A main grid and distribution network multi-source heterogeneous data anomaly monitoring method and related device

CN122553527APending Publication Date: 2026-08-11ZHEJIANG TAILUN POWER GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-04-30
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0007]本发明的目的在于提供一种主配网多源异构数据异常监测方法与相关装置,以解决现有技术主配网数据监测方法中对主配网异构数据适配性差、异常识别准确率低、缺乏动态调整能力的技术问题

Benefits of technology

本发明公开了一种主配网多源异构数据异常监测方法与相关装置,通过构建多源数据协同采集体系,采用分层检测架构,主网层适配稳态高频数据、配网层适配暂态数据、用户侧适配海量低频数据,提高了异常检测覆盖率,实现主配网异构数据的标准化融合;同时,通过多维特征提取结合时空关联校验,提高了异常检测准确率并降低了误报率,为调度决策提供可靠数据支撑;此外,结合拓扑关系与特征匹配实现溯源,具备较高的溯远准确率,可快速区分数据故障与设备故障,避免运维资源浪费。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122553527A_ABST
    Figure CN122553527A_ABST
Patent Text Reader

Abstract

This invention discloses a method and related device for monitoring anomalies in multi-source heterogeneous data from main grid and distribution network, belonging to the field of power system data processing technology. The method collects multi-source heterogeneous data from main grid SCADA data, distribution network FTU / DTU data, user-side metering data, and environmental monitoring data, and preprocesses this data. Based on the preprocessed multi-source heterogeneous data, it calls the corresponding hierarchical anomaly detection models at the main grid layer, distribution network layer, and user side to perform anomaly detection and output preliminary anomaly results. A spatiotemporal correlation verification mechanism is used to verify the preliminary anomaly results and determine the actual anomaly data. This invention achieves standardized fusion of heterogeneous data from main grid and distribution network by constructing a multi-source data collaborative acquisition system, improving the comprehensiveness and accuracy of data anomaly monitoring.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of power system data processing technology, and relates to a method and related device for monitoring anomalies in multi-source heterogeneous data of the main distribution network. Background Technology

[0002] With the deepening of smart grid construction, the data acquisition system of the power system has been expanded like never before. In the main grid (transmission network) and distribution network, a multi-source heterogeneous data system has been deployed, including SCADA systems, distribution terminals, smart meters, and environmental monitoring. However, current power system methods for anomaly monitoring of such multi-source heterogeneous data have several inherent defects, making it difficult to meet the requirements of smart grids for data quality and state perception accuracy. Specifically, these defects manifest in the following aspects: First, there is poor adaptability to heterogeneous data. Traditional anomaly detection methods are mostly designed for single, homogeneous data sources, using uniform algorithms and thresholds. When applied to a scenario of main and distribution network integration, they cannot effectively accommodate the significant differences in frequency domain and characteristics of data at different levels. For example, algorithms suitable for high-frequency, steady-state main network data are insensitive to low-frequency, fluctuating user-side data, leading to a large number of missed anomalies; conversely, sensitive algorithms designed for the transient characteristics of the distribution network may generate a large number of false alarms when applied to the main network. This "one-size-fits-all" approach results in insufficient anomaly detection coverage, especially for anomalies in low-frequency data such as user-side data, which are easily missed. Overall coverage may be less than 60%, creating monitoring blind spots.

[0003] Secondly, the accuracy of anomaly identification is low, and the false alarm rate is high. Existing methods typically use single threshold methods or fixed statistical algorithms to process all data, failing to fully consider the fundamental differences in physical mechanisms and time scales between steady-state anomalies in the main grid (such as slow voltage limits exceeding limits and power imbalances) and transient anomalies in the distribution network (such as short-circuit current surges and grounding faults). Using the same "ruler" to measure all data inevitably leads to poor algorithm performance under complex operating conditions, making it difficult to distinguish between real equipment failures, grid disturbances, sensor malfunctions, and communication interference. This results in a false alarm rate as high as 25%-30%, which not only increases the workload of operators but may also lead to the neglect of real risks.

[0004] Secondly, there is a lack of cross-source and cross-domain correlation verification mechanisms. Most current monitoring systems analyze data anomalies from single data sources or single monitoring points in isolation, failing to effectively utilize the inherent electrical connections and spatiotemporal correlation characteristics of the power grid. The power grid is an organic whole; anomalies in the main grid lines should be reflected in the downstream distribution network feeders and user-side data. Existing methods, lacking this spatiotemporal correlation verification, cannot verify the logical consistency of anomalies, often resulting in anomaly localization errors, with error rates exceeding 40%. For example, a localized data anomaly in the downstream distribution network might be misjudged as the source, ignoring its actual origin in changes in the upstream main grid, thus misleading dispatch decisions and fault handling directions.

[0005] Finally, the monitoring model lacks dynamic adaptability and self-optimization capabilities. The power grid's operating status changes dynamically with load variations, distributed power generation integration, and network topology adjustments; fixed detection model parameters struggle to adapt to this time-varying nature. Under complex conditions such as peak loads and drastic fluctuations in renewable energy sources, the performance of fixed-threshold monitoring methods significantly degrades, with the false negative rate potentially exceeding 15%. Furthermore, as system operating time accumulates, equipment characteristics and data patterns may slowly drift. Monitoring systems lacking online learning and parameter optimization mechanisms will experience significant long-term performance degradation, failing to meet the demands for continuous and reliable monitoring.

[0006] In summary, there is an urgent need for an anomaly monitoring method that can integrate multi-source heterogeneous data and has correlation verification and dynamic optimization capabilities to improve the data quality and status perception accuracy of the main distribution network. Summary of the Invention

[0007] The purpose of this invention is to provide a method and related device for monitoring anomalies in multi-source heterogeneous data of main distribution networks, so as to solve the technical problems of poor adaptability to heterogeneous data of main distribution networks, low accuracy of anomaly identification, and lack of dynamic adjustment capability in existing main distribution network data monitoring methods.

[0008] To achieve the above objectives, the present invention employs the following technical solution: In a first aspect, the present invention provides a method for monitoring anomalies in multi-source heterogeneous data in a main distribution network, comprising the following steps: Multi-source heterogeneous data is obtained by collecting SCADA data from the main network, FTU / DTU data from the distribution network, metering data from the user side, and environmental monitoring data. The multi-source heterogeneous data is then preprocessed. Based on the preprocessed multi-source heterogeneous data, the corresponding hierarchical anomaly detection models of the main network layer, distribution network layer and user side are called to perform anomaly detection and output preliminary anomaly results. A spatiotemporal correlation verification mechanism is used to verify the preliminary abnormal results and determine the real abnormal data.

[0009] Furthermore, the step of collecting main network SCADA data, distribution network FTU / DTU data, user-side metering data, and environmental monitoring data to obtain multi-source heterogeneous data specifically includes: On the main grid side, the SCADA system collects the 220kV and above bus voltage and line power flow; on the distribution network side, the FTU / DTU collects the 10kV line current and switch status; on the user side, the smart meter collects the 0.4kV voltage and power; and on the environmental side, the sensor collects the temperature and wind speed.

[0010] Furthermore, the preprocessing step for the multi-source heterogeneous data specifically includes: The time scale of each data source in the multi-source heterogeneous data is unified by using a GPS synchronized clock; the Z-Score standardization method is used to unify the dimensions of the multi-source heterogeneous data. Based on standardized multi-source heterogeneous data, weighted average method is used to fuse data of the same type; Kalman filtering is used to calibrate the bias of data of different types; and missing data is filled by linear interpolation or data migration from similar devices.

[0011] Furthermore, the step of calling the corresponding hierarchical anomaly detection models of the main network layer, distribution network layer, and user side based on the preprocessed multi-source heterogeneous data to perform anomaly detection and output preliminary anomaly results specifically includes: The main network layer uses the isolated forest algorithm to introduce electrical constraints, taking power conservation and voltage range as pruning conditions, and outputs anomaly confidence levels in the range of [0%, 100%]. Anomalies with a confidence level ≥ 60% are marked as preliminary anomalies. The distribution network anomaly detection adopts the LSTM-Autoencoder model, which is based on a bidirectional LSTM structure. It identifies transient anomalies through reconstruction error. When the reconstruction error is greater than the preset threshold, it is marked as a preliminary anomaly and the anomaly confidence level is output, ranging from [0% to 100%]. When the confidence level is ≥70%, it is included in the set to be verified. User-side anomaly detection uses a dynamic threshold method, setting a threshold based on a 95% confidence interval plus load offset. When an anomaly exceeds the threshold and persists for more than or equal to a preset sampling period, it is marked as a preliminary anomaly. When the confidence level is ≥50%, it is included in the set to be verified.

[0012] Furthermore, in the step of using a spatiotemporal correlation verification mechanism to verify the preliminary abnormal results and determine the real abnormal data, at least one of time consistency verification, spatial correlation verification, and cross-source consistency verification is used. The time consistency verification includes: analyzing the duration of abnormal data in the preliminary abnormal results and comparing it with historical data from the same period to remove isolated false alarms; The spatial correlation verification includes: verifying the anomaly propagation characteristics based on the power grid topology, and calculating the electrical distance between the abnormal device and the associated device; The cross-source consistency verification includes: comparing the same monitoring object from different data sources, and determining whether it is a real anomaly based on the magnitude and duration of the deviation.

[0013] Furthermore, after the step of using a spatiotemporal correlation verification mechanism to verify the preliminary abnormal results and determine the actual abnormal data, the method further includes: The system performs source tracing analysis on real abnormal data to locate the source of the anomaly and generates differentiated processing strategies based on the source tracing results; at the same time, it dynamically implements the hierarchical anomaly detection model based on abnormal cases.

[0014] Furthermore, the steps of performing source tracing analysis on real abnormal data to locate the source of the anomaly and generating differentiated processing strategies based on the source tracing results, and simultaneously dynamically implementing the hierarchical anomaly detection model according to anomaly cases, specifically include: Anomaly propagation maps are drawn based on power grid topology to determine the anomaly initiation point; the characteristics of the real anomaly data are matched with a preset fault mode library to determine the fault category. When data acquisition is abnormal, interpolation is used to correct it, or data is re-acquired and transmitted through a backup channel. When equipment fails, alarms are triggered and the monitoring frequency is increased. Collect historical anomaly cases to expand the model training set; periodically retrain the hierarchical anomaly detection models of the main network layer, distribution network layer, and user side using the training set; and dynamically adjust the model weights of each layer by optimizing the verification rules using reinforcement learning.

[0015] Secondly, the present invention provides a multi-source heterogeneous data anomaly monitoring system for main and distribution networks, comprising: The data acquisition and fusion module is used to collect SCADA data from the main network, FTU / DTU data from the distribution network, metering data from the user side, and environmental monitoring data to obtain multi-source heterogeneous data, and to preprocess the multi-source heterogeneous data. The hierarchical anomaly detection module is used to perform anomaly detection based on preprocessed multi-source heterogeneous data, and call the corresponding hierarchical anomaly detection models of the main network layer, distribution network layer and user side respectively to perform anomaly detection and output preliminary anomaly results. The correlation verification module is used to verify the preliminary abnormal results using a spatiotemporal correlation verification mechanism to determine the real abnormal data.

[0016] Thirdly, the present invention provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method for monitoring anomalies of multi-source heterogeneous data in a main distribution network as described above.

[0017] Fourthly, the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the method for monitoring anomalies in multi-source heterogeneous data in a main distribution network.

[0018] Compared with the prior art, the present invention has the following beneficial effects: This invention discloses a method and related device for monitoring anomalies in multi-source heterogeneous data in a main distribution network. By constructing a multi-source data collaborative acquisition system and adopting a hierarchical detection architecture, the main network layer is adapted to steady-state high-frequency data, the distribution network layer to transient data, and the user side to massive low-frequency data, thereby improving the anomaly detection coverage and achieving standardized fusion of heterogeneous data in the main distribution network. Simultaneously, by combining multi-dimensional feature extraction with spatiotemporal correlation verification, the accuracy of anomaly detection is improved and the false alarm rate is reduced, providing reliable data support for scheduling decisions. Furthermore, by combining topological relationships and feature matching to achieve source tracing, a high tracing accuracy is achieved, which can quickly distinguish between data faults and equipment faults, avoiding waste of operation and maintenance resources. Attached Figure Description

[0019] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 This is a flowchart of the method of the present invention; Figure 2 This is a schematic diagram of the system of the present invention; Figure 3 This is a schematic diagram of the computer device structure of the present invention. Detailed Implementation

[0021] The present invention will now be described in detail with reference to the accompanying drawings and embodiments. It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other.

[0022] The following detailed description is exemplary and intended to provide further detailed explanation of the invention. Unless otherwise specified, all technical terms used in this invention have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains. The terminology used in this invention is for the purpose of describing particular embodiments only and is not intended to limit the scope of exemplary embodiments according to the invention.

[0023] See Figure 1 This invention discloses a method for monitoring anomalies in multi-source heterogeneous data in a main distribution network, comprising the following steps: S1. Collect multi-source heterogeneous data from main network SCADA data, distribution network FTU / DTU data, user-side metering data, and environmental monitoring data. Standardize and fuse this multi-source heterogeneous data to unify data timescales, units, and formats. Specifically, this includes the following steps: Deploying multi-source data acquisition nodes: On the main grid side, the SCADA system collects 220kV and above bus voltage and line power flow at a sampling frequency of 1-10Hz to ensure the capture of grid operation trends. Line power flow is the total electrical quantity transmitted in power lines, including active power, reactive power, voltage, and current, reflecting the flow and distribution of power in transmission lines. On the distribution network side, FTU / DTU collects 10kV line current and switch status at a sampling frequency of 0.5-5Hz to adapt to the frequent faults in the distribution network. On the user side, smart meters collect 0.4kV voltage and power at a sampling frequency of 0.1-1Hz to cover the monitoring needs of a large number of users. On the environmental side, meteorological sensors are deployed near substations and line corridors to collect data such as temperature, wind speed, and rainfall at a sampling frequency of 0.1Hz to analyze the impact of external interference on grid data. All acquisition nodes transmit data through a hybrid communication method of fiber optic + wireless public network. Fiber optic is used preferentially for main grid data, while wireless transmission is used for distribution network and user-side data to ensure data real-time performance. Data standardization processing: GPS-synchronized clocks are used to unify data time stamps, and Z-Score standardization is used to unify data dimensions. Data is stored in the format of [12-bit device ID - 13-bit timestamp - 4-bit data type code - value]. For example, [220010100001-202501015103000-VLTG-230.5] indicates that the voltage of bus 01 of the 220kV substation is 230.5kV at 10:30:00 on October 15, 2025, which facilitates subsequent querying and analysis. Multi-source data fusion: Data of the same type are fused using a weighted average method. The weights of each type of data are dynamically allocated based on sensor accuracy. Data of different types are calibrated using Kalman filtering to correct deviations, such as power flow balance calibration of distribution network line current and main network outgoing current. Missing data are filled using linear interpolation or migration of data from similar equipment. Linear interpolation is used for short-term missing data, and migration of data from similar equipment is used for long-term missing data.

[0024] S2, based on preprocessed multi-source heterogeneous data, calls the corresponding hierarchical anomaly detection models for the main network layer, distribution network layer, and user side for anomaly detection. The main network layer uses an improved isolated forest algorithm to detect steady-state data anomalies, the distribution network layer uses LSTM-Autoencoder to detect transient data anomalies, and the user side uses a dynamic threshold method to detect basic data anomalies. The model outputs preliminary anomaly results. Specifically, this includes: Main network layer anomaly detection: The improved isolated forest algorithm introduces electrical constraints, using power conservation and voltage range as pruning conditions. Key data such as voltage and frequency are given high weights, with values ​​ranging from [0.6, 0.8], to improve anomaly sensitivity. For example, key data affecting power grid safety, such as voltage and frequency, are given a high weight of 0.6-0.8, while secondary data, such as switch status, are given a low weight of 0.2-0.4. This allows the algorithm to prioritize the identification of high-risk anomalies and output anomaly confidence levels ranging from [0%, 100%]. Anomalies with a confidence level ≥ 60% are marked as preliminary anomalies. Distribution network anomaly detection: Distribution network anomaly detection adopts the LSTM-Autoencoder model. Through a bidirectional LSTM structure, the input layer is the time series features of 100 consecutive sampling points, such as the rate of change and fluctuation amplitude of line current. The hidden layer is set to 3 layers with 64, 32 and 64 nodes respectively. The output layer reconstructs the input time series and identifies transient anomalies, such as short circuits and grounding, through reconstruction errors. The anomaly threshold is determined based on the ROC curve. When the reconstruction error is greater than the threshold, it is marked as a preliminary anomaly and the anomaly confidence is output, ranging from [0% to 100%]. When the confidence is ≥70%, it is included in the set to be verified. User-side anomaly detection: A dynamic threshold method is adopted, with thresholds set according to a 95% confidence interval plus load offset. For example, if the voltage is 220V ± 10% and the current is ≤ 120% of the rated value, anomalies are marked as preliminary anomalies if they exceed the threshold and continue for ≥ 3 sampling periods. If the confidence level is ≥ 50%, the anomalies are included in the set to be verified.

[0025] S3 employs a spatiotemporal correlation verification mechanism to check the temporal consistency, spatial correlation, and cross-source consistency of preliminary anomaly results, eliminating false positives and identifying genuine anomaly data. Specifically, this includes: Time consistency verification: Analyze the duration of abnormal data in the preliminary anomaly results. If the instantaneous anomaly is less than 2 sampling points, the confidence level is reduced. If there are 3 consecutive anomalies, the confidence level is increased. Compare with historical data of the same period to remove isolated false alarms. Match with the high-incidence period of the fault to increase the confidence level. Spatial correlation verification: Based on the power grid topology, verify the anomaly propagation characteristics. For example, an anomaly in the main grid line should cause a voltage drop in the downstream distribution network. Calculate the electrical distance between the abnormal equipment and the associated equipment. The impact of the anomaly decreases with distance. If it does not conform to the topology logic, it is marked as a suspicious anomaly. Cross-source consistency verification: Compare the line current of the same monitoring object from different data sources, such as SCADA and FTU. If the deviation is >5% and the duration is ≥30s, it is considered a real anomaly. If the deviation is ≤5% and the duration is <30s, it is considered a data fluctuation and false detections are eliminated.

[0026] S4 performs source analysis on real anomaly data to pinpoint the source of the anomaly (data acquisition failure / equipment failure / external interference), generates differentiated processing strategies, and dynamically optimizes the detection model parameters based on anomaly cases to achieve iterative upgrades of monitoring capabilities. Specifically, this includes: Anomaly tracing: Based on topological relationships, an anomaly propagation map is drawn to determine the starting point. Anomaly characteristics are matched with a fault mode library, which records fault categories, including sensor failure, communication interruption, and equipment overload. High-risk anomalies trigger on-site inspection and verification. Differentiated processing: When data acquisition is abnormal, interpolation is used to correct it, or data is re-acquired and transmitted through a backup channel. When equipment fails, alarms are triggered and the monitoring frequency is increased. Model optimization: Collect abnormal cases daily to expand the training set, and retrain the main network layer, distribution network layer and user side layer anomaly detection models in step S20 every 24 hours. Use reinforcement learning to optimize the verification rules and dynamically adjust the weights of each layer model. For example, increase the weight of the distribution network layer to 0.5 during periods of frequent distribution network faults.

[0027] See Figure 2 This invention discloses a multi-source heterogeneous data anomaly monitoring system for a main grid and distribution network. It includes a data acquisition and fusion module, a hierarchical anomaly detection module, and a correlation verification module. The data acquisition and fusion module constructs a multi-source data acquisition unit for the main grid and distribution network, acquiring main grid SCADA data, distribution network FTU / DTU data, user-side metering data, and environmental monitoring data to obtain multi-source heterogeneous data. It then standardizes and fuses this multi-source heterogeneous data, unifying data timescales, dimensions, and formats. The hierarchical anomaly detection module constructs hierarchical anomaly detection models for the main grid layer, distribution network layer, and user side based on the characteristics of the multi-source heterogeneous data. The main grid layer uses an improved isolated forest algorithm to detect steady-state data anomalies, the distribution network layer uses LSTM-Autoencoder to detect transient data anomalies, and the user side uses a dynamic threshold method to detect basic data anomalies. The model outputs preliminary anomaly results. The correlation verification module uses a spatiotemporal correlation verification mechanism to verify the temporal consistency, spatial correlation, and cross-source consistency of the preliminary anomaly results, eliminating false detections and determining the true anomaly data. Preferably, it also includes a source tracing and optimization module: used to perform source tracing analysis on real abnormal data, locate the source of the abnormality (data acquisition failure / equipment failure / external interference), generate differentiated processing strategies, and dynamically optimize the detection model parameters based on abnormal cases to achieve iterative upgrades of monitoring capabilities.

[0028] This invention provides a multi-source heterogeneous data anomaly monitoring system for main and distribution networks. It employs a multi-source heterogeneous data anomaly monitoring method for main and distribution networks as described in the above embodiments, and can solve the technical problems of poor adaptability to heterogeneous data in existing main and distribution network data monitoring methods, such as low anomaly identification accuracy and lack of dynamic adjustment capabilities. Compared with the prior art, the beneficial effects of the multi-source heterogeneous data anomaly monitoring system for main and distribution networks provided in this application are the same as those of the multi-source heterogeneous data anomaly monitoring method for main and distribution networks provided in the above embodiments. Furthermore, other technical features of the multi-source heterogeneous data anomaly monitoring system for main and distribution networks are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.

[0029] In one embodiment of the invention, see [link to embodiment]. Figure 3 A computer device is provided, comprising a processor and a memory. The memory stores a computer program, which includes program instructions. The processor executes the program instructions stored in the computer storage medium. The processor may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing and control core of the terminal, suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions from the computer storage medium to achieve a corresponding method flow or function. The processor described in this embodiment can be used in the operation of a method for monitoring anomalies in multi-source heterogeneous data in a main distribution network.

[0030] This invention also provides a storage medium, specifically a computer-readable storage medium (Memory), which is a memory device in a computer device used to store programs and data. It is understood that the computer-readable storage medium here can include both the built-in storage medium in the computer device and extended storage media supported by the computer device. The computer-readable storage medium provides storage space that stores the terminal's operating system. Furthermore, this storage space also stores one or more instructions suitable for loading and execution by a processor. These instructions can be one or more computer programs (including program code). It should be noted that the computer-readable storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device. The processor can load and execute one or more instructions stored in the computer-readable storage medium to implement the corresponding steps of the above-described method for monitoring anomalies in multi-source heterogeneous data in a main distribution network.

[0031] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0032] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0033] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1The function specified in one or more boxes.

[0034] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0035] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A method for monitoring abnormality of multi-source heterogeneous data in main distribution network, characterized in that, Includes the following steps: Multi-source heterogeneous data is obtained by collecting SCADA data from the main network, FTU / DTU data from the distribution network, metering data from the user side, and environmental monitoring data. The multi-source heterogeneous data is then preprocessed. Based on the preprocessed multi-source heterogeneous data, the corresponding hierarchical anomaly detection models of the main network layer, distribution network layer and user side are called to perform anomaly detection and output preliminary anomaly results. A spatiotemporal correlation verification mechanism is used to verify the preliminary abnormal results and determine the real abnormal data. 2.The main grid-connected multi-source heterogeneous data anomaly monitoring method of claim 1, wherein, The steps for obtaining multi-source heterogeneous data by collecting SCADA data from the main network, FTU / DTU data from the distribution network, user-side metering data, and environmental monitoring data specifically include: On the main grid side, the SCADA system collects the 220kV and above bus voltage and line power flow; on the distribution network side, the FTU / DTU collects the 10kV line current and switch status; on the user side, the smart meter collects the 0.4kV voltage and power; and on the environmental side, the sensor collects the temperature and wind speed. 3.The main grid-connected multi-source heterogeneous data anomaly monitoring method of claim 1, wherein, The preprocessing steps for the multi-source heterogeneous data specifically include: The time scale of each data source in the multi-source heterogeneous data is unified by using a GPS synchronized clock; the Z-Score standardization method is used to unify the dimensions of the multi-source heterogeneous data. Based on standardized multi-source heterogeneous data, weighted average method is used to fuse data of the same type; Kalman filtering is used to calibrate the bias of data of different types; and missing data is filled by linear interpolation or data migration from similar devices.

4. The main network and distribution network multi-source heterogeneous data anomaly monitoring method according to claim 1, characterized in that, The steps of using preprocessed multi-source heterogeneous data to call the corresponding hierarchical anomaly detection models at the main network layer, distribution network layer, and user side for anomaly detection and outputting preliminary anomaly results specifically include: The main network layer uses the isolated forest algorithm to introduce electrical constraints, taking power conservation and voltage range as pruning conditions, and outputs anomaly confidence levels in the range of [0%, 100%]. Anomalies with a confidence level ≥ 60% are marked as preliminary anomalies. The distribution network anomaly detection adopts the LSTM-Autoencoder model, which is based on a bidirectional LSTM structure. It identifies transient anomalies through reconstruction error. When the reconstruction error is greater than the preset threshold, it is marked as a preliminary anomaly and the anomaly confidence level is output, ranging from [0% to 100%]. When the confidence level is ≥70%, it is included in the set to be verified. User-side anomaly detection uses a dynamic threshold method, setting a threshold based on a 95% confidence interval plus load offset. When an anomaly exceeds the threshold and persists for more than or equal to a preset sampling period, it is marked as a preliminary anomaly. When the confidence level is ≥50%, it is included in the set to be verified.

5. The method of claim 1, wherein, In the step of using a spatiotemporal correlation verification mechanism to verify the preliminary abnormal results and determine the real abnormal data, at least one of time consistency verification, spatial correlation verification, and cross-source consistency verification is used. The time consistency verification includes: analyzing the duration of abnormal data in the preliminary abnormal results and comparing it with historical data from the same period to remove isolated false alarms; The spatial correlation verification includes: verifying the anomaly propagation characteristics based on the power grid topology, and calculating the electrical distance between the abnormal device and the associated device; The cross-source consistency verification includes: comparing the same monitoring object from different data sources, and determining whether it is a real anomaly based on the magnitude and duration of the deviation.

6. The main network and distribution network multi-source heterogeneous data anomaly monitoring method according to claim 1, characterized in that, After the step of using a spatiotemporal correlation verification mechanism to verify the preliminary abnormal results and determine the real abnormal data, the method further includes: The system performs source tracing analysis on real abnormal data to locate the source of the anomaly and generates differentiated processing strategies based on the source tracing results; at the same time, it dynamically implements the hierarchical anomaly detection model based on abnormal cases.

7. The main network multi-source heterogeneous data anomaly monitoring method according to claim 6, characterized in that, The process involves tracing and analyzing real abnormal data to pinpoint the source of the anomaly and generating differentiated processing strategies based on the tracing results. Simultaneously, based on the steps of the hierarchical anomaly detection model dynamically described in the abnormal cases, the specific steps include: Anomaly propagation maps are drawn based on power grid topology to determine the anomaly initiation point; the characteristics of the real anomaly data are matched with a preset fault mode library to determine the fault category. When data acquisition is abnormal, interpolation is used to correct it, or data is re-acquired and transmitted through a backup channel. When equipment fails, alarms are triggered and the monitoring frequency is increased. Collect historical anomaly cases to expand the model training set; periodically retrain the hierarchical anomaly detection models of the main network layer, distribution network layer, and user side using the training set; and dynamically adjust the model weights of each layer by optimizing the verification rules using reinforcement learning.

8. A multi-source heterogeneous data anomaly monitoring system for main and distribution networks, characterized in that, include: The data acquisition and fusion module is used to collect SCADA data from the main network, FTU / DTU data from the distribution network, metering data from the user side, and environmental monitoring data to obtain multi-source heterogeneous data, and to preprocess the multi-source heterogeneous data. The hierarchical anomaly detection module is used to perform anomaly detection based on preprocessed multi-source heterogeneous data, calling the corresponding hierarchical anomaly detection models of the main network layer, distribution network layer and user side respectively, and outputting preliminary anomaly results. The correlation verification module is used to verify the preliminary abnormal results using a spatiotemporal correlation verification mechanism to determine the real abnormal data.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method for monitoring anomalies in multi-source heterogeneous data in a main distribution network as described in any one of claims 1-7.

10. A computer-readable storage medium storing a computer program, the computer program comprising instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1 to 9. When the computer program is executed by the processor, it implements the steps of the method for monitoring anomalies in multi-source heterogeneous data in a main distribution network as described in any one of claims 1-7.