Power plant alarm event processing method and processing system based on topological correlation
Patent Information
- Application Number
- CN202610936192.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-26
- Publication Date
- 2026-08-28
AI Technical Summary
[0003]目前,现有技术对发电厂报警数据的处理采用固定阈值规则,仅依据单一参数的数值超差范围划定等级,导致分级结果与实际故障严重程度脱节,易产生“虚高报警”或“漏判高危报警”,且对报警事件的处理多为孤立分析,导致同一故障引发的多个连锁报警被逐一推送,造成严重的“报警疲劳”
[0009]To achieve the above objectives, a fourth aspect of this application provides a computer-readable storage medium storing computer-executable instructions for causing a computer to execute the above-described method for handling power plant alarm events based on topology association.
Smart Images

Figure CN122658064A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of electrical digital data processing technology, and in particular to a method and system for processing power plant alarm events based on topology association. Background Technology
[0002] Power plants are a core component of the power system, and the stability of their equipment operation directly determines the safety of the power grid and the reliability of power supply. With the continuous improvement of automation and digitalization in power plants, various monitoring devices generate massive amounts of operational alarm data. This data is the core basis for maintenance personnel to detect anomalies and handle faults. Efficient and accurate alarm processing technology can significantly shorten fault response time and reduce the risk of equipment downtime. This technology is widely applicable to the operation monitoring systems of various power generation scenarios, including thermal power plants, hydropower plants, and new energy power plants.
[0003] Currently, existing technologies for processing power plant alarm data use fixed threshold rules, classifying levels based solely on the deviation range of a single parameter. This leads to a disconnect between the classification results and the actual severity of the fault, easily resulting in "false high alarms" or "missed high-risk alarms." Furthermore, the processing of alarm events is mostly done through isolated analysis, causing multiple chain alarms triggered by the same fault to be pushed one by one, resulting in severe "alarm fatigue." Summary of the Invention
[0004] The main objective of this disclosure is to propose a method and system for handling power plant alarm events based on topological association.
[0005] A first aspect of this application provides a power plant alarm event processing method based on topology association, the method comprising: The initial alarm data of the target power plant is semantically parsed to obtain structured alarm data; the target power plant includes at least two devices. Construct an equipment object model for the target power plant; the equipment object model shall at least include the topological relationships between the equipment. Based on the device object model and the structured alarm data, an alarm event cluster is constructed; Based on the alarm event cluster, determine the core root cause alarm in the alarm event cluster; Based on the core root cause alarm, the corresponding equipment of the core root cause alarm, and the real-time operating conditions of the target power plant, the final alarm level of the alarm event cluster is determined. Based on the final alarm level and the core root cause alarm, structured alarm information for the alarm event cluster is generated.
[0006] The first aspect of this application provides a power plant alarm event processing method based on topological association. This method obtains structured alarm data by semantically parsing the initial alarm data of a target power plant. The target power plant includes at least two devices. A device object model of the target power plant is constructed. The device object model includes at least the topological association relationships between the devices. Based on the device object model and the structured alarm data, an alarm event cluster is constructed. According to the alarm event cluster, core root cause alarm information is determined. Based on the core root cause alarm information, the corresponding device, and the real-time operating conditions of the target power plant, the final alarm level of the alarm event cluster is determined. Based on the final alarm level and the core root cause alarm information, structured alarm information of the alarm event cluster is generated. This method enables precise alarm integration, root cause localization, and adaptive level output through root cause scoring and dynamic grading.
[0007] To achieve the above objectives, a second aspect of this application provides a power plant alarm event processing system based on topology association, the system comprising: The parsing module is used to perform semantic parsing on the initial alarm data of the target power plant to obtain structured alarm data; the target power plant includes at least two devices; A construction module is used to construct an equipment object model of the target power plant; the equipment object model includes at least the topological relationships between equipment. The first module is used to construct an alarm event cluster based on the device object model and the structured alarm data; The second module is used to determine the core root cause alarm in the alarm event cluster based on the alarm event cluster; The third module is used to determine the final alarm level of the alarm event cluster based on the core root cause alarm, the corresponding equipment of the core root cause alarm, and the real-time operating conditions of the target power plant. The fourth module is used to generate structured alarm information for the alarm event cluster based on the final alarm level and the core root cause alarm.
[0008] To achieve the above objectives, a third aspect of this application provides an electronic device, including: at least one control processor and a memory for communicatively connecting to the at least one control processor; the memory stores instructions executable by the at least one control processor, which, when executed by the at least one control processor, enable the at least one control processor to perform the above-described topology-based power plant alarm event handling method.
[0009] To achieve the above objectives, a fourth aspect of this application provides a computer-readable storage medium storing computer-executable instructions for causing a computer to execute the above-described method for handling power plant alarm events based on topology association.
[0010] It is understood that the beneficial effects of the second to fourth aspects compared with the related technologies are the same as the beneficial effects of the first aspect compared with the related technologies. Please refer to the relevant description in the first aspect above, which will not be repeated here. Attached Figure Description
[0011] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the description of the embodiments taken in conjunction with the following drawings, in which: Figure 1 This is a flowchart illustrating a power plant alarm event handling method based on topological association, provided in an embodiment of this application. Figure 2 This is a schematic diagram of the structure of a power plant alarm event processing system based on topology association, provided in an embodiment of this application. Figure 3 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0012] The embodiments of this application are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting this application.
[0013] In the description of this application, the use of terms such as "first," "second," etc., is for the purpose of distinguishing technical features only and should not be construed as indicating or implying relative importance or implicitly indicating the number of technical features indicated or the order of the technical features indicated.
[0014] In the description of this application, it should be understood that the orientation descriptions, such as up, down, etc., are based on the orientation or positional relationship shown in the accompanying drawings, and are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of this application.
[0015] In the description of this application, it should be noted that, unless otherwise explicitly defined, terms such as "setup," "installation," and "connection" should be interpreted broadly, and those skilled in the art can reasonably determine the specific meaning of the above terms in this application in conjunction with the specific content of the technical solution.
[0016] Power plants are a core component of the power system, and the stability of their equipment operation directly determines the safety of the power grid and the reliability of power supply. With the continuous improvement of automation and digitalization in power plants, various monitoring devices generate massive amounts of operational alarm data. This data is the core basis for maintenance personnel to detect anomalies and handle faults. Efficient and accurate alarm processing technology can significantly shorten fault response time and reduce the risk of equipment downtime. This technology is widely applicable to the operation monitoring systems of various power generation scenarios, including thermal power plants, hydropower plants, and new energy power plants.
[0017] Currently, existing technologies for processing power plant alarm data use fixed threshold rules, classifying levels based solely on the deviation range of a single parameter. This leads to a disconnect between the classification results and the actual severity of the fault, easily resulting in "false high alarms" or "missed high-risk alarms." Furthermore, the processing of alarm events is mostly done through isolated analysis, causing multiple chain alarms triggered by the same fault to be pushed one by one, resulting in severe "alarm fatigue."
[0018] Based on this, the embodiments of this application provide a power plant alarm event processing method and system based on topology association, which aims to achieve accurate alarm integration, root cause location and adaptive level output through root cause scoring and dynamic classification.
[0019] The power plant alarm event processing method and system based on topology association provided in this application are specifically described through the following embodiments. First, the power plant alarm event processing method based on topology association in this application is described.
[0020] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence (AI) refers to the theories, methods, technologies, and application systems that use digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0021] Foundational technologies for artificial intelligence generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interactive systems, and mechatronics. AI software technologies mainly encompass computer vision, robotics, biometrics, speech processing, natural language processing, and machine learning / deep learning.
[0022] The power plant alarm event handling method based on topology association provided in this application relates to the field of electrical digital data processing technology. This method can be applied to a terminal, a server, or software running on either a terminal or a server. In some embodiments, the terminal can be a smartphone, tablet, laptop, desktop computer, etc.; the server can be configured as an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application implementing the power plant alarm event handling method based on topology association, but is not limited to the above forms.
[0023] This application can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0024] It should be noted that in all specific embodiments of this application, when processing data related to user identity or characteristics, such as user information, user behavior data, user historical data, and user location information, user permission or consent is obtained first. Furthermore, the collection, use, and processing of this data comply with relevant laws, regulations, and standards. In addition, when embodiments of this application require access to sensitive personal information of users, separate permission or consent from the user is obtained through pop-ups or redirection to confirmation pages. Only after obtaining the user's separate permission or consent is the necessary user-related data required for the proper functioning of these embodiments acquired.
[0025] Therefore, referring to Figure 1This application provides a power plant alarm event processing method based on topology association. This method is applied to a central controller, which can be a server, an electronic device, or a mobile terminal, etc. There are no specific limitations here. The method includes the following steps S110 to S160.
[0026] Step S110: Semantically analyze the initial alarm data of the target power plant to obtain structured alarm data; the target power plant includes at least two devices; Step S120: Construct the equipment object model of the target power plant; the equipment object model shall at least contain the topological relationships between the equipment. Step S130: Based on the device object model and structured alarm data, construct an alarm event cluster; Step S140: Based on the alarm event cluster, determine the core root cause alarm in the alarm event cluster; Step S150: Determine the final alarm level of the alarm event cluster based on the core root cause alarm, the corresponding equipment of the core root cause alarm, and the real-time operating conditions of the target power plant. Step S160: Based on the final alarm level and the core root cause alarm, generate structured alarm information for alarm event clusters.
[0027] In this step, since the original alarm data generated by different equipment (such as boilers, steam turbines, and feedwater pumps) during the operation of power plants has diverse formats and inconsistent descriptions, a set of alarm semantic specifications for power plants is first formulated, and an alarm semantic ontology model (including equipment hierarchical relationship mapping, measurement point category mapping relationship, and alarm action semantic template) is constructed. This model is used to perform multi-level mapping and parsing of equipment identifiers, measurement point numbers, process parameter semantic tags, and status modifiers in the original alarm text, transforming the unstructured original alarm data into structured alarm data containing fields such as equipment code, equipment name, alarm type, alarm parameters, parameter values, rated values, and alarm occurrence time.
[0028] For example, the message "Water pump P1: Outlet pressure 0.8MPa, lower than rated 1.2MPa" is parsed into a standardized record containing equipment code SB01, equipment name water pump P1, alarm type low pressure, parameter value 0.8MPa, rated value 1.2MPa, and alarm time 10:00:00, providing a unified data foundation for subsequent intelligent analysis.
[0029] Furthermore, a digital equipment object model is constructed. First, the equipment list, measurement point list, and rated operating parameters from the plant-level monitoring system are collected through standardized communication protocol interfaces to establish the basic equipment layer. Then, the logical configuration of process piping and instrumentation diagrams is parsed to identify upstream and downstream process connections and data associations between equipment, generating a topology association layer.
[0030] Furthermore, based on the internal equipment classification standards, each piece of equipment is automatically assigned an importance weight value, forming an attribute weight layer. Simultaneously, real-time operating status signals from the generating unit are input to initialize an operating condition adaptation layer, which describes the characteristic parameters and classification adjustment rules of the equipment under different operating conditions. Finally, by integrating the above four layers of information, a complete equipment object model is generated. This model includes the topological relationships between equipment, providing a structured equipment-dimensional knowledge graph for subsequent alarm clustering and root cause identification.
[0031] Furthermore, the scattered alarm information is clustered and integrated based on causal relationships. This is done in two levels: First, time-based clustering is performed, setting a configurable time window and grouping all alarms appearing within that window into a time-related alarm set. Then, topological clustering is performed: based on the topological relationship layer of the device object model, alarms belonging to the same topological link and having upstream and downstream causal relationships are selected. For example, alarms such as low feedwater pump pressure, high feedwater pump current, and low boiler drum water level are all located on the same propagation link in the feedwater system, therefore they are merged into the same alarm event cluster, and a unique cluster identifier is assigned to this cluster. Alarms not belonging to the same topological link (such as an alarm indicating normal induced draft fan speed unrelated to the fault) are excluded. Thus, each alarm event cluster represents a set of cascading alarms triggered by the same root cause fault, significantly reducing alarm redundancy.
[0032] Furthermore, for each alarm event cluster, four core features of each alarm within the cluster are first extracted: parameter deviation (the ratio of the deviation between the actual parameter value and the rated value), device importance weight (from the attribute weight layer of the device object model), topology coreness (the degree of criticality of the device in the topology link, with core devices having higher weight), and temporal sequence (the order in which alarms occur, with earlier alarms having higher weight).
[0033] Based on the contribution of each feature in the historical fault sample set to the final fault event, a feature influence coefficient matrix is pre-generated. During online operation, the four feature values of each alarm are multiplied by their corresponding feature influence coefficients and then weighted and summed to calculate the root cause score of the alarm. The alarm with the highest score is the core root cause alarm.
[0034] For example, in the alarm cluster caused by the failure of the water pump, the low water pump pressure alarm has the highest root cause score and is therefore identified as the core root cause alarm, indicating that the low water pump outlet pressure is the root cause of this cascading alarm.
[0035] Furthermore, the root cause score of the core root cause alarm is used as the basic classification criterion to set a scoring threshold range. For example, a score of 80 or higher is a Level 1 alarm (high risk), 60 to 80 is a Level 2 alarm (medium risk), and below 60 is a Level 3 alarm (low risk). Then, an initial adjustment is made based on the importance of the equipment: if the equipment corresponding to the core root cause alarm is a core main equipment, the basic level is raised by one level.
[0036] A second adjustment is made based on real-time operating conditions: if the unit is operating at full load or in steady state, with low fault tolerance and high safety risks, the alarm level is increased by one level; if it is in startup or maintenance condition, the level is decreased by one level (not lower than level three). After the above dynamic adjustments, the final alarm level of the alarm event cluster is determined.
[0037] Furthermore, information compression is performed: retain the complete information of core root cause alarms (including device name, parameters, time, root cause score, etc.), and for non-core related alarms within the cluster, only retain the device name, alarm type, and a brief description of core parameters, while removing irrelevant secondary information.
[0038] Furthermore, alarm event clusters are sorted and pushed according to their final alarm level from highest to lowest. Simultaneously, differentiated control strategies are generated based on the final alarm level: Level 1 alarms trigger a forced top display and audio-visual linkage output on the monitoring system's human-machine interface, alerting maintenance personnel to take immediate action; Level 2 alarms trigger a confirmation process on designated terminal positions, requiring manual confirmation; Level 3 alarms are sent to a delayed confirmation queue, automatically deactivated after the equipment status recovers. The final output includes structured alarm information such as cluster identifier, final alarm level, complete information on the core root cause alarm, brief description of related alarms, root cause scoring results, and the scope of fault impact, providing maintenance personnel with accurate and concise fault decision-making basis.
[0039] In some embodiments, the above-described construction of the equipment object model of the target power plant includes: Collect basic information, measuring point information, and rated operating parameters of all equipment in the target power plant to establish the equipment basic layer; Identify the upstream and downstream process connections and data associations among the various equipment in the target power plant to establish a topological association layer; Based on the preset power plant equipment classification standards, determine the weight values of each piece of equipment in the target power plant to establish an attribute weight layer; Access the real-time operating status signal of the target power plant to initialize the operating condition adaptation layer; A device object model is generated based on the equipment base layer, topology association layer, attribute weight layer, and operating condition adaptation layer.
[0040] In this embodiment, basic data is first read from the power plant’s plant-level monitoring information system, distributed control system, or data acquisition and monitoring control system through a standardized communication protocol interface (such as OPC UA, Modbus TCP, IEC 104).
[0041] The specific data collected includes: an equipment list (covering the codes, names, types, and systems of all physical equipment in the plant), a list of measuring points (each measuring point corresponds to a specific monitoring parameter, such as temperature, pressure, current, etc., and is associated with its respective equipment through the equipment code), and rated operating parameters (such as the equipment's rated power, rated pressure, normal operating range, and alarm thresholds). This data, after being processed, forms the equipment foundation layer, providing the lowest-level physical entity information support for subsequent topology analysis, weight assignment, and operating condition adaptation.
[0042] Above the equipment base layer, the logical configuration in the power plant process piping and instrumentation diagram (P&ID) is analyzed, or the equipment master data association relationship defined in the power plant production management system is read, thereby automatically identifying the upstream and downstream connection relationship and data association relationship between each piece of equipment.
[0043] For example, the outlet of the feedwater pump is connected to the inlet of the boiler drum, and the duct of the induced draft fan is connected to the furnace. The transmission paths of these process media (water, steam, and flue gas) constitute the topological connections of the equipment. By analyzing these relationships, directed topological links between equipment are generated, clarifying the upstream source and downstream destination of each equipment, forming a topological association layer. This layer is the core basis for topological dimension clustering when constructing subsequent alarm event clusters, used to determine whether multiple alarms are located on the same causal propagation link.
[0044] Furthermore, based on pre-defined power plant equipment classification standards (such as an internal equipment classification system for power plants), the importance of each piece of equipment in the equipment list is assessed. Primary equipment (such as core equipment like boilers, steam turbines, generators, feedwater pumps, and induced draft fans) is assigned a higher weight value (e.g., 1.0), important auxiliary equipment is assigned a medium weight value (e.g., 0.8), and general auxiliary equipment is assigned a lower weight value (e.g., 0.5). These weight values reflect the impact of equipment failures on the safe operation of the power plant and will be used as the key feature of "equipment importance weight" in the subsequent root cause scoring calculation. Finally, the weight values of all equipment are aggregated to form an attribute weight layer, providing the basic parameters for the equipment dimension of the quantitative model for root cause identification.
[0045] The system accesses real-time data interfaces to monitor the status of power plant units, including start-up and shutdown status, current load rate, and operating mode (start-up, steady state, full load, shutdown, maintenance, etc.). These real-time signals originate from the real-time database of a distributed control system or a data acquisition and monitoring control system, and are correlated with measurement point data in the measurement point list via timestamps. Based on these signals, a condition adaptation layer is initialized for the equipment object model. This layer describes the characteristic parameters of the equipment under different operating conditions and the adjustment rules for subsequent dynamic classification.
[0046] For example, when the unit is operating at full load in steady state, the equipment has a low tolerance for faults, and the alarm level should be increased accordingly; while under maintenance conditions, the alarm level can be appropriately reduced. The establishment of the operating condition adaptation layer enables the equipment object model to dynamically perceive the real-time operating environment, providing key input conditions for the dynamic hierarchical module.
[0047] Finally, the information from the four levels is integrated and correlated to form a complete equipment object model. This model uses the equipment foundation layer as the core entity, and is further linked to a topology association layer (describing the connections between equipment), an attribute weight layer (describing the importance weights of equipment), and an operating condition adaptation layer (describing the dynamic characteristics of equipment under different operating states). Each layer is logically linked through equipment coding, forming a unified digital object model. This model covers the attribute information, topology, weight parameters, and real-time operating condition characteristics of all equipment in the power plant, providing an equipment-dimensional knowledge graph for the structured alarm data after alarm semantic parsing. It serves as the foundation for subsequent alarm event cluster construction, root cause scoring, and dynamic grading.
[0048] In some embodiments, the above-mentioned construction of alarm event clusters based on the device object model and structured alarm data includes: Structured alarm data is clustered according to a preset time window to obtain a time-related alarm set; Based on the topology association layer of the device object model, alarm data belonging to the same topology link and having a causal relationship in the time-related alarm set are filtered out, so that the filtered alarm data can be classified into the same alarm event cluster.
[0049] In this embodiment, alarm information is initially aggregated from a time perspective. A configurable time window is set (default value is 30 seconds). This default value is set based on the fact that it is longer than the minimum data acquisition and processing cycle of the power plant's distributed control system or data acquisition and monitoring control system (usually 1-2 seconds), and statistical analysis of historical fault cases from multiple power plants shows that over 95% of cascading faults trigger associated alarms within this 30-second time window. In practical applications, users can also adjust this time window configuration according to the dynamic response characteristics of specific power plant equipment.
[0050] By performing a sliding scan of the structured alarm data according to this time window, all alarms appearing within the window are grouped into a time-related alarm set. For example, alarms such as low feedwater pump pressure, high feedwater pump current, and low boiler drum water level occurring between 10:00:00 and 10:00:30 are clustered into the same time set. This allows for the rapid capture of alarms with temporal proximity, narrowing the analysis scope for subsequent topological association filtering.
[0051] Furthermore, a refined selection process is performed from a topological perspective. Based on the topological association layer in the equipment object model, which describes the upstream and downstream process connections and data relationships between various devices in the power plant, a directed process topology graph is formed. For each alarm in the time-related alarm set, the position of its corresponding device in the topological association layer is located, and the alarms are traced upstream and downstream along the directed topological link to determine whether multiple alarms are located on the same process medium transmission path. Only when multiple alarms simultaneously meet the time proximity condition (guaranteed by time clustering) and belong to the same directed topological propagation link are they merged into the same alarm event cluster.
[0052] For example, the three alarms—low feedwater pump pressure, high feedwater pump current, and low boiler drum water level—are all located on the same topology link in the feedwater system (feedwater pump -> boiler drum) and have a causal relationship (low feedwater pump outlet pressure directly leads to low boiler drum water level). Therefore, they are clustered into the same alarm event cluster. Alarms that do not belong to the same topology link (such as alarms indicating normal induced draft fan speed unrelated to the fault) are excluded. Ultimately, each alarm event cluster is assigned a unique cluster identifier, representing a set of cascading alarms triggered by the same root cause fault, thus achieving effective integration of massive alarm data.
[0053] In some embodiments, determining the core root cause alarm within an alarm event cluster based on the alarm event cluster includes: Extract the parameter deviation, device importance weight, topology coreness, and temporal order of each alarm data in the alarm event cluster; A feature influence coefficient matrix is generated based on a pre-set historical fault sample set. Based on the feature influence coefficient matrix and the parameter deviation, equipment importance weight, topological core degree, and temporal order of each alarm data in the alarm event cluster, the root cause score of each alarm data in the alarm event cluster is calculated. The alarm data with root cause scores greater than a preset threshold in the root cause scoring are used to determine the core root cause alarm of the alarm event cluster.
[0054] In this embodiment, for each alarm event cluster, four core features of each alarm within the cluster are first extracted: The first feature is the parameter deviation, which is the ratio of the actual measured value of the alarm parameter to the rated value of the equipment. It is used to quantify the severity of the parameter deviation (for example, the deviation between the actual value of the water pump outlet pressure of 0.8 MPa and the rated value of 1.2 MPa is 0.33). The second feature is the equipment importance weight, which comes from the attribute weight layer of the equipment object model and reflects the criticality of the equipment in the power plant (e.g., main equipment weight 1.0, important auxiliary equipment weight 0.8). The third characteristic is topological coreness, which indicates the degree to which the device is central in the topological link. Devices located upstream or at the hub of the process transfer path have higher topological coreness. The fourth characteristic is temporal sequence. Alarms are assigned different weights according to their order of appearance within an event cluster. Usually, the first alarm to appear has a higher temporal weight because root cause alarms often occur earliest.
[0055] Among them, the parameter deviation degree represents the deviation between the actual value and the rated value of the alarm parameter in the alarm data; the topology core degree represents the coreness of the device corresponding to the alarm data in the topology link; and the temporal sequence represents the weight value corresponding to the order of occurrence of the alarm data in the alarm event cluster. Thus, by extracting these four features, multi-dimensional basic data is provided for subsequent quantitative root cause scoring.
[0056] Furthermore, an offline training method was used to establish the parameter basis of the root cause scoring model. Various failure cases and their corresponding alarm data from the power plant's history were collected, and the final root cause result was labeled for each failure sample. For these historical samples, the contribution of four features—parameter deviation, equipment importance weight, topology core degree, and temporal sequence—to the final failure event (such as shutdown or equipment damage) was statistically analyzed.
[0057] For example, regression analysis or weighted learning algorithms are used to calculate the influence coefficient of each feature in root cause identification. These four coefficients constitute a feature influence coefficient matrix. This matrix reflects the relative importance of different features in root cause determination: parameter deviation likely has the highest weight, followed by device importance and topology coreness, and then temporal sequence. Once generated, this matrix can be used during online operation to calculate the root cause score of alarms in real time.
[0058] During online operation, for each alarm in the alarm event cluster, its four extracted feature values are multiplied by the corresponding coefficients in the feature influence coefficient matrix. The products are then weighted and summed to obtain the root cause score for that alarm. Based on this, the score quantitatively represents the probability that each alarm is the root cause of the fault; a higher score indicates that the alarm is more likely to be the core root cause of the entire event cluster. This achieves objectivity and automation in root cause identification.
[0059] After calculating the root cause scores of all alarms within the alarm event cluster, this step determines the core root cause based on a preset scoring threshold. Preferably, the alarm with the highest score is directly identified as the core root cause alarm, or a threshold (e.g., 80 points) is set, and one or more alarms with the highest scores exceeding this threshold are identified as core root causes, providing a core basis for subsequent dynamic grading and compressed output. Simultaneously, the root cause scores of other alarms within the cluster also reflect their correlation with the core root cause, helping maintenance personnel to fully understand the cascading effects of the fault.
[0060] In some embodiments, determining the final alarm level of an alarm event cluster based on the core root cause alarm, the corresponding equipment of the core root cause alarm, and the real-time operating conditions of the target power plant includes: The basic alarm level is determined based on the root cause score of the core root cause alarm. Based on the importance level of the device corresponding to the core root cause alarm, the alarm base level is adjusted for the first time to obtain the first alarm adjustment level. Based on the real-time operating conditions of the target power plant, the alarm level after the first adjustment is adjusted a second time to obtain the final alarm level of the alarm event cluster.
[0061] In this embodiment, a basic alarm level is first established to ensure the objectivity and consistency of the classification results. For example, a mapping relationship between root cause scores and alarm levels is preset: core root cause alarms with a root cause score of 80 or higher are classified as Level 1 alarms (high risk); root cause alarms with a score between 60 and 80 are classified as Level 2 alarms (medium risk); and root cause alarms with a score below 60 are classified as Level 3 alarms (low risk). This basic classification rule uses the quantitative score of the core root cause as the sole basis.
[0062] Based on the importance level defined in the attribute weight layer of the equipment object model, determine whether the equipment corresponding to the core root cause alarm is critical equipment. Referring to the equipment classification standards in the "Safety Production Standards for Power Plants," main equipment (such as boilers, steam turbines, generators, feedwater pumps, etc.) belongs to core equipment, and its failure has a wider impact and higher safety risks. Therefore, if the equipment corresponding to the core root cause alarm is core main equipment, the alarm's basic level will be raised by one level.
[0063] For example, a water pump is a core main device, and its basic alarm level is Level 1. Even after being upgraded to Level 1, it remains Level 1 (having reached the highest level). If the basic alarm level of a core root cause is Level 2, and the corresponding device is a core main device, then it will be upgraded to Level 1.
[0064] The current operating condition is determined based on real-time operating status signals from the power plant (such as start-up / shutdown status and load factor). Specific adjustment rules are as follows: When the unit is operating at full load or in a steady-state condition, the equipment has a lower tolerance for faults, and the risk of a fault evolving into an accident is higher; therefore, the alarm level is increased by one level. When the unit is in start-up or maintenance condition, some equipment is in an unstable state, and the sensitivity to alarms can be appropriately reduced; therefore, the alarm level is decreased by one level (not lower than level three).
[0065] For example, a low water pump pressure alarm, under full-load steady-state conditions, will remain at level one even though its base level is already level one. However, if an alarm's base level is level three, under full-load conditions, after a first adjustment based on equipment importance (upgrading to level two if it's core equipment), and then a second adjustment based on operating conditions (upgrading by one level again under full load), it may be upgraded to level one. The level obtained after these two dynamic adjustments is the final alarm level for the alarm event cluster. Thus, this embodiment enables the alarm level to accurately match the severity of the actual fault, effectively solving the problems of "falsely high alarms" and "missed high-risk alarms."
[0066] In some embodiments, the structured alarm information that generates alarm event clusters based on the final alarm level and the core root cause alarm includes: Each alarm data in the alarm event cluster is divided into a first event and a second event; the first event includes the core root cause alarm; the second event represents the alarm data in the alarm event cluster other than the core root cause alarm. Extract the device name, alarm type, and a brief description of the core parameters from the alarm data in the second event; Based on the device name, alarm type, and core parameter summary of the alarm data in the first and second events, generate initial alarm information; Structured alarm information is generated based on the final alarm level and the initial alarm information.
[0067] In this embodiment, all alarm data within the alarm event cluster is first classified. The core root cause alarm is designated as the first event because it represents the root cause of the fault, and all its information needs to be fully retained so that maintenance personnel can directly locate the problem. All other alarms within the event cluster, excluding the core root cause alarm, are designated as the second event. These alarms are chain reactions or accompanying phenomena triggered by the same root cause fault, which help in understanding the propagation path and scope of the fault, but do not need to be presented with the same level of detail as the core root cause alarm.
[0068] Furthermore, for each associated alarm in the second event, information compression is performed. Unlike core root cause alarms, which require retaining complete alarm fields (such as device code, parameter values, rated values, alarm time, root cause score, etc.), for non-core associated alarms, only the most critical information elements are extracted. This aims to reduce the amount of redundant information pushed while retaining the basic clues necessary for maintenance personnel to understand the full picture of the fault. Specifically, this includes: the name of the device that triggered the alarm, the alarm type, and a brief description of the core parameters.
[0069] After processing the information from the first and second events separately, they are combined to form the initial alarm information structure. The first event provides complete information on the core root cause alarm (including device name, alarm type, parameter value, rated value, alarm time, root cause score, etc.), while the second event provides brief information on each related alarm (only device name, alarm type, and brief description of core parameters). These two parts of information are organized in a logical order, for example, listing the core root cause alarm first, and then listing each related alarm in list or summary form. The initial alarm information generated in this way highlights the root cause of the fault and shows the cascading effects of the fault, forming a complete content body for adding subsequent level information.
[0070] Finally, the final alarm level (i.e., the Level 1, Level 2, or Level 3 alarm level determined after dynamic grading) is merged with the initial alarm information to form the final structured alarm information. Specifically, this structured alarm information includes the following core fields: a unique cluster identifier for the alarm event cluster, the final alarm level, complete information on the core root cause alarm, a brief list of associated alarms, root cause scoring results, and the fault impact range inferred based on the device object model.
[0071] Furthermore, based on the final alarm level, this embodiment will generate differentiated push strategies: Level 1 alarms trigger a forced top display and audio-visual linkage output on the monitoring system's human-machine interface; Level 2 alarms trigger a confirmation process on designated personnel terminals; Level 3 alarms are sent to a delayed confirmation queue and automatically deactivated based on the equipment status recovery signal. Thus, the final structured alarm information output can provide maintenance personnel with accurate, concise, and tiered fault decision-making basis, significantly improving fault handling efficiency.
[0072] In one embodiment, the above-mentioned power plant alarm event processing method based on topology association is applied to construct an integrated alarm classification system based on equipment object model + event cluster + root cause identification. The overall implementation process is as follows: raw alarm data input → alarm semantic parsing → equipment object model matching → construction of alarm event clusters in two dimensions of time and topology → quantitative identification of root cause scoring model → dynamic classification based on equipment attributes and operating conditions → compressed output based on root causes and event clusters. Each link is seamlessly connected and data is interconnected, realizing standardized, intelligent and accurate processing of power plant alarm data. The specific implementation steps are as follows: 1. Alarm Semantic Parsing Module: This module establishes a general alarm semantic specification for power plants, used to parse raw input alarm data into structured alarm data. The structured alarm data includes at least the following fields: equipment code, equipment name, alarm type, alarm parameters, parameter values, upper threshold, lower threshold, alarm occurrence time, and alarm status. Semantic parsing is achieved through a predefined power plant alarm semantic ontology model. This model defines the mapping relationship between alarm text and structured fields, performing multi-level mapping parsing of equipment identifiers, measurement point numbers, process parameter semantic tags, and status modifiers in the alarm text. The semantic ontology model includes at least equipment hierarchy relationships, measurement point category mapping relationships, and alarm action semantic templates to achieve a unified structured expression of alarm data from heterogeneous distributed control systems (DCS) or supervisory control and data acquisition (SCADA) systems, transforming it into standardized structured alarm data and providing standardized data input for subsequent processes. The original alarm data can be either online alarm data collected in real time by the power plant or historical alarm data; preferably, real-time alarm data is input in online operation scenarios, and historical alarm data is input in model training or rule optimization scenarios.
[0073] Specifically, the alarm semantic parsing module adopts a three-layer architecture of "input-processing-output". The input layer receives online real-time or historical alarm data from heterogeneous DCS / SCADA systems; the intermediate core processing layer performs multi-level mapping and parsing of elements such as equipment identifiers and measurement point numbers in the original alarm text through the "General Alarm Semantic Specification for Power Plants" and the "Alarm Semantic Ontology Model" (which includes equipment hierarchy relationships, measurement point category mapping, and alarm action semantic templates); the output layer finally generates structured alarm data containing key fields such as equipment codes, alarm types, and parameter values, providing standardized input for subsequent modules.
[0074] 2. Equipment Object Model Module: Constructs a digital object model of all equipment in the power plant. The construction method for this model is as follows: (1) Data acquisition: Read data from the power plant’s plant-level monitoring information system (SIS), distributed control system (DCS) or SCADA through standardized interfaces (such as OPC UA, Modbus TCP, 104) to obtain equipment list, measurement point list and basic parameters.
[0075] The equipment list refers to the collection of all physical equipment in the power plant, including equipment codes, equipment names, equipment types and their respective systems; the monitoring point list refers to the collection of monitoring points installed on the equipment, with each monitoring point corresponding to a specific monitoring parameter (such as temperature, pressure, current, etc.); the basic parameters include the equipment's rated parameters, operating range and alarm thresholds; and the equipment list and the monitoring point list are linked through equipment codes, meaning that each monitoring point belongs to a unique piece of equipment.
[0076] (2) Automatic topology identification: Parse the logical configuration of the process piping and instrumentation diagram (P&ID) in the SIS, DCS, and SCADA systems, or read the equipment master data association relationship defined in the power plant production management system. Based on the logical configuration of the process piping and instrumentation diagram (P&ID), determine the process connection relationship and data association relationship between each piece of equipment in the equipment list, thereby automatically identifying the upstream and downstream connection relationship between equipment and generating the topology association layer.
[0077] (3) Automatic weight assignment: Based on the level of each equipment in the equipment list in the "Safety Production Specifications for Power Plants" or the internal equipment classification standard of the power plant (such as main equipment, important auxiliary equipment, and general auxiliary equipment), the attribute weight value of each equipment in the equipment object model is automatically assigned. The weight is used as the input parameter of the equipment importance feature in the subsequent root cause scoring model calculation to affect the root cause scoring result (such as main equipment weight 1.0, important auxiliary equipment weight 0.8, and general auxiliary equipment weight 0.5).
[0078] (4) Initialization of the operating condition adaptation layer: The real-time operating status signals of the unit (such as start-up / shutdown status, load rate) in the DCS or SCADA system are accessed to dynamically update the operating condition adaptation layer. The operating condition adaptation layer is used to describe the operating characteristic parameters and graded adjustment rules of the equipment under different operating states (including start-up, steady state, full load, shutdown, maintenance, etc.). The real-time operating status signals of the unit are associated with the measurement point data in the measurement point list through timestamps to characterize the current equipment operating environment and serve as the input conditions for the dynamic grading module. (5) Manual review and correction: Based on the automatically generated equipment object model (generated by the data acquisition and topology identification steps), a visual interface is provided for operation and maintenance personnel to manually review and correct the equipment relationships, weight parameters and operating rules in the model.
[0079] The model ultimately includes a basic equipment layer (equipment code, name, type, installation location), a topology association layer (upstream and downstream related equipment, topology connection relationship), an operating parameter layer (rated parameters, normal operating range, fault threshold), an attribute weight layer (equipment importance weight, fault impact weight), and an operating condition adaptation layer (parameter characteristics of different operating conditions such as start-up, steady state, shutdown, and maintenance).
[0080] Specifically, the system first collects equipment lists and other data from SIS / DCS / SCADA via standardized interfaces such as OPC UA. Based on P&ID logical configuration, it automatically identifies topology relationships and assigns weights to equipment according to power plant safety production standards (e.g., main equipment weight 1.0). Simultaneously, it accesses real-time unit operating status signals to initialize the operating condition adaptation layer. Finally, it supports manual review and correction. Each stage corresponds to a layer in the equipment object model module, including the equipment foundation layer, topology association layer, operating parameter layer, attribute weight layer, and operating condition adaptation layer, providing fundamental data support for alarm clustering, root cause identification, and dynamic classification.
[0081] 3. Alarm Event Cluster Construction Module: Taking structured alarm data and device object models as input, a time window is set (configurable, default 30 seconds, the basis for setting this default value is: longer than the data acquisition cycle of the DCS or SCADA system and covering more than 95% of the time range of chained alarms). First, the structured alarm data within the time window is clustered by time to obtain a time-related alarm set; then, combined with the topology association layer of the device object model, the time-related alarm set is clustered by topology to filter out alarms belonging to the same topology link and having causal relationship, and finally forming an alarm event cluster. Each event cluster is assigned a unique cluster ID and records the structured information and topology association information of all alarms in the cluster.
[0082] Specifically, the alarm event cluster construction module takes structured alarm data and the topological association layer of the device object model as input. First, it performs a first-level clustering (time-based clustering), aggregating alarm data within a default 30-second time window (configurable, covering over 95% of cascading alarms) to form a time-related alarm set. Then, it performs a second-level clustering (topological clustering), filtering alarms belonging to the same topological link and having a causal relationship based on the topological association layer. Finally, it outputs alarm event clusters with unique cluster IDs, achieving precise integration of related alarms.
[0083] 4. Root cause scoring model module: for each alarm event cluster, four core features are extracted: parameter deviation degree of each alarm in the cluster ((actual parameter value - rated parameter value) / rated parameter value), device importance weight (from the attribute weight layer of the device object model), topological core degree (the core degree of the device in the topological link, with higher weight for core devices), and temporal sequence (the time sequence of alarms triggered by faults, with higher weight for alarms occurring earlier); based on the contribution of each alarm feature in the historical fault sample set to the final shutdown event, a feature influence coefficient matrix is generated offline, and said feature influence coefficient matrix is called in the online operation phase to complete root cause score calculation.
[0084] Specifically, the root cause scoring model module takes a single alarm event cluster as input, and first extracts four core features: parameter deviation degree, device importance weight, topological core degree and temporal sequence. At the computing level, the root cause scoring model module adopts an offline-online linkage mode: in the offline phase, the contribution of each feature to the shutdown event is calculated based on the historical fault sample set to generate the feature influence coefficient matrix; in the online phase, said matrix is called to complete the quantitative calculation of the root cause score in combination with the four extracted features, and finally output the root cause score of each alarm in the event cluster, providing a basis for dynamic grading.
[0085] 5. Dynamic grading module: taking the root cause score of the core root cause alarm as the basic grading basis, basic grading thresholds are set (default: score ≥80 is level 1 alarm (high risk), 60 ≤ score < 80 is level 2 alarm (medium risk), score < 60 is level 3 alarm (low risk)); dynamic adjustment is then performed in combination with the device importance weight of the device object model and real-time working conditions, with the adjustment rules as follows: the basic alarm level of core devices is increased by 1 level (basis: faults of core devices have a wider impact range, defined in accordance with *Code for Safety Production of Power Plants*); the basic alarm level when the unit is operating at full load / steady state is increased by 1 level (basis: devices have lower fault tolerance under high-load working conditions, with higher safety risks); the basic alarm level under start-up / maintenance working conditions is decreased by 1 level (the minimum level is level 3). The grade increase / decrease range (1 level) of the above adjustment rules is a typical configuration value, which can be modified by the user according to actual safety management requirements; the final alarm grade of each alarm event cluster is finally output.
[0086] Specifically, the grading process of the dynamic grading module is divided into three layers: first, the basic grading layer determines the basic alarm level according to the score of the core root cause alarm and the preset thresholds (score ≥80 is level 1 high risk, 60≤score≤80 is level 2 medium risk, score < 60 is level 3 low risk). Then, the dynamic adjustment layer performs secondary calibration on the basic level in combination with device importance (increase the level by 1 for core devices) and real-time working conditions (increase the level by 1 for full load / steady state operation, decrease the level by 1 for start-up / maintenance working conditions). Finally, the output layer generates the final alarm grade of each alarm event cluster.
[0087] 6. Alarm Compression Output Module: For each alarm event cluster, based on the final alarm level and root cause identification results, the module compresses and structures the alarm information for output. It retains complete information on the core root cause alarm, and for associated alarms, only retains brief information such as device name, alarm type, and core parameters. Alarms are pushed in descending order of final alarm level, and differentiated control strategies are generated based on the final alarm level. Level 1 alarms trigger forced top placement and audio-visual linkage output on the DCS or SCADA HMI; Level 2 alarms trigger a confirmation process on a designated terminal; and Level 3 alarms enter a delayed confirmation queue and are automatically deactivated based on the device's recovery status. The output includes cluster ID, final alarm level, complete information on the core root cause alarm, brief description of associated alarms, root cause scoring results, and fault impact range (based on the device topology model).
[0088] Specifically, the alarm compression output module takes into account the final alarm level and root cause identification results. At the core processing layer, alarm information is first compressed (retaining complete core root cause information, while only brief descriptions of associated alarms are retained), and then sorted from highest to lowest alarm level. The output layer consists of two parts: first, a structured alarm event cluster report (including cluster ID, level, root cause details, etc.); second, differentiated control strategies, where a Level 1 alarm triggers forced top placement of the DCS / SCADA interface and audible / visual linkage, a Level 2 alarm triggers a job confirmation process, and a Level 3 alarm enters a delayed confirmation queue.
[0089] Based on this, this embodiment reconstructs the software algorithms and processing flow of the existing power plant monitoring system, creating an integrated closed-loop system of "semantic parsing → equipment modeling → event clusters → root cause identification → dynamic grading → compressed output". Data is interconnected and logically coordinated across all stages, achieving end-to-end processing. A time-plus-topology dual-dimensional alarm event cluster construction method is proposed, designed for the topological characteristics of power plant equipment and the temporal characteristics of fault alarms, achieving accurate integration of related alarms. A multi-feature weighted root cause scoring model is constructed to achieve quantitative identification of fault root causes and assessment of their impact, improving accuracy. A dynamic grading mechanism based on root cause scoring, equipment importance, and operating conditions is established, ensuring that the grading results accurately match the actual severity of faults, overcoming the limitations of fixed thresholds. Based on the root cause identification results and alarm event clusters, integrated compression is performed, not simply reducing the number of events, but retaining core information and integrating related information, while structuredly pushing grading and root cause results. A universal alarm semantic parsing specification and a full-equipment object model for power plants are established, achieving standardized processing of alarm data and intelligent upgrading of alarm grading and classification, laying the foundation for subsequent intelligent analysis.
[0090] In one embodiment, taking a cascading alarm triggered by a boiler feedwater pump malfunction in a thermal power plant as an example, the specific application process of this application is illustrated, and the specific implementation steps are as follows: 1. Original alarm data input: (1) "Feed pump P1: outlet pressure 0.8MPa, lower than rated 1.2MPa, 10:00:00"; (2) "Boiler drum: water level 100mm, lower than rated 200mm, 10:00:15"; (3) "Feed pump P1: motor current 80A, higher than rated 60A, 10:00:05"; (4) "Induced draft fan F2: speed 1200r / min, normal, 10:00:20" (irrelevant alarm). It can be seen that the original alarm data is not uniform in format.
[0091] 2. Alarm semantic parsing: Parsing is performed according to preset specifications to convert the data into structured data, and core fields are extracted, as shown in Table 1: Table 1
[0092] 3. Equipment object model matching: Matching the equipment object model of the thermal power plant, it is found that: feedwater pump P1 is the core upstream equipment of the boiler (topological core degree 0.9), equipment importance weight 0.9; boiler drum is the core equipment (topological core degree 1.0, equipment importance weight 1.0); induced draft fan F2 has no direct topological association with feedwater pump / boiler drum; the current unit is operating at full load in steady state (the operating condition adaptation layer is marked as steady state).
[0093] 4. Construction of alarm event clusters: Set a time window of 30 seconds, first perform time clustering. The above 4 alarms all fall within 10:00:00-10:00:30, forming a time-related alarm set; then perform topological clustering, remove the normal alarm of induced draft fan F2 that has no direct topological association, and cluster the low pressure of feedwater pump P1, high current of feedwater pump P1, and low water level of boiler drum into alarm event cluster C001.
[0094] 5. Root Cause Scoring Model Calculation: Extract four core features from the three alarms within the cluster. Based on the contribution of each alarm feature to the final shutdown event from the historical fault sample set, generate a feature influence coefficient matrix offline. During the online operation phase, call the feature influence coefficient matrix to complete the root cause scoring calculation (assuming the calculated parameter deviation is 0.4, equipment importance is 0.2, topology coreness is 0.2, and time chronology is 0.2). Calculate the root cause score: (1) Low pressure of water pump P1: Parameter deviation = |(0.8-1.2)| / 1.2 = 0.33; Equipment importance 0.9; Topological coreness 0.9; Time sequence 1.0 (first to appear) → Root cause score = 0.33×0.4+0.9×0.2+0.9×0.2+1.0×0.2 = 0.812 (81.2 points).
[0095] (2) High current of water pump P1: Parameter deviation = (80-60) / 60 = 0.33; Equipment importance 0.9; Topological coreness 0.9; Time sequence 0.8 → Root cause score = 0.33×0.4+0.9×0.2+0.9×0.2+0.8×0.2 = 0.772 (77.2 points).
[0096] (3) Boiler drum water level is low: parameter deviation = (100-200) / 200 = 0.5; equipment importance 1.0; topological coreness 1.0; time sequence 0.6 → root cause score = 0.5×0.4+1.0×0.2+1.0×0.2+0.6×0.2 = 0.72 (72 points) The low pressure of feedwater pump P1 is determined to be the core root cause alarm (the highest score is 81.2 points).
[0097] 6. Dynamic classification: The core root cause score is 81.2 points, and the basic classification is Level 1 alarm (high risk); the current unit is operating at full load in steady state, and the feedwater pump P1 is the core equipment. According to the adjustment rules, there is no need to upgrade it further (it is already at the highest level). The final alarm level of the final alarm event cluster C001 is Level 1 (high risk).
[0098] 7. Alarm Compression Output: The alarm event cluster C001 is compressed, irrelevant information is removed, and a structured push of the Level 1 alarm is generated. The output content is as follows: [Level 1 High-Risk Alarm - Cluster ID: C001], its core root cause: low outlet pressure of feedwater pump P1 (SB01), parameter value 0.8MPa, rated value 1.2MPa, alarm time 10:00:00, root cause score 81.2 points; related alarms: high current of feedwater pump P1 (77.2 points), low water level of boiler drum (72 points); scope of fault impact: boiler feedwater system → boiler drum water level system; push method: real-time pop-up window of monitoring system + SMS reminder of operation and maintenance personnel.
[0099] Based on this, this embodiment quickly integrates scattered alarm data into alarm event clusters, accurately locates the core root cause as low pressure of water pump P1, dynamically determines it as a level one high-risk alarm, and integrates related information for precise push, so that operation and maintenance personnel can directly deal with the core root cause, which greatly improves the efficiency of fault handling.
[0100] like Figure 2 As shown in some embodiments of this application, a power plant alarm event processing system based on topology association is provided. The system includes a parsing module 210, a construction module 220, a first module 230, a second module 240, a third module 250, and a fourth module 260. Specifically: The parsing module 210 is used to perform semantic parsing on the initial alarm data of the target power plant to obtain structured alarm data; the target power plant includes at least two devices; Module 220 is used to construct the equipment object model of the target power plant; the equipment object model contains at least the topological relationships between equipment. The first module 230 is used to construct alarm event clusters based on the device object model and structured alarm data; The second module 240 is used to determine the core root cause alarm in the alarm event cluster based on the alarm event cluster; The third module 250 is used to determine the final alarm level of the alarm event cluster based on the core root cause alarm, the corresponding equipment of the core root cause alarm, and the real-time operating conditions of the target power plant. The fourth module 260 is used to generate structured alarm information for alarm event clusters based on the final alarm level and the core root cause alarm.
[0101] It should be noted that the power plant alarm event processing system based on topology association provided in this embodiment is based on the same inventive concept as the power plant alarm event processing method based on topology association described above. Therefore, the relevant content of the power plant alarm event processing method based on topology association described above also applies to the content of the power plant alarm event processing system based on topology association. Therefore, it will not be repeated here.
[0102] The system performs semantic parsing on the initial alarm data of the target power plant to obtain structured alarm data. The target power plant includes at least two devices. An equipment object model of the target power plant is constructed, containing at least the topological relationships between devices. Based on the equipment object model and the structured alarm data, alarm event clusters are constructed. The core root cause alarm information within each alarm event cluster is determined. Based on the core root cause alarm information, the corresponding devices, and the real-time operating conditions of the target power plant, the final alarm level of each alarm event cluster is determined. Based on the final alarm level and the core root cause alarm information, structured alarm information for each alarm event cluster is generated. In this way, precise alarm integration, root cause localization, and adaptive level output can be achieved through root cause scoring and dynamic grading.
[0103] This application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-described power plant alarm event handling method based on topology association.
[0104] like Figure 3 , Figure 3 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application. The electronic device includes: At least one battery; At least one memory; At least one processor; At least one program; The program is stored in memory, and the processor executes at least one program to implement the above-described method for handling power plant alarm events based on topology association.
[0105] This electronic device can be any smart terminal, including mobile phones, tablets, personal digital assistants (PDAs), and in-vehicle computers.
[0106] The electronic devices according to embodiments of this application will now be described in detail.
[0107] The processor 1600 can be implemented using a general-purpose central processing unit (CPU), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this disclosure. The memory 1700 can be implemented as a read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory 1700 can store the operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1700 and is called and executed by the processor 1600 to execute a power plant alarm event handling method based on topology association according to an embodiment of this disclosure.
[0108] The input / output interface 1800 is used to implement information input and output. The communication interface 1900 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). Bus 2000 transmits information between various components of the device (e.g., processor 1600, memory 1700, input / output interface 1800, and communication interface 1900); The processor 1600, memory 1700, input / output interface 1800 and communication interface 1900 are connected to each other within the device via bus 2000.
[0109] This disclosure also provides a storage medium, which is a computer-readable storage medium storing computer-executable instructions for causing a computer to execute the above-described power plant alarm event handling method based on topology association.
[0110] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0111] The embodiments described in this disclosure are for the purpose of more clearly illustrating the technical solutions of this disclosure and do not constitute a limitation on the technical solutions provided by this disclosure. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by this disclosure are also applicable to similar technical problems.
[0112] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this disclosure, and may include more or fewer steps than shown, or combine certain steps, or different steps.
[0113] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0114] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.
[0115] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any related variations, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0116] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0117] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0118] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0119] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0120] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause an electronic device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0121] The above is a detailed description of the preferred embodiments of this application. However, the embodiments of this application are not limited to the above-described implementation methods. Those skilled in the art can make various equivalent modifications or substitutions without departing from the spirit of the embodiments of this application. All such equivalent modifications or substitutions are included within the scope defined by the claims of the embodiments of this application.
[0122] The embodiments of this application have been described in detail above with reference to the accompanying drawings. However, this application is not limited to the above embodiments. Within the scope of knowledge possessed by those skilled in the art, various changes can be made without departing from the spirit of this application.
Claims
1. A method for handling power plant alarm events based on topological association, characterized in that, The method includes: The initial alarm data of the target power plant is semantically parsed to obtain structured alarm data; the target power plant includes at least two devices. Construct an equipment object model for the target power plant; the equipment object model shall at least include the topological relationships between the equipment. Based on the device object model and the structured alarm data, an alarm event cluster is constructed; Based on the alarm event cluster, determine the core root cause alarm in the alarm event cluster; Based on the core root cause alarm, the corresponding equipment of the core root cause alarm, and the real-time operating conditions of the target power plant, the final alarm level of the alarm event cluster is determined. Based on the final alarm level and the core root cause alarm, structured alarm information for the alarm event cluster is generated.
2. The power plant alarm event processing method based on topological association according to claim 1, characterized in that, The construction of the equipment object model of the target power plant includes: Collect basic information, measuring point information, and rated operating parameters of all equipment in the target power plant to establish the equipment basic layer; Identify the upstream and downstream process connections and data associations between various equipment in the target power plant to establish a topological association layer; Based on the preset power plant equipment classification standard, the weight value of each piece of equipment in the target power plant is determined to establish an attribute weight layer; Access the real-time operating status signal of the target power plant to initialize the operating condition adaptation layer; The device object model is generated based on the device base layer, the topology association layer, the attribute weight layer, and the operating condition adaptation layer.
3. The power plant alarm event processing method based on topological association according to claim 1, characterized in that, The construction of alarm event clusters based on the device object model and the structured alarm data includes: The structured alarm data is clustered according to a preset time window to obtain a time-related alarm set; Based on the topology association layer of the device object model, alarm data belonging to the same topology link and having a causal relationship in the time-related alarm set are filtered out, so that the filtered alarm data are classified into the same alarm event cluster.
4. The power plant alarm event processing method based on topological association according to claim 1, characterized in that, The step of determining the core root cause alarm in the alarm event cluster based on the alarm event cluster includes: Extract the parameter deviation, device importance weight, topology core degree, and temporal order of each alarm data in the alarm event cluster; Based on a pre-set historical fault sample set, a feature influence coefficient matrix is generated. Based on the feature influence coefficient matrix and the parameter deviation, device importance weight, topological core degree, and temporal order of each alarm data in the alarm event cluster, calculate the root cause score of each alarm data in the alarm event cluster; The alarm data with root cause scores greater than a preset threshold in the root cause scoring are used to determine the core root cause alarm of the alarm event cluster.
5. The power plant alarm event processing method based on topological association according to claim 4, characterized in that, The parameter deviation degree characterizes the deviation between the actual value and the rated value of the alarm parameter in the alarm data; the topology core degree characterizes the coreness of the device corresponding to the alarm data in the topology link; the temporal sequence characterizes the weight value corresponding to the order of occurrence of the alarm data in the alarm event cluster.
6. The power plant alarm event processing method based on topological association according to claim 1, characterized in that, The step of determining the final alarm level of the alarm event cluster based on the core root cause alarm, the corresponding equipment of the core root cause alarm, and the real-time operating conditions of the target power plant includes: The basic alarm level is determined based on the root cause score of the core root cause alarm. Based on the importance level of the device corresponding to the core root cause alarm, the alarm base level is adjusted for the first time to obtain the first alarm adjustment level; Based on the real-time operating conditions of the target power plant, the alarm level after the first adjustment is adjusted a second time to obtain the final alarm level of the alarm event cluster.
7. The power plant alarm event processing method based on topological association according to claim 1, characterized in that, The structured alarm information for generating the alarm event cluster based on the final alarm level and the core root cause alarm includes: Each alarm data in the alarm event cluster is divided into a first event and a second event; the first event includes the core root cause alarm; the second event represents alarm data in the alarm event cluster other than the core root cause alarm. Extract the device name, alarm type, and a brief description of core parameters from the alarm data in the second event; Based on the device name, alarm type, and core parameter summary of the alarm data in the first and second events, generate initial alarm information; The structured alarm information is generated based on the final alarm level and the initial alarm information.
8. A power plant alarm event processing system based on topological association, characterized in that, The system includes: The parsing module is used to perform semantic parsing on the initial alarm data of the target power plant to obtain structured alarm data; the target power plant includes at least two devices; A construction module is used to construct an equipment object model of the target power plant; the equipment object model includes at least the topological relationships between equipment. The first module is used to construct an alarm event cluster based on the device object model and the structured alarm data; The second module is used to determine the core root cause alarm in the alarm event cluster based on the alarm event cluster; The third module is used to determine the final alarm level of the alarm event cluster based on the core root cause alarm, the corresponding equipment of the core root cause alarm, and the real-time operating conditions of the target power plant. The fourth module is used to generate structured alarm information for the alarm event cluster based on the final alarm level and the core root cause alarm.
9. An electronic device, characterized in that, It includes at least one control processor and a memory for communicatively connecting to the at least one control processor; the memory stores instructions executable by the at least one control processor, which, when executed by the at least one control processor, enable the at least one control processor to perform a power plant alarm event handling method based on topology association as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions for causing a computer to perform a power plant alarm event handling method based on topology association as described in any one of claims 1 to 7.