Analysis instrument linkage type liquid sample recovery risk prevention and control system
Patent Information
- Application Number
- CN202611045187.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-14
- Publication Date
- 2026-09-29
AI Technical Summary
[0003]本发明的目的在于提供分析仪表联动型液态样品回收风险防控系统,用于解决现有技术中关键传感器故障与执行器卡涩同时发生时,系统无法有效容错,导致联锁保护完全失效的技术问题
1、本发明通过构建多源数据融合与深度学习的协同机制,实现了对双故障并发场景的容错控制,当关键传感器失效与执行器卡涩同时发生时,系统能够基于关联传感器的实时数据和历史工况特征,动态生成高置信度的替代工艺参数,并据此触发替代性联锁保护动作,确保在极端工况下系统仍能维持安全运行状态,避免了因多重失效导致的安全防护空白;
Smart Images

Figure CN122837170A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of automated safety control technology, specifically relating to a risk prevention and control system for liquid sample recovery linked to analytical instruments. Background Technology
[0002] In industrial sectors such as chemical, pharmaceutical, and environmental protection, liquid sample recovery systems are critical links in the production process, involving the recovery and treatment of hazardous media such as flammable, toxic, high-temperature, and high-pressure substances. The safety and reliability requirements for these systems are extremely stringent. Current technologies for analytical instrument-linked liquid sample recovery systems generally employ interlocking protection mechanisms based on programmable logic controllers (PLCs). These mechanisms use sensors to collect process parameters, logic solvers to determine whether interlocking is triggered, and actuators to perform protective actions, forming a basic sampling-analysis-recovery closed-loop control. However, in practical industrial applications, traditional interlocking systems suffer from the following technical shortcomings: Traditional interlocking systems primarily design protection logic for single faults, such as using sensor redundancy to prevent single sensor failure. However, when critical sensor failure and actuator jamming occur simultaneously, the system lacks an effective fault tolerance mechanism. For example, in a chemical plant's waste solvent recovery tank, when a float switch is used for level interlocking protection, it often fails due to impurities jamming under high temperature and pressure. If the pressure sensor also experiences drift failure at this time, the interlocking system will be completely out of control, unable to trigger safety protection actions, posing a significant safety hazard. Existing interlocking protection schemes heavily rely on communication networks to transmit trip signals, but lack alternative protection measures in the event of communication interruptions or network fluctuations. When the communication link upon which the sampling-analysis-recovery linkage process depends is interrupted, the logic solver cannot obtain real-time sampling data and cannot issue instructions to the actuator, causing the entire risk control system to collapse. An analysis report on the 2025 Chilean blackout points out that traditional protection schemes based on offline models have serious limitations when facing abnormal operating conditions such as communication interruptions. Therefore, there is an urgent need for an analytical instrument-linked liquid sample recovery risk control system to solve the above problems. Summary of the Invention
[0003] The purpose of this invention is to provide a risk control system for liquid sample recovery linked to analytical instruments, which solves the technical problem in the prior art where the system cannot effectively tolerate faults when key sensor failure and actuator jamming occur simultaneously, leading to the complete failure of interlock protection.
[0004] To achieve the above objectives, the present invention adopts the following technical solution: The sample recovery execution module is used to control the recovery path of liquid samples, and it includes at least one recovery valve and a corresponding bypass valve; The instrument sensing module is used to collect process parameters. It includes multiple sensors, including critical sensors and non-critical sensors, and the critical sensors adopt at least a dual-redundancy configuration. The interlocking control module is used to receive sampled data and generate interlocking commands. It includes a logic solver that monitors the status of key sensors and valve action feedback in real time. When both key sensor failure and actuator jamming are detected simultaneously, it extracts the dynamic features of historical operating conditions. By inputting the dynamic features of historical operating conditions into the edge computing module, it obtains the predicted values of alternative process parameters and further generates alternative interlocking commands. The edge computing module communicates with the instrument sensing module and the interlocking control module respectively. It performs spatiotemporal alignment and feature extraction on the real-time sampling data uploaded by the instrument sensing module, outputs the predicted values and confidence levels of alternative process parameters, eliminates redundant alarm information and identifies key features, trains a fault prediction model based on historical fault data, provides early warning based on key features, and takes over the local control logic of the system when an interruption in communication with the upper management system is detected until communication is restored.
[0005] Furthermore, the sample recovery execution module controls the recovery path of the liquid sample, specifically as follows: By receiving valve opening or switching commands generated by the interlocking control module, the system drives the recovery valve to perform corresponding actions. At the same time, it collects the actual valve opening feedback signal and valve position status signal, and uploads the feedback signal to the interlocking control module and edge computing module in real time for closed-loop control and status monitoring.
[0006] Furthermore, the instrument sensing module is used to collect process parameters, specifically through the following method: Key sensors with dual redundancy configuration synchronously acquire the same process parameter, generating two independent measurement signals. The two measurement signals are transmitted to the interlocking control module through independent hardwired channels. The hardware-level heterogeneous comparator in the interlocking control module performs real-time comparison and consistency verification of the two measurement signals with a preset scan cycle and a preset consistency deviation threshold. When the deviation between the two measurement signals exceeds the preset deviation threshold and continues to exceed the preset fault determination time, the hardware-level heterogeneous comparator directly triggers the sensor fault alarm and uploads the alarm signal to the logic solver through hardwire. Non-critical sensors collect process parameters at a preset sampling frequency, generate digital signals, and transmit them to the edge computing module via industrial Ethernet.
[0007] Furthermore, the logic solver monitors the status of key sensors and valve action feedback in real time, specifically through the following method: The logic solver monitors the status of key sensors and valve action feedback in real time. When an abnormal signal from a key sensor is detected and the corresponding valve is stuck, it is determined that there are two concurrent faults. At this time, the logic solver immediately extracts the dynamic characteristics of the operating condition.
[0008] Furthermore, the dynamic features of historical operating conditions are extracted, specifically using the following method: When a dual-fault concurrent state is determined, the logic solver immediately collects the real-time measurement values of all non-critical sensors at the current moment, performs normalization processing, and constructs the current operating condition state vector. At the same time, the logic solver retrieves historical sampling data from the M consecutive scan cycles before the fault occurred and constructs a dynamic feature window of the operating condition.
[0009] Furthermore, by inputting the dynamic characteristics of historical operating conditions into the edge computing module, predicted values of alternative process parameters are obtained. The specific method is as follows: The logic solver packages the current operating condition state vector and the operating condition dynamic feature window into a data request frame and sends it to the edge computing module via Ethernet; After receiving the data, the edge computing module uses the dynamic feature window of the operating condition as the query condition, and uses a similarity matching algorithm in the local historical operating condition database to retrieve the historical cases that are closest to the current operating condition. It then selects the non-critical sensors with the highest correlation with the failed sensor as alternative parameter sources, calculates the correlation between each non-critical sensor and the failed sensor using the maximum information coefficient method, selects the top K non-critical sensors with the highest correlation to form a set of associated sensors, and inputs the real-time measurement values of each sensor in the set of associated sensors into a deep hybrid density network. The network outputs the predicted values of alternative process parameters.
[0010] Furthermore, alternative interlocking instructions are generated, specifically as follows: The prediction confidence level is calculated based on the predicted values of the alternative process parameters. When the confidence level is greater than or equal to the preset confidence level acceptance threshold, the predicted values of the alternative process parameters and their confidence levels are packaged and sent back to the interlocking control module. When the confidence level is lower than the acceptance threshold, a low confidence level warning sign is returned to the interlocking control module, and the interlocking control module executes the preset conservative safety strategy.
[0011] Furthermore, the input is a deep mixing density network, and the network outputs predicted values for alternative process parameters. The specific method is as follows: After normalizing the real-time measurement values of each sensor in the associated sensor set, they are combined into the input feature vector of the deep hybrid density network. The deep hybrid density network adopts a multi-layer feedforward neural network structure. Its input layer receives the aforementioned input feature vector, the hidden layer extracts high-order features from the input data through nonlinear transformation, and the output layer contains several output nodes. These nodes are divided into three groups, which correspond to the weight coefficients, mean parameters, and standard deviation parameters of a preset number of Gaussian components, respectively. The network dynamically calculates the weight coefficients, mean parameters, and standard deviation parameters of each Gaussian component based on the input real-time sensor data, and uses this to construct the conditional probability distribution of the alternative process parameters. The final output of the network, the predicted value of the alternative process parameters, is obtained by weighted averaging of the mean parameters of each Gaussian component, where the weight is the weight coefficient of the corresponding component.
[0012] Furthermore, a fault prediction model is trained based on historical fault data, and early warnings are issued based on key features. The specific method is as follows: A lightweight neural network is used as the fault prediction model. Historical normal operation data and fault data are used as training samples. The model output labels are fault type, fault occurrence probability, and equipment remaining service life. When the fault occurrence probability is greater than or equal to the preset warning threshold, standardized warning information is generated and sent to the interlocking control module simultaneously.
[0013] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are: 1. This invention achieves fault-tolerant control for concurrent dual-fault scenarios by constructing a collaborative mechanism of multi-source data fusion and deep learning. When critical sensor failure and actuator jamming occur simultaneously, the system can dynamically generate high-confidence alternative process parameters based on real-time data and historical operating condition characteristics of associated sensors, and trigger alternative interlocking protection actions accordingly, ensuring that the system can still maintain a safe operating state under extreme operating conditions and avoiding safety protection gaps caused by multiple failures. 2. This invention uses a substitution parameter generation method based on historical operating condition similarity matching and deep hybrid density network to mine the potential correlation between non-critical sensors and failure parameters, and reconstruct reliable process parameters under the condition of missing key information. This significantly improves the credibility and accuracy of fault-tolerant control decisions and avoids misjudgment or failure to operate due to missing data. 3. This invention constructs a condition feature window and integrates probabilistic modeling methods to endow fault-tolerant control logic with the ability to adapt to changes in process state. It can intelligently generate differentiated alternative interlocking instructions based on the characteristic differences of different fault scenarios, breaking the limitations of traditional single fixed control logic, realizing the technical optimization from static preset decision to dynamic intelligent decision, adapting to diverse actual process fault scenarios, and realizing the progress from single fixed logic to intelligent dynamic decision. Attached Figure Description
[0014] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0015] Figure 1 This invention illustrates a module diagram of the analytical instrument-linked liquid sample recovery risk control system. Figure 2 The flowchart of the interlocking control decision-making process under the scenarios of key sensor failure and actuator jamming in this invention is shown. Figure 3 The flowchart illustrates the data spatiotemporal alignment, fault warning, and local takeover of communication interruptions in the edge computing module of this invention. Detailed Implementation
[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0017] like Figure 1 The analytical instrument-linked liquid sample recovery risk control system shown includes the following steps: The sample recovery execution module is used to control the recovery path of liquid samples, and it includes at least one recovery valve and a corresponding bypass valve; The module includes 3 sets of main recovery valves (model: V101-V103), corresponding bypass valves (model: V201-V203, corresponding one-to-one with the main recovery valves), and a spare discharge valve (model: XV-201). Each valve is equipped with an absolute encoder to collect the actual opening feedback signal and dual limit switches to collect the valve position status signal (fully open / fully closed / intermediate position). The module also has a built-in valve drive unit that supports the input and output of analog signals and switch signals within a fixed range (e.g., 4-20mA). It transmits command and feedback signals to the interlocking control module via hardwiring, and uploads valve action frequency, opening fluctuation data, and fault records (such as jamming and internal leakage) to the edge computing module via the ModbusTCP protocol. It also receives valve maintenance early warning information (such as lubrication cycle reminders) issued by the edge computing module.
[0018] The system receives 4-20mA opening commands (corresponding to valve openings of 0-100%) or switching signals (DC24V) from the interlock control module, driving the main recovery valve or bypass valve to perform actions. For example, when the interlock control module determines that the sample is qualified, it issues a V101 fully open + V201 closed command, driving the V101 electric ball valve to rotate to the fully open position, while the V201 pneumatic diaphragm valve exhausts and closes. The encoder collects the actual valve opening in real time, and the limit switch confirms the valve position status synchronously. The two signals are uploaded to the interlocking control module and the edge computing module in real time through hard wiring. The interlocking control module compares the command opening with the feedback opening. For example, if the deviation is ≥5% and lasts for more than 1 second, the valve adjustment closed loop is triggered, and the output command is corrected through the PID algorithm until the deviation is ≤2%.
[0019] The instrument sensing module is used to collect process parameters. It includes multiple sensors, including critical sensors and non-critical sensors, and the critical sensors adopt at least a dual-redundancy configuration. The module contains 6 types of sensors, including 3 critical sensors (pressure sensor, liquid level sensor, and temperature sensor, each set of key parameters is configured with dual redundancy) and 3 non-critical sensors (flow sensor, conductivity sensor, and pH sensor). The module has a built-in hardware-level heterogeneous comparator. The signals of the critical sensors are hardwired to the comparator through independent shielded cables, while the signals of the non-critical sensors are transmitted through industrial Ethernet.
[0020] The dual-configuration key sensors synchronously acquire the same process parameter, generating two independent 4-20mA measurement signals at a sampling frequency of 100Hz. Non-critical sensors acquire the corresponding parameters at a frequency of 50Hz, generating digital signals.
[0021] A fixed window width T (T = 1 second in this embodiment) is used, and the window slides with a step size ΔT (ΔT = 100 ms in this embodiment) to divide the continuous sampling data into overlapping time window sequences. For the k-th window, its data set is... ,in, The sampled value at time t This is the start time.
[0022] In each window Within this framework, an improved local deviation factor algorithm is used to identify anomalous time points. First, the sampled value t at each time point is calculated. The local reachability density lrd(t) is obtained, and then the local outlier factor LOF(t) is obtained: ; in for The k-neighborhood (k=10 in this embodiment). When When the time is right, the point is determined to be an outlier and marked as a candidate to be removed. Here, a1 is the outlier determination threshold, which is obtained based on the distribution statistics of local outlier factors in historical normal operation data.
[0023] In addition, a threshold check based on a physical model is introduced: if a certain point If the deviation from the sensor's nominal response curve exceeds three times the standard deviation, or exceeds the process safety limit (such as pressure > 1.2 MPa), it is directly identified as an anomaly.
[0024] After removing all outliers from the window, a set of valid points is obtained. .
[0025] The hardware-level heterogeneous comparator performs real-time comparison of two key sensor signals at fixed intervals, with a preset consistency verification threshold, such as 0.5%FS (i.e., the deviation between the two pressure signals ≤ 0.005MPa). When the deviation exceeds the threshold and continues for more than 3 scan cycles (30ms), the comparator directly triggers a sensor fault alarm. The alarm signal is uploaded to the interlocking control module via hardwired connection. The comparator hardwires the two measurement signals and the fault alarm signal of the key sensor to the interlocking control module, and simultaneously transmits the window representative value and trend metadata after time window analysis via Ethernet. It transmits the real-time acquisition data of all sensors and the window analysis results (anomaly markers, trend parameters, etc.) to the edge computing module via the OPCUA protocol. It receives sensor calibration commands (such as zero-point calibration trigger signals) and suggestions for dynamically adjusting window parameters (such as anomaly detection threshold adjustment) issued by the edge computing module.
[0026] The interlocking control module is used to receive sampled data and generate interlocking commands. It includes a logic solver that monitors the status of key sensors and valve action feedback in real time. When both key sensor failure and actuator jamming are detected simultaneously, it extracts the dynamic features of historical operating conditions. By inputting the dynamic features of historical operating conditions into the edge computing module, it obtains the predicted values of alternative process parameters and further generates alternative interlocking commands. like Figure 2 As shown, the logic solver compares the sampled data uploaded by the fixed-cycle scanner sensing module with preset safety interlock thresholds (such as a high pressure threshold of 0.8 MPa, a high liquid level threshold of 1.2 m, and a high temperature threshold of 60 °C). When the sampled data exceeds the interlock threshold and continues to exceed the preset delay time (2 seconds, configurable via software), the logic solver calls the built-in interlock logic table (pre-stored in the storage unit) to generate the corresponding valve opening and closing command—for example, if the recovery pipeline pressure is ≥0.8 MPa and continues for 2 seconds, a V101 close + XV-201 open command is generated and output to the sample recovery execution module via hardwiring. The logic solver monitors the status of key sensors and valve action feedback in real time. When an abnormality is detected in a key sensor signal (such as a broken pressure sensor signal) and the corresponding valve (V101) is stuck (the deviation between the opening feedback and the command is ≥10% and lasts for 500ms), it is determined to be a dual fault concurrently. At this time, the logic solver immediately constructs the current operating condition state vector: It consists of the normalized measurements of all non-critical sensors at time t. The normalization method is the maximum-minimum method, and the reference range is taken from historical normal operation data. This represents the normalized measurement value of the i-th non-critical sensor at time t, where n is the total number of non-critical sensors. Simultaneously, the logic solver extracts a window of historical data from the 10 scan cycles prior to the fault. As a dynamic feature window for operating conditions, it is used to represent the dynamic features of historical operating conditions.
[0027] The interlocking control module will The package is sent to the edge computing module. After receiving it, the edge computing module calculates the similarity between the current operating condition and the local historical operating condition database.
[0028] in This is a window for historical operating data. To normalize the path, the top K historical cases with the highest similarity are selected. Then, the maximum information coefficient method is used to calculate the correlation between each non-critical sensor and the failed sensor. ; in, This is a non-critical sensor sequence. This is a sequence of historical normal data from a failed sensor. To maximize mutual information, and Divide the grid into dimensions, namely the number of rows and columns. Upper limit of grid division (in this embodiment, we take...) The three non-critical sensors with the largest MIC values were selected as the associated sensor set. .
[0029] Selected associated sensor sets The real-time measurement value at the current time t, along with its historical sequence, is combined into a multidimensional feature tensor. Each sensor takes its current value and the previous L-1 historical values (a total of L time steps) to form the input matrix. Where N is the number of associated sensors, L is the time window length, and the input matrix is... :
[0030] Will Input a feature extractor consisting of a one-dimensional convolutional neural network (1D-CNN). This feature extractor contains three convolutional kernels of different sizes to capture dynamic features at different time scales: Small-scale kernel (1×3): extracts local transient change features; medium-scale kernel (1×5): extracts short-term trend features; large-scale kernel (1×7): extracts periodic pattern features. The output feature maps of the three convolutional layers are concatenated along the channel dimension to obtain fused features. To transform the fused high-dimensional feature vector into effective parameters required by the hybrid density network, while ensuring that these parameters meet mathematical constraints (such as parameters representing the discreteness of the data always being positive and the sum of parameters representing the weights being one), parallel fully connected layer branches are designed, corresponding to the generation of three types of core parameters: Mean generation branch: The fused high-dimensional feature vector is input into the first fully connected layer, which directly outputs the mean vectors of multiple Gaussian distribution components. These mean vectors are used to characterize the central location of each Gaussian distribution. This is the mean of the m-th Gaussian component, which is the core basis for subsequent calculations and predictions.
[0031] The variance generation branch inputs the fused high-dimensional feature vector into a second fully connected layer. This layer first outputs multiple unnormalized discreteness factors. To ensure these factors are always positive (compliant with the mathematical definition of variance), a smooth activation function—a variant of the modified linear unit—is used to process them, resulting in a consistently positive output. Simultaneously, a very small positive number is added to the processed result to prevent overflow issues in subsequent numerical calculations. After this processing, the standard deviation of each Gaussian distribution component is finally obtained. This is the standard deviation of the m-th Gaussian component, which is used to characterize the dispersion of the corresponding Gaussian distribution. The mixing coefficient generation branch inputs the fused high-dimensional feature vector into a third fully connected layer, which outputs multiple unnormalized weight factors. To satisfy the constraint that the sum of the weight factors must be one (ensuring a reasonable contribution ratio for each Gaussian component), a normalized activation function is used to process these weight factors. This activation function, through exponential and normalization operations, ensures that the sum of all weight factors equals one, ultimately yielding the weight coefficients for each Gaussian distribution component. This is the weighting coefficient of the m-th Gaussian component, which is used to characterize the contribution ratio of the corresponding Gaussian component in the overall prediction.
[0032] Real-time data from the associated sensor set C is input into a pre-trained deep mixture density network, which outputs alternative process parameters through a Gaussian mixture model. The probability distribution, given a set of associated sensors Under the conditions, Conditional probability distribution: ; This represents the real-time measurement value of the associated sensor set at the current time t. Let M represent the probability density function of the m-th Gaussian component, where M represents the number of Gaussian components. The network is trained using negative log-likelihood as the loss function.
[0033] j represents the j-th time point. Representing the time interval, the model ultimately approximates the true posterior distribution by mixing multiple Gaussian distributions, thereby outputting predicted values for the alternative process parameters. Then calculate the conditional variance. To obtain dimensionless confidence, a normalization metric is defined. (Determined by statistical analysis of the standard deviation of prediction errors under historical normal operating conditions), defining the confidence level. ,when When (a2 represents the Conf threshold, which is set based on the statistical distribution of model prediction errors under historical normal operating conditions, taking the confidence value corresponding to the 95th percentile of the error distribution as the acceptance threshold, such as a2=0.85), If the parameter is returned as an effective alternative, a low confidence warning is triggered, and the interlocking control module executes a conservative safety strategy (such as forcing the system to degrade).
[0034] The interlocking control module receives alternative process parameters. Afterwards, if Immediately generate commands to activate the standby discharge valve XV-201, close all main recovery valves, and start the safety relief pump, triggering the preset safety recovery mode. a3 indicates the preset safety interlock threshold, which is set according to the design safety limits of the process equipment.
[0035] The logic solver packages real-time sampled data, interlock trigger status (not triggered / triggered / reset), and actuator response status (normal / fault) into data frames (frame length 128 bytes, including CRC32 check bits) in a fixed format and sends them to the edge computing module via Ethernet. After determining that two faults occur concurrently, the logic solver sends a request for alternative parameters to the edge computing module, setting a maximum waiting time Tr. If no valid response is received within Tr (including communication timeout, CRC check failure, confidence level below the threshold, edge module unavailable, or missing input features), the logic solver does not use the alternative parameters and directly enters a conservative safety strategy: outputting preset safety interlock commands (including closing the main recovery valve, opening the bypass / standby discharge valve, triggering pressure relief / degradation operation, etc.) and recording the event as an unavailable alternative parameter fault type for subsequent maintenance and tracking of alternative process parameters. It serves as a temporary alternative only in the event of concurrent double failures and hardware interlocking failures, and any anomalies (timeout / low confidence / input anomalies) directly trigger the conservative safety policy.
[0036] The edge computing module communicates with the instrument sensing module and the interlocking control module respectively. It performs spatiotemporal alignment and feature extraction on the real-time sampling data uploaded by the instrument sensing module, outputs the predicted values and confidence levels of alternative process parameters, eliminates redundant alarm information and identifies key features, trains a fault prediction model based on historical fault data, provides early warning based on key features, and takes over the local control logic of the system when an interruption in communication with the upper management system is detected until communication is restored.
[0037] like Figure 3As shown, using the scanning cycle (10ms) of the interlocking control module as a unified time reference, the timestamps of the multi-source heterogeneous data received from the instrument sensing module and the sample recovery execution module are aligned to eliminate the sampling delay differences between different sensors and actuators. Subsequently, the sliding window technique is used to smooth and filter the continuously aligned data. Combined with the abnormal point marking results of the instrument sensing module, unidentified random outliers (such as spike data caused by electromagnetic interference) are removed a second time. For the filtered effective data, frequency domain features (spectral energy distribution, main frequency, frequency domain variance) are extracted by Fast Fourier Transform (FFT), and time domain features (mean, variance, data change rate, peak factor) are extracted by wavelet packet decomposition (db4 wavelet basis, decomposition level 3). All features are vectorized into 64-dimensional feature vectors. Principal component analysis (PCA) is used to reduce the dimensionality of the 64-dimensional feature vectors, retaining the principal components with a cumulative contribution rate ≥95%, resulting in 16-dimensional key feature vectors.
[0038] Equipped with a lightweight neural network model (improved MobileNetV3), the model uses historical normal operation data and historical fault data (including 12 types of faults such as sensor drift, valve jamming, and pipeline pressure drop fluctuations) as training samples. The input features are the above-mentioned 16-dimensional key feature vectors (sensor drift rate, valve action lag time, and pipeline pressure drop fluctuations are the core inputs), and the output labels are fault type (12 types), fault occurrence probability, and equipment remaining service life (RUL). The fault prediction engine receives key feature vectors from the multi-source data fusion unit at a frequency of 100Hz and outputs the probability of occurrence and estimated remaining time for various faults in real time.
[0039] The preset fault warning threshold is ≥70% probability of occurrence. When the threshold is reached, standardized warning information is generated immediately, including fault location (such as pressure sensor 1#, main recovery valve V101), fault type (such as sensor zero drift, valve jamming), probability of occurrence, expected remaining service life, and recommended handling measures (such as immediate calibration, shutdown and lubrication). The warning information is also sent to the interlock control module via Ethernet, uploaded to the upper management system via industrial Ethernet, and recorded in the local fault log.
[0040] Establish an alarm association rule base to merge alarms of the same type that are triggered at the same time (such as drift alarms and fault alarms of the same sensor) and causal alarms (such as pipeline pressure drop fluctuation alarms caused by valve jamming), and eliminate redundant alarm information.
[0041] When the duration of a communication interruption exceeds a preset threshold (e.g., 3 seconds), the autonomous control mode is automatically activated. Specifically: Autonomous mode initialization: Call the latest model parameters (fault prediction model, alternative parameter calculation model) and model structure cached in the local solid-state drive, build a temporary inference engine locally on the edge controller, independently take over the local control logic of the system, and do not depend on any instructions from the upper management system.
[0042] Local predictive control: Using real-time data uploaded by the instrument sensing module and the sample recovery execution module as input, the local temporary inference engine independently performs fault prediction, risk analysis, and alternative parameter calculation. The inference logic is completely consistent with the network status. If the prediction result reaches the preset risk level (fault occurrence probability ≥ 80%), the offline autonomous unit directly sends an intervention request to the interlocking control module through hard wiring. The interlocking control module then performs preventive control actions (such as valve switching and safety pressure relief).
[0043] Local data storage: In autonomous mode, all system operation data, fault prediction results, interlock action logs, and intervention request records are stored locally on industrial-grade solid-state drives. The storage capacity supports local caching of data when the network is offline, ensuring that data is not lost.
[0044] Automatic network recovery and data retransmission: When the communication link is restored, the autonomous control mode is exited, and control is returned to the upper management system. At the same time, the data retransmission program is automatically started to upload all local storage data during the autonomous period to the upper management system in timestamp order to complete data synchronization.
[0045] The above formulas are all dimensionless calculations, and the preset parameters in the formulas should be set by those skilled in the art according to the actual situation.
[0046] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
[0047] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to specific implementations. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.
Claims
1. An analytical instrument-linked liquid sample recovery risk control system, characterized in that, include: The sample recovery execution module is used to control the recovery path of liquid samples, and it includes at least one recovery valve and a corresponding bypass valve; The instrument sensing module is used to collect process parameters. It includes multiple sensors, including critical sensors and non-critical sensors, and the critical sensors adopt at least a dual-redundancy configuration. The interlocking control module is used to receive sampled data and generate interlocking commands. It includes a logic solver that monitors the status of key sensors and valve action feedback in real time. When both key sensor failure and actuator jamming are detected simultaneously, it extracts the dynamic features of historical operating conditions. By inputting the dynamic features of historical operating conditions into the edge computing module, it obtains the predicted values of alternative process parameters and further generates alternative interlocking commands. The edge computing module communicates with the instrument sensing module and the interlocking control module respectively. It performs spatiotemporal alignment and feature extraction on the real-time sampling data uploaded by the instrument sensing module, outputs the predicted values and confidence levels of alternative process parameters, eliminates redundant alarm information and identifies key features, trains a fault prediction model based on historical fault data, provides early warning based on key features, and takes over the local control logic of the system when an interruption in communication with the upper management system is detected until communication is restored.
2. The analytical instrument-linked liquid sample recovery risk control system according to claim 1, characterized in that, The sample recovery execution module controls the recovery path of liquid samples, specifically as follows: By receiving valve opening or switching commands generated by the interlocking control module, the system drives the recovery valve to perform corresponding actions. At the same time, it collects the actual valve opening feedback signal and valve position status signal, and uploads the feedback signal to the interlocking control module and edge computing module in real time for closed-loop control and status monitoring.
3. The analytical instrument-linked liquid sample recovery risk control system according to claim 1, characterized in that, The instrument sensing module is used to collect process parameters, and the specific method is as follows: Key sensors with dual redundancy configuration synchronously acquire the same process parameter, generating two independent measurement signals. The two measurement signals are transmitted to the interlocking control module through independent hardwired channels. The hardware-level heterogeneous comparator in the interlocking control module performs real-time comparison and consistency verification of the two measurement signals with a preset scan cycle and a preset consistency deviation threshold. When the deviation between the two measurement signals exceeds the preset deviation threshold and continues to exceed the preset fault determination time, the hardware-level heterogeneous comparator directly triggers the sensor fault alarm and uploads the alarm signal to the logic solver through hardwire. Non-critical sensors collect process parameters at a preset sampling frequency, generate digital signals, and transmit them to the edge computing module via industrial Ethernet.
4. The analytical instrument-linked liquid sample recovery risk control system according to claim 1, characterized in that, The logic solver monitors the status of key sensors and valve action feedback in real time, specifically through the following method: The logic solver monitors the status of key sensors and valve action feedback in real time. When an abnormal signal from a key sensor is detected and the corresponding valve is stuck, it is determined that there are two concurrent faults. At this time, the logic solver immediately extracts the dynamic characteristics of the operating condition.
5. The analytical instrument-linked liquid sample recovery risk control system according to claim 1, characterized in that, Extracting dynamic features from historical operating conditions, the specific method is as follows: When a dual-fault concurrent state is determined, the logic solver immediately collects the real-time measurement values of all non-critical sensors at the current moment, performs normalization processing, and constructs the current operating condition state vector. At the same time, the logic solver retrieves historical sampling data from the M consecutive scan cycles before the fault occurred and constructs a dynamic feature window of the operating condition to represent the dynamic features of the historical operating condition.
6. The analytical instrument-linked liquid sample recovery risk control system according to claim 1, characterized in that, By inputting the dynamic characteristics of historical operating conditions into the edge computing module, predicted values of alternative process parameters are obtained. The specific method is as follows: The logic solver packages the current operating condition state vector and the operating condition dynamic feature window into a data request frame and sends it to the edge computing module via Ethernet; After receiving the data, the edge computing module uses the dynamic feature window of the operating condition as the query condition, and uses a similarity matching algorithm in the local historical operating condition database to retrieve the historical cases that are closest to the current operating condition. It then selects the non-critical sensors with the highest correlation with the failed sensor as alternative parameter sources, calculates the correlation between each non-critical sensor and the failed sensor using the maximum information coefficient method, selects the top K non-critical sensors with the highest correlation to form a set of associated sensors, and inputs the real-time measurement values of each sensor in the set of associated sensors into a deep hybrid density network. The network outputs the predicted values of alternative process parameters.
7. The analytical instrument-linked liquid sample recovery risk control system according to claim 1, characterized in that, The method for generating alternative interlocking instructions is as follows: The prediction confidence level is calculated based on the predicted values of the alternative process parameters. When the confidence level is greater than or equal to the preset confidence level acceptance threshold, the predicted values of the alternative process parameters and their confidence levels are packaged and sent back to the interlocking control module. When the confidence level is lower than the acceptance threshold, a low confidence level warning sign is returned to the interlocking control module, and the interlocking control module executes the preset conservative safety strategy.
8. The analytical instrument-linked liquid sample recovery risk control system according to claim 1, characterized in that, The input is a deep mixing density network, and the network outputs predicted values of alternative process parameters. The specific method is as follows: After normalizing the real-time measurement values of each sensor in the associated sensor set, they are combined into the input feature vector of the deep hybrid density network. The deep hybrid density network adopts a multi-layer feedforward neural network structure. Its input layer receives the aforementioned input feature vector, the hidden layer extracts high-order features from the input data through nonlinear transformation, and the output layer contains several output nodes. These nodes are divided into three groups, which correspond to the weight coefficients, mean parameters, and standard deviation parameters of a preset number of Gaussian components, respectively. The network dynamically calculates the weight coefficients, mean parameters, and standard deviation parameters of each Gaussian component based on the input real-time sensor data, and uses this to construct the conditional probability distribution of the alternative process parameters. The final output of the network, the predicted value of the alternative process parameters, is obtained by weighted averaging of the mean parameters of each Gaussian component, where the weight is the weight coefficient of the corresponding component.
9. The analytical instrument-linked liquid sample recovery risk control system according to claim 1, characterized in that, A fault prediction model is trained based on historical fault data, and early warning is provided based on key features. The specific method is as follows: A lightweight neural network is used as the fault prediction model. Historical normal operation data and fault data are used as training samples. The model output labels are fault type, fault occurrence probability, and equipment remaining service life. When the fault occurrence probability is greater than or equal to the preset warning threshold, standardized warning information is generated and sent to the interlocking control module simultaneously.