An AI control strategy-oriented shadow mode simulation verification system and method
Patent Information
- Application Number
- CN202611233815.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-14
- Publication Date
- 2026-09-29
AI Technical Summary
[0003]现有AI控制策略上线前的验证方式多依赖人工审查、静态规则比对以及离线仿真,人工审查效率低且判断尺度不稳定,静态规则比对难以反映控制策略在连续执行过程中的设备响应延时、功率变化限制和储能状态变化,常规离线仿真也容易将各仿真时刻割裂处理,难以体现单个设备控制量变化对馈线负载、电压偏差和频率偏差的连续传递影响
[0013]与现有技术相比,本发明所达到的有益效果是:本发明通过数据同步与策略解析、影子递推仿真、违约追溯与边界输出形成完整验证链路,使AI控制策略在不直接作用于真实设备的情况下完成上线前模拟验证;在每一仿真步中,先计算设备受响应延时、功率变化限制和储能状态变化影响后的实际响应,再基于该实际响应更新电气耦合结果,使仿真过程能够反映控制动作在连续执行中的累积影响;当出现电压偏差、频率偏差、馈线负载以及储能状态越限时,系统能够追溯导致违约的控制指令并重新确定控制量边界,从而不仅能够判断策略是否可上线,还能够输出可执行边界、违约事件和收益差值,为微电网、虚拟电厂及电力市场控制策略的安全上线提供明确依据。
Smart Images

Figure CN122837255A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of artificial intelligence technology, specifically to a shadow pattern simulation verification system and method for AI control strategies. Background Technology
[0002] As artificial intelligence (AI) technology is increasingly applied in industrial control, AI servers can generate corresponding control strategies based on operational status data, market price data, and control objectives in scenarios such as microgrids, virtual power plants, electricity market pricing, and multi-device collaborative control. Industrial control strategies typically involve the relationships between energy storage devices, photovoltaic inverters, adjustable loads, feeders, and grid operational constraints. Before being officially implemented, these strategies need to be validated based on equipment operating status, electrical network status, and market profitability to ensure they meet the operational requirements of the actual industrial control system.
[0003] Current verification methods for AI control strategies before deployment largely rely on manual review, static rule comparison, and offline simulation. Manual review is inefficient and the judgment criteria are unstable. Static rule comparison cannot reflect the device response latency, power change limits, and energy storage state changes during continuous execution of the control strategy. Conventional offline simulation is also prone to treating each simulation moment in isolation, making it difficult to reflect the continuous transmission impact of changes in individual device control quantities on feeder load, voltage deviation, and frequency deviation. Therefore, existing methods can usually only provide a rough conclusion on whether the strategy is potentially usable, making it difficult to pinpoint the specific control command that leads to safety violations, and even more difficult to determine the boundaries to which the AI control strategy can be executed under safety constraints. This affects the safety and economic assessment of the AI control strategy before its formal deployment. Summary of the Invention
[0004] The purpose of this invention is to provide a shadow mode simulation verification system and method for AI control strategies, so as to solve the problems mentioned in the background art.
[0005] To address the aforementioned technical problems, this invention provides the following technical solution: a shadow mode simulation verification system for AI control strategies, comprising a data synchronization and strategy parsing module, a shadow recursive simulation module, and a default tracing and boundary output module; the data synchronization and strategy parsing module is used to acquire the current operating status data of the target industrial control system and parse the AI control strategy generated by the AI server into a sequence of control instructions arranged according to the execution timing; the shadow recursive simulation module is used to simulate the dynamic response of the controlled equipment sequentially according to the control instruction sequence without issuing control instructions to the actual controlled equipment, and recursively calculate the electrical operation results based on the dynamic response of the controlled equipment; the default tracing and boundary output module is used to determine safety constraint default events based on the electrical operation results and equipment status, trace the control instructions that caused the safety constraint default events, and output the safe executable boundary and verification results of the AI control strategy.
[0006] According to the above technical solution, the data synchronization and strategy parsing module includes a state access submodule, a strategy parsing submodule, and an initial state generation submodule; the state access submodule is used to access the equipment power, energy storage status, voltage, frequency, feeder load, and market price data of the target industrial control system; the strategy parsing submodule is used to identify the controlled equipment, execution time, and target control quantity in the AI control strategy; the initial state generation submodule is used to form the initial execution state of the shadow simulation based on the accessed data; The shadow recursive simulation module includes a device response submodule, an electrical coupling submodule, and a state recursive submodule. The device response submodule is used to calculate the actual response state of the controlled device under the action of control commands. The electrical coupling submodule is used to calculate the feeder load, voltage deviation, and frequency deviation based on the actual response state. The state recursive submodule is used to pass the device state and electrical operation results of the current simulation step to the next simulation step. The default tracing and boundary output module includes a safety constraint verification submodule, a default association location submodule, a boundary adjustment submodule, and a verification result output submodule. The safety constraint verification submodule is used to determine whether the equipment status and electrical operation results meet the preset safety constraints. The default association location submodule is used to determine the control command that causes the safety constraint default event. The boundary adjustment submodule is used to adjust the boundary of the actual response increment corresponding to the default association control command and re-simulate. The verification result output submodule is used to output the safe executable boundary, default event, revenue difference, and online determination result.
[0007] A shadow pattern simulation verification method for AI control strategies includes the following steps: S1. Obtain the current operating status data of the target industrial control system and receive the AI control strategy generated by the AI server. Parse the AI control strategy into a sequence of control instructions arranged according to the execution time sequence. Each control instruction corresponds to a controlled device, an execution time, and a target control quantity. Form the initial execution state of the shadow simulation based on the current operating status data. S2. In the shadow execution environment, control commands are simulated and executed sequentially according to the control command sequence. In each simulation step, the actual response state that the controlled device can achieve is calculated based on the actual response state of the controlled device in the previous simulation step, the power change limit, and the current device state. The control commands are not sent to the real controlled device. The shadow execution environment is a simulation environment initialized with the current running state data, isolated from the control interface of the real controlled device, and used only for simulating the execution of control commands. S3. Update the electrical coupling relationship represented by the electrical coupling matrix according to the actual response state obtained in the current simulation step, and calculate the electrical operation result of the current simulation step. The electrical operation result includes feeder load, voltage deviation and frequency deviation. Use the equipment state and electrical operation result of the current simulation step as the input of the next simulation step, so that the shadow simulation is continuously recursively pushed according to the execution time sequence. S4. Compare the equipment status and electrical operation results of each simulation step with the preset safety constraints. When a safety constraint violation event occurs, record the time of violation, the violation item and the degree of violation. Based on the changes in control quantities and electrical coupling effects before and after the time of violation, determine the violation-related control command that caused the safety constraint violation event. S5. When no safety constraint default event occurs, the actual response trajectory corresponding to the original AI control strategy is determined as the safe executable boundary, and the revenue difference is calculated based on the shadow simulation results. When a safety constraint default event occurs, the actual response increment corresponding to the default-related control instruction is adjusted, and the shadow simulation is re-executed based on the adjusted actual response amount. If the re-simulation result meets the preset safety constraints, the safe executable boundary of the AI control strategy is determined, and the verification result is output based on the safe executable boundary, the default event, and the revenue difference.
[0008] According to the above technical solution, step S1 includes the following steps: S1-1. To enable the natural language strategy, table strategy, or interface strategy generated by the AI server to enter the stepwise shadow simulation process, the AI control strategy is first uniformly organized into a sequence of control targets arranged according to the execution time sequence. Each control target corresponds to the target control quantity that each controlled device needs to achieve within a simulation step. The AI control strategy is then parsed into a sequence of control targets. ,in, Indicates the control target sequence. Indicates the simulation step number. This indicates the total number of simulation steps contained in the control target sequence. Indicates the first The control objective corresponding to each simulation step; S1-2, The control objective for each simulation step is expressed as: ,in, Indicates the total number of controlled devices, let For the first In the simulation step, the first The target control quantity of the controlled device. Indicates the serial number of the controlled device, and ; S1-3. Establish the initial shadow execution state based on the current running status data. The initial shadow execution state This includes the initial actual control quantities of each controlled device, the initial energy storage state of the energy storage device, the feeder load, voltage deviation, and frequency deviation. The market price sequence is retained separately as input data for subsequent revenue evaluation. The significance of this step is to enable the shadow simulation to start from the current state of the real industrial control system, rather than from a fixed sample detached from the field state. The actual response state includes at least the actual response quantity of the controlled device in the corresponding simulation step.
[0009] According to the above technical solution, step S2 includes: S2-1, for the first The first simulation step For each controlled device, since it cannot directly reach the target control quantity given by the AI control strategy without being limited by power changes within a single simulation step, the actual response quantity of the controlled device in the previous simulation step is first read. Then, based on the maximum allowable rate of change of the control quantity of the controlled device, the maximum increase or decrease in response magnitude that can be achieved in the current simulation step is determined. Finally, the actual response quantity of the current simulation step is calculated based on the difference between the target control quantity and the actual response quantity of the previous simulation step. ,in, Indicates the first The controlled device in the first The actual response quantity of each simulation step Indicates the first The actual response of the controlled device in the previous simulation step. Indicates the first The maximum allowable rate of change of the control quantity for each controlled device. This indicates the time length between two adjacent simulation steps. The principle behind this formula is that when the target control quantity given by the AI control strategy changes too much, the shadow execution environment does not directly use the target control quantity, but instead calculates the actual response quantity that the device can achieve in the current simulation step according to the maximum rate of change allowed by the device. S2-2. In the simulation of energy storage devices, a positive actual response is defined as the energy storage device discharging power or outputting power to the system, and a negative actual response is defined as the energy storage device charging power or absorbing power from the system. When a controlled device is an energy storage device, the energy storage status is updated based on the actual response of the current simulation step: ,in, Indicates the first The energy storage device in the first Energy storage status in each simulation step Indicates the first The energy storage device's energy storage state in the previous simulation step, Indicates the first The energy conversion coefficient of an energy storage device Indicates the first The rated capacity of an energy storage device is given by a formula that reflects the state changes of the energy storage device during continuous charging and discharging, enabling subsequent safety verification to identify risks of exceeding the energy storage state limits.
[0010] According to the above technical solution, step S3 includes: S3-1. Combine the actual response quantities of all controlled devices in the current simulation step to form the actual response vector: ,in, Indicates the first The actual response vector of each simulation step, symbol Indicates transpose; S3-2. After obtaining the actual response vector of the current simulation step, based on the network topology, line impedance, node power reference of the target industrial control system, and the electrical operation results of the previous simulation step, generate an electrical coupling matrix to characterize the influence of the equipment response on the feeder load, voltage deviation, and frequency deviation. The elements in the electrical coupling matrix represent the influence coefficients of the actual response changes of the corresponding controlled equipment on the corresponding electrical operation components, and the electrical operation results are calculated according to the following formula: ,in, Indicates the first The electrical operation result vector for each simulation step, wherein the electrical operation result vector includes feeder load, voltage deviation and frequency deviation; Indicates the first The electrical coupling matrix for each simulation step, the electrical coupling matrix This is obtained by applying a unit disturbance to the actual response of each controlled device near the current shadow execution state and recording the changes in feeder load, voltage deviation, and frequency deviation; where... The matrix element in row h and column j represents the degree of influence of the unit actual response change of the j-th controlled device on the h-th electrical operation component; Indicates the first The electrical reference vector of each simulation step when the current control objective is not executed. The significance of this formula is to map the actual response of the equipment to the electrical operation result, so that the control quantity change of a single controlled equipment can be transmitted to the feeder load, voltage deviation and frequency deviation through the electrical coupling matrix. S3-3. The actual response state of the equipment and the electrical operation results of the current simulation step are used as the input state for the safety simulation in the next simulation step, and the market price series is retained as input data for subsequent revenue evaluation. ,in, Indicates the first The shadow execution state after each simulation step is completed Indicates the first The energy storage state vectors of all energy storage devices in each simulation step are used to ensure that the shadow simulation is recursively based on the control timing, avoiding treating each simulation step as an independent static verification process. Market price data is not involved in the electrical state recursion, but is used to calculate the revenue difference of the AI control strategy in the subsequent calculation.
[0011] According to the above technical solution, step S4 includes: S4-1, From the first Shadow execution state after each simulation step is completed Extracting electrical operation result vectors and energy storage state vector The electrical operation result vector and the energy storage state vector are then combined into a safety verification vector: ,in, Indicates the first A safety verification vector for each simulation step, wherein the safety verification vector is used to verify the feeder load, voltage deviation, frequency deviation, and upper and lower limits of energy storage status; S4-2. For each security check component in the security check vector, a security constraint upper limit and a security constraint lower limit are pre-configured for that security check component, wherein the security constraint upper limit is greater than the security constraint lower limit; when a security check component exceeds the corresponding upper limit or falls below the corresponding lower limit, the degree of breach is calculated according to the proportion of the exceedance relative to the width of the security constraint interval. ,in, Indicates the first The degree of breach of contract in each simulation step. This represents the component index in the security check vector. Indicates the first In the simulation step, the first The value of each security check component. Indicates the first The upper limit of security constraints for each security verification component Indicates the first The lower bound of security constraints for each security verification component, the significance of this formula lies in transforming security constraints of different dimensions into a unified degree of breach; when When it is greater than zero, determine the first If a safety constraint violation event occurs in a simulation step, the safety verification component that exceeds the corresponding upper limit of the safety constraint or falls below the corresponding lower limit of the safety constraint is identified as a violation item. The simulation step number, component name, component value, corresponding upper or lower limit of the safety constraint, and degree of violation of the safety verification component are written into the safety constraint violation event. S4-3. To avoid merely recording the result of a breach without determining its source, after the first occurrence of a safety constraint breach event, the safety verification component with the highest breach severity is selected as the tracing object. The actual response increment of each controlled device in the breach simulation step is multiplied by the electrical coupling coefficient corresponding to the breach component to estimate the contribution of each controlled device to the breach component. The simulation step in which the first safety constraint breach event occurs is recorded as the breach simulation step. The security verification component with the highest degree of breach is recorded as the breach component. Based on the matrix elements corresponding to the default components in the electrical coupling matrix, calculate the contribution of each controlled device to the default components: ,in, Indicates the first The controlled device is in the default simulation step Default weight Impact and contribution Represents the electrical coupling matrix The Middle Line 1 Column matrix elements, Indicates the first The controlled device is in the default simulation step The actual response quantity, Indicates the first The controlled device is in the default simulation step The actual response of the previous simulation step; S4-4. Identify the control instructions corresponding to the controlled equipment with the greatest impact as default-related control instructions: ,in, This indicates the sequence number of the controlled device associated with the default. This formula is used to trace the security constraint default event back to the specific controlled device and the specific simulation step, giving subsequent boundary adjustments a clear target. In the simulation step, the first The control instructions corresponding to each controlled device are identified as default-related control instructions.
[0012] According to the above technical solution, step S5 includes: S5-1. After determining the default-related control instruction, instead of regenerating the complete AI control strategy, the control direction of the instruction is kept unchanged. Only the actual response increment of the instruction relative to the previous simulation step is reduced to determine the maximum safe range that the instruction can be executed under the original control direction. The actual response increment of the default-related controlled device in the default simulation step is proportionally adjusted to obtain the adjusted actual response quantity. ,in, This indicates the actual response of the controlled device associated with the default after adjustments in the default simulation step. Indicates the boundary adjustment ratio, and The value of is between zero and one. The significance of this formula is to preserve the control direction of the original AI control strategy, while only reducing the actual response increment that leads to default, thereby determining the maximum extent to which the control command can be executed under safety constraints. This indicates the actual response quantity of the controlled device associated with the default in the default simulation step. This indicates the actual response of the controlled device associated with the default in the simulation step preceding the default simulation step; S5-2. Repeat steps S2 to S4 under different boundary adjustment ratios, and determine the maximum boundary adjustment ratio that satisfies all safety constraints: ,in, Indicates the maximum safety boundary adjustment ratio. Indicates the use of boundary adjustment ratio During resimulation The formula is used to determine the safe executable boundary of the AI control strategy under the condition of not triggering a safety constraint default event. If there is no boundary adjustment ratio that makes the default degree of all simulation steps zero, it is determined that the AI control strategy does not have a safe executable boundary, and the result of not recommending going online and the corresponding safety constraint default event are output. S5-3. Determine the actual boundary response amount corresponding to the default-related control instruction based on the maximum safety boundary adjustment ratio: ,in, This indicates that the controlled device is associated with the breach of contract in the breach simulation step. The actual response value of the boundary is used to limit the maximum executable range of the corresponding control command in the shadow simulation, and serves as the output content of the safe executable boundary of the AI control strategy. S5-4. After determining the safety boundary, based on the actual response quantities, market price sequences, and equipment operating times obtained during the shadow simulation process, calculate the market revenue when using the AI control strategy, the baseline revenue when not using the AI control strategy, the equipment depreciation cost, and the default cost, and calculate the revenue difference accordingly: ,in, Indicates the difference in earnings. This indicates the market returns obtained through shadow simulation using an AI control strategy. This represents the baseline return without the AI control strategy. This indicates the cost of equipment depreciation. The default cost arising from a breach of security constraints is represented by the following: the market revenue is obtained by summing the actual response volume of each simulation step participating in market settlement, the corresponding market price, and the time length between two adjacent simulation steps; the benchmark revenue is calculated based on the benchmark control plan when the AI control strategy is not executed; the equipment depreciation cost is calculated based on the actual response volume variation of each controlled device and the corresponding equipment depreciation coefficient; the default cost is zero when no security constraint default event occurs, and is calculated based on the degree of default and a preset default cost coefficient when a security constraint default event occurs. S5-5. When no security constraint default event occurs and the revenue difference reaches the preset revenue threshold, output a go-live result. When the maximum security boundary adjustment ratio is one, it means that the default-related control instruction in the AI control strategy can pass the security constraint verification without reduction. Based on this, if the revenue difference reaches the preset revenue threshold, output a go-live result. When the maximum security boundary adjustment ratio is less than one, output the default-related control instruction, the actual boundary response amount, and a re-verification suggestion. When the revenue difference does not reach the preset revenue threshold, output a go-live result that is not recommended. The verification result includes the safe executable boundary, the revenue difference, and the go-live judgment result. When a security constraint default event occurs, the verification result also includes the time of default, the default item, the degree of default, and the default-related control instruction.
[0013] Compared with existing technologies, the beneficial effects achieved by this invention are as follows: This invention forms a complete verification link through data synchronization and strategy parsing, shadow recursive simulation, default tracing, and boundary output, enabling AI control strategies to complete pre-launch simulation verification without directly acting on real equipment; in each simulation step, the actual response of the equipment after being affected by response delay, power change limitations, and energy storage state changes is first calculated, and then the electrical coupling results are updated based on the actual response, so that the simulation process can reflect the cumulative impact of control actions in continuous execution; when voltage deviation, frequency deviation, feeder load, and energy storage state exceedances occur, the system can trace the control commands that caused the default and redetermine the control quantity boundaries, thereby not only determining whether the strategy can be launched, but also outputting the executable boundary, default event, and revenue difference, providing a clear basis for the safe launch of microgrid, virtual power plant, and power market control strategies. Attached Figure Description
[0014] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is a flowchart illustrating the present invention; Figure 2 This is a schematic diagram of the overall modular structure of the present invention. Detailed Implementation
[0015] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0016] Please see Figure 1 and Figure 2This invention provides a technical solution: a shadow mode simulation verification system for AI control strategies, comprising a data synchronization and strategy parsing module, a shadow recursive simulation module, and a default tracing and boundary output module. The data synchronization and strategy parsing module is used to acquire the current operating status data of the target industrial control system and parse the AI control strategy generated by the AI server into a sequence of control instructions arranged according to the execution time sequence. The shadow recursive simulation module is used to simulate the dynamic response of the controlled equipment sequentially according to the control instruction sequence without issuing control instructions to the actual controlled equipment, and recursively calculate the electrical operation results based on the dynamic response of the controlled equipment. The default tracing and boundary output module is used to determine safety constraint default events based on the electrical operation results and equipment status, trace the control instructions that caused the safety constraint default events, and output the safe executable boundary and verification results of the AI control strategy. The data synchronization and strategy parsing module includes a state access submodule, a strategy parsing submodule, and an initial state generation submodule. The state access submodule is used to access the equipment power, energy storage status, voltage, frequency, feeder load, and market price data of the target industrial control system. The strategy parsing submodule is used to identify the controlled equipment, execution time, and target control quantity in the AI control strategy. The initial state generation submodule is used to generate the initial execution state of the shadow simulation based on the accessed data. The shadow recursive simulation module includes a device response submodule, an electrical coupling submodule, and a state recursive submodule. The device response submodule is used to calculate the actual response state of the controlled device under the action of control commands. The electrical coupling submodule is used to calculate the feeder load, voltage deviation, and frequency deviation based on the actual response state. The state recursive module is used to pass the device state and electrical operation results of the current simulation step to the next simulation step. The default tracing and boundary output module includes a safety constraint verification submodule, a default correlation location submodule, a boundary adjustment submodule, and a verification result output submodule. The safety constraint verification submodule is used to determine whether the equipment status and electrical operation results meet the preset safety constraints. The default correlation location submodule is used to determine the control command that causes the safety constraint default event. The boundary adjustment submodule is used to adjust the boundary of the actual response increment corresponding to the default-related control command and re-simulate. The verification result output submodule is used to output the safe executable boundary, default event, revenue difference, and online judgment result. A shadow pattern simulation verification method for AI control strategies includes the following steps: S1. Obtain the current operating status data of the target industrial control system and receive the AI control strategy generated by the AI server. Parse the AI control strategy into a sequence of control instructions arranged according to the execution time sequence. Each control instruction corresponds to a controlled device, an execution time and a target control quantity. Form the initial execution state of the shadow simulation based on the current operating status data. S2. In the shadow execution environment, control commands are simulated and executed sequentially according to the sequence of control commands. In each simulation step, the actual response state that the controlled device can achieve is calculated based on the actual response state of the controlled device in the previous simulation step, the power change limit, and the current device state. Control commands are not sent to the real controlled device. The shadow execution environment is a simulation environment initialized with the current running state data, isolated from the control interface of the real controlled device, and used only for simulating the execution of control commands. S3. Update the electrical coupling relationship represented by the electrical coupling matrix based on the actual response state obtained in the current simulation step, and calculate the electrical operation result of the current simulation step. The electrical operation result includes feeder load, voltage deviation and frequency deviation. Use the equipment state and electrical operation result of the current simulation step as the input of the next simulation step, so that the shadow simulation is continuously recursively pushed according to the execution sequence. S4. Compare the equipment status and electrical operation results of each simulation step with the preset safety constraints. When a safety constraint violation event occurs, record the time of violation, the violation item and the degree of violation. Based on the changes in control quantities and electrical coupling effects before and after the time of violation, determine the violation-related control command that caused the safety constraint violation event. S5. When no safety constraint default event occurs, the actual response trajectory corresponding to the original AI control strategy is determined as the safe executable boundary, and the revenue difference is calculated based on the shadow simulation results. When a safety constraint default event occurs, the actual response increment corresponding to the default-related control instruction is adjusted, and the shadow simulation is re-executed based on the adjusted actual response amount. If the re-simulation result meets the preset safety constraints, the safe executable boundary of the AI control strategy is determined, and the verification result is output based on the safe executable boundary, the default event, and the revenue difference. Step S1 includes the following steps: S1-1. To enable the natural language strategy, table strategy, or interface strategy generated by the AI server to enter the stepwise shadow simulation process, the AI control strategy is first uniformly organized into a sequence of control objectives arranged according to the execution time sequence. Each control objective corresponds to the target control quantity that each controlled device needs to achieve within a simulation step. The AI control strategy is then parsed into a sequence of control objectives. ,in, Indicates the control target sequence. Indicates the simulation step number. This indicates the total number of simulation steps contained in the control target sequence. Indicates the first The control objective corresponding to each simulation step; S1-2, The control objective for each simulation step is expressed as: ,in, Indicates the total number of controlled devices, let For the first In the simulation step, the first The target control quantity of the controlled device. Indicates the serial number of the controlled device, and ; S1-3. Establish the initial shadow execution state based on the current running status data. Initial shadow execution state This includes the initial actual control quantities of each controlled device, the initial energy storage state of the energy storage device, the feeder load, voltage deviation, and frequency deviation. The market price sequence is retained separately as input data for subsequent revenue evaluation. The significance of this step is to make the shadow simulation start from the current state of the real industrial control system, rather than from a fixed sample detached from the field state. The actual response state includes at least the actual response quantity of the controlled device in the corresponding simulation step. In step S1, this invention does not simply treat the AI control strategy as a text to be reviewed. Instead, it first converts the AI control strategy into a sequence of control objectives that can be executed step by step, and then maps this sequence of control objectives to the current operating state of the target industrial control system. This process ensures that subsequent shadow simulations have a clear starting point and a clear execution order, allowing for a clear distinction between the strategy input, the initial system state, and the subsequent simulation state during review. Compared to simply manually reading or statically comparing the AI control strategy, this step transforms the AI control strategy from an abstract decision into an object that can be processed step by step by the simulation environment, providing a unified data foundation for subsequent equipment response calculations, electrical coupling recursion, and safety boundary determination.
[0017] Step S2 includes: S2-1, for the first The first simulation step For each controlled device, since it cannot directly reach the target control quantity given by the AI control strategy without being limited by power changes within a single simulation step, the actual response quantity of the controlled device in the previous simulation step is first read. Then, based on the maximum allowable rate of change of the control quantity of the controlled device, the maximum increase or decrease in response magnitude that can be achieved in the current simulation step is determined. Finally, the actual response quantity of the current simulation step is calculated based on the difference between the target control quantity and the actual response quantity of the previous simulation step. ,in, Indicates the first The controlled device in the first The actual response quantity of each simulation step Indicates the first The actual response of the controlled device in the previous simulation step. Indicates the first The maximum allowable rate of change of the control quantity for each controlled device. This indicates the time length between two adjacent simulation steps. The principle behind this formula is that when the target control quantity given by the AI control strategy changes too much, the shadow execution environment does not directly use the target control quantity, but instead calculates the actual response quantity that the device can achieve in the current simulation step according to the maximum rate of change allowed by the device. S2-2. In the simulation of energy storage devices, a positive actual response is defined as the energy storage device discharging power or outputting power to the system, and a negative actual response is defined as the energy storage device charging power or absorbing power from the system. When a controlled device is an energy storage device, the energy storage status is updated based on the actual response of the current simulation step: ,in, Indicates the first The energy storage device in the first Energy storage status in each simulation step Indicates the first The energy storage device's energy storage state in the previous simulation step, Indicates the first The energy conversion coefficient of an energy storage device Indicates the first The rated capacity of an energy storage device is given by this formula, which reflects the state changes of the energy storage device during continuous charging and discharging, so that subsequent safety verification can identify the risk of the energy storage state exceeding the limit. In step S2, this invention does not directly regard the target control quantity given by the AI control strategy as the actual operating state already reached by the controlled equipment. Instead, it calculates the actual response state that the equipment can truly achieve in the current simulation step based on the actual response state of the controlled equipment in the previous simulation step and the equipment's allowable change capability. This process reflects the continuous change process that industrial control equipment undergoes when executing control commands, avoiding the deviation where the equipment instantly reaches the target value in the simulation, but the equipment in the real system cannot reach that target value. The role of this step in this solution is to convert the ideal control target in the AI control strategy into an executable response trajectory at the equipment level, so that subsequent electrical operation results and safety verification are based on the actual executable state of the equipment. Compared with the conventional offline simulation method of directly using the strategy target value for calculation, this step better reflects the constraint of the equipment's own operating capability on the strategy execution effect, thus enabling the early detection of safety risks caused by insufficient equipment response capability.
[0018] Step S3 includes: S3-1. Combine the actual response quantities of all controlled devices in the current simulation step to form the actual response vector: ,in, Indicates the first The actual response vector of each simulation step, symbol Indicates transpose; S3-2. After obtaining the actual response vector of the current simulation step, based on the network topology, line impedance, node power reference of the target industrial control system, and the electrical operation results of the previous simulation step, generate an electrical coupling matrix to characterize the influence of the equipment response on the feeder load, voltage deviation, and frequency deviation. The elements in the electrical coupling matrix represent the influence coefficients of the actual response changes of the corresponding controlled equipment on the corresponding electrical operation components, and the electrical operation results are calculated according to the following formula: ,in, Indicates the first The electrical operation result vector for each simulation step includes feeder load, voltage deviation, and frequency deviation. Indicates the first The electrical coupling matrix for each simulation step. This is obtained by applying a unit disturbance to the actual response of each controlled device near the current shadow execution state and recording the changes in feeder load, voltage deviation, and frequency deviation; where... The matrix element in row h and column j represents the degree of influence of the unit actual response change of the j-th controlled device on the h-th electrical operation component; Indicates the first The electrical reference vector of each simulation step when the current control objective is not executed. The significance of this formula is to map the actual response of the equipment to the electrical operation result, so that the control quantity change of a single controlled equipment can be transmitted to the feeder load, voltage deviation and frequency deviation through the electrical coupling matrix. S3-3. The actual response state of the equipment and the electrical operation results of the current simulation step are used as the input state for the safety simulation in the next simulation step, and the market price series is retained as input data for subsequent revenue evaluation. ,in, Indicates the first The shadow execution state after each simulation step is completed Indicates the first The energy storage state vectors of all energy storage devices in each simulation step are used to ensure that the shadow simulation is recursively based on the control timing, avoiding treating each simulation step as an independent static verification process. Market price data does not participate in the electrical state recursion, but is used to calculate the revenue difference of the AI control strategy in the subsequent calculation. In step S3, the present invention further maps the actual response state of the equipment obtained in the current simulation step to electrical operating results such as feeder load, voltage deviation, and frequency deviation, and passes the shadow execution state formed in this simulation step to the next simulation step. The key to this approach is that the electrical effects caused by the current control action are not discarded after the end of this simulation step, but continue to affect the calculation process of subsequent simulation steps, thus forming a continuously recursive shadow simulation link. The role of this step in this scheme is to transform the response changes at the equipment level into electrical operating changes at the system level, and to reflect the continuous influence between multiple control actions through state recursion. Compared to the conventional method of verifying each moment as an independent sample, this step can capture the cumulative influence of preceding control actions on subsequent electrical states, making the shadow simulation results closer to the continuous operation process of a real industrial control system.
[0019] Step S4 includes: S4-1, From the first Shadow execution state after each simulation step is completed Extracting electrical operation result vectors and energy storage state vector The electrical operation result vector and the energy storage state vector are then merged into a safety verification vector. ,in, Indicates the first Each simulation step has a safety verification vector, which is used to verify the feeder load, voltage deviation, frequency deviation, and upper and lower limits of energy storage status. S4-2. For each security check component in the security check vector, pre-configure the upper and lower limits of the security constraints corresponding to that component, with the upper limit being greater than the lower limit. When a security check component exceeds the corresponding upper limit or falls below the corresponding lower limit, calculate the degree of breach based on the proportion of the excess to the width of the security constraint interval. ,in, Indicates the first The degree of breach of contract in each simulation step. This represents the component index in the security check vector. Indicates the first In the simulation step, the first The value of each security check component. Indicates the first The upper limit of security constraints for each security verification component Indicates the first The lower bound of security constraints for each security verification component, the significance of this formula lies in transforming security constraints of different dimensions into a unified degree of breach; when When it is greater than zero, determine the first If a safety constraint violation event occurs in a simulation step, the safety verification component that exceeds the corresponding upper limit of the safety constraint or falls below the corresponding lower limit of the safety constraint is identified as a violation item. The simulation step number, component name, component value, corresponding upper or lower limit of the safety constraint, and degree of violation of the safety verification component are written into the safety constraint violation event. S4-3. To avoid merely recording the result of a breach without determining its source, after the first occurrence of a safety constraint breach event, the safety verification component with the highest breach severity is selected as the tracing object. The actual response increment of each controlled device in the breach simulation step is multiplied by the electrical coupling coefficient corresponding to the breach component to estimate the contribution of each controlled device to the breach component. The simulation step in which the first safety constraint breach event occurs is recorded as the breach simulation step. The security verification component with the highest degree of breach is recorded as the breach component. Based on the matrix elements corresponding to the default components in the electrical coupling matrix, calculate the contribution of each controlled device to the default components: ,in, Indicates the first The controlled device is in the default simulation step Default weight Impact and contribution Represents the electrical coupling matrix The Middle Line 1 Column matrix elements, Indicates the first The controlled device is in the default simulation step The actual response quantity, Indicates the first The controlled device is in the default simulation step The actual response of the previous simulation step; S4-4. Identify the control instructions corresponding to the controlled equipment with the greatest impact as default-related control instructions: ,in, This indicates the sequence number of the controlled device associated with the default. This formula is used to trace the security constraint default event back to the specific controlled device and the specific simulation step, giving subsequent boundary adjustments a clear target. In the simulation step, the first The control instructions corresponding to each controlled device are identified as default-related control instructions. In step S4, this invention not only determines whether a safety constraint violation event has occurred in a certain simulation step, but also further determines the violation item, violation time, and violation-related control instruction corresponding to the violation event. The working principle of this process is as follows: first, identify the operating components exceeding the safety constraint range in the continuously recursively obtained shadow execution states; then, combine the changes in equipment response and electrical coupling effects before and after the violation occurred to determine which controlled device's control action at that moment contributed most to the violation result. The role of this step in this scheme is to extend safety verification from simple pass / fail judgment to cause localization, enabling the system to explain why the strategy is unsafe and which control instruction the unsafety originates from. Compared to conventional safety verification that only outputs over-limit alarms, this step can trace the violation result back to the specific control object and the specific execution time, providing a clear object for subsequent boundary adjustments.
[0020] Step S5 includes: S5-1. After determining the default-related control instruction, instead of regenerating the complete AI control strategy, the control direction of the instruction is kept unchanged. Only the actual response increment of the instruction relative to the previous simulation step is reduced to determine the maximum safe range that the instruction can be executed under the original control direction. The actual response increment of the default-related controlled device in the default simulation step is proportionally adjusted to obtain the adjusted actual response quantity. ,in, This indicates the actual response of the controlled device associated with the default after adjustments in the default simulation step. Indicates the boundary adjustment ratio, and The value of is between zero and one. The significance of this formula is to preserve the control direction of the original AI control strategy, while only reducing the actual response increment that leads to default, thereby determining the maximum extent to which the control command can be executed under safety constraints. This indicates the actual response quantity of the controlled device associated with the default in the default simulation step. This indicates the actual response of the controlled device associated with the default in the simulation step preceding the default simulation step; S5-2. Repeat steps S2 to S4 under different boundary adjustment ratios, and determine the maximum boundary adjustment ratio that satisfies all safety constraints: ,in, Indicates the maximum safety boundary adjustment ratio. Indicates the use of boundary adjustment ratio During resimulation The formula is used to determine the safe executable boundary of the AI control strategy under the condition of not triggering safety constraint default events. If there is no boundary adjustment ratio that makes the default degree of all simulation steps zero, it is determined that the AI control strategy does not have a safe executable boundary, and the result of not recommending deployment and the corresponding safety constraint default event are output. S5-3. Determine the actual boundary response amount corresponding to the default-related control instruction based on the maximum safety boundary adjustment ratio: ,in, This indicates that the controlled device is associated with the breach of contract in the breach simulation step. The actual boundary response is used to limit the maximum executable range of the corresponding control command in the shadow simulation and serves as the output content of the safe executable boundary of the AI control strategy. S5-4. After determining the safety boundary, based on the actual response quantities, market price sequences, and equipment operating times obtained during the shadow simulation process, calculate the market revenue when using the AI control strategy, the baseline revenue when not using the AI control strategy, the equipment depreciation cost, and the default cost, and calculate the revenue difference accordingly: ,in, Indicates the difference in earnings. This indicates the market returns obtained through shadow simulation using an AI control strategy. This represents the baseline return without the AI control strategy. This indicates the cost of equipment depreciation. The default cost is calculated as follows: market revenue is calculated by summing the actual response volume of each simulation step participating in market settlement, the corresponding market price, and the time length between two adjacent simulation steps; benchmark revenue is calculated based on the benchmark control plan when the AI control strategy is not executed; equipment depreciation cost is calculated based on the actual response volume variation of each controlled device and the corresponding equipment depreciation coefficient; default cost is zero when no safety constraint default event occurs, and is calculated based on the degree of default and the preset default cost coefficient when a safety constraint default event occurs. S5-5. When no security constraint default event occurs and the revenue difference reaches the preset revenue threshold, output a go-live result. When the maximum security boundary adjustment ratio is one, it means that the default-related control instruction in the AI control strategy can pass the security constraint verification without reduction. Based on this, if the revenue difference reaches the preset revenue threshold, output a go-live result. When the maximum security boundary adjustment ratio is less than one, output the default-related control instruction, the actual boundary response amount, and a re-verification suggestion. When the revenue difference does not reach the preset revenue threshold, output a go-live result that is not recommended. The verification result includes the safe executable boundary, the revenue difference, and the go-live judgment result. When a security constraint default event occurs, the verification result also includes the time of default, the default item, the degree of default, and the default-related control instruction.
[0021] In step S5, after determining the default-related control instruction, the present invention does not directly negate the entire AI control strategy, nor does it regenerate a new control strategy. Instead, while maintaining the original control direction, it reduces the actual response increment corresponding to the default-related control instruction and re-simulates it. The purpose of this process is to find the maximum extent to which the original AI control strategy can still be executed within safety constraints, given that the original AI control strategy already has certain economic objectives and control directions, thereby obtaining a safe and executable boundary. Compared to conventional methods that only provide a conclusion on whether the strategy is usable or unusable, this step further provides the extent to which the strategy should be executed to be safe, making the verification results not only have a judgment function but also a pre-deployment correction and decision support function. The calculation of the revenue difference is used to illustrate whether the strategy under this safety boundary still has implementation value, avoiding the direct deployment of strategies that only meet safety conditions but lack economic viability.
[0022] Through the above processing, this invention forms a complete verification chain from AI control strategy input, actual equipment response calculation, electrical operation result derivation, safety constraint violation tracing to safe executable boundary output. The core value of this chain lies in the fact that the AI control strategy is no longer merely statically reviewed, but rather unfolds step-by-step in a shadow environment corresponding to the actual operating state, according to the execution sequence. Each control action is first transformed into the actual equipment response, then into electrical operation impact, and continues to participate in the calculation of subsequent simulation steps. When a strategy has safety risks, this invention can indicate at which simulation moment the risk occurs, which corresponding safety constraint item, and which control instruction is mainly associated, and further provide the executable boundary of that control instruction within the safe range. Therefore, this invention can simultaneously solve the problems of difficulty in accurately reflecting the dynamic response of equipment, difficulty in demonstrating the continuous impact of electrical coupling, difficulty in locating the cause of exceeding limits, and difficulty in determining the safe execution range before the AI control strategy is deployed, thereby improving the reliability of AI control strategies in microgrid, virtual power plant, and power market control scenarios.
[0023] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0024] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A shadow mode simulation verification system for AI control strategies, characterized in that: The system includes a data synchronization and strategy parsing module, a shadow recursive simulation module, and a breach tracing and boundary output module. The data synchronization and strategy parsing module is used to acquire the current operating status data of the target industrial control system and parse the AI control strategy generated by the AI server into a sequence of control instructions arranged according to the execution time sequence. The shadow recursive simulation module is used to simulate the dynamic response of the controlled equipment in sequence according to the control instruction sequence without issuing control instructions to the actual controlled equipment, and recursively calculate the electrical operation results based on the dynamic response of the controlled equipment. The breach tracing and boundary output module is used to determine the safety constraint breach event based on the electrical operation results and equipment status, trace the control instruction that caused the safety constraint breach event, and output the safe executable boundary and verification results of the AI control strategy.
2. The shadow mode simulation verification system for AI control strategies according to claim 1, characterized in that: The data synchronization and strategy parsing module includes a state access submodule, a strategy parsing submodule, and an initial state generation submodule. The state access submodule is used to access the equipment power, energy storage status, voltage, frequency, feeder load, and market price data of the target industrial control system. The strategy parsing submodule is used to identify the controlled equipment, execution time, and target control quantity in the AI control strategy. The initial state generation submodule is used to form the initial execution state of the shadow simulation based on the accessed data. The shadow recursive simulation module includes a device response submodule, an electrical coupling submodule, and a state recursive module; The device response submodule is used to calculate the actual response state of the controlled device under the action of control commands; The electrical coupling submodule is used to calculate the feeder load, voltage deviation, and frequency deviation based on the actual response status. The state recursion submodule is used to pass the device state and electrical operation results of the current simulation step to the next simulation step; The default tracing and boundary output module includes a safety constraint verification submodule, a default association location submodule, a boundary adjustment submodule, and a verification result output submodule; the safety constraint verification submodule is used to determine whether the equipment status and electrical operation results meet the preset safety constraints. The default association location submodule is used to determine the control instructions that cause a security constraint default event; The boundary adjustment submodule is used to adjust the boundary of the actual response increment corresponding to the default-related control instruction and re-simulate; the verification result output submodule is used to output the safe and executable boundary, default event, profit difference and online determination result.
3. A shadow pattern simulation verification method for AI control strategies, characterized in that: The method, when applied to the system of claim 2, includes the following steps: S1. Obtain the current operating status data of the target industrial control system and receive the AI control strategy generated by the AI server. Parse the AI control strategy into a sequence of control instructions arranged according to the execution time sequence. Each control instruction corresponds to a controlled device, an execution time, and a target control quantity. Form the initial execution state of the shadow simulation based on the current operating status data. S2. In the shadow execution environment, control commands are simulated and executed sequentially according to the control command sequence. In each simulation step, the actual response state that the controlled device can achieve is calculated based on the actual response state of the controlled device in the previous simulation step, the power change limit, and the current device state. The control commands are not sent to the real controlled device. S3. Update the electrical coupling relationship represented by the electrical coupling matrix according to the actual response state obtained in the current simulation step, and calculate the electrical operation result of the current simulation step. The electrical operation result includes feeder load, voltage deviation and frequency deviation. Use the equipment state and electrical operation result of the current simulation step as the input of the next simulation step, so that the shadow simulation is continuously recursively pushed according to the execution time sequence. S4. Compare the equipment status and electrical operation results of each simulation step with the preset safety constraints. When a safety constraint violation event occurs, record the time of violation, the violation item and the degree of violation. Based on the changes in control quantities and electrical coupling effects before and after the time of violation, determine the violation-related control command that caused the safety constraint violation event. S5. When no safety constraint default event occurs, the actual response trajectory corresponding to the original AI control strategy is determined as the safe executable boundary, and the revenue difference is calculated based on the shadow simulation results. When a safety constraint default event occurs, the actual response increment corresponding to the default-related control instruction is adjusted, and the shadow simulation is re-executed based on the adjusted actual response amount. If the re-simulation result meets the preset safety constraints, the safe executable boundary of the AI control strategy is determined, and the verification result is output based on the safe executable boundary, the default event, and the revenue difference.
4. The shadow mode simulation verification method for AI control strategies according to claim 3, characterized in that: Step S1 includes the following steps: S1-1. The AI control strategy is uniformly organized into a sequence of control targets arranged according to the execution time sequence. Each control target corresponds to the target control quantity that each controlled device needs to achieve within a simulation step. The AI control strategy is parsed into a sequence of control targets: ,in, Indicates the control target sequence. Indicates the simulation step number. This indicates the total number of simulation steps contained in the control target sequence. Indicates the first The control objective corresponding to each simulation step; S1-2. The control objective for each simulation step is expressed as: ,in, Indicates the total number of controlled devices, let For the first In the simulation step, the first The target control quantity of the controlled device. Indicates the serial number of the controlled device, and ; S1-3. Establish the initial shadow execution state based on the current running status data. The initial shadow execution state This includes the initial actual control quantities of each controlled device, the initial energy storage status of the energy storage device, the feeder load, voltage deviation, and frequency deviation, while retaining the market price series as separate input data for subsequent revenue assessment.
5. The shadow mode simulation verification method for AI control strategies according to claim 4, characterized in that: Step S2 includes: S2-1, for the first The first simulation step For each controlled device, first read the actual response of the controlled device in the previous simulation step, and determine the maximum response amplitude that can be increased or decreased in the current simulation step based on the maximum allowable rate of change of the controlled device's control quantity. Then, calculate the actual response of the current simulation step based on the difference between the target control quantity and the actual response of the previous simulation step. ,in, Indicates the first The controlled device in the first The actual response quantity of each simulation step Indicates the first The actual response of the controlled device in the previous simulation step. Indicates the first The maximum allowable rate of change of the control quantity for each controlled device. This indicates the time length between two adjacent simulation steps; S2-2. In the simulation of energy storage devices, a positive actual response is defined as the energy storage device discharging power or outputting power to the system, and a negative actual response is defined as the energy storage device charging power or absorbing power from the system. When a controlled device is an energy storage device, the energy storage status is updated based on the actual response of the current simulation step: ,in, Indicates the first The energy storage device in the first Energy storage status in each simulation step Indicates the first The energy storage device's energy storage state in the previous simulation step, Indicates the first The energy conversion coefficient of an energy storage device Indicates the first The rated capacity of each energy storage device.
6. The shadow pattern simulation verification method for AI control strategies according to claim 5, characterized in that: Step S3 includes: S3-1. Combine the actual response quantities of all controlled devices in the current simulation step to form the actual response vector: ,in, Indicates the first The actual response vector of each simulation step, symbol Indicates transpose; S3-2. Calculate the electrical operation results according to the following formula: ,in, Indicates the first The electrical operation result vector for each simulation step, wherein the electrical operation result vector includes feeder load, voltage deviation and frequency deviation; Indicates the first The electrical coupling matrix for each simulation step, the electrical coupling matrix This is obtained by applying a unit disturbance to the actual response of each controlled device near the current shadow execution state and recording the changes in feeder load, voltage deviation, and frequency deviation; where... The matrix element in row h and column j represents the degree of influence of the unit actual response change of the j-th controlled device on the h-th electrical operation component; Indicates the first The electrical reference vector for each simulation step when the current control objective is not being executed; S3-3. The actual response state of the equipment and the electrical operation results of the current simulation step are used as the input state for the safety simulation in the next simulation step, and the market price series is retained as input data for subsequent revenue evaluation. ,in, Indicates the first The shadow execution state after each simulation step is completed Indicates the first The energy storage state vectors of all energy storage devices in each simulation step.
7. The shadow mode simulation verification method for AI control strategies according to claim 6, characterized in that: Step S4 includes: S4-1, From the first Shadow execution state after each simulation step is completed Extracting electrical operation result vectors and energy storage state vector The electrical operation result vector and the energy storage state vector are then combined into a safety verification vector: ,in, Indicates the first Security verification vector for each simulation step; S4-2. For each security check component in the security check vector, pre-configure the upper and lower limits of the security constraints corresponding to that component. When a security check component exceeds the corresponding upper limit or falls below the corresponding lower limit, calculate the degree of breach based on the proportion of the exceedance relative to the width of the security constraint interval. ,in, Indicates the first The degree of breach of contract in each simulation step. This represents the component index in the security check vector. Indicates the first In the simulation step, the first The value of each security check component. Indicates the first The upper limit of security constraints for each security verification component Indicates the first The lower limit of security constraints for each security verification component; when When it is greater than zero, determine the first If a safety constraint violation event occurs in a simulation step, the safety verification component that exceeds the corresponding upper limit of the safety constraint or falls below the corresponding lower limit of the safety constraint is identified as a violation item. The simulation step number, component name, component value, corresponding upper or lower limit of the safety constraint, and degree of violation of the safety verification component are written into the safety constraint violation event. S4-3. Record the simulation step in which the first safety constraint breach event occurs as the breach simulation step. The security verification component with the highest degree of breach is recorded as the breach component. Based on the matrix elements corresponding to the default components in the electrical coupling matrix, calculate the contribution of each controlled device to the default components: ,in, Indicates the first The controlled device is in the default simulation step Default weight Impact and contribution Represents the electrical coupling matrix The Middle Line number Column matrix elements, Indicates the first The controlled device is in the default simulation step The actual response quantity, Indicates the first The controlled device is in the default simulation step The actual response of the previous simulation step; S4-4. Identify the control instructions corresponding to the controlled equipment with the greatest impact as default-related control instructions: ,in, This indicates the serial number of the controlled equipment associated with the breach of contract.
8. The shadow mode simulation verification method for AI control strategies according to claim 7, characterized in that: Step S5 includes: S5-1. Proportionally adjust the actual response increment of the controlled equipment associated with default in the default simulation step to obtain the adjusted actual response quantity: ,in, This indicates the actual response of the controlled device associated with the default after adjustments in the default simulation step. Indicates the boundary adjustment ratio, and The value range is from zero to one. This indicates the actual response quantity of the controlled device associated with the default in the default simulation step. This indicates the actual response of the controlled device associated with the default in the simulation step preceding the default simulation step; S5-2. Repeat steps S2 to S4 under different boundary adjustment ratios, and determine the maximum boundary adjustment ratio that satisfies all safety constraints: ,in, Indicates the maximum safety boundary adjustment ratio. Indicates the use of boundary adjustment ratio During resimulation The degree of breach of contract in each simulation step; S5-3. Determine the actual boundary response amount corresponding to the default-related control instruction based on the maximum safety boundary adjustment ratio: ,in, This indicates that the controlled device is associated with the breach of contract in the breach simulation step. The actual response quantity at the boundary; S5-4. Calculate the market revenue when using the AI control strategy, the baseline revenue when not using the AI control strategy, the equipment depreciation cost, and the default cost, and calculate the revenue difference accordingly: ,in, Indicates the difference in earnings. This indicates the market returns obtained through shadow simulation using an AI control strategy. This represents the baseline return without the AI control strategy. This indicates the cost of equipment depreciation. This indicates the cost of breaching a security constraint. S5-5. When no security constraint default event occurs and the profit difference reaches the preset profit threshold, output a result indicating that the system can be deployed. When the maximum security boundary adjustment ratio is one, it means that the default-related control instruction in the AI control strategy can pass the security constraint verification without being reduced. Based on this, if the profit difference reaches the preset profit threshold, output a result indicating that the system can be deployed. When the maximum security boundary adjustment ratio is less than one, output the default-related control instruction, the actual response amount at the boundary, and a re-verification suggestion. When the profit difference does not reach the preset profit threshold, output a result indicating that deployment is not recommended.