Data processing method and device for distributed micro-grid cyber-physical system
Patent Information
- Application Number
- CN202611049432.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-15
- Publication Date
- 2026-09-11
- Estimated Expiration
- 2046-07-15
AI Technical Summary
[0003]传统技术中,对微电网的安全防护措施,主要集中于物理设备的硬保护和通信通道的加密传输,缺乏对边缘侧人工智能模型自身脆弱性的针对性防护
[0010]上述分布式微电网信息物理系统的数据处理方法、装置、计算机设备、存储介质和计算机程序产品,
Smart Images

Figure CN122572803B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of distributed power grid technology, and in particular to a data processing method, apparatus, computer equipment, storage medium and computer program product for a distributed microgrid cyber-physical system. Background Technology
[0002] With the rapid development of the energy internet and advanced metering systems, distributed microgrids, especially high-reliability microgrids supplying power to critical facilities such as data centers and hospitals, are increasingly exposed to new and severe cybersecurity threats due to their highly distributed intelligence and networking. Attackers may exploit the limited resources and relatively weak security of edge devices to launch attacks. Because the nodes within a microgrid are tightly coupled through power and information networks, abnormal decisions by a single node can spread rapidly through power interaction and state correlation, ultimately jeopardizing the synchronous operation and global power balance of the entire microgrid. Therefore, it is necessary to implement corresponding data protection.
[0003] Traditional technologies primarily focus on hardware protection of physical devices and encrypted transmission of communication channels for microgrid security, lacking targeted protection against the inherent vulnerabilities of edge-side AI models. Summary of the Invention
[0004] Therefore, it is necessary to provide a data processing method, apparatus, computer equipment, computer-readable storage medium, and computer program product for a distributed microgrid cyber-physical system that can solve the above-mentioned technical problems.
[0005] Firstly, this application provides a data processing method for a distributed microgrid cyber-physical system. The method includes: At the edge node, a global prediction model and a digital twin verification model are run synchronously to obtain the residual sequence of the edge node; wherein, the global prediction model is based on data-driven calculation, the digital twin verification model is based on physical laws for simulation calculation, the input of the digital twin verification model and the global prediction model is the same, and the residual sequence represents the difference between the outputs of the global prediction model and the digital twin verification model respectively. When the residual sequence triggers the adaptive threshold, the fused evidence feature vector containing the residual sequence is input into the anomaly classification model of the edge node, and the anomaly type of the edge node is output; wherein, the anomaly type includes data poisoning attack, prediction model tampering, physical equipment failure and benign operating condition change; Perform data processing actions that match the anomaly type, including rolling back the version of the global prediction model, enhancing the aggregation constraints in the edge nodes, and recording the data processing results in the edge nodes.
[0006] Secondly, this application also provides a data processing device for a distributed microgrid cyber-physical system. The device includes: A synchronous operation module is used to synchronously run a global prediction model and a digital twin verification model on edge nodes to obtain the residual sequence of the edge nodes; wherein, the global prediction model is based on data-driven calculation, the digital twin verification model is based on physical laws for simulation calculation, the input of the digital twin verification model and the global prediction model is the same, and the residual sequence represents the difference between the outputs of the global prediction model and the digital twin verification model respectively. The classification module is used to input the fused evidence feature vector containing the residual sequence into the anomaly classification model of the edge node when the residual sequence triggers an adaptive threshold, and output the anomaly type of the edge node; wherein, the anomaly type includes data poisoning attack, prediction model tampering, physical equipment failure and benign operating condition change; An execution module is used to perform data processing actions that match the anomaly type. The data processing actions include rolling back the version of the global prediction model, enhancing the aggregation constraints in the edge nodes, and recording the data processing results in the edge nodes.
[0007] Thirdly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the above method steps.
[0008] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, implements the above method steps.
[0009] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the above method steps.
[0010] The data processing methods, devices, computer equipment, storage media, and computer program products of the aforementioned distributed microgrid cyber-physical systems At the edge nodes, the global prediction model and the digital twin verification model are run synchronously to obtain the residual sequence of the edge nodes. The global prediction model is based on data-driven calculation, while the digital twin verification model is based on physical laws for simulation calculation. The inputs of the digital twin verification model and the global prediction model are the same, and the residual sequence represents the difference between the outputs of the global prediction model and the digital twin verification model.
[0011] By introducing a digital twin model based on physical laws as an immutable reference frame, and simultaneously comparing it with a vulnerable data-driven global prediction model, edge nodes no longer rely solely on external signatures or encryption. Instead, they utilize physical consistency for runtime self-checks, embedding security capabilities into the prediction process and proactively discovering highly concealed internal threats.
[0012] When the residual sequence triggers the adaptive threshold, the fused evidence feature vector containing the residual sequence is input into the anomaly classification model of the edge node, and the anomaly type of the edge node is output. The anomaly type includes data poisoning attack, prediction model tampering, physical equipment failure and benign operating condition change.
[0013] First, edge nodes do not need to continuously run complex anomaly detection algorithms; instead, they only calculate the difference between the outputs of the two models, i.e., the residual sequence. Subsequent high-dimensional feature fusion and classification models are only initiated when the residual triggers an adaptive threshold. This significantly saves the scarce CPU computing power and battery power at the edge, solving the challenge of security monitoring under resource constraints.
[0014] Secondly, anomalies are precisely categorized into four types: data poisoning, model tampering, physical failure, and benign mutation. By fusing residual features with the classification model, the traditional single-model approach avoids treating all deviations as attacks, significantly reducing the interference of false alarms on operations and maintenance personnel.
[0015] Perform data processing actions that match the anomaly type. These actions include rolling back the version of the global prediction model, enhancing aggregation constraints in edge nodes, and recording data processing results in edge nodes.
[0016] When the model is tampered with, the version can be rolled back to achieve recovery within seconds. When data poisoning occurs, the aggregation constraints are enhanced to isolate the poison without taking the node offline. When a fault or mutation occurs, it is recorded and left for subsequent analysis. This isolation strategy minimizes the mishandling of normal prediction tasks.
[0017] This method can accurately detect abnormal predictive behavior, intelligently diagnose attack types and perform targeted self-healing. Its execution results further form a feedback loop, thereby significantly improving the overall resilience, operational reliability and power balance stability of distributed microgrids in the face of complex attacks such as data poisoning and model theft. Attached Figure Description
[0018] Figure 1 This is a flowchart illustrating a data processing method for a distributed microgrid cyber-physical system in one embodiment. Figure 2 This is a flowchart illustrating a method for determining a global prediction model in one embodiment; Figure 3This is a structural block diagram of a data processing device for a distributed microgrid cyber-physical system in one embodiment. Figure 4 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0020] In one embodiment, such as Figure 1 As shown, a data processing method for a distributed microgrid cyber-physical system is provided, specifically including: S101, on the edge nodes, the global prediction model and the digital twin verification model are run synchronously to obtain the residual sequence of the edge nodes.
[0021] Edge nodes refer to computing entities located at the network edge, such as industrial gateways, smart routers, embedded AI boxes, and base station edge servers. Edge nodes are deployed close to data sources, such as sensors, cameras, and PLC controllers, and are responsible for performing data acquisition, preprocessing, and real-time inference locally to reduce cloud communication latency and bandwidth pressure.
[0022] A global prediction model refers to a model trained using a data-driven approach. This model can predict the power of edge nodes in real time based on sensor data from those nodes.
[0023] A digital twin verification model is a simulation calculation model built based on physical laws or mechanisms. Digital twin verification models do not rely on historical data for training, but rather deduce the theoretical output value of the system, such as the predicted power of edge nodes, based on the current input physical parameters and through mathematical physical variance.
[0024] The inputs to both the digital twin verification model and the global prediction model are the same: real-time sensor data acquired by edge nodes.
[0025] A residual sequence represents the difference between the outputs of the global prediction model and the digital twin verification model. In other words, under the same input, the residual sequence is the sequence of differences between the outputs of the global prediction model and the digital twin verification model arranged in chronological order.
[0026] Specifically, S101 includes: synchronously running a pre-built digital twin verification model and a global prediction model on the edge node to obtain the future power prediction value output by the global prediction model and the power verification value output by the digital twin verification model; and determining the residual sequence of the edge node based on the difference between the future power prediction value and the power verification value corresponding to each of the multiple sampling points.
[0027] Specifically, S101 includes: synchronously running a digital twin verification model and a global prediction model at the edge node to obtain a first output of the digital twin verification model and a second output of the global prediction model; both the first and second outputs are discrete values of the target physical quantity that change over time; for the same target physical quantity, the difference between the discrete values of the first and second outputs is determined as a residual sequence. Target physical quantities include power, current, voltage, etc.
[0028] Specifically, prior to S101, the steps for determining the global prediction model include: acquiring multiple sensor data points from edge nodes and configuring local prediction models for each sensor data point; wherein, the local prediction models are used to output multiple power prediction values for edge nodes based on the sensor data; constructing update packages for edge nodes based on consensus-verified sensor data, model update parameters of the local prediction models for edge nodes, and data storage proofs of the consensus-verified sensor data; wherein, the model update parameters are model parameters obtained by training the local prediction models based on consensus-verified sensor data; aggregating the update packages corresponding to each edge node according to a dynamic evaluation strategy to obtain the global prediction model corresponding to each edge node; the global prediction model is used to replace each local prediction model.
[0029] First, the residual abstracts the high-dimensional outputs of two complex models into a concise difference index, greatly reducing the feature dimensions required for subsequent anomaly detection and adapting to the lightweight deployment requirements of edge nodes. Second, different anomaly types, such as data poisoning, model tampering, physical failures, and benign mutations, exhibit different fluctuation patterns in the residual sequence, such as sudden jumps, gradual changes, and periodic disorder. This provides highly discriminative feature basis for subsequent anomaly classification models.
[0030] S102, when the residual sequence triggers the adaptive threshold, the fused evidence feature vector containing the residual sequence is input into the anomaly classification model of the edge node, and the anomaly type of the edge node is output.
[0031] Here, the adaptive threshold represents a dynamic threshold calculated using a threshold generation function to determine the residual sequence. If the rate of change of the residual sequence exceeds the adaptive threshold, the residual sequence is considered to have triggered the adaptive threshold; conversely, if the rate of change of the residual sequence does not exceed the adaptive threshold, the residual sequence is considered not to have triggered the adaptive threshold.
[0032] The fused evidence feature vector is a multi-dimensional comprehensive feature representation that not only includes the residual sequence itself but also integrates data layer features, pattern contribution features, and residual pattern features (including the residual sequence). Relying solely on residual values can easily misclassify data latency caused by network fluctuations as data poisoning. The fused feature introduces contextual information about the system's runtime state, enabling the anomaly classification model to make comprehensive judgments based on a richer chain of evidence, significantly reducing the risk of misclassification.
[0033] An anomaly classification model represents a lightweight machine learning classifier deployed on edge nodes, such as a decision tree, random forest, LightGBM (Lightweight Gradient Boosting Tree), or a small neural network with pruned quantization. The input to an anomaly classification model is a fused evidence feature vector, and the output is a discrete anomaly category label.
[0034] Anomaly type indicates the specific output label type of the anomaly classification model. Anomaly types include data poisoning attacks, prediction model tampering, physical equipment failures, and sudden changes in benign operating conditions.
[0035] It should be noted that if the anomaly type is data poisoning attack, it means that the input data has been maliciously constructed or contaminated, such as through sensor signal injection or adversarial examples, causing the global prediction model output to deviate from physical reality. If the anomaly type is prediction model tampering, it means that the model parameters or inference logic have been maliciously altered, such as through backdoor implantation or parameter hijacking, making the model itself unreliable. If the anomaly type is physical equipment failure, it means that physical components such as sensors and actuators have aged, drifted, or been damaged, causing the input data to be distorted, and the simulation under the constraints of physical laws also deviates from the true state. If the anomaly type is benign operating condition change, it means that the system has experienced drastic changes in operating conditions (such as start-up, shutdown, or load jumps), causing the residuals to deviate temporarily, but the system itself poses no security threat.
[0036] Understandably, data poisoning attacks and prediction model tampering can be classified under the same anomaly category. If the anomaly type is data poisoning attack and prediction model tampering, it means that the input data has been maliciously constructed or contaminated, and the model parameters or inference logic have been maliciously tampered with.
[0037] Specifically, the method for determining the adaptive threshold includes: after obtaining the specific anomaly type, performing data processing actions that match the anomaly type; monitoring the target monitoring indicators of each edge node after performing the data processing actions to obtain feedback reward signals; and adjusting the adaptive threshold based on the feedback reward signals.
[0038] Specifically, the method for obtaining fused evidence features based on residual sequences includes: acquiring data layer features, model contribution features, and residual pattern features, wherein the residual pattern features contain the residual sequence; and concatenating the features based on the data layer features, model contribution features, and residual pattern features to obtain a fused evidence feature vector containing the residual sequence.
[0039] First, once the anomaly type is clearly identified, operations and maintenance personnel or automated control strategies can execute corresponding data processing actions, rather than applying the same emergency response to all anomalies, thus avoiding deviations in handling. Second, classifying benign operational condition changes as a separate type means the system can identify and tolerate legitimate drastic changes in operational conditions, preventing false triggering of safety circuit breakers due to residual jumps during normal production scheduling and ensuring business continuity. Third, edge nodes do not need to continuously run complex anomaly detection algorithms; instead, they only calculate the difference between the outputs of two models, i.e., the residual sequence. Subsequent high-dimensional feature fusion and classification models are only initiated when the residual triggers an adaptive threshold. This significantly saves on the scarce CPU computing power and battery power at the edge, solving the problem of security monitoring under resource constraints. Fourth, anomalies are accurately located into four categories: data poisoning, model tampering, physical failure, and benign mutations. Through the fusion and inference of residual features and classification models, the traditional single-model approach of treating all deviations as attacks is avoided, significantly reducing the interference of false alarms on operations and maintenance personnel.
[0040] S103, execute data processing actions that match the anomaly type. Data processing actions include rolling back the version of the global prediction model, enhancing aggregation constraints in edge nodes, and recording data processing results in edge nodes.
[0041] Data processing actions refer to a series of strategic response operations automatically triggered by edge nodes after identifying specific anomaly types. These actions can be closed-loop control commands that directly affect the prediction system itself or its data flow paths, aiming to block threat spread, restore the system's trusted state, or retain forensic information. Compared to traditional solutions that stop at reporting alerts, executing data processing actions corresponding to anomaly types enables edge nodes to possess a complete closed-loop capability of perception, judgment, and handling, achieving self-healing intrinsic security.
[0042] Rolling back the version of the global prediction model means that when the anomaly classification model determines that the anomaly type is prediction model tampering and / or data poisoning attack, the edge node immediately performs targeted isolation and rollback.
[0043] This includes marking invalid data in a lightweight DAG ledger network and restoring the global model from a secure repository. Marking invalid data involves issuing a special transaction to the DAG ledger network, marking the ledger record identifier associated with the physical fingerprint corresponding to the abnormal period as "untrusted," so subsequent queries will return an invalid status. Restoring the global model from the secure repository means retrieving the previous stable version from a secure storage maintained by the aggregation server that only stores historical global model versions that have undergone multiple rounds of verification and have received positive contribution evaluations, forcibly distributing it and replacing the current local prediction model of the edge node. The rollback process typically employs atomic operations, i.e., a one-time switch, ensuring that no intermediate prediction outputs are generated during the switch.
[0044] Enhanced aggregation constraints in edge nodes indicate that when the anomaly type is determined to be a physical device failure, enhanced monitoring is initiated for the edge node and its contribution to safe aggregation in model updates is temporarily limited.
[0045] Enabling enhanced monitoring could involve doubling the frequency of data verification for the edge node and temporarily lowering the first weighting coefficient in the adaptive threshold generation function (used to determine the adaptive threshold) by 0.1 to make the judgment more sensitive. Limiting contribution could mean that in the next training cycle of the local prediction model, the aggregate weight of the edge node would be forcibly set to 0.1 times the original calculated value, significantly reducing its impact.
[0046] Recording the data processing results in edge nodes can indicate that when the anomaly type is determined to be a benign change in operating conditions, isolation will not be performed temporarily, and the event will only be recorded for subsequent parameter optimization.
[0047] The "record" process involves storing the fused evidence feature vector, the probability distribution output by the classification model, the confidence level, the final anomaly type label, and subsequent microgrid state observation results within a short period as a sample in a dedicated online learning sample library. Specifically, after performing data processing actions, the target monitoring indicators of each edge node can be monitored to obtain feedback reward signals. Based on these feedback reward signals, the confidence weight coefficient, smoothing factor, and adaptive threshold are adjusted. The confidence weight coefficient and smoothing factor can be indicators used to evaluate the local prediction model of the edge nodes.
[0048] In the data processing method of the above-mentioned distributed microgrid cyber-physical system, a global prediction model and a digital twin verification model are run synchronously at the edge nodes to obtain the residual sequence of the edge nodes. The global prediction model is based on data-driven calculation, while the digital twin verification model is based on physical laws for simulation calculation. The inputs of the digital twin verification model and the global prediction model are the same, and the residual sequence represents the difference between the outputs of the global prediction model and the digital twin verification model.
[0049] By introducing a digital twin model based on physical laws as an immutable reference frame, and simultaneously comparing it with a vulnerable data-driven global prediction model, edge nodes no longer rely solely on external signatures or encryption. Instead, they utilize physical consistency for runtime self-checks, embedding security capabilities into the prediction process and proactively discovering highly concealed internal threats.
[0050] When the residual sequence triggers the adaptive threshold, the fused evidence feature vector containing the residual sequence is input into the anomaly classification model of the edge node, and the anomaly type of the edge node is output. The anomaly type includes data poisoning attack, prediction model tampering, physical equipment failure and benign operating condition change.
[0051] First, edge nodes do not need to continuously run complex anomaly detection algorithms; instead, they only calculate the difference between the outputs of the two models, i.e., the residual sequence. Subsequent high-dimensional feature fusion and classification models are only initiated when the residual triggers an adaptive threshold. This significantly saves the scarce CPU computing power and battery power at the edge, solving the challenge of security monitoring under resource constraints.
[0052] Secondly, anomalies are precisely categorized into four types: data poisoning, model tampering, physical failure, and benign mutation. By fusing residual features with the classification model, the traditional single-model approach avoids treating all deviations as attacks, significantly reducing the interference of false alarms on operations and maintenance personnel.
[0053] Perform data processing actions that match the anomaly type. These actions include rolling back the version of the global prediction model, enhancing aggregation constraints in edge nodes, and recording data processing results in edge nodes.
[0054] When the model is tampered with, the version can be rolled back to achieve recovery within seconds. When data poisoning occurs, the aggregation constraints are enhanced to isolate the poison without taking the node offline. When a fault or mutation occurs, it is recorded and left for subsequent analysis. This isolation strategy minimizes the mishandling of normal prediction tasks.
[0055] This method utilizes a digital twin verification model and an adaptive threshold generation function for real-time consistency verification, enabling accurate detection of abnormal prediction behaviors. It can intelligently diagnose attack types and perform targeted self-healing. The execution results further form a feedback loop, thereby significantly improving the overall resilience, operational reliability, and power balance stability of distributed microgrids when facing complex attacks such as data poisoning and model theft.
[0056] In one embodiment, prior to S101, the method further includes: S201 acquires multiple sensor data from edge nodes, as well as local prediction models configured for each sensor data.
[0057] The local prediction model is used to output multiple power prediction values for edge nodes based on sensor data.
[0058] Sensor data refers to the digitized time-series signals collected by various physical sensors deployed around edge nodes. Sensor data reflects the current physical operating status and environmental conditions of the monitored system, such as wind turbines, photovoltaic arrays, and generator sets.
[0059] A local prediction model refers to a lightweight artificial intelligence model that runs on an edge node and is trained or configured for a specific type of sensor data or a specific device unit (such as a single wind turbine or a single photovoltaic string). This model typically employs a time-series prediction architecture, taking historical sensor data sequences as input and outputting physical quantities (such as power) at future moments.
[0060] Power prediction: The local prediction model is a quantitative estimate of the electrical power output by the devices under the jurisdiction of the edge node within a specific future time window (such as the next 15 minutes, 4 hours, or the entire next day) based on current and historical sensor data.
[0061] Specifically, acquiring multiple sensing data from edge nodes in S201 includes: for each edge node, acquiring sensing data from the electrical connection point associated with the edge node at the same sampling time.
[0062] Specifically, after obtaining the sensor data, the physical consistency verification result corresponding to the sensor data can be calculated based on the preset physical laws and the local network topology relationship where the edge node is located; the physical fingerprint of the sensor data is broadcast to the ledger network and stored and verified through consensus to obtain the sensor data that has passed the consensus verification; wherein, the physical fingerprint includes the physical consistency verification result and the digital signature used to identify the physical consistency verification result.
[0063] S202, based on the consensus-verified sensor data, the model update parameters of the local prediction model of the edge node, and the data storage proof of the consensus-verified sensor data, construct the update package of the edge node.
[0064] Among them, consensus-verified sensor data refers to sensor data uploaded by edge nodes that has been formally accepted as trusted data after its authenticity, integrity, and temporal consistency have been confirmed by a multi-party consensus mechanism. The consensus verification process includes verifying digital signatures and performing physical consistency verification.
[0065] Model update parameters are the model parameters obtained by training the local prediction model based on consensus-verified sensor data. Specifically, model update parameters refer to the parameters of the model obtained by incrementally training the current local prediction model using consensus-verified clean sensor data as the training set.
[0066] Data proof of evidence refers to a cryptographically non-repudiable credential generated from sensor data verified through consensus.
[0067] An update package represents a delivery unit that packages consensus-based sensor data, model update parameters, and data storage proofs according to a standard protocol. This delivery unit can be securely transmitted to the cloud center or distributed to other edge nodes within the collaboration group, and can be used for global model aggregation updates.
[0068] Specifically, the consensus verification process for sensor data in S202 may include: calculating the physical consistency verification result corresponding to the sensor data based on the preset physical laws and the local network topology relationship where the edge node is located; broadcasting the physical fingerprint of the sensor data to the ledger network and performing notarization and consensus verification to obtain the sensor data that has passed the consensus verification; wherein, the physical fingerprint includes the physical consistency verification result and the digital signature used to identify the physical consistency verification result.
[0069] For example, the process of determining the encrypted model update parameters includes: After each edge node completes local prediction model training in each training cycle, it encrypts the model update generated during this training using the homomorphic encryption public key published by the aggregation server, resulting in an encrypted model update. The encryption process uses an additive homomorphic encryption algorithm, such as the Paillier algorithm. The encryption process is as follows: the edge node first converts each floating-point value in the model update parameter vector into a sufficiently large integer to prevent precision loss. Then, it uses the Paillier algorithm's encryption function, with the aggregation server's public key, to independently encrypt each integer, generating corresponding ciphertext. All ciphertexts, arranged in their original order, constitute the encrypted model update.
[0070] The process of determining digital evidence proof includes: For each batch of verified local sensor data with valid ledger record identifiers used in this training cycle, all ledger record identifiers associated with that batch of local sensor data are extracted. A Merkle tree is then constructed based on these ledger record identifiers, and the root hash value of the Merkle tree is used as the data verification proof for that batch of training data. The process of constructing the Merkle tree is as follows: all ledger record identifiers in the batch are used as leaf nodes, and their hash values are calculated pairwise. The resulting hash value is used as the parent node of the next level. If the number of nodes in a level is odd, the last node is copied and then paired again. This pairwise hash calculation and the operation at the next level are repeated until a unique root node hash value is generated. This root hash value is the root hash value of the Merkle tree.
[0071] After obtaining the encrypted model update parameters and data storage proofs, an update packet is formed by packaging together the edge node's unique node identifier, the current training cycle number used to identify the training order, the encrypted model update parameters, and a list of data storage proofs for all batches, and attaching a digital signature generated using the edge node's private key. The digital signature generation process is as follows: First, the node identifier, training cycle number, encrypted model update byte stream, and data storage proof list byte stream are concatenated into a complete message byte stream in a predetermined order; then, the hash digest of this message byte stream is calculated using the SM3 hash algorithm; finally, the hash digest is signed using the elliptic curve digital signature algorithm and the edge node's private key to generate the digital signature. Packaging refers to encoding and serializing all the aforementioned components according to a predefined TLV format to generate a complete, transmittable update packet data unit.
[0072] S203, based on the dynamic evaluation strategy, aggregate the update packages corresponding to each edge node to obtain the global prediction model corresponding to each edge node.
[0073] The global prediction model is used to replace each local prediction model.
[0074] The dynamic evaluation strategy refers to an evaluation mechanism that dynamically calculates the aggregation weight of each node based on its real-time status indicators when aggregating update packages uploaded by each edge node.
[0075] The global prediction model refers to a unified prediction model that integrates the knowledge of all edge nodes in the network, generated by weighting and aggregating the update packets uploaded by each edge node according to a dynamic evaluation strategy.
[0076] Specifically, S203 includes: for each edge node's local prediction model, obtaining a common validation set containing data from various typical operating conditions, and a dynamic credibility evaluation term including credibility weight coefficients and smoothing factors; wherein, the credibility weight coefficients represent the weight of the data proof verification pass rate in the aggregation process, and the smoothing factor is used to control the ratio between credibility values of adjacent training times; based on the common validation set, determining the model update quality evaluation value of the local prediction model; based on the dynamic credibility evaluation term and the model update quality evaluation value, determining the aggregation weight of each local prediction model; and performing aggregation processing according to the aggregation weights of each local prediction model and the model update parameters of each local prediction model to obtain the global prediction model corresponding to each edge node.
[0077] The aggregation process here can be visualized as follows: a centralized aggregation server receives update packets from multiple edge nodes; each update packet contains an encrypted model update and a proof pointing to trusted data on the chain; after verifying the proof, the aggregation server performs a weighted fusion of all model update parameters in the encrypted state to generate a new global model. This constitutes a central-edge collaborative model training architecture.
[0078] In this embodiment, the global prediction model is used to replace each local prediction model, effectively addressing new security threats in distributed edge intelligence scenarios, ensuring the immutability and physical validity of the original sensor data, guaranteeing the security of global model updates, and suppressing the pollution of malicious nodes.
[0079] In one embodiment, the acquisition of multiple sensing data from edge nodes in S201 specifically includes: for each edge node, acquiring sensing data from the electrical connection point associated with the edge node at the same sampling time.
[0080] The data processing method for the aforementioned distributed microgrid information system further includes: calculating the physical consistency verification result corresponding to the sensor data based on preset physical laws and the local network topology relationship where the edge nodes are located; broadcasting the physical fingerprint of the sensor data to the ledger network for notarization and consensus verification to obtain the sensor data that has passed consensus verification.
[0081] Electrical connection points refer to the electrical interfaces / nodes in a distributed microgrid where edge nodes are directly connected to the physical power network, such as the grid connection point of a wind turbine, the combiner box access point of a photovoltaic string, the AC side port of an energy storage system, and the switchgear measurement point at a feeder branch.
[0082] Predefined physical laws represent the fundamental physical and circuit principles that govern the operation of the power system and are hard-coded into the verification logic of edge nodes. For example, preset physical laws include Kirchhoff's current / voltage laws, Ohm's law, power balance equations, and power flow equations.
[0083] Local network topology represents the local physical connection structure of the microgrid where the edge nodes are located. Specifically, it includes: the line connection relationship between nodes (tree-ring structure of bus-line-load), line impedance parameters (resistance R, reactance X), electrical distance between nodes and upstream and downstream hierarchical relationship, and the current open / closed state of switches / circuit breakers, etc.
[0084] The physical consistency verification result represents a quantitative confidence index or consistency judgment vector output after substituting the actual collected sensor data into preset physical laws and local network topology relationships for calculation.
[0085] This calculation process can be completed by a data preprocessing module deployed at the edge node. This process directly addresses the core security issue in distributed microgrids where network attacks (such as data poisoning) or equipment failures can distort raw measurement data. By performing an initial screening of the raw data based on physical laws, malicious data that clearly violates circuit laws is intercepted at the source, providing a reliable data foundation for subsequent power prediction and regulation.
[0086] A physical fingerprint is a fixed-length digital digest that uniquely identifies a batch of data and its physical consistency status, extracted using cryptographic hash functions or physically unclonable functions based on sensor data and its physical consistency verification results.
[0087] Specifically, a physical fingerprint includes a physical consistency verification result and a digital signature used to identify the physical consistency verification result.
[0088] Specifically, based on preset physical laws and the local network topology of the edge nodes, the physical consistency verification result corresponding to the sensor data is calculated. This includes: summing all current measurements from electrical connection points according to Kirchhoff's current law, and using the absolute value of the deviation between the summation result and the theoretical zero value as the physical consistency verification result. For example, for a bus node connecting a photovoltaic inverter, an energy storage converter, and a load, the sum of its real-time collected injected currents should be close to zero, and the verification result is the absolute value of this summation.
[0089] Specifically, the process of determining the physical fingerprint of sensor data includes: calculating the cryptographic hash value of the original sensor data using the national cryptographic SM3 hash algorithm; digitally signing the physical consistency verification result using the private key of the edge node; and defining the structured data packet containing the unique node identifier, sampling time, cryptographic hash value, and digital signature of each edge node as the physical fingerprint of the sensor data.
[0090] Specifically, the physical fingerprint of the sensor data is broadcast to the ledger network for notarization and consensus verification, resulting in sensor data that has passed consensus verification, including: Upon receiving the physical fingerprint of the new broadcast, the validity of the digital signature in the physical fingerprint is verified through a lightweight DAG ledger network (i.e., evidence storage and consensus verification).
[0091] The process of verifying the validity of a digital signature is as follows: the verification node queries the corresponding public key from the list of legitimate node public keys maintained locally based on the node identifier contained in the physical fingerprint. Then, using the same public key and the same elliptic curve digital signature algorithm, it decrypts and compares the physical consistency verification result and signature data contained in the physical fingerprint. Based on the preset physical laws and network topology relationship corresponding to the edge node that sent the physical fingerprint, it performs consistency verification on the physical consistency verification result contained in the physical fingerprint.
[0092] Among them, consistency verification determines whether the norm of the physical consistency verification result is less than a preset dynamic tolerance threshold. The dynamic tolerance threshold is adaptively set based on historical data statistics; the specific setting process is as follows: collect multiple physical consistency verification results generated by the edge node during historical normal and fault-free operation periods, calculate the statistical distribution of these results, and set the threshold as the average of the historical results plus three times the standard deviation; the norm calculation uses the L2 norm, that is, calculate the square root of the sum of squares of the physical consistency verification results; the dynamic tolerance threshold is usually set in the range of one-thousandth to one-hundredth of the rated value. For example, for current verification, the threshold can be set to 0.5% of the total rated current.
[0093] Only when the digital signature is valid and the consistency verification passes, is the physical fingerprint recognized as a legitimate evidence record by the lightweight DAG ledger network and given a unique ledger record identifier. At this point, the sensor data that has passed consensus verification is obtained.
[0094] The process of generating a unique ledger record identifier involves performing an SM3 hash operation on the verified physical fingerprint data unit itself, using the resulting hash value as the globally unique identifier for that record, i.e., the ledger record identifier. At this point, the original sensor data and its corresponding physical fingerprint are jointly considered as a trusted data source. The formation of a trusted data source means that the binding relationship between the original sensor data, its physical fingerprint, and the ledger record identifier is permanently recorded by the distributed ledger network. Any subsequent query and verification can trace back to this immutable record through the ledger record identifier. For distributed microgrids, this step constructs a traceable and tamper-proof "trusted data source" infrastructure covering the entire network. It solves the data source trust problem faced by distributed microgrids at the edge, ensuring reliable guarantees for all subsequent model training and decision-making based on this data. This is a prerequisite for achieving precise and coordinated power balance regulation.
[0095] The lightweight DAG ledger network here can be understood as a peer-to-peer network composed of multiple verification nodes. The network topology is distributed and there is no central server. Each edge node acts as a "client" and broadcasts its physical fingerprint to the network. The ledger structure is a directed acyclic graph. New transactions need to be verified and referenced from several previous transactions to form an irreversible chain, ensuring the timeliness and tamper-proof nature of the data.
[0096] In this embodiment, firstly, sensor data and physical consistency verification results are jointly bound to generate a physical fingerprint. This means that even if an attacker tampers with the sensor data, the generated physical fingerprint will be completely mismatched with the on-chain evidence version because the physical consistency verification result will inevitably change accordingly. This fundamentally eliminates the possibility of subsequently tampering with the data while retaining the original evidence. Secondly, the physical fingerprint uses a fixed-length hash value to represent the entire batch of data. The amount of data uploaded to the ledger network for evidence storage and consensus is extremely small, greatly reducing the storage pressure and consensus communication overhead of the blockchain network, enabling resource-constrained edge nodes to participate in blockchain evidence storage.
[0097] In one embodiment, step S203 above, based on a dynamic evaluation strategy, aggregates the update packages corresponding to each edge node to obtain a global prediction model for each edge node. Specifically, this includes: for each edge node's local prediction model, obtaining a common validation set containing data from various typical operating conditions, and a dynamic reliability evaluation term including reliability weight coefficients and smoothing factors. Based on the common validation set, determining the model update quality evaluation value of the local prediction model. Based on the dynamic reliability evaluation term and the model update quality evaluation value, determining the aggregation weights for each local prediction model. Aggregating the data according to the aggregation weights and model update parameters of each local prediction model to obtain the global prediction model corresponding to each edge node.
[0098] The public validation set is a standardized test dataset maintained centrally in the cloud and not used for local training on any edge nodes. This dataset covers various typical operating conditions that distributed microgrids may encounter (such as rated wind speed / low wind speed / cut-off wind speed, high irradiance / low irradiance / cloudy weather, full load / light load / impact load, etc.), and is used to fairly and objectively evaluate the true performance of the model update parameters uploaded by each edge node.
[0099] The model update evaluation value represents the performance of the model update parameters uploaded by a certain edge node on the public validation set.
[0100] Specifically, the model update quality assessment value of the local prediction model can be determined based on a public validation set.
[0101] For example, the specific process of the model update quality assessment value is as follows: The aggregation server uses its Paillier private key to decrypt the encrypted model update in an update package to obtain the plaintext model update parameters; this parameter is added to the current global model parameters to obtain a temporary model; forward inference prediction is performed on the public validation set using the temporary model, the prediction result is compared with the true value of the validation set, the percentage reduction of the mean squared error is calculated, and this percentage is used as the model update quality assessment value for this model update. This value ranges from negative 100% to positive infinity, and is usually truncated to the interval [-1, 1].
[0102] The dynamic credibility evaluation term represents the reputation value that changes dynamically with each training round. It preserves the long-term trust accumulation of nodes (through a smoothing factor that transmits historical information) while also incorporating current data verification results. This approach balances robustness and sensitivity, avoiding the bias associated with relying solely on single performance or historical records.
[0103] Specifically, dynamic credibility assessment items may include credibility weighting coefficients and smoothing factors.
[0104] The credibility weight coefficient represents the weight of the data proof verification pass rate in the aggregation process. Understandably, any attack will leave a trace in the consensus verification process (increasing the verification failure rate). The credibility coefficient allows these historical behaviors to directly affect the current aggregation weight; even if the current update performance metrics are high, if a node has a poor historical reputation, its aggregation influence will be significantly reduced.
[0105] The smoothing factor controls the ratio between confidence values in adjacent training iterations. Specifically, a larger smoothing factor means a greater influence of historical confidence on the current value (smoother performance), while a smaller smoothing factor means a greater influence on the current validation pass rate (more sensitive performance). When a node is under continuous attack, the validation pass rate will remain low for several consecutive rounds. A smaller smoothing factor can accelerate the decline in dynamic confidence, causing the confidence of malicious nodes to drop below the warning threshold in a shorter time, enabling rapid response and isolation of persistent threats.
[0106] Aggregate weights represent the weighted coefficients for the final model aggregation calculated by combining dynamic credibility assessment items and model update quality assessment values, balancing accuracy and safety.
[0107] Specifically, the dynamic credibility assessment item can be the product of the natural logarithm of the dynamic credibility value and a preset credibility weight coefficient.
[0108] The credibility weighting coefficient is a configurable hyperparameter, with a recommended value between 0.5 and 5, used to adjust the relative influence of credibility in the overall evaluation score (e.g., a default value of 1.5). The natural logarithmic value is calculated with the mathematical constant e as the base and the dynamic credibility value as the argument.
[0109] The dynamic credibility value is updated and calculated using an exponential moving average method based on the success rate sequence of data storage proofs submitted by edge nodes in the past training cycles in the lightweight DAG ledger network.
[0110] The calculation formula updated using the exponential moving average method is: the new dynamic confidence value equals the smoothing factor multiplied by the old dynamic confidence value, plus the difference between the smoothing factor and the current verification pass rate.
[0111] The smoothing factor is a decimal between zero and one, and can take the value of 0.9. It is used to control the weight ratio between historical information and current information.
[0112] The pass rate for this verification is the percentage of ledger record identifiers corresponding to all data storage proofs in this update package that are valid after being queried in the lightweight DAG ledger network.
[0113] The initial value of the dynamic credibility value can be set to one.
[0114] Specifically, after aggregating the aggregated weights and model update parameters of each local prediction model, a global prediction model corresponding to each edge node is obtained, which includes: In the aggregation server, the encrypted model update parameters in the update package of the local prediction model can be directly weighted and summed according to the calculated corresponding aggregation weights to obtain the global model update parameters in an encrypted state. Then, the parameters are decrypted to obtain the plaintext global model update parameters. Finally, this update is applied to the previous round of global model to generate a new global prediction model.
[0115] The weighted summation process, utilizing the homomorphic encryption algorithm's characteristics, specifically applies to the Paillier algorithm: Since the Paillier algorithm supports additive homomorphism and constant-multiplication homomorphism in ciphertext, each encrypted model update is treated as a ciphertext vector, and the calculated aggregate weights are considered constants. The weighted summation operation involves performing a constant multiplication (multiplying by the corresponding aggregate weight) on each ciphertext vector, then summing all weighted ciphertext vectors element-wise to obtain a new ciphertext vector, which represents the global model update parameters in the encrypted state. The subsequent decryption operation uses the Paillier private key to decrypt each element of this new ciphertext vector, obtaining the plaintext global model update parameter vector; this parameter vector is then added to the parameter vector of the previous round of the global model to generate a new global prediction model.
[0116] First, homomorphic encryption ensures that the model parameters uploaded by nodes are not spied on by the aggregation server or other nodes, preventing model theft attacks. Second, the dynamic evaluation strategy combines model quality with the credibility of historical data, automatically reducing the update weights from nodes with questionable data or poor model quality (which may be malicious or faulty nodes), thereby suppressing their pollution of the global model. This ensures that the final global (power) prediction model distributed to each edge node is accurate and robust, serving as the common intelligent basis for each node to make independent and parallel power regulation decisions.
[0117] Specifically, the target monitoring indicators of each edge node after performing data processing actions can be monitored to obtain feedback reward signals; based on the feedback reward signals, the credibility weight coefficient and smoothing factor can be adjusted.
[0118] In this embodiment, firstly, a public validation set containing data from various typical operating conditions is obtained. Based on this set, the model update quality assessment value of the local prediction model is determined, ensuring that the performance of each node's model can be fairly compared under identical operating conditions, eliminating evaluation bias caused by differences in local data distribution. Secondly, based on the dynamic credibility assessment item and the model update quality assessment value, the aggregation weight of each local prediction model is determined, balancing model performance (model update quality assessment value) and data security. Thirdly, the model update parameters of each local prediction model are aggregated based on the aggregation weights to obtain the global prediction model corresponding to each edge node. Through weighted aggregation, high-performance and high-reputation nodes dominate the direction of the global model; meanwhile, abnormal nodes are only downweighted rather than completely removed, preserving the possibility of their rapid reintegration into the system after recovery. The final generated global prediction model achieves optimal synergy in accuracy and credibility.
[0119] In one embodiment, S101 specifically includes: synchronously running a pre-built digital twin verification model and a global prediction model on the edge node to obtain the future power prediction value output by the global prediction model and the power verification value output by the digital twin verification model. Based on the differences between the predicted future power values and the power verification values corresponding to multiple sampling points, the residual sequence of edge nodes is determined.
[0120] The future power prediction value represents a quantitative estimate of the electrical power that the devices under the jurisdiction of the edge node will output at a certain future moment (such as 5 minutes, 15 minutes or 4 hours) calculated by the global prediction model based on sensor data (such as wind speed, irradiance, temperature, etc.).
[0121] The power calibration value represents the theoretical power estimate for the same future moment, obtained through forward simulation calculations based on identical input sensor data and using preset physical laws (such as wind turbine blade momentum theory, photovoltaic module single-diode equivalent circuit model, power flow equations, etc.). This value is not trained on historical data but is derived from physical mechanisms.
[0122] The digital twin verification model is a lightweight simulation model pre-built based on the precise mechanistic model of the physical devices managed by the same edge node and the topology parameters of the local microgrid where the edge node is located.
[0123] The precise mechanistic model of the physical devices represents a single-diode equivalent circuit model for the photovoltaic unit, incorporating diode characteristics, series resistance, parallel resistance, photocurrent source, and temperature coefficient. The energy storage unit is represented by a second-order RC equivalent circuit model, including ohmic internal resistance, polarization resistance, and polarization capacitance. The local microgrid topology parameters include the impedance parameters and connection relationships of each branch connected to the edge node. The lightweight simulation model loads these model parameters and topology parameters during initialization, forming a system of differential-algebraic equations that can be solved numerically.
[0124] Specifically, the power verification value is obtained by running the digital twin model, including: The sensor data is used as input to the digital twin model, and by solving its embedded physical equations, a power verification value with a fixed short delay is output, which is derived based on physical laws and is for the same prediction time domain as the local prediction model.
[0125] The embedded physical equations are solved using a numerical integration method, specifically the fourth-order Runge-Kutta method. The solution process is as follows: at each sampling time, the current real-time sensor data (such as node voltage, irradiance, and temperature) is used as the initial or boundary conditions for the differential-algebraic equation system. The Runge-Kutta method is used to numerically integrate the differential equations describing the device's dynamics with a fixed step size, deriving the device's internal state variables (such as capacitor voltage and inductor current) one step ahead. Then, based on the derived state variables and algebraic constraints, the predicted total injected power of the edge nodes at future times is calculated. The fixed short delay is typically set to be consistent with the prediction time domain of the local prediction model, for example, five seconds.
[0126] Specifically, based on the differences between the predicted future power values and the power verification values corresponding to multiple sampling points, the residual sequence of the edge nodes is determined, including: At each sampling moment, the instantaneous difference between the future power prediction value output by the global prediction model for the same moment and the corresponding power verification value output by the digital twin verification model is calculated, and the instantaneous differences of the most recent consecutive sampling moments are stored in chronological order to form a fixed-length real-time residual sequence for subsequent calculations.
[0127] The fixed length is set according to the sampling frequency and the duration of the anomaly of interest. For example, if the sampling interval is one second and the anomaly of interest lasts for more than one minute, the fixed length can be set to sixty. Storage is implemented using a first-in-first-out circular queue data structure.
[0128] Specifically, based on the obtained residual sequence, an adaptive threshold can be determined. Furthermore, when the adaptive threshold is triggered by the residual sequence, the fused evidence feature vector containing the residual sequence is input into the anomaly classification model of the edge node, and the anomaly type of the edge node is output.
[0129] Among them, determining the adaptive threshold based on the residual sequence specifically includes: firstly, normalizing the real-time residual sequence to eliminate the differences in the residual benchmark under different operating conditions.
[0130] The specific calculation process for normalization is as follows: calculate the arithmetic mean of all elements in the real-time residual sequence, and then calculate the standard deviation of these elements.
[0131] Then, subtract the arithmetic mean from each element in the sequence and divide by the standard deviation to obtain a normalized sequence with a mean of zero and a standard deviation of one. Then, calculate a preset higher-order quantile of the normalized residual sequence to characterize the statistical upper bound of the recent normal fluctuations of the sequence.
[0132] The higher-order quantile is usually taken as the 0.95 quantile. The method for calculating the 0.95 quantile is as follows: sort the elements of the normalized sequence in ascending order of value, and take the element value corresponding to the position where the index after sorting is the sequence length multiplied by 0.95 and rounded up. This element value is taken as the higher-order quantile.
[0133] Simultaneously, the absolute value of the average rate of change of the total injected power at the current edge node within a short time window is calculated and normalized to the rated capacity of the edge node to obtain the normalized rate of change of the physical state. This rate of change is used to characterize the drastic nature of the transient change in the physical state. The short time window is typically five to ten sampling periods. The method for calculating the average rate of change is as follows: a linear least-squares fit is performed on the total injected power sequence within the short time window, and the absolute value of the slope of the resulting fitted line is the absolute value of the average rate of change. The rated capacity is the absolute value of the sum of the rated power of all power generation and consumption equipment connected to the edge node, and is a known constant.
[0134] Finally, based on the higher-order quantiles and the normalized rate of change of physical state, an adaptive threshold is generated through a weighted summation formula. The first and second weighting coefficients are used to adjust their respective contributions to the threshold. The recommended value range for the first weighting coefficient is 0.6 to 0.8, and the recommended value range for the second weighting coefficient is 0.2 to 0.4, with their sum being one. The weighted summation formula is: the adaptive threshold equals the first weighting coefficient multiplied by the higher-order quantile, plus the second weighting coefficient multiplied by the normalized rate of change of physical state.
[0135] Furthermore, the method for determining whether the residual sequence triggers the adaptive threshold specifically includes: The absolute value of the latest instantaneous difference in the residual sequence must exceed the adaptive threshold calculated at the current time multiple times consecutively, rather than exceeding it only once, to avoid false alarms caused by transient noise interference. The threshold for multiple consecutive exceedances is typically set to three to five times. The judgment logic is as follows: a counter is set, initially zero; after each calculation, if the absolute value of the latest instantaneous difference is greater than the current dynamic judgment threshold, the counter is incremented; otherwise, the counter is reset to zero; when the counter reaches the threshold, it is determined that the condition is continuously met, indicating that the residual sequence triggers the adaptive threshold.
[0136] Furthermore, in the case where the residual sequence triggers an adaptive threshold, the method also includes: When the residual sequence triggers an adaptive threshold, a structured alarm data packet is generated. This alarm data packet contains at least the trigger time, the residual sequence fragment recorded during the trigger period, and the corresponding adaptive threshold for use in subsequent steps. The alarm data packet also includes the identifier of the edge node at the time of triggering; the residual sequence fragment refers to the value of the real-time residual sequence corresponding to the accumulation from the start of the counter to the time of alarm triggering; and the corresponding adaptive threshold refers to the record of the dynamically determined threshold calculated each time within the same time period.
[0137] For power balance in distributed microgrids, parallel regulation is a crucial real-time guarantee of reliability. In a distributed microgrid, each edge node makes regulation decisions (such as adjusting inverter output power) in parallel and independently based on its local prediction model. If a node's prediction model is tampered with or its data is compromised, its predictions will be inaccurate, leading to erroneous regulation commands and disrupting local and even global power balance. A digital twin verification model, acting as an independent, physically-based arbiter, can detect in real-time, online deviations from local model predictions. Adaptive thresholds can distinguish between sudden changes in normal operating conditions (such as a sharp drop in photovoltaic power due to cloud cover) and anomalies caused by malicious attacks. Once a persistent anomaly is detected, an alarm is triggered, providing a basis for targeted self-healing, thus intervening before erroneous regulation commands cause substantial harm and ensuring the overall stability of the parallel regulation process.
[0138] In this embodiment, firstly, based on identical input sensor data, two power estimation results with independent sources and drastically different computational paradigms are generated in parallel: one derived from data-driven statistical learning, and the other from mechanistic simulation based on physical laws, forming a multi-dimensional verification architecture. For an attacker to conceal their attack, they must simultaneously deceive two completely different computational paradigms, exponentially increasing the attack difficulty. Secondly, the differences among multiple sampling points are arranged into a sequence in chronological order, ensuring the complete preservation of the residual's evolutionary patterns over time (such as sudden jumps, gradual changes, periodic disturbances, mean shifts, etc.), providing highly discriminative temporal feature inputs for subsequent anomaly classification models. Different types of anomalies (data poisoning, model tampering, physical failures, benign mutations) exhibit distinct fluctuation fingerprints on the residual sequence, providing a reliable basis for the system's accurate handling.
[0139] In one embodiment, the data processing method for the distributed microgrid information system further includes: acquiring data layer features, model contribution features, and residual pattern features. The data layer features, model contribution features, and residual pattern features are then concatenated to obtain a fused evidence feature vector containing the residual sequence.
[0140] Among them, data layer features represent quality and reliability indicators extracted from the entire chain of sensor data acquisition, storage, and verification, and are used to characterize the health status of the input data itself.
[0141] Among them, the data layer features include the evidence storage success rate of the physical fingerprint representing the evidence storage status of the sensor data, the anomaly ratio of the physical consistency verification results of the sensor data, and the pattern complexity entropy value of the physical consistency verification results.
[0142] The evidence storage success rate represents the proportion of times that the physical fingerprints of sensor data uploaded by edge nodes to the ledger network are successfully verified by the blockchain consensus within a certain time window.
[0143] The anomaly ratio represents the proportion of data samples that failed the physical consistency check (i.e., violated Kirchhoff's laws, power balance, or other preset physical constraints) in the sensor data collected by edge nodes within a statistical window, out of the total number of collected samples.
[0144] Pattern complexity entropy is a measure of the disorder or unpredictability of the physical consistency verification result sequence. The higher the entropy value, the more random and unpredictable the fluctuation pattern of the verification results; the lower the entropy value, the stronger the regularity or periodicity of the verification results.
[0145] Model contribution features represent time-series indicators extracted from the historical evolution trajectory of the local prediction model, used to characterize the historical performance and participation of the node in the global model aggregation.
[0146] The model contribution features include sequences of confidence values of the local prediction model, sequences of aggregate weights, and sequences of model update quality assessment values formed during multiple model training cycles. The sequence of credibility values represents a time series showing the dynamic credibility evaluation term of the edge node changing over multiple consecutive model training / update cycles. A continuous increase in the element values in this time series indicates that the node has provided reliable data over a long period, while a sudden drop may suggest a sudden attack or equipment failure, providing a historical credibility context in the time dimension for the anomaly classification model.
[0147] The sequence of aggregated weights represents the time series showing the change in the aggregated weights assigned to the marginal node during global model aggregation across multiple training epochs. A continuously decreasing aggregated weight in this time series indicates that the node has been automatically marginalized by the system, potentially due to attacks or continuous low-quality updates.
[0148] The sequence of model update quality assessment values represents a time series showing the change of the model update quality assessment value on the public validation set at a given node over multiple training epochs. A continuous decline in the model update quality assessment value in this time series may indicate that the model has suffered gradual parameter manipulation, while a sudden decline is more likely to indicate a one-time training failure caused by a data poisoning attack.
[0149] Residual pattern features represent the statistical and temporal morphological features extracted from the residual sequence, used to quantify the fluctuation amplitude, energy distribution, and irregularity of the residuals.
[0150] The residual pattern features include the approximate entropy of the target segment sequence in the residual sequence, the cumulative energy exceeding the threshold, and the peak factor.
[0151] The target segment sequence can be the sequence corresponding to the segment in the residual sequence that triggers the adaptive threshold. Specifically, it can be extracted from the alarm data packet that triggers the alarm.
[0152] Approximate entropy is a statistic used to measure the complexity and unpredictability of time series. For a target segment in a residual sequence, the larger the approximate entropy value, the more complex and irregular the residual change pattern; the smaller the value, the more regular and predictable the residual change.
[0153] The cumulative energy exceeding the threshold refers to the sum of the squares (or absolute values) of segments in the residual sequence that exceed the preset adaptive threshold within a statistical window.
[0154] Peak factor is the ratio of the peak value (maximum value) to the effective value (root mean square value, RMS) of the target segment of the residual sequence.
[0155] Specifically, the methods for determining the entropy value of pattern complexity include: The vectors of all physical consistency check results retrieved from the ledger within the time window are arranged into a matrix in chronological order. Singular value decomposition is performed on this matrix to obtain a set of singular values. These singular values are then normalized so that their sum equals 1. Finally, the Shannon entropy of these normalized singular values is calculated; this entropy value is the pattern complexity entropy. The pattern complexity entropy value can be used to quantify the complexity of data anomaly patterns. The time window length is typically set to one to five minutes before the alarm is triggered.
[0156] Specifically, the methods for determining the sequences formed by reliability scores, aggregated weights, and model update quality assessment values include: Calculating short-term trends involves using linear least squares to fit a straight line to the data points of each extracted sequence within the most recent five to ten periods before the alarm is triggered. The absolute value of the slope of the fitted line is the short-term trend value of that sequence. The most recent training periods typically refer to the most recent ten to twenty periods.
[0157] Specifically, the methods for determining residual pattern characteristics include: The residual sequence fragment and its corresponding adaptive threshold are directly extracted from the alarm data packet that triggers the alarm, and multiple residual pattern features, including the approximate entropy, cumulative energy exceeding the threshold, and peak factor of the residual sequence fragment (target fragment sequence), are calculated.
[0158] The process of calculating the approximate entropy is as follows: set an embedding dimension and a tolerance parameter; divide the residual sequence fragment into multiple overlapping sub-vectors of length equal to the embedding dimension in sequence; calculate the ratio of the distance between each sub-vector and other sub-vectors under the tolerance parameter that is less than the parameter, and then take the average of the natural logarithms of these ratios; then increase the embedding dimension and repeat this calculation, and the difference between the two is the approximate entropy.
[0159] The process of calculating the cumulative energy exceeding the threshold is as follows: for each residual value in the residual sequence segment that is greater than the dynamic determination threshold at the corresponding time, calculate the square of the excess part, and then sum all the squared values to obtain the cumulative energy exceeding the threshold.
[0160] The process of calculating the peak factor is as follows: calculate the residual with the largest absolute value in the residual sequence segment, and divide it by the root mean square value of all residual values in the sequence segment to obtain the peak factor.
[0161] Specifically, after obtaining the data layer features, the sequence formed by confidence values, the sequence formed by aggregated weights, the sequence formed by model update quality assessment values, and the residual pattern features, a multi-dimensional fused evidence feature vector can be constructed by sequentially splicing the model contribution features, data layer features, and residual pattern features based on the sequence formed by confidence values, the sequence formed by aggregated weights, the sequence formed by model update quality assessment values, and the trend of change.
[0162] Specifically, after obtaining the fused evidence features, these features can be input into a pre-trained classification model using a graph neural network architecture. The graph neural network architecture is as follows: data layer features, model contribution features, and residual pattern features are used as the initial feature vectors of three independent nodes; fully connected edges are established between the three nodes to form a ternary complete graph; this graph neural network contains two message-passing layers. In each layer, each node aggregates the feature information of all its neighboring nodes, combines it with its own features, and updates it through a non-linear activation function; finally, the final feature vectors of all nodes are concatenated, mapped to the preset number of anomaly types through a fully connected layer, and then output as a probability distribution after passing through a softmax function. This model needs to be pre-trained to convergence using historically labeled anomaly event data.
[0163] This classification model models data layer features, model contribution features, and residual pattern features as nodes in a graph structure. Through message passing and feature updates between nodes, it learns the correlation between cross-layer evidence. The anomaly types of the final output edge nodes include at least data poisoning attacks, prediction model tampering, physical equipment failures, and benign operating condition changes.
[0164] Meanwhile, the classification model calculates the confidence level of the classification result based on the entropy value of the output probability distribution. The formula for calculating the confidence level is: subtract the ratio of the Shannon entropy of the output probability distribution to the maximum possible entropy of the probability distribution (i.e., the logarithm of the number of categories to the base 2) from 1. When the probability distribution is concentrated in a certain category, the entropy is small and the confidence level is high; when the probability distribution is uniform, the entropy is large and the confidence level is low. The high confidence threshold can be preset to 0.8, and the low confidence threshold can be preset to 0.5.
[0165] In this embodiment, firstly, a single feature may produce false positives due to noise interference. However, by fusing evidence from three dimensions—data source, model history, and residual morphology—the anomalous signals from each dimension corroborate each other, significantly improving the reliability and robustness of anomaly classification. Secondly, traditional schemes only use the current residual value for threshold judgment (point detection), while the fused vector contains multi-dimensional information such as time series trends, statistical patterns, and historical reputation, enabling the anomaly classification model to have the ability to perform comprehensive diagnosis based on context and accurately distinguish various anomaly types.
[0166] In one embodiment, the data processing method for the distributed microgrid information system further includes: monitoring the target monitoring indicators of each edge node after performing data processing actions to obtain a feedback reward signal; and adjusting the confidence weight coefficient, smoothing factor, and adaptive threshold based on the feedback reward signal.
[0167] Among them, target monitoring indicators are a set of observable business metrics used to quantitatively evaluate the effectiveness of data processing actions (such as rolling back model versions, enhancing aggregation constraints, and recording results) after edge nodes have completed data processing actions matching the anomaly type. Specific target detection indicators may include: the average deviation of the voltage of key microgrid buses and the average deviation of the system frequency.
[0168] Feedback reward signals are scalar values calculated according to a preset reward function based on the measured values of the target monitoring indicators. For example, positive values represent rewards and negative values represent penalties, which are used to quantitatively evaluate the quality of this data processing action.
[0169] Specifically, the target monitoring indicators of each edge node after performing data processing actions are monitored to obtain feedback reward signals, including: Monitor and evaluate the recovery effect of the microgrid power balance state after the execution of the graded response actions, and generate a quantitative feedback reward signal.
[0170] The feedback reward signal is generated as follows: an evaluation time window is set, for example, three minutes after the alarm is triggered. Within this window, the average deviation of the voltage of the key bus in the microgrid and the average deviation of the system frequency are calculated to see if they quickly converge and stabilize within the allowable range. Simultaneously, it is evaluated whether the actual attack source was accurately isolated without harming normal nodes. The speed and accuracy of stabilization recovery are combined into a scalar value, which serves as the feedback reward signal; a positive value indicates a valid response, while a negative value indicates an inappropriate or invalid response.
[0171] Specifically, after receiving the feedback reward signal, the key parameters can be dynamically optimized using an online learning mechanism that combines policy gradient and Bayesian optimization.
[0172] Specifically, the confidence weight coefficients used in calculating the aggregate weights and the smoothing factor used in updating the dynamic confidence values can be adjusted based on the feedback reward signal. The optimization process using the policy gradient method is as follows: the confidence weight coefficients and smoothing factor are treated as learnable policy parameters; after each execution of the hierarchical response and obtaining the feedback reward signal, the gradient of the signal with respect to these policy parameters is calculated; then, these parameters are updated along the gradient direction with a small step size, increasing the probability of obtaining higher rewards in similar future situations; the learning step size is typically set to a very small positive number, such as 0.01.
[0173] Specifically, the adaptive threshold can be adjusted based on the feedback reward signal. Using a Bayesian optimization framework, the first weighting coefficient, the second weighting coefficient, and the higher-order quantile values used to balance the residual statistics and the rate of change of physical state in the adaptive threshold generation function are adjusted based on the feedback reward signal and the accumulated alarm data packets. The specific process of using the Bayesian optimization framework is as follows: the combination of the first weighting coefficient, the second weighting coefficient, and the higher-order quantile values is considered as an input point, and the feedback reward signal of the corresponding sample is considered as the output; based on the accumulated samples, a Gaussian process regression model is constructed to simulate the black-box functional relationship between parameters and rewards; then, by maximizing a collection function, such as the expected improvement function, the next set of parameter values to be tried is suggested; after running under the new parameters for a period of time and collecting new feedback rewards, the Gaussian process model is updated, and this process is iterated repeatedly to gradually approach the optimal parameter combination.
[0174] In this embodiment, based on feedback reward signals, the credibility weight coefficient, smoothing factor, and adaptive threshold are adjusted to achieve intelligent self-healing and closed-loop optimization. It is no longer a simple anomaly detection and isolation, but rather a targeted approach achieved through evidence fusion and intelligent classification. For example, it distinguishes between data poisoning, model tampering, equipment failure, and normal fluctuations, and takes responses of varying intensities, from isolation and rollback to enhanced monitoring. This directly improves the resilience of the distributed microgrid when subjected to complex attacks or internal failures, that is, the system's ability to maintain core functions (power balance) and recover quickly after being disturbed. Simultaneously, the response effect is used as feedback to continuously optimize key parameters (credibility weight coefficient, smoothing factor, and adaptive threshold) in the preceding steps, enabling the entire security protection system to adaptively evolve and continuously strengthen. This constitutes a complete perception-decision-learning closed loop, giving the power balance parallel control system dynamically evolving security immunity.
[0175] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0176] Based on the same inventive concept, this application also provides a data processing apparatus for a distributed microgrid cyber-physical system for implementing the data processing method of the distributed microgrid cyber-physical system described above. The solution provided by this apparatus is similar to the implementation scheme described in the above method. Therefore, the specific limitations in one or more embodiments of the data processing apparatus for a distributed microgrid cyber-physical system provided below can be found in the limitations of the data processing method for the distributed microgrid cyber-physical system described above, and will not be repeated here.
[0177] In one embodiment, such as Figure 3 As shown, a data processing device for a distributed microgrid cyber-physical system is provided, wherein: The synchronous operation module 301 is used to synchronously run a global prediction model and a digital twin verification model on an edge node to obtain the residual sequence of the edge node; wherein, the global prediction model is based on data-driven calculation, the digital twin verification model is based on physical laws for simulation calculation, the input of the digital twin verification model and the global prediction model is the same, and the residual sequence represents the difference between the outputs of the global prediction model and the digital twin verification model respectively. The classification module 302 is used to input the fused evidence feature vector containing the residual sequence into the anomaly classification model of the edge node when the residual sequence triggers the adaptive threshold, and output the anomaly type of the edge node; wherein, the anomaly type includes data poisoning attack, prediction model tampering, physical equipment failure and benign operating condition change. The execution module 303 is used to perform data processing actions that match the anomaly type. The data processing actions include rolling back the version of the global prediction model, enhancing the aggregation constraints in the edge nodes, and recording the data processing results in the edge nodes.
[0178] Each module in the data processing device of the aforementioned distributed microgrid cyber-physical system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the operations corresponding to each module.
[0179] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 4As shown, the computer device includes a processor, memory, input / output (I / O) interfaces, and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operating system and computer programs stored in the non-volatile storage media. The database stores data such as residual sequences. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network. When the computer program is executed by the processor, it implements a data processing method for a distributed microgrid cyber-physical system.
[0180] Those skilled in the art will understand that Figure 4 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0181] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the above-described method steps.
[0182] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the above method steps.
[0183] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the above-described method steps.
[0184] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0185] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0186] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A data processing method for a distributed microgrid cyber-physical system, characterized in that, The method includes: At the edge node, a global prediction model and a digital twin verification model are run synchronously to obtain the residual sequence of the edge node; wherein, the global prediction model is based on data-driven calculation, the digital twin verification model is based on physical laws for simulation calculation, the input of the digital twin verification model and the global prediction model is the same, and the residual sequence represents the difference between the outputs of the global prediction model and the digital twin verification model respectively. When the residual sequence triggers the adaptive threshold, the fused evidence feature vector containing the residual sequence is input into the anomaly classification model of the edge node, and the anomaly type of the edge node is output; wherein, the anomaly type includes data poisoning attack, prediction model tampering, physical equipment failure and benign operating condition change; Perform data processing actions that match the anomaly type, including rolling back the version of the global prediction model, enhancing the aggregation constraints in the edge nodes, and recording the data processing results in the edge nodes; The method further includes: acquiring multiple sensor data from the edge node, and configuring a local prediction model for each sensor data; wherein the local prediction model is used to output multiple power prediction values for the edge node based on the sensor data; constructing an update package for the edge node based on consensus-verified sensor data, model update parameters of the local prediction model of the edge node, and data storage proof of the consensus-verified sensor data; wherein the model update parameters are model parameters obtained by training the local prediction model based on the consensus-verified sensor data; aggregating the update packages corresponding to each edge node according to a dynamic evaluation strategy to obtain a global prediction model corresponding to each edge node; the global prediction model is used to replace each of the local prediction models. The process involves aggregating the update packages corresponding to each edge node according to a dynamic evaluation strategy to obtain a global prediction model for each edge node. This includes: for each edge node's local prediction model, obtaining a common validation set containing data from various typical operating conditions, and a dynamic credibility evaluation term including a credibility weight coefficient and a smoothing factor; wherein the credibility weight coefficient represents the weight of the data proof verification pass rate in the aggregation process, and the smoothing factor controls the ratio between credibility values of adjacent training iterations; determining the model update quality evaluation value of the local prediction model based on the common validation set; determining the aggregation weight of each local prediction model based on the dynamic credibility evaluation term and the model update quality evaluation value; and performing aggregation processing based on the aggregation weights and model update parameters of each local prediction model to obtain a global prediction model corresponding to each edge node. The method further includes: acquiring data layer features, model contribution features, and residual pattern features; wherein, the data layer features include the evidence storage success rate representing the evidence storage status of the physical fingerprint of the sensing data, the anomaly ratio of the physical consistency verification results of the sensing data, and the pattern complexity entropy value of the physical consistency verification results; the model contribution features include the sequence formed by each confidence value of the local prediction model in multiple model training cycles, the sequence formed by each aggregation weight, and the sequence formed by each model update quality evaluation value; the residual pattern features include the approximate entropy, cumulative excess threshold energy, and peak factor corresponding to the target segment sequence in the residual sequence; and the data layer features, pattern contribution features, and residual pattern features are concatenated to obtain a fused evidence feature vector containing the residual sequence.
2. The method according to claim 1, characterized in that, The acquisition of multiple sensing data from the edge nodes includes: For each of the aforementioned edge nodes, sensor data is acquired from the electrical connection point associated with the edge node at the same sampling time; The method further includes: Based on the preset physical laws and the local network topology relationship where the edge node is located, the physical consistency verification result corresponding to the sensing data is calculated. The physical fingerprint of the sensor data is broadcast to the ledger network and stored and verified through consensus to obtain sensor data that has passed consensus verification; wherein, the physical fingerprint includes the physical consistency verification result and a digital signature used to identify the physical consistency verification result.
3. The method according to claim 1, characterized in that, The step of synchronously running a global prediction model and a digital twin verification model at the edge nodes to obtain the residual sequence of the edge nodes includes: At the edge nodes, a pre-built digital twin verification model and a global prediction model are run synchronously to obtain the future power prediction value output by the global prediction model and the power verification value output by the digital twin verification model. The residual sequence of the edge nodes is determined based on the difference between the future power prediction value corresponding to each of the multiple sampling points and the power prediction value.
4. The method according to claim 1, characterized in that, The method further includes: Monitor the target monitoring indicators of each edge node after it performs the data processing action, and obtain feedback reward signals; Based on the feedback reward signal, the credibility weight coefficient, the smoothing factor, and the adaptive threshold are adjusted.
5. A data processing device for a distributed microgrid cyber-physical system, characterized in that, The device includes: A synchronous operation module is used to synchronously run a global prediction model and a digital twin verification model on edge nodes to obtain the residual sequence of the edge nodes; wherein, the global prediction model is based on data-driven calculation, the digital twin verification model is based on physical laws for simulation calculation, the input of the digital twin verification model and the global prediction model is the same, and the residual sequence represents the difference between the outputs of the global prediction model and the digital twin verification model respectively. The classification module is used to input the fused evidence feature vector containing the residual sequence into the anomaly classification model of the edge node when the residual sequence triggers an adaptive threshold, and output the anomaly type of the edge node; wherein, the anomaly type includes data poisoning attack, prediction model tampering, physical equipment failure and benign operating condition change; An execution module is used to perform data processing actions that match the anomaly type. The data processing actions include rolling back the version of the global prediction model, enhancing the aggregation constraints in the edge nodes, and recording the data processing results in the edge nodes. The device further includes: acquiring multiple sensor data from the edge nodes, and configuring a local prediction model for each of the sensor data; wherein the local prediction model is used to output multiple power prediction values for the edge nodes based on the sensor data; constructing an update package for the edge nodes based on consensus-verified sensor data, model update parameters of the local prediction models of the edge nodes, and data storage proof of the consensus-verified sensor data; wherein the model update parameters are model parameters obtained by training the local prediction models based on the consensus-verified sensor data; aggregating the update packages corresponding to each of the edge nodes according to a dynamic evaluation strategy to obtain a global prediction model corresponding to each edge node; the global prediction model is used to replace each of the local prediction models. The process involves aggregating the update packages corresponding to each edge node according to a dynamic evaluation strategy to obtain a global prediction model for each edge node. This includes: for each edge node's local prediction model, obtaining a common validation set containing data from various typical operating conditions, and a dynamic credibility evaluation term including a credibility weight coefficient and a smoothing factor; wherein the credibility weight coefficient represents the weight of the data proof verification pass rate in the aggregation process, and the smoothing factor controls the ratio between credibility values of adjacent training iterations; determining the model update quality evaluation value of the local prediction model based on the common validation set; determining the aggregation weight of each local prediction model based on the dynamic credibility evaluation term and the model update quality evaluation value; and performing aggregation processing based on the aggregation weights and model update parameters of each local prediction model to obtain a global prediction model corresponding to each edge node. The device further includes: acquiring data layer features, model contribution features, and residual pattern features; wherein the data layer features include the evidence storage success rate representing the evidence storage status of the physical fingerprint of the sensing data, the anomaly ratio of the physical consistency verification results of the sensing data, and the pattern complexity entropy value of the physical consistency verification results; the model contribution features include a sequence formed by each confidence value of the local prediction model in multiple model training cycles, a sequence formed by each aggregation weight, and a sequence formed by each model update quality evaluation value; the residual pattern features include the approximate entropy, cumulative excess threshold energy, and peak factor corresponding to the target segment sequence in the residual sequence; and the data layer features, pattern contribution features, and residual pattern features are concatenated to obtain a fused evidence feature vector containing the residual sequence.
Citation Information
Patent Citations
Digital twinborn visual modeling method and system based on neural network
CN120196672A
Valve real-time flow monitoring method based on big data analysis
CN121188677A