Real-time exception diagnosis method, system and device of power meter and fusion terminal cooperation

CN122595057APending Publication Date: 2026-08-18QINGDAO SHIZE ELECTRONIC METER CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610623752.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-08
Publication Date
2026-08-18

AI Technical Summary

Technical Problem

这种单一维度的数据采集方式无法全面反映用电异常的完整特征

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122595057A_ABST
    Figure CN122595057A_ABST
Patent Text Reader

Abstract

The application provides a real-time exception diagnosis method, system and device of an electric energy meter and a fusion terminal, and relates to the technical field of power system metering safety. In the method, predicted metering data corresponding to each electric energy meter is calculated based on operation data at each time point in a preset time period, the power grid topology structure of a transformer area, and historical operation data. The predicted metering data at each time point is subjected to ratio calculation with metering data to obtain a first deviation sequence. The metering data of all electric energy meters at the same time point is counted, and the total metering data is subjected to ratio calculation with operation data corresponding to each time point to obtain a second deviation sequence. The first deviation sequence and the second deviation sequence are subjected to interactive verification to obtain exception candidate data. The exception candidate data is subjected to exception identification verification to obtain a verification result. When the verification result is that there is an exception, exception alarm information with a time stamp is generated and reported to a power supply management platform, and the diagnostic precision can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power system metering safety technology, specifically to a real-time anomaly diagnosis method, system, and device for the coordinated operation of an electricity meter and a fusion terminal. Background Technology

[0002] With the deepening of power market reform and the rapid development of smart grid construction, the operation and management of power systems are facing increasingly complex challenges. Electricity theft, a long-standing illegal phenomenon that plagues power supply companies, is a top priority in diagnosing abnormal electricity usage. Its methods have gradually evolved from traditional mechanical intervention to new, technologically advanced, covert, and intelligent models, posing a potential threat to the safe and stable operation of the power grid.

[0003] In related technologies, collecting metering parameters such as voltage, current, and power from the electricity meter itself fails to effectively integrate overall operational data from the entire distribution area for comprehensive analysis. This single-dimensional data collection method cannot fully reflect the complete characteristics of abnormal electricity consumption. While the converged terminal, as the core of data aggregation at the distribution area level, possesses strong data processing and analysis capabilities, under the current technical architecture, the electricity meter and the converged terminal operate independently. An effective data exchange and collaborative verification mechanism has not yet been established between them. This results in the converged terminal's capabilities not being fully utilized in electricity theft detection scenarios, ultimately leading to problems such as high false alarm rates and insufficient response time, making it difficult to meet the actual needs of refined management in the current power system. Summary of the Invention

[0004] This application provides a real-time anomaly diagnosis method, system, and device that integrates an electricity meter and a converged terminal, which can improve the accuracy and efficiency of real-time detection of electricity anomalies.

[0005] The technical solution of this application embodiment is as follows: In a first aspect, embodiments of this application provide a real-time anomaly diagnosis method for the collaboration of an electricity meter and a converged terminal, applied to an edge computing node, the method comprising: Acquire real-time metering data from each electricity meter, operational data from the integrated terminals in the distribution area, and historical operational data; Based on the operating data at each time point in the preset time period, the power grid topology of the transformer area, and the historical operating data, the predicted metering data corresponding to each of the electricity meters is calculated, and the ratio of the predicted metering data at each time point to the corresponding metering data is calculated to obtain the first deviation sequence. The metering data of all the electricity meters in the same distribution area at each of the same time points are statistically analyzed to obtain the total metering data. The ratio of the total metering data to the operating data corresponding to each of the time points is calculated to obtain the second deviation sequence. The first deviation sequence and the second deviation sequence are interactively verified to obtain abnormal candidate data. The abnormal candidate data is then subjected to anomaly identification verification to obtain the verification result. If the verification result indicates an anomaly, an anomaly alarm message with a timestamp is generated and reported to the power supply management platform.

[0006] In the above technical solution, firstly, real-time metering data from each electricity meter, operational data from the integrated terminal of the distribution area, and historical operational data are acquired to construct a multi-source data foundation, avoiding the limitations of single data and providing data support for subsequent data analysis. Based on the operational data at each time point within a preset time period, the power grid topology of the distribution area, and historical operational data, the predicted metering data corresponding to each electricity meter is calculated. The ratio of the predicted metering data at each time point to the corresponding metering data is calculated to obtain the first deviation sequence, establishing a predictive mapping mechanism from integrated data to electricity meter segments. This allows each electricity meter to obtain a global information reference benchmark, providing a basis for subsequent anomaly detection. Finally, the metering data of all electricity meters within the distribution area at the same time points are statistically analyzed to obtain the total metering data. The ratio of total metering data to the corresponding operational data at each time point is calculated to obtain the second deviation sequence, thus constructing a convergence feedback channel for the electricity meter group data to the fusion terminal, enabling real-time monitoring of the overall power balance status of the distribution area. The first and second deviation sequences are interactively verified to obtain abnormal candidate data. Anomaly identification verification is performed on the abnormal candidate data to obtain the verification result, realizing the collaborative verification between the electricity meter and the fusion terminal. Through multi-dimensional cross-comparison, the missed detection rate and false alarm rate are reduced, improving the accuracy of electricity theft anomaly detection. When the verification result indicates the presence of an anomaly, an anomaly alarm message with a timestamp is generated and reported to the power supply management platform. Real-time detection at the edge computing node can improve response time and detection efficiency.

[0007] In some embodiments of this application, the step of calculating the predicted metering data corresponding to each of the electricity meters based on the operating data at various time points within a preset time period, the power grid topology of the distribution area, and the historical operating data includes: A directed graph model for communication of the distribution network is constructed based on the power grid topology. The directed graph model has the fusion terminal as the root node, each branch box of the power grid topology as the intermediate node, and each of the electricity meters as the leaf node. The directed edges between the nodes represent the flow relationship of electrical energy. The total output power in the operating data is used as the input feature of the root node, and the load features of each energy meter in the historical operating data are used as the historical feature vectors of the corresponding leaf nodes. The shunting coefficients of each level are calculated based on the historical feature vectors. The layer-by-layer feature aggregation operation is performed along the hierarchical direction of the communication directed graph model. The intermediate node of each level performs matrix multiplication of the input features from the upstream and the diversion coefficient of the current level and then propagates it to the downstream nodes until the leaf nodes are reached, thereby obtaining the corresponding predicted measurement data.

[0008] In some embodiments of this application, the step of calculating the ratio between the predicted measurement data at each time point and the corresponding measurement data to obtain the first deviation sequence includes: In the directed graph model of communication, the deviation ratio between the predicted measurement data and the corresponding measurement data is calculated for each leaf node, and the deviation ratio is used as the abnormal feature value of the leaf node. Feature backtracking aggregation is performed along the reverse hierarchy of the communication directed graph model. Each intermediate node performs a weighted sum of the abnormal feature values ​​of all its downstream leaf nodes to obtain the subtree abnormal aggregation value of the intermediate node. The abnormal feature values ​​of each leaf node and the abnormal aggregate values ​​of its respective subtree are normalized and then arranged in order of time points to form the first deviation sequence.

[0009] In some embodiments of this application, the step of interactively verifying the first deviation sequence and the second deviation sequence to obtain abnormal candidate data includes: Obtain the transmission jitter delay parameter under the heterogeneous communication network, use the transmission jitter delay parameter to perform timestamp sliding alignment on the first deviation sequence and the second deviation sequence, and perform a first-order difference operation on the aligned second deviation sequence to obtain the difference result; The time point when the absolute value of the difference result exceeds the preset mutation threshold is marked as the mutation time point. A time mask vector is generated based on the mutation time point and the time points within the preset range before and after it. The mask element value corresponding to the mutation time point and its neighborhood is a first value, and the mask element value corresponding to the other time points is a second value. The first value is greater than the second value. Based on the aligned first deviation sequence, the two-dimensional feature matrix is ​​expanded according to the node identifier of the leaf node in the directed graph model of the communication, and the rows of the two-dimensional feature matrix correspond to each of the energy meters and the columns correspond to each sampling time point. Perform row-by-row dot product operations between the time mask vector and the two-dimensional feature matrix to obtain a mask-weighted feature matrix. Extract the data in the mask-weighted feature matrix whose mask element value is the column corresponding to the first value as a local feature submatrix. Data within the time period corresponding to the mutation time point is extracted from the aligned second deviation sequence as a global mutation feature vector, and the similarity value between each row vector in the local feature submatrix and the global mutation feature vector is calculated. The similarity value corresponding to each of the energy meters is compared with a preset similarity threshold. If the similarity value is greater than the similarity threshold, and the linear regression slope of the corresponding row vector of the energy meter in the local feature sub-matrix is ​​negative and the absolute value of the slope is greater than the preset slope threshold, then the metering data of the energy meter is marked as the abnormal candidate data.

[0010] In some embodiments of this application, after calculating the ratio of the total measurement data to the operating data corresponding to each of the time points to obtain the second deviation sequence, the method further includes: The sudden deviation value of the station area is calculated based on the second deviation sequence, and it is determined whether the sudden deviation value exceeds the preset event trigger threshold. If the mutation deviation value exceeds the event trigger threshold, the intermediate node with the largest deviation contribution and its corresponding downstream subtree range are located according to the communication directed graph model. For the target energy meters within the downstream subtree range, the fusion terminal dynamically allocates high-priority uplink communication time slots and sends high-frequency sampling wake-up signaling to the target energy meters to obtain the time-series metering data of the target energy meters in the corresponding wake-up period and update the corresponding metering data.

[0011] In some embodiments of this application, the step of performing anomaly identification and verification on the abnormal candidate data to obtain a verification result includes: In the directed graph model of the communication, the energy meter corresponding to the abnormal candidate data is taken as the leaf node to be verified, and the set of sibling leaf nodes that share the same parent node with the leaf node to be verified is obtained. Compare the time-series measurement data of the leaf node to be verified with the measurement data of each node in the set of sibling leaf nodes to determine the consistency of their changing trends within the same time window. If the trends of change are inconsistent and the degree of deviation matches the negative offset trend of the second deviation sequence within the corresponding time window, then the verification result indicates that the electricity meter is abnormal.

[0012] In some embodiments of this application, generating the abnormal alarm information with a timestamp includes: Based on the verification path from the leaf node to the root node in the communication directed graph model, the identification information of each level node on the verification path is extracted to form an anomaly location path chain. The time of the high-frequency sampling wake-up signaling is used as the abnormal start timestamp, and the suspected power loss is calculated based on the cumulative difference between the time-series metering data and the corresponding predicted metering data. The abnormal location path chain, the abnormal start timestamp, the suspected power loss, and the degree of deviation are encapsulated to form the abnormal alarm information.

[0013] Secondly, embodiments of this application provide a real-time anomaly diagnosis system for the collaboration of an electricity meter and a converged terminal, applied to an edge computing node, the system comprising: The data acquisition module is used to acquire real-time metering data from each electricity meter, operational data from the integrated terminal of the distribution area, and historical operational data. The positive verification module is used to calculate the predicted metering data corresponding to each of the electricity meters based on the operating data at each time point in a preset time period, the power grid topology of the transformer area, and the historical operating data, and to calculate the ratio between the predicted metering data at each time point and the corresponding metering data to obtain the first deviation sequence. The reverse verification module is used to statistically analyze the metering data of all the electricity meters in the same distribution area at each of the same time points to obtain the total metering data, and to calculate the ratio of the total metering data with the operating data corresponding to each of the time points to obtain the second deviation sequence. The cross-validation module is used to perform interactive validation between the first deviation sequence and the second deviation sequence to obtain abnormal candidate data, and to perform anomaly identification and validation on the abnormal candidate data to obtain the validation result. The anomaly reporting module is used to generate an anomaly alarm message with a timestamp when the verification result indicates an anomaly, and to report the anomaly alarm message to the power supply management platform.

[0014] Thirdly, embodiments of this application provide an electronic device including a processor, a memory, a user interface, a communication bus, and a network interface. The processor, the memory, the user interface, and the network interface are respectively connected to the communication bus. The memory is used to store instructions. The user interface and the network interface are used to communicate with other devices. The processor is used to execute the instructions stored in the memory to cause the electronic device to perform the method described in any one of the first aspects.

[0015] Fourthly, embodiments of this application provide a computer-readable storage medium storing instructions that, when executed, perform the method described in any one of the methods provided in the first aspect above.

[0016] In summary, one or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages: 1. By first acquiring real-time metering data from individual electricity meters, operational data from the integrated terminals in the distribution area, and historical operational data, a multi-source data foundation was constructed, avoiding the limitations of single-source data and providing data support for subsequent data analysis. Based on the operational data at each time point within a preset time period, the power grid topology of the distribution area, and historical operational data, the predicted metering data corresponding to each electricity meter was calculated. The ratio of the predicted metering data at each time point to the corresponding metering data was calculated to obtain the first deviation sequence, establishing a predictive mapping mechanism from integrated data to electricity meter segments. This enabled each electricity meter to obtain a global information reference benchmark, providing a basis for subsequent anomaly detection. The metering data of all electricity meters in the distribution area at the same time points were statistically analyzed to obtain the total metering data. The ratio of total metering data to corresponding operational data at various time points is calculated to obtain a second deviation sequence, constructing a convergence feedback channel from the electricity meter group data to the fusion terminal, realizing real-time monitoring of the overall power balance status of the distribution area. The first and second deviation sequences are interactively verified to obtain anomaly candidate data. Anomaly candidate data is then identified and verified to obtain verification results, achieving collaborative verification between the electricity meters and the fusion terminal. Multi-dimensional cross-comparison reduces the false alarm rate and improves the accuracy of electricity theft detection. When the verification result indicates an anomaly, a timestamped anomaly alarm is generated and reported to the power supply management platform for real-time detection at edge computing nodes, improving response time and detection efficiency. Therefore, this effectively solves the problems of insufficient real-time performance and detection accuracy caused by the single data dimension and insufficient system collaboration in related electricity theft detection technologies.

[0017] 2. By using a time mask vector, abrupt change points and their neighborhoods are assigned higher mask values, focusing on data within that time period. Neighborhood expansion takes into account the duration of abnormal events, recognizing the value of neighboring data. Further mask weighting eliminates interference from normal time periods in anomaly detection. Similarity calculations between local and global features enable dual-condition judgment, effectively filtering out sporadic fluctuations and irrelevant anomalies.

[0018] 3. Event-driven high-frequency sampling avoids wasting resources and ensures that no abnormal windows are missed. This improves detection accuracy and enables timely detection of anomalies, saving resources. Attached Figure Description

[0019] Figure 1 This is a flowchart illustrating a real-time anomaly diagnosis method for the collaboration of an energy meter and a converged terminal, provided in one embodiment of this application. Figure 2 This is a schematic diagram of the overall structure of a real-time anomaly diagnosis method for the collaboration of an energy meter and a fusion terminal provided in one embodiment of this application. Figure 3 This is a schematic diagram of the module structure of a real-time anomaly diagnosis system for the collaboration of an energy meter and a fusion terminal, provided in one embodiment of this application. Figure 4 This is a schematic diagram of the structure of an electronic device provided in one embodiment of this application. Detailed Implementation

[0020] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.

[0021] In the description of the embodiments of this application, the words "for example" or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design that is described as "for example" or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design options. Rather, the use of the words "for example" or "for instance" is intended to present the relevant concepts in a specific manner.

[0022] In the description of the embodiments of this application, the term "multiple" means two or more. For example, multiple systems means two or more systems, and multiple screen terminals means two or more screen terminals. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, a feature defined with "first" or "second" may explicitly or implicitly include one or more of that feature. The terms "comprising," "including," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.

[0023] Existing electricity theft detection technologies primarily rely on single-terminal data from electricity meters for analysis, which suffers from the following core technical shortcomings: electricity meter data is mostly uploaded periodically, lacking real-time analysis capabilities; and single-terminal data cannot quickly verify the authenticity of anomalies, often only being detected after electricity theft has been ongoing for some time, leading to increased losses. Among related technologies, some solutions attempt to introduce edge computing for electricity meter fault detection or to detect electricity theft through single-dimensional current and voltage comparisons, but none have achieved bidirectional collaborative verification between the electricity meter and the integrated terminal, nor have they constructed a multi-dimensional correlation analysis diagnostic model, failing to address the existing technical shortcomings. Therefore, a novel collaborative real-time diagnostic solution for preventing electricity theft is urgently needed.

[0024] Based on this, embodiments of this application provide a real-time anomaly diagnosis method, system, electronic device, and readable storage medium for the collaborative operation of electricity meters and converged terminals. This real-time anomaly diagnosis method for the collaborative operation of electricity meters and converged terminals first acquires real-time metering data from each electricity meter, operational data from the converged terminal in the distribution area, and historical operational data, constructing a multi-source data foundation to avoid the limitations of single data and provide data support for subsequent data analysis. Based on the operational data at each time point within a preset time period, the power grid topology of the distribution area, and historical operational data, the predicted metering data corresponding to each electricity meter is calculated. The ratio of the predicted metering data at each time point to the corresponding metering data is calculated to obtain a first deviation sequence, establishing a predictive mapping mechanism from converged data to electricity meter segments. This enables each electricity meter to obtain a global information reference benchmark, providing a basis for subsequent anomaly judgment. Metering data from all electricity meters within the same distribution area at various time points are collected to obtain total metering data. The ratio of the total metering data to the corresponding operating data at each time point is calculated to obtain a second deviation sequence. This establishes a convergence and feedback channel for electricity meter group data to the fusion terminal, enabling real-time monitoring of the overall power balance status of the distribution area. The first and second deviation sequences are interactively verified to obtain anomaly candidate data. Anomaly candidate data is then identified and verified to obtain verification results, achieving collaborative verification between electricity meters and the fusion terminal. Multi-dimensional cross-comparison reduces the missed detection rate and false alarm rate, improving the accuracy of electricity theft anomaly detection. When the verification result indicates an anomaly, an anomaly alarm message with a timestamp is generated and reported to the power supply management platform. Real-time detection at the edge computing node improves response time and detection efficiency.

[0025] It should be noted that this real-time anomaly diagnosis method, which integrates the electricity meter with the fusion terminal, is used for electricity metering security protection in various distribution areas. It can achieve real-time identification and early warning of concealed electricity theft, ensuring the security of power grid metering data and protecting the legitimate rights and interests of power supply companies. It should also be noted that the real-time anomaly detection in this application primarily targets abnormal electricity theft behavior during electricity consumption, but can also be used for other anomaly diagnosis.

[0026] The technical solutions provided in the embodiments of this application will be further described below with reference to the accompanying drawings.

[0027] Reference Figure 1 , Figure 1This is a flowchart illustrating a real-time anomaly diagnosis method for the collaboration between an energy meter and a converged terminal, provided in an embodiment of this application. The real-time anomaly diagnosis method for the collaboration between an energy meter and a converged terminal is applied to an edge computing node, which can be a converged terminal. The method is executed by a processor in an electronic device or a readable storage medium, and includes steps S100, S200, S300, S400, and S500.

[0028] Step S100: Obtain real-time metering data from each electricity meter, operational data from the integrated terminal of the distribution area, and historical operational data.

[0029] In one embodiment, metering data includes real-time data collected by the electricity meter, such as voltage, current, power, and energy consumption, which directly reflects the electricity consumption status of an individual user. The operational data of the distribution area's converged terminal covers the terminal's own operational status parameters and the overall power supply parameters of the distribution area, including total power, total voltage, total current, and line loss data, which is core data reflecting the overall power supply operation of the distribution area. Historical operational data, i.e., historical records retained over a period of time (e.g., 3 months, 6 months, or 1 year), includes historical metering data under normal electricity consumption conditions, historical operational parameters of the converged terminal, and electricity theft-related data corresponding to past abnormal electricity consumption events.

[0030] Within the target detection area, extract the device number, installation location, and communication status of all smart meters within the area. Confirm the operating status and communication interface parameters of the integrated terminal in the area to ensure that both the meters and the integrated terminal are in normal working order. Simultaneously, configure the data acquisition module's acquisition frequency (which can be set to 15-60 minutes / time depending on the required accuracy of electricity theft detection) and data transmission protocol, and establish communication links between the data acquisition module and the meters, integrated terminals, and the power supply company's database to ensure smooth data transmission. The above information can be obtained through the power structure deployed in the area.

[0031] The ammeter's metering data is collected by monitoring all deployed smart meters within the distribution area. Each meter corresponds to a user and records its own metering information in real time. Real-time metering data from each meter within the distribution area is acquired via power line carrier communication and then tagged. The distribution area's integrated terminal's operational data originates from the integrated terminals deployed within the area. These terminals act as distribution area-level data aggregation nodes, collecting their own operational status and overall power supply data for the entire distribution area in real time. Real-time operational data from the integrated terminals is collected via fiber optic communication or a dedicated wireless network, with timestamps added to ensure accurate correspondence between real-time data and the time dimension. A data interface connects to the power company's historical database, retrieving historical metering data from all meters within the target distribution area and historical operational data from the integrated terminals according to preset timeframes.

[0032] It should be noted that the acquired metering data, operational data, and historical operational data underwent data preprocessing, including deduplication, noise reduction, and data completion, to ensure data integrity, consistency, and accuracy. By acquiring this data, data connectivity between the electricity metering layer and the fusion terminal detection layer was achieved, establishing a technical foundation for multi-source heterogeneous data fusion. This overcomes the limitations of existing technologies with single data dimensions and provides comprehensive data support for subsequent multi-dimensional correlation analysis.

[0033] Step S200: Based on the operating data at each time point in the preset time period, the power grid topology of the distribution area, and the historical operating data, calculate the predicted metering data corresponding to each of the electricity meters, and calculate the ratio between the predicted metering data at each time point and the corresponding metering data to obtain the first deviation sequence.

[0034] In one embodiment, the preset time period is a pre-defined time period for subsequent calculations, which can be 1 day, 5 days, or 15 days, etc. The power grid topology of the distribution area refers to the connection relationships and layout structure of the distribution lines and equipment within the target detection area, including the installation locations of the fusion terminal, branch boxes, and electricity meters, the line routes, and the power supply range, clearly defining the transmission path of electrical energy from the fusion terminal to the branch boxes and then to each electricity meter. The predicted metering data is the calculated metering data of each electricity meter at each time point within the preset time period (corresponding to the real-time metering data collected in step S100), used to reflect the predicted electricity consumption of each electricity meter under normal power consumption conditions.

[0035] In one embodiment, the step of calculating the predicted metering data corresponding to each of the electricity meters based on the operating data at various time points within a preset time period, the power grid topology of the distribution area, and the historical operating data includes, but is not limited to, the following steps: Step S210: Construct a directed graph model of the power distribution network based on the power grid topology. The directed graph model has the fusion terminal as the root node, each branch box of the power grid topology as the intermediate node, and each energy meter as the leaf node. The directed edges between the nodes represent the flow relationship of electrical energy.

[0036] Specifically, the directed graph model of the distribution network is a graphical model used to characterize the structure of the distribution network and the direction of power flow in the transformer area. Through the combination of nodes and directed edges, it intuitively reflects the connection relationship and power transmission direction between the fusion terminal, branch box, and electricity meter. It is the basic carrier for subsequent calculation of the diversion coefficient and feature aggregation operation.

[0037] Based on the power grid topology, nodes for the fusion terminal, branch boxes, and electricity meters are extracted. The fusion terminal is designated as the unique root node, each branch box as an intermediate node, and each electricity meter as a leaf node. Attribute tags are added to the extracted nodes, including node type (root node, intermediate node, leaf node), equipment model, installation location, and rated parameters (such as the rated current of the branch box and the metering accuracy of the electricity meter), and stored in the model node library. The root node points to all directly connected intermediate nodes, and intermediate nodes point to their directly connected downstream intermediate or leaf nodes. The arrow direction is consistent with the direction of power transmission. Attributes are added to each directed edge, including line resistance, line length, and line loss rate, associated with the corresponding line parameters. For example, the directed edge from the root node to branch box 1 is labeled with a resistance of 0.5Ω, a length of 100m, and a loss rate of 2%.

[0038] For example, a certain distribution area has 1 converged terminal (RTU-001), 2 branch boxes (BOX-001, BOX-002), and 50 electricity meters (METER-001 to METER-0050). RTU-001 is directly connected to BOX-001 and BOX-002. BOX-001 is connected to METER-001 to METER-0025. BOX-002 is connected to METER-0026 to METER-0050. The structure of the directed graph model of communication is as follows: RTU-001 (root node) → BOX-001 (intermediate node) → METER-001 to METER-0025 (leaf nodes); RTU-001 (root node) → BOX-002 (intermediate node) → METER-0026 to METER-0050 (leaf nodes). Each directed edge is associated with the corresponding line parameters.

[0039] Through the above settings, the complex power grid topology of the distribution area is transformed into a directed graph model of communication, which clearly presents the hierarchical relationship and power flow of the fusion terminal, branch box, and electricity meter, so as to improve the accuracy of subsequent calculation and prediction of metering data.

[0040] Step S220: Use the total output power in the operating data as the input feature of the root node, use the load features of each electricity meter in the historical operating data as the historical feature vector of the corresponding leaf node, and calculate the shunting coefficient corresponding to each level based on the historical feature vector.

[0041] Specifically, total output power is a core parameter in the operation data of the integrated terminal in the distribution area, that is, the total electrical power output by the integrated terminal to the distribution area. It is the core input data of the root node, representing the total electrical energy available for distribution in the distribution area in real time. Load characteristics refer to the relevant parameters of electricity load of each electricity meter during its historical operation, including historical average power, load fluctuation coefficient, peak load period, and off-peak load period, reflecting the historical electricity consumption patterns of the electricity meters. The current distribution coefficient is used to determine the proportion of electricity distribution from the upstream node to each downstream node, ensuring that the electricity distribution conforms to the actual power distribution logic and the historical electricity consumption patterns of each electricity meter.

[0042] Within a preset time period, the total output power at each time point is extracted and used as the input feature of the fusion terminal root node for subsequent power distribution. Historical power, load fluctuation coefficient, and peak load percentage are extracted from historical operating data. The average values ​​of historical power, load fluctuation coefficient, and peak load percentage for the corresponding time period are calculated and normalized. The normalized data forms a historical feature vector, yielding the historical feature vector of the theoretical leaf node. The normalization process uses min-max normalization, which will not be elaborated here. The values ​​of the directed graph model are initialized using the above historical data and total output power to facilitate subsequent derivation of predicted metering data.

[0043] Then, the average of the historical feature vectors of all leaf nodes connected to each intermediate node is calculated to obtain the comprehensive feature value of each intermediate node. A normalization algorithm is used to convert the comprehensive feature values ​​of all intermediate nodes into a current distribution coefficient: Intermediate node current distribution coefficient = the comprehensive feature value of the intermediate node divided by the sum of the comprehensive feature values ​​of all intermediate nodes. For all leaf nodes under each intermediate node, their historical feature vectors are extracted, and the same weighted summation method is used to calculate the comprehensive feature value of each electricity meter. The current distribution coefficient of the corresponding level of the electricity meter is the comprehensive feature value of the electricity meter divided by the sum of the comprehensive feature values ​​of all leaf nodes under that intermediate node. The current distribution coefficients from root node to intermediate node and from intermediate node to leaf node are verified separately to ensure that the sum of the current distribution coefficients at each level is 1. The current distribution coefficients of each level are then obtained and associated with the corresponding nodes and directed edges. Through the above settings and the calculation of the current distribution coefficients, a basis is provided for subsequent calculations, ensuring the accuracy of the predicted metering data.

[0044] Step S230: Perform layer-by-layer feature aggregation operation along the hierarchical direction of the directed graph model of the communication. The intermediate node of each level performs matrix multiplication of the input features of the upstream and the diversion coefficient of the current level and then propagates it to the downstream nodes until each leaf node, to obtain the corresponding predicted measurement data.

[0045] Specifically, the hierarchical direction refers to the hierarchical order of nodes in the directed graph model of communication, consistent with the direction of power transmission. The upstream and downstream node order is root node - intermediate node - leaf node, with leaf nodes being the bottom-level downstream nodes. Layer-by-layer feature aggregation operation refers to the process of processing and propagating features along the hierarchical direction, starting from the root node and sequentially processing and passing them down through each level. In the first layer of aggregation operation, the root node serves as the upstream input feature, which is then passed to the downstream intermediate node (the "hull"), where a matrix multiplication is performed between the input feature and the current layer's splitting coefficient to propagate it to the next layer. The second layer of aggregation operation involves propagating from intermediate nodes to downstream intermediate nodes, or from intermediate nodes to downstream leaf nodes. Since the diversion coefficient is calculated based on historical data, and each level is configured with a diversion coefficient, the upstream input features are calculated with the diversion coefficient, and the process is repeated layer by layer until the leaf nodes are reached. This yields the predicted metering data corresponding to each electricity meter, establishing a prediction mapping mechanism from fusion terminal data to the electricity meter end. This allows the metering behavior of each electricity meter to obtain a reference benchmark based on the global information of the distribution area, and combines it with historical data to ensure that the prediction results conform to the actual power distribution scenario, thereby improving the accuracy of the prediction.

[0046] In one embodiment, the step of calculating the ratio between the predicted measurement data at each of the time points and the corresponding measurement data to obtain the first deviation sequence includes, but is not limited to, the following steps: Step S240: In the directed graph model of communication, calculate the deviation ratio between the predicted measurement data and the corresponding measurement data for each leaf node, and use the deviation ratio as the abnormal feature value of the leaf node.

[0047] Specifically, for each leaf node obtained in step S230, the predicted measurement data is used to calculate the difference between the predicted measurement data and the measured data detected by that leaf node for each leaf node and each matching valid time point. The ratio of the difference to the measured data is then calculated to obtain the deviation ratio. If the absolute value of the deviation ratio is greater than a preset deviation threshold, the deviation ratio is recorded as the deviation ratio. This deviation ratio is used as the abnormal feature value of the leaf node and is labeled according to the leaf node identifier, timestamp, and abnormal feature value format for subsequent calculations to obtain the first deviation sequence. The preset deviation threshold can be 15%. By marking potential outliers, interference data is filtered out in advance, reducing the computational load of subsequent steps and thus lowering the false alarm rate and false negative rate in subsequent calculations.

[0048] Step S250: Perform feature backtracking aggregation along the reverse hierarchy of the communication directed graph model. Each intermediate node performs a weighted sum of the abnormal feature values ​​of all its downstream leaf nodes to obtain the subtree abnormal aggregation value of the intermediate node.

[0049] Specifically, the reverse hierarchy refers to the direction opposite to the forward hierarchy of the directed graph model (root node → intermediate node → leaf node), i.e., the bottom-up direction from leaf node to intermediate node, which is the execution direction of feature backtracking aggregation. Feature backtracking aggregation starts from the leaf node, passing the abnormal feature values ​​of downstream nodes upwards to the corresponding intermediate nodes. The intermediate nodes perform aggregation operations, ultimately achieving backtracking of abnormal features from leaf nodes to intermediate nodes, reflecting the overall abnormal state of the subtrees managed by the intermediate nodes. For each leaf node with abnormal feature values, the corresponding intermediate node is obtained through reverse hierarchical backtracking. The weighted sum of the abnormal feature values ​​of all leaf nodes in that intermediate node is calculated by multiplying the abnormal feature value of each leaf node by the corresponding distribution coefficient of that leaf node, and then adding the products to obtain the subtree abnormal aggregation value of the intermediate node. Through reverse hierarchical backtracking aggregation, the abnormal feature values ​​of a single leaf node are summarized to the corresponding intermediate node, realizing a hierarchical representation from single-node anomaly to the overall subtree anomaly, enriching the dimensions of anomaly identification, and avoiding the situation of focusing only on a single node while ignoring the overall anomaly.

[0050] Step S260: After normalizing the abnormal feature values ​​of each leaf node and the abnormal aggregate values ​​of its subtree, arrange them in the order of the time points to form the first deviation sequence.

[0051] Specifically, a normalization function is used to normalize the abnormal feature values ​​of each leaf node and the abnormal aggregate values ​​of its corresponding subtree, resulting in normalized abnormal feature values ​​and corresponding normalized subtree abnormal aggregate values. The normalization function can be the sigmoid() function. For each time point, the normalized abnormal feature values ​​of all leaf nodes and their corresponding normalized subtree abnormal aggregate values ​​are sorted by "leaf node identifier" to form a subsequence for that time point. Within a preset time period, all subsequences from all time points are sequentially concatenated to form a complete first deviation sequence. Each entry in the sequence includes a timestamp, leaf node identifier, normalized abnormal feature value, and normalized subtree abnormal aggregate value, ensuring data integrity and correct order.

[0052] Step S300: Collect the metering data of all the electricity meters in the same distribution area at each time point to obtain the total metering data. Calculate the ratio of the total metering data to the operating data corresponding to each time point to obtain the second deviation sequence.

[0053] In one embodiment, at various times within the same time period, the sum of metering data from all electricity meters at intermediate nodes is calculated based on the directed graph model of communication to obtain the intermediate total metering data of the intermediate nodes. The sum of all intermediate total metering data within the distribution area at each time point is then calculated to obtain the total metering data, which can be represented as a total power value. The ratio of the intermediate total metering data to the intermediate power value of each intermediate node in each operational data point is calculated, and the ratio of the total metering data to the total power value of the operational data corresponding to each time point is also calculated to obtain the corresponding power deviation percentage. If the power deviation percentage is greater than a preset deviation threshold, the corresponding power deviation percentage and the corresponding time point are selected to form a second deviation sequence. The preset deviation threshold can be 25%. This constructs a convergence feedback channel for electricity meter group data to the fusion terminal, enabling real-time monitoring of the overall power balance status of the distribution area. This provides an observation window for capturing abnormal events at the macro level and also lays the data foundation for bidirectional verification between the electricity meter end and the terminal. It should be noted that if a certain electricity meter is found to be involved in electricity theft, then the first deviation sequence and the second deviation sequence should correspond to each other, both of which can reflect the corresponding electricity theft behavior.

[0054] In one embodiment, after calculating the ratio of the total metering data to the operating data corresponding to each of the time points to obtain the second deviation sequence, the real-time anomaly diagnosis method for the coordinated operation of the electricity meter and the fusion terminal further includes, but is not limited to, the following steps: Step S301: Calculate the mutation deviation value of the station area based on the second deviation sequence, and determine whether the mutation deviation value exceeds a preset event trigger threshold.

[0055] Specifically, the event trigger threshold is a pre-set critical value used to determine whether the sudden deviation value has reached the abnormal level. The setting of the event trigger threshold takes into account the normal load fluctuation range of the distribution area, the statistical characteristics of historical abnormal events, and the detection sensitivity requirements of the system.

[0056] The second deviation sequence data consists of 24 hours of data over a preset period, with a sampling interval of 15 minutes, and includes 96 data points. A first-order difference operation is performed on the second deviation sequence to calculate the abrupt deviation value. The difference between each subsequent data point and the preceding data point in the second deviation sequence is used to obtain a difference value representing the rate of change. The calculation range is from the second data point to the nth data point, forming a difference sequence of n-1 data points. At each time point, the absolute difference value is used as the abrupt deviation value. The abrupt deviation value at each time point is compared with a preset event trigger threshold. If the abrupt deviation value does not exceed the event trigger threshold, it indicates that no abrupt event has occurred and electricity usage is normal. Through the difference operation, a quantitative characterization of the rate of change in the overall power balance state of the distribution area is achieved, effectively capturing state abrupt changes caused by the start or end of electricity theft. The event trigger threshold can be a fixed threshold, such as 0.03, or an adaptive threshold. The mean and variance of the differences within the sliding window are calculated. The event trigger threshold is the product of the mean, the confidence coefficient, and the variance. The event trigger threshold is adjusted using the confidence coefficient, achieving a balance between false alarm rate and false negative rate through dynamic adjustment of detection sensitivity. The confidence coefficient can be 2 or 3.

[0057] Step S302: If the mutation deviation value exceeds the event trigger threshold, then locate the intermediate node with the largest deviation contribution and its corresponding downstream subtree range according to the communication directed graph model.

[0058] Specifically, if the mutation deviation value exceeds the event trigger threshold, it indicates that a mutation has occurred and an abnormal electricity theft event has occurred. By using the identifier and time point in the second deviation sequence, the communication directed graph model locates the intermediate node with the largest deviation contribution and its corresponding downstream subtree range, providing a reliable basis for the collection range of subsequent high-frequency sampling commands.

[0059] Step S303: For the target energy meter within the downstream subtree range, the fusion terminal dynamically allocates high-priority uplink communication time slots and sends high-frequency sampling wake-up signaling to the target energy meter to obtain the time-series metering data of the target energy meter in the corresponding wake-up period and update the corresponding metering data.

[0060] Specifically, a high-priority uplink communication slot refers to a time window with priority transmission authority specifically allocated by the converged terminal for the target energy meter within its communication scheduling mechanism. High-frequency sampling wake-up signaling refers to the control command issued by the converged terminal to the target energy meter to trigger the high-frequency sampling mode, employing a sampling mode with shorter time intervals. The wake-up period refers to the continuous operating time of the energy meter after entering the high-frequency sampling mode, which can be set from 10 minutes to 30 minutes by specifying parameters in the wake-up command.

[0061] For the target energy meters within the downstream subtree range, the fusion terminal extracts the communication parameters of these energy meters from the data structure of the directed graph model of the communication, including communication address, communication branch, and current communication status, to prepare for subsequent time slot allocation and signaling. The fusion terminal maintains a communication scheduling table, which records the uplink time slot allocation and priority settings of each energy meter. In normal mode, the uplink time slots of each energy meter are evenly allocated according to a preset polling cycle, with the same priority. When there is a sudden deviation, the fusion terminal temporarily adjusts the communication scheduling table: raising the priority mark of the target energy meter from the normal level to the high priority level; allocating additional uplink time slots to the target energy meter, the specific number of time slots being dynamically calculated based on the data volume requirements of high-frequency sampling and the current idle level of communication bandwidth; and appropriately compressing or delaying the uplink time slots of non-target energy meters to free up communication resources for the target energy meter. After adjustment, a high-frequency sampling wake-up signaling message is sent to the target electricity meter. The high-frequency sampling parameter configuration, including wake-up duration, sampling frequency, and data reporting method, is determined according to the anomaly detection requirements. The high-frequency sampling wake-up signaling message frame is encapsulated according to the format requirements of the transformer area communication protocol. The signaling message frame is sent to each target electricity meter sequentially through the downlink communication channel, and the system waits for the electricity meter to return an acknowledgment response. For electricity meters that do not return an acknowledgment response within the specified time, a signaling retransmission mechanism is executed. Electricity meters that still do not respond after the maximum number of retransmissions are marked as having communication anomalies and are logged.

[0062] The wake-up duration is set to 20 minutes, which can cover multiple high-frequency sampling cycles and provide sufficient data for anomaly verification; the sampling frequency is set to once per minute, which improves the time resolution by 15 times compared to the conventional 15-minute sampling interval; the data reporting method is set to active reporting mode, that is, the energy meter immediately uploads the data to the converged terminal after each high-frequency sampling, instead of waiting for the converged terminal to poll the data.

[0063] In high-frequency sampling mode, the target electricity meter collects metering data and transmits it to the fusion terminal to obtain time-series metering data at various time points. This time-series metering data then replaces the metering data for the corresponding time period. By adjusting the high-frequency sampling of potentially abnormal data, more data can be collected to capture the characteristics of electricity theft on a short time scale and avoid misjudgments.

[0064] For example, in power line carrier communication scenarios, the conventional polling meter reading cycle is typically once every 15 minutes, with all nodes competing for the channel equally. Once a candidate suspected meter is identified through similarity calculation using a two-dimensional feature matrix and global mutation features, the fusion terminal, acting as a central coordinator, sends out a beacon frame with a priority control field. This beacon frame re-allocates the TDMA time slots, forcibly setting the uplink communication priority of the suspected meter and its physically adjacent nodes (sibling nodes) in the same transformer area to the highest level, and specifying that the sampling frequency be increased to once every 1 minute. This design, based on algorithm identification results and the underlying hardware MAC layer protocol for dynamic time slot allocation, effectively avoids network storms and channel congestion caused by high-frequency sampling across the entire network, capturing time-series metering data with extremely low bandwidth consumption.

[0065] Step S400: The first deviation sequence and the second deviation sequence are interactively verified to obtain abnormal candidate data. The abnormal candidate data is then subjected to anomaly identification verification to obtain the verification result.

[0066] In one embodiment, the step of interactively verifying the first deviation sequence and the second deviation sequence to obtain abnormal candidate data includes, but is not limited to, the following steps: Step S410: Obtain the transmission jitter delay parameter under the heterogeneous communication network, use the transmission jitter delay parameter to perform timestamp sliding alignment on the first deviation sequence and the second deviation sequence, and perform a first-order difference operation on the aligned second deviation sequence to obtain the difference result.

[0067] Specifically, heterogeneous communication networks refer to hybrid communication networks involving multiple communication methods between electricity meters and converged terminals. Transmission jitter refers to the variation in the transmission time of data packets from the sender to the receiver at different times, and its causes include network congestion, channel interference, routing changes, and fluctuations in equipment processing capacity.

[0068] Based on historical network transmission data, transmission jitter delay parameters are statistically analyzed to obtain transmission jitter delay parameters under heterogeneous communication networks. These parameters include transmission link and transmission delay time. Based on the transmission jitter delay parameters, the average transmission delay of the communication branch to which each energy meter belongs is calculated. The data timestamps of the energy meters are shifted forward by the corresponding delay amount to restore the actual sampling time. For each energy meter data sequence in the first deviation sequence, timestamp correction is performed according to the average delay parameter of the communication branch to which the energy meter belongs. The comprehensive transmission delay of the second deviation sequence is calculated; this delay is the weighted average of the delays of each communication branch, with the weight being the proportion of energy meters connected to each branch. Timestamp resampling is performed on each corrected data sequence to unify all data sequences onto the same time grid. The resampling method uses linear interpolation to maintain data continuity. Following the calculation method in step S301 above, a first-order difference operation is performed on the aligned second deviation sequence to obtain the difference result. Through the above sliding alignment, the computability between the first and second deviation sequences is ensured for subsequent cross-validation.

[0069] Step S420: Mark the time point when the absolute value of the difference result exceeds the preset mutation threshold as the mutation time point, and generate a time mask vector based on the mutation time point and the time points within the preset range before and after it. The mask element value corresponding to the mutation time point and its neighborhood is a first value, and the mask element value corresponding to the other time points is a second value. The first value is greater than the second value.

[0070] Specifically, the preset range is a time window range extending forward and backward from the mutation time point. The time point where the absolute value of the difference result exceeds the preset mutation threshold is marked as the mutation time point. Based on this mutation time point and the identifier in the sequence, the moment of the anomaly and the abnormal energy meter are determined. The mask vector is initialized with all values ​​of 0. Based on the mutation time point, the corresponding abnormal energy meter is found using a directed graph model of communication, and its mask vector value is set to 1. A time mask vector is generated from the mutation time point and the time points within a preset range before and after it. The preset range can be 3 sampling periods. The mask element values ​​corresponding to the time points within this range (the first value) are set to 1, and the mask element values ​​corresponding to the remaining time points (the second value) are set to 0. Based on the time points and the corresponding masks, a matrix of time points and masks with rows and columns is constructed to obtain the time mask vector for subsequent calculations. The mask element values ​​highlight the points where anomalies occur, thereby filtering out data focusing on the anomalies.

[0071] Step S430: Based on the aligned first deviation sequence, expand it into a two-dimensional feature matrix according to the node identifier of the leaf node in the directed graph model of the communication, wherein the rows of the two-dimensional feature matrix correspond to each of the energy meters and the columns correspond to each sampling time point.

[0072] Specifically, the node identifier list is arranged according to the hierarchical traversal order in the directed graph model of communication or a preset sorting rule. Attribute information of each leaf node is extracted from the model, including its communication branch, parent node identifier, and depth in the tree structure. Based on the aligned first deviation sequence, an N×T two-dimensional array is created, where N is the number of energy meters and T is the number of sampling time points. Following the order of the node identifier list, the deviation sequences of each energy meter are sequentially filled into the corresponding rows of the matrix. The element F[i,j] of matrix F represents the deviation value of the energy meter with node identifier IDi at the j-th sampling time point. By integrating the scattered one-dimensional deviation sequences into a structured two-dimensional feature matrix, a correspondence between the data organization structure and the communication topology is established, facilitating subsequent matrix operations and vectorized calculations, significantly improving data processing efficiency.

[0073] Step S440: Perform row-by-row dot product operation on the time mask vector and the two-dimensional feature matrix to obtain the mask weighted feature matrix, and extract the data in the mask weighted feature matrix whose mask element value is the column corresponding to the first value as the local feature submatrix.

[0074] Specifically, the time mask vector and the two-dimensional feature matrix are multiplied row by row, i.e., matrix multiplication, to obtain a mask-weighted feature matrix. This mask-weighted feature matrix can extract the values ​​corresponding to time points with a value of 1 in the time mask vector, while other values ​​are 0. The data in the columns corresponding to mask elements with a value of 1 in the mask-weighted feature matrix are extracted as local feature submatrices. The data in these local feature submatrices may be anomalous data. Through the above processing, the data of abrupt change time points and their neighborhoods receive higher attention in subsequent analysis, while the influence of data in non-abrupt time periods is weakened, improving the sensitivity of anomaly detection to critical time periods. It also ensures that subsequent calculations are performed only on data during periods of high anomaly incidence, significantly reducing computational complexity and resource consumption, and improving the system's processing efficiency and real-time response capability.

[0075] Step S450: Extract data within the time period corresponding to the mutation time point from the aligned second deviation sequence as a global mutation feature vector, and calculate the similarity value between each row vector in the local feature submatrix and the global mutation feature vector.

[0076] Specifically, data within the time period corresponding to the mutation time point is extracted from the aligned second deviation sequence as a global mutation feature vector. The similarity value between the local feature submatrix and the global mutation feature vector is calculated using cosine similarity or Pearson correlation coefficient. By calculating the similarity value, a quantitative index of the correlation between individual deviation changes and overall deviation changes is established, which prepares for subsequent screening of abnormal candidate data in the investigation of electricity theft.

[0077] Step S460: Compare the similarity value corresponding to each of the energy meters with a preset similarity threshold. If the similarity value is greater than the similarity threshold, and the linear regression slope of the corresponding row vector of the energy meter in the local feature sub-matrix is ​​negative and the absolute value of the slope is greater than the preset slope threshold, then the metering data of the energy meter is marked as the abnormal candidate data.

[0078] Specifically, the preset similarity threshold is a balance between detection sensitivity and false alarm rate. Setting the threshold too low will result in a large number of irrelevant energy meters being included in the candidate range, while setting it too high may miss some abnormal energy meters. The similarity threshold is set in the range of 0.5 to 0.8. The preset slope threshold is a pre-set critical value used to determine whether the slope of the linear regression has reached a significant level. Energy meters with an absolute slope value greater than the preset threshold are considered to have a significant unidirectional trend in deviation value during the abrupt change period. The threshold is set higher than the normal fluctuation range to avoid false alarms.

[0079] The similarity values ​​corresponding to each of the aforementioned electricity meters are compared with a preset similarity threshold. If the similarity value is greater than the threshold, it indicates a strong correlation with the overall abnormal changes in the transformer area, making it a candidate for further analysis. The linear regression slope of the corresponding row vector in the local feature submatrix of the electricity meter is calculated. Row vectors are extracted from the local feature submatrix, and a univariate linear regression is performed using time as the index as the independent variable and the row vector as the deviation value as the dependent variable. The regression model is an existing linear regression model, which will not be elaborated here. Then, the least squares method is used to calculate the linear regression slope. If the regression slope is negative and the absolute value of the slope is greater than a preset slope threshold, it indicates possible electricity theft, and the metering data of that electricity meter is marked as an abnormal candidate data. If any of the above conditions are not met, the electricity meter is not included in the abnormal candidate range. Electricity meter readings filtered using dual criteria are marked as anomaly candidate data, and anomaly candidate flags are added to the electricity meter data records. Specific parameter values ​​triggering the anomaly candidate marking are recorded, including similarity values ​​and regression slopes. The trigger time and associated mutation time points of the anomaly candidates are also recorded. These anomaly candidate data are then aggregated into an anomaly candidate dataset, which is then passed to the subsequent anomaly identification and verification stage. By employing a logical AND combination of similarity and slope conditions as the anomaly candidate judgment criteria, a multi-dimensional evidence fusion screening mechanism is established. Single-dimensional accidental anomalies are unlikely to simultaneously satisfy multiple conditions, thus reducing the false alarm rate, improving the reliability of the anomaly candidate data, and providing high-quality input data for subsequent verification stages.

[0080] The aforementioned logic, which uses a negative linear regression slope with an absolute value greater than a preset slope threshold, has the physical significance of the following: While normal start-up and shutdown of household appliances can lead to a decrease in electricity consumption, the statistically significant drop in this slope is fundamentally different from the abrupt, precipitous drop caused by electricity theft (such as instantaneous short-circuiting of current terminals or increasing bypass resistance). Adding the condition of a similarity value greater than the threshold ensures that the meter's power consumption drop events, in terms of occurrence time window and drop pattern, highly match the sudden increase in unexplained line loss detected by the fusion terminal. This allows for a complete distinction between normal shutdowns and malicious electricity theft / leakage through mathematical morphological characteristics.

[0081] In one embodiment, the step of performing anomaly identification and verification on the abnormal candidate data to obtain a verification result includes, but is not limited to, the following steps: Step S470: In the directed graph model of communication, the energy meter corresponding to the abnormal candidate data is taken as the leaf node to be verified, and the set of sibling leaf nodes that share the same parent node with the leaf node to be verified is obtained.

[0082] Specifically, the aforementioned abnormal candidate data is mapped to a directed graph model of communication. The energy meter corresponding to the abnormal candidate data is taken as the leaf node to be verified. Based on the directed edges in the directed graph model of communication, the parent node is located by reverse pointer search or depth-first traversal backtracking. The intermediate node of the corresponding level is located. The intermediate node is the same parent node. The parent node is taken as the new traversal root node. Breadth-first search is performed or the child node routing mapping table maintained under the parent node is read to find all leaf nodes under the intermediate node. These are taken as the set of sibling leaf nodes sharing the same parent node. The sibling nodes are selected as reference points. It is possible to determine whether the noise is caused by anomalies or severe weather or overall fluctuations in grid voltage, thus providing a reference benchmark for analysis.

[0083] Step S480: Compare the time-series measurement data of the leaf node to be verified with the measurement data of each node in the sibling leaf node set within the same time window to ensure consistency in their trends.

[0084] Specifically, to ensure the accuracy of reference and calculation, data from the same time window are selected for calculation to avoid deviations or data mismatches. A reference sequence matrix is ​​constructed from the data of each node in the set of all sibling leaf nodes. A target sequence vector is constructed from the time-series measurement data of the leaf node to be verified. Each row of the target sequence vector and the reference sequence matrix is ​​then subjected to sliding difference calculation or first-order polynomial smoothing fitting to obtain the corresponding slope sequence representation. Then, using Pearson correlation coefficient or cosine similarity algorithms, the aggregate distance between the slope feature of the target and the slope feature measure of each sibling is calculated. If the correlation coefficient is greater than 0 or the distance is less than a preset Euclidean space boundary, they are considered consistent; otherwise, they are considered inconsistent. Performing trend consistency comparison within the time window can eliminate delay jitter and message arrival time differences caused by heterogeneous communication networks, improving the accuracy of anomaly identification.

[0085] Step S490: If the changing trends are inconsistent and the degree of deviation matches the negative offset trend of the second deviation sequence within the corresponding time window, then the verification result is that the electricity meter is abnormal.

[0086] Specifically, if the trends of change are inconsistent, the degree of inconsistency is taken as the degree of deviation, which reflects the severity of the deviation of local micro-level individuals. The calculated correlation value is compared with a preset correlation threshold, which can be 80%. The greater the difference from the correlation threshold, the greater the degree of deviation. In the second deviation sequence, the first derivative of the function within the same time window is checked for negativity. If the trends of change are inconsistent, and the degree of deviation matches the negative offset trend of the second deviation sequence within the corresponding time window, it indicates that the boundary of the rate of change function of the degree of deviation is enveloped within the negative offset trend of the second deviation sequence. Therefore, the verification result indicates that the electricity meter is abnormal. This effectively filters out situations where the electricity consumption momentarily drops to zero due to the user simply leaving the house and turning off the main power switch (this situation will cause micro-level deviations but will not cause a deterioration in the macro-level negative offset of the second deviation sequence), ensuring the accuracy of anomaly identification.

[0087] In step S500, if the verification result indicates an anomaly, an anomaly alarm message with a timestamp is generated and the anomaly alarm message is reported to the power supply management platform.

[0088] In one embodiment, if the verification result indicates an anomaly, it signifies that electricity theft has occurred after multi-level verification, and an anomaly alarm message with a timestamp is generated. The generation of the anomaly alarm message with a timestamp includes, but is not limited to, the following steps: Step S510: Based on the verification path from the leaf node to the root node in the communication directed graph model, extract the identification information of each level node on the verification path to form an anomaly location path chain.

[0089] Specifically, starting from the storage address of the identified leaf node to be verified, reverse addressing of the parent pointer is performed in the directed graph model of the communication. Each time the pointer jumps upstream, the hardware identifier field of the current intermediate node is pushed into a preset cache stack, until the addressing reaches the root node representing the fusion terminal. At this point, the tracing process terminates, and a pop operation or sequence reversal is performed from the cache stack, generating an array structure arranged in a strict hierarchical order of source node—...—leaf node. This array structure is the anomaly location path chain. This anomaly location path is implemented to facilitate subsequent location and verification of anomalies.

[0090] Step S520: The time of the high-frequency sampling wake-up signaling is used as the abnormal start timestamp, and the suspected power loss is calculated based on the cumulative difference between the time-series metering data and the corresponding predicted metering data.

[0091] Specifically, the time when the high-frequency sampling wake-up signal is issued is used as the anomaly start timestamp, and the current time is used as the end timestamp. During the time between the anomaly start timestamp and the end timestamp, the cumulative difference between the time-series metering data and the corresponding predicted metering data is calculated to obtain the suspected power loss, which reflects the difference between the theoretical load and the actual metering after the actual load drop, so that it can be recorded and reported for verification.

[0092] Step S530: The abnormal location path chain, the abnormal start timestamp, the suspected power loss, and the degree of deviation are encapsulated to form the abnormal alarm information.

[0093] Specifically, the anomaly location path chain, the anomaly start timestamp, the suspected lost electricity, and the degree of deviation are encapsulated into a data dictionary, recorded as JSON objects in key-value pairs, and then compressed and hashed to generate an anomaly alarm message for subsequent reporting. This avoids the problem of traditional terminals constantly transmitting raw meter data back to the platform, which consumes a lot of network resources. By assembling these components, cloud computing power consumption and uplink bandwidth usage are greatly reduced.

[0094] In one embodiment, the edge computing node is connected to the power supply management platform and reports abnormal alarm information to the power supply management platform, realizing real-time response and accurate location of abnormal events. It provides power supply companies with traceable abnormal records, supports subsequent on-site verification and evidence fixation, and improves the efficiency of investigating and handling electricity theft and the ability to manage closed loops, so as to control electricity theft.

[0095] like Figure 3As shown in the figure, this application embodiment provides a real-time anomaly diagnosis system 100 for the collaboration of electricity meters and converged terminals, applied to an edge computing node, which can be a converged terminal. The real-time anomaly diagnosis system 100 for the collaboration of electricity meters and converged terminals acquires real-time metering data of each electricity meter, operational data of the converged terminal in the distribution area, and historical operational data through a data acquisition module 110. Using a forward verification module 120, based on the operational data at each time point within a preset time period, the power grid topology of the distribution area, and the historical operational data, it calculates the predicted metering data corresponding to each electricity meter, and compares the predicted metering data at each time point with the corresponding metering data. The ratio is calculated to obtain a first deviation sequence; the reverse verification module 130 is used to statistically analyze the metering data of all the electricity meters in the same distribution area at each time point to obtain total metering data, and the ratio of the total metering data to the operating data corresponding to each time point is calculated to obtain a second deviation sequence; the first deviation sequence and the second deviation sequence are interactively verified by the cross-verification module 140 to obtain abnormal candidate data, and the abnormal candidate data is subjected to anomaly identification verification to obtain a verification result; if the verification result indicates the existence of an anomaly, the anomaly reporting module 150 generates an anomaly alarm message with a timestamp and reports the anomaly alarm message to the power supply management platform.

[0096] It should be noted that the data acquisition module 110 is connected to the forward verification module 120, the forward verification module 120 is connected to the reverse verification module 130, the reverse verification module 130 is connected to the cross-verification module 140, and the cross-verification module 140 is connected to the anomaly reporting module 150. The above-mentioned real-time anomaly diagnosis method for the collaboration between electricity meters and converged terminals is applied to the real-time anomaly diagnosis system 100 for the collaboration between electricity meters and converged terminals. The system 100 acquires real-time metering data from each electricity meter, operational data from the converged terminals in the distribution area, and historical operational data, constructing a multi-source data foundation to avoid the limitations of single data and provide data support for subsequent data analysis. Based on the operational data at each time point within a preset time period, the power grid topology of the distribution area, and historical operational data, it calculates the predicted metering data corresponding to each electricity meter. The predicted metering data at each time point is compared with the corresponding metering data to obtain the first deviation sequence, establishing a predictive mapping mechanism from converged data to electricity meter segments. This allows each electricity meter to obtain a global information reference benchmark, providing a basis for subsequent anomaly judgment. Metering data from all electricity meters within the same distribution area at various time points are collected to obtain total metering data. The ratio of the total metering data to the corresponding operating data at each time point is calculated to obtain a second deviation sequence. This establishes a convergence and feedback channel for electricity meter group data to the fusion terminal, enabling real-time monitoring of the overall power balance status of the distribution area. The first and second deviation sequences are interactively verified to obtain anomaly candidate data. Anomaly candidate data is then identified and verified to obtain verification results, achieving collaborative verification between electricity meters and the fusion terminal. Multi-dimensional cross-comparison reduces the missed detection rate and false alarm rate, improving the accuracy of electricity theft anomaly detection. When the verification result indicates an anomaly, an anomaly alarm message with a timestamp is generated and reported to the power supply management platform. Real-time detection at the edge computing node improves response time and detection efficiency.

[0097] It should also be noted that the apparatus provided in the above embodiments is only illustrated by the division of the above functional modules. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments, which will not be repeated here.

[0098] This application also discloses an electronic device. (See reference...) Figure 4 , Figure 4This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. The electronic device 500 may include: at least one processor 501, at least one network interface 504, a user interface 503, a memory 505, and at least one communication bus 502.

[0099] The communication bus 502 is used to enable communication between these components.

[0100] The user interface 503 may include a display screen and a camera. Optionally, the user interface 503 may also include a standard wired interface and a wireless interface.

[0101] The network interface 504 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).

[0102] The processor 501 may include one or more processing cores. The processor 501 connects to various parts of the server using various interfaces and lines, and performs various server functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in memory 505, and by calling data stored in memory 505. Optionally, the processor 501 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array. The processor 501 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and Modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content required for display; and the modem handles wireless communication. It is understood that the modem may also be implemented as a separate chip without being integrated into the processor 501.

[0103] The memory 505 may include random access memory (RAM) or read-only memory. Optionally, the memory 505 may include a non-transitory computer-readable storage medium. The memory 505 may be used to store instructions, programs, code, code sets, or instruction sets. The memory 505 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-described method embodiments, etc.; the data storage area may store data involved in the above-described method embodiments, etc. Optionally, the memory 505 may also be at least one storage device located remotely from the aforementioned processor 501. (Refer to...) Figure 4 The memory 505, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and an application program for a real-time anomaly diagnosis method that coordinates an energy meter with a fusion terminal.

[0104] exist Figure 4 In the illustrated electronic device 500, the user interface 503 is mainly used to provide an input interface for the user and acquire user input data; while the processor 501 can be used to call an application program stored in the memory 505 for a real-time anomaly diagnosis method for the collaboration of an energy meter and a converged terminal. When executed by one or more processors 501, the electronic device 500 performs one or more methods as described in the above embodiments. It should be noted that, for the foregoing method embodiments, for the sake of simplicity, they are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, because according to this application, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0105] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0106] In the various embodiments provided in this application, it should be understood that the disclosed apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some service interface; the indirect coupling or communication connection between apparatuses or units may be electrical or other forms.

[0107] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0108] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0109] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as USB flash drives, portable hard drives, magnetic disks, or optical disks.

[0110] The above are merely exemplary embodiments of this disclosure and should not be construed as limiting the scope of this disclosure. Any equivalent changes and modifications made in accordance with the teachings of this disclosure shall still fall within the scope of this disclosure. Other embodiments of this disclosure will readily conceive of those skilled in the art upon consideration of the specification and the disclosure of practical truths.

[0111] This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not described in this disclosure. The specification and embodiments are to be considered exemplary only, and the scope and spirit of this disclosure are defined by the claims.

Claims

1. A real-time anomaly diagnosis method for the coordinated operation of an electricity meter and a converged terminal, characterized in that, Applied to edge computing nodes, the method includes: Acquire real-time metering data from each electricity meter, operational data from the integrated terminals in the distribution area, and historical operational data; Based on the operating data at each time point in the preset time period, the power grid topology of the transformer area, and the historical operating data, the predicted metering data corresponding to each of the electricity meters is calculated, and the ratio of the predicted metering data at each time point to the corresponding metering data is calculated to obtain the first deviation sequence. The metering data of all the electricity meters in the same distribution area at each of the same time points are statistically analyzed to obtain the total metering data. The ratio of the total metering data to the operating data corresponding to each of the time points is calculated to obtain the second deviation sequence. The first deviation sequence and the second deviation sequence are interactively verified to obtain abnormal candidate data. The abnormal candidate data is then subjected to anomaly identification verification to obtain the verification result. If the verification result indicates an anomaly, an anomaly alarm message with a timestamp is generated and reported to the power supply management platform.

2. The method according to claim 1, characterized in that, The calculation of predicted metering data for each electricity meter based on the operating data at various points in a preset time period, the power grid topology of the distribution area, and the historical operating data includes: A directed graph model for communication of the distribution network is constructed based on the power grid topology. The directed graph model has the fusion terminal as the root node, each branch box of the power grid topology as the intermediate node, and each of the electricity meters as the leaf node. The directed edges between the nodes represent the flow relationship of electrical energy. The total output power in the operating data is used as the input feature of the root node, and the load features of each energy meter in the historical operating data are used as the historical feature vectors of the corresponding leaf nodes. The shunting coefficients of each level are calculated based on the historical feature vectors. The layer-by-layer feature aggregation operation is performed along the hierarchical direction of the communication directed graph model. The intermediate node of each level performs matrix multiplication of the input features from the upstream and the diversion coefficient of the current level and then propagates it to the downstream nodes until the leaf nodes are reached, thereby obtaining the corresponding predicted measurement data.

3. The method according to claim 2, characterized in that, The step of calculating the ratio between the predicted measurement data at each of the aforementioned time points and the corresponding measurement data to obtain the first deviation sequence includes: In the directed graph model of communication, the deviation ratio between the predicted measurement data and the corresponding measurement data is calculated for each leaf node, and the deviation ratio is used as the abnormal feature value of the leaf node. Feature backtracking aggregation is performed along the reverse hierarchy of the communication directed graph model. Each intermediate node performs a weighted sum of the abnormal feature values ​​of all its downstream leaf nodes to obtain the subtree abnormal aggregation value of the intermediate node. The abnormal feature values ​​of each leaf node and the abnormal aggregate values ​​of its respective subtree are normalized and then arranged in order of time points to form the first deviation sequence.

4. The method according to claim 3, characterized in that, The step of interactively verifying the first deviation sequence and the second deviation sequence to obtain abnormal candidate data includes: Obtain the transmission jitter delay parameter under the heterogeneous communication network, use the transmission jitter delay parameter to perform timestamp sliding alignment on the first deviation sequence and the second deviation sequence, and perform a first-order difference operation on the aligned second deviation sequence to obtain the difference result; The time point when the absolute value of the difference result exceeds the preset mutation threshold is marked as the mutation time point. A time mask vector is generated based on the mutation time point and the time points within the preset range before and after it. The mask element value corresponding to the mutation time point and its neighborhood is a first value, and the mask element value corresponding to the other time points is a second value. The first value is greater than the second value. Based on the aligned first deviation sequence, the two-dimensional feature matrix is ​​expanded according to the node identifier of the leaf node in the directed graph model of the communication, and the rows of the two-dimensional feature matrix correspond to each of the energy meters and the columns correspond to each sampling time point. Perform row-by-row dot product operations between the time mask vector and the two-dimensional feature matrix to obtain a mask-weighted feature matrix. Extract the data in the mask-weighted feature matrix whose mask element value is the column corresponding to the first value as a local feature submatrix. Data within the time period corresponding to the mutation time point is extracted from the aligned second deviation sequence as a global mutation feature vector, and the similarity value between each row vector in the local feature submatrix and the global mutation feature vector is calculated. The similarity value corresponding to each of the energy meters is compared with a preset similarity threshold. If the similarity value is greater than the similarity threshold, and the linear regression slope of the corresponding row vector of the energy meter in the local feature sub-matrix is ​​negative and the absolute value of the slope is greater than the preset slope threshold, then the metering data of the energy meter is marked as the abnormal candidate data.

5. The method according to claim 2, characterized in that, After calculating the ratio of the total measurement data to the operational data corresponding to each of the time points to obtain the second deviation sequence, the method further includes: The sudden deviation value of the station area is calculated based on the second deviation sequence, and it is determined whether the sudden deviation value exceeds the preset event trigger threshold. If the mutation deviation value exceeds the event trigger threshold, the intermediate node with the largest deviation contribution and its corresponding downstream subtree range are located according to the communication directed graph model. For the target energy meters within the downstream subtree range, the fusion terminal dynamically allocates high-priority uplink communication time slots and sends high-frequency sampling wake-up signaling to the target energy meters to obtain the time-series metering data of the target energy meters in the corresponding wake-up period and update the corresponding metering data.

6. The method according to claim 5, characterized in that, The step of performing anomaly identification and verification on the abnormal candidate data to obtain verification results includes: In the directed graph model of the communication, the energy meter corresponding to the abnormal candidate data is taken as the leaf node to be verified, and the set of sibling leaf nodes that share the same parent node with the leaf node to be verified is obtained. Compare the time-series measurement data of the leaf node to be verified with the measurement data of each node in the set of sibling leaf nodes to determine the consistency of their changing trends within the same time window. If the trends of change are inconsistent and the degree of deviation matches the negative offset trend of the second deviation sequence within the corresponding time window, then the verification result indicates that the electricity meter is abnormal.

7. The method according to claim 6, characterized in that, The generation of abnormal alarm information with timestamps includes: Based on the verification path from the leaf node to the root node in the communication directed graph model, the identification information of each level node on the verification path is extracted to form an anomaly location path chain. The time of the high-frequency sampling wake-up signaling is used as the abnormal start timestamp, and the suspected power loss is calculated based on the cumulative difference between the time-series metering data and the corresponding predicted metering data. The abnormal location path chain, the abnormal start timestamp, the suspected power loss, and the degree of deviation are encapsulated to form the abnormal alarm information.

8. A real-time anomaly diagnosis system for the coordinated operation of an electricity meter and a fusion terminal, characterized in that, The system, applied to edge computing nodes, includes: The data acquisition module is used to acquire real-time metering data from each electricity meter, operational data from the integrated terminal of the distribution area, and historical operational data. The positive verification module is used to calculate the predicted metering data corresponding to each of the electricity meters based on the operating data at each time point in a preset time period, the power grid topology of the transformer area, and the historical operating data, and to calculate the ratio between the predicted metering data at each time point and the corresponding metering data to obtain the first deviation sequence. The reverse verification module is used to statistically analyze the metering data of all the electricity meters in the same distribution area at each of the same time points to obtain the total metering data, and to calculate the ratio of the total metering data with the operating data corresponding to each of the time points to obtain the second deviation sequence. The cross-validation module is used to perform interactive validation between the first deviation sequence and the second deviation sequence to obtain abnormal candidate data, and to perform anomaly identification and validation on the abnormal candidate data to obtain the validation result. The anomaly reporting module is used to generate an anomaly alarm message with a timestamp when the verification result indicates an anomaly, and to report the anomaly alarm message to the power supply management platform.

9. An electronic device, characterized in that, The device includes a processor, a memory, a user interface, a communication bus, and a network interface. The processor, the memory, the user interface, and the network interface are respectively connected to the communication bus. The memory is used to store instructions. The user interface and the network interface are used to communicate with other devices. The processor is used to execute the instructions stored in the memory to cause the electronic device to perform the method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed, perform the method as described in any one of claims 1-7.