A method, device, electronic equipment, and storage medium for monitoring timing anomalies in power distribution communication networks.

CN122570547APending Publication Date: 2026-08-14POWER DISPATCHING CONTROL CENT OF GUANGDONG POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-29
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

[0004]本发明实施例提供一种配电通信网时序异常监测方法、装置、电子设备及存储介质,能够解决现有技术中对时序数据的正常规律性波动误报率高、对复杂结构性异常漏报严重且监测结果缺乏直观溯源证据的问题

Benefits of technology

本发明实施例提供一种配电通信网时序异常监测方法、装置、电子设备及存储介质。所述方法获取配电通信网待监测对象的实时往返时延序列流;截取预设查询窗口内的数据并进行周期映射,确定查询相位;依据查询相位从正常序列知识库中筛选参考条目,构建相位对齐候选集;对查询窗口数据进行线图渲染及多模态特征提取,并计算与各参考条目的特征相似度,筛选得到正常对照证据;基于查询线图进行异常类型初步诊断,并从异常序列知识库中检索异常先例证据;将查询线图、参考线图及先例线图拼接生成多模态对比证据图像;将所述图像与结构化提示词输入预设的多模态大语言模型,输出时序异常监测结果。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122570547A_ABST
    Figure CN122570547A_ABST
Patent Text Reader

Abstract

This invention discloses a method, device, electronic equipment, and storage medium for monitoring timing anomalies in power distribution communication networks, belonging to the technical field of timing anomaly monitoring in power distribution communication networks. The method includes: acquiring the real-time round-trip delay sequence stream of the object to be monitored in the power distribution communication network; extracting query window data and performing periodic mapping to determine the query phase; selecting reference entries from a normal sequence knowledge base based on the query phase, and determining normal control evidence based on feature similarity; diagnosing suspected anomaly types based on the query window data, and retrieving anomaly precedent evidence from the anomaly sequence knowledge base; and concatenating the query line graph, reference line graph, and precedent line graph and inputting them into a multimodal large language model to output the timing anomaly monitoring results. Therefore, by implementing this invention, the problems of high false alarm rates for normal regular fluctuations in timing data, serious underreporting of complex structural anomalies, and lack of intuitive traceability evidence in the monitoring results of existing technologies can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of timing anomaly monitoring technology in power distribution communication networks, specifically to a method, device, electronic equipment, and storage medium for timing anomaly monitoring in power distribution communication networks. Background Technology

[0002] With the advancement of new power system construction, the distribution communication network, as the underlying foundation for carrying massive monitoring and control services, directly affects the safety and stability of the power grid. In the daily operation and maintenance of the distribution communication network, key status indicators such as link round-trip delay exhibit typical time-series characteristics. Accurate anomaly monitoring of time-series data is an important prerequisite for achieving proactive network defense and ensuring the continuity of communication services.

[0003] Current methods for monitoring timing anomalies in power distribution communication networks primarily rely on single numerical thresholds or local sliding window models. In practical applications, these methods commonly suffer from high false alarm rates for normal, regular fluctuations and a lack of reliable evidence for anomaly identification. The reasons for false alarms and insufficient evidence lie in the fact that existing technologies typically perform isolated one-dimensional feature analysis on the captured time-period data, ignoring the inherent cross-cycle rhythms of network operation. They fail to introduce historical normal operating baselines for comparison and investigation under the same operating phase. Furthermore, existing methods lack the ability to transform monotonous timing signals into intuitive visual morphological features. When faced with complex communication network anomalies, they cannot combine real historical anomalies for in-depth multimodal feature comparison. This results in the monitoring process not only failing to capture subtle temporal structural variations but also only outputting weak over-limit alarm labels. There is a lack of an analytical mechanism for jointly comparing and reasoning with multidimensional visual morphology and both positive and negative historical evidence, leading to a lack of comprehensive and intuitive source tracing support in the final monitoring results. Summary of the Invention

[0004] This invention provides a method, device, electronic device, and storage medium for monitoring timing anomalies in power distribution communication networks. These solutions address the problems in the prior art, such as high false alarm rates for normal and regular fluctuations in timing data, severe underreporting of complex structural anomalies, and a lack of intuitive evidence for tracing the source of monitoring results.

[0005] An embodiment of the present invention provides a method for monitoring timing anomalies in a power distribution communication network, comprising: Obtain the real-time round-trip delay sequence stream of the objects to be monitored in the power distribution communication network; Extract data from the real-time round-trip delay sequence stream within a preset query window to generate query window data; perform periodic mapping on the start time of the query window data to generate a query phase; Based on the query phase, phase alignment filtering is performed on the preset normal sequence knowledge base to generate reference entries, and all reference entries are combined to generate a phase alignment candidate set; each reference entry has a corresponding reference line graph. Visual rendering is performed on the query window data to generate a query line graph; multimodal feature extraction is performed on the query window data to generate a query multimodal feature vector; the multimodal feature similarity between the query multimodal feature vector and each reference item in the phase alignment candidate set is calculated; the phase alignment candidate set is sorted according to the multimodal feature similarity, and the reference items whose ranking meets the preset ranking requirements are identified as normal control evidence; Based on the query line graph, a preliminary diagnosis of the anomaly type is performed to generate suspected anomaly types; according to the suspected anomaly types, a search is conducted from the preset anomaly sequence knowledge base to generate anomaly precedent evidence; each anomaly precedent evidence has a corresponding precedent line graph. The query line graph, the reference line graph corresponding to normal control evidence, and the precedent line graph corresponding to abnormal precedent evidence are stitched together to generate a multimodal comparison evidence image. The multimodal comparison evidence image and the preset structured prompts are input into a preset multimodal large language model to generate time series anomaly monitoring results.

[0006] Furthermore, a periodic mapping is performed on the start time of the query window data to generate a query phase, including: The query phase is generated by performing a modulo operation based on the start time of the query window data and the preset main period.

[0007] Furthermore, the normal sequence knowledge base stores the reference phase corresponding to each knowledge base entry; Based on the query phase, a phase alignment filter is performed on a pre-defined normal sequence knowledge base to generate reference entries. All reference entries are then combined to generate a phase alignment candidate set, including: Calculate the circumferential distance between the query phase and the reference phase corresponding to each knowledge base entry in the preset normal sequence knowledge base; Knowledge base entries whose circumferential distance meets the preset tolerance threshold are identified as reference entries; Combine all reference entries to generate a phase alignment candidate set.

[0008] Furthermore, the query window data is visually rendered to generate a query line chart; multimodal feature extraction is performed on the query window data to generate a query multimodal feature vector, including: The query window data is mapped to a two-dimensional polyline image data according to the time series, and a query line chart is generated. Extract the query numerical feature vector from the query window data; The query window data is converted into angular field images and reproduced images, respectively. The angle field image and the reproduced image are input into a preset visual encoder to extract the embedding vector of the query angle field image and the embedding vector of the query reproduced image, respectively. The query numerical feature vector, the query angle field image embedding vector, and the query reproduced image embedding vector are combined to generate a query multimodal feature vector.

[0009] Furthermore, the normal sequence knowledge base stores reference numerical feature vectors, reference angle field image embedding vectors, and reference reproduction image embedding vectors corresponding to each knowledge base entry. Calculate the multimodal feature similarity between the query's multimodal feature vector and each reference entry in the phase-aligned candidate set, including: For each reference entry in the phase alignment candidate set, calculate the numerical feature similarity between the query numerical feature vector and the reference numerical feature vector corresponding to the current reference entry. Calculate the similarity of angular field features between the query angular field image embedding vector and the reference angular field image embedding vector corresponding to the current reference entry; Calculate the similarity of reproduction features between the query reproduced image embedding vector and the reference reproduced image embedding vector corresponding to the current reference entry; Based on the preset weight ratio, the numerical feature similarity, angular field feature similarity, and recurrence feature similarity corresponding to each reference item are weighted and summed to generate the multimodal feature similarity corresponding to each reference item.

[0010] Furthermore, the abnormal sequence knowledge base stores the abnormal multimodal feature vectors corresponding to each abnormal knowledge base entry; A preliminary diagnosis of anomaly types is performed based on the query line graph, generating suspected anomaly types. Based on these suspected anomaly types, a search is conducted from a pre-defined anomaly sequence knowledge base to generate prior evidence of anomalies, including: The query line graph is input into a preset lightweight diagnostic model for processing, the abnormality category corresponding to the query line graph is identified, and the identified abnormality category is determined as a suspected abnormality type. Based on the suspected anomaly type, the preset anomaly sequence knowledge base is filtered by type matching to extract anomaly knowledge base entries that match the suspected anomaly type. Combine all anomaly knowledge base entries that match the suspected anomaly type to generate an anomaly type candidate set; Calculate the multimodal feature similarity between the query multimodal feature vector and the multimodal feature vector corresponding to each anomaly knowledge base entry in the anomaly type candidate set; The candidate set of anomaly types is sorted according to the similarity of the anomaly multimodal features, and the anomaly knowledge base entries that meet the preset ranking requirements are identified as anomaly precedent evidence.

[0011] Furthermore, the query line graph, the reference line graph corresponding to normal control evidence, and the precedent line graph corresponding to abnormal precedent evidence are stitched together to generate a multimodal comparison evidence image. This multimodal comparison evidence image, along with preset structured prompts, is then input into a preset multimodal large language model to generate time-series anomaly monitoring results, including: The query line graph is used as the central target graph, and the reference line graphs corresponding to the normal control evidence are arranged in the central target graph. Figure 1 On the other side, the line graphs corresponding to the abnormal precedent evidence are arranged on the other side of the central target image, and a stitching operation is performed to generate a multimodal comparison evidence image; The multimodal comparison evidence images and preset structured prompts are input into a preset multimodal large language model, so that the multimodal large language model can generate time series anomaly monitoring results based on the multimodal comparison evidence images and preset structured prompts.

[0012] Based on the above method embodiments, the present invention provides corresponding apparatus embodiments.

[0013] An embodiment of the present invention provides a timing anomaly monitoring device for power distribution communication networks, comprising: a data preprocessing module, a normal comparison retrieval module, an anomaly precedent retrieval module, and a multimodal reasoning monitoring module; The data preprocessing module is used to acquire the real-time round-trip delay sequence stream of the object to be monitored in the power distribution communication network; extract the data of the real-time round-trip delay sequence stream within a preset query window to generate query window data; and perform periodic mapping on the start time of the query window data to generate a query phase. The normal control retrieval module is used to perform phase alignment filtering on a preset normal sequence knowledge base based on the query phase, generate reference entries, and combine all reference entries to generate a phase alignment candidate set; wherein, each reference entry has a corresponding reference line graph; perform visual rendering on the query window data to generate a query line graph; extract multimodal features from the query window data to generate a query multimodal feature vector; calculate the multimodal feature similarity between the query multimodal feature vector and each reference entry in the phase alignment candidate set; sort the phase alignment candidate set according to the multimodal feature similarity, and determine the reference entries whose ranking meets the preset ranking requirements as normal control evidence; The abnormal precedent retrieval module is used to perform preliminary diagnosis of abnormality type based on query line graph and generate suspected abnormality type; and to retrieve abnormal precedent evidence from a preset abnormal sequence knowledge base according to the suspected abnormality type; wherein, each abnormal precedent evidence has a corresponding precedent line graph. The multimodal reasoning monitoring module is used to stitch together the query line graph, the reference line graph corresponding to normal control evidence, and the precedent line graph corresponding to abnormal precedent evidence to generate a multimodal comparison evidence image; and input the multimodal comparison evidence image and preset structured prompts into a preset multimodal large language model to generate time series anomaly monitoring results.

[0014] Based on the above method embodiments, the present invention provides corresponding electronic device embodiments.

[0015] An embodiment of the present invention provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements any one of the power distribution communication network timing anomaly monitoring methods described in the above method embodiments.

[0016] Based on the above method embodiments, the present invention provides corresponding storage medium embodiments.

[0017] One embodiment of the present invention provides a storage medium storing a computer program thereon, wherein, when the computer program is running, it controls the device where the storage medium is located to execute any of the power distribution communication network timing anomaly monitoring methods described in the above-described method embodiments.

[0018] Compared with the prior art, the present invention has the following beneficial effects: This invention provides a method, apparatus, electronic device, and storage medium for monitoring timing anomalies in power distribution communication networks. The method acquires the real-time round-trip delay sequence stream of the object to be monitored in the power distribution communication network; extracts data within a preset query window and performs periodic mapping to determine the query phase; filters reference entries from a normal sequence knowledge base based on the query phase to construct a phase alignment candidate set; renders a line graph and extracts multimodal features from the query window data, calculates the feature similarity with each reference entry, and filters out normal control evidence; performs a preliminary diagnosis of the anomaly type based on the query line graph and retrieves anomaly precedent evidence from the anomaly sequence knowledge base; stitches the query line graph, reference line graph, and precedent line graph together to generate a multimodal comparison evidence image; inputs the image and structured prompts into a preset multimodal large language model and outputs the timing anomaly monitoring results.

[0019] This invention periodically maps the start time of query window data and uses phase alignment filtering on a pre-set normal sequence knowledge base to determine normal control evidence. It accurately introduces historical baselines under the same operating phase, solving the problem of high false alarm rates in existing technologies due to isolated analysis ignoring cross-period rhythms. Simultaneously, this invention retrieves anomalous precedent evidence by visually rendering and extracting multimodal features from time-series data. It then stitches the query line graph with both positive and negative historical evidence into a multimodal comparative evidence image, which is then used for reasoning by a large language model. This overcomes the lack of morphological perception in traditional one-dimensional shallow analysis and fills the gap in existing methods lacking a joint comparative reasoning mechanism, resulting in comprehensive and intuitive traceability support for the final monitoring results. Attached Figure Description

[0020] Figure 1 This is a flowchart illustrating a method for monitoring timing anomalies in a power distribution communication network according to an embodiment of the present invention.

[0021] Figure 2 This is a schematic diagram of the structure of a timing anomaly monitoring device for a power distribution communication network provided in an embodiment of the present invention. Detailed Implementation

[0022] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0023] like Figure 1 As shown, to address the problems of high false alarm rates for normal, regular fluctuations in time-series data, severe underreporting of complex structural anomalies, and lack of intuitive evidence for tracing the source of monitoring results in existing technologies, an embodiment of the present invention provides a method for monitoring time-series anomalies in power distribution communication networks, comprising at least the following steps: Step S1: Obtain the real-time round-trip delay sequence stream of the object to be monitored in the power distribution communication network; extract the data of the real-time round-trip delay sequence stream within the preset query window to generate query window data; perform periodic mapping on the start time of the query window data to generate the query phase; In a preferred embodiment, periodic mapping is performed on the start time of the query window data to generate a query phase, including: The query phase is generated by performing a modulo operation based on the start time of the query window data and the preset main period.

[0024] Specifically, the implementation process for obtaining the real-time round-trip delay sequence stream of the objects to be monitored in the power distribution communication network is as follows: using communication detection nodes or link monitoring plugins deployed in the power distribution communication network, the single round-trip delay time values ​​generated by each link to be monitored during the communication service interaction are continuously collected, and the round-trip delay time values ​​are arranged and combined according to the timestamp of the collection time, so as to form a real-time round-trip delay sequence stream that can dynamically reflect the network link delay fluctuation.

[0025] After acquiring the real-time round-trip delay sequence stream, the step of extracting data from the real-time round-trip delay sequence stream within a preset query window and generating query window data is performed. The preset query window mentioned above refers to a predefined continuous time interval. By extracting all delay sampling points falling within the preset query window time span from the real-time round-trip delay sequence stream, query window data for subsequent anomaly diagnosis and analysis is obtained.

[0026] To accurately pinpoint the relative stage of query window data within the long-term operating rhythm of the network, it is necessary to perform a periodic mapping operation on the start time of the query window data to generate a query phase. Since the service load and communication activities of power distribution communication networks typically exhibit distinct periodic rhythms, such as a daily service cycle on a 24-hour basis or a weekly service cycle on a 7-day basis, the periodic mapping operation can project the start time of the query window data onto a relative operating phase. In a preferred embodiment, performing periodic mapping on the start time of the query window data to generate a query phase specifically includes the following steps: performing a modulo operation based on the start time of the query window data and a preset main period to generate the query phase.

[0027] The specific mathematical calculation process is as follows: in, This is the generated query phase. This is the starting time for querying window data. The preset main cycle is a time constant that is pre-set according to the operating characteristics of the power distribution communication network service.

[0028] By taking the modulo of the start time of the query window data with the preset main cycle, the absolute time background in the start time can be removed, and the start time can be transformed into a query phase that reflects the business cycle stage. This allows subsequent steps to cross the absolute time interval and introduce accurate historical baseline data as a reference under the same business rhythm phase.

[0029] Step S2: Based on the query phase, perform phase alignment filtering on the preset normal sequence knowledge base to generate reference entries, and combine all reference entries to generate a phase alignment candidate set; each reference entry has a corresponding reference line graph; perform visual rendering on the query window data to generate a query line graph; extract multimodal features from the query window data to generate a query multimodal feature vector; calculate the multimodal feature similarity between the query multimodal feature vector and the multimodal features of each reference entry in the phase alignment candidate set; sort the phase alignment candidate set according to the multimodal feature similarity, and determine the reference entries whose ranking meets the preset ranking requirements as normal control evidence; In a preferred embodiment, the normal sequence knowledge base stores the reference phase corresponding to each knowledge base entry; Based on the query phase, a phase alignment filter is performed on a pre-defined normal sequence knowledge base to generate reference entries. All reference entries are then combined to generate a phase alignment candidate set, including: Calculate the circumferential distance between the query phase and the reference phase corresponding to each knowledge base entry in the preset normal sequence knowledge base; Knowledge base entries whose circumferential distance meets the preset tolerance threshold are identified as reference entries; Combine all reference entries to generate a phase alignment candidate set.

[0030] In a preferred embodiment, the query window data is visually rendered to generate a query line graph; multimodal feature extraction is performed on the query window data to generate a query multimodal feature vector, including: The query window data is mapped to a two-dimensional polyline image data according to the time series, and a query line chart is generated. Extract the query numerical feature vector from the query window data; The query window data is converted into angular field images and reproduced images, respectively. The angle field image and the reproduced image are input into a preset visual encoder to extract the embedding vector of the query angle field image and the embedding vector of the query reproduced image, respectively. The query numerical feature vector, the query angle field image embedding vector, and the query reproduced image embedding vector are combined to generate a query multimodal feature vector.

[0031] In a preferred embodiment, the normal sequence knowledge base stores reference numerical feature vectors, reference angle field image embedding vectors, and reference reproduction image embedding vectors corresponding to each knowledge base entry. Calculate the multimodal feature similarity between the query's multimodal feature vector and each reference entry in the phase-aligned candidate set, including: For each reference entry in the phase alignment candidate set, calculate the numerical feature similarity between the query numerical feature vector and the reference numerical feature vector corresponding to the current reference entry. Calculate the similarity of angular field features between the query angular field image embedding vector and the reference angular field image embedding vector corresponding to the current reference entry; Calculate the similarity of reproduction features between the query reproduced image embedding vector and the reference reproduced image embedding vector corresponding to the current reference entry; Based on the preset weight ratio, the numerical feature similarity, angular field feature similarity, and recurrence feature similarity corresponding to each reference item are weighted and summed to generate the multimodal feature similarity corresponding to each reference item.

[0032] Specifically, for the generated query phase, the preset normal sequence knowledge base pre-stores a large number of historical normal operating latency data segments, and also pre-stores the reference phase corresponding to each knowledge base entry. The specific method for obtaining the reference phase is as follows: during the offline construction phase, the starting record time of each historical normal latency sequence in the preset normal sequence knowledge base is extracted, and the starting record time is moduloed with the preset main period to obtain the reference phase bound to each historical normal latency sequence, which is then persistently stored.

[0033] Based on the query phase, a phase alignment filter is performed on a pre-defined normal sequence knowledge base to generate reference entries. All reference entries are then combined to form a phase alignment candidate set. Specifically, the circumferential distance between the query phase and the reference phases corresponding to each knowledge base entry in the pre-defined normal sequence knowledge base is calculated. The corresponding mathematical expression is: in, It represents the circumferential distance. To query the phase. The reference phase is extracted from a pre-defined normal sequence knowledge base. This is the preset main cycle.

[0034] Based on the calculated circumferential distance, knowledge base entries whose circumferential distance meets a preset tolerance threshold are identified as reference entries. The preset tolerance threshold is set according to the allowable time deviation range of power distribution communication network service traffic fluctuations, with a standard of 5% of the preset main cycle, aiming to ensure that the selected historical data has a high degree of synchronization in service rhythm. All reference entries meeting the tolerance threshold are combined to generate a phase alignment candidate set. Each reference entry in the phase alignment candidate set is pre-associated with and stored with a corresponding reference line graph, which is pre-rendered based on historical normal latency data.

[0035] Visual rendering is performed on the query window data to generate a query line graph; multimodal feature extraction is performed on the query window data to generate a query multimodal feature vector. The implementation details of mapping the query window data to a two-dimensional polyline image to generate the query line graph are as follows: the time delay values ​​in the query window data are normalized and mapped to the height range of the pixel coordinate system; using the timestamp as the horizontal axis pixel coordinate and the normalized time delay value as the vertical axis pixel coordinate, adjacent coordinate points are connected using a linear interpolation algorithm to generate a query line graph reflecting the time delay fluctuation pattern on an image canvas of a preset resolution.

[0036] In the operation of extracting the query numerical feature vector from the query window data, the query numerical feature vector consists of multiple indicators reflecting the distribution characteristics of the sequence. The logic for extracting numerical features using statistical algorithms is as follows: in, To query numerical feature vectors. This is the arithmetic mean of the data in the query window. This represents the standard deviation of the query window data. This is the maximum value. It is the minimum value. This is a skewness index. This is a kurtosis index.

[0037] The query window data is converted into angle field images and reconstructed images. For the angle field image conversion, the query window data is scaled to a value range of -1 to 1. The scaled values ​​are then encoded into angles in polar coordinates using an inverse cosine function. An angle field matrix is ​​generated by calculating the cosine of the sum of angles between different time points, and the resulting angle field image is output. For the reconstructed image conversion, the Euclidean distance between any two time points in the query window data is calculated. If the Euclidean distance is less than a preset distance threshold, a point is marked at the corresponding position in the two-dimensional matrix, forming a reconstructed image reflecting the cyclical patterns within the time delay sequence.

[0038] The angular field image and the reproduced image are input into a pre-defined visual encoder, which extracts the query angular field image embedding vector and the query reproduced image embedding vector, respectively. The pre-defined visual encoder employs a deep learning model based on a residual network structure. The pre-defined visual encoder is trained using a dataset of time delay distribution images accumulated during the historical operation of the power distribution communication network. During the training phase, a contrastive learning loss function is used as the optimization objective. The input samples are image pairs labeled with normal operation and abnormal operation, driving the pre-defined visual encoder to automatically learn high-order nonlinear features that distinguish different time delay fluctuation modes. The trained visual encoder has the ability to compress the input angular field image and the reproduced image into fixed-dimensional feature vectors. The extracted query numerical feature vector, query angular field image embedding vector, and query reproduced image embedding vector are combined and concatenated to generate a complete query multimodal feature vector.

[0039] In addition to the reference phase, the pre-defined normal sequence knowledge base also stores the reference numerical feature vector, reference angle field image embedding vector, and reference reproduction image embedding vector corresponding to each knowledge base entry. When calculating the multimodal feature similarity between the query multimodal feature vector and each reference entry in the phase alignment candidate set, similarity is measured for each reference entry in the phase alignment candidate set from three dimensions: numerical, angle field, and reproduction image.

[0040] The process of calculating the numerical feature similarity between the query numerical feature vector and the reference numerical feature vector corresponding to the reference entry is as follows: in, This represents the numerical feature similarity. To query the first element in the numerical feature vector Each feature component. For the reference numerical eigenvector, the first Each feature component. This represents the total dimension of the feature vector.

[0041] The similarity of angular field features between the query angular field image embedding vector and the reference angular field image embedding vector corresponding to the reference entry is calculated using the following method: in, For the similarity of angular field features. The embedding vector is used to query the angle field image. The embedding vector is used for the reference angle field image.

[0042] The similarity of reproduction features between the query reproduced image embedding vector and the reference reproduced image embedding vector corresponding to the reference entry is calculated, also by calculating the cosine similarity between the query reproduced image embedding vector and the reference reproduced image embedding vector. Based on a preset weight ratio, the numerical feature similarity, angular field feature similarity, and reproduction feature similarity corresponding to each reference entry are weighted and summed to generate the multimodal feature similarity for each reference entry. The phase alignment candidate set is sorted in descending order according to the multimodal feature similarity, and reference entries that meet the preset ranking requirements are identified as normal control evidence.

[0043] The embodiments of the present invention not only achieve accurate alignment of historical data in terms of time phase, but also complete in-depth feature matching from the perspectives of statistical values ​​and multi-dimensional visual morphology, providing an extremely accurate and complete historical normal baseline as factual evidence for subsequent time series anomaly determination.

[0044] Step S3: Perform preliminary diagnosis of anomaly type based on query line graph and generate suspected anomaly type; retrieve from the preset anomaly sequence knowledge base according to the suspected anomaly type to generate anomaly precedent evidence; wherein, each anomaly precedent evidence has a corresponding precedent line graph. In a preferred embodiment, the abnormal sequence knowledge base stores the abnormal multimodal feature vectors corresponding to each abnormal knowledge base entry; A preliminary diagnosis of anomaly types is performed based on the query line graph, generating suspected anomaly types. Based on these suspected anomaly types, a search is conducted from a pre-defined anomaly sequence knowledge base to generate prior evidence of anomalies, including: The query line graph is input into a preset lightweight diagnostic model for processing, the abnormality category corresponding to the query line graph is identified, and the identified abnormality category is determined as a suspected abnormality type. Based on the suspected anomaly type, the preset anomaly sequence knowledge base is filtered by type matching to extract anomaly knowledge base entries that match the suspected anomaly type. Combine all anomaly knowledge base entries that match the suspected anomaly type to generate an anomaly type candidate set; Calculate the multimodal feature similarity between the query multimodal feature vector and the multimodal feature vector corresponding to each anomaly knowledge base entry in the anomaly type candidate set; The candidate set of anomaly types is sorted according to the similarity of the anomaly multimodal features, and the anomaly knowledge base entries that meet the preset ranking requirements are identified as anomaly precedent evidence.

[0045] Specifically, after screening for normal control evidence, a preliminary diagnosis of anomalies is performed based on the query line graph to generate suspected anomaly types. The specific implementation process involves inputting the query line graph into a pre-defined lightweight diagnostic model for processing, identifying the anomaly category corresponding to the query line graph, and determining the identified anomaly category as the suspected anomaly type. The aforementioned pre-defined lightweight diagnostic model is an image classification model based on a convolutional neural network structure, characterized by a small number of parameters and fast inference speed.

[0046] The training process of the pre-defined lightweight diagnostic model is as follows: In the offline phase, images of various typical abnormal delay sequences that occurred during the historical operation of the power distribution communication network are collected to construct a training dataset. For each image in the training dataset, a corresponding anomaly category label is pre-labeled, including sudden increases in delay, periodic severe jitter, linear upward trends, and step shifts. A supervised learning algorithm is used to iteratively train the convolutional neural network, utilizing the cross-entropy loss function to minimize the difference between the predicted result and the anomaly category label, enabling the pre-defined lightweight diagnostic model to learn the texture features of different anomaly patterns in the image space. After training, the pre-defined lightweight diagnostic model can perform feature mapping on the input query line graph and output the anomaly category with the highest probability as the suspected anomaly type.

[0047] Based on the suspected anomaly type, a search is performed from a pre-defined anomaly sequence knowledge base to generate anomaly precedent evidence. The pre-defined anomaly sequence knowledge base stores the multimodal feature vectors corresponding to each anomaly knowledge base entry. The search process first performs type matching filtering on the pre-defined anomaly sequence knowledge base based on the suspected anomaly type. The logic of type matching filtering is as follows: traverse the pre-defined anomaly sequence knowledge base and extract all anomaly knowledge base entries whose anomaly category attributes are completely consistent with the suspected anomaly type. Through this filtering operation, the search scope can be narrowed down to specific anomaly patterns. Subsequently, all anomaly knowledge base entries that match the suspected anomaly type are combined to generate an anomaly type candidate set.

[0048] For each anomaly knowledge base entry in the anomaly type candidate set, calculate the anomaly multimodal feature similarity between the query multimodal feature vector and the corresponding anomaly multimodal feature vector in the anomaly knowledge base entry. The anomaly multimodal feature similarity is measured using the cosine similarity between vectors, and the specific calculation logic is as follows: In the above formula, This is the calculated similarity of the abnormal multimodal features. To query the first feature vector in a multimodal feature vector Each feature component. The first element in the multimodal feature vector corresponding to the entry in the anomaly knowledge base Each feature component. This represents the total dimension of the multimodal feature vectors.

[0049] After obtaining the anomaly multimodal feature similarity scores for all entries in the anomaly type candidate set, the candidate set is sorted in descending order according to these similarities. Anomaly knowledge base entries that meet a preset ranking requirement are identified as anomaly precedent evidence. The preset ranking requirement refers to selecting the top-ranked anomaly knowledge base entry in the sorting results, or selecting the first entry whose similarity score exceeds a preset threshold. Each anomaly precedent evidence is pre-associated with and stored with a corresponding precedent line graph. The method for obtaining the precedent line graph is the same as the query line graph. Figure 1 The corresponding historical anomaly time delay sequence is normalized and then generated on the image canvas through polyline mapping, which is used to intuitively display the fluctuation pattern of the historical anomaly precedent.

[0050] By introducing a lightweight diagnostic model for initial screening and combining it with multimodal feature retrieval of abnormal precedents, this embodiment of the invention can locate the most representative abnormal reference samples from historical experience based on clearly defined abnormal attributes, providing key comparisons for the subsequent generation of evidence-supported monitoring results.

[0051] Step S4: Combine the query line graph, the reference line graph corresponding to the normal control evidence, and the precedent line graph corresponding to the abnormal precedent evidence to generate a multimodal comparison evidence image; input the multimodal comparison evidence image and the preset structured prompts into the preset multimodal large language model to generate the time series anomaly monitoring results.

[0052] In a preferred embodiment, the query line graph, the reference line graph corresponding to normal control evidence, and the precedent line graph corresponding to abnormal precedent evidence are stitched together to generate a multimodal comparison evidence image. The multimodal comparison evidence image and preset structured prompts are input into a preset multimodal large language model to generate time-series anomaly monitoring results, including: The query line graph is used as the central target graph, and the reference line graphs corresponding to the normal control evidence are arranged in the central target graph. Figure 1 On the other side, the line graphs corresponding to the abnormal precedent evidence are arranged on the other side of the central target image, and a stitching operation is performed to generate a multimodal comparison evidence image; The multimodal comparison evidence images and preset structured prompts are input into a preset multimodal large language model, so that the multimodal large language model can generate time series anomaly monitoring results based on the multimodal comparison evidence images and preset structured prompts.

[0053] Specifically, after completing the screening of normal control evidence and the retrieval of abnormal precedent evidence, the system performs an operation to stitch together the query line graph, the reference line graph corresponding to the normal control evidence, and the precedent line graph corresponding to the abnormal precedent evidence to generate a multimodal comparison evidence image. The specific stitching process is as follows: A two-dimensional blank canvas with a preset pixel size is constructed, and the query line graph is placed at the center of the two-dimensional blank canvas as the central target image. Next, the reference line graph corresponding to the normal control evidence is arranged in an adjacent area on one side of the central target image, and the precedent line graph corresponding to the abnormal precedent evidence is arranged in the corresponding area on the other side of the central target image. During the image arrangement and combination process, the horizontal time axis scale ratio and the vertical numerical axis scale ratio of the central target image, reference line graph, and precedent line graph are strictly aligned. Through pixel matrix merging operations, a multimodal comparison evidence image that integrates the current real-time state, historical normal baseline, and historical abnormal precedent views is output.

[0054] After generating multimodal contrast evidence images, the process involves inputting these images and pre-defined structured prompts into a pre-defined multimodal large language model to generate time-series anomaly monitoring results. The pre-defined structured prompts are pre-configured guidance text templates that encapsulate the specific numerical values ​​of the query phase, the quantified values ​​of the multimodal feature similarity between the normal control evidence and the monitored object, and the suspected anomaly type labels in text form, thus providing the model with necessary numerical background prior information.

[0055] Regarding the acquisition and preparation of the pre-set multimodal large language model, a base model that has already been pre-trained on massive cross-modal data is selected. The base model can be obtained by downloading pre-trained model weight files from open-source technology communities or by calling the multimodal model application programming interface provided by a cloud platform. To enable the base model to accurately identify the time delay sequence characteristics of the power distribution communication network and generate monitoring results with professional logic, supervised fine-tuning is performed using professional corpus in the power distribution communication network field. The implementation details of supervised fine-tuning are as follows: Power distribution communication network operation and maintenance procedures, historical fault work order texts, and corresponding abnormal time delay image data are collected to construct an industry instruction fine-tuning dataset; for each sample in the industry instruction fine-tuning dataset, an instruction pair containing the problem, multimodal comparison evidence images, and standard diagnostic conclusions is constructed. During the fine-tuning process, the basic parameters of the visual encoding layer and language processing layer in the pre-set multimodal large language model remain unchanged; parameter optimization is only performed on the connection layer or specific adapter layers. By minimizing the textual log-likelihood loss function between the model's predicted output and the standard diagnostic conclusion, the pre-defined multimodal large language model is equipped with the ability to understand the mapping between time-series fluctuation images and power operation and maintenance terminology. After fine-tuning, the pre-defined multimodal large language model can extract deep correlation features from multimodal comparative evidence images based on specific input task instructions.

[0056] During the reasoning process, a pre-defined multimodal big language model receives multimodal comparison evidence images and pre-defined structured prompts. An internal cross-attention mechanism aligns the visual feature vectors in the multimodal comparison evidence images with the textual semantic vectors in the pre-defined structured prompts. The pre-defined multimodal big language model, through multi-layered self-attention transformation, compares the visual morphological differences between the central target image and a reference line image on one side of the multimodal comparison evidence image, locating waveform anomaly segments that deviate from the normal historical business cycle by identifying non-overlapping morphological regions. Simultaneously, the pre-defined multimodal big language model extracts the consistency of local peak and trough textures between the waveform anomaly segments and the precedent line image on the other side, verifying whether the waveform anomaly segments highly match known historical anomaly patterns.

[0057] The final temporal anomaly monitoring results are generated by a pre-defined multimodal large language model through autoregressive decoding. The pre-defined multimodal large language model predicts each character based on probability distribution, forming structured text. The temporal anomaly monitoring results include a determination of whether a network anomaly has occurred, the specific sampling time span of the abnormal fluctuation, the specific type of anomaly, the confidence probability score of the determination, and evidence citations generated by combining features from multiple spliced ​​line diagrams. The evidence citations are automatically organized by the pre-defined multimodal large language model based on the specific coordinates of the deviation segments in the multimodal comparative evidence images and descriptions of similarity features with historical precedents.

[0058] By introducing a spatial stitching mechanism at the visual level and the cross-modal reasoning capability of a large language model, this invention enables cross-temporal and spatial joint analysis and insight into the current fluctuation state, historical normal baseline, and historical abnormal precedents, providing highly reliable diagnostic results with complete logical reasoning chains and intuitive image comparison support for the operation and maintenance of power distribution communication networks.

[0059] Based on the above method embodiments, the present invention provides corresponding apparatus embodiments.

[0060] like Figure 2 As shown, an embodiment of the present invention provides a timing anomaly monitoring device for power distribution communication networks, including: a data preprocessing module, a normal comparison retrieval module, an anomaly precedent retrieval module, and a multimodal reasoning monitoring module; The data preprocessing module is used to acquire the real-time round-trip delay sequence stream of the object to be monitored in the power distribution communication network; extract the data of the real-time round-trip delay sequence stream within a preset query window to generate query window data; and perform periodic mapping on the start time of the query window data to generate a query phase. The normal control retrieval module is used to perform phase alignment filtering on a preset normal sequence knowledge base based on the query phase, generate reference entries, and combine all reference entries to generate a phase alignment candidate set; wherein, each reference entry has a corresponding reference line graph; perform visual rendering on the query window data to generate a query line graph; extract multimodal features from the query window data to generate a query multimodal feature vector; calculate the multimodal feature similarity between the query multimodal feature vector and each reference entry in the phase alignment candidate set; sort the phase alignment candidate set according to the multimodal feature similarity, and determine the reference entries whose ranking meets the preset ranking requirements as normal control evidence; The abnormal precedent retrieval module is used to perform preliminary diagnosis of abnormality type based on query line graph and generate suspected abnormality type; and to retrieve abnormal precedent evidence from a preset abnormal sequence knowledge base according to the suspected abnormality type; wherein, each abnormal precedent evidence has a corresponding precedent line graph. The multimodal reasoning monitoring module is used to stitch together the query line graph, the reference line graph corresponding to normal control evidence, and the precedent line graph corresponding to abnormal precedent evidence to generate a multimodal comparison evidence image; and input the multimodal comparison evidence image and preset structured prompts into a preset multimodal large language model to generate time series anomaly monitoring results.

[0061] In a preferred embodiment, the data preprocessing module performs periodic mapping on the start time of the query window data to generate a query phase, including: The query phase is generated by performing a modulo operation based on the start time of the query window data and the preset main period.

[0062] In a preferred embodiment, the normal control retrieval module stores reference phases corresponding to each knowledge base entry in the normal sequence knowledge base; Based on the query phase, a phase alignment filter is performed on a pre-defined normal sequence knowledge base to generate reference entries. All reference entries are then combined to generate a phase alignment candidate set, including: Calculate the circumferential distance between the query phase and the reference phase corresponding to each knowledge base entry in the preset normal sequence knowledge base; Knowledge base entries whose circumferential distance meets the preset tolerance threshold are identified as reference entries; Combine all reference entries to generate a phase alignment candidate set.

[0063] In a preferred embodiment, the normal comparison retrieval module performs visual rendering on the query window data to generate a query line graph; and performs multimodal feature extraction on the query window data to generate a query multimodal feature vector, including: The query window data is mapped to a two-dimensional polyline image data according to the time series, and a query line chart is generated. Extract the query numerical feature vector from the query window data; The query window data is converted into angular field images and reproduced images, respectively. The angle field image and the reproduced image are input into a preset visual encoder to extract the embedding vector of the query angle field image and the embedding vector of the query reproduced image, respectively. The query numerical feature vector, the query angle field image embedding vector, and the query reproduced image embedding vector are combined to generate a query multimodal feature vector.

[0064] In a preferred embodiment, the normal comparison retrieval module stores reference numerical feature vectors, reference angle field image embedding vectors, and reference reproduction image embedding vectors corresponding to each knowledge base entry in the normal sequence knowledge base. Calculate the multimodal feature similarity between the query's multimodal feature vector and each reference entry in the phase-aligned candidate set, including: For each reference entry in the phase alignment candidate set, calculate the numerical feature similarity between the query numerical feature vector and the reference numerical feature vector corresponding to the current reference entry. Calculate the similarity of angular field features between the query angular field image embedding vector and the reference angular field image embedding vector corresponding to the current reference entry; Calculate the similarity of reproduction features between the query reproduced image embedding vector and the reference reproduced image embedding vector corresponding to the current reference entry; Based on the preset weight ratio, the numerical feature similarity, angular field feature similarity, and recurrence feature similarity corresponding to each reference item are weighted and summed to generate the multimodal feature similarity corresponding to each reference item.

[0065] In a preferred embodiment, the abnormal precedent retrieval module stores the abnormal sequence knowledge base containing the abnormal multimodal feature vectors corresponding to each abnormal knowledge base entry. A preliminary diagnosis of anomaly types is performed based on the query line graph, generating suspected anomaly types. Based on these suspected anomaly types, a search is conducted from a pre-defined anomaly sequence knowledge base to generate prior evidence of anomalies, including: The query line graph is input into a preset lightweight diagnostic model for processing, the abnormality category corresponding to the query line graph is identified, and the identified abnormality category is determined as a suspected abnormality type. Based on the suspected anomaly type, the preset anomaly sequence knowledge base is filtered by type matching to extract anomaly knowledge base entries that match the suspected anomaly type. Combine all anomaly knowledge base entries that match the suspected anomaly type to generate an anomaly type candidate set; Calculate the multimodal feature similarity between the query multimodal feature vector and the multimodal feature vector corresponding to each anomaly knowledge base entry in the anomaly type candidate set; The candidate set of anomaly types is sorted according to the similarity of the anomaly multimodal features, and the anomaly knowledge base entries that meet the preset ranking requirements are identified as anomaly precedent evidence.

[0066] In a preferred embodiment, the multimodal reasoning monitoring module stitches together the query line graph, the reference line graph corresponding to normal control evidence, and the precedent line graph corresponding to abnormal precedent evidence to generate a multimodal comparison evidence image; it then inputs the multimodal comparison evidence image and preset structured prompts into a preset multimodal large language model to generate time-series anomaly monitoring results, including: The query line graph is used as the central target graph, and the reference line graphs corresponding to the normal control evidence are arranged in the central target graph. Figure 1 On the other side, the line graphs corresponding to the abnormal precedent evidence are arranged on the other side of the central target image, and a stitching operation is performed to generate a multimodal comparison evidence image; The multimodal comparison evidence images and preset structured prompts are input into a preset multimodal large language model, so that the multimodal large language model can generate time series anomaly monitoring results based on the multimodal comparison evidence images and preset structured prompts.

[0067] Specifically, the data preprocessing module is used to acquire the real-time round-trip delay sequence stream of the object to be monitored in the power distribution communication network. In specific implementation, the data preprocessing module uses probes deployed at communication nodes to acquire dynamic round-trip delay data reflecting link quality, and arranges it into a sequence stream according to the order of acquisition time. The data preprocessing module extracts data from the real-time round-trip delay sequence stream within a preset query window to generate query window data. The data preprocessing module performs periodic mapping on the start time of the query window data to generate a query phase. In a preferred embodiment, the data preprocessing module performs periodic mapping on the start time of the query window data to generate a query phase, specifically including: performing a modulo operation based on the start time of the query window data and a preset master period to generate the query phase. By performing a modulo operation on the start time and the preset master period, the data preprocessing module can convert absolute time coordinates into relative phase coordinates reflecting the service cycle stage, wherein the preset master period is preset according to the daily or weekly cycle characteristics of the power distribution communication network service.

[0068] The normal comparison retrieval module is used to perform phase alignment filtering on a preset normal sequence knowledge base based on the query phase, generate reference entries, and combine all reference entries to generate a phase alignment candidate set. In a preferred embodiment, the normal sequence knowledge base stores reference phases corresponding to each knowledge base entry. Specifically, the normal comparison retrieval module performs phase alignment filtering on the preset normal sequence knowledge base based on the query phase, generates reference entries, and combines all reference entries to generate a phase alignment candidate set. This includes calculating the circumferential distance between the query phase and the reference phases corresponding to each knowledge base entry in the preset normal sequence knowledge base. The circumferential distance refers to the distance between two phase points along the shortest arc direction within a periodic cyclic space. The normal comparison retrieval module calculates the circumferential distance by considering the characteristic of the beginning and end of the cycle. The normal comparison retrieval module determines knowledge base entries whose circumferential distance meets a preset tolerance threshold as reference entries. The preset tolerance threshold represents the allowable time offset and is used to filter historical data that is in a similar business operation stage to the current monitoring time. The normal comparison retrieval module combines all reference entries to generate a phase alignment candidate set. Within the phase alignment candidate set, each reference entry is pre-associated with and stored with a corresponding reference line diagram.

[0069] In a preferred embodiment, the normal control retrieval module performs visual rendering on the query window data to generate a query line graph; it also performs multimodal feature extraction on the query window data to generate a query multimodal feature vector. Specifically, the normal control retrieval module maps the query window data into a two-dimensional polyline image data according to the time series, generating a query line graph. The normal control retrieval module first performs normalization processing on the time delay values, maps the processed values ​​onto a preset resolution canvas, and uses a pixel-connection algorithm to depict a polyline reflecting the fluctuation pattern. The normal control retrieval module extracts query numerical feature vectors from the query window data. The query numerical feature vectors contain multiple statistical components, including mean, variance, skewness, and kurtosis, used to characterize the sequence features from the numerical distribution dimension. The normal control retrieval module converts the query window data into an angle field image and a reproducible image. The angle field image refers to the image data generated by mapping the sequence to a polar coordinate system using an inverse cosine function; the reproducible image refers to the image data reflecting the internal cyclic characteristics generated by calculating the distance matrix between points within the sequence and performing binarization. The normal comparison retrieval module inputs the angle field image and the reproduced image into a preset visual encoder, extracting the query angle field image embedding vector and the query reproduced image embedding vector, respectively. The preset visual encoder adopts a residual structure based on a deep convolutional neural network and is pre-trained using a contrastive learning algorithm on a normal and abnormal image dataset from the power communication field, enabling it to compress image signals into high-dimensional feature embedding space vectors. The normal comparison retrieval module combines the query numerical feature vector, the query angle field image embedding vector, and the query reproduced image embedding vector to generate a query multimodal feature vector.

[0070] In a preferred embodiment, the normal comparison retrieval module stores reference numerical feature vectors, reference angle field image embedding vectors, and reference reproduction image embedding vectors corresponding to each knowledge base entry. The normal comparison retrieval module calculates the multimodal feature similarity between the query multimodal feature vector and each reference entry in the phase alignment candidate set. Specifically, for each reference entry in the phase alignment candidate set, the normal comparison retrieval module calculates the numerical feature similarity between the query numerical feature vector and the reference numerical feature vector corresponding to the reference entry. The numerical feature similarity is measured using the reciprocal of the Euclidean distance. The normal comparison retrieval module calculates the angle field feature similarity between the query angle field image embedding vector and the reference angle field image embedding vector corresponding to the reference entry. The normal comparison retrieval module calculates the reproduction feature similarity between the query reproduction image embedding vector and the reference reproduction image embedding vector corresponding to the reference entry. Both the angle field feature similarity and the reproduction feature similarity are measured using the cosine angle between the vectors. The normal comparison retrieval module performs a weighted summation of the numerical feature similarity, angle field feature similarity, and reproduction feature similarity corresponding to each reference entry according to a preset weight ratio to generate the multimodal feature similarity corresponding to each reference entry. The normal control retrieval module sorts the phase alignment candidate set according to the multimodal feature similarity and determines the reference entries that meet the preset ranking requirements as normal control evidence.

[0071] The anomaly precedent retrieval module is used to perform preliminary anomaly type diagnosis based on the query line graph and generate suspected anomaly types; it then retrieves evidence of anomalies from a preset anomaly sequence knowledge base based on the suspected anomaly types. In a preferred embodiment, the anomaly sequence knowledge base stores anomaly multimodal feature vectors corresponding to each anomaly knowledge base entry. The specific steps of the anomaly precedent retrieval module are as follows: The anomaly precedent retrieval module inputs the query line graph into a preset lightweight diagnostic model for processing, identifies the anomaly category corresponding to the query line graph, and determines the identified anomaly category as a suspected anomaly type. The preset lightweight diagnostic model uses a lightweight convolutional neural network, pre-trained using anomaly sequence images labeled with categories such as jitter, mutation, and upward trend, and can output the anomaly probability distribution to which the current morphology belongs. The anomaly precedent retrieval module performs type matching filtering on the preset anomaly sequence knowledge base based on the suspected anomaly type, extracting anomaly knowledge base entries that match the suspected anomaly type. The anomaly precedent retrieval module combines all anomaly knowledge base entries that match the suspected anomaly type to generate an anomaly type candidate set. The anomaly precedent retrieval module calculates the anomaly multimodal feature similarity between the query multimodal feature vector and the anomaly multimodal feature vector corresponding to each anomaly knowledge base entry in the anomaly type candidate set. The anomaly multimodal feature similarity is obtained through vector dot product operations. The anomaly precedent retrieval module sorts the anomaly type candidate set according to the anomaly multimodal feature similarity and determines the anomaly knowledge base entries whose ranking meets the preset requirements as anomaly precedent evidence. Each anomaly precedent evidence is associated with a corresponding precedent line graph.

[0072] The multimodal inference monitoring module is used to generate time-series anomaly monitoring results. In a preferred embodiment, the multimodal inference monitoring module performs a graphic stitching operation: the multimodal inference monitoring module uses the query line graph as the central target graph, and arranges the reference line graphs corresponding to the normal control evidence in the central target graph. Figure 1 On one side, the precedent line graphs corresponding to the abnormal precedent evidence are arranged on the other side of the central target graph to generate a multimodal comparison evidence image. The multimodal inference monitoring module inputs the multimodal comparison evidence image and preset structured prompts into a preset multimodal large language model, so that the multimodal large language model can generate time-series anomaly monitoring results based on the multimodal comparison evidence image and preset structured prompts. The preset multimodal large language model is obtained by supervised fine-tuning based on a large-scale pre-trained model using power distribution communication network operation and maintenance corpus, fault diagnosis expert experience text, and associated time delay distribution maps. The multimodal inference monitoring module utilizes the cross-modal understanding capability of the preset multimodal large language model to compare the deviation of the query line graph from the reference line graph, and combines the morphological features of the precedent line graph to finally output structured text containing anomaly judgment, anomaly interval, anomaly type, confidence level, and evidence description.

[0073] The device provided by this invention can perform precise analysis of time-series data of power distribution communication networks from multiple modal dimensions such as phase, numerical value, and visual morphology through modular collaboration, which significantly improves the accuracy of anomaly monitoring and the traceability of monitoring results.

[0074] It should be noted that the embodiments of the device described above correspond to the embodiments of the present invention described above, and can realize the power distribution communication network timing anomaly monitoring method described in any one of the above embodiments of the present invention. Furthermore, the embodiments of the device described above are merely illustrative. The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. In addition, in the accompanying drawings of the device embodiments provided by the present invention, the connection relationship between modules indicates that they have a communication connection, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without creative effort.

[0075] Based on the above-described method embodiments of the present invention, a corresponding embodiment of an electronic device is provided.

[0076] An embodiment of the present invention provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the power distribution communication network timing anomaly monitoring method according to any one of the present invention, or, when the processor executes the computer program, it implements the functions of each module in the above-described device embodiments.

[0077] For example, the computer program may be divided into one or more modules, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules may be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the terminal device.

[0078] The terminal device may be a desktop computer, laptop, handheld computer, or cloud server, etc. The terminal device may include, but is not limited to, a processor and a memory.

[0079] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the terminal device, connecting all parts of the terminal device via various interfaces and lines.

[0080] The memory can be used to store the computer programs and / or modules. The processor implements various functions of the terminal device by running or executing the computer programs and / or modules stored in the memory and by calling data stored in the memory. The memory may mainly include a program storage area and a data storage area. The program storage area may store the operating system, applications required for at least one function, etc.; the data storage area may store data created based on the use of the mobile phone, etc. In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital card (SD card), flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0081] Based on the above method embodiments, the present invention provides corresponding storage medium embodiments; Another embodiment of the present invention provides a storage medium including a stored computer program, wherein, when the computer program is running, it controls the device where the storage medium is located to execute any of the above-described power distribution communication network timing anomaly monitoring methods of the present invention.

[0082] The aforementioned storage medium is a computer-readable storage medium, and the computer program includes computer program code, which may be in the form of source code, object code, executable file, or certain intermediate forms. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.

[0083] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of those different embodiments or examples.

[0084] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.

Claims

1. A method for monitoring timing anomalies in a power distribution communication network, characterized in that, include: Obtain the real-time round-trip delay sequence stream of the objects to be monitored in the power distribution communication network; Extract data from the real-time round-trip delay sequence stream within a preset query window and generate query window data; Periodically map the start time of the query window data to generate a query phase; Based on the query phase, phase alignment filtering is performed on the preset normal sequence knowledge base to generate reference entries, and all reference entries are combined to generate a phase alignment candidate set; each reference entry has a corresponding reference line graph. Visual rendering is performed on the query window data to generate a query line graph; multimodal feature extraction is performed on the query window data to generate a query multimodal feature vector; the multimodal feature similarity between the query multimodal feature vector and each reference item in the phase alignment candidate set is calculated; the phase alignment candidate set is sorted according to the multimodal feature similarity, and the reference items whose ranking meets the preset ranking requirements are identified as normal control evidence; Based on the query line graph, a preliminary diagnosis of the anomaly type is performed to generate suspected anomaly types; according to the suspected anomaly types, a search is conducted from the preset anomaly sequence knowledge base to generate anomaly precedent evidence; each anomaly precedent evidence has a corresponding precedent line graph. The query line graph, the reference line graph corresponding to normal control evidence, and the precedent line graph corresponding to abnormal precedent evidence are stitched together to generate a multimodal comparison evidence image. The multimodal comparison evidence image and the preset structured prompts are input into a preset multimodal large language model to generate time series anomaly monitoring results.

2. The method for monitoring timing anomalies in power distribution communication networks as described in claim 1, characterized in that, Periodically map the start time of the query window data to generate a query phase, including: The query phase is generated by performing a modulo operation based on the start time of the query window data and the preset main period.

3. The method for monitoring timing anomalies in power distribution communication networks as described in claim 2, characterized in that, The normal sequence knowledge base stores the reference phase corresponding to each knowledge base entry; Based on the query phase, a phase alignment filter is performed on a pre-defined normal sequence knowledge base to generate reference entries. All reference entries are then combined to generate a phase alignment candidate set, including: Calculate the circumferential distance between the query phase and the reference phase corresponding to each knowledge base entry in the preset normal sequence knowledge base; Knowledge base entries whose circumferential distance meets the preset tolerance threshold are identified as reference entries; Combine all reference entries to generate a phase alignment candidate set.

4. The method for monitoring timing anomalies in power distribution communication networks as described in claim 3, characterized in that, Visually render the data in the query window to generate a query line chart; Multimodal feature extraction is performed on the query window data to generate a query multimodal feature vector, including: The query window data is mapped to a two-dimensional polyline image data according to the time series, and a query line chart is generated. Extract the query numerical feature vector from the query window data; The query window data is converted into angular field images and reproduced images, respectively. The angle field image and the reproduced image are input into a preset visual encoder to extract the embedding vector of the query angle field image and the embedding vector of the query reproduced image, respectively. The query numerical feature vector, the query angle field image embedding vector, and the query reproduced image embedding vector are combined to generate a query multimodal feature vector.

5. The method for monitoring timing anomalies in power distribution communication networks as described in claim 4, characterized in that, The normal sequence knowledge base stores the reference numerical feature vector, the reference angle field image embedding vector, and the reference reproduction image embedding vector corresponding to each knowledge base entry. Calculate the multimodal feature similarity between the query's multimodal feature vector and each reference entry in the phase-aligned candidate set, including: For each reference entry in the phase alignment candidate set, calculate the numerical feature similarity between the query numerical feature vector and the reference numerical feature vector corresponding to the current reference entry. Calculate the similarity of angular field features between the query angular field image embedding vector and the reference angular field image embedding vector corresponding to the current reference entry; Calculate the similarity of reproduction features between the query reproduced image embedding vector and the reference reproduced image embedding vector corresponding to the current reference entry; Based on the preset weight ratio, the numerical feature similarity, angular field feature similarity, and recurrence feature similarity corresponding to each reference item are weighted and summed to generate the multimodal feature similarity corresponding to each reference item.

6. The method for monitoring timing anomalies in power distribution communication networks as described in claim 5, characterized in that, The abnormal sequence knowledge base stores the abnormal multimodal feature vectors corresponding to each abnormal knowledge base entry; Based on the query line graph, a preliminary diagnosis of anomaly types is performed to generate suspected anomaly types; Based on the suspected anomaly type, a search is performed from a pre-defined anomaly sequence knowledge base to generate anomaly precedent evidence, including: The query line graph is input into a preset lightweight diagnostic model for processing, the abnormality category corresponding to the query line graph is identified, and the identified abnormality category is determined as a suspected abnormality type. Based on the suspected anomaly type, the preset anomaly sequence knowledge base is filtered by type matching to extract anomaly knowledge base entries that match the suspected anomaly type. Combine all anomaly knowledge base entries that match the suspected anomaly type to generate an anomaly type candidate set; Calculate the multimodal feature similarity between the query multimodal feature vector and the multimodal feature vector corresponding to each anomaly knowledge base entry in the anomaly type candidate set; The candidate set of anomaly types is sorted according to the similarity of the anomaly multimodal features, and the anomaly knowledge base entries that meet the preset ranking requirements are identified as anomaly precedent evidence.

7. The method for monitoring timing anomalies in power distribution communication networks as described in claim 6, characterized in that, The query line graph, the reference line graph corresponding to normal control evidence, and the precedent line graph corresponding to abnormal precedent evidence are stitched together to generate a multimodal comparison evidence image. Multimodal contrastive evidence images and pre-defined structured cue words are input into a pre-defined multimodal large language model to generate temporal anomaly detection results, including: The query line graph is used as the central target graph. The reference line graphs corresponding to the normal comparison evidence are arranged on one side of the central target graph, and the precedent line graphs corresponding to the abnormal precedent evidence are arranged on the other side of the central target graph. The stitching operation is performed to generate a multimodal comparison evidence image. The multimodal comparison evidence images and preset structured prompts are input into a preset multimodal large language model, so that the multimodal large language model can generate time series anomaly monitoring results based on the multimodal comparison evidence images and preset structured prompts.

8. A timing anomaly monitoring device for power distribution communication networks, characterized in that, include: The module includes a data preprocessing module, a normal control retrieval module, an abnormal precedent retrieval module, and a multimodal reasoning monitoring module. The data preprocessing module is used to acquire the real-time round-trip delay sequence stream of the object to be monitored in the power distribution communication network; extract the data of the real-time round-trip delay sequence stream within a preset query window, and generate query window data; Periodically map the start time of the query window data to generate a query phase; The normal control retrieval module is used to perform phase alignment filtering on a preset normal sequence knowledge base based on the query phase, generate reference entries, and combine all reference entries to generate a phase alignment candidate set; wherein, each reference entry has a corresponding reference line graph; perform visual rendering on the query window data to generate a query line graph; extract multimodal features from the query window data to generate a query multimodal feature vector; calculate the multimodal feature similarity between the query multimodal feature vector and each reference entry in the phase alignment candidate set; sort the phase alignment candidate set according to the multimodal feature similarity, and determine the reference entries whose ranking meets the preset ranking requirements as normal control evidence; The abnormal precedent retrieval module is used to perform preliminary diagnosis of abnormality type based on query line graph and generate suspected abnormality type; and to retrieve abnormal precedent evidence from a preset abnormal sequence knowledge base according to the suspected abnormality type; wherein, each abnormal precedent evidence has a corresponding precedent line graph. The multimodal reasoning monitoring module is used to stitch together the query line graph, the reference line graph corresponding to normal control evidence, and the precedent line graph corresponding to abnormal precedent evidence to generate a multimodal comparison evidence image; and input the multimodal comparison evidence image and preset structured prompts into a preset multimodal large language model to generate time series anomaly monitoring results.

9. An electronic device, characterized in that, The method includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor executes the computer program to implement the timing anomaly monitoring method for power distribution communication networks as described in any one of claims 1 to 7.

10. A storage medium, characterized in that, The storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device where the storage medium is located to perform the power distribution communication network timing anomaly monitoring method as described in any one of claims 1 to 7.