A control method and system of a stand-alone power distribution monitoring system

CN122823748APending Publication Date: 2026-09-25ZHONGSHAN MINGYE ELECTRIC APPLIANCES COMPLETE SET CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610764014.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-29
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

[0005]为解决现有的在不牺牲数据隐私的前提下,实现配电柜数据的可靠备份与精准恢复的问题,本发明提供了一种独立式配电监控系统的控制方法及系统

Benefits of technology

[0016]故障触发的临时备份,兼顾隐私与可恢复性:正常运行时,配电柜仅每隔第一设定时间将自身运行数据的哈希树根(数字指纹)发送给本地控制中心,原始数据从不离开配电柜,彻底保护数据隐私。当配电柜通过全局故障检测模型检测到故障时,才将故障发生时刻前后第二设定时间的运行数据备份到本地控制中心。这种“常态不上传,故障时临时拷贝”的策略,既避免了集中采集带来的隐私泄露风险,又为后续数据恢复保留了关键依据。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122823748A_ABST
    Figure CN122823748A_ABST
Patent Text Reader

Abstract

The application discloses a kind of control method and system of independent power distribution monitoring system, system is composed of local control center and several power distribution cabinets.Power distribution cabinet only sends the hash tree root of operation data to control center periodically, and the original data is stored locally to protect privacy.When a fault is detected, the power distribution cabinet temporarily backs up the data before and after the fault to the control center and reports the fault type for federated learning to update the global fault detection model, and other power distribution cabinets are updated synchronously, realizing cross-cabinet fault experience sharing under privacy protection.After maintenance is completed, the hash tree root before and after the fault is compared to accurately locate the damaged data block, and the control center only returns the missing block instead of the full data, completing rapid recovery and deleting the temporary backup.The application replaces the traditional normal centralized collection with "fault-triggered backup + hash fingerprint verification + federated learning", which not only guarantees data sovereignty, but also realizes accurate and efficient data recovery and model co-evolution.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power distribution cabinet technology, and specifically to a control method and system for an independent power distribution monitoring system. Background Technology

[0002] In modern industrial power distribution systems, many factories, for reasons of data confidentiality and business security, explicitly require that equipment operating data (such as three-phase current, voltage curves, number of switch actions, temperature records, etc.) be stored locally in the distribution cabinet by default, and not be accessible to external or remote centers for extended periods. This "independent" deployment model effectively protects data sovereignty and privacy, avoiding the risk of leakage associated with centralized data collection.

[0003] However, this model also brings new technical contradictions: prioritizing data sovereignty requires data to remain "in the cabinet" under normal circumstances, while data recovery after a failure depends on reliable backup sources. Specifically, there is a lack of regular data interaction between distribution cabinets and between distribution cabinets and the local control center. When a distribution cabinet experiences hardware failure, software crashes, or aging storage media, resulting in the corruption or loss of local operating data, it is impossible to obtain backup data from other nodes or to accurately recover the data. Traditional methods can only rely on manual parameter reconfiguration or manual recovery from scattered logs, which is not only inefficient and error-prone, but also often only recovers some key parameters, failing to restore the complete waveform data before and after the failure, making post-failure analysis difficult.

[0004] Current power distribution monitoring systems primarily employ two extreme solutions: one is centralized, routine data collection, uploading raw data from all distribution cabinets to a central server in real time. While this facilitates recovery, it severely infringes on data sovereignty and fails to meet the confidentiality requirements of many factories; the other is completely isolated operation, where data never leaves the distribution cabinets, resulting in permanent data loss in the event of a storage failure. How to achieve reliable backup and accurate, rapid recovery of distribution cabinet data without sacrificing data privacy, while simultaneously enabling each distribution cabinet to share fault detection experience, has become a pressing technical challenge in the industrial power distribution field. Summary of the Invention

[0005] To address the existing problem of achieving reliable backup and accurate recovery of power distribution cabinet data without sacrificing data privacy, this invention provides a control method and system for a stand-alone power distribution monitoring system. The specific technical solution of this invention is as follows:

[0006] A control method for an independent power distribution monitoring system, comprising a local control center and several distribution cabinets, includes the following steps: Each distribution cabinet acquires its own operational data and saves it to its own storage module. Then, every first predetermined time interval, it sends the hash tree root of the operational data in the storage module to the local control center. During operation, the distribution cabinet uses a global fault detection model for fault detection. If the global fault detection model detects a fault, the distribution cabinet backs up its operational data for a second predetermined time interval before and after the fault occurrence to the local control center. The distribution cabinet uses the global fault detection model to determine its own fault type and sends the fault type and fault data to the local control center, enabling the local control center to dispatch a maintenance task to repair the distribution cabinet. The local control center receives fault data and then updates the global fault detection model using federated learning. The updated parameters of the global fault detection model are sent to the distribution cabinets, enabling them to update their own global fault detection models. Normal data follows the federated learning principle (does not leave the cabinet), while fault data is uploaded temporarily as an exception. This data is compressed and encrypted before uploading, and access constraints are set after uploading before secure deletion. After the distribution cabinet is repaired, it sends the hash tree root of the current storage module's operating data to the local control center. The local control center compares the last received hash tree root before the fault with the currently received hash tree root to determine the missing data from the distribution cabinet. The local control center then transfers the missing data from the operating data backup to the distribution cabinet and deletes the operating data backup.

[0007] Furthermore, the local control center constructs a global fault detection model through the following steps: the power distribution cabinet constructs a local training model based on the operating data in the storage module, and then sends the encrypted model gradient of the local training model to the local control center; the local control center constructs a global fault detection model based on the received encrypted model gradient through federated aggregation; the local control center sends the constructed global fault detection model to the power distribution cabinets respectively, so that the power distribution cabinets can use the global fault detection model to perform fault detection.

[0008] Furthermore, the power distribution cabinet sends the hash tree root of the operating data in the storage module to the local control center at a first set time interval, including the following steps: the power distribution cabinet scans the operating data in its own storage module and generates a hash tree root based on the scanned operating data; the power distribution cabinet digitally signs the generated hash tree root and then sends the hash tree root with the added digital signature to the local control center; the local control center receives the hash tree root, verifies the digital signature of the received hash tree root, and then saves the received hash tree root, the power distribution cabinet's ID, and the timestamp sequentially into its own database.

[0009] Furthermore, the method for generating the hash tree root in the power distribution cabinet includes the following steps: the power distribution cabinet divides the running data in the storage module into data blocks of fixed size; the power distribution cabinet calculates the hash value of each data block to obtain the first leaf node; the power distribution cabinet concatenates the hash values ​​of two adjacent first leaf nodes, and then calculates the hash value of the two concatenated first leaf nodes to obtain the second leaf node; the power distribution cabinet then concatenates the hash values ​​of two adjacent second leaf nodes, and then calculates the hash value of the two concatenated second leaf nodes to obtain the third leaf node; the above steps are repeated until a unique root hash value is obtained, and this root hash value is sent to the local control center as the hash tree root.

[0010] Furthermore, the local control center updates the global fault detection model based on fault data using federated learning, including the following steps: The local control center extracts fault waveform features and fault type labels from the fault data as an incremental training sample set; the local control center adopts an incremental learning rate lower than the initial training learning rate of the initial global fault detection model and sets a small number of iterations to limit the parameter update magnitude; the local control center inputs the incremental training sample set into the current global fault detection model, performs gradient descent through backpropagation algorithm, iteratively updates the model parameters, and completes several local fine-tunings; the local control center introduces a regularization term or mixes in representative old samples into the loss function to constrain the change magnitude of key parameters of the original fault diagnosis capability; the local control center uses a validation set to quickly validate the updated global fault detection model, confirming that its accuracy in identifying new faults reaches a set threshold and that the decrease in accuracy in identifying old faults does not exceed the allowable range, and then distributes the updated model parameters to all distribution cabinets.

[0011] Furthermore, the local control center dispatches maintenance tasks to repair the distribution cabinets, including the following steps: After receiving the maintenance task, the local control center sends the maintenance task with the fault type to an external server via a wireless network, so that the external server can dispatch maintenance personnel; the local control center receives the maintenance task start instruction sent by the maintenance personnel, and then guides the maintenance personnel to the corresponding distribution cabinet for maintenance based on the ID of the distribution cabinet that sent the maintenance task; when the distribution cabinet does not detect a fault through the global fault detection model, it sends a maintenance completion instruction to the local control center, so that the local control center ends the maintenance task.

[0012] Further, the local control center determines the missing data in the power distribution cabinet by including the following steps: After the power distribution cabinet is repaired, a hash tree root is generated based on the current operating data of the storage module, and the generated hash tree root is sent to the local control center; the local control center compares the currently received hash tree root with the last received hash tree root in the database before the power distribution cabinet failure, layer by layer, to identify the corrupted data blocks in the operating data; the local control center extracts the backup data block corresponding to the corrupted data block from the operating data backup and transmits the backup data block to the power distribution cabinet; after receiving the backup data block, the power distribution cabinet writes the backup data block to the corresponding location in the storage module, and then generates a new hash tree root based on the updated data; the power distribution cabinet sends the new hash tree root to the local control center, so that the local control center can compare the new hash tree root with the last received hash tree root before the power distribution cabinet failure, and if the comparison is successful, the data repair is completed.

[0013] Furthermore, the local control center will delete the operational data backup, including the following steps: After the local control center confirms that the power distribution cabinet has been repaired and its integrity has been verified, it will mark the corresponding operational data backup stored in the control center as pending deletion and start a preset retention period; During the retention period, access constraints will be imposed on the data to be deleted, allowing only authorized and anonymized analysis operations; When the retention period is reached, the operational data backup will be securely deleted, generating an irrecoverable deletion certificate.

[0014] A stand-alone power distribution monitoring system is provided, which executes the control method of the stand-alone power distribution monitoring system described above. The stand-alone power distribution monitoring system includes a local control center and several distribution cabinets. The local control center includes a network module for transmitting data to a local area network and a database for storing data. The distribution cabinets include a communication module for accessing the local area network and a storage module for storing operational data. The distribution cabinets are communicatively connected to the local control center via the local area network.

[0015] This invention provides a control method for an independent power distribution monitoring system. Under normal circumstances, only the "hash fingerprint" (hash tree root) of the data is transmitted to verify its integrity, and the original data is always stored locally. Only when a fault is triggered is the operational data for the critical periods before and after the fault temporarily backed up to the control center. After the fault is repaired, the damaged data blocks are accurately located by comparing the hash tree root, and only the missing blocks are sent back to complete the recovery. At the same time, the backed-up fault data is used to update the global fault detection model through incremental learning and distributed to all distribution cabinets, realizing cross-cabinet experience sharing under privacy protection. The specific technical effects are as follows:

[0016] The fault-triggered temporary backup balances privacy and recoverability: During normal operation, the distribution cabinet only sends the hash tree root (digital fingerprint) of its own operating data to the local control center at a first predetermined interval. The original data never leaves the distribution cabinet, completely protecting data privacy. Only when the distribution cabinet detects a fault through the global fault detection model will it back up the operating data for a second predetermined interval before and after the fault occurrence to the local control center. This strategy of "no upload under normal circumstances, temporary copy during faults" avoids the privacy leakage risks brought by centralized data collection and retains crucial evidence for subsequent data recovery.

[0017] Hash tree root verification enables precise data block repair: The distribution cabinet periodically calculates the hash tree root of the stored data and sends it to the control center. After fault repair is completed, the distribution cabinet resends the current hash tree root. By comparing the differences between the two roots layer by layer, the control center can accurately locate the specific damaged or lost data block, rather than making a general judgment of "complete / incomplete". Subsequently, the control center only sends back the damaged data block, rather than the entire dataset, greatly reducing network overhead and recovery time, demonstrating the precision and efficiency of the solution.

[0018] Federated learning constructs a global model, continuously evolving fault detection capabilities: The local control center receives fault data (excluding normal data) reported by all distribution cabinets, and aggregates the gradients of encrypted models trained locally in each cabinet through federated learning to construct a global fault detection model. Raw data never leaves the cabinet; only parameter updates are transmitted during training. Each distribution cabinet can indirectly learn from the fault experience of other cabinets. When a new fault occurs in one cabinet, the updated model enables all distribution cabinets to acquire defensive capabilities, achieving collective intelligence while protecting privacy.

[0019] Fault triggering, model fine-tuning, and maintenance closed loop: When a fault occurs, the distribution cabinet reports the fault type and fault data, and the control center issues a maintenance task. After maintenance is completed, missing data is verified and accurately restored using a hash tree root. Once the data verification is successful, the control center deletes the temporary backup and releases storage space. The entire process forms a complete closed loop of "detection → backup → maintenance → verification → recovery → deletion," ensuring the system's self-healing capability and data consistency. Attached Figure Description

[0020] Figure 1 This is a flowchart illustrating a control method for an independent power distribution monitoring system according to an embodiment of the present invention. Detailed Implementation

[0021] The embodiments of the present invention are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout.

[0022] In the description of this invention, it should be noted that the directional terms such as "center", "lateral", "longitudinal", "length", "width", "thickness", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", "clockwise", and "counterclockwise" indicate the orientation and positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. They should not be construed as limiting the specific protection scope of this invention.

[0023] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features. Thus, the use of "first" and "second" to define a feature may explicitly or implicitly include one or more of that feature, and in the description of this invention, "at least" means one or more, unless otherwise explicitly specified.

[0024] In this invention, unless otherwise explicitly specified and limited, the terms "assembly," "connection," and "joining" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can also refer to a mechanical connection; they can refer to a direct connection or a connection through an intermediate medium; or they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0025] In this invention, unless otherwise specified and limited, "above" or "below" the second feature can include direct contact between the first and second features, or contact between the first and second features through another feature between them. Furthermore, "above," "below," and "over" the second feature includes the first feature being directly above or diagonally above the second feature, or simply indicates that the first feature is at a higher horizontal level than the second feature. "Above," "below," and "under" the second feature includes the first feature being directly below or diagonally below the second feature, or simply indicates that the first feature is at a lower horizontal level than the second feature.

[0026] The following description, in conjunction with the accompanying drawings, further illustrates specific embodiments of the present invention, making the technical solution and its beneficial effects clearer and more explicit. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain the present invention, but should not be construed as limiting the invention.

[0027] like Figure 1As shown, a control method for an independent power distribution monitoring system is described. The independent power distribution monitoring system includes a local control center and several distribution cabinets. The control method includes the following steps: the distribution cabinet acquires its own operating data (such as real-time monitoring parameters such as three-phase voltage, current, power factor, temperature, and switch status) during its operation and saves the operating data to its own storage module (the storage module can be a local solid-state drive or an industrial-grade memory card to ensure data persistence). Then, every first set time interval, the hash tree root (MerkleTreeRoot, a cryptographic digest used to verify data integrity) of the operating data in the storage module is sent to the local control center. The first set time interval is preferably 12 hours or 24 hours (the specific interval can be adjusted according to the data change rate of the distribution cabinet and the network load). The sending time can be set at night or during idle time. When the power distribution cabinet is operating, it uses a global fault detection model to detect faults (this model runs in the edge computing unit built into the power distribution cabinet, analyzing sampled data in real time). If the global fault detection model detects a fault, the power distribution cabinet backs up its operating data for a second set time period before and after the fault occurrence to the local control center (i.e., it compresses and packages the data and transmits it to the control center server via the local area network). The second set time period can be 15 minutes, 30 minutes, 45 minutes, or 60 minutes, etc. When the second set time period is 30 minutes, the power distribution cabinet backs up its operating data for 30 minutes before and after the fault occurrence (i.e., 30 minutes before the fault and 30 minutes after the fault, a total of 60 minutes) to the local control center. The power distribution cabinet uses the global fault detection model to determine its own fault type (this is a conventional technique and will not be elaborated here; specifically, a DNN-based or decision tree-based classifier can be used to output a fault code), and sends the fault type and fault data to the local control center, so that the local control center can issue a maintenance task to repair the power distribution cabinet (e.g., notifying maintenance personnel via SMS, APP push, or work order system). The local control center receives fault data and then updates the global fault detection model using federated learning (using fault data as incremental training samples to optimize the model without exposing normal data from other distribution cabinets). The updated parameters of the global fault detection model are then sent to the distribution cabinets, enabling them to update their own global fault detection models (achieving asynchronous or synchronous iteration). After the distribution cabinet is repaired (i.e., after hardware replacement or software repair), the hash root of the current storage module's running data is sent to the local control center. The local control center compares the last received hash root before the fault with the currently received hash root to determine the missing data in the distribution cabinet (which may have been corrupted or lost due to the fault). The local control center then transfers the missing data from the running data backup to the distribution cabinet and deletes the running data backup (to free up storage space and protect data privacy).

[0028] As one embodiment, the local control center constructs a global fault detection model through the following steps: The distribution cabinet constructs a locally trained model (e.g., a fault diagnosis model based on a Long Short-Term Memory (LSTM) network or a Convolutional Neural Network (CNN)) based on the operating data in the storage module, and then sends the encrypted model gradient of the locally trained model (processed using homomorphic encryption or differential privacy techniques) to the local control center. The local control center constructs a global fault detection model based on the received encrypted model gradient through federated aggregation (such as the FedAvg algorithm). The local control center sends the constructed global fault detection model to the distribution cabinets respectively, enabling the distribution cabinets to use the global fault detection model for fault detection. Specifically:

[0029] The control center first creates an initial global machine learning model (such as a neural network for fault detection, typically a multilayer perceptron or a lightweight ResNet), and sets the hyperparameters required for this round of training, such as the learning rate (e.g., 0.01) and batch size (e.g., 32). Then, it securely distributes the current global model parameters to all online and selected distribution cabinet clients in the area (via HTTPS or MQTT protocol).

[0030] Upon receiving the global fault detection model, the distribution cabinet will independently train the model multiple times using its locally stored real operating data (which never leaves the local area and is only stored in a protected safety environment inside the cabinet). Each distribution cabinet will perform several rounds of forward and backward propagation based on its own data characteristics.

[0031] Each distribution cabinet has unique local data (such as current and voltage waveforms), so the model update obtained after training also reflects the personalized characteristics of the equipment (such as load characteristics and harmonic background).

[0032] The power distribution cabinet calculation model calculates the prediction error (loss, such as cross-entropy loss) on its local data and calculates the direction to reduce this error, i.e., the gradient.

[0033] During training, specific optimization strategies are needed to address challenges such as differences in data distribution. For example, the FedProx algorithm can be used to add a "penalty term" (i.e., a proximal term) to the loss function to prevent the local model from deviating too far from the global model during the personalization process, which helps the global model to converge stably.

[0034] After local training is complete, the distribution cabinet does not upload any raw data. Instead, it uploads the calculated model updates (usually model weights or gradients) back to the control center. The uploaded information is the "learning experience" after training, not the raw data, and therefore does not constitute data leakage.

[0035] This is a crucial step for the local control center to function as a "command hub." It needs to securely receive model updates from various distribution cabinets and perform aggregation operations.

[0036] Aggregation Algorithm: The core algorithm of aggregation is Federated Averaging (FedAvg). The server calculates a weighted average of all received local model parameters, with the weights typically determined by the amount of local data used for training by each distribution cabinet.

[0037] Update the global model: The server uses the calculated aggregation results to update the global model, completing the iteration of a new version of the global model.

[0038] The above four steps constitute a "Communication Round". This iterative process continues until the performance of the global model reaches a preset standard (such as sufficiently high accuracy or no longer significant improvement).

[0039] As one embodiment, the local control center introduces a semi-supervised learning strategy when updating the global fault detection model:

[0040] Step A: Construct a pseudo-label queue

[0041] The local control center uses the fault data (labeled) reported by each distribution cabinet as seed samples, and at the same time periodically collects anonymized operating features (such as dimensionality-reduced statistical features or intermediate layer outputs of the model, excluding the original waveforms) from normal distribution cabinets to form an unlabeled dataset.

[0042] Step B: Consistency Regularization Training

[0043] The local control center uses semi-supervised algorithms such as MeanTeacher or FixMatch:

[0044] Calculate the cross-entropy loss for labeled faulty data;

[0045] For unlabeled data, apply different data augmentations (such as slight noise addition or temporal pruning) to the same input to force the model to maintain consistent predictions before and after the perturbation (consistency loss).

[0046] Total loss = Supervision loss + λ × Consistency loss.

[0047] Step C: Confidence Screening

[0048] Only unlabeled samples with a model prediction confidence level higher than a threshold (e.g., 0.9) are included in the pseudo-label iteration to avoid erroneous pseudo-labels contaminating the model.

[0049] Step D: Federal Semi-Supervised Aggregation

[0050] Each distribution cabinet can also perform semi-supervised training using its own unlabeled data (updating only the local model), and then send the model parameters or gradients to the control center. When aggregating data, the control center can adjust the aggregation weights based on the number of labeled samples in each cabinet.

[0051] In one embodiment, the power distribution cabinet sends the hash tree root of the operating data in its storage module to the local control center at a predetermined time interval. This process includes the following steps: The power distribution cabinet scans the operating data in its own storage module (traversing all data blocks) and generates a hash tree root (MerkleTreeRoot) based on the scanned data. The power distribution cabinet digitally signs the generated hash tree root (using its private key) and then sends the digitally signed hash tree root to the local control center. The local control center receives the hash tree root, verifies the digital signature on the received hash tree root (using the power distribution cabinet's public key), and then sequentially saves the received hash tree root, the power distribution cabinet's ID, and a timestamp into its own database (as a basis for subsequent integrity verification). The power distribution cabinet also performs incremental hash verification: the cabinet divides the operating data in the storage module into continuous data segments according to a fixed time window (e.g., every 10 minutes) or a fixed data volume (e.g., every 512KB), and generates a segment hash value for each data segment; the cabinet maintains a hash chain, where the hash value H_i of the i-th node is Hash(H_{i-1}||segment hash value_i), initially H_0=0; the cabinet sends the latest H_i to the local control center every three set time intervals (e.g., 5 minutes); when the cabinet detects a fault, the local control center can quickly determine whether the data has undergone abnormal changes within the interval based on the two most recently received H_i and H_{i-1}, and further locate the damaged data segment by combining the complete Merkle tree. This greatly shortens the window period for data integrity detection (from 24 hours to minutes); it can more quickly determine the time period of data corruption after a fault occurs; the reported data volume is small (only one hash value, tens of bytes each time), and it hardly increases the network burden.

[0052] As one embodiment, the method for generating a hash tree root in a power distribution cabinet includes the following steps: The power distribution cabinet divides the running data in the storage module into fixed-size data blocks (e.g., each data block is 1MB). The power distribution cabinet calculates the hash value (e.g., SHA-256) of each data block to obtain the first leaf node. The power distribution cabinet concatenates the hash values ​​of two adjacent first leaf nodes, and then calculates the hash value of the concatenated two first leaf nodes to obtain the second leaf node. The power distribution cabinet then concatenates the hash values ​​of two adjacent second leaf nodes, and then calculates the hash value of the concatenated two second leaf nodes to obtain the third leaf node. The above steps are repeated until a unique root hash value is obtained, and this root hash value is sent as the hash tree root to the local control center.

[0053] In one embodiment, the local control center updates the global fault detection model using federated learning based on fault data, including the following steps: The local control center extracts fault waveform features and fault type labels from the fault data as an incremental training sample set. The local control center adopts an incremental learning rate lower than the initial training learning rate of the initial global fault detection model (e.g., the initial learning rate is 0.001, and the incremental learning rate is set to 0.0001), and sets a small number of iteration rounds (e.g., 5 rounds) to limit the magnitude of parameter updates. The local control center inputs the incremental training sample set into the current global fault detection model, performs gradient descent through the backpropagation algorithm, iteratively updates the model parameters, and completes several local fine-tuning rounds. The local control center introduces a regularization term (e.g., L2 regularization) into the loss function or mixes in representative old samples (extracted from a historical anonymized fault database) to constrain the magnitude of changes to key parameters of the original fault diagnosis capability. The local control center uses a validation set (containing a small number of samples of both new and old faults) to quickly validate the updated global fault detection model. Once it confirms that the accuracy rate for identifying new faults reaches a set threshold (e.g., 95%) and the decrease in accuracy for identifying old faults does not exceed an allowable range (e.g., less than 2%), the updated model parameters are distributed to all distribution cabinets. Specifically:

[0054] Step 1: Data Preprocessing and Augmentation

[0055] Format alignment: Align the format of the faulty data packets with the input format used during model training (e.g., uniform sampling rate to 1kHz, normalize to the [0,1] range). Sample augmentation (optional): Since faulty samples are usually scarce, simple data augmentation can be performed: add slight noise (SNR=30dB); fine-tune the time axis (shift ±5 sampling points); scale the amplitude (within a reasonable range, such as ±10%); generate a small number of variant samples to prevent overfitting.

[0056] Step 2: Set the hyperparameters for incremental training

[0057] Learning rate: Use a smaller learning rate than the initial training rate (e.g., 1 / 10 or 1 / 100 of the initial learning rate) to avoid drastic parameter changes that could destroy existing knowledge. Number of training epochs: Typically only 1-10 epochs are needed due to the small amount of data. Batch size: If there are few new samples (e.g., only one fault record), single-sample online learning can be used; if there are multiple fault records, use smaller batches (e.g., 4 or 8). Loss function: Same as the original training (e.g., cross-entropy loss), but a regularization term (e.g., Fisher information matrix penalty in EWC) can be added to constrain the magnitude of changes in important parameters (see the anti-forgetting strategy in step 4).

[0058] Step 3: Perform incremental training (gradient descent)

[0059] Input the new fault data (X_new, y_new) into the current global model. Calculate the loss L_new between the model prediction and the true label. Perform backpropagation to calculate the gradient of the loss with respect to the model parameters. Update the model parameters θ_new = θ_old - η * ∇L_new using an optimizer (such as SGD or Adam) with a small learning rate.

[0060] Step 4: Prevent catastrophic amnesia (optional but important)

[0061] If the new fault mode differs significantly from the old mode, direct fine-tuning may cause the model to "forget" its diagnostic capabilities for old faults. One of the following strategies can be adopted: Elastic Weight Consolidation (EWC), which adds a regularization term to the loss function: L=L_new+λ*ΣF_i*(θ_i-θ_old_i)^2, where F_i is the diagonal of the Fisher information matrix, representing parameter importance. Applicable scenario: Old tasks are very important, and new samples are few. Rehearsal sampling, which mixes in a small number of representative old fault samples (which can be extracted from the historical anonymized fault database of the control center) in each batch of incremental training. Applicable scenario: The control center has anonymized versions of past fault samples. Freezing some layers, freezing the first few layers of the model (responsible for general feature extraction), and only fine-tuning the last few layers (responsible for specific classification). Applicable scenario: New faults share underlying features with old faults, and only the decision boundary needs adjustment.

[0062] Step 5: Validation and Merging

[0063] After incremental training is completed, the model performance is evaluated using a validation set (which can be a small number of retained old fault samples plus new fault samples). The following conditions are confirmed to be met: new fault identification accuracy ≥ threshold (e.g., 90%); old fault identification accuracy decrease ≤ threshold (e.g., 2%). If these conditions are met, the original global model is replaced with the updated parameters; otherwise, this incremental update is abandoned, and a more complete retraining process is triggered (e.g., retraining using historical fault data).

[0064] Step 6: Deploy the update

[0065] The control center distributes the incrementally updated global model parameters to all online distribution cabinets. Each distribution cabinet loads the new model locally for subsequent real-time fault inference.

[0066] In one embodiment, the local control center dispatches maintenance tasks to repair the power distribution cabinet, including the following steps: After receiving the maintenance task, the local control center sends the fault-related maintenance task to an external server (such as a cloud-based operation and maintenance management platform) via a wireless network (e.g., a hardened wireless network (such as a private APN / 5G: using SIM cards for physical isolation and authentication, combined with end-to-end encryption and private APN solutions, which can effectively prevent most network attacks). The external server then dispatches maintenance personnel. The local control center receives the maintenance task start instruction sent by the maintenance personnel (who confirm via a mobile app scanning the power distribution cabinet's QR code or logging into the system). Then, based on the ID of the power distribution cabinet that sent the maintenance task, the local control center guides the maintenance personnel to the corresponding power distribution cabinet for maintenance (e.g., via map navigation or cabinet number). When the power distribution cabinet does not detect a fault through the global fault detection model (i.e., the self-test passes after maintenance), a maintenance completion instruction is sent to the local control center, causing the local control center to terminate the maintenance task.

[0067] In one embodiment, the local control center determines the missing data in the power distribution cabinet by including the following steps: After the power distribution cabinet is repaired, a hash tree root is generated based on the current operating data of the storage module, and the generated hash tree root is sent to the local control center. The local control center compares the currently received hash tree root with the last received hash tree root in the database before the power distribution cabinet failure (recursively comparing node hash values ​​from the root node downwards) to identify the corrupted data blocks in the operating data (i.e., the data blocks corresponding to leaf nodes with mismatched hash values). The local control center extracts the backup data block corresponding to the corrupted data block from the operating data backup and transmits the backup data block to the power distribution cabinet. After receiving the backup data block, the power distribution cabinet writes the backup data block to the corresponding location in the storage module, and then generates a new hash tree root based on the updated data. The power distribution cabinet sends the new hash tree root to the local control center, allowing the local control center to compare the new hash tree root with the last received hash tree root before the power distribution cabinet failure (verifying integrity and consistency). If the comparison is successful, the data repair is completed.

[0068] As one embodiment, the local control center deletes the operational data backup by following these steps: After the local control center confirms that the power distribution cabinet has been repaired and its integrity verification has passed (after the power distribution cabinet has been repaired and verified, a repair success signal can be sent to the local control center), the corresponding operational data backup stored in the control center is marked as pending deletion and a preset retention period is initiated; during the retention period, access constraints are imposed on the data to be deleted, allowing only authorized and anonymized analysis operations; when the retention period is reached, the operational data backup is securely deleted, generating an irrecoverable deletion certificate.

[0069] Specifically, after the power distribution cabinet is repaired and the local data is confirmed to be fully restored through integrity verification, the control center does not immediately delete the temporarily stored copy of the fault data. Instead, it starts a delayed deletion timer and sets a preset retention period (e.g., 7 days, 30 days, or configured according to the audit strategy). The fault data copy is marked as "pending deletion" (or "soft deletion") in the control center's storage status. At this time, the data is not visible to regular business queries, but it is still accessible for authorized fault analysis, model training, or audit operations. During the retention period, access constraints are imposed on the data marked as pending deletion, including: only allowing operations that do not involve the original identity information, such as anonymized model training and fault feature statistics; prohibiting the forwarding of data to external systems; and generating immutable audit logs for all access operations. The control center periodically (e.g., hourly or daily) scans the retention time of the dataset to be deleted. For data that has reached the preset retention period, a secure deletion process is triggered. Expired data copies are physically deleted or encrypted and shredded, specifically including: overwrite deletion: multiple writes of random data (such as all 0s, all 1s, or random patterns) to the storage area; or key destruction: if the data is stored encrypted, the corresponding decryption key is deleted, making the ciphertext permanently unrecoverable; a deletion certificate (such as hash value, timestamp, operator) is generated and written to the audit log. After secure deletion is completed, the control center sends data deletion confirmation information to the power distribution cabinet and operation and maintenance management system, and may selectively delete relevant local audit records (retaining necessary logs as required by compliance).

[0070] A stand-alone power distribution monitoring system is disclosed, which executes the control method of the stand-alone power distribution monitoring system described above. The stand-alone power distribution monitoring system includes a local control center and several distribution cabinets. The local control center includes a network module (such as an Ethernet switch or industrial router) for transmitting data to a local area network and a database (such as MySQL or SQLite) for storing data. The distribution cabinets include a communication module (such as a LAN port or Wi-Fi module) for accessing the local area network and a storage module (such as eMMC or SSD) for storing operational data. The distribution cabinets are communicatively connected to the local control center via the local area network.

[0071] This invention provides a control method for an independent power distribution monitoring system. Through a mechanism combining "fault-triggered temporary backup" and "hash tree root fingerprint verification," it ensures data security while achieving accurate and rapid data recovery after a power distribution cabinet failure. Furthermore, it utilizes federated learning to achieve collaborative evolution of fault detection models across different cabinets. Compared to conventional power distribution monitoring systems, this invention possesses the following distinguishing technical features and correspondingly produces the following technical effects:

[0072] Difference 1: Normally, only hash fingerprints are transmitted, not the original runtime data.

[0073] Conventional systems, in order to facilitate data recovery, often continuously collect and upload the original operating data of all power distribution cabinets to the central server, resulting in the loss of data sovereignty and a high risk of privacy leaks.

[0074] The technical advantages achieved by this invention are as follows: Under normal operating conditions, the power distribution cabinet only sends the hash tree root (an irreversible "digital fingerprint") of the operating data to the local control center, while the original data remains in the local storage module. The control center cannot deduce any original data from the hash tree root, thus eliminating the privacy risks associated with centralized data collection at the source and achieving the independent deployment requirement of "data sovereignty first".

[0075] Difference 2: Fault-triggered temporary backup, rather than normalized centralized storage.

[0076] Even if conventional systems use local storage, they lack effective off-site recovery methods after a failure, or they need to occupy a large amount of central storage resources for a long time.

[0077] The technical advantages achieved by this invention are as follows: the distribution cabinet only temporarily backs up the operating data of the second predetermined time before and after the fault occurrence to the control center when a fault is detected by the global fault detection model. This backup data is much smaller than the full historical data and is used only for fault recovery and incremental model training. It is safely deleted after the repair is completed and verified. Therefore, it preserves crucial evidence for accurate recovery while avoiding the long-term burden of central storage and the risk of data stagnation.

[0078] Difference 3: The hash tree root is compared layer by layer, and the corrupted data is accurately located at the block level, rather than being sent back in full.

[0079] Conventional data recovery methods either require manual log searching or backing up the entire backup image to the power distribution cabinet, resulting in high network overhead and long recovery time.

[0080] The technical advantages achieved by this invention are as follows: After maintenance is completed, the control center compares the hash tree root currently uploaded by the power distribution cabinet with the hash tree root received last time before the fault, layer by layer. This allows for precise location of the specific damaged or lost data block, rather than a general determination of "complete / incomplete". Subsequently, the control center only sends back the missing data block, rather than the entire dataset. This mechanism significantly reduces network transmission volume, shortens recovery time, and achieves efficient and precise data self-healing.

[0081] Difference 4: Incremental learning based on fault data and synchronization with cross-cabinet models, rather than an isolated fault detection model.

[0082] In conventional power distribution systems, the fault detection models of each distribution cabinet are independent of each other. A new type of fault occurring in one location cannot be identified by other distribution cabinets, and fault experience cannot be shared.

[0083] The technical advantages achieved by this invention are as follows: The local control center utilizes temporarily backed-up fault data (without needing to collect additional normal data) for incremental learning or federated learning, updating only the model parameters, and then distributing the updated global fault detection model to all distribution cabinets. This allows any newly discovered fault type in any distribution cabinet to be quickly learned by the entire system, achieving collective intelligence of "one fault, whole cabinet defense." Simultaneously, throughout the entire process, the normal operation data of each distribution cabinet never leaves the cabinet, ensuring complete privacy protection.

[0084] Difference 5: Secure deletion loop ensures no temporary backups are left behind.

[0085] Conventional systems often neglect to clean up faulty data after use, or simply delete it but it can still be recovered, posing a risk of data leakage.

[0086] The technical advantages achieved by this invention are as follows: After confirming that the power distribution cabinet has been repaired and its integrity has been verified, the control center marks the temporary backup as pending deletion and initiates a preset retention period. During the retention period, only authorized de-identified analysis is allowed. After the retention period expires, secure deletion (overwriting or key destruction) is performed, and an irrecoverable deletion certificate is generated. This closed loop ensures that the entire lifecycle of the temporary backup is controllable, completely eliminating the risk of data legacy.

[0087] In the description of this specification, the terms "an embodiment," "preferred," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the present invention. The illustrative expressions of the above terms in this specification do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described can be combined in any suitable manner in one or more embodiments or examples. The connection methods linked in the description of this specification have significant effects and practical utility.

[0088] Based on the above description of the structure and principle, those skilled in the art should understand that the present invention is not limited to the specific embodiments described above. Improvements and substitutions made using techniques known in the art based on the present invention all fall within the protection scope of the present invention and should be defined by the claims.

Claims

1. A control method for a stand-alone power distribution monitoring system, the stand-alone power distribution monitoring system comprising a local control center and several distribution cabinets, characterized in that, The control method includes the following steps: The power distribution cabinet acquires its own operating data during operation and saves the operating data to its own storage module. Then, every first set time interval, it sends the hash tree root of the operating data in the storage module to the local control center. When the power distribution cabinet is working, it uses a global fault detection model to detect faults. If the global fault detection model detects a fault, the power distribution cabinet will back up the operating data of the second set time before and after the time of the fault to the local control center. The power distribution cabinet will use a global fault detection model to determine its own fault type and send the fault type and fault data to the local control center, so that the local control center can send out maintenance tasks to repair the power distribution cabinet. The local control center receives fault data and then updates the global fault detection model through federated learning based on the fault data. The updated parameters of the global fault detection model are then sent to the distribution cabinets, enabling the distribution cabinets to update their own global fault detection models. After the power distribution cabinet is repaired, the hash tree root of the current storage module's operating data is sent to the local control center. The local control center compares the last received hash tree root before the fault occurred with the currently received hash tree root to determine the missing data of the power distribution cabinet. The local control center transfers the missing data from the operation data backup to the distribution cabinet, and then deletes the operation data backup.

2. The control method for the stand-alone power distribution monitoring system according to claim 1, characterized in that, The local control center constructs a global fault detection model through the following steps: The power distribution cabinet builds a local training model based on the operating data in the storage module, and then sends the encrypted model gradient of the local training model to the local control center. The local control center constructs a global fault detection model based on the received encrypted model gradients through federated aggregation; The local control center sends the constructed global fault detection model to the distribution cabinets, enabling the distribution cabinets to use the global fault detection model for fault detection.

3. The control method for the stand-alone power distribution monitoring system according to claim 1, characterized in that, The power distribution cabinet sends the hash tree root of the operating data in the storage module to the local control center at a first set time interval, including the following steps: The power distribution cabinet scans the operating data in its own storage module and generates a hash tree root based on the scanned operating data. The power distribution cabinet digitally signs the generated hash tree root, and then sends the digitally signed hash tree root to the local control center. The local control center receives the hash tree root, verifies the digital signature of the received hash tree root, and then saves the received hash tree root, the ID of the power distribution cabinet, and the timestamp into its own database in sequence.

4. The control method for the stand-alone power distribution monitoring system according to claim 3, characterized in that, The method for generating the root of a hash tree for a power distribution cabinet includes the following steps: The power distribution cabinet divides the operating data in the storage module into fixed-size data blocks; The power distribution cabinet calculates the hash value of each data block to obtain the first leaf node; The power distribution cabinet concatenates the hash values ​​of two adjacent first leaf nodes, and then calculates the hash values ​​of the two concatenated first leaf nodes to obtain the second leaf node; The distribution cabinet then concatenates the hash values ​​of two adjacent second leaf nodes, and then calculates the hash values ​​of the concatenated two second leaf nodes to obtain the third leaf node; Repeat the above steps until a unique root hash value is obtained, and send the root hash value as the root of the hash tree to the local control center.

5. The control method for the stand-alone power distribution monitoring system according to claim 1, characterized in that, The local control center updates the global fault detection model based on fault data through federated learning, including the following steps: The local control center extracts fault waveform features and fault type labels from fault data as an incremental training sample set. The local control center uses an incremental learning rate lower than the initial training learning rate of the initial global fault detection model and sets a small number of iteration rounds to limit the magnitude of parameter updates. The local control center inputs the incremental training sample set into the current global fault detection model, performs gradient descent through the backpropagation algorithm, iteratively updates the model parameters, and completes several local fine-tunings. The local control center introduces a regularization term or mixes in representative old samples into the loss function to constrain the magnitude of changes to key parameters of the original fault diagnosis capability. The local control center uses the validation set to quickly validate the updated global fault detection model. After confirming that its accuracy in identifying new faults reaches the set threshold and the decrease in accuracy in identifying old faults does not exceed the allowable range, the updated model parameters are distributed to all distribution cabinets.

6. The control method for the stand-alone power distribution monitoring system according to claim 5, characterized in that, The local control center dispatches maintenance tasks to repair the distribution cabinet, including the following steps: After receiving a maintenance task, the local control center sends the maintenance task with the fault type to an external server via a wireless network, so that the external server can dispatch maintenance personnel. The local control center receives the maintenance task start instruction sent by the maintenance personnel, and then guides the maintenance personnel to the corresponding distribution cabinet to carry out maintenance based on the ID of the distribution cabinet that sent the maintenance task. When the power distribution cabinet does not detect a fault through the global fault detection model, it sends a maintenance completion instruction to the local control center, causing the local control center to end the maintenance task.

7. The control method for the stand-alone power distribution monitoring system according to claim 6, characterized in that, The local control center identifies missing data for the distribution cabinet by including the following steps: After the power distribution cabinet is repaired, a hash tree root is generated based on the current operating data of the storage module, and the generated hash tree root is sent to the local control center. The local control center compares the currently received hash tree root with the last received hash tree root in the database before the power distribution cabinet failure to identify the corrupted data blocks in the running data. The local control center extracts the backup data block corresponding to the damaged data block from the running data backup and transmits the backup data block to the power distribution cabinet; After receiving the backup data block, the power distribution cabinet writes the backup data block to the corresponding location in the storage module, and then generates a new hash tree root based on the updated data; The power distribution cabinet sends the new hash tree root to the local control center, which then compares the new hash tree root with the hash tree root received last before the power distribution cabinet malfunctioned. If the comparison is successful, the data repair is completed.

8. The control method for the stand-alone power distribution monitoring system according to claim 7, characterized in that, The local control center will delete the running data backup, including the following steps: After the local control center confirms that the power distribution cabinet has been repaired and its integrity has been verified, it will mark the corresponding operation data backup stored in the control center as pending deletion and start the preset retention period. During the retention period, access constraints are imposed on the data to be deleted, allowing only authorized and anonymized analysis operations; When the retention period is reached, the backup of the running data is securely deleted, generating an irrecoverable deletion certificate.

9. A stand-alone power distribution monitoring system, characterized in that, The stand-alone power distribution monitoring system implements the control method of any one of claims 1 to 8. The stand-alone power distribution monitoring system includes a local control center and several distribution cabinets. The local control center includes a network module for transmitting data to a local area network and a database for storing data. The distribution cabinets include a communication module for accessing the local area network and a storage module for storing operating data. The distribution cabinets are communicatively connected to the local control center via the local area network.