Power Quality and Electricity Theft Monitoring System and Methods for Distribution Radio Areas
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-29
- Publication Date
- 2026-08-11
AI Technical Summary
台区实际运行中,窃电行为可能会引发波形畸变而被误判为电能质量异常,电能质量异常也可能会导致计量偏差而被误判为窃电行为,因此,现有监测方式的异常判定依据片面,易出现判断偏差,难以保证异常判断的准确性
Smart Images

Figure CN122545913A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power distribution monitoring technology, and in particular to a power quality and electricity theft monitoring system and method for power distribution substations. Background Technology
[0002] Currently, low-voltage distribution substations use independent architectures for power quality monitoring and electricity theft monitoring. Power quality monitoring devices only collect and calculate indicators such as harmonics, imbalance, and voltage transients, and issue threshold alarms. Anti-theft systems rely solely on metering data such as electricity consumption, line loss, and voltage / current loss for anomaly detection. In actual operation, electricity theft may cause waveform distortion, leading to misjudgments as power quality anomalies, and vice versa. Therefore, existing monitoring methods rely on limited data for anomaly detection, are prone to bias, and cannot guarantee the accuracy of anomaly assessments. Summary of the Invention
[0003] The purpose of this invention is to provide a power quality and electricity theft monitoring system and method for distribution substations, so as to alleviate the technical problem that it is difficult to guarantee the accuracy of anomaly judgment in the prior art.
[0004] In a first aspect, the present invention provides a power quality and electricity theft monitoring system for a distribution transformer substation, comprising: a cloud platform and a smart terminal installed in the distribution transformer substation; the smart terminal is used to collect raw waveform data of three-phase electrical parameters in real time, and to extract features from the raw waveform data within each preset time window to obtain feature vectors for the corresponding time windows; the smart terminal is also used to perform anomaly screening on all feature vectors and send the abnormal feature vectors to the cloud platform; the cloud platform is used to perform power quality anomaly analysis and electricity theft identification in parallel based on the abnormal feature vectors to obtain preliminary anomaly results; the cloud platform is also used to perform bidirectional verification and joint judgment on the preliminary anomaly results according to preset cross-constraint rules to obtain the root cause and location of the anomaly source.
[0005] In an optional implementation, the smart terminal has a built-in lightweight anomaly screening model for anomaly screening of all feature vectors. Specifically, it includes: reconstructing the target feature vector using an autoencoder to obtain a reconstructed feature vector; wherein the target feature vector represents any one of the feature vectors; calculating the anomaly score of the target feature vector based on the target feature vector and the reconstructed feature vector; and determining the target feature vector as an anomaly feature vector if the anomaly score exceeds a preset threshold.
[0006] In an optional implementation, the smart terminal is also used to dynamically adjust the preset threshold based on the verification results returned by the cloud platform; if the false alarm rate exceeds the first preset value, the preset threshold is increased; if the false negative rate exceeds the second preset value, the preset threshold is decreased.
[0007] In an optional implementation, the preset cross-constraint rules include: if the initial anomaly result is a power quality anomaly, then determine whether the power quality anomaly is accompanied by load characteristics representing electricity theft; if so, then correct the root cause of the anomaly to a secondary power quality disturbance caused by electricity theft; if the initial anomaly result is electricity theft, then determine whether the electricity theft is accompanied by waveform characteristics representing a power quality event on the common side; if so, then trigger spatial correlation analysis of the anomaly feature vectors of other smart terminals in the same distribution area; if it is determined that the waveform characteristics originate from the common side, then correct the root cause of the anomaly to a metering deviation caused by a power quality event; if it is determined that the waveform characteristics originate from the user side, then maintain the initial determination of electricity theft.
[0008] In an optional implementation, the cloud platform is also used to: acquire abnormal feature vectors uploaded by multiple smart terminals within the same distribution area; perform spatiotemporal correlation analysis on the multiple abnormal feature vectors to determine the propagation path or attenuation law of the abnormal features between different terminals; and locate the feeder or user side where the abnormal source is located based on the propagation path or attenuation law.
[0009] In an optional implementation, the cloud platform is equipped with a monitoring model that performs parallel analysis of power quality anomalies and identification of electricity theft, as well as two-way verification and joint judgment.
[0010] In an optional implementation, the cloud platform is also used to: generate labeled data based on the root causes of anomalies and on-site inspection feedback data, and use the labeled data to incrementally train the monitoring model and the lightweight anomaly screening model; and send the parameters of the incrementally trained lightweight anomaly screening model to the smart terminal to update the lightweight anomaly screening model of the smart terminal.
[0011] Secondly, the present invention provides a method for monitoring power quality and electricity theft in a distribution substation, applied to the power quality and electricity theft monitoring system of any of the aforementioned embodiments, comprising: real-time acquisition of raw waveform data of three-phase electrical parameters, and feature extraction of raw waveform data within each preset time window to obtain feature vectors for the corresponding time windows; anomaly screening of all feature vectors to obtain anomaly feature vectors; parallel execution of power quality anomaly analysis and electricity theft identification based on the anomaly feature vectors to obtain preliminary anomaly results; and bidirectional verification and joint determination of the preliminary anomaly results according to preset cross-constraint rules to obtain the root cause and location of the anomaly source.
[0012] Thirdly, the present invention provides an electronic device, including a memory and a processor, wherein the memory stores a computer program that can run on the processor, and the processor executes the computer program to implement the power quality and electricity theft monitoring method for distribution substations described in the foregoing embodiments.
[0013] Fourthly, the present invention provides a computer-readable storage medium storing computer instructions, which, when executed by a processor, implement the power quality and electricity theft monitoring method for distribution substations described in the foregoing embodiments.
[0014] This invention provides a power quality and electricity theft monitoring system for distribution substations. The system completes the acquisition of raw waveforms of three-phase electrical parameters, feature extraction, and anomaly screening through a smart terminal, which can simplify the data upload and provide a reliable basis for subsequent analysis. The cloud platform performs two types of anomaly analysis in parallel based on anomaly feature vectors and uses preset cross-constraint rules to achieve bidirectional verification and joint judgment, which can accurately obtain the root cause and location of the anomaly source and improve the accuracy of anomaly judgment. Attached Figure Description
[0015] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0016] Figure 1 This is a schematic diagram of the architecture of a power quality and electricity theft monitoring system for a distribution substation, provided in an embodiment of the present invention. Figure 2 This invention provides a flowchart of an anomaly screening process for all feature vectors built into a smart terminal. Figure 3 A flowchart of a method for monitoring power quality and electricity theft in a distribution substation, provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0018] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.
[0019] The following detailed description of some embodiments of the present invention is provided in conjunction with the accompanying drawings. Unless otherwise specified, the following embodiments and features can be combined with each other.
[0020] Example 1 This invention provides a power quality and electricity theft monitoring system for distribution substations, such as... Figure 1 As shown, the system specifically includes: a cloud platform 10 and a smart terminal 20 installed in the distribution radio area.
[0021] The intelligent terminal is used to collect raw waveform data of three-phase electrical parameters in real time, and extract features from the raw waveform data within each preset time window to obtain the feature vector of the corresponding time window.
[0022] The monitoring system provided in this embodiment of the invention consists of a cloud platform and intelligent terminals deployed at the distribution substation site. Specifically, intelligent terminals are installed in the low-voltage side outgoing cabinets of the transformer and in each branch feeder cabinet. Each terminal is connected to the three-phase circuit through a high-precision voltage and current transformer, and has the synchronous sampling capability of 512 points per cycle (exemplary value), with a sampling rate of up to 25.6kHz (exemplary value). The terminal has a built-in edge computing chip, which can perform waveform feature extraction and anomaly feature screening. All terminals are connected to the cloud platform through a remote communication module (such as 5G).
[0023] During system operation, the intelligent terminal continuously acquires the three-phase voltage and current values in the power supply circuit of the transformer substation through a high sampling rate, thereby obtaining raw waveform data reflecting the actual operating status of the substation. Based on this, the intelligent terminal performs feature extraction on the raw waveform data within each preset time window. This feature extraction aims to transform the high-dimensional raw waveform data into low-dimensional feature vectors, and the feature vectors are used to characterize the core attributes of power quality and load consumption behavior within that time window, such as time-domain waveform morphology, frequency-domain harmonic distribution, and load dynamic characteristics.
[0024] As an optional implementation, the feature vector includes: time-domain features, frequency-domain features, and load features. The time-domain features include: RMS voltage value, RMS current value, crest factor (peak / RMS), voltage sag / rise depth, and waveform distortion. The frequency-domain features include: fundamental amplitude, 2nd to 50th harmonic amplitude, total harmonic distortion (THD), and interharmonic content calculated using lightweight FFT. The load features include: slope of the current waveform near the zero-crossing point, phase angle deviation, and three-phase current imbalance.
[0025] Optionally, before performing feature extraction on the raw waveform data within a preset time window (e.g., 1 second), the preprocessing unit built into the terminal first normalizes the raw sampled values and then performs digital filtering (e.g., first-order / second-order low-pass filtering) to filter out DC offset and high-frequency noise introduced by the sensor. Finally, the preprocessed clean waveform data is sent to the feature extraction unit.
[0026] The smart terminal is also used to filter out anomalies in all feature vectors and send the abnormal feature vectors to the cloud platform.
[0027] After obtaining the feature vectors corresponding to each time window, the smart terminal further performs anomaly assessment on each feature vector to determine whether the corresponding waveform data falls within the normal range. Based on this assessment, the smart terminal only sends abnormal feature vectors to the cloud platform, while feature vectors determined to be normal can be directly discarded, eliminating the need for uploading and effectively reducing data communication volume and cloud storage pressure.
[0028] The cloud platform is used to perform power quality anomaly analysis and electricity theft identification in parallel based on anomaly feature vectors, and obtain preliminary anomaly results.
[0029] Specifically, the cloud platform collects feature vectors corresponding to various anomalies in advance, and uses a large number of samples to train its built-in anomaly classification model, so that the cloud platform can output preliminary anomaly results based on anomaly feature vectors.
[0030] After receiving the abnormal feature vector from the smart terminal, the cloud platform first performs two analysis tasks in parallel based on the abnormal feature vector: the first is power quality anomaly analysis, used to identify whether there are power quality events such as excessive harmonics, voltage sags and dips, and three-phase imbalance; the second is electricity theft behavior identification, used to identify whether there are abnormal electricity consumption behaviors such as half-wave electricity theft, current shunting electricity theft, and meter circumvention theft. Based on this, the monitoring system can simultaneously obtain the power quality analysis results and electricity theft behavior analysis results for the same abnormal feature vector, and use these two results together as the preliminary anomaly result.
[0031] The power quality analysis results include at least one of the following: voltage sag, voltage rise, excessive harmonics (covering harmonics from 2nd to 50th), excessive interharmonics, flicker, and three-phase imbalance. It should be noted that when accurately classifying anomalies, the cloud platform can further identify equipment fault anomalies (transformer anomalies such as overload and excitation anomalies, line anomalies such as poor contact and leakage, instrument transformer anomalies such as excessive error and open circuit), load anomalies (sudden load changes, illegal load access (such as unauthorized use of high-power equipment), and load imbalance), and other anomalies (sensor failures, terminal sampling anomalies, and false anomalies caused by communication interference). The above classification results can serve as auxiliary information for determining the root cause of anomalies.
[0032] The analysis results of electricity theft behavior include one of the following: half-wave electricity theft (thyristor voltage regulation type), shunt electricity theft (illegal wiring type), meter bypassing electricity theft (skipping the electricity meter), reverse wiring electricity theft (meter reversal), voltage reduction electricity theft (series resistor), and new intelligent electricity theft (PLC controlled voltage regulation).
[0033] The cloud platform is also used to perform bidirectional verification and joint judgment on preliminary anomaly results based on preset cross-constraint rules, so as to obtain the root cause and location of the anomaly.
[0034] After obtaining preliminary anomaly results, the cloud platform needs to further verify and jointly determine these results based on preset cross-constraint rules. In this embodiment of the invention, the core idea of the cross-constraint rules is that power quality anomalies and electricity theft may have mutual interference or causal relationships in terms of waveform characteristics. Therefore, the cloud platform cross-verifies the correlation between power quality analysis results and electricity theft identification results to mutually verify or correct the preliminary anomaly results. Finally, the cloud platform outputs the root cause of the anomaly and the location of the anomaly source after verification and joint determination, achieving accurate diagnosis of abnormal events in the distribution transformer area.
[0035] This invention provides a power quality and electricity theft monitoring system for distribution substations. The system uses a smart terminal to collect raw waveforms of three-phase electrical parameters, extract features, and screen anomalies. It can simplify the data upload and provide a reliable basis for subsequent analysis. The cloud platform performs two types of anomaly analysis in parallel based on anomaly feature vectors and uses preset cross-constraint rules to achieve bidirectional verification and joint judgment. It can accurately obtain the root cause and location of the anomaly source, improving the accuracy of anomaly judgment.
[0036] In one optional implementation, the smart terminal has a built-in lightweight anomaly screening model for anomaly screening of all feature vectors, such as... Figure 2 As shown, the specific steps include the following: Step S102: The target feature vector is reconstructed using an autoencoder to obtain the reconstructed feature vector.
[0037] Here, the target feature vector represents any one of the feature vectors.
[0038] Specifically, the autoencoder inside the lightweight anomaly screening model relies on the data processing logic of encoding compression and decoding reconstruction to perform feature compression and reconstruction on the input target feature vector, and finally generate a reconstructed feature vector that is consistent with the input dimension.
[0039] Let the target feature vector be 'n' represents the number of feature vector dimensions, corresponding to electrical operation feature dimensions in the time domain, frequency domain, etc. After the autoencoder is pre-trained on a large number of normal operation samples (with normal electrical feature distribution) in the transformer area, the feature dimension is compressed through the encoding layer and the feature distribution is restored through the decoding layer. Finally, the output is a reconstructed feature vector with dimensions completely consistent with the input. .
[0040] Step S104: Calculate the anomaly score of the target feature vector based on the target feature vector and the reconstructed feature vector.
[0041] To avoid misjudgment due to a single feature bias, this embodiment of the invention uses a weighted fusion deviation method to calculate the anomaly score, taking into account the discrimination weights of core electrical features and secondary electrical features. Specifically, the formula for calculating the anomaly score is as follows: ,in, Let represent the weight coefficients of the i-th feature, and , This represents the value of the i-th dimension of the target feature vector. This represents the value of the i-th dimension of the reconstructed feature vector. Clearly, the anomaly score objectively reflects the degree of deviation of the current electrical characteristics from the normal electrical characteristics; the higher the anomaly score, the more significantly the current waveform characteristics deviate from normal operating patterns.
[0042] Optionally, higher weights (0.15-0.2) are assigned to key characteristics such as voltage sags / droops and excessive harmonics (core characteristics affecting the safe operation of distribution transformer areas), while lower weights (0.03-0.05) are assigned to secondary characteristics such as phase angle deviation. This scoring method can better meet the needs of anomaly detection in distribution transformer areas and reduce false alarms.
[0043] Step S106: If the abnormal score exceeds the preset threshold, the target feature vector is determined to be an abnormal feature vector.
[0044] Specifically, the smart terminal pre-stores preset thresholds T for anomaly detection adapted to different operating scenarios in different transformer substations. After calculating the anomaly score S using the aforementioned weighted fusion deviation formula, it executes threshold comparison and judgment logic. When the calculated anomaly score S > T, it indicates that the electrical operating state corresponding to this set of target feature vectors deviates significantly from the normal operating pattern, and it is judged as an abnormal feature vector. When the anomaly score S ≤ T, it is judged as a normal feature vector, directly discarded, and not transmitted further; only the filtered abnormal feature vectors are uploaded to the cloud platform.
[0045] Optionally, in the initial stage of system deployment, based on the normal operation data of the transformer area in the previous 72 hours (without abnormal waveform characteristics collected by the terminal), the abnormal score of all normal samples is calculated, and 1.2 times the maximum score of normal samples is taken as the initial threshold T0 (for example: if the maximum score of normal samples is 0.08, the initial threshold T0 = 0.096) to ensure that normal data in the initial stage is not misjudged as abnormal.
[0046] In one optional implementation, the smart terminal is further configured to dynamically adjust the preset threshold based on the verification results returned by the cloud platform; if the false alarm rate exceeds a first preset value, the preset threshold is increased; if the false negative rate exceeds a second preset value, the preset threshold is decreased.
[0047] In this embodiment of the invention, the smart terminal continuously receives on-site anomaly verification feedback results from the cloud platform, and counts the number of false alarms and missed detections generated by data filtering within a fixed statistical period (e.g., hourly, daily, weekly), thereby dynamically optimizing the preset threshold for anomaly judgment.
[0048] A first preset value α and a second preset value β are set. The actual false alarm rate is P1 and the false negative rate is P2 within the statistical period. When P1 > α, it indicates that the current threshold setting is too low, which may easily misjudge normal electrical characteristics as abnormalities. The intelligent terminal automatically increases the preset threshold T to narrow the range of abnormality judgment. When P2 > β, it indicates that the current threshold setting is too high, which may easily miss hidden electrical abnormalities. The intelligent terminal automatically decreases the preset threshold T to expand the coverage of abnormality identification. This achieves adaptive adjustment of the threshold according to the actual on-site operating status, further optimizing the accuracy of abnormality screening based on weighted fusion deviation.
[0049] This invention does not specifically limit the magnitude of threshold adjustment, but to avoid excessive threshold fluctuations, upper and lower limits are set: the lower limit is not lower than 0.8 times the initial threshold, and the upper limit is not higher than 1.5 times the initial threshold, to ensure the stability and rationality of threshold adjustment.
[0050] Optionally, the dynamic adjustment of the preset threshold also includes: if there is no abnormal confirmation in the past 24 hours (no real abnormality reported by the cloud) and the average score of normal samples decreases, the threshold will be lowered by 5% (to avoid missed judgment); if there is a sudden change in the load in the distribution area (such as the addition of large charging piles or industrial loads), the terminal will simultaneously collect the normal data after the change, recalculate the distribution of normal sample scores, and adjust the threshold to 1.2 times the new maximum value of normal samples.
[0051] To avoid errors in judgment caused by interference between power quality issues and electricity theft, and to ensure that anomaly assessment results better reflect the actual operating conditions of the transformer substation, in one optional implementation, preset cross-constraint rules include: If the initial anomaly result is a power quality anomaly, then determine whether the power quality anomaly is accompanied by load characteristics that characterize electricity theft. If so, then correct the root cause of the anomaly to a secondary power quality disturbance caused by electricity theft.
[0052] Specifically, when the cloud platform's preliminary anomaly result determines that there is a power quality anomaly in the current distribution area, the system will not directly pinpoint the ultimate cause of the anomaly. Instead, it will further retrieve the load characteristic information contained within the anomaly feature vector to verify whether the power quality anomaly is accompanied by load change characteristics consistent with the patterns of electricity theft. Once load characteristics corresponding to electricity theft are detected, it indicates that the power quality distortion is not caused by fluctuations in the grid's own operating conditions, but rather indirectly induced by illegal electricity use. The initial judgment result will then be revised, and the root cause of the anomaly will be classified as a secondary power quality disturbance caused by electricity theft.
[0053] If the initial anomaly result indicates electricity theft, it is determined whether the electricity theft is accompanied by waveform characteristics that characterize a power quality event on the public side. If so, spatial correlation analysis is triggered on the abnormal feature vectors of other smart terminals in the same distribution area. If it is determined that the waveform characteristics originate from the public side, the root cause of the anomaly is corrected to a metering deviation caused by a power quality event. If it is determined that the waveform characteristics originate from the user side, the initial determination of electricity theft is maintained.
[0054] Specifically, when the cloud platform's preliminary anomaly result determines that electricity theft has occurred in the current distribution area, the system further initiates a correlation feature verification process. This process specifically identifies whether waveform feature data corresponding to the suspected electricity theft behavior exists that reflects a sudden anomaly in the power quality of the power grid's public side. If a matching waveform feature related to a power quality event on the public side is detected, the system immediately initiates a cross-terminal collaborative analysis mechanism. This mechanism retrieves the anomaly feature vectors uploaded by other smart terminals within the same distribution area to conduct spatial correlation data analysis across the entire distribution area.
[0055] After completing the spatial correlation analysis of multi-terminal data in the distribution area, the system distinguishes the source of the anomaly based on information such as the range of synchronous occurrence of characteristic data and the trend of fluctuation transmission. Specifically, if it is determined that the abnormal waveform characteristics are prevalent in the public power supply area of the distribution area (e.g., exceeding a specified percentage), then the source of the anomaly is determined to be from the public side of the power grid. This proves that the deviation in the metering data is caused by the abnormal power quality of the public power grid, and not by the user's active violation of electricity use. In this case, the root cause of the anomaly is revised and identified as a power quality event causing the electricity metering deviation. However, if spatial correlation analysis confirms that the relevant abnormal characteristics are only concentrated in a single user-side area, and there is no large-scale synchronous abnormality in the distribution area, then grid-side interference factors are excluded, and the preliminary conclusion of the previous judgment that user electricity theft exists is retained.
[0056] As an optional implementation, the specified percentage can be set to 50% of the total number of smart terminals in the same area. That is, when more than 50% of the smart terminals detect the same abnormal waveform feature, it is determined that the waveform feature originates from the public side; otherwise, it is determined that it originates from the user side.
[0057] In one alternative implementation, the cloud platform is also used to perform the following steps: Step S201: Obtain the abnormal feature vectors uploaded by multiple smart terminals within the same area.
[0058] Step S202: Perform spatiotemporal correlation analysis on multiple abnormal feature vectors to determine the propagation path or attenuation law of abnormal features between different terminals.
[0059] Step S203: Based on the propagation path or attenuation law, locate the feeder or user side where the anomaly source is located.
[0060] As described above, several smart terminals are deployed within the distribution transformer area. Different terminals correspond to different feeders or different power monitoring nodes. Each terminal can independently collect and upload abnormal feature vectors generated within its jurisdiction. The cloud platform centrally collects and aggregates the abnormal feature vectors reported by all smart terminals within the same distribution transformer area, thereby integrating them to form an abnormal feature dataset covering the entire transformer area, providing complete data support for subsequent correlation analysis.
[0061] Specifically, after aggregating abnormal feature vectors uploaded from multiple terminals, the cloud platform performs spatiotemporal correlation analysis on all abnormal feature vectors. The temporal dimension is used to compare the sequence of occurrence of abnormal features from different terminals, the duration of the anomaly, and the nodes of feature mutation. The spatial dimension is used to comprehensively characterize the dynamic changes of abnormal signals in the distribution network by combining the deployment location of each smart terminal in the distribution topology and the connection relationships between upstream and downstream feeders. Through spatiotemporal coupling analysis, the cloud platform can accurately capture the changing patterns of abnormal features as they are transmitted through power lines, clarify the transmission order of abnormal features between various smart terminals, identify a clear anomaly propagation path, and quantify the attenuation patterns of abnormal waveforms during line transmission, such as amplitude attenuation and distortion weakening.
[0062] In a power distribution topology, abnormal signals typically propagate outwards from the source, with higher distortion and more pronounced signal amplitude closer to the source. Conversely, the signal weakens and attenuates further from the source due to line impedance and electrical equipment damping. Based on these electrical propagation characteristics, the cloud platform uses reverse engineering to determine the origin of the anomaly, combining multi-terminal timing differences with spatial topology. This allows for precise identification of whether the anomaly source is on the common feeder side or an independent user side, enabling hierarchical and refined source tracing of anomalies within the distribution transformer area.
[0063] In one alternative implementation, the cloud platform is equipped with a monitoring model that performs power quality anomaly analysis and electricity theft identification in parallel, as well as two-way verification and joint determination.
[0064] Specifically, the cloud platform integrates power quality analysis, electricity theft identification, and cross-constraint judgment logic into the same monitoring model. After receiving the abnormal feature vector uploaded by the smart terminal, it simultaneously starts the power quality anomaly analysis process and the electricity theft identification process based on the internal parallel inference architecture. It extracts distortion features suitable for power quality evaluation and electricity consumption anomaly features suitable for electricity theft identification, respectively. Under the premise of non-interference, it outputs two types of analysis results in parallel (that is, the above-mentioned preliminary anomaly results), effectively shortening the judgment time caused by serial analysis and improving the overall processing efficiency of cloud anomaly identification.
[0065] After generating preliminary anomaly results, the monitoring model continues to invoke its internally preset judgment logic to complete the bidirectional verification and joint judgment of the preliminary anomaly results. Specifically, the monitoring model compares and verifies the two parallel output preliminary anomaly results based on the built-in cross-constraint logic, eliminates abnormal interference factors by combining the electrical operation logic of the transformer area, comprehensively judges to obtain a unique and accurate root cause of the anomaly, and matches the spatial analysis results to pinpoint the location of the anomaly source.
[0066] In one alternative implementation, the cloud platform is also used for: Label data is generated based on the root causes of anomalies and feedback data from on-site inspections. The label data is then used to incrementally train the monitoring model and the lightweight anomaly screening model. The parameters of the incrementally trained lightweight anomaly screening model are then sent to the smart terminal to update the lightweight anomaly screening model on the smart terminal.
[0067] Specifically, after the cloud platform completes the anomaly root cause determination and pushes the analysis results to the operations and maintenance personnel, it further receives feedback data from on-site inspections. On-site inspection feedback data includes: the verification and confirmation results of the anomaly events by the operations and maintenance personnel (whether the anomaly is real), the effectiveness of the governance measures, and feedback on missed detections, among other practical information. The cloud platform correlates and integrates the previously analyzed anomaly root causes with the on-site inspection feedback data to form labeled data with authenticity annotations. This labeled data can indicate the true anomaly type and root cause corresponding to a certain anomaly feature vector, such as "confirmed as half-wave electricity theft" or "confirmed as harmonic exceedance of a certain feeder," thereby providing supervisory signals for subsequent model training.
[0068] Optionally, the tags include: successful case tags, misjudged case tags, missed case tags, and novel anomaly case tags. A successful case tag indicates a case where the cloud platform determined the anomaly type, root cause, and source to be correct, which was verified by on-site inspection / management, and the anomaly was eliminated after management; this case is labeled "Correct Case" (tag: anomaly type + root cause + "Correct"); for example: "Harmonic exceedance + charging pile cluster + Correct". A misjudged case tag indicates a case where the cloud platform determined it to be an anomaly, but on-site inspection confirmed no anomaly (e.g., a false anomaly caused by terminal sampling interference); this case is labeled "Misjudged Case" (tag: anomaly type + "Misjudged" + interference cause); for example: "Voltage sag + Misjudgment + Communication interference". A missed case tag indicates a case where anomalies were found on-site, but were not detected by the terminal or analyzed by the cloud platform; supplementary collection of characteristic data for this anomaly is required, and this case is labeled "Misjudged Case" (tag: anomaly type + root cause + "Misjudged"); for example: "Diverting electricity for theft + Unauthorized wiring + Missed detection". The "novel anomaly case" label indicates a new type of anomaly discovered on-site (such as: new type of smart electricity theft, new type of harmonic source). Its characteristic data is collected and labeled as "novel case" (label: anomaly type + root cause + "novel").
[0069] Next, correct cases are added as positive samples to the model training set to strengthen the model's mapping relationship between this type of feature and root cause (increasing the weight of this type of feature). This allows the model to determine the anomaly type and root cause more quickly and accurately when encountering similar features in the future. The feature data of misjudged cases are added as negative samples to the training set to optimize the model's feature recognition logic, reduce the weight of these interfering features, and adjust the adaptive algorithm for the anomaly score threshold to avoid similar misjudgments in the future. For missed cases (e.g., missed detection of electricity theft by diverting current): the reasons for missed detection are analyzed (e.g., incomplete terminal feature extraction, excessively high anomaly screening threshold). The lightweight feature extraction model for the terminal is optimized, key features of missed cases are added (e.g., current imbalance features of electricity theft by diverting current), and the adaptive logic for the anomaly screening threshold is adjusted to ensure that similar anomalies can be filtered out by the terminal in the future. Feature data of new types of cases are added to the model training set to expand the model's anomaly recognition range. The model is trained to learn the features and root causes of new anomalies, and the "anomaly-root cause feature library" built into the cloud platform is updated, enabling the model to identify new anomalies.
[0070] The cloud platform uses the generated labeled data to incrementally train the monitoring model. Incremental training refers to further optimizing and adjusting the model parameters based on the existing pre-trained model using newly added labeled data, rather than retraining from scratch. Through incremental training, the monitoring model can continuously learn new abnormal waveform features, root cause analysis logic, and application scenarios of cross-constraint rules, thereby improving its accuracy in identifying various abnormal events and the precision in root cause localization.
[0071] Due to the limited computing resources and storage space of smart terminals, this lightweight anomaly screening model typically employs a lightweight neural network architecture. The cloud platform also uses labeled data for incremental training of this lightweight anomaly screening model. After incremental training, it extracts the updated model parameters (such as the weights and biases of the neural network) and sends these parameters to the corresponding smart terminals via remote communication methods (such as 5G or fiber optic networks). Upon receiving the parameters, the smart terminal loads and replaces the original model parameters, thus completing the online update of the local lightweight anomaly screening model. Since the model has learned the new distributions of normal and abnormal waveform features, incremental training can improve the accuracy and sensitivity of anomaly screening on the terminal side, reducing missed and false positives.
[0072] The incremental training process described above forms a closed-loop iterative mechanism for edge-cloud collaboration. The intelligent terminal uses the updated model to screen for anomalies and uploads the anomaly feature vectors to the cloud platform. The cloud platform analyzes and determines the root causes based on this data and generates labeled data based on on-site inspection feedback. The cloud platform then uses the labeled data to incrementally train the monitoring model and the lightweight anomaly screening model. Finally, the optimized lightweight model parameters are distributed to the terminal, forming a complete closed loop of "data collection - cloud analysis - on-site feedback - model optimization - terminal update." With accumulated runtime and continuously enriched data, the system's overall recognition capability and accuracy will continue to improve, achieving adaptive capabilities to new anomalies and complex scenarios.
[0073] Example 2 This invention also provides a method for monitoring power quality and electricity theft in a distribution substation. This method is mainly applied to the power quality and electricity theft monitoring system provided in Embodiment 1 above. The following is a detailed description of the power quality and electricity theft monitoring method for a distribution substation provided in this invention.
[0074] Figure 3 This is a flowchart of a method for monitoring power quality and electricity theft in a distribution substation, as provided in an embodiment of the present invention. Figure 3 As shown, the method specifically includes the following steps: Step S301: Real-time acquisition of raw waveform data of three-phase electrical parameters, and feature extraction of raw waveform data within each preset time window to obtain feature vectors for the corresponding time windows.
[0075] Step S302: Perform anomaly screening on all feature vectors to obtain abnormal feature vectors.
[0076] Step S303: Based on the abnormal feature vector, perform power quality anomaly analysis and electricity theft behavior identification in parallel to obtain preliminary anomaly results.
[0077] Step S304: Perform bidirectional verification and joint judgment on the preliminary anomaly results according to the preset cross-constraint rules to obtain the root cause and location of the anomaly source.
[0078] The workflow and principle of the power quality and electricity theft monitoring system for distribution substations have been described in detail above, and will not be repeated here. Please refer to the content described in Example 1 for details.
[0079] Example 3 See Figure 4This invention provides an electronic device, which includes a processor 60, a memory 61, a bus 62, and a communication interface 63. The processor 60, the communication interface 63, and the memory 61 are connected via the bus 62. The processor 60 is used to execute executable modules, such as computer programs, stored in the memory 61.
[0080] The memory 61 may include high-speed random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Communication between this system network element and at least one other network element is achieved through at least one communication interface 63 (which can be wired or wireless), such as the Internet, wide area network, local area network, metropolitan area network, etc.
[0081] Bus 62 can be an ISA bus, PCI bus, or EISA bus, etc. The bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 4 The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.
[0082] The memory 61 is used to store programs. After receiving an execution instruction, the processor 60 executes the program. The method executed by the apparatus defined by the process disclosed in any of the foregoing embodiments of the present invention can be applied to the processor 60 or implemented by the processor 60.
[0083] Processor 60 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of processor 60 or by instructions in software form. Processor 60 can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this invention. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this invention can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 61. Processor 60 reads the information in memory 61 and, in conjunction with its hardware, completes the steps of the above method.
[0084] The computer program product of the power quality and electricity theft monitoring system and method for distribution substations provided in this embodiment of the invention includes a computer-readable storage medium storing non-volatile program code executable by a processor. The instructions included in the program code can be used to execute the methods described in the preceding method embodiments. For specific implementation, please refer to the method embodiments, which will not be repeated here.
[0085] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0086] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0087] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0088] In the description of this invention, it should be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings, or the orientation or positional relationship commonly used when the product of this invention is in use. They are only for the convenience of describing this invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of this invention. In addition, the terms "first," "second," "third," etc., are only used to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0089] Furthermore, terms such as "horizontal," "vertical," and "sag" do not imply that components must be absolutely horizontal or suspended, but rather that they can be slightly tilted. For example, "horizontal" simply means that its direction is more horizontal relative to "vertical," and does not mean that the structure must be completely horizontal, but can be slightly tilted.
[0090] In the description of this invention, it should also be noted that, unless otherwise explicitly specified and limited, the terms "set," "install," "connect," and "link" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.
[0091] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A power quality and electricity theft monitoring system for a distribution substation, characterized in that, include: Cloud platform and smart terminals installed in the distribution radio area; The intelligent terminal is used to collect raw waveform data of three-phase electrical parameters in real time, and to extract features from the raw waveform data within each preset time window to obtain the feature vector of the corresponding time window. The smart terminal is also used to perform anomaly screening on all feature vectors and send the abnormal feature vectors to the cloud platform. The cloud platform is used to perform power quality anomaly analysis and electricity theft behavior identification in parallel based on the anomaly feature vector, and obtain preliminary anomaly results; The cloud platform is also used to perform bidirectional verification and joint judgment on the preliminary anomaly results according to preset cross-constraint rules, so as to obtain the root cause and location of the anomaly source.
2. The power quality and electricity theft monitoring system for distribution substations according to claim 1, characterized in that, The smart terminal has a built-in lightweight anomaly screening model for screening all feature vectors for anomalies, specifically including: The target feature vector is reconstructed using an autoencoder to obtain a reconstructed feature vector; wherein the target feature vector represents any one of the all feature vectors. Based on the target feature vector and the reconstructed feature vector, calculate the anomaly score of the target feature vector; If the abnormal score exceeds a preset threshold, the target feature vector is determined to be an abnormal feature vector.
3. The power quality and electricity theft monitoring system for distribution substations according to claim 2, characterized in that, The smart terminal is also used to dynamically adjust the preset threshold based on the verification result returned by the cloud platform; If the false alarm rate exceeds the first preset value, the preset threshold is increased. If the false negative rate exceeds the second preset value, the preset threshold will be lowered.
4. The power quality and electricity theft monitoring system for distribution substations according to claim 1, characterized in that, The preset cross constraint rules include: If the preliminary abnormal result is a power quality abnormality, then determine whether the power quality abnormality is accompanied by load characteristics that characterize electricity theft. If so, then correct the root cause of the abnormality to a secondary power quality disturbance caused by electricity theft. If the preliminary abnormal result is electricity theft, it is determined whether the electricity theft is accompanied by waveform features that characterize a power quality event on the public side; if so, spatial correlation analysis is triggered on the abnormal feature vectors of other smart terminals in the same distribution area; if it is determined that the waveform features originate from the public side, the abnormal root cause is corrected to a metering deviation caused by a power quality event; if it is determined that the waveform features originate from the user side, the preliminary determination of electricity theft is maintained.
5. The power quality and electricity theft monitoring system for distribution substations according to claim 1, characterized in that, The cloud platform is also used for: Obtain abnormal feature vectors uploaded by multiple smart terminals within the same area; Spatiotemporal correlation analysis is performed on multiple abnormal feature vectors to determine the propagation path or attenuation law of abnormal features between different terminals; Based on the propagation path or attenuation pattern, locate the feeder or user side where the anomaly source is located.
6. The power quality and electricity theft monitoring system for distribution substations according to claim 2, characterized in that, The cloud platform is equipped with a monitoring model, which is used to perform power quality anomaly analysis and electricity theft identification in parallel, as well as the two-way verification and joint judgment.
7. The power quality and electricity theft monitoring system for distribution substations according to claim 6, characterized in that, The cloud platform is also used for: Label data is generated based on the root causes of the anomalies and the on-site inspection feedback data, and the label data is used to incrementally train the monitoring model and the lightweight anomaly screening model. The parameters of the incrementally trained lightweight anomaly screening model are sent to the smart terminal to update the lightweight anomaly screening model of the smart terminal.
8. A method for monitoring power quality and electricity theft in a distribution substation, characterized in that, The power quality and electricity theft monitoring system applied to any one of claims 1-7 includes: The raw waveform data of the three-phase electrical parameters are collected in real time, and the features of the raw waveform data in each preset time window are extracted to obtain the feature vector of the corresponding time window. Anomaly screening is performed on all feature vectors to obtain anomalous feature vectors; Based on the aforementioned abnormal feature vectors, power quality anomaly analysis and electricity theft behavior identification are performed in parallel to obtain preliminary anomaly results; The preliminary anomaly results are bidirectionally verified and jointly determined according to the preset cross-constraint rules to obtain the root cause and location of the anomaly.
9. An electronic device comprising a memory and a processor, wherein the memory stores a computer program executable on the processor, characterized in that, When the processor executes the computer program, it implements the power quality and electricity theft monitoring method for distribution substations as described in claim 8.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, which, when executed by a processor, implement the power quality and electricity theft monitoring method for distribution substations as described in claim 8.