An industrial control sequence generation method and system with dynamic physical constraint checking

CN122736279APending Publication Date: 2026-09-11BEIJING EASY TIMES DIGITAL TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611210713.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-11
Publication Date
2026-09-11

AI Technical Summary

Technical Problem

[0005]鉴于此,本发明提出了一种动态物理约束校验的工业控制序列生成方法及系统,旨在解决生成结果与实际运行条件存在偏差,难以保证生成结果满足工业控制的安全性和可靠性要求,影响控制序列生成效率和实时性的问题

Benefits of technology

[0015] Compared with existing technologies, the beneficial effects of this invention are as follows: In terms of security and reliability, this invention achieves absolute security at the physical level and "zero illusion" in control commands. This invention does not rely on the self-judgment of a large model, but rather infers that "dual physical hard constraints must be imposed at the source and the output." At the input end, the Dynamic Integrity Operation Window (IOW) is calculated using real-time telemetry data, directly masking unsafe historical procedure vectors and blocking dangerous associations and cognitive poisoning by the large model. At the output end, by forcing the large model to generate a Directed Acyclic Graph (DAG) and performing deterministic dimensionality reduction compilation without a neural network, the interpretive ambiguity caused by divergent natural language is suppressed. Combined with exhaustive verification of the state machine model, this ensures that every system control action is supported by rigorous mathematical and physical proofs. In terms of operating efficiency, computational cost, and reaction speed, this invention reduces the probability of generating control sequences that do not conform to physical rules, improves the reliability of control sequences through formal verification and physical simulation before execution, reduces the number of invalid reconstructions and shortens the convergence time, and outputs control sequences that meet security constraints under preset verification conditions. The reasoning logic of this invention lies in "using mathematical proof to guide precise approximation": when verification fails, the unsatisfiable core containing counterexample trajectories is extracted, and it is transformed into adversarial prompts with mandatory preconditions through abductive reasoning. This mechanism instantly reduces the open correction space of a large model to a strongly constrained local fixed-point repair. This not only achieves an optimal balance between computing power and timeliness, but also enables the system to respond extremely quickly to dynamic and complex industrial scheduling (such as emergency switching of chemical processes and smart grid switching operations).

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122736279A_ABST
    Figure CN122736279A_ABST
Patent Text Reader

Abstract

This invention relates to the field of industrial control technology and discloses a method and system for generating industrial control sequences with dynamic physical constraint verification. The method includes: acquiring operation requests and real-time telemetry data; determining the boundary threshold of the dynamic integrity operation window of the target device; performing constraint retrieval in a vector database based on the boundary threshold; extracting the security context; generating an intermediate-state directed acyclic graph (DAG) based on the operation request and security context; performing temporal logic verification and physical simulation verification based on the intermediate-state DAG; when verification fails, outputting counterexample trajectories and extracting unsatisfiable kernels, converting the unsatisfiable kernels into adversarial repair prompts; regenerating the intermediate-state DAG based on the adversarial repair prompt feedback until verification passes; and when verification passes, distributing the industrial control code to the industrial system for execution. This application achieves deterministic generation of industrial control sequences.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial control technology, and more specifically, to a method and system for generating industrial control sequences with dynamic physical constraint verification. Background Technology

[0002] With the rapid development of industrial automation, intelligent manufacturing, and the Industrial Internet, industrial control systems are gradually evolving from traditional rule-driven models to intelligent decision-making models. In high-risk and complex industrial scenarios such as chemical production, power dispatching, metallurgical manufacturing, and nuclear power operation, the quality of Standard Operating Procedures (SOPs) and control sequences directly affects production efficiency, equipment safety, and personnel safety. Therefore, how to quickly and accurately generate industrial control sequences that meet process constraints and safety requirements has become an important research direction in the field of industrial intelligence.

[0003] Currently, common industrial control sequence generation schemes include: receiving operation requests; retrieving historical operating procedures related to the operation request from a knowledge base; using the retrieval results as context input to a large language model to generate operation steps; performing simple logical checks or semantic corrections on the generated results; and then converting the generated control commands into equipment execution commands and sending them to the field control system for execution. However, existing technologies still have the following problems in actual industrial applications: Existing retrieval-enhanced generation schemes mainly rely on static knowledge bases for retrieval, making it difficult to fully integrate real-time changes in equipment status and operating conditions in the industrial field. When equipment is in abnormal or boundary conditions, historical operating procedures that do not match the current state may still be retrieved, leading to deviations between the generated results and actual operating conditions. The results generated by the large language model have a certain degree of uncertainty, while industrial control scenarios have strict requirements for control logic, execution timing, and safety rules. Existing schemes lack systematic verification methods for control sequences, making it difficult to ensure that the generated results meet the safety and reliability requirements of industrial control. When the generated control sequence has logical conflicts or process constraint conflicts, existing technologies usually rely on error messages or repeated generation for correction, which makes it difficult to accurately locate the key reasons for failure, easily causing multiple rounds of iteration, affecting the efficiency and real-time performance of control sequence generation.

[0004] Therefore, it is necessary to design a method and system for generating industrial control sequences with dynamic physical constraint verification to solve the problems existing in the current technology. Summary of the Invention

[0005] In view of this, the present invention proposes an industrial control sequence generation method and system with dynamic physical constraint verification, aiming to solve the problem that the generated results deviate from the actual operating conditions, making it difficult to ensure that the generated results meet the safety and reliability requirements of industrial control, thus affecting the efficiency and real-time performance of control sequence generation.

[0006] In one aspect, this invention proposes a method for generating industrial control sequences for dynamic physical constraint verification, comprising: Obtain operation requests from the industrial system and acquire real-time telemetry data of the target device; based on the real-time telemetry data, determine the boundary threshold of the dynamic integrity operation window of the target device; Constraint retrieval is performed in the vector database based on the boundary threshold; and historical standard operating procedure documents that do not meet the boundary threshold are filtered out, while compliant historical standard operating procedure documents are extracted as security context. In the retrieval-enhanced generation framework, the security context obtained from controlled retrieval is input into a large language model or a neural symbol generation module; the large language model generates an intermediate directed acyclic graph or graph node data representing the SOP under structural constraints; adversarial repair prompts are fed back to the large language model or neural symbol generation module for local structural reconstruction; the intermediate directed acyclic graph is compiled in a dual-track manner to generate industrial control code and state machine logic code; the state machine logic code is run to perform timing logic verification; and the industrial control code is run to perform physical simulation verification. When verification fails, the counterexample trajectory is output and the unsatisfiable kernel is extracted. The unsatisfiable kernel is transformed into an adversarial repair prompt word. Based on the feedback of the adversarial repair prompt word, the intermediate state directed acyclic graph is regenerated until the verification passes. Once the verification is successful, the industrial control code will be sent to the industrial system for execution.

[0007] Furthermore, determining the boundary threshold of the dynamic integrity operation window of the target device includes: The real-time telemetry data is time-aligned and status-organized to obtain the current status information of the target device; based on the current status information and physical security rules, the allowed operation boundaries of the target device at the current moment are determined; and the operation boundaries are used as the boundary thresholds of the dynamic integrity operation window.

[0008] Furthermore, when performing constraint retrieval in the vector database based on the boundary threshold, the process includes: A filter mask is generated based on the boundary threshold; a constraint retrieval is performed on the historical standard operating procedure documents in the vector database based on the filter mask.

[0009] Furthermore, the constraint retrieval includes: Traverse the metadata of each historical standard operating procedure document in the vector database and determine whether the operation conditions of the metadata meet the boundary threshold. When the operating conditions do not meet the boundary threshold, the historical standard operating procedure document is set to an unsearchable state or the search priority is reduced; when the operating conditions meet the boundary threshold, the historical standard operating procedure document is set to a searchable state, and the search result is used as the security context.

[0010] Furthermore, when generating an intermediate directed acyclic graph based on the operation request and security context, the process includes: The operation request and security context are input into a large language model to generate an operation sequence. Structural constraints are applied during the output process of the large language model to restrict the graph node information output by the large language model. Entity recognition and syntactic analysis are performed on the operation sequence to extract action information, device information, and parameter information. Directed edges are established according to the execution order and dependencies between the action information to form the intermediate directed acyclic graph.

[0011] Furthermore, when performing dual-track compilation on the intermediate directed acyclic graph to generate industrial control code and state machine logic code, the following steps are included: Traverse the nodes of the intermediate directed acyclic graph and convert each node into structured text code, sequential function chart code, or ladder diagram code; generate the industrial control code based on the order of the directed edges of the intermediate directed acyclic graph. The nodes in the intermediate directed acyclic graph are used as state variables, and the directed edges are used as temporal constraints to generate the state machine logic code.

[0012] Furthermore, when performing timing logic verification and physical simulation verification, the following are included: In an isolated sandbox environment, the reachable states of the state machine logic code are traversed to detect deadlocks, mutual exclusion conflicts, or timing conflicts; the industrial control code is run synchronously to simulate the physical state changes of the target device when it executes the industrial control code.

[0013] Furthermore, when outputting counterexample trajectories and extracting unsatisfiable kernels, the following steps are included: When the timing conflict or physical state change is detected to exceed the safety range, the verification is deemed to have failed and a counterexample trajectory is output; conflict analysis is performed on the counterexample trajectory; state variables unrelated to the verification failure are removed; and an unsatisfiable kernel or equivalent minimum conflict constraint set is extracted, wherein the unsatisfiable kernel includes state variables, action nodes, timing constraints and / or physical constraints that cause the safety attribute to be unsatisfiable.

[0014] Furthermore, when converting the unsatisfiable kernel into an adversarial repair suggestion, it includes: Based on the minimum conflict variable set, backtrack the missing dependency nodes in the intermediate directed acyclic graph to obtain backtracking topology information; convert the minimum conflict variable set and the backtracking topology information into constraint instructions in natural language form to generate adversarial repair prompts; feed the adversarial repair prompts back to the input of the large language model to drive the large language model to perform structural repair in the local range of the missing dependency nodes and regenerate the intermediate directed acyclic graph.

[0015] Compared with existing technologies, the beneficial effects of this invention are as follows: In terms of security and reliability, this invention achieves absolute security at the physical level and "zero illusion" in control commands. This invention does not rely on the self-judgment of a large model, but rather infers that "dual physical hard constraints must be imposed at the source and the output." At the input end, the Dynamic Integrity Operation Window (IOW) is calculated using real-time telemetry data, directly masking unsafe historical procedure vectors and blocking dangerous associations and cognitive poisoning by the large model. At the output end, by forcing the large model to generate a Directed Acyclic Graph (DAG) and performing deterministic dimensionality reduction compilation without a neural network, the interpretive ambiguity caused by divergent natural language is suppressed. Combined with exhaustive verification of the state machine model, this ensures that every system control action is supported by rigorous mathematical and physical proofs. In terms of operating efficiency, computational cost, and reaction speed, this invention reduces the probability of generating control sequences that do not conform to physical rules, improves the reliability of control sequences through formal verification and physical simulation before execution, reduces the number of invalid reconstructions and shortens the convergence time, and outputs control sequences that meet security constraints under preset verification conditions. The reasoning logic of this invention lies in "using mathematical proof to guide precise approximation": when verification fails, the unsatisfiable core containing counterexample trajectories is extracted, and it is transformed into adversarial prompts with mandatory preconditions through abductive reasoning. This mechanism instantly reduces the open correction space of a large model to a strongly constrained local fixed-point repair. This not only achieves an optimal balance between computing power and timeliness, but also enables the system to respond extremely quickly to dynamic and complex industrial scheduling (such as emergency switching of chemical processes and smart grid switching operations).

[0016] On the other hand, this application also provides an industrial control sequence generation system for dynamic physical constraint verification, used to apply the above-mentioned industrial control sequence generation method for dynamic physical constraint verification, including: The dynamic sensing and retrieval module is used to acquire real-time telemetry data of the industrial system and determine the boundary threshold of the dynamic integrity operation window of the target equipment based on the real-time telemetry data. The dynamic sensing and retrieval module includes a digital twin data interface, an industrial operation window status calculator, and a constrained vector database. The output end of the digital twin data interface is connected to the input end of the industrial operation window status calculator. The output end of the industrial operation window status calculator is used to generate a filter mask and connect to the query entry of the constrained vector database to perform constraint retrieval on historical standard operating procedure documents. The neural symbol generation module is used to receive the search results filtered by the restricted vector database and the operation request of the industrial system, and generate intermediate generation results representing the target standard operating procedure based on the search results and operation request; A two-layer deterministic compiler is used to receive the intermediate generation results output by the neural symbol generation module and convert the intermediate generation results into intermediate state directed acyclic graphs; the two-layer deterministic compiler includes a semantic-graph parser and a graph-code dimensionality reducer, the graph-code dimensionality reducer is used to compile the intermediate state directed acyclic graph into industrial control code for physical execution and state machine logic code for formal verification, respectively; The physical and temporal sandbox verification engine is used to receive the industrial control code and the state machine logic code, and to perform temporal logic verification on the state machine logic code and physical simulation verification on the industrial control code in an isolated virtual sandbox environment; the physical and temporal sandbox verification engine outputs an execution signal when the verification is successful, and outputs a counterexample trajectory when the verification fails. The abductive feedback mentor module is used to receive the counterexample trajectory, extract the unsatisfiable kernel from the counterexample trajectory, transform the unsatisfiable kernel into an adversarial cue word containing mandatory constraints, and feed the adversarial cue word back to the input of the neural symbol generation module to drive the neural symbol generation module to regenerate the intermediate generation result until the physical and temporal sandbox verification engine passes the verification.

[0017] It is understandable that the above-mentioned method and system for generating industrial control sequences for dynamic physical constraint verification have the same beneficial effects, and will not be elaborated further here. Attached Figure Description

[0018] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings: Figure 1A flowchart of an industrial control sequence generation method for dynamic physical constraint verification provided in an embodiment of the present invention; Figure 2 A functional block diagram of an industrial control sequence generation system for dynamic physical constraint verification provided in an embodiment of the present invention. Detailed Implementation

[0019] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the disclosure to those skilled in the art. It should be noted that, unless otherwise specified, embodiments and features in the embodiments of the present invention can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0020] In some embodiments of this application, see Figure 1 As shown, a method for generating industrial control sequences for dynamic physical constraint verification is proposed, including: Obtain operation requests from the industrial system and acquire real-time telemetry data of the target device; based on the real-time telemetry data, determine the boundary threshold of the dynamic integrity operation window of the target device; Constraint retrieval is performed in the vector database based on boundary thresholds; historical standard operating procedure documents that do not meet the boundary thresholds are hidden, and compliant historical standard operating procedure documents are extracted as security context. In the retrieval-enhanced generation framework, the security context obtained from controlled retrieval is input into a large language model or a neural symbol generation module; the large language model generates an intermediate-state directed acyclic graph or graph node data representing the SOP under structural constraints; adversarial repair prompts are fed back to the large language model or neural symbol generation module for local structural reconstruction; the intermediate-state directed acyclic graph is compiled in a dual-track manner to generate industrial control code and state machine logic code; the state machine logic code is run for timing logic verification; and the industrial control code is run for physical simulation verification. When verification fails, output the counterexample trajectory and extract the unsatisfiable kernel, and transform the unsatisfiable kernel into adversarial repair prompt words; based on the feedback of the adversarial repair prompt words, regenerate the intermediate state directed acyclic graph until the verification passes; Once the verification is successful, the industrial control code will be sent to the industrial system for execution.

[0021] In one implementation, the industrial control sequence generation method first receives an operation request from the industrial system and simultaneously acquires real-time telemetry data from the target equipment. The operation request can be a text command or voice-transcribed command input by a field operator, or a control request from an upper-level scheduling system; the real-time telemetry data is acquired in real time by a digital twin platform, data acquisition gateway, or control system interface connected to the industrial site.

[0022] Real-time telemetry data includes at least the current operating status information of the target equipment. This operating status information may include one or more of the following: pressure status, temperature status, flow rate status, liquid level status, valve opening / closing status, motor operating status, and interlock status. First, the real-time telemetry data undergoes time alignment and status processing to eliminate time differences and status expression discrepancies between different acquisition sources, thereby forming the target equipment's status information at the current moment. Based on this status information, and in conjunction with preset physical safety rules, the permissible operational boundaries of the target equipment at the current moment are determined, and these operational boundaries are used as the boundary thresholds of the dynamic integrity operation window.

[0023] Specifically, physical safety rules are derived from equipment operating procedures, process interlocking rules, process protection rules, equipment design constraints, or historical accident procedures. The dynamic integrity operation window is not fixed but dynamically adjusted according to the real-time status changes of the target equipment, ensuring that subsequent retrieval processes remain consistent with the current operating conditions. In one optional implementation, the construction process of the dynamic integrity operation window includes establishing the association between equipment status parameters and safe operating rules. For different types of industrial equipment, corresponding sets of safety rules are pre-established, with each safety rule associated with at least one equipment status parameter and corresponding permitted operating conditions. When real-time telemetry data enters the system, the corresponding set of safety rules is automatically invoked based on the equipment type of the target equipment, and the current status parameters are matched with each safety rule to determine the currently permitted range of operations. The set of safety rules can be stored in a rule base and can be maintained and updated based on equipment upgrades, process adjustments, or operational experience, thereby ensuring that the dynamic integrity operation window continuously reflects the actual operating requirements of the industrial site.

[0024] After obtaining the boundary threshold, constraint retrieval is performed in the vector database based on the boundary threshold. Specifically, a filter mask is first generated based on the boundary threshold, and then the historical standard operating procedure documents in the vector database are searched and filtered based on the filter mask.

[0025] In one implementation, the vector database stores multiple historical standard operating procedure (SOP) documents. Each historical SOP document corresponds to metadata, which includes at least one or more of the following: applicable equipment, applicable operating conditions, applicable parameter range, process stage, historical execution results, and safety tags. The metadata of the historical SOP documents is traversed to determine whether the recorded applicable parameter limits exceed the current boundary threshold (e.g., whether the maximum operating pressure required in the historical document metadata is greater than the currently calculated real-time safety pressure limit).

[0026] When the applicable parameter limit value corresponding to a historical standard operating procedure (SOP) document exceeds the current boundary threshold, the document is set to an unsearchable state or its search priority is reduced. When the applicable parameter limit value corresponding to a historical SOP document does not exceed the current boundary threshold, the document is set to a searchable state and allowed to participate in subsequent sorting and filtering. This method allows historical procedures unsuitable for the current working conditions to be filtered out during the retrieval stage, preventing the input of knowledge that does not conform to the current physical conditions into the subsequent generation process.

[0027] In one implementation, the filter mask can be applied to the retrieval entry point of the vector database or to the retrieval ranking stage. When the filter mask is applied to the retrieval entry point, historical standard operating procedure documents that meet the criteria are directly included in the candidate set. When the filter mask is applied to the ranking stage, documents that do not meet the criteria are downweighted, thereby reducing their probability of entering the security context. Regardless of the method used, controlled retrieval of historical standard operating procedure documents is achieved.

[0028] After completing the constraint retrieval, compliant historical standard operating procedure documents are extracted as safety context, and this safety context is input into the subsequent generation module. The safety context may include work steps, equipment operation sequence, process precautions, interlock conditions, and abnormal handling requirements related to the current operation request.

[0029] In one implementation, not only is the full text of the document extracted, but also key segments related to the current target device state are extracted and used as security context input to the large language model. In this way, the security context retains the knowledge background relevant to the current operation request while avoiding the introduction of historical experience that does not match the current operating conditions, thereby improving the consistency between the generated results and the actual operating conditions.

[0030] In one implementation, after obtaining the operation request and security context, the process proceeds to the intermediate directed acyclic graph (DAG) generation stage. Specifically, the operation request and security context are input into a large language model, enabling the model to generate an operation sequence related to the target industrial operation. To prevent the generated results from being too divergent, structural constraints (such as JSON Schema or GBNF syntax network format) are applied during the output process of the large language model, limiting its output to structured graph node data that can represent the logic of the industrial operation. The structured graph node data includes at least one or more of the following: action information, equipment information, parameter information, and identifiers of preceding dependent nodes.

[0031] In one implementation, structured graph node data is directly parsed, and directed edges are established based on the identifiers of the pre-dependent nodes, thus forming an intermediate directed acyclic graph (DAG). This eliminates the need for entity recognition and syntactic analysis of natural language, thereby avoiding semantic loss and structural errors caused by natural language parsing. The intermediate DAG is used to represent the action sequence, step relationships, and preconditions of the target standard operating procedure. By adopting a graph structure representation method, the operation sequence generated by the large language model can be converted into an intermediate expression form that is easy to compile and verify later.

[0032] After forming the intermediate-state directed acyclic graph (DAG), it undergoes dual-track compilation to generate industrial control code and state machine logic code, respectively. Specifically, an instruction template library containing the mapping relationship between standard industrial action semantics and underlying control instructions is pre-built. When generating the industrial control code, the nodes of the intermediate-state DAG are traversed, extracting action and equipment information from the nodes. The corresponding code templates (such as structured text code, sequential function chart code, or ladder diagram code templates) are matched in the instruction template library, and parameter information is filled into placeholders in the templates to complete instantiation. The industrial control code is then generated based on the sequential relationships represented by the directed edges. Simultaneously, when generating the state machine logic code, based on predefined state variable naming rules, equipment information is mapped to state variables, and the sequential dependencies of actions are instantiated into temporal logic expressions (such as linear time logic (LTL) formulas) using logic formula templates. During this dual-track compilation process, a tracking mapping dictionary between DAG node identifiers and compiled underlying state variables is simultaneously established for accurate backtracking of subsequent conflicts. This dual-track compilation method can map the same set of operational logic into executable and verifiable tracks, thereby ensuring that the generated results can be executed and are subject to rule verification.

[0033] After completing the dual-track compilation, the process enters the sandbox verification phase. Specifically, state machine logic code is run in an isolated sandbox environment for timing logic verification; simultaneously, industrial control code is run for physical simulation verification. To achieve collaboration between control code and physical simulation, a Virtual Programmable Logic Controller (VPLC) or Software-in-the-Loop (SIL) simulation interface is deployed in the sandbox environment. The industrial control code is sent to the virtual PLC for execution. The virtual PLC transmits the device control commands output by the control code to the multiphysics simulation engine in real time through industrial communication protocols (such as OPC UA) or shared memory mechanisms. The multiphysics simulation engine updates the boundary conditions of the physical model based on the received control commands, calculates and outputs the physical state change data of the device, and feeds it back to the virtual PLC to form a closed-loop simulation. Timing logic verification is used to detect the existence of deadlocks, mutual exclusion conflicts, or timing conflicts; physical simulation verification is used to simulate the physical state changes of the target device when executing industrial control code and to determine whether the physical state changes exceed the preset safety range. By combining timing logic verification and physical simulation verification in parallel, the logical correctness and physical safety of the control sequence can be double-confirmed before actual execution.

[0034] In one implementation, when a timing conflict or physical state change exceeds the safety range, verification is deemed a failure, and a counterexample trajectory is output. The counterexample trajectory records the state change process leading to the verification failure, the order of action execution, and the location of the conflict. Further conflict analysis is performed on the counterexample trajectory to eliminate state variables unrelated to the verification failure, determining the minimum set of conflicting variables that caused the failure, and identifying this minimum set of conflicting variables as the unsatisfiable kernel. After extracting the minimum set of conflicting variables, the underlying conflicting state variables are reverse-mapped to corresponding DAG graph node identifiers by querying the tracing mapping dictionary, thereby accurately locating the missing dependency nodes causing the conflict. This method allows for the extraction of the core factors causing the problem from a long failure path, rather than simply outputting general error information.

[0035] In another implementation, the unsatisfiable kernel is transformed into adversarial repair prompts. Specifically, based on the topological structure of the backtracking intermediate directed acyclic graph (DAG) of the located missing dependency nodes, backtracking topological information is obtained. Then, the minimum conflict variable set and the backtracking topological information are converted into constraint instructions in natural language form, forming adversarial repair prompts. Subsequently, the adversarial repair prompts are fed back to the input of the large language model, driving the large language model to perform structural repair within the local scope corresponding to the missing dependency nodes, regenerating the intermediate DAG. Through this closed-loop approach, the feedback after verification failure can be transformed from vague prompts into local, explicit, and executable repair constraints, thereby improving the re-generation's relevance and convergence efficiency.

[0036] Once verification is successful, the industrial control code is sent to the industrial system for execution. Preferably, before execution, the verification result and the corresponding code can be stored together for subsequent traceability, auditing, and review.

[0037] Specific Example 1: Online Isolation and Maintenance Scenario of Butane Removal Tower in Chemical Industry In the petrochemical industry, butane removal towers are high-temperature, high-pressure, flammable, and explosive equipment. In this embodiment, it is deployed in the control center of a petrochemical plant and connected to the field sensor network, DCS system, digital twin gateway, and sandbox verification server.

[0038] When the operator inputs "Prepare for online maintenance of Butane Removal Tower No. 2, shut down the feed system," the digital twin platform collects real-time telemetry data such as tower pressure, reboiler temperature, feed valve status, gas phase discharge valve status, and pressure relief valve status. Based on the current status, it determines that the equipment is in a hot, high-pressure critical condition and generates a corresponding dynamic integrity operation window. Subsequently, the vector database retains only safety procedure fragments related to hot pressure reduction and isolation, and masks all cold start-up and shutdown procedures that are incompatible with the current operating conditions.

[0039] The large language model generates an initial operation sequence under safety context constraints, which is then converted into industrial control code and state machine logic code by a two-layer deterministic compiler. The sandbox verification engine detects in a virtual environment that if the discharge valve is closed before the pressure relief channel is opened, the pressure inside the tower will rise rapidly and exceed the safety limit during the interval between the two switching steps, thus determining verification failure. The cause-feedback mentor module extracts the unsatisfiable kernel from the counterexample trajectory and generates constraint prompts, forcing the model to retain at least one pressure relief channel. After regeneration, a control sequence that satisfies the constraints is obtained, and after verification, it is executed.

[0040] This embodiment demonstrates that the present invention can intercept unsafe control strategies in advance without contacting actual equipment, thereby significantly reducing the risk of misoperation under high-risk working conditions.

[0041] Specific Implementation Example 2: Automated Scheduling Scenario for Flexible Nodes in Smart Grids In new power systems, flexible wind, solar, and energy storage nodes often face voltage fluctuations and concurrent dispatch conflicts. In this embodiment, they are deployed in a regional dispatch center to address scenarios involving sudden drops in bus voltage.

[0042] When a short-circuit disturbance occurs in the power grid, the digital twin platform acquires the power flow status, converter status, and circuit breaker status in real time, and dynamically calculates the current permissible operating boundaries. It retrieves scheduling procedures that meet the boundary conditions from the constrained vector database, generates a safety context, and inputs it into the large language model. The model generates a scheduling sequence containing multiple concurrent actions, which is then compiled via a dual-track system to form executable control code and state machine logic code, respectively.

[0043] During the sandbox validation phase, it was detected that if two flexible nodes simultaneously perform reactive power reverse injection in the same time slice, a transient overvoltage conflict would occur. Unsatisfied kernels were then extracted, and adversarial repair prompts with mandatory time interval requirements were generated, prompting the model to repair the timing relationships locally. After reconstruction, the scheduling sequence passed validation and was safely deployed for execution.

[0044] This embodiment shows that the present invention is not only applicable to single-device isolation maintenance scenarios, but also to multi-node concurrent control, rapid scheduling and complex interlocking scenarios.

[0045] Based on another preferred embodiment described above, see [link to preferred embodiment]. Figure 2 As shown, this embodiment provides an industrial control sequence generation system for dynamic physical constraint verification, used to apply the above-described industrial control sequence generation method for dynamic physical constraint verification, including: The dynamic sensing and retrieval module is used to acquire real-time telemetry data of the industrial system and determine the boundary threshold of the dynamic integrity operation window of the target equipment based on the real-time telemetry data. The dynamic sensing and retrieval module includes a digital twin data interface, an industrial operation window status calculator, and a constrained vector database. The output end of the digital twin data interface is connected to the input end of the industrial operation window status calculator. The output end of the industrial operation window status calculator is used to generate a filter mask and connect to the query entry of the constrained vector database to perform constraint retrieval on historical standard operating procedure documents. The neural symbol generation module is used to receive the search results filtered by the restricted vector database and the operation requests of the industrial system, and generate intermediate generation results representing the target standard operating procedure based on the search results and operation requests. A two-layer deterministic compiler is used to receive intermediate generation results from the neural symbol generation module and convert the intermediate generation results into intermediate state directed acyclic graphs. The two-layer deterministic compiler includes a semantic-graph parser and a graph-code dimensionality reducer. The graph-code dimensionality reducer is used to compile the intermediate state directed acyclic graph into industrial control code for physical execution and state machine logic code for formal verification, respectively. The physics and timing sandbox verification engine receives industrial control code and state machine logic code, and performs timing logic verification on the state machine logic code and physical simulation verification on the industrial control code in an isolated virtual sandbox environment. When the verification passes, the physics and timing sandbox verification engine outputs an execution signal, and when the verification fails, it outputs a counterexample trajectory. The abductive feedback mentor module is used to receive counterexample trajectories, extract unsatisfiable kernels from them, transform unsatisfiable kernels into adversarial cue words containing mandatory constraints, and feed the adversarial cue words back to the input of the neural symbol generation module to drive the neural symbol generation module to regenerate intermediate generation results until the physics and temporal sandbox verification engine passes the verification.

[0046] Specifically, it includes a dynamic perception and retrieval module, a neural symbol generation module, a two-layer deterministic compiler, a physical and temporal sandbox verification engine, and a causal feedback mentor module. The modules are connected in a closed-loop data flow manner.

[0047] The system comprises the following modules: a dynamic sensing and retrieval module for receiving real-time telemetry data from the industrial site and forming dynamic constraints on the current equipment status based on this data; a neural symbol generation module for receiving operation requests and a safety context filtered by constraints, and generating an intermediate state representation of the target standard operating procedure; a two-layer deterministic compiler for converting the intermediate state representation into executable industrial control code and verifiable state machine logic code; a physical and temporal sandbox verification engine for performing temporal logic verification and physical simulation verification on the two types of code, respectively; and a causal feedback mentor module for extracting unsatisfiable kernels when verification fails and generating adversarial repair prompts to feed back to the neural symbol generation module to drive regeneration.

[0048] In one implementation, the dynamic sensing and retrieval module includes a digital twin data interface, an industrial operation window status calculator, and a constrained vector database. The digital twin data interface connects to an industrial field sensor network, DCS, SCADA, or edge acquisition gateway to acquire telemetry data such as pressure, temperature, flow rate, liquid level, valve status, and motor status. The industrial operation window status calculator determines the permissible operational boundaries of the target equipment at the current moment based on the current telemetry data and generates a filter mask. The constrained vector database performs a historical standard operating procedure (SOP) document retrieval under the constraints of the filter mask, thereby retaining only the procedure fragments matching the current operating conditions as the safety context.

[0049] The neural symbol generation module is preferably a control sequence generator with a built-in large-scale language model. Its input receives the user's original operation request and security context, and its output generates standard operating procedures in natural language or structured format. The two-layer deterministic compiler includes a semantic-graph parser and a graph-code dimensionality reducer. The semantic-graph parser converts the generated results into a directed acyclic graph (DAG), and the graph-code dimensionality reducer then synchronously converts the DAG into industrial control code for execution and state machine logic code for verification. The physical and temporal sandbox verification engine runs both types of code in an isolated environment and outputs pass signals or counterexample trajectories based on the verification results. The abductive feedback mentor module extracts a set of conflicting variables from the counterexample trajectories, maps the set of conflicting variables to constraint patches, and feeds them back to the neural symbol generation module to form a closed-loop correction.

[0050] In summary, regarding security and reliability, this invention achieves absolute security at the physical level and "zero illusion" in control commands. Instead of relying on the self-judgment of a large model, this invention deduces that "dual physical hard constraints must be imposed at both the source and the output." At the input end, a Dynamic Integrity Operation Window (IOW) is calculated using real-time telemetry data, directly masking unsafe historical procedure vectors and blocking dangerous associations and cognitive poisoning from the large model. At the output end, by forcing the large model to generate a Directed Acyclic Graph (DAG) and performing deterministic dimensionality reduction compilation using non-neural networks, interpretive ambiguities caused by divergent natural language are suppressed. Combined with exhaustive verification using a state machine model, this ensures that every system control action is supported by rigorous mathematical and physical proof. In terms of operational efficiency, computational cost, and response speed, this invention reduces system error correction costs and achieves millisecond-level efficient convergence. The reasoning logic of this invention lies in "using mathematical proof to guide precise approximation": when verification fails, an unsatisfiable core containing counterexample trajectories is extracted and transformed into an adversarial prompt word with mandatory preconditions through abductive reasoning. This mechanism instantly reduces the open correction space of a large model to a highly constrained local fixed-point repair. This not only achieves an optimal balance between computing power and timeliness, but also enables the system to respond extremely quickly to dynamic and complex industrial scheduling (such as emergency switching of chemical processes and smart grid switching operations).

[0051] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the present invention.

Claims

1. A method for generating industrial control sequences for dynamic physical constraint verification, characterized in that, include: Obtain operation requests from the industrial system and acquire real-time telemetry data from the target equipment; Based on the real-time telemetry data, the boundary threshold of the dynamic integrity operation window of the target device is determined; Constraint retrieval is performed in the vector database based on the aforementioned boundary threshold; It also filters out historical standard operating procedure documents that do not meet the boundary thresholds and extracts compliant historical standard operating procedure documents as security contexts; In the retrieval-enhanced generation framework, the security context obtained from controlled retrieval is input into a large language model or a neural symbol generation module; the large language model generates an intermediate directed acyclic graph or graph node data representing the SOP under structural constraints; adversarial repair prompts are fed back to the large language model or neural symbol generation module for local structural reconstruction; the intermediate directed acyclic graph is compiled in a dual-track manner to generate industrial control code and state machine logic code; the state machine logic code is run to perform timing logic verification; and the industrial control code is run to perform physical simulation verification. When verification fails, output the counterexample trajectory and extract the unsatisfiable kernel, and convert the unsatisfiable kernel into an adversarial repair prompt word; Based on the feedback of the adversarial repair prompt, the intermediate directed acyclic graph is regenerated until the verification is successful; Once the verification is successful, the industrial control code will be sent to the industrial system for execution.

2. The industrial control sequence generation method for dynamic physical constraint verification according to claim 1, characterized in that, Determining the boundary threshold of the dynamic integrity operation window of the target device includes: The real-time telemetry data is time-aligned and status-organized to obtain the current status information of the target device; based on the current status information and physical security rules, the allowed operation boundaries of the target device at the current moment are determined; and the operation boundaries are used as the boundary thresholds of the dynamic integrity operation window.

3. The method for generating industrial control sequences for dynamic physical constraint verification according to claim 2, characterized in that, When performing constraint retrieval in the vector database based on the aforementioned boundary threshold, the following is included: A filter mask is generated based on the boundary threshold; a constraint retrieval is performed on the historical standard operating procedure documents in the vector database based on the filter mask.

4. The method for generating industrial control sequences for dynamic physical constraint verification according to claim 3, characterized in that, The constraint retrieval includes: Traverse the metadata of each historical standard operating procedure document in the vector database and determine whether the operation conditions of the metadata meet the boundary threshold. When the operating conditions do not meet the boundary threshold, the historical standard operating procedure document is set to an unsearchable state or the search priority is reduced; when the operating conditions meet the boundary threshold, the historical standard operating procedure document is set to a searchable state, and the search result is used as the security context.

5. The method for generating industrial control sequences for dynamic physical constraint verification according to claim 4, characterized in that, When generating an intermediate directed acyclic graph based on the operation request and security context, the process includes: The operation request and security context are input into a large language model to generate an operation sequence. Structural constraints are applied during the output process of the large language model to restrict the graph node information output by the large language model. Entity recognition and syntactic analysis are performed on the operation sequence to extract action information, device information, and parameter information. Directed edges are established according to the execution order and dependencies between the action information to form the intermediate directed acyclic graph.

6. The method for generating industrial control sequences for dynamic physical constraint verification according to claim 1, characterized in that, When performing dual-track compilation on the intermediate directed acyclic graph to generate industrial control code and state machine logic code, the following steps are included: Traverse the nodes of the intermediate directed acyclic graph and convert each node into structured text code, sequential function chart code, or ladder diagram code; generate the industrial control code based on the order of the directed edges of the intermediate directed acyclic graph. The nodes in the intermediate directed acyclic graph are used as state variables, and the directed edges are used as temporal constraints to generate the state machine logic code.

7. The method for generating industrial control sequences for dynamic physical constraint verification according to claim 6, characterized in that, When performing timing logic verification and physical simulation verification, the following are included: In an isolated sandbox environment, the reachable states of the state machine logic code are traversed to detect deadlocks, mutual exclusion conflicts, or timing conflicts; the industrial control code is run synchronously to simulate the physical state changes of the target device when it executes the industrial control code.

8. The method for generating industrial control sequences for dynamic physical constraint verification according to claim 7, characterized in that, When outputting counterexample trajectories and extracting unsatisfiable kernels, the following should be included: When the timing conflict or physical state change is detected to exceed the safety range, the verification is deemed to have failed and a counterexample trajectory is output; conflict analysis is performed on the counterexample trajectory; state variables unrelated to the verification failure are removed; and an unsatisfiable kernel or equivalent minimum conflict constraint set is extracted, wherein the unsatisfiable kernel includes state variables, action nodes, timing constraints and / or physical constraints that cause the safety attribute to be unsatisfiable.

9. The method for generating industrial control sequences for dynamic physical constraint verification according to claim 8, characterized in that, When converting the unsatisfiable kernel into an adversarial repair suggestion, the following is included: Based on the minimum conflict variable set, backtrack the missing dependency nodes in the intermediate directed acyclic graph to obtain backtracking topology information; convert the minimum conflict variable set and the backtracking topology information into constraint instructions in natural language form to generate adversarial repair prompts; feed the adversarial repair prompts back to the input of the large language model to drive the large language model to perform structural repair in the local range of the missing dependency nodes and regenerate the intermediate directed acyclic graph.

10. An industrial control sequence generation system for dynamic physical constraint verification, used to apply the industrial control sequence generation method for dynamic physical constraint verification as described in any one of claims 1-9, characterized in that, include: The dynamic sensing and retrieval module is used to acquire real-time telemetry data of the industrial system and determine the boundary threshold of the dynamic integrity operation window of the target equipment based on the real-time telemetry data. The dynamic sensing and retrieval module includes a digital twin data interface, an industrial operation window status calculator, and a constrained vector database. The output end of the digital twin data interface is connected to the input end of the industrial operation window status calculator. The output end of the industrial operation window status calculator is used to generate a filter mask and connect to the query entry of the constrained vector database to perform constraint retrieval on historical standard operating procedure documents. The neural symbol generation module is used to receive the search results filtered by the restricted vector database and the operation request of the industrial system, and generate intermediate generation results representing the target standard operating procedure based on the search results and operation request; A two-layer deterministic compiler is used to receive the intermediate generation results output by the neural symbol generation module and convert the intermediate generation results into intermediate state directed acyclic graphs; the two-layer deterministic compiler includes a semantic-graph parser and a graph-code dimensionality reducer, the graph-code dimensionality reducer is used to compile the intermediate state directed acyclic graph into industrial control code for physical execution and state machine logic code for formal verification, respectively; The physical and temporal sandbox verification engine is used to receive the industrial control code and the state machine logic code, and to perform temporal logic verification on the state machine logic code and physical simulation verification on the industrial control code in an isolated virtual sandbox environment; the physical and temporal sandbox verification engine outputs an execution signal when the verification is successful, and outputs a counterexample trajectory when the verification fails. The abductive feedback mentor module is used to receive the counterexample trajectory, extract the unsatisfiable kernel from the counterexample trajectory, transform the unsatisfiable kernel into an adversarial cue word containing mandatory constraints, and feed the adversarial cue word back to the input of the neural symbol generation module to drive the neural symbol generation module to regenerate the intermediate generation result until the physical and temporal sandbox verification engine passes the verification.