Urban rail transit pass system risk fine classification method
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-22
- Publication Date
- 2026-08-04
AI Technical Summary
在长期运营过程中,通号系统易受到高温、低温、积水、电磁干扰、设备老化等不同场景因素影响,进而诱发设备故障、功能退化和风险传播,严重时可能导致行车中断、列车降级运行、信号误显示等后果
[0061]This invention focuses on urban rail transit signaling systems, refining risk classification to the smallest maintenance unit, significantly improving the precision of risk identification and classification. By introducing different scenarios such as high temperature, low temperature, water accumulation, electromagnetic interference, and equipment aging, it effectively matches risk assessment results with actual operating environments, improving the scenario adaptability of risk classification. By constructing a risk propagation network composed of scenario nodes, risk factor nodes, equipment nodes, and consequence nodes, it can identify key propagation links and key risk nodes, more accurately revealing the risk evolution mechanism. By establishing a dynamic update mechanism, it can promptly update the risk point set and risk level when fault data increases, environmental scenarios change, or equipment is iterated, improving the timeliness and accuracy of risk assessment results. Thus, it provides reliable technical support for risk early warning, precise control, and operation and maintenance decision-making in urban rail transit signaling systems.
Smart Images

Figure CN122509701A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of urban rail transit operation safety risk management technology, specifically to a method for refined risk classification of urban rail transit signaling systems. Background Technology
[0002] The urban rail transit signaling system is a core system ensuring safe train operation, train management, and operational scheduling. It mainly comprises communication and signaling systems, and is characterized by a wide variety of equipment, complex system hierarchy, high functional coupling, and stringent real-time requirements. During long-term operation, the signaling system is susceptible to various factors such as high and low temperatures, water accumulation, electromagnetic interference, and equipment aging, which can induce equipment failure, functional degradation, and risk propagation. In severe cases, this can lead to train service disruptions, degraded train operation, and signal misreading.
[0003] Existing risk classification methods for the China Railway Signal & Communication Corporation (CRSC) mostly employ general risk matrix methods or qualitative evaluation methods, typically conducting risk assessments only from the perspective of a single equipment failure or a single consequence. This approach has the following shortcomings: First, the risk classification granularity is too coarse, making it difficult to refine to the smallest maintenance unit, thus failing to meet the needs of refined operation and maintenance and precise control. Second, it does not adequately consider the differences in risks under different operating scenarios, lacking targeted analysis for typical scenarios such as high temperature, water accumulation, electromagnetic interference, and equipment aging, making it difficult to truly reflect the scenario-adaptive characteristics of risks. Third, it does not adequately depict the propagation process of risks from scenario triggering, the formation of hazard factors, the spread of equipment failure, to the evolution of consequences, making it difficult to identify key propagation links and key risk nodes. Fourth, existing methods lack dynamic updating capabilities; when fault data, environmental scenarios, or equipment composition change, the risk point set and risk level cannot be adjusted in a timely manner, causing the assessment results to lag behind the actual operating status of the system.
[0004] Therefore, there is an urgent need to propose a refined risk classification method for urban rail transit signaling systems in different scenarios, so as to achieve precise extraction of risk points, effective analysis of risk propagation process, scenario-based classification of risk levels, and dynamic updating of risk results, thereby improving the accuracy, pertinence, and real-time nature of risk management in signaling systems. Summary of the Invention
[0005] This invention aims to provide a method for refined risk classification of urban rail transit signaling systems to solve the above problems.
[0006] The technical solution of this invention is: a method for refined risk classification of urban rail transit signaling systems, comprising the following steps:
[0007] S1, Basic Data Preprocessing; This includes acquiring basic data from the urban rail transit signaling system, including fault data, risk database data, hidden danger database data, maintenance data, environmental monitoring data, and equipment ledger data, and cleaning, standardizing, and classifying the basic data.
[0008] S2, Constructing the correlation between scenarios and risk points under different scenarios; including constructing a risk point set of the smallest maintenance unit based on preprocessed basic data and combining the communication system and signal system structure of the urban rail transit signaling system, and establishing the correlation between scenarios and risk points under different scenarios;
[0009] S3, calculate the risk index for each risk point; including quantifying the probability of risk occurrence L and the severity of consequences C for each risk point based on the traditional LC model, and calculating the risk index D.
[0010] S4, identify high-risk propagation paths and key risk nodes; including constructing a risk propagation network composed of scenario nodes, risk factor nodes, equipment nodes and consequence nodes, analyzing the propagation probability, node impact, occurrence frequency and control efficiency of risk propagation paths, and identifying high-risk propagation paths and key risk nodes in different scenarios;
[0011] S5, refines risk classification and generates risk level results for different scenarios; including combining risk index D, the relationship between scenarios and risk points, risk propagation path characteristics, and key risk node identification results to refine the risk classification of urban rail transit signaling system and generate risk level results for different scenarios.
[0012] S6 updates the results of dynamic updates of risk point sets and risk levels triggered by data updates, scenario changes, and equipment iterations; including dynamic updates of risk point sets and risk levels triggered by data updates, scenario changes, and equipment iterations, and synchronizing the update results to the risk management platform and operation and maintenance management system.
[0013] Preferably, in step S1, the basic data processing includes:
[0014] S11, extract data related to the signaling system from the fault database, operation and maintenance work order system, environmental monitoring platform and equipment management system;
[0015] S12, the extracted data is deduplicated, missing values are filled in, outliers are removed and uniformly encoded to form a standardized dataset;
[0016] S13. The standardized dataset is classified and stored according to communication system, signal system, subsystem, equipment level, component level and scene category.
[0017] Preferably, in step S2, constructing the risk point set includes:
[0018] S21, using text mining to extract candidate risk points from fault reports, maintenance logs and emergency plan texts;
[0019] S22, in conjunction with expert review, candidate risk points are deduplicated, merged, supplemented and standardized to form standardized risk points;
[0020] S23 categorizes standardized risk points into two main categories: communication systems and signal systems, and further refines them to the smallest maintenance unit to form a risk point set.
[0021] Preferably, in step S2, the different scenarios include high temperature scenario, low temperature scenario, water accumulation scenario, electromagnetic interference scenario and equipment aging scenario, and the correlation between the scenario and the risk point is obtained through correlation analysis of historical fault data.
[0022] Preferably, in step S2, establishing the association between the scenario and the risk point includes:
[0023] S24, Statistical analysis of the frequency of failures at various risk points under different scenarios;
[0024] S25, calculate the support and confidence between scenarios and risk points based on association rule mining algorithms;
[0025] S26. Associate scenarios with risk points whose confidence level reaches a preset threshold with risk points to form a scenario-risk point association matrix.
[0026] Preferably, in step S3, the probability of risk occurrence L is quantified based on the historical frequency of occurrence of the fault event corresponding to the risk point, the maintenance frequency, and the exposure frequency of the scenario, and the severity of consequences C is quantified based on the degree of driving impact, equipment damage, passenger impact range, and operational interruption caused by the risk event.
[0027] Preferably, in step S4, the construction of the risk propagation network includes:
[0028] S41, abstract different scenarios into scenario nodes, abstract risk factors that cause risk evolution into risk factor nodes, abstract signaling system equipment into equipment nodes, and abstract accident or failure results into consequence nodes.
[0029] S42, establish trigger edges between scene nodes and risk factor nodes, establish propagation edges between risk factor nodes and device nodes and between device nodes, and establish consequence edges between device nodes and consequence nodes.
[0030] S43 determines the propagation probability of each side based on historical fault data and expert experience, forming a risk propagation network.
[0031] Preferably, in step S4, the identification of high-risk transmission paths and key nodes includes:
[0032] S44, starting from the scene node and ending at the consequence node, calculates the product of the propagation probabilities of each edge along the risk propagation path to obtain the path propagation probability; the path propagation probability is the product of the propagation probabilities of all edges along a propagation path, reflecting the likelihood of risk spreading along that path, as shown in the following formula:
[0033]
[0034] Where Pi is the propagation probability of the i-th edge on the path, and n is the number of edges on the path;
[0035] S45, count the number of downstream node failures caused by the failure of a device node, and calculate the node impact degree; the node impact degree is the proportion of downstream node failures caused by a node failure to the total number of nodes, reflecting the criticality of the node in the propagation network, as shown in the formula below:
[0036]
[0037] in, N represents the number of downstream nodes that fail due to node failure, and N is the total number of nodes in the network.
[0038] S46, Calculate the occurrence frequency; the occurrence frequency is the ratio of the frequency of the risk chain from the scene node to the consequence node Ci to the frequency of propagation from the scene node, as shown in the formula:
[0039]
[0040] Please explain the meaning of all parameters in the above formula in words here.
[0041] in, For risk scenarios To the consequences The frequency of occurrence of risk chains; For risk scenarios Frequency of transmission.
[0042] S47, Calculate the control efficiency; the control efficiency D is the percentage decrease in the probability of transmission after setting control measures along a certain transmission path, reflecting the effectiveness of the measures. The formula is:
[0043]
[0044] Where E0 is the propagation probability before the measure is taken, and E1 is the propagation probability after the measure is taken;
[0045] S48. High-risk propagation paths and key risk nodes are selected based on path propagation probability, node impact, occurrence frequency, and control efficiency.
[0046] In step S44, the path propagation probability is the product of the propagation probabilities of each edge on the path; in step S45, the node influence degree is the proportion of the number of downstream failed nodes caused by node failure to the total number of nodes in the network.
[0047] Preferably, in step S5, the risk refinement classification includes:
[0048] S51, Initial classification of risk points based on risk index D;
[0049] S52, Scenario correction is performed on the initial classification results by combining the correlation between scenarios and risk points;
[0050] S53, combining the propagation probability of high-risk propagation paths, the node influence of key risk nodes, and the frequency of occurrence of risk chains, the risk level is comprehensively adjusted to obtain the final risk level; the final risk level is divided into any one or more levels among low risk, medium risk, high risk, and extremely high risk.
[0051] Preferably, in step S6, the dynamic update includes:
[0052] S61, when the number of newly added fault data reaches a preset threshold or the maintenance frequency changes significantly, a data update is triggered;
[0053] S62, when the scene feature parameters exceed the historical threshold or a new scene type is added, a scene update is triggered;
[0054] S63, when new or replaced equipment is added to the signaling system, iterative updates of the equipment are triggered;
[0055] In step S6, the dynamic update process includes:
[0056] Re-collect the latest data from the fault database, maintenance work order system, and environmental monitoring platform;
[0057] Recalculate the probability of risk occurrence (L), severity of consequences (C), risk index (D), and scenario-related confidence level for each risk point.
[0058] Remove the associations between scenarios and risk points that are below the preset confidence threshold, add new risk points, and delete invalid risk points;
[0059] The updated results are reviewed by experts and synchronized to the risk management platform and operation and maintenance management system after the review is approved.
[0060] The beneficial effects of this invention are as follows:
[0061] This invention focuses on urban rail transit signaling systems, refining risk classification to the smallest maintenance unit, significantly improving the precision of risk identification and classification. By introducing different scenarios such as high temperature, low temperature, water accumulation, electromagnetic interference, and equipment aging, it effectively matches risk assessment results with actual operating environments, improving the scenario adaptability of risk classification. By constructing a risk propagation network composed of scenario nodes, risk factor nodes, equipment nodes, and consequence nodes, it can identify key propagation links and key risk nodes, more accurately revealing the risk evolution mechanism. By establishing a dynamic update mechanism, it can promptly update the risk point set and risk level when fault data increases, environmental scenarios change, or equipment is iterated, improving the timeliness and accuracy of risk assessment results. Thus, it provides reliable technical support for risk early warning, precise control, and operation and maintenance decision-making in urban rail transit signaling systems. Attached Figure Description
[0062] Figure 1 This is a flowchart illustrating a method for refined risk classification of urban rail transit signaling systems for different scenarios, provided by an embodiment of the present invention.
[0063] Figure 2 This is a schematic diagram of network propagation probability calculation provided in an embodiment of the present invention;
[0064] Figure 3 This is a schematic diagram illustrating the calculation of network node influence rate provided in an embodiment of the present invention;
[0065] Figure 4 This is a network propagation example diagram provided in an embodiment of the present invention;
[0066] Figure 5 This is a schematic diagram illustrating the evolution process of a high-temperature scenario provided in an embodiment of the present invention. Detailed Implementation
[0067] The present invention will be further described below with reference to the accompanying drawings and specific embodiments, so that those skilled in the art can better understand and implement the present invention. The embodiments of the present invention are not limited thereto.
[0068] Example 1
[0069] like Figure 1 As shown, this is a method for refined risk classification of urban rail transit signaling systems for different scenarios, including:
[0070] S1 Data Acquisition and Standardization Processing
[0071] Acquire basic data from the urban rail transit signaling system. This basic data includes fault data, risk database data, hazard database data, maintenance data, environmental monitoring data, and equipment ledger data. Fault data can be sourced from the fault database and maintenance work order system, environmental monitoring data can be sourced from the environmental monitoring platform, and equipment ledger data can be sourced from the equipment management system.
[0072] The collected basic data undergoes preprocessing, including data deduplication, outlier removal, missing value completion, unified coding, and field standardization, to form a standardized dataset suitable for subsequent analysis. Furthermore, the data can be categorized and stored according to communication systems, signal systems, subsystems, equipment layers, component layers, and scenario categories.
[0073] S2 Risk Point Extraction and Scenario Association Construction
[0074] Based on the standardized data obtained in step S1, risk points of the urban rail transit signaling system are extracted. A combination of text mining and expert review is used to extract candidate risk points from fault reports, maintenance logs, emergency plans, and historical cases. Then, expert review merges duplicate risk points, supplements missing risk points, and standardizes risk point naming and coding rules to form a standardized risk point set.
[0075] The risk point set is refined to the smallest maintenance unit, enabling the risk classification results to directly serve equipment inspection and maintenance. Based on this, and combined with scenarios such as high temperature, low temperature, water accumulation, electromagnetic interference, and equipment aging, the correlation between scenarios and risk points is established, forming a scenario-risk point correlation matrix.
[0076] The correlation between scenarios and risk points can be obtained through association rule mining of historical failure data. Support and confidence are used as indicators of association strength to identify highly correlated risk points in different scenarios.
[0077] S3 Risk Index Calculation
[0078] For each extracted risk point, the LC risk grading model is used for risk quantification. In the LC risk grading model, the risk index D is jointly determined by the probability of risk occurrence L and the severity of the consequences C, and its expression is:
[0079] (1)
[0080] Where D is the risk index, L is the probability of a risk event occurring, and C is the severity of the consequences of a risk event.
[0081] Furthermore, the probability of risk occurrence (L) can be quantified based on the frequency of historical failures, maintenance frequency, and exposure frequency in different scenarios; the severity of consequences (C) can be quantified based on the degree of impact on driving, the extent of equipment damage, the scope of passenger impact, and the degree of operational disruption. Based on the risk index (D), the initial risk level for each risk point can be obtained.
[0082] S4 Risk Transmission Network Construction and Analysis
[0083] Based on the physical topology of the signaling system and combined with the ABC risk propagation process, the nodes and edges of the risk propagation network are defined as follows:
[0084] 1) Node types: divided into four categories: scenario node A, risk factor node B, equipment node, and consequence node C. Node attributes include risk level (RR4), propagation probability (P), and occurrence frequency (F).
[0085] Scene node A: such as high temperature (A1) and electromagnetic interference (A6), with attributes of magnetic field strength and duration;
[0086] Risk factor node B: such as CPU overload (B1) and decreased insulation resistance (B2), with attributes of "affect range (e.g., single device / multiple devices)" and "trigger threshold (e.g., CPU load rate > 85%)".
[0087] Equipment nodes: such as "Interlocking host (system layer)", "Railwayside AP (subsystem layer)" and "Power supply module (component layer)", with attributes of "Structural importance (S)" and "Functional importance (F)";
[0088] Consequence node C: such as "Training interruption (C1)" and "Signal false trigger (C2)", with attributes of "Severity of consequences (e.g., full line shutdown / single station delay)" and "Number of people affected (e.g., 100,000 people / 1,000 people)".
[0089] 2) Definition of edge: It represents the risk propagation relationship between nodes and is divided into three categories: "trigger edge (A→B, B→device)", "diffusion edge (device→device)" and "consequence edge (device→C)". The weight of the edge is "propagation probability (P)" and is assigned based on historical fault data and expert experience.
[0090] Triggering edge: such as "A1 (high temperature 65℃) → B1 (CPU overload)", propagation probability P=0.85 (in historical data, the CPU overload occurrence rate is 85% when the high temperature is ≥60℃);
[0091] Diffusion edge: such as "trackside AP (fault) → vehicle communication unit (fault)", propagation probability P=0.6 (the probability of the vehicle communication unit being affected when the trackside AP fails is 60%).
[0092] Consequence edge: such as "interlocking host (failure) → C1 (train interruption)", propagation probability P=0.95 (the probability of train interruption caused by interlocking host failure is 95%).
[0093] 3) Network construction steps:
[0094] Basic topology mapping: Import the device nodes in the physical topology network of the signaling system into Gephi software, retain the core nodes with "degree centrality > 10" and "between centrality > 0.6" (such as interlocking host, ATS server, vehicle-to-ground communication unit) to form the device base layer of the risk propagation network;
[0095] Embedding of Class A and Class B nodes: Based on the risk characteristic indicators of some typical scenarios (such as "equipment temperature" and "CPU load rate" in high temperature scenarios), embed corresponding Class A scenario nodes and Class B risk factor nodes next to the equipment nodes. For example, embed "A1 (high temperature)" node and "B3 (poor heat dissipation of signal)" node near the trackside signal equipment node.
[0096] Propagation edge construction: Based on the actual risk propagation cases of the subway company (such as "high temperature (A) → power module aging (B) → on-board ATP failure (equipment) → train degraded operation (C)"), the propagation probability between nodes is calculated by Boolean algebra method, and triggering edges, diffusion edges and consequence edges are constructed to form a complete risk propagation network;
[0097] To further characterize the evolution of risks in different scenarios, a risk propagation network is constructed, consisting of scenario nodes, risk-causing factor nodes, equipment nodes, and consequence nodes.
[0098] Among them, the scenario node is used to represent operating scenarios such as high temperature, low temperature, water accumulation, electromagnetic interference, and equipment aging; the risk factor node is used to represent the direct risk factors formed under the action of the scenario; the equipment node is used to represent the relevant equipment or components in the signaling system; and the consequence node is used to represent the operational or safety consequences ultimately caused by the risk event.
[0099] The risk propagation chain is the core carrier of risk evolution in the signaling system, and its path characteristics, triggering conditions, and diffusion speed vary significantly depending on the scenario. This section, based on the risk propagation model constructed in the previous section (Category A scenario node → Category B risk factor node → equipment node → Category C consequence node), and combining the environmental characteristics, equipment attributes, and historical failure cases of some typical scenarios, dissects the risk propagation chain structure under different scenarios, clarifying the "key triggering node - core diffusion path - consequence transmission logic," providing a precise basis for subsequent targeted control.
[0100] To quantify the characteristics of risk propagation, four core analytical indicators are defined to support subsequent path identification and evolution speed analysis:
[0101] Propagation probability (E): The product of the propagation probabilities of all edges along a propagation path, reflecting the likelihood of risk spreading along that path. The formula is as follows:
[0102] (2)
[0103] P i Let be the propagation probability of the i-th edge on the path, and n be the number of edges on the path.
[0104] For example, the propagation probability E of the path "A1→B1→Interlocking Host→C1" is 0.85(A1→B1)×0.9(B1→Interlocking Host)×0.95(Interlocking Host→C1)=0.726. Figure 2 As shown:
[0105] Node Impact (I): The proportion of downstream node failures triggered by a node's failure out of the total number of nodes. It reflects the criticality of the node in the propagation network, as shown in the formula below:
[0106] (3)
[0107] in, N represents the number of downstream nodes that fail due to node failure, and N is the total number of nodes in the network.
[0108] like Figure 3 As shown, when node N5 fails, the node loses its working capability. At this time, the risk will propagate along the dotted line to other downstream nodes. When the downstream nodes cannot bear too much risk load, they will also fail one after another. Assuming that the failure of the interlocking host causes 20 downstream nodes to fail, and the total number of nodes in the network is 50, then the node influence of the interlocking host in the network is I=40%.
[0109] Frequency of occurrence (F): The propagation of risk from the scenario node to the consequence node. The ratio of the frequency of occurrence of a risk chain to the frequency of propagation from scene nodes is expressed by the formula:
[0110] (4)
[0111] in, For risk scenarios To the consequences The frequency of occurrence of risk chains; For risk scenarios Frequency of transmission.
[0112] Control Efficiency (D): The percentage decrease in the probability of transmission after control measures are implemented along a transmission path, reflecting the effectiveness of the measures. The formula is: (E0 is the propagation probability before the measure, and E1 is the propagation probability after the measure). For example, if E0 = 0.726 before the measure and E1 = 0.1 after the measure, then D = 86.2%.
[0113] To address the characteristics of risk propagation networks—multiple sources (Class A nodes) and multiple sinks (Class C nodes)—an improved Dijkstra algorithm is employed, using "propagation probability (E)" as the weight to filter out "high-risk paths" (E≥0.6). The specific steps are as follows:
[0114] Initialization: Set all A-type scenario nodes as the starting point and C-type consequence nodes as the ending point, and initialize the "current highest propagation probability" of each node (starting point node E=1, other nodes E=0).
[0115] Path search: Starting from the origin, traverse all adjacent nodes, calculate the propagation probability (E) of each path, and update the "current highest propagation probability" of the node (only retain paths with higher E values);
[0116] Path filtering: When the search reaches the endpoint node, extract all paths with E≥0.6 as "high-risk propagation paths";
[0117] Key node identification: Nodes that appear ≥3 times in high-risk paths are identified, and their impact (I≥30%) is used to determine the "key risk nodes".
[0118] Taking a high-temperature scenario as an example, two high-risk paths were identified using an algorithm (as shown in Table 1), and key risk nodes were located:
[0119] Table 1 High-risk pathways
[0120]
[0121] The high-risk paths identified by the algorithm were compared and verified with actual ABC risk point cases of the subway company to ensure that the paths conformed to the actual situation on site:
[0122] like Figure 4 As shown, the case matching is as follows: Three fault cases in the high-temperature scenario of Beijing Metro in 2024 (interlocking host overload, trackside signal failure, and onboard ATP degradation) were selected, and the actual propagation path was extracted (e.g., "high temperature (A) → CPU overload (B) → interlocking host failure → train operation interruption (C)").
[0123] Consistency analysis: Compare the overlap between the algorithm output path and the actual case path. If the overlap is ≥90% (e.g., 2 out of 3 cases are completely consistent with the algorithm path, and 1 case only has a 5-minute difference in propagation delay), then the path identification is deemed effective.
[0124] Based on the "occurrence frequency (F)" and "propagation probability (E)" of the risk propagation network, the probability of the evolution from node A to Ci is constructed. The formula is as follows:
[0125] (5)
[0126] The larger the P-value, the higher the likelihood of the risk spreading within a unit of time, and the more priority should be given to intervention.
[0127] Taking the core high-risk paths in some typical scenarios as examples, the calculation evolution speed is shown in the table below:
[0128] Table 2 Calculation of Evolution Rate
[0129]
[0130] By comparing the evolutionary rate (V) in different scenarios, two typical evolutionary characteristics are summarized, providing a basis for differentiated management and control:
[0131] Rapidly spreading scenarios (V≥3.5): These include scenarios involving water accumulation and electromagnetic interference. The risk factors (B) in these scenarios are characterized by "short propagation paths and direct impacts".
[0132] Slow-accumulation scenarios (V < 2): These include scenarios involving equipment aging and dust. The risk factors (B) in these scenarios require long-term accumulation (e.g., component wear and tear, dust buildup).
[0133] S5 Risk Refined Classification
[0134] By combining the risk index calculation results in step S3, the scenario-risk point correlation in step S2, and the risk propagation characteristics in step S4, the risks of the signaling system are classified in a refined manner.
[0135] First, risk points are initially classified based on the risk index D. Then, the risk level is modified according to the correlation strength of the risk points in specific scenarios. Finally, the risk level is comprehensively adjusted by combining the propagation probability of high-risk propagation paths, the impact of key risk nodes, and the frequency of occurrence of risk chains to obtain the final risk level result.
[0136] The final risk level can be divided into four levels: low risk, medium risk, high risk, and extremely high risk.
[0137] Based on the above framework, and combined with historical failure cases of subways in Beijing, Qingdao, Nanjing and other cities (a total of 127 typical risk propagation events from 2019 to 2024), the core propagation links of typical scenarios are deeply analyzed to clarify the link characteristics and key nodes of each scenario.
[0138] like Figure 5As shown, (1) High temperature scenario (rapid diffusion type)
[0139] Risk propagation in high-temperature scenarios revolves around the core logic of "thermal failure," with the primary risk factor being "equipment overheating." The propagation chain is characterized by "rapid penetration across levels and strong cross-subsystem correlation," with the core chain as follows:
[0140] Core propagation chain 1: High temperature → CPU overload → Interlocking host → Train operation interruption
[0141] Triggering phase (A1→B1): When the ambient temperature is ≥60℃ (A1, high temperature), the heat dissipation efficiency of the trackside / station level equipment decreases, and the activation probability of "CPU overload (B1)" increases linearly with the temperature. Among them, the B1 activation probability of high-density computing equipment such as interlocking host and ATS server is the highest.
[0142] Diffusion stage (B1 → Equipment → Equipment):
[0143] B1 (CPU overload) first causes a decrease in the computing efficiency of the interlocking host, triggering a "master-slave switchover delay", with a propagation probability of P=0.92 (based on Beijing Metro's high-temperature fault data in 2024).
[0144] If the master / slave switchover fails, the interlocking master fault will propagate to the trackside signal via the "signal control link" (propagation probability P=0.78), causing the signal to display incorrectly.
[0145] Meanwhile, the "data interaction link" between the interlocking host and the central ATS server triggered an ATS data synchronization anomaly (propagation probability P=0.65), exacerbating the spread of risk;
[0146] Consequence stage (equipment → C1 / C2): Interlocking host failure directly causes "train interruption (C1)" (propagation probability P=0.95), and signal misreading may lead to "train wrong route (C2)" (propagation probability P=0.83);
[0147] Key features: path length = 4, propagation efficiency E = 0.92 × 0.78 × 0.95 ≈ 0.68, node influence I (interlocking host) = 42%.
[0148] Core transmission chain 2: High temperature → Cooling fan failure → Onboard ATP → Train degradation
[0149] Triggering phase (A1→B2): When the temperature of the vehicle equipment compartment rises (A1), the activation probability of "cooling fan failure (B2)" increases significantly, especially for older models (operated for more than 8 years) where the risk of fan failure is higher.
[0150] Diffusion phase (B2→device→device): B2 causes the temperature of the on-board ATP module to rise, triggering the "module protection mechanism" and degrading the ATP vehicle control function (propagation probability P=0.90).
[0151] The ATP downgrade spreads to the trackside ZC system via the "vehicle-to-ground communication link" (propagation probability P=0.62), causing anomalies in the ZC's calculation of the train's movement authorization.
[0152] Consequence stage (equipment → C3): Onboard ATP downgrade directly triggers "train downgrade operation (C3)" (propagation probability P=0.98). If ZC authorization is abnormal, it may further lead to "train emergency braking (C4)" (propagation probability P=0.75).
[0153] Key features: path length = 3, propagation probability E = 0.88 × 0.90 × 0.98 ≈ 0.78, node influence I (vehicle-mounted ATP) = 38%, evolution period T = 20 minutes.
[0154] (2) Water accumulation scenario (extremely rapid diffusion type)
[0155] The risk propagation in waterlogged scenarios revolves around the core logic of "electrical short circuits," with the hazard factor concentrated in "insulation failure." The propagation chain is characterized by "short paths, severe consequences, and rapid cross-level diffusion," with the core chain as follows:
[0156] Core transmission chain: water accumulation → electrical leakage → power distribution room → complete operational interruption
[0157] Triggering phase (A4→B4): When the water depth in the low-lying area beside the track / station is ≥10cm (A4, water accumulation), the activation probability of "equipment leakage (B4)" increases sharply (the activation probability reaches 0.95 when the water depth is 15cm). Among them, components that are in direct contact with water, such as power distribution room cables and trackside equipment bases, are high-risk triggering points.
[0158] Diffusion stage (B4 → Equipment → Equipment):
[0159] B4 (leakage) first causes a short circuit in the power distribution equipment in the power distribution room (propagation probability P=0.98), triggering the "leakage protection device tripping";
[0160] A short circuit in the power distribution equipment propagates through the "power supply link" to all equipment on the station level (such as interlocking main unit and communication cabinet), causing a power outage in all equipment in the station (propagation probability P=0.92).
[0161] If the station is a transfer station, the risk of power failure can spread to the station equipment of adjacent lines through the "interconnection power supply link" (propagation probability P=0.70), forming a cross-line risk;
[0162] Consequence stage (equipment → C15 / C16): Power failure of all equipment in the station causes "large-scale operation interruption (C15)" (propagation probability P=0.99), and long-term short circuit of power distribution equipment may lead to "equipment burnout and scrapping (C16)" (propagation probability P=0.85);
[0163] Key features: path length = 3, propagation probability E = 0.95 × 0.98 × 0.99 ≈ 0.92, node impact I (power distribution room) = 55%, making it the fastest spreading and most serious link in all scenarios.
[0164] (3) Equipment aging scenario (slow cumulative type, T=60-120 minutes)
[0165] The risk propagation in equipment aging scenarios revolves around the core logic of "performance degradation," with the causative factors concentrated on "component failure." The propagation chain is characterized by "long paths, slow diffusion, and gradual failure at multiple nodes," with the core chain as follows:
[0166] Core propagation chain: Equipment aging → Hard drive failure → ATS server → Overall scheduling failure
[0167] Triggering phase (A7→B7): When the equipment has been in operation for more than 4 years (A7, equipment aging) or MTBF (Mean Time Between Failures) <1000 hours, the activation probability of "hard disk failure (B7)" gradually increases (the activation probability reaches 0.85 when the equipment has been in operation for 12 years). Storage-intensive equipment such as ATS servers and database servers are high-risk trigger points.
[0168] Propagation phase (B7→Device→Device→Device): B7 (hard drive failure) first causes data read / write errors on the ATS server (propagation probability P=0.90), and the scheduler workstation displays a delay;
[0169] If not handled in time, the erroneous data will spread to the central ATS primary and backup servers through the "data synchronization link" (propagation probability P=0.75), causing primary and backup synchronization to fail.
[0170] The failure of primary and backup synchronization further spread to the station's ATS extensions (propagation probability P=0.68), causing the station level to be unable to receive central dispatch instructions;
[0171] Consequence stage (equipment → C25 / C26): A complete failure of the ATS server leads to "complete operational paralysis (C25)" (propagation probability P=0.95), and hard disk failure may result in "loss of scheduling data (C26)" (propagation probability P=0.80).
[0172] Key characteristics: Path length = 5, propagation probability E = 0.85 × 0.90 × 0.75 × 0.95 ≈ 0.55, node influence I (ATS server) = 48%, it is a "slow cumulative link" with a long intervention window.
[0173] By dissecting the core propagation links in typical scenarios, and comparing them across scenarios from four dimensions—"path, efficiency, nodes, and cycle"—the common patterns and differentiated characteristics of risk propagation in the signaling system are extracted, providing a basis for the formulation of subsequent control strategies.
[0174] (1) Cross-scenario link feature comparison
[0175] Table 3 Specific Results of Cross-Scenario Links
[0176]
[0177] (2) Extraction of the core laws of the propagation chain
[0178] The scenario determines the propagation logic: The core characteristics of the environmental scenario directly determine the type of risk factor and the propagation path. Water / electricity related scenarios (water accumulation, high humidity) use "electrical short circuit" as the propagation logic, temperature related scenarios (high temperature, low temperature) use "thermal failure / mechanical jamming" as the propagation logic, and interference scenarios (electromagnetic interference) use "signal distortion" as the propagation logic.
[0179] Key nodes are highly concentrated: In the core propagation links of all scenarios, "interlocking host, vehicle ATP, ATS server, and power distribution room" are high-frequency key nodes (appearing ≥6 times). The failure of these nodes will directly lead to a 30%-50% increase in link propagation efficiency.
[0180] The diffusion speed is positively correlated with the urgency of the scenario: the evolution cycle of rapidly spreading scenarios (water accumulation, electromagnetic interference, strong wind) is less than 45 minutes, and intervention needs to be completed within 10-20 minutes; the evolution cycle of slowly accumulating scenarios (equipment aging, dust) is greater than 60 minutes, and there is an intervention window of 30-40 minutes.
[0181] Cross-level diffusion relies on "link hubs": the risk spreads across levels from "trackside level → station level → center level" mainly relying on three major hubs: "power supply link (power distribution room), data link (ATS server), and control link (interlocking host)". Cutting off the hub links can reduce the probability of cross-level diffusion by more than 60%.
[0182] S6 Dynamic Updates and System Synchronization
[0183] The risk point set needs to be adjusted in real time according to "data updates, scenario changes, and equipment iterations" to ensure that it always keeps pace with the actual operating status of the signaling system. The update mechanism includes three triggering conditions and a complete process:
[0184] (1) Update trigger conditions
[0185] Data update trigger: When new fault data (e.g., ≥10 new fault records per month) or maintenance data (e.g., a significant increase in the maintenance frequency of a certain risk point) is added, an update is automatically triggered to ensure that the risk point set reflects the latest fault patterns;
[0186] Scene change trigger: When scene feature parameters exceed historical thresholds (such as an increase in high temperature thresholds or the addition of new extreme weather scenes) or when a new scene is added (such as an extreme rainstorm scene), manual updates are triggered to adapt to scene changes.
[0187] Equipment iteration trigger: When the signaling system adds new equipment (such as introducing a 5G vehicle communication module) or replaces old equipment (such as replacing traditional track circuits with axle counters), the technical department submits an update application. Once approved, the update is triggered, either by adding new risk points or deleting failed risk points.
[0188] (2) Update process
[0189] Data Acquisition: Obtain the latest data from fault databases, maintenance work order systems, and environmental monitoring platforms to support risk level assessment;
[0190] Risk level assessment: Reanalyze the L, E, C values and scenario association confidence of risk points, delete associations with confidence levels <50%, add new risk points and further calculate the corresponding levels;
[0191] Expert review: Three experts will be invited to review the updated content. If the pass rate is ≥2 / 3, the update will be confirmed to ensure the rationality of the updated content.
[0192] System synchronization: The updated risk point set and risk level are synchronized to the risk management platform and operation and maintenance work order system to ensure data consistency across departments and avoid information discrepancies.
[0193] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for refined risk classification of urban rail transit signaling systems, characterized in that, Includes the following steps: S1, Basic data preprocessing; This includes acquiring basic data from the urban rail transit signaling system, which includes fault data, risk database data, hidden danger database data, maintenance data, environmental monitoring data, and equipment ledger data. The basic data is then cleaned, standardized, and categorized. S2, constructing the correlation between scenarios and risk points under different scenarios; This includes constructing a risk point set for the smallest maintenance unit based on preprocessed basic data, combined with the communication and signaling system structure of the urban rail transit signaling system, and establishing the correlation between scenarios and risk points under different scenarios; S3, calculate the risk index for each risk point; This includes quantifying the probability of risk occurrence (L) and the severity of consequences (C) at each risk point based on the traditional LC model, and calculating the risk index (D). S4 identifies high-risk transmission paths and key risk nodes; This includes constructing a risk propagation network composed of scenario nodes, risk factor nodes, equipment nodes, and consequence nodes; analyzing the propagation probability, node impact, occurrence frequency, and control efficiency of risk propagation paths; and identifying high-risk propagation paths and key risk nodes in different scenarios. S5 refines and classifies risks, generating risk level results for different scenarios; This includes combining the risk index D, the correlation between scenarios and risk points, the characteristics of risk propagation paths, and the identification results of key risk nodes to conduct a refined classification of the risks of urban rail transit signaling systems, forming risk level results for different scenarios; S6 updates are based on the results of dynamic updates of risk point sets and risk levels triggered by data updates, scenario changes, and equipment iterations. This includes dynamic updates of risk point sets and risk levels triggered by data updates, scenario changes, and equipment iterations, and synchronizing the update results to the risk management platform and operation and maintenance management system.
2. The method for refined risk classification of urban rail transit signaling systems according to claim 1, characterized in that, In step S1, basic data processing includes: S11, extract data related to the signaling system from the fault database, operation and maintenance work order system, environmental monitoring platform and equipment management system; S12, the extracted data is deduplicated, missing values are filled in, outliers are removed and uniformly encoded to form a standardized dataset; S13. The standardized dataset is classified and stored according to communication system, signal system, subsystem, equipment level, component level and scene category.
3. The method for refined risk classification of urban rail transit signaling systems according to claim 1, characterized in that, In step S2, constructing the risk point set includes: S21, using text mining to extract candidate risk points from fault reports, maintenance logs and emergency plan texts; S22, in conjunction with expert review, candidate risk points are deduplicated, merged, supplemented and standardized to form standardized risk points; S23 categorizes standardized risk points into two main categories: communication systems and signal systems, and further refines them to the smallest maintenance unit to form a risk point set.
4. The method for refined risk classification of urban rail transit signaling systems according to claim 1, characterized in that, In step S2, the different scenarios include high temperature scenario, low temperature scenario, water accumulation scenario, electromagnetic interference scenario and equipment aging scenario. The correlation between the scenario and the risk point is obtained through correlation analysis of historical fault data.
5. A method for refined risk classification of urban rail transit signaling systems according to claim 4, characterized in that, In step S2, establishing the correlation between the scenario and the risk point includes: S24, Statistical analysis of the frequency of failures at various risk points under different scenarios; S25, calculate the support and confidence between scenarios and risk points based on association rule mining algorithms; S26. Associate scenarios with risk points whose confidence level reaches a preset threshold with risk points to form a scenario-risk point association matrix.
6. The method for refined risk classification of urban rail transit signaling systems according to claim 1, characterized in that, In step S3, the probability of risk occurrence L is quantified based on the historical frequency of occurrence of the fault event corresponding to the risk point, the maintenance frequency, and the exposure frequency of the scenario. The severity of consequences C is quantified based on the degree of driving impact, equipment damage, passenger impact range, and operational interruption caused by the risk event.
7. The method for refined risk classification of urban rail transit signaling systems according to claim 1, characterized in that, In step S4, the construction of the risk transmission network includes: S41, abstract different scenarios into scenario nodes, abstract risk factors that cause risk evolution into risk factor nodes, abstract signaling system equipment into equipment nodes, and abstract accident or failure results into consequence nodes. S42, establish trigger edges between scene nodes and risk factor nodes, establish propagation edges between risk factor nodes and device nodes and between device nodes, and establish consequence edges between device nodes and consequence nodes. S43 determines the propagation probability of each side based on historical fault data and expert experience, forming a risk propagation network.
8. The method for refined risk classification of urban rail transit signaling systems according to claim 1, characterized in that, In step S4, the identification of high-risk transmission paths and key nodes includes: S44, starting from the scene node and ending at the consequence node, calculates the product of the propagation probabilities of each edge along the risk propagation path to obtain the path propagation probability; the path propagation probability is the product of the propagation probabilities of all edges along a propagation path, reflecting the likelihood of risk spreading along that path, as shown in the formula below: Where Pi is the propagation probability of the i-th edge on the path, and n is the number of edges on the path; S45, count the number of downstream node failures caused by the failure of a device node, and calculate the node impact degree; the node impact degree is the proportion of downstream node failures caused by a node failure to the total number of nodes, reflecting the criticality of the node in the propagation network, as shown in the formula below: in, N represents the number of downstream nodes that fail due to node failure, where N is the total number of nodes in the network. S46, Calculate the occurrence frequency; the occurrence frequency is the ratio of the frequency of the risk chain from the scene node to the consequence node Ci to the frequency of propagation from the scene node, as shown in the formula: Please explain the meaning of all parameters in the above formula in words here. in, For risk scenarios To the consequences The frequency of occurrence of risk chains; For risk scenarios Frequency of transmission. S47, Calculate the control efficiency; the control efficiency D is the percentage decrease in the probability of transmission after setting control measures along a certain transmission path, reflecting the effectiveness of the measures. The formula is: Where E0 is the propagation probability before the measure is taken, and E1 is the propagation probability after the measure is taken; S48. High-risk propagation paths and key risk nodes are selected based on path propagation probability, node impact, occurrence frequency, and control efficiency. In step S44, the path propagation probability is the product of the propagation probabilities of each edge on the path; in step S45, the node influence degree is the proportion of the number of downstream failed nodes caused by node failure to the total number of nodes in the network.
9. A method for refined risk classification of urban rail transit signaling systems according to claim 1, characterized in that, In step S5, the refined risk classification includes: S51, Initial classification of risk points based on risk index D; S52, Scenario correction is performed on the initial classification results by combining the correlation between scenarios and risk points; S53, combining the propagation probability of high-risk propagation paths, the node influence of key risk nodes, and the frequency of occurrence of risk chains, the risk level is comprehensively adjusted to obtain the final risk level; the final risk level is divided into any one or more levels among low risk, medium risk, high risk, and extremely high risk.
10. A method for refined risk classification of urban rail transit signaling systems according to claim 1, characterized in that, In step S6, dynamic updates include: S61, when the number of newly added fault data reaches a preset threshold or the maintenance frequency changes significantly, a data update is triggered; S62, when the scene feature parameters exceed the historical threshold or a new scene type is added, a scene update is triggered; S63, when new or replaced equipment is added to the signaling system, iterative updates of the equipment are triggered; In step S6, the dynamic update process includes: Re-collect the latest data from the fault database, maintenance work order system, and environmental monitoring platform; Recalculate the probability of risk occurrence (L), severity of consequences (C), risk index (D), and scenario-related confidence level for each risk point. Remove the associations between scenarios and risk points that are below the preset confidence threshold, add new risk points, and delete invalid risk points; The updated results are reviewed by experts and synchronized to the risk management platform and operation and maintenance management system after the review is approved.