them with historical normal periodic features obtained through large-scale model self-learning. Specifically, the large model employs a time-series feature clustering algorithm to extract and cluster periodic features from signals under historical normal operating conditions, forming a periodic feature library for different devices and operating conditions. During the learning process, a periodic feature matching model is established by comparing the amplitude, phase, and frequency correlations of different periodic signals. The currently extracted periodic features are compared with the feature library in real time, and the matching degree is calculated using cosine similarity. The model autonomously corrects the feature library deviation to ensure the accuracy of periodic anomaly identification. The periodic matching degree is calculated as follows: (matching degree = 1 - |real-time period - historical period| / historical period - |real-time amplitude - historical amplitude| / historical amplitude). The preset periodic matching threshold is 0.7, and the periodic amplitude deviation rate threshold is 10%. When either threshold condition is met, it is determined to be a periodic anomaly, and the cause of the anomaly is traced (equipment failure, sensor failure, etc.).
[0146] The over-limit anomaly analysis is based on equipment type and operating condition level, and establishes a dynamic safety threshold library, which includes physical limit thresholds (hard thresholds) and safe operating thresholds (soft thresholds). For example, the safe threshold for the main transformer winding temperature is 80℃, and the physical limit threshold is 120℃. The relationship between the signal amplitude and the threshold is compared in real time. Soft over-limit (exceeding the safety threshold) with a duration ≥1s and hard over-limit (exceeding the physical limit threshold) regardless of the duration are both judged as over-limit anomalies. Instantaneous soft over-limit (duration <1s) is judged as normal operating condition fluctuation.
[0147] For discrete equipment status signals, anomalies are mainly categorized into three types: false status transition anomalies, missing status anomalies, and linkage anomalies. False status transition anomaly analysis counts the number of status changes per unit time (default 1 minute) in real time. Combined with OCS operation command records and fault alarm records, it distinguishes between proactive changes (manual operation, fault triggering) and unexpected changes. The preset status change frequency threshold is 3 times / min. When the number of unexpected changes per unit time is ≥3, it is determined to be a false status transition anomaly. Simultaneously, the transition timestamp and transition count are recorded to trace the cause of the transition (actuator failure, signal transmission anomaly, etc.). Missing status anomaly analysis monitors the update frequency of the signal status in real time. If a device's status signal is not updated for more than a preset time (default 5 seconds) and no device maintenance or offline status notification is received, it is determined to be a status missing anomaly. A signal missing alarm is immediately triggered and pushed to the linkage interface module to check the operating status of sensors and smart terminals at the acquisition layer. The linkage anomaly analysis is based on the logical linkage relationship of power grid equipment (e.g., when a circuit breaker is tripped, the corresponding disconnector should trip synchronously). A device status linkage rule library is established to verify the consistency of the status of associated devices in real time. If the status of associated devices does not conform to the linkage rules (e.g., the circuit breaker is tripped but the disconnector is not tripped) and there is no manual operation instruction, it is determined to be a linkage anomaly, and the abnormal associated device, abnormal status, and violation linkage type are marked.
[0148] For raw alarm event signals, the core function of the analysis module 300 is to verify their authenticity and determine their severity level. First, the raw alarm event signals are categorized into three types: instantaneous alarms, continuous alarms, and fault alarms. For instantaneous alarms (such as instantaneous voltage fluctuations), the module combines the corresponding baseline operating parameter signals to determine if it is a genuine anomaly. If there is no obvious anomaly in the corresponding parameters, it is considered a false alarm and is filtered out. For continuous alarms and fault alarms, the module combines equipment status signals and historical alarm records to verify the authenticity of the alarm and eliminate false alarms (such as sensor mis-collection). Simultaneously, based on the severity of the anomaly, the alarm level is determined (Level I: Emergency, such as equipment hard over-limit, fault triggering; Level II: Important, such as trend deviation, abnormal status linkage; Level III: General, such as instantaneous sudden change, false status jump), providing a priority basis for subsequent handling.
[0149] When the anomaly detection unit determines that a certain type of signal is abnormal, it immediately extracts the core information of the anomaly (device ID, anomaly type, anomaly timestamp, anomaly amplitude / status, anomaly duration, and judgment basis), and classifies the alarm level (Level I, Level II, Level III) based on the severity of the anomaly. It then encapsulates the information into standardized alarm information (i.e., anomaly alarm signal), which includes seven core fields: alarm ID, device ID, alarm level, anomaly type, anomaly details, judgment basis, and handling suggestions. The handling suggestions are generated by the large model based on historical handling records and are adapted to different anomaly scenarios. Specifically, the large-scale model for handling recommendations adopts a sequence-to-sequence (Seq2Seq) architecture. It pre-imports a historical power grid anomaly handling case library (including anomaly type, equipment type, handling steps, handling effects, and debriefing summaries). Through supervised learning, it trains a mapping model between anomaly scenarios and handling recommendations. The core logic is to extract the correlation between the core features of the anomaly (anomaly type, equipment ID, operating condition, and anomaly amplitude) and historical handling records. It focuses on key handling steps through an attention mechanism and combines real-time anomaly details (such as anomaly duration and associated equipment status) to dynamically generate handling recommendations adapted to the current scenario. It will also continuously learn from new handling cases to optimize the rationality and operability of the recommendations.
[0150] Optionally, Level I alarms are simultaneously pushed to the OCS monitoring and display module (pop-up notification), the dispatcher's mobile app (SMS + push notification), and the dispatch center's large screen, with a push latency of ≤100ms, requiring dispatchers to respond within 1 minute; Level II alarms are pushed to the OCS monitoring and display module (prominent label) and the dispatcher's mobile app, with a push latency of ≤200ms, requiring dispatchers to respond within 5 minutes; Level III alarms are only pushed to the OCS monitoring and display module, requiring no real-time response, only logging. Simultaneously, all abnormal alarm information is synchronously pushed to the data storage layer and stored in the historical database for subsequent trend analysis and algorithm optimization. Alarm backtracking and false alarm marking are also supported. Information marked as false alarms is fed back to the anomaly judgment unit for optimizing judgment thresholds and algorithm parameters.
[0151] In another embodiment, if the analysis module 300 determines that there is an anomaly in the OCS monitoring signal, it not only pushes alarm information but also outputs standardized anomaly judgment instructions, and links the protection information preprocessing module 200 to send protection information. Then, through fusion analysis, it realizes anomaly verification, accurate positioning and efficient handling suggestions, and implements the entire process based on the list of suspected abnormal nodes generated by the node capture module 100.
[0152] Optionally, the standardized anomaly determination instruction follows a fixed format, which includes: instruction ID, abnormal device ID, anomaly type, anomaly timestamp, node unique identifier (associated with the list of suspected abnormal nodes generated by the node capture module 100, including the node unique identifier, device ID, anomaly timing window, anomaly feature description, and anomaly confidence level), protection information requirement list (specifying the types of protection information to be fed, such as protection action records, protection device status, fault waveform data, etc.), and instruction priority, with the instruction format adopting a standardized JSON format to ensure that the protection information preprocessing module 200 can directly parse it.
[0153] Optionally, the anomaly detection command is pushed to the protection information preprocessing module 200 via the interface adaptation unit of the analysis module 300 using the TCP / IP protocol with an encryption delay of ≤100ms. At the same time, a copy of the command is stored in the log storage unit for subsequent tracing and verification. If the command push fails, the analysis module 300 will start a retry mechanism, retrying 3 times (each time with an interval of 50ms). If the retry fails, the backup push channel will be triggered to ensure that the command is successfully delivered.
[0154] Furthermore, Figure 5 A schematic diagram of the structure of the protection information preprocessing module of this embodiment is shown, including:
[0155] The timing alignment unit 210 is configured to receive a list of suspected abnormal nodes and extract the timing window of each suspected abnormal node using a timestamp synchronization mechanism. Through the northbound interface of the security information system, it captures all protection information of the device within the timing window.
[0156] The heterogeneous data preprocessing unit 220 is configured as follows:
[0157] For structured data in protected information, data cleaning, feature normalization, and encoding conversion are performed to generate standardized structured feature vectors;
[0158] Natural language processing techniques are used to transform unstructured data in protected information into structured data through word segmentation, entity recognition, and text embedding.
[0159] The processed structured and unstructured data are integrated to generate a unified format of credit guarantee data feature package, which is consistent with the input requirements of the large model.
[0160] Data caching unit 230 is configured to temporarily cache the preprocessed information security data feature packets, with configurable caching duration; and
[0161] The feed control unit 240 is configured to send a security data feature packet to the analysis module 300 after receiving an anomaly determination command.
[0162] like Figure 5 As shown, the protection information preprocessing module 200, in order to achieve accurate capture, standardized processing, caching, and on-demand feeding of protection information, clearly divides into four core functional units: a timing alignment unit 210, a heterogeneous data preprocessing unit 220, a data caching unit 230, and a feeding control unit 240. These units work collaboratively, operating entirely based on the list of suspected abnormal nodes generated by the node capture module 100. First, the timing alignment unit 210 receives the list of suspected abnormal nodes pushed by the node capture module 100 in real time, immediately initiates a timestamp synchronization mechanism, and accurately extracts the timing window corresponding to each suspected abnormal node (the timing window range is consistent with the capture window of the node capture module 100). Then, through the northbound interface of the protection information system, it captures all protection information of the devices within the timing window according to the device ID of the suspected abnormal node. This includes full protection data such as protection action records, protection device activation / deactivation status, fault waveform data, protection setting parameters, and protection alarm logs, ensuring that the captured protection information completely matches the timing and device of the suspected abnormal node, providing accurate data support for subsequent preprocessing and fusion analysis. After the capture is completed, the timing alignment unit 210 will push all protection information to the heterogeneous data preprocessing unit 220 simultaneously, and record the capture log, including capture time, device ID, timing window, protection information type and quantity, for subsequent data traceability and verification.
[0163] After receiving the full amount of protection information pushed by the timing alignment unit 210, the heterogeneous data preprocessing unit 220 takes targeted processing measures to address the differences between structured and unstructured data in the protection information, ensuring data standardization and adaptability to large model input requirements. The specific processing flow is as follows: For structured data in the protection information (such as protection action time, protection settings, fault recording values, protection device status, etc.), data cleaning is first performed to remove missing values, outliers, and redundant data. Then, feature normalization is used to map structured data of different dimensions to the same interval (0-1). Finally, encoding conversion is performed to convert discrete structured data (such as protection device activation / deactivation status) into standardized numerical codes, ultimately generating standardized structured feature vectors. For unstructured data in the protection information (such as protection alarm descriptions, fault analyses, etc.), the processing steps are as follows: Logs, maintenance records, etc., are processed using Natural Language Processing (NLP) technology. First, word segmentation is performed to break down the core words in the text. Then, entity recognition technology is used to extract key entities such as device ID, anomaly type, and fault location from the text. Finally, a text embedding algorithm is used to convert the unstructured text into a fixed-dimensional feature vector, realizing the structured transformation of unstructured data. After processing, the heterogeneous data preprocessing unit 220 integrates the standardized structured feature vector with the transformed unstructured data feature vector to generate a unified format guarantee data feature package. The format of this guarantee data feature package is completely consistent with the input requirements of the large model, ensuring that the analysis module 300 can directly call the large model for fusion analysis. At the same time, auxiliary information such as data integrity identifier, data processing time, and data source are added to the feature package to facilitate subsequent verification.
[0164] The data caching unit 230 is configured to receive the security data feature packets output by the heterogeneous data preprocessing unit 220 and temporarily cache them. The caching duration can be flexibly configured according to actual application needs (the default caching duration is 10 minutes, which can be manually adjusted in the module configuration interface, with a maximum setting of 1 hour). The caching adopts a first-in, first-out (FIFO) mode. When the cached data exceeds the caching duration or the cache capacity reaches the threshold, the oldest cached security data feature packet is automatically cleaned up to ensure sufficient cache space. At the same time, the data caching unit 230 classifies and stores the cached security data feature packets, indexing them by device ID, node unique identifier, and timing window, which facilitates quick retrieval and retrieval by the subsequent feed control unit 240. During the caching process, data integrity is monitored in real time. If cached data is found to be corrupted or missing, it is immediately fed back to the heterogeneous data preprocessing unit 220 to regenerate and cache the corresponding security data feature packet, ensuring the validity of the cached data.
[0165] The feed control unit 240 is configured to monitor and analyze the anomaly determination instructions pushed by the analysis module 300 in real time. Upon receiving the anomaly determination instruction, it immediately parses the unique node identifier and protection information requirement list in the instruction. Through the index of the data cache unit 230, it quickly retrieves and calls up the protection information data feature packets in the corresponding timing window of the device. According to the requirement list in the instruction, it removes redundant features that are irrelevant to the analysis, performs final standardized encapsulation, and feeds the protection information data feature packets to the analysis module 300 using the same TCP / IP encrypted transmission method as the anomaly determination instruction. The feed delay is strictly controlled to be ≤200ms to ensure that the analysis module 300 can quickly obtain effective protection information. During the feeding process, the feeding control unit 240 simultaneously includes information such as the integrity identifier, cache time, and data processing details of the protection information data feature package, which facilitates the analysis module 300 in verifying the validity and timeliness of the protection information. If the corresponding protection information data feature package cannot be retrieved, or the cached data has expired, the feeding control unit 240 will immediately report back to the analysis module 300. At the same time, it will simultaneously trigger the timing alignment unit 210 to re-extract the timing window of the corresponding suspected abnormal node, capture the protection information, and link the heterogeneous data preprocessing unit 220 to regenerate and cache the protection information data feature package, ensuring the accuracy and integrity of the protection information feeding and guaranteeing the smooth progress of subsequent fusion analysis.
[0166] Optionally, when performing fusion analysis, the analysis module 300 uses protection information to verify the authenticity of suspected abnormal nodes and outputs anomaly handling suggestions, which are then synchronously fed back to the OCS scheduling interface (i.e., the visualization interface of the monitoring and display module). Specifically, after the analysis module 300 receives the protection information feature packet pushed by the control unit 240 from the protection information preprocessing module 200, it immediately starts the fusion analysis process. The core is to deeply fuse the received protection information feature packet (which, after being standardized by the heterogeneous data preprocessing unit 220, can be directly adapted to large model input) with the OCS monitoring signal anomaly data it analyzes, focusing on achieving two core objectives: anomaly verification and anomaly location, and generating more effective handling suggestions.
[0167] For anomaly verification, the analysis module 300 compares the abnormal characteristics of the OCS monitoring signal (such as current over-limit amplitude, temperature change trend, and status linkage anomaly type) with the fed-in protection information one by one. This double verification confirms the authenticity of the anomaly and avoids misjudgment. The specific verification logic is as follows: If the OCS monitoring signal determines a current over-limit anomaly, it compares the fault waveform data in the protection information to confirm whether there is a corresponding current change record and whether the protection device has overcurrent protection action; if the OCS monitoring signal determines an equipment status linkage anomaly, it compares the protection device's on / off status and actuator action records in the protection information to confirm whether the linkage anomaly is triggered by protection action or caused by equipment failure; if the OCS monitoring signal determines a trend deviation anomaly, it compares the historical protection parameters and equipment operation records in the protection information to confirm whether the deviation trend is consistent with the equipment operating condition changes and fault hazard records in the protection information. Meanwhile, a verification threshold is set (e.g., a feature matching degree of ≥85% is considered a successful verification). If the verification is successful, the anomaly is confirmed as a real anomaly and proceeds to the subsequent location and handling suggestion generation stage. If the verification fails, it is judged as a suspected false anomaly, marked as pending review, pushed to the monitoring and display module to remind staff to conduct further verification, and simultaneously fed back to the anomaly judgment unit to optimize the subsequent anomaly judgment algorithm.
[0168] For anomaly location, the system combines the abnormal device ID and suspected abnormal node identifier corresponding to the OCS monitoring signal with the protection device location information, the collection point of fault recording data, and the associated information of equipment wiring diagram in the protection information to achieve precise location of the anomaly. Specifically, the fault recording data in the protection information determines the specific equipment location where the anomaly occurred (such as the main transformer winding, line joint, circuit breaker contact); the location code of the protection device locates the specific installation location of the abnormal equipment (such as the #1 main transformer in a substation, the #3 tower of a line); and the suspected abnormal node time sequence window of the node capture module 100 locates the specific time point and evolution process of the anomaly, ultimately generating a three-dimensional location result of "equipment location-location-time", accurate to the specific point where maintenance can be directly carried out, avoiding blind investigation by staff.
[0169] Regarding the generation of handling suggestions, based on the anomaly characteristics from fusion analysis, the fault types in the protection information, and historical handling records, a large model performs deep matching to generate highly targeted and directly executable handling suggestions. Unlike the general suggestions of the previous method, the new handling suggestions include: anomaly cause analysis (combining protection action records and abnormal characteristics of monitoring signals to clarify whether the anomaly is an equipment fault, sensor fault, or signal transmission anomaly), specific handling steps (such as "immediately shut down #1 main transformer, check the winding temperature sensor and wiring, and verify the protection settings"), handling priority (combining the anomaly level and the severity of the fault in the protection information to clarify the handling order), and emergency backup plans (such as "if immediate shutdown is not possible, temporarily adjust the protection settings and strengthen real-time monitoring"). Simultaneously, historical handling cases are linked for staff reference, ensuring the effectiveness and implementability of the handling suggestions, and even directly guiding staff to complete anomaly handling, improving handling efficiency.
[0170] After completing the fusion analysis, the analysis module 300 generates a standardized fusion analysis report, which includes five core parts: anomaly determination results, protection information verification details, anomaly 3D location results, handling suggestions, and fusion analysis basis. Simultaneously, based on the anomaly level, the fusion analysis report is pushed to the corresponding terminals (Level I, Level II, and Level III correspond to different push channels) according to the push logic of Method 1, for dispatchers and maintenance personnel to refer to and execute. At the same time, the fusion analysis report, anomaly determination instructions, and protection information feed records are synchronously stored in the data storage layer for subsequent fault tracing, algorithm optimization, and providing training data for large models, continuously improving the accuracy of the fusion analysis and the effectiveness of the handling suggestions.
[0171] The process will be illustrated with a specific example below.
[0172] S100. For each type of OCS monitoring signal corresponding to each device, extract timing features window by window. The timing features cover core parameters such as signal amplitude, rate of change, fluctuation range, and timing continuity. This ensures that the extracted features match the requirements of threshold determination and association table query, providing basic data for subsequent threshold triggering and association table matching. For example, for the winding temperature signal (signal type: temperature) of the #1 main transformer (equipment ID: T1) of the 35kV substation, extract timing features such as temperature amplitude, temperature change rate within 100ms, and temperature fluctuation range between the current window and the previous 5 windows in 100ms time windows (T1, T2, T3...Tn).
[0173] S200. For each type of OCS monitoring signal extracted from each device, obtain its corresponding full-type threshold (using the same threshold library as in the previous embodiment to ensure consistent judgment criteria); for each type of threshold of each type of OCS monitoring signal corresponding to each device, determine the timing characteristics of the timing window corresponding to that type of OCS monitoring signal of that device, and whether it meets the triggering conditions of that type of threshold. If it does, the timing window is identified as a suspected abnormal node. Continuing with the above example, the winding temperature safety threshold of #1 main transformer (T1) is 80℃, and the instantaneous change threshold is 5℃ / 100ms. If the temperature of timing window T5 is 86℃ (exceeding the safety threshold of 6℃), and the temperature change rate within 100ms is 6℃ / 100ms (exceeding the instantaneous change threshold), then timing window T5 (Device ID: T1, Signal Type: Temperature, Timing Window: T5) is identified as a suspected abnormal node.
[0174] S300. Obtain suspected anomaly supplementary nodes based on the association table. The association table is pre-built based on historical fault cases and anomaly handling records, containing the correspondence between devices, signal types, threshold triggering conditions, and suspected anomaly supplementary nodes. By querying the association table, supplementary nodes related to the suspected anomaly node across devices and time windows can be obtained. The specific steps are as follows:
[0175] First, based on the device (e.g., T1) corresponding to the suspected abnormal node, the type of OCS monitoring signal (e.g., temperature), and the threshold triggering conditions (e.g., temperature exceeding the safety threshold by 5%-15%, instantaneous change exceeding the threshold), a preset association table is queried. Second, based on the correspondence in the association table, two types of suspected abnormal supplementary nodes are extracted: one is to extract other devices that are associated with the device, obtain the time sequence window of the other devices that is the same as the suspected abnormal node, and identify the time sequence window as the suspected abnormal supplementary node; the other is to extract the extended time sequence windows before and after the device in the time sequence window, and identify the extended time sequence window as the suspected abnormal supplementary node. Based on the above example, the suspected abnormal node is T1-temperature-T5 (exceeding the safety threshold by 7.5% and the instantaneous change threshold by 20%). After querying the association table, two types of supplementary nodes can be obtained: the associated equipment supplementary node (the #1 cooling system, which has a cooling linkage relationship with the T1 main transformer, device ID: C1, timing window T5); and the extended timing supplementary node (the extended windows T3, T4, T6, and T7 of the T1 main transformer temperature signal, covering the complete timing interval from 200ms before to 200ms after the anomaly).
[0176] S400: Form the final suspected abnormal node package. The suspected abnormal supplementary nodes obtained in S300 are integrated with the suspected abnormal nodes determined in the second step, and packaged into the final suspected abnormal node package. The node package contains the core information of each node: device ID, signal type, timing window, threshold trigger condition, node type (original suspected abnormal node / supplementary node), and association description. This node package is then pushed in real-time to the timing alignment unit 210 of the protection information pre-processing module 200, and simultaneously cached in its own node cache unit for subsequent tracing and retrieval. Following the above example, the final suspected abnormal node package includes: the original node (T1-temperature-T5), the associated device supplementary node (C1-temperature-T5), and the extended timing supplementary nodes (T1-temperature-T3, T1-temperature-T4, T1-temperature-T6, T1-temperature-T7), a total of 6 nodes, providing comprehensive support for subsequent cross-device and cross-timing protection information capture and fusion analysis.
[0177] Optionally, the association table is stored in a structured table format. The core fields cover the association conditions, associated devices, supplementary time series window, association basis, and update time. The following is a specific example, combined with the case of the #1 main transformer mentioned above, to clarify how the association table supports the acquisition of suspected abnormal supplementary nodes, as shown in Table 1:
[0178] Table 1. Relationship Table
[0179]
[0180] Table 1 is constructed based on actual historical fault cases in the power grid. Each correlation record corresponds to a specific threshold trigger condition. The correlated devices are all devices that have an operational linkage with the triggering device (such as the main transformer and cooling system, busbar and line). The supplementary timing window is set according to the fault evolution pattern in historical cases to ensure the relevance and effectiveness of the supplementary nodes. For example, when the temperature of the T1 main transformer triggers the R001 correlation condition, the simultaneous timing windows of the correlated devices C1 and B1, as well as the extended timing window of T1 itself, can be directly queried through the correlation table to quickly obtain the suspected abnormal supplementary node without additional analysis and calculation, greatly improving the speed of node determination.
[0181] It should be noted that in some possible embodiments, the associated device may also supplement the timing window.
[0182] The specific steps for creating a related table are as follows:
[0183] Collect all abnormal fault cases and abnormal handling records during the operation of OCS in the past 3-5 years, covering abnormal scenarios of various equipment (main transformer, circuit breaker, bus, cooling system, etc.) and various signal types (temperature, current, voltage, status signal, etc.). Each case must include: abnormal equipment ID, abnormal signal type, threshold trigger condition, abnormal occurrence time window, operating status of associated equipment, abnormal evolution process (time range), fault cause, handling result and other core information. Invalid cases (such as false alarms and abnormalities caused by human operation) are removed to form a standardized historical case library.
[0184] For each case in the historical case database, the following correlation features are extracted: First, the linkage relationship between the abnormal equipment and other equipment is extracted (such as the heat dissipation linkage between the main transformer and the cooling system, the power supply linkage between the busbar and the line, and the operation linkage between the circuit breaker and the disconnector), clarifying which equipment has a direct or indirect operational linkage with the abnormal equipment; Second, the extended features of the abnormal timing are extracted, analyzing whether there are characteristics of fault precursors or fault continuation within the timing window before and after the occurrence of the abnormality, and determining the reasonable range of the extended timing window (such as 200ms before and after the abnormality); Third, the corresponding features of the threshold trigger range and the correlation relationship are extracted, clarifying the differences in the corresponding associated equipment and extended timing window under different threshold trigger conditions (such as the associated equipment and extended window are different for temperature exceeding the limit by 5%-15% and exceeding the limit by more than 15%).
[0185] Based on the extracted correlation features, a large-model self-learning algorithm (in collaboration with the large model of analysis module 300) is used to generate correlation rules, namely the correspondence between "device + signal type + threshold trigger range" and "associated device + supplementary timing window". Simultaneously, each correlation rule is labeled with its correlation basis (corresponding historical case ID) to ensure the rationality and traceability of the correlation rules. For example, by analyzing multiple historical cases of main transformer temperature anomalies, correlation rule R001 is generated, clarifying the associated devices and extended windows when the temperature exceeds the limit by 5%-15%.
[0186] The organization mobilized professionals from three categories—power grid dispatching, equipment maintenance, and system operation and maintenance—to manually verify the generated association rules. The focus was on checking the rationality of the associated devices, the applicability of the supplementary time-series windows, and the accuracy of the threshold trigger range. Unreasonable association rules (such as rules without historical case support or inconsistent association logic) were eliminated, and association parameters were optimized (such as adjusting the number of sampling points in the extended time-series window and correcting the range of associated devices) to ensure that the association table closely matches the actual operating scenario and can be directly used to obtain suspected abnormal supplementary nodes.
[0187] Optionally, the association table is stored in the local storage unit of the node capture module 100, using a structured database (MySQL), and is simultaneously backed up to the historical database of the OCS data storage layer to ensure that the association table data is not lost; the local cache uses a Redis in-memory database to cache commonly used association rules (such as association rules for core devices) in memory, improve the query speed of the association table, ensure the rapid acquisition of suspected abnormal supplementary nodes, and the query latency is ≤50ms.
[0188] Optionally, the core fields of the association table are fixed as association ID, association condition, association device, supplementary time series window, association basis, and update time. The association condition field adopts a combination format of "device ID + signal type + threshold trigger range" to facilitate fast query and matching. The association device field supports multiple device IDs, separated by commas, to adapt to multi-device association scenarios. The supplementary time series window field adopts the format of "N sampling points before and after the original window", and the value of N can be flexibly configured according to the device type and signal type (default N=2, core devices can be adjusted to N=3).
[0189] Optionally, a visual configuration interface is provided, allowing operations and maintenance personnel to manually add, modify, and delete association rules. Historical cases can be manually imported to generate new association rules, and association parameters (such as associated devices and supplementary timing windows) can be manually adjusted. Batch import / export of association tables is also supported, facilitating cross-site deployment and synchronous updates. The configuration interface has access control functions, allowing only authorized personnel to perform modification operations, ensuring the security of association tables.
[0190] Optionally, when querying the association table, the node capture module 100 uses a combination of exact matching and fuzzy matching. It accurately matches the device ID and signal type, and fuzzily matches the threshold trigger range (e.g., the threshold trigger value of a suspected abnormal node is 7.5%, which can match the threshold range of 5%-15% in the association table). This ensures the accuracy and flexibility of the association rules and avoids the inability to match supplementary nodes due to slight differences in the threshold trigger value.
[0191] In one embodiment, the association table is a pre-updated table that includes the association relationships of all devices, all types of OCS monitoring signals, and different timing windows.
[0192] According to the preset cycle, the correlation table is comprehensively checked and calibrated based on the update status of the power grid equipment ledger, the self-learning optimization results of the large model, and recent abnormal cases of the power grid.
[0193] In this implementation, the core data sources are the power grid equipment ledger, historical data from the OCS and the information security system, and power grid operation specifications. All related relationships are comprehensively entered. The specific operations are as follows:
[0194] First, extract basic information of all equipment from the power grid equipment ledger, clarify the operational linkages between each piece of equipment (such as the linkage between main transformers and cooling systems, busbars and lines, circuit breakers and disconnectors), and label the core parameters of associated equipment (equipment ID, equipment type, and operational priority). Second, sort out all types of OCS monitoring signals (temperature, current, voltage, status signals, etc.), enter the correspondence between each signal type and equipment, and clarify the reference standards for the threshold trigger range of different signal types (in conjunction with power grid operation specifications). Third, combine historical data from OCS and the power grid information protection system to analyze the evolution of abnormal time sequences, enter the time sequence window associations corresponding to different equipment and different signal types, and clarify the core parameters such as the number of sampling points and time range of extended time sequence windows. Finally, standardize the labeling of all entered associations (equipment associations, signal type associations, and time sequence window associations), unify the field format and parameter range, and ensure the standardization of the associations. After the data is entered, the historical anomaly case data of the power grid is called to perform batch verification of all relationships. By comparing the abnormal relationship scenarios in the historical cases, invalid relationships (such as equipment relationships without actual operation linkage, and time window relationships that are completely inconsistent with historical cases) are eliminated, and deviation relationships are corrected (such as adjusting the threshold trigger range and optimizing the extended time window parameters). Finally, an initial relationship table is formed as the basis for subsequent node capture.
[0195] Then, during the expansion of suspected abnormal supplementary nodes, three types of feedback data are collected simultaneously to achieve dynamic optimization and update of the related tables. The specific process is as follows:
[0196] First, it collects supplementary feedback data on suspected anomalies, including the matching accuracy of supplementary nodes, the validity of protection information corresponding to supplementary nodes, and the dependence of fusion analysis on supplementary nodes. Second, it collects fusion analysis feedback data, including the anomaly location accuracy based on fusion analysis of supplementary nodes, the validity of handling suggestions, and misjudgments. Third, it collects power grid operation feedback data, including newly added equipment linkage relationships, signal type anomaly characteristics, and time-series window evolution patterns in actual power grid operation. Based on the above three types of feedback data, through a large model self-learning algorithm (in collaboration with the large model of analysis module 300), it automatically identifies and adds valid relationships that have not been entered (such as linkage relationships of newly added equipment and signal type associations that are not covered); optimizes existing relationship parameters (such as adjusting the number of sampling points in the extended time-series window, correcting the threshold trigger range, and optimizing the priority of associated equipment); deletes invalid relationships (such as relationships with extremely low matching accuracy and no practical application value as shown in the feedback data); marks key relationships (such as relationships with high dependence on fusion analysis and high anomaly location accuracy) and increases their query priority to ensure that efficient relationships are matched first when capturing subsequent nodes, thereby improving the speed of node determination.
[0197] Optionally, the aforementioned large model self-learning algorithm (in collaboration with the large model of the analysis module 300) adopts a graph neural network (GNN) architecture. It constructs an association feature graph from the extracted associated features (device linkage relationship, time-series extension features, and threshold trigger features). The nodes represent devices, signal types, and threshold ranges, and the edges represent the strength of the association relationship. Through self-supervised learning, the feature graph is clustered and association rule mining is performed. The core logic is to calculate the association weights between different feature nodes, select association combinations with weights higher than a preset threshold, and generate corresponding rules for "device + signal type + threshold trigger range" and "associated device + supplementary time-series window". At the same time, the rules are labeled with historical case IDs to ensure that the rules are traceable. Furthermore, the abnormal feature learning model of the analysis module 300 is reused through transfer learning to avoid repeated training and improve the efficiency and adaptability of rule generation.
[0198] After each update (dynamic update) of the related table is completed, the updated relationships are automatically verified in real time. The verification includes the standardization of the relationships, the rationality of the parameters, and the compatibility with the existing related tables. If the verification passes, a complete update record is retained, including the update time, update content (new / modified / deleted relationships), update basis (corresponding feedback data or historical cases), update operator, and other information, to ensure that the updates of the related tables are traceable and facilitate subsequent review and troubleshooting. If the verification fails, the system automatically rolls back to the version of the related tables before the update and prompts the operations and maintenance personnel to check the updated data to ensure the stability of the related tables.
[0199] According to a preset cycle (default once a quarter, which can be adjusted to once a month depending on the power grid operation), a comprehensive review and calibration of the association table is conducted in conjunction with three types of core information, as follows: First, based on the update status of the power grid equipment ledger, the accuracy of equipment information in the association table is checked, associations of decommissioned equipment are deleted, associations of new equipment are added, and association parameters after equipment parameter changes are corrected; Second, based on the self-learning optimization results of the large model, the matching logic and parameter settings of the association relationships are optimized to improve the adaptability of the association table to abnormal scenarios; Third, based on recent abnormal cases of the power grid (new abnormal cases within the recent cycle), new association relationships are added, and association parameters that are inconsistent with recent abnormal scenarios are corrected to ensure that the association table always fits the actual operating conditions of the power grid and ensures the accuracy of obtaining suspected abnormal supplementary nodes.
[0200] In one implementation method, Figure 6 A schematic diagram of the protection information preprocessing module of this embodiment is shown, which also includes:
[0201] The effective information integration unit 250 is configured to use a large model to filter out redundant data after preprocessing and protection information that does not match the requirements of subsequent fusion analysis, ultimately leaving effective protection information; and
[0202] The information integration unit 260 is configured to receive valid protection information, integrate the valid protection information in conjunction with the requirements of subsequent fusion analysis and the association table, and output the integrated protection information dataset.
[0203] Optionally, such as Figure 6 As shown, the protection information preprocessing module 200 includes:
[0204] Anomaly prediction unit 270 is configured to receive protection information dataset and perform correlation prediction on the protection information dataset. The correlation prediction includes:
[0205] By combining the association table, we can predict abnormal tendencies in the linkage of protection information;
[0206] The confidence level of the prediction results is determined, and the core information of any prediction anomalies is marked.
[0207] The analysis result output and processing trigger unit 280 is configured as follows:
[0208] If the confidence level assessment result indicates that no potential anomaly was detected, the information dataset will be effectively protected and simultaneously pushed to the analysis module 300 for fusion analysis.
[0209] If the confidence level assessment result is a valid potential anomaly, a preliminary anomaly report will be generated, and an early intervention mechanism will be triggered.
[0210] Specifically, the core function of the effective information integration unit 250 is to use a large model to perform secondary screening on the security data feature package output by the heterogeneous data preprocessing unit 220, thoroughly filtering out redundant data and protection information that does not match the needs of subsequent fusion analysis, and finally retaining effective protection information to provide high-quality data support for subsequent integration and prediction.
[0211] The OCS large-scale model, which shares the same origin as the analysis module 300, is selected (a dedicated large-scale model based on the Seed large-scale model, specifically fine-tuned and trained to suit the characteristics of power grid OCS and information protection system data, as well as the needs of fusion analysis). This model has been pre-imported with the power grid protection information feature library, the fusion analysis requirement tag library, and the redundant data identification rule library. Redundant data is defined as: protection information that, after preprocessing, is irrelevant to the current suspected abnormal node, is repeatedly recorded, and has no actual analytical value. The large-scale model achieves redundancy screening through a dual logic of feature matching and rule verification. The specific steps are as follows:
[0212] The large model automatically labels each piece of protection information (including structured feature vectors and unstructured transformed feature vectors) in the protection information data feature package. The labeling content includes: protection information type (protection action record, fault waveform data, etc.), device ID, corresponding timing window, core feature parameters (such as the current amplitude of the fault waveform and the timestamp of the protection action), and correlation with suspected abnormal nodes (0-100 points).
[0213] Based on the annotation results, the large model, combined with a pre-set redundant data identification rule base, performs three types of redundancy removal operations: First, duplicate data removal, identifying and deleting completely duplicate protection information (such as duplicate fault waveform data and duplicate protection action records of the same device and the same sequence window), retaining only one core record; Second, irrelevant data removal, removing protection information that is not related to any node (original node and supplementary node) in the current suspected abnormal node package (such as devices not appearing in the association table and protection information exceeding the extended sequence window). For example, if the suspected abnormal node package contains the T3-T7 sequence windows of devices T1 and C1, the large model will remove protection information of other devices (such as L2 line) and other sequence windows (such as T1-T2 of T1); Third, valueless data removal, removing protection information that has no actual analytical significance (such as duplicate status records of normal operation of protection devices, fault waveform data without abnormal values, and invalid alarm descriptions).
[0214] Data that does not match the requirements of fusion analysis is defined as: protection information that cannot support the three core requirements of the analysis module: anomaly verification, anomaly location, and handling suggestion generation. The large model filters this out through requirement tag matching, and the specific steps are as follows:
[0215] The large model pre-imports the fusion analysis requirement tag library of the analysis module 300. The tags are divided into three categories, each corresponding to specific protection information requirements: anomaly verification tags (which need to match fault waveform data, protection action records, and protection device status), anomaly location tags (which need to match protection device location information, fault waveform acquisition points, and equipment wiring association information), and handling suggestion generation tags (which need to match protection setting parameters, historical protection action records, and maintenance records). Each tag corresponds to specific core parameter requirements for protection information (such as anomaly verification tags needing to match parameters such as "current surge amplitude ≥ threshold" and "protection action type is overcurrent / overheating").
[0216] The large model identifies the features of each protection information entry and matches them one by one with the fusion analysis requirement tags, calculating the matching degree (matching degree = number of matched requirement tags / total number of requirement tags × 100%). A preset matching degree threshold of 60% is used. If the matching degree of a protection information entry is <60% and it lacks core parameters supporting any type of fusion analysis requirement, it is considered mismatched and filtered out. If the matching degree is ≥60%, or if the matching degree is <60% but it contains core parameters for a certain type of fusion analysis requirement (e.g., only current surge data from fault waveform recordings, which can support anomaly verification), it is considered a match and retained. For example, if a protection information entry only records the model information of the protection device and lacks any parameters related to anomaly verification or location, its matching degree is 0 and it is filtered out. However, if a protection information entry contains fault waveform data (current surge parameters) of the C1 cooling system, which can support anomaly verification, it is retained even though it does not match location or handling suggestion tags.
[0217] After the large model completes the screening of redundant and mismatched data, the remaining protection information is initially organized and labeled with the corresponding fusion analysis requirement tags for each piece of information (such as "abnormal verification - current change" and "location - protection device location") to form an effective protection information set. This set is then pushed to the integrated information unit 260, and a screening log (including the data type, quantity, and reason for screening) is recorded for subsequent review and large model optimization.
[0218] Information Unit 260 integrates information by leveraging the relationships in the association table to effectively protect information, improving integration efficiency and targeting. The specific steps are as follows:
[0219] The core premise of integration is to clarify the three core requirements of fusion analysis (anomaly verification, anomaly location, and generation of handling suggestions). The core basis is the association table of the node capture module 100 (including device association and time-series window association). The core function of the association table is to avoid the disorganization of effective protection information and ensure that the integrated dataset can directly support fusion analysis without the need for the analysis module to sort out the association relationship.
[0220] The integrated information unit 260 first calls the association table of the node capture module 100 to extract the association relationships corresponding to the current suspected abnormal node packets (such as the associated devices C1 and B1 corresponding to the T1 main transformer, and the extended time sequence windows T3-T7). Then, the effective protection information is classified in two ways according to "association relationship + fusion analysis requirements": First, it is classified according to the device association relationship, grouping the effective protection information of the core device (such as T1) and the associated devices (such as C1 and B1) into the same category and labeling the association relationship type (such as "heat dissipation linkage" and "power supply linkage"), which facilitates the analysis module to investigate cross-device cascading anomalies in the future; Second, it is classified according to the time sequence window association relationship, sorting the effective protection information of the extended time sequence windows of the same device (such as T3-T7 of T1) in chronological order and labeling the time sequence association logic (such as "precursor data before anomaly", "core data during anomaly", and "continuing data after anomaly"), which facilitates the analysis module to trace the anomaly evolution process; Third, it is classified according to the fusion analysis requirements, labeling the effective protection information of each type of device and each time sequence window with three major requirement tags: anomaly verification, anomaly location, and handling suggestions, which facilitates the analysis module to call them as needed.
[0221] Based on the relationships in the association table, the logical connections of various valid protection information are sorted out to fill information gaps: First, cross-device association is filled out. If the valid protection information of the core device (such as T1) includes abnormal characteristics (such as temperature exceeding the limit), but the corresponding timing window (T5) of the associated device (such as C1) lacks relevant protection information (such as cooling system operating current data), the information integration unit will feed back to the timing alignment unit 210 to supplement and capture the corresponding protection information (ensuring no new redundant data is added); Second, timing association is filled out. If the valid protection information of the extended timing window (such as T3) is missing, a complete abnormal evolution chain cannot be formed, and supplementary capture is triggered synchronously; Third, logical association is sorted out. The valid protection information of the associated devices and extended timing windows is sorted out according to the association basis of the association table (such as the linkage logic in historical cases) to sort out the logical relationship of "core device abnormality - associated device response - timing evolution", and the association node of each protection information is marked (such as "the current abnormality of C1 is linked with the temperature abnormality of T1").
[0222] After integration, the effective protection information is encapsulated into a standardized protection information dataset according to the hierarchical structure of "equipment category - time sequence window - requirement tag". The dataset contains three core modules: first, the basic information module (equipment ID, time sequence window, association description, data integrity identifier); second, the classified protection information module (generating and storing effective protection information according to anomaly verification, anomaly location, and handling suggestions, and labeling core parameters); and third, the association module (based on the association table, labeling the association logic and basis of protection information for each device and each time sequence window). The dataset format is fully compatible with the fusion analysis interface of the analysis module 300 and can be directly pushed to the anomaly prediction unit 270, while being cached in the data cache unit 230 for easy subsequent retrieval and traceability.
[0223] The functions of the association table are: first, to replace manual sorting of relationships, significantly improving integration efficiency (reducing integration delay by more than 30%); second, to ensure the relevance and comprehensiveness of protection information, avoiding the omission of effective protection information across devices and time series; and third, to sort out the logic in advance for the fusion analysis of the analysis module 300, reducing the workload of the analysis module in sorting out relationships and improving the speed of fusion analysis.
[0224] The anomaly prediction unit 270 receives the protection information dataset output by the integrated information unit 260, and, in conjunction with the correlation table, makes a preliminary prediction of the linkage anomaly trend of the protection information. Simultaneously, it uses a standardized formula to determine the confidence level and marks the core information of the predicted anomaly, providing a basis for subsequent early intervention or fusion analysis. Specifically:
[0225] The definition of linkage anomaly tendency is: based on the device linkage and time-series linkage relationships in the association table, the potential trends presented in the protection information that may trigger core device anomalies or cross-device cascading anomalies are identified. The prediction process relies entirely on the association rules of the association table, combined with the characteristics of the protection information dataset, and is implemented in three steps:
[0226] The first step is for the anomaly prediction unit 270 to call the association table of the node capture module 100 and extract all the association rules corresponding to the current protection information dataset (e.g., R001: When the T1 temperature exceeds the limit by 5%-15%, the C1 cooling system and B1 bus may experience linkage anomalies). The "trigger condition-associated equipment-abnormal tendency characteristics" in the association rules are clarified (e.g., trigger condition: T1 temperature exceeds the limit; associated equipment: C1, B1; abnormal tendency characteristics: abnormal C1 current, voltage fluctuation of B1).
[0227] The second step involves performing feature matching on each valid piece of protection information in the protection information dataset with the extracted association rules, focusing on matching "protection information features of associated devices" and "abnormal tendency features in association rules". For example, for the R001 association rule, if the protection information dataset contains information about T1 temperature exceeding the limit (86℃) and information about C1 cooling system operating current exceeding the rated current by 12%, and both correspond to the time window T5, then it is determined that the C1 cooling system has a linkage abnormal tendency with the T1 temperature abnormality; if it also contains information about B1 bus voltage being lower than the rated voltage by 6%, then it is determined that the B1 bus also has a linkage abnormal tendency.
[0228] The third step is to summarize all successfully matched linkage anomaly tendencies, and combine them with the association basis (historical cases) in the association table to preliminarily determine the type of linkage anomaly (such as "heat dissipation linkage anomaly" or "power supply linkage anomaly"), the scope of impact (core equipment + related equipment), and the evolution trend (such as "abnormal C1 current may cause T1 temperature to rise continuously"). At the same time, "invalid linkage tendencies" marked in the association table (such as linkage relationships with extremely low matching degree in historical cases) are excluded to form a preliminary prediction result.
[0229] The confidence level assessment quantifies the initial predicted tendency of linkage anomalies, determines the reliability of the prediction results, and avoids false predictions. A standardized calculation formula is used, and all parameters are derived from the protection information dataset and association table, as detailed below:
[0230] Confidence level calculation formula:
[0231] ;
[0232] In the formula, The confidence level for the correlation anomaly tendency is 0-100. The higher the confidence level, the more reliable the prediction result. To protect the matching degree (%) between information features and anomalous tendency features in association rules, the value ranges from 0 to 100. The calculation method is "number of matched features / total number of anomalous tendency features in association rules × 100%". For example, if an association rule requires two features (C1 current anomaly and B1 voltage fluctuation), and only the feature C1 current anomaly matches, then... The value is 50%; this parameter comes from the feature comparison results between the protection information dataset and the associated table. The correlation strength (%) between the associated device and the core device ranges from 0 to 100 and is pre-marked by the correlation table (set according to the frequency of linkage anomalies in historical cases; the higher the linkage frequency, the higher the correlation strength). For example, the correlation strength between T1 and C1 in the correlation table is 90% (frequent heat dissipation linkage), and the correlation strength between T1 and B1 is 75% (moderate power supply linkage frequency). This parameter comes directly from the correlation table. This represents the probability (%) of similar linked anomalies occurring in historical cases, ranging from 0 to 100. The calculation method is "number of similar linked anomaly cases / total number of linked anomaly cases × 100%". For example, in historical cases, there were 85 cases where C1 experienced abnormal current after T1 exceeded its limit, and the total number of linked anomaly cases was 100. The value is 85%; this parameter comes from the association basis of the association table (historical case library). The fluctuation coefficient (%) of the protection information characteristic is used, ranging from 0 to 100. The lower the fluctuation coefficient, the more stable the protection information and the more reliable the prediction result. It is calculated as "standard deviation of protection information characteristic / mean of protection information characteristic × 100%". For example, if the mean of the C1 current data is 10A and the standard deviation is 0.5A, then... The value is 5%; this parameter comes from the feature calculation results of the protection information dataset; , , and These are weighting coefficients, all ranging from 0 to 1, and Based on the requirements of fusion analysis and the priority of power grid operation, the default value is: (Matching degree is the core indicator) (Association strength is an important indicator) (Historical probability is an important indicator) (The fluctuation coefficient is an auxiliary indicator and can be dynamically adjusted according to the actual operation of the power grid.)
[0233] Confidence level criteria (preset fixed threshold, configurable):
[0234] High confidence level (valid potential anomaly): If the accuracy rate is ≥80%, the prediction result is considered reliable, but there is a clear tendency for abnormal linkage, and the early intervention mechanism needs to be triggered.
[0235] Low confidence (no potential anomalies): If the percentage is less than 80%, it is determined that a potential anomaly was not anticipated, and the protection information dataset is directly pushed to the analysis module 300.
[0236] Taking the linked abnormal tendency of excessive temperature T1 and abnormal current C1 as an example, it is known that: The accuracy rate is 80% (matching 1.6 of the two characteristics: abnormal C1 current and voltage fluctuation in B1, calculated based on the actual matching degree). The correlation strength between T1 and C1 is 90%. The probability is 85% (based on historical similar cases). The value is 5% (C1 current fluctuation coefficient). Substitute this value into the formula to calculate:
[0237] ;
[0238] The confidence level is 75.25%, which is considered low confidence. It is determined that the potential anomaly was not predicted and is pushed to the analysis module 300.
[0239] For prediction results with a confidence level of ≥80%, core information is marked to facilitate subsequent handling and verification. The marking content includes: the type of predicted anomaly (such as "heat dissipation linkage anomaly"), the IDs of the core equipment and related equipment, the corresponding timing window, the ID of the triggered association rule, the confidence level value, the characteristics of the core protection information (such as "T1 temperature 86℃, C1 current 11.2A"), and the evolution trend of the predicted anomaly. After marking, the results are pushed to the analysis result output and handling triggering unit 280.
[0240] The core function of the analysis result output and handling triggering unit 280 is to receive the prediction results and confidence level judgment results from the anomaly prediction unit 270, and process them according to different scenarios. The core is divided into "no potential anomaly" scenario and "effective potential anomaly" scenario. The key point is to clarify the early handling mechanism for effective potential anomalies, which is implemented as follows:
[0241] No potential anomalies (Conf < 80%): The integrated protection information dataset is directly pushed to the analysis module 300 via encrypted transmission for subsequent fusion analysis. At the same time, the processing log is recorded and marked "No potential anomalies, directly push for fusion analysis".
[0242] Valid potential anomalies (Conf≥80%): Immediately generate a pre-judgment anomaly report and trigger an early handling mechanism. The pre-judgment anomaly report includes: core information of the predicted anomaly, confidence calculation process, basis of association rules, historical case reference, and impact assessment of the predicted anomaly. It is simultaneously pushed to the analysis module 300, the monitoring and display module, and the dispatcher's terminal to support early handling and subsequent integrated analysis.
[0243] Optionally, in this embodiment, the supervision labels required for training a large model are automatically generated through the closed-loop feedback data of the monitored signal processing. Specifically:
[0244] Positive Label Determination: After the analysis module (300) outputs anomaly handling suggestions, the system monitors the OCS monitoring signal of the corresponding device ID in real time within a preset time period (e.g., 5 minutes). If the signal amplitude returns to the safe threshold range, the state transition stops, and no new alarms are triggered, the handling is deemed effective. The system automatically encapsulates the "OCS anomaly characteristics + security data feature package + handling suggestions" into a high-confidence positive sample and labels it as a "recommended path".
[0245] Error Label Determination: If the dispatcher manually modifies or rejects the system-generated handling suggestions on the OCS dispatch interface, the system will record the sequence of instructions executed by the dispatcher. The system uses natural language processing technology to extract the core action keywords from the execution record and uses them as the "standard answer." After comparing them with the original anomaly features, an error correction sample is generated and labeled as the "correction path."
[0246] Sample denoising and storage: The data storage layer periodically denoises the automatically generated samples, removes invalid feedback caused by communication jitter or human error, and forms a standardized incremental training set which is then stored in the historical database.
[0247] Using the aforementioned incremental training set, the online self-learning process of the large model is triggered periodically or when the sample size reaches a preset value:
[0248] Attention weight adjustment: The large model adopts a Transformer architecture. During incremental learning, the system adjusts the weight parameters of the attention mechanism through the backpropagation algorithm. If the feedback data shows that a certain type of protection information (such as fault recording data) contributes more to verifying a specific anomaly (such as a transient mutation anomaly), the system automatically increases the attention weight of the model in that feature dimension, thereby optimizing the accuracy of subsequent fusion analysis.
[0249] The self-learning algorithm not only optimizes the internal weights of the model, but also simultaneously corrects the weight coefficients in the prediction formula. For example, the system uses regression analysis to assess the probability of historical linkage anomalies and dynamically adjusts the historical probability weights in the confidence calculation formula. Association strength weight This makes the preliminary prediction results more consistent with the actual operation of the power grid.
[0250] The results of the large model's self-learning will directly drive the automated iteration of the association table (Table 1):
[0251] The large model automatically identifies valid equipment linkage relationships that have not been recorded (such as the newly added linkage between the cooling pump and the main transformer temperature control) based on implicit causal relationships discovered through self-learning, and adds them to the association table. At the same time, outdated association rules with matching accuracy consistently below the threshold are deleted or marked as downgraded.
[0252] Before officially updating the live network model, the system uses a "shadow model" for parallel simulation testing. The shadow model receives real-time data but does not output actual commands; it only verifies the match between its predictions and the actual operations of the schedulers. Only when the accuracy of the shadow model runs continuously for a cycle (e.g., 24 hours) and is better than the current main model can the system perform weight coverage and complete the smooth evolution of the model.
[0253] Furthermore, the proactive handling mechanism is designed to protect the information pre-processing module 200 from high-confidence linkage anomaly tendencies. Before the analysis module 300 completes the fusion analysis, targeted measures are taken in advance to prevent the linkage anomaly from escalating (e.g., a core equipment failure spreading to related equipment) or worsening (e.g., a sustained increase in T1 temperature leading to equipment damage). This also buys time for subsequent fusion analysis and formal handling, improving anomaly handling efficiency and reducing failure losses. This mechanism does not replace the fusion analysis and formal handling of the analysis module 300, but rather serves as a preliminary auxiliary measure. The final handling plan still needs to be refined based on the fusion analysis results.
[0254] The classification and handling plan of the advance handling mechanism:
[0255] Mild linkage anomaly (confidence level 80%-89%, only related devices show a slight tendency to malfunction, without affecting the normal operation of core equipment):
[0256] Handling measures: ① Enhance real-time monitoring by increasing the sampling frequency of core and related equipment to 50ms / time, focusing on monitoring the changing trends of abnormal characteristics (such as whether the C1 current continues to rise); ② Push early warning prompts to the terminals of maintenance personnel to remind them to pay close attention to the equipment and prepare for handling; ③ Do not adjust the equipment operating status for the time being, only record the changes in abnormal tendencies and feed them back to the analysis module simultaneously for further judgment based on the results of the fusion analysis.
[0257] Example: T1 temperature is 82℃ (2.5% above the safety threshold), C1 current exceeds the rated current by 10% (confidence level 85%), which is judged as a minor linkage abnormality. Real-time monitoring of T1 and C1 is strengthened, and an early warning prompt is pushed. No adjustment is made to the equipment operation.
[0258] Moderate linkage anomaly (confidence level 90%-94%, related devices show obvious abnormal tendencies, which may affect the operation of core equipment, but there is no risk of emergency failure):
[0259] Handling measures: ① Initiate temporary adjustments to related equipment, such as reducing the load on related equipment (e.g., increasing the operating power of the C1 cooling system to alleviate the temperature rise of T1), and adjusting protection settings (temporarily lowering the abnormal trigger threshold of related equipment to facilitate rapid response); ② Dispatch personnel respond within 5 minutes, verify the core information of the predicted abnormality, and confirm the rationality of the handling measures; ③ Maintenance personnel rush to the site, prepare for equipment maintenance, and if the abnormality tends to worsen, immediately initiate further handling; ④ Simultaneously feed the handling situation back to the analysis module to provide handling feedback data for integrated analysis.
[0260] Example: T1 temperature 86℃ (7.5% above safety threshold), C1 current 15% above rated current (92% confidence level), judged as moderate linkage abnormality, C1 cooling system operating power increased, dispatch personnel to check, maintenance personnel rush to the site.
[0261] Severe linkage anomaly (confidence level ≥ 95%, associated devices show serious abnormality tendency, which has affected the operation of core equipment and poses a risk of emergency failure):
[0262] Handling Measures: ① Immediately trigger emergency shutdown or isolation measures, stop the operation of core equipment or related equipment (e.g., shut down the C1 cooling system to prevent the fault from spreading to the T1 main transformer), isolate abnormal equipment, and prevent the fault from escalating; ② Level I alarms are simultaneously pushed to the dispatch center, maintenance personnel terminals, and the emergency response team, requiring a response within 1 minute; ③ The emergency response team immediately rushes to the site to conduct fault investigation and repair; ④ Simultaneously collect protection information during the handling process, push it to the analysis module, and optimize the final handling plan based on the fusion analysis results; ⑤ After the fault handling is completed, review the advance handling measures and optimize the correlation table parameters and confidence weight coefficients.
[0263] Example: T1 temperature 95℃ (18.75% above safety threshold), C1 current 25% above rated current, B1 bus voltage 10% below rated voltage (96% confidence level), judged as severe linkage abnormality, immediately shut down C1 cooling system, isolate B1 bus, and start emergency repair.
[0264] After the early intervention is completed, the intervention triggering unit records the intervention process (intervention measures, intervention time, intervention personnel, and intervention effect), and pushes it to the analysis module 300 and the data storage layer. This is used to optimize the fusion analysis results and to dynamically update the correlation table (such as adjusting the correlation strength and historical case probability) and enable the self-learning of the large model (optimizing redundancy screening and prediction logic), thereby continuously improving the effectiveness and accuracy of the early intervention mechanism.
[0265] After receiving the protection information dataset (including datasets corresponding to potential anomalies with no potential anomalies and potential anomalies to be verified) and the pre-judgment anomaly report (if any) pushed by the protection information pre-processing module 200 and the handling triggering unit 280, the analysis module 300 immediately starts the fusion analysis process. The core is to deeply fuse the received protection information dataset (which can be directly adapted to large model input after being standardized by the heterogeneous data pre-processing unit 220, filtered for redundancy by the effective information integration unit 250, and integrated by the information integration unit 260) with the OCS monitoring signal anomaly data analyzed by itself. The main goal is to achieve two core objectives: anomaly verification and anomaly location, and to generate more effective handling suggestions. At the same time, the fusion analysis process is optimized by combining the pre-judgment anomaly results and the early handling situation.
[0266] Figure 7 A schematic diagram of the structure of the electronic device provided in this application. Figure 7As shown, the electronic device 50 provided in this embodiment includes at least one processor 501 and a memory 502. Optionally, the device 50 further includes a communication component 503. The processor 501, memory 502, and communication component 503 are connected via a bus 504.
[0267] In a specific implementation, at least one processor 501 executes computer execution instructions stored in memory 502, causing at least one processor 501 to perform the above-described method.
[0268] The specific implementation process of processor 501 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0269] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.
[0270] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.
[0271] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.
[0272] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0273] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.
[0274] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.
[0275] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.
[0276] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0277] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0278] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0279] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0280] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0281] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.
Claims
1. A method for processing power grid monitoring signals, characterized in that, The method includes: Acquire monitoring signals from the power grid dispatching and monitoring system (OCS); Based on the OCS monitoring signals, suspected abnormal nodes were identified; Based on the device and OCS monitoring signal type corresponding to the suspected abnormal node, a suspected abnormal supplementary node is determined based on a preset association table; wherein, the association table includes the association relationship of all devices, all types of OCS monitoring signals, and the association relationship of different time windows; The suspected abnormal nodes and the suspected abnormal supplementary nodes are taken as a suspected abnormal node package. Based on the time sequence window corresponding to each node in the suspected abnormal node package, the protection information in the information protection system is obtained. Based on the protection information and the OCS monitoring signal, anomaly diagnosis is performed using a deep learning model, and anomaly diagnosis results are output.
2. The method according to claim 1, characterized in that, The step of identifying suspected abnormal nodes based on the OCS monitoring signal includes: For each type of OCS monitoring signal from each device, time-series features are extracted window by window, and a preset threshold corresponding to the time-series feature type is obtained. If the value of the time-series feature is greater than the threshold, then the time-series window is determined to be a suspected abnormal node.
3. The method according to claim 1, characterized in that, The step of determining supplementary suspected abnormal nodes based on the devices and OCS monitoring signal types corresponding to the suspected abnormal nodes, using a preset association table, includes: From the association table, identify other devices that are associated with the device corresponding to the suspected abnormal node; Obtain the timing window that is the same as the suspected abnormal node from the other devices, and identify the timing window as a suspected abnormal supplementary node.
4. The method according to claim 3, characterized in that, The method further includes: Obtain the extended timing windows of the other devices before and after the timing window, and identify the extended timing windows as the suspected abnormal supplementary nodes.
5. The method according to any one of claims 1-4, characterized in that, The method further includes: Using power grid equipment ledgers, historical data from OCS and the information protection system, and power grid operation specifications as data sources, we input equipment association relationships, association relationships of all types of OCS monitoring signals, and time sequence window association relationships. We call up historical abnormal case data of the power grid to verify the association relationships, eliminate invalid associations and correct deviation associations, and form an initial association table. Acquire supplementary feedback data from suspected abnormal nodes, integrate and analyze feedback data, and collect power grid operation feedback data. Based on feedback data, identify valid relationships that were not entered. The valid association relationship is added to the initial association table to obtain the updated association table.
6. The method according to any one of claims 1-4, characterized in that, Before performing anomaly diagnosis based on the protection information and the OCS monitoring signal using a deep learning model, the method further includes: The structured data in the protection information is cleaned, normalized, and encoded to generate a standardized structured feature vector. Natural language processing technology is used to transform unstructured data in the protected information into structured data through word segmentation, entity recognition, and text embedding. The processed structured data and unstructured data are integrated to generate a unified format credit guarantee data feature package.
7. A power grid monitoring signal processing system, characterized in that, The system includes: a node capture module, a protection information preprocessing module, and an analysis module; The node capture module is configured to capture suspected abnormal node packets in the OCS monitoring signal in real time. The protection information preprocessing module is configured to receive suspected abnormal node packets and obtain protection information in the protection information system based on the time sequence window of each abnormal node in the suspected abnormal node packet. The analysis module is configured to perform anomaly analysis on the OCS monitoring signal, and output an anomaly determination command if the analysis result is abnormal. The protection information preprocessing module, upon receiving an anomaly determination instruction, feeds the cached protection information to the analysis module as needed. The analysis module integrates the received protection information with the OCS monitoring signal for analysis.
8. An electronic device, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by the processor, implement the method described in any one of claims 1-6.
10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-6.