Safety domain determination method and device for equipment assembly process and equipment assembly system
Patent Information
- Application Number
- CN202611358269.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-09-03
- Publication Date
- 2026-09-29
AI Technical Summary
[0003]本发明提供一种设备装配过程的安全域确定方法、装置及设备装配系统,以至少解决相关技术中设备装配过程中关键状态反演误差未量化且多失效模式耦合效应被忽略导致安全域构造不准的问题
[0026]本发明的实施例提供的技术方案至少带来以下有益效果:首先,通过在反演估计阶段同步确定目标状态估计值及其对应的状态估计误差界,将反演过程中由观测噪声、模型偏差等因素引起的不确定性以量化边界的形式显式表征,并在后续安全裕度计算中利用该误差界对名义安全裕度进行缩减,使得最终得到的保守安全裕度真实反映了在状态不可直接测量条件下评估结果的可信程度,从根本上解决了相关技术中因忽略反演不确定性而导致安全裕度存在虚假置信风险的问题。
Smart Images

Figure CN122837401A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of equipment assembly control technology, and in particular to a method, apparatus and system for determining the safety domain in the equipment assembly process. Background Technology
[0002] In the assembly process of precision equipment such as heavy rotating machinery, the contact state of key mating interfaces (such as contact pressure distribution, real-time interference fit, and interface friction state) often cannot be directly measured by sensors and usually requires indirect inversion estimation based on external observable signals. However, when conducting safety assessments, most related technologies directly substitute the inverted state estimates into safety criteria for calculation without quantifying and analyzing the estimation errors introduced by the inversion process itself, resulting in low accuracy of the calculated safety margin. Furthermore, due to the computational time of complex models, the aforementioned technologies cannot construct a state-space safety domain containing uncertainty quantification and coupling correction information in real time within millisecond-level control cycles, failing to meet the needs of online accurate early warning and optimal control decision-making in the assembly process. Summary of the Invention
[0003] This invention provides a method, apparatus, and system for determining the safety domain during equipment assembly, to at least address the problems in related technologies where the inversion error of critical states during equipment assembly is not quantified and the coupling effect of multiple failure modes is ignored, leading to inaccurate safety domain construction. The technical solution of this invention is as follows: According to a first aspect of the present invention, a method for determining the safety domain in a device assembly process is provided. The method includes: acquiring multi-channel observation signals during the device assembly process; performing inversion estimation on a target state that cannot be directly observed based on the multi-channel observation signals to obtain a target state estimate and a corresponding state estimation error bound; determining the nominal safety margin for each of multiple failure modes based on the target state estimate, and reducing the nominal safety margin using the state estimation error bound to obtain a conservative safety margin for each failure mode; acquiring coupling correlation parameters between multiple failure modes, and performing linkage correction on the conservative safety margin based on the coupling correlation parameters to obtain a corrected safety margin; and determining the state-space safety domain that satisfies the constraints of all failure modes based on the corrected safety margin.
[0004] Safety margin represents the remaining margin between the current state and the critical point of a certain failure mode. For example, if the contact pressure limit is 350 MPa, the safety margin corresponding to the current pressure of 280 MPa is 70 MPa.
[0005] The state-space safety region represents the set of states where all failure modes simultaneously satisfy the safety constraints. In essence, the state-space safety region is a closed feasible region enclosed by the safety margins of multiple failure modes.
[0006] It is understandable that the conservative safety margin is the amount of risk introduced by subtracting the state estimation error bound from the nominal safety margin.
[0007] In the above technical solution, by explicitly introducing the state estimation error boundary into the safety margin calculation link, the nominal safety margin is conservatively reduced to cover the uncertainty risk of inversion. At the same time, the coupling correlation parameters are used to realize the dynamic linkage correction between multiple failure modes. Finally, a state space safety domain that takes into account both reliability and real-time performance is constructed, which solves the problem of safety boundary distortion caused by neglecting estimation error and mode coupling in traditional methods.
[0008] As a technical solution, the target state estimate is determined based on the state estimation function and multi-channel observation signals; the state estimation error bound is determined based on the observation noise of the multi-channel observation signals, the inversion model error, and the partial derivatives of the state estimation function with respect to the multi-channel observation signals; the partial derivatives characterize the sensitivity of the state estimation function to the channel observation signals; the risk reduction amount is determined based on the state estimation error bound and the gradient of the constraint function of the failure mode with respect to the target state, and the risk reduction amount is subtracted from the nominal safety margin to obtain the conservative safety margin, wherein the gradient characterizes the sensitivity of the constraint function to each state variable.
[0009] In the above technical solution, the impact of observation signal fluctuations on state estimation and the impact of state fluctuations on safety margin are quantified by partial derivatives and gradients, respectively. This achieves accurate propagation of error from the observation layer to the safety assessment layer and risk reduction, avoiding the problems of over-conservatism or under-conservatism caused by the empirical coefficient method.
[0010] As a technical solution, when the state variables of the target state satisfy the first state condition, the following worst-case algorithm formula is used to determine the conservative safety margin: ; In the formula, For the first Conservative safety margin for each failure mode in the worst-case scenario. For nominal safety margin, For the first Constraint functions for various failure modes Regarding the target state vector In the target state estimate The gradient vector at that point, This is the state estimation error bound vector. This indicates that the absolute value of each element of the vector is taken and then transposed; the first state condition includes one or both of the following: the distribution of the observation noise is uncertain, and the superposition degree of the errors between any two state variables is greater than the preset superposition degree; when the state variables of the target state satisfy the second state condition, the conservative safety margin is determined using the following confidence level formula: ; In the formula, For the first Conservative safety margins for each failure mode at the confidence level. For the corresponding confidence level Standard normal quantiles It is a diagonal matrix composed of the squares of the elements of the state estimation error boundary vector; the second state condition includes one or both of the following: the observation noise follows a known probability distribution, and the error correlation between state variables is lower than a preset threshold.
[0011] The above technical solutions provide two conservative shrinkage strategies to adapt to different working conditions: the first, the worst-case method, is applicable to extreme scenarios where noise characteristics are unknown or errors may be superimposed in the same direction, ensuring absolute safety as a safety net; the second, the confidence level method, is applicable to conventional scenarios where noise statistical characteristics are clear, reducing unnecessary over-conservatism while ensuring a specified confidence level, and improving the engineering applicability of safety margin calculation.
[0012] As a technical solution, based on the safety margin time series of different failure modes, the real-time correlation coefficient between any two failure modes is calculated as a coupling correlation parameter; when the safety margin of the first failure mode decreases, based on the real-time correlation coefficient, the conservative safety margin of the second failure mode, which is positively correlated with the first failure mode, is reduced proportionally to obtain the corrected safety margin.
[0013] In the above technical solution, the coupling strength between failure modes is dynamically captured by real-time correlation coefficient. When the safety status of a certain mode deteriorates, the safety boundaries of other modes that are positively correlated with it are automatically tightened proportionally. This realizes the transformation from single-mode independent monitoring to multi-mode linkage perception and effectively avoids the risk of systemic omission due to ignoring coupling effects.
[0014] As a technical solution, the conservative safety margin of the second failure mode, which is positively correlated with the first failure mode, is reduced proportionally to obtain the modified safety margin. The calculation formula for the coupled modification is as follows: ; In the formula, For the first The corrected safety margin after coupling correction for each failure mode. For the first Conservative safety margin for each failure mode The coupling reduction factor is calculated using the following formula: ; In the formula, This is the coupling strength coefficient, used to adjust the overall sensitivity of the coupling correction. Failure mode and The real-time correlation coefficient between them; Failure mode The reference margin level is usually taken as the safety margin value of the initial assembly state; Failure mode The current security margin; the construction conditions for the state-space security domain are: ; In the formula, For state-space safe domain, Let be the state vector in the state space. Failure mode constraint functions, The risk reduction amount is determined by the state estimation error bound. For the first Corrected safety margins for various failure modes For the first Conservative safety margin for each failure mode This represents the total number of failure modes.
[0015] In the above technical solution, the complex coupling correction logic is transformed into a mathematical expression that can be calculated in real time by using the coupling reduction factor and the security domain construction conditions in analytical form. This allows the security domain boundary to be dynamically adjusted as the coupling strength changes, ensuring comprehensive coverage of multi-mode coupling risks while meeting the performance requirements of millisecond-level online computing.
[0016] As a technical solution, the gradient information of the corrected safety margin with respect to the control action is obtained; in the set of feasible control actions, the control action that maximizes the gradient information that minimizes all failure modes is selected as the recommended control instruction.
[0017] In the above technical solution, decision-making is based on gradient information of the safety domain boundary rather than a single margin value. It can automatically search for the control direction that improves the overall safety of the system the fastest in a multi-dimensional constraint space, realizing a leap from passive safety monitoring to active safety optimization.
[0018] As a technical solution, a soft warning threshold and a hard red line threshold are set for the conservative safety margin of each failure mode. The soft warning threshold is greater than the hard red line threshold. When the conservative safety margin reaches the soft warning threshold, a warning is triggered and a recommended control command is output. When the conservative safety margin reaches the hard red line threshold, an emergency shutdown protection is triggered.
[0019] In the above technical solution, an actionable adjustment suggestion is provided in the early stage of risk to avoid accidental shutdown through a dual-threshold graded response mechanism, and rigid protection is implemented before the risk gets out of control to ensure equipment safety, thus taking into account both the continuity and safety of the assembly process.
[0020] As a technical solution, after the equipment assembly process is completed, the measured values of failure modes and the estimated target state of the final assembly state are obtained. Based on the deviation between the measured values and the estimated target state after mapping by a performance function, and combined with a preset learning rate, the limit threshold parameters of the failure modes are iteratively updated to narrow the state estimation error bound. The calculation formula for the iterative update is as follows: ; In the formula, For the first The first update after the second assembly The limit threshold parameters for each failure mode For the first Limit threshold parameters during the second assembly. To preset the learning rate, For the first Measured values from the second assembly For the first The target state estimate of the final state of the second assembly is obtained by the first... Performance function of various failure modes The output after mapping.
[0021] In the above technical solution, the measured true values after each assembly are used to perform closed-loop correction of the model parameters. As the number of assembly times accumulates, the model error boundary is gradually reduced, and the accuracy of the safety margin calculation is continuously improved, solving the problem that fixed parameter models are difficult to adapt to individual differences and long-term drift.
[0022] According to a second aspect of the present invention, a safety domain determination apparatus for a device assembly process is provided, comprising: a state inversion module, configured to acquire multi-channel observation signals during the device assembly process, perform inversion estimation on a target state that cannot be directly observed based on the multi-channel observation signals, and obtain a target state estimate and a corresponding state estimation error bound; a margin calculation module, configured to determine the nominal safety margin of each of multiple failure modes based on the target state estimate, and reduce the nominal safety margin using the state estimation error bound to obtain a conservative safety margin for each failure mode; a coupling correction module, configured to acquire coupling correlation parameters between multiple failure modes, perform linkage correction on the conservative safety margin based on the coupling correlation parameters, and obtain a corrected safety margin; and a safety domain construction module, configured to construct a state-space safety domain that satisfies the constraints of all failure modes based on the corrected safety margin.
[0023] The aforementioned device achieves software solidification of the safety domain determination method through a modular architecture. Each module works collaboratively to complete the entire process from signal acquisition to safety domain output, making it easy to integrate into existing assembly control systems.
[0024] According to a third aspect of the present invention, a device assembly system is provided, comprising: a multi-channel sensing unit configured to acquire multi-channel observation signals during the device assembly process; and a controller communicatively connected to the multi-channel sensing unit, the controller being configured to execute a security domain determination method for the device assembly process as described above.
[0025] According to a fourth aspect of the present invention, a computer-readable storage medium is provided, on which instructions are stored, which, when executed by a processor of an electronic device, enable the electronic device to perform a security domain determination method for a device assembly process as described in the first aspect and any possible implementation thereof.
[0026] The technical solution provided by the embodiments of the present invention brings at least the following beneficial effects: First, by simultaneously determining the target state estimate and its corresponding state estimation error bound during the inversion estimation stage, the uncertainty caused by factors such as observation noise and model bias during the inversion process is explicitly characterized in the form of a quantitative boundary. In the subsequent safety margin calculation, this error bound is used to reduce the nominal safety margin, so that the final conservative safety margin truly reflects the credibility of the evaluation result under the condition that the state cannot be directly measured. This fundamentally solves the problem of false confidence risk in the safety margin caused by ignoring inversion uncertainty in related technologies.
[0027] Secondly, by acquiring the coupling correlation parameters between multiple failure modes and accordingly making a linkage correction on the conservative safety margin of each failure mode, when the safety status of a certain failure mode deteriorates, it can automatically sense and tighten the safety boundaries of other failure modes that are coupled with it. This effectively avoids the problem in related technologies that treat multiple failure modes as independent events and thus overlook the risk of systemic coupling, and improves the comprehensiveness and accuracy of safety monitoring of complex assembly processes.
[0028] Finally, based on the corrected safety margin after coupling and linkage correction, the state space safety domain that satisfies all failure mode constraints is directly determined. Uncertainty quantification and multi-mode coupling correction information are uniformly incorporated into the construction conditions of the safety domain, providing complete multi-dimensional safety boundary information for online safety assessment and control decisions in the assembly process. This enables the safety domain to be constructed in real time within the control cycle, thereby improving the efficiency of online early warning.
[0029] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0030] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure, and are not intended to unduly limit this disclosure.
[0031] Figure 1 This is a flowchart illustrating a method for determining the security domain in a device assembly process according to an exemplary embodiment; Figure 2 This is a block diagram illustrating a safety domain determination device for an equipment assembly process according to an exemplary embodiment; Figure 3 This is a schematic block diagram of a controller according to an exemplary embodiment. Detailed Implementation
[0032] To enable those skilled in the art to better understand the technical solutions of this disclosure, the technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings.
[0033] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.
[0034] For ease of understanding, the method for determining the safety domain in the equipment assembly process provided in this application will be described in detail below with reference to the accompanying drawings.
[0035] Figure 1 This is a flowchart illustrating a method for determining the security domain in a device assembly process according to an exemplary embodiment, such as... Figure 1 As shown, the method for determining the safety domain during the equipment assembly process includes the following steps.
[0036] Step S100: Acquire multi-channel observation signals during equipment assembly, and perform inversion estimation on the target state that cannot be directly observed based on the multi-channel observation signals to obtain the target state estimate and the corresponding state estimation error bound.
[0037] In precision equipment assembly scenarios such as hot fitting of heavy rotors and press fitting of bearings, the key interface states that determine the assembly quality and safety (such as the actual contact pressure distribution of mating surfaces, real-time interference fit, and interface friction coefficient) are often obscured by the metal entity and cannot be directly measured by sensors.
[0038] Based on this, the embodiments of this application do not rely on a single direct measurement value, but instead collect multi-modal observation signals such as temperature, displacement, strain, and pressure through multi-channel sensing units arranged on an accessible surface; that is, multi-channel observation signals. Then, a pre-set inversion model (such as a multiphysics coupling model or a data-driven model) is used to indirectly calculate the accurate internal target state. More importantly, considering factors such as sensor noise, model simplification bias, and operating condition disturbances, the inverted state value inevitably contains uncertainties. The state estimation error bound in this embodiment is not a simple measurement error, but a quantitative characterization of the overall uncertainty of the inversion process; it defines the maximum deviation range that the true state may have.
[0039] For example, if the inverted interface contact pressure is 100 MPa, and the corresponding state estimation error bound is ±5 MPa, it means that at the current confidence level, the actual contact pressure falls between 95 MPa and 105 MPa with a very high probability. This method of extending the point estimate to a bounded interval provides a reliable input basis for subsequent safety assessments, avoiding complete distortion of the safety margin due to blindly trusting the inverted values.
[0040] Step S200: Determine the nominal safety margin of each of the various failure modes based on the target state estimate, and reduce the nominal safety margin using the state estimation error bound to obtain the conservative safety margin of each failure mode.
[0041] The nominal safety margin refers to the theoretical safety margin calculated based on design criteria or material limits, assuming that the inversion state is completely accurate.
[0042] However, since the state estimation has been confirmed to have an error bound in step S100, directly using the nominal margin for judgment carries the risk of underreporting.
[0043] In this implementation step, by mapping the state estimation error boundary to the safety margin space, the potential risk caused by uncertainty is subtracted from the nominal safety margin to obtain the conservative safety margin. In this way, the uncertainty at the state level is transformed into a reliability safety net at the safety indicator level.
[0044] For example, for the failure mode of excessive contact pressure, if the state estimation error boundary indicates that the actual pressure may be 5 MPa higher than the estimated value, then this 5 MPa risk will be subtracted from the nominal margin before calculating the conservative safety margin. Although the conservative safety margin obtained in this way is smaller in numerical value than the nominal margin, it truly reflects the safety bottom line under conditions of incomplete information, ensuring that the system remains within a controllable and safe range even under the most unfavorable combination of errors.
[0045] Step S300: Obtain the coupling correlation parameters between multiple failure modes, and perform linkage correction on the conservative safety margin based on the coupling correlation parameters to obtain the corrected safety margin.
[0046] In complex equipment assembly processes, various failure modes often do not occur in isolation, but rather are coupled together through multi-physical field mechanisms such as heat, force, and friction. For example, an increase in interface temperature may not only lead to material softening (temperature failure mode), but also cause thermal expansion, thereby changing the contact pressure (pressure failure mode), and even affect the coefficient of friction, leading to jamming (friction failure mode). If an independent assessment method is used, this dynamic correlation is ignored, making it prone to failure when multiple risks are superimposed.
[0047] Based on this, this embodiment calculates the correlation or physical mechanism-based coupling coefficient between the time series of safety margins of different failure modes in real time, using this as a coupling correlation parameter. When a significant decrease in the safety margin of a certain failure mode is detected, the system automatically reduces the conservative safety margin of other positively correlated failure modes proportionally according to this coupling correlation parameter. This linkage correction mechanism enables safety assessment to have a system-level perception capability that affects the whole system, effectively identifying and warning of hidden risks that, while appearing safe on a single indicator, are already approaching the edge of system collapse due to coupling effects.
[0048] Step S400: Based on the modified safety margin, determine the state space safety domain that satisfies all failure mode constraints.
[0049] A state-space safety domain is a closed feasible region in a multi-dimensional state space, enclosed by the modified safety margins of all failure modes. Within this region, any combination of system states ensures that all failure modes remain within the safety threshold; conversely, if the system state trajectory touches or crosses the boundary of this safety domain, it means that at least one failure mode's risk exceeds the acceptable range. Unlike alarms based on single-parameter thresholds, the state-space safety domain provides a global, multi-dimensional safety envelope. It not only indicates whether the current state is safe but also visually displays how far the current state is from the safety boundaries in each direction, and which direction's boundary is most critical. This geometric safety representation provides a direct mathematical basis and decision-making support for subsequent assembly progress prediction, optimal control action recommendation, and tiered early warning, enabling a leap from passive monitoring to proactive safety management.
[0050] Based on the above embodiments, this embodiment further refines the method for determining the error boundary and the specific calculation algorithm for the conservative safety margin, so as to construct a complete uncertainty quantification technology defense line.
[0051] As one implementation method, the target state estimate is determined based on the state estimation function and multi-channel observation signals; the state estimation error bound is determined based on the observation noise of the multi-channel observation signals, the inversion model error, and the partial derivative of the state estimation function with respect to the multi-channel observation signals; the partial derivative characterizes the sensitivity of the state estimation function to the channel observation signals; the risk reduction amount is determined based on the state estimation error bound and the gradient of the constraint function of the failure mode with respect to the target state, and the risk reduction amount is subtracted from the nominal safety margin to obtain the conservative safety margin, wherein the gradient characterizes the sensitivity of the constraint function to each state variable.
[0052] This implementation method achieves precise chain propagation of errors from the observation layer to the safety assessment layer. The partial derivatives of the state estimation function with respect to multi-channel observation signals mathematically constitute the Jacobian matrix elements of the inversion model, physically representing the maximum possible change in the target state estimate caused by a unit fluctuation in the observed signal. For example, a large partial derivative value for a temperature channel indicates that the measurement noise of that channel will be significantly amplified by the inversion model into the estimation uncertainty of the interface contact pressure. The gradient of the constraint function with respect to the target state describes the rate at which each state variable deviates from its estimate, thus affecting the safety margin. By combining the observation-end uncertainty determined by the partial derivatives with the assessment-end sensitivity determined by the gradients, the maximum potential loss of safety margin caused by state estimation errors, i.e., the risk reduction, can be quantitatively calculated. This analytical sensitivity-based quantification method avoids the blindness of relying on manual experience to set fixed safety factors in traditional methods. It prevents both reduced assembly efficiency due to excessively large coefficients and safety oversights caused by excessively small coefficients, ensuring that the conservative safety margin truly reflects the completeness of information under the current operating conditions.
[0053] As one implementation method, this application provides two adaptive algorithms to adapt to different operating conditions when reducing the nominal safety margin by utilizing the state estimation error bound.
[0054] The first approach is to determine the conservative safety margin by using the worst-case algorithm formula as follows, when the state variables of the target state satisfy the first state condition.
[0055] .
[0056] In the formula, For the first Conservative safety margin for each failure mode in the worst-case scenario. For nominal safety margin, For the first Constraint functions for various failure modes Regarding the target state vector In the target state estimate The gradient vector at that point, Let be the state estimation error bound vector. This means that after taking the absolute value of each element of the vector and performing a transpose operation, the dot product of the vector and the error bound vector represents the maximum risk when all error components are superimposed in the most unfavorable direction for safety.
[0057] The aforementioned first state condition may include one or both of the following: the distribution of the observed noise is uncertain, and the superposition degree of the errors between any two state variables is greater than the preset superposition degree.
[0058] The worst-case algorithm is a non-probabilistic robust estimation method that assumes all uncertainties act on the system simultaneously in the worst-case scenario. In the initial stages of equipment assembly or during periods of abnormal disturbance, the statistical distribution of observed noise is often unknown and difficult to model because sensors have not yet entered their steady-state operating range or environmental interference is strong. Simultaneously, strong coupling of multiple physical fields such as heat, force, and friction can lead to a high positive correlation between the estimation errors of different state variables; that is, a positive deviation in one variable is highly likely to be accompanied by a positive deviation in another. In such cases, using probabilistic methods based on the independence assumption would severely underestimate the actual risk. Therefore, when the system detects unclear noise distribution characteristics or an error correlation coefficient exceeding a preset threshold (e.g., 0.8), it automatically switches to the worst-case algorithm, using the dot product of absolute values to cover all possible error combinations, ensuring the absolute reliability of the safety assessment results.
[0059] The second approach is to determine the conservative safety margin by using the following confidence level formula when the state variables of the target state satisfy the second state condition.
[0060] .
[0061] In the formula, For the first Conservative safety margins for each failure mode at the confidence level. For the corresponding confidence level The standard normal quantile.
[0062] For example, when hour , The matrix is a diagonal matrix composed of the squares of the elements of the state estimation error bound vector. This matrix form implies the assumption that the estimation errors of each state variable are independent of each other. The quadratic expression within the square root characterizes the statistical fluctuation range of the safety margin at a given confidence level.
[0063] The confidence level algorithm is a probabilistic and statistical risk quantification method suitable for stable system operation and well-defined noise characteristics under normal operating conditions. In the mid-to-late stages of the assembly process, as sensors preheat and process parameters stabilize, the observed noise typically follows a zero-mean Gaussian distribution, and the correlation of estimation errors among state variables is significantly reduced after decoupling. Continuing to use the worst-case algorithm at this point would lead to an excessive compression of the safety margin, resulting in unnecessary warnings or shutdowns.
[0064] Therefore, when the system confirms that the noise distribution conforms to normal characteristics and the error correlation is lower than the preset threshold, it automatically switches to the confidence level algorithm. This confidence level algorithm uses standard normal quantiles to transform the error boundary into a risk deduction amount at a specific confidence level. Under the premise of ensuring that the safety assessment results have a clear probability guarantee (such as 95% confidence level), it effectively reduces the performance loss caused by excessive conservatism and improves the continuity and economy of the assembly process.
[0065] It should be noted that the switching between the two algorithms is not limited to a fixed time period, but is a dynamic decision based on real-time state conditions. The system can estimate the statistical moments such as kurtosis and skewness of the noise online through a sliding window to determine the distribution pattern, or evaluate the degree of superposition in the same direction by calculating the off-diagonal elements of the error covariance matrix, thereby achieving adaptive and seamless switching between algorithms.
[0066] By employing the aforementioned dual-modal conservative contraction method, the security domain construction method of this application embodiment can not only meet the security requirements under extreme uncertainty, but also take into account the evaluation accuracy under normal operating conditions, demonstrating the strong adaptability and engineering practical value of the technical solution in complex industrial environments.
[0067] Based on the above embodiments, this embodiment further refines the coupling correction mechanism between multiple failure modes and the analytical construction method of the state-space safety domain.
[0068] As one implementation method, based on the safety margin time series of different failure modes, the real-time correlation coefficient between any two failure modes is calculated as a coupling correlation parameter; when the safety margin of the first failure mode decreases, based on the real-time correlation coefficient, the conservative safety margin of the second failure mode, which is positively correlated with the first failure mode, is reduced proportionally to obtain the corrected safety margin.
[0069] The aforementioned real-time correlation coefficients are not fixed design constants, but rather time-varying indicators that reflect the dynamic evolution of the multi-physics coupling strength during the assembly process.
[0070] In practical engineering implementation, the sliding window method can be used to calculate the Pearson correlation coefficient. For example, the window length can be set to 50 sampling periods. As the assembly process progresses, the safety margin data within the window is continuously updated, thereby capturing the instantaneous changes in the correlation between failure modes caused by factors such as temperature rise and contact pressure changes. This dynamic sensing mechanism enables the system to identify risk combinations that appear independent under steady-state conditions but are highly coupled in specific transient processes.
[0071] When a significant decrease in the safety margin of a failure mode (such as excessive interface temperature) is detected, if its real-time correlation coefficient with another failure mode (such as excessive contact pressure) is positive and large, it indicates a strong positive correlation between the two under the current operating conditions. In this case, the system will automatically reduce the conservative safety margin of the latter proportionally. Through this linkage correction method, single-point risks are transformed into system-level risk warnings, effectively avoiding the omission of cascading failure risks induced by coupling effects due to isolated evaluation of each failure mode.
[0072] As one implementation method, in the above embodiments, the conservative safety margin of the second failure mode that is positively correlated with the first failure mode is reduced proportionally to obtain the modified safety margin. The calculation formula for the coupled modification of the modified safety margin is as follows.
[0073] .
[0074] In the formula, For the first The corrected safety margin after coupling correction for each failure mode. For the first The conservative safety margins calculated for each failure mode in Example 2 This is the coupling reduction factor. The formula for calculating the coupling reduction factor is as follows.
[0075] .
[0076] In the formula, The coupling strength coefficient is used to adjust the overall sensitivity of the coupling correction. Its value is usually between 0 and 1 and can be tuned through offline calibration or expert experience. For example, it can be 0.3 in the case of a heavy rotor with strong thermo-mechanical coupling. Failure mode and The real-time correlation coefficient between them is used to trigger reduction only when the value is positive; negative or unrelated patterns are not included in the correction. Failure mode The reference margin level is usually selected as the nominal safety margin value at the initial moment of assembly, which serves as the benchmark for measuring the current degree of margin loss. Failure mode The current safety margin. The summation term in the above formula accumulates all other relevant mode-to-mode pairs. Risk transmission volume, The function ensures that the reduction effect only occurs when the margins of other modes are below the reference level, thus avoiding erroneous corrections in a safe state.
[0077] Based on the above-mentioned modified safety margin, the formula for the construction conditions of the state-space safe domain is as follows.
[0078] .
[0079] In the formula, for State-space safety domain at any given time. Let be the state vector in the state space. Failure mode constraint functions, The risk reduction amount is determined by the state estimation error bound. For the first Corrected safety margins for various failure modes For the first Conservative safety margin for each failure mode This represents the total number of failure modes.
[0080] This construction condition defines a multidimensional closed region whose boundary is determined by the modified constraints of all failure modes. In the formula... The ratio reflects the tightening effect of coupling correction on the safety region boundary: when the coupling effect leads to a reduction in the safety margin... Less than the conservative safety margin When the ratio is greater than 1, the effective contraction increases, the safety domain boundary contracts inward, and thus the multi-mode coupling risk is explicitly incorporated into the geometry of the safety domain.
[0081] In a specific implementation, the safety domain determination method for the equipment assembly process of this application is adopted. During the implementation process, the construction and dynamic evolution of the safety domain are observed, yielding the following results: In the initial stage of assembly (time t1), the margins of each failure mode are sufficient, the coupling reduction factor is close to 1, and the safety domain... The volume is relatively large; as assembly progresses to the middle stage (time t2), if the margin of a certain mode decreases and shows a positive correlation with other modes, the coupling reduction factor... The reduction causes the safety domain boundary to shrink inward, resulting in a smaller volume. When assembly is nearing completion (time t3), if the coupling effect continues to increase, the safety domain... This will further shrink to near the target threshold. Therefore, this dynamic change in geometric boundaries not only quantifies the evolution trend of the overall system safety level but also provides operators with a visualized risk situation awareness.
[0082] The aforementioned coupling correction and safety domain construction both employ analytical mathematical expressions, rather than relying on time-consuming numerical iterative simulations. This analytical structure allows the safety domain boundary and its gradient information to be obtained in real time through simple algebraic operations, with the computation time for a single calculation controlled within milliseconds, fully meeting the requirements for online monitoring and real-time control of the equipment assembly process. Thus, this embodiment, through the combination of analytical modeling and dynamic parameter correction, achieves an order-of-magnitude improvement in computational efficiency while ensuring the accuracy of coupling risk assessment, laying a real-time foundation for subsequent optimal decision-making and hierarchical early warning.
[0083] Based on the above embodiments, this embodiment further transforms the security assessment results into real-time control decisions and hierarchical protection mechanisms, forming a complete closed loop of early warning, recommendation and execution.
[0084] As one implementation method, gradient information of the corrected safety margin with respect to the control action is obtained; in the set of feasible control actions, the control action that maximizes the gradient information that minimizes all failure modes is selected as the recommended control instruction.
[0085] The gradient information of the safety margin with respect to control actions physically characterizes the rate of safety gain resulting from a unit change in control input. For example, in a heavy-duty rotor hot-fitting scenario, if the control action is heating power, this gradient reflects how many MPa the safety margin of the interface contact pressure increases by 1 kW of heating power. Unlike passive monitoring that only focuses on the current margin value, gradient information reveals the trend and controllability of system state evolution.
[0086] Based on this, this embodiment employs a Max-Min strategy for decision optimization. This means that among all feasible control actions, the one that maximizes the safety improvement for the most dangerous failure mode (i.e., the one with the smallest safety margin or the most unfavorable gradient) is prioritized. This strategy not only prevents the system from neglecting other near-failure modes due to over-optimization of a particular safety metric, but also ensures a balanced improvement in the overall safety of the assembly process.
[0087] For example, when the interface temperature margin is sufficient but the contact pressure margin is critical, the system will not continue to recommend heating actions (although this may not have a significant impact on the temperature margin). Instead, it will search for and recommend a control combination that can mitigate the contact pressure risk to the greatest extent without significantly worsening the temperature margin, thereby guiding the system state trajectory back to the center of the safety domain.
[0088] As one implementation method, a soft warning threshold and a hard red line threshold are set for the conservative safety margin of each failure mode, with the soft warning threshold being greater than the hard red line threshold. When the conservative safety margin reaches the soft warning threshold, a warning is triggered and a recommended control command is output. When the conservative safety margin reaches the hard red line threshold, an emergency shutdown protection is triggered.
[0089] The specific implementation logic of this tiered response mechanism is as follows.
[0090] Firstly, the warning threshold is usually set as a preset proportion of the nominal safety margin at the initial moment of assembly, such as 30%. Its physical meaning is that the system has entered the area of concern, and although no substantial failure has occurred, it has deviated from the optimal process window.
[0091] Secondly, the hard red line threshold is set to a lower critical value, such as 10% of the initial margin or an absolute safety baseline determined based on material limits, representing that the system is already in an unacceptable risk zone. When the conservative safety margin of any failure mode drops below the soft warning threshold but has not yet reached the hard red line, the system is judged to be in a yellow warning state. At this time, not only are visual or auditory prompts issued to the operator, but more importantly, the recommended control instructions calculated in the aforementioned steps are automatically output to guide personnel or the automated system to take corrective measures to restore the safety level. However, when the conservative safety margin further deteriorates and reaches the hard red line threshold, the system is judged to be in a red danger state, immediately bypassing manual intervention and directly triggering emergency shutdown protection, locking the hydraulic push-in system or cutting off the heat source to prevent catastrophic accidents.
[0092] This dual-threshold collaborative approach effectively solves the problem of frequent false alarms and production interruptions caused by alarm-based shutdown in traditional single-threshold monitoring, while also overcoming the risk of missed alarms that may arise from a single lenient threshold. By embedding proactive optimization suggestions into the soft warning stage, the system empowers operators to make fine-tuning adjustments in the early stages of risk, activating rigid protection only when the risk becomes uncontrollable. This ensures the inherent safety of the equipment while maximizing the continuity of the assembly process and the stability of the technology.
[0093] It should be noted that the specific values of the soft warning threshold and the hard red line threshold are not fixed. In practical applications, they can be dynamically adjusted according to the assembly stage, the value of the workpiece, or the historical failure rate. For example, the soft warning threshold can be appropriately increased in the critical assembly stage to increase safety sensitivity, while it can be appropriately relaxed in the non-critical preheating stage to reduce unnecessary interference.
[0094] Based on the above embodiments, this embodiment further introduces a closed-loop feedback mechanism after assembly to achieve continuous self-optimization of model parameters.
[0095] As one implementation method, after the equipment assembly process is completed, the measured values of the failure modes and the target state estimates of the final assembly state are obtained; based on the deviation between the measured values and the target state estimates after being mapped by the performance function, and combined with a preset learning rate, the limit threshold parameters of the failure modes are iteratively updated to narrow the state estimation error bound.
[0096] Specifically, the calculation formula for the above iterative update is as follows.
[0097] .
[0098] In the formula, For the first The first update after the second assembly The limit threshold parameters for each failure mode. For the first The limit threshold parameter used during the second assembly. To preset the learning rate, For the first Measured values from the second assembly. For the first The target state estimate of the final state of the second assembly is obtained by the first... Performance function of various failure modes The output after mapping.
[0099] This formula is a parameter adaptive law based on the idea of gradient descent. It utilizes the truth information obtained after assembly to calibrate the baseline of the online inversion model.
[0100] Among them, the preset learning rate It is a key hyperparameter for controlling the convergence speed and stability of the control parameters, and its value range is usually between 0.01 and 0.5.
[0101] like Setting the parameters too high, while resulting in faster convergence, makes them susceptible to oscillations caused by occasional measurement noise during a single assembly, leading to frequent fluctuations in safety assessment standards. If... Setting the value too low can ensure a smooth and stable update process, but it will significantly prolong the cycle for the system to adapt to new operating conditions or correct inherent biases in the model.
[0102] In practical engineering applications, an adaptive learning rate strategy can be adopted, which involves using a larger learning rate in the initial few assembly steps to quickly approximate the true parameter level, and then gradually decreasing the learning rate to lock in steady-state accuracy, thereby balancing response speed and long-term stability.
[0103] Regarding the measured values The acquisition of measured values is not limited to a single detection method. Since the interface state during the assembly process often becomes observable or verifiable by destructive / non-destructive means after assembly, the sources of measured values are diverse.
[0104] In some implementation examples, for failure modes such as excessive contact pressure or excessive residual stress, the true values can be obtained after assembly through ultrasonic non-destructive testing, X-ray diffraction stress measurement, or indentation measurement after disassembling the specimen. For interference fit deviations, the actual interference distribution can be obtained by scanning and reconstructing the mating surfaces using a high-precision coordinate measuring machine. For excessive interface temperatures, although historical temperatures cannot be directly measured afterward, the highest temperature peak experienced during assembly can be inferred through metallographic analysis.
[0105] It should be understood that, regardless of the detection method used, as long as the physical true value can reflect the final state of assembly or the extreme value of the process, it can be used as the input benchmark for iterative updates in this embodiment.
[0106] Through the above implementation method, this online adaptive correction mechanism gradually eliminates systematic biases in the inversion model caused by factors such as simplification assumptions, material parameter drift, or sensor aging by continuously incorporating the measured true values from each assembly. With the number of iterations... The increase of the limit threshold parameter The model gradually converges to the true physical boundary, substantially reducing the error bound of state estimation determined by model uncertainties. This reduction in the error bound directly translates to the conservative safety margin calculation stage in the above embodiments, reducing unnecessary risk deductions and making the subsequent assembly safety margin assessment results more accurate and closer to the actual safety level. In the above embodiments, this characteristic of becoming more accurate with use effectively solves the problem of the gradual degradation of assessment accuracy of traditional fixed-parameter models when facing individual differences and long-term operating condition evolution, significantly improving the long-term engineering applicability of the safety domain construction method.
[0107] It is important to note that the online adaptive correction step described in this embodiment is completely decoupled from the real-time safety domain construction process of the above embodiments in terms of timing. The real-time process runs within a millisecond-level control cycle, focusing on the safety monitoring and decision-making of the current assembly process; while the adaptive correction is a background task, triggered only during non-production periods after assembly or during data playback. This decoupling ensures that parameter update calculations do not consume valuable real-time control computing power, and also avoids interference with the ongoing assembly process due to dynamic parameter adjustments, thus guaranteeing the determinism and security of the real-time monitoring system.
[0108] To achieve the above functions, the safety domain determination device for the equipment assembly process includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art will readily recognize that, based on the algorithmic steps of the examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0109] This disclosure also provides an embodiment such as Figure 2 The device for determining the safety domain in the equipment assembly process shown is a specific implementation of the aforementioned method embodiment at the functional module level. It aims to solidify complex safety assessment logic into software or firmware components that can be embedded in the control system through standardized data interfaces and processing units.
[0110] The device mainly includes a state inversion module 210, a margin calculation module 220, a coupling correction module 230, and a security domain construction module 240.
[0111] The state inversion module 210 is used to acquire multi-channel observation signals during the equipment assembly process, and to perform inversion estimation on the target state that cannot be directly observed based on the multi-channel observation signals, so as to obtain the target state estimate and the corresponding state estimation error bound.
[0112] The margin calculation module 220 is used to determine the nominal safety margin of each of the various failure modes based on the target state estimate, and to reduce the nominal safety margin by using the state estimation error bound to obtain the conservative safety margin of each failure mode.
[0113] The coupling correction module 230 is used to obtain the coupling correlation parameters between multiple failure modes, and to perform linkage correction on the conservative safety margin based on the coupling correlation parameters to obtain the corrected safety margin.
[0114] The security domain construction module 240 is used to construct a state-space security domain that satisfies all failure mode constraints based on a modified security margin.
[0115] As one implementation method, the state inversion module 210 is specifically used for: determining the target state estimate based on the state estimation function and multi-channel observation signals; determining the state estimation error bound based on the observation noise of the multi-channel observation signals, the inversion model error, and the partial derivatives of the state estimation function with respect to the multi-channel observation signals; the partial derivatives characterize the sensitivity of the state estimation function to the channel observation signals; determining the risk reduction amount based on the state estimation error bound and the gradient of the constraint function of the failure mode with respect to the target state, and subtracting the risk reduction amount from the nominal safety margin to obtain the conservative safety margin, wherein the gradient characterizes the sensitivity of the constraint function to each state variable.
[0116] As one implementation method, the margin calculation module 220 is specifically used to: determine the conservative safety margin by using the following worst-case algorithm formula when the state variables of the target state satisfy the first state condition: .
[0117] In the formula, For the first Conservative safety margin for each failure mode in the worst-case scenario. For nominal safety margin, For the first Constraint functions for various failure modes Regarding the target state vector In the target state estimate The gradient vector at that point, This is the state estimation error bound vector. This indicates that the absolute value of each element of the vector is taken and then transposed; the first state condition includes one or both of the following: the distribution of the observation noise is uncertain, and the superposition degree of the errors between any two state variables is greater than the preset superposition degree; when the state variables of the target state satisfy the second state condition, the conservative safety margin is determined using the following confidence level formula: .
[0118] In the formula, For the first Conservative safety margins for each failure mode at the confidence level. For the corresponding confidence level Standard normal quantiles It is a diagonal matrix composed of the squares of the elements of the state estimation error boundary vector; the second state condition includes one or both of the following: the observation noise follows a known probability distribution, and the error correlation between state variables is lower than a preset threshold.
[0119] As one implementation method, the coupling correction module 230 is specifically used to: calculate the real-time correlation coefficient between any two failure modes based on the safety margin time series of different failure modes, as a coupling correlation parameter; when the safety margin of the first failure mode decreases, reduce the conservative safety margin of the second failure mode that is positively correlated with the first failure mode proportionally based on the real-time correlation coefficient, to obtain the corrected safety margin.
[0120] As one implementation method, the calculation formula for the coupling correction of the safety margin coupling by the coupling correction module 230 is as follows: .
[0121] In the formula, For the first The corrected safety margin after coupling correction for each failure mode. For the first Conservative safety margin for each failure mode The coupling reduction factor is calculated using the following formula: .
[0122] In the formula, This is the coupling strength coefficient, used to adjust the overall sensitivity of the coupling correction. Failure mode and Real-time correlation coefficient between them; Failure mode The reference margin level is usually taken as the safety margin value of the initial assembly state; Failure mode The current security margin; the construction conditions for the state-space security domain are: .
[0123] In the formula, For state-space safe domain, Let be the state vector in the state space. Failure mode constraint functions, The risk reduction amount is determined by the state estimation error bound. For the first Corrected safety margins for various failure modes For the first Conservative safety margin for each failure mode This represents the total number of failure modes.
[0124] In one implementation, the device is also used to: acquire gradient information of the corrected safety margin with respect to the control action; and select, from the set of feasible control actions, the control action that maximizes the gradient information that minimizes all failure modes as the recommended control instruction.
[0125] In one implementation, the device is also used to: set a soft warning threshold and a hard red line threshold for the conservative safety margin of each failure mode, wherein the soft warning threshold is greater than the hard red line threshold; when the conservative safety margin reaches the soft warning threshold, trigger a warning and output a recommended control command; and when the conservative safety margin reaches the hard red line threshold, trigger an emergency shutdown protection.
[0126] In one implementation, the device is also used to: after the equipment assembly process is completed, acquire the measured values of the failure modes and the target state estimate of the final assembly state; based on the deviation between the measured values and the target state estimate after mapping by a performance function, and combined with a preset learning rate, iteratively update the limit threshold parameters of the failure modes to reduce the state estimation error bound; the calculation formula for the iterative update is: .
[0127] In the formula, For the first The first update after the second assembly The limit threshold parameters for each failure mode For the first Limit threshold parameters during the second assembly. To preset the learning rate, For the first Measured values from the second assembly For the first The target state estimate of the final state of the second assembly is obtained by the first... Performance function of various failure modes The output after mapping.
[0128] Regarding the apparatus in the above embodiments, the specific manner in which each unit module performs its operations has been described in detail in the embodiments related to the method, and will not be elaborated upon here.
[0129] This embodiment provides a device assembly system, which is a concrete implementation of the aforementioned method embodiments at the physical hardware level, designed to provide end-to-end real-time safety monitoring capabilities for the device assembly process. The device assembly system includes a multi-channel sensing unit and a controller.
[0130] Figure 3 This is a schematic diagram of a controller provided in this application. (For example...) Figure 3The controller 70 may include at least one first processor 701 and a memory 703 for storing processor-executable instructions. The first processor 701 is configured to execute instructions in the memory 703 to implement the security domain determination method for the device assembly process in the following embodiments.
[0131] In addition, the controller 70 may also include a communication bus 702, at least one communication interface 704, an input device 706, and an output device 705.
[0132] The first processor 701 may be a processor (central processing unit, CPU), a microprocessor unit, an ASIC, or one or more integrated circuits for controlling the execution of programs according to the present application.
[0133] The communication bus 702 may include a path for transmitting information between the aforementioned components.
[0134] The communication interface 704 uses any transceiver-like device for communicating with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area networks (WLAN), etc.
[0135] Input device 706 is used to receive input signals and output device 705 is used to output signals.
[0136] The memory 703 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital versatile optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. The memory may exist independently and be connected to the processing unit via a bus. The memory may also be integrated with the processing unit.
[0137] The memory 703 stores instructions for executing the scheme of this application, and the execution is controlled by the first processor 701. The first processor 701 executes the instructions stored in the memory 703 to realize the functions of the method of this application.
[0138] In a specific implementation, as one example, the first processor 701 may include one or more CPUs, for example... Figure 3 CPU0 and CPU1 in the CPU.
[0139] In a specific implementation, as one example, the controller 70 may include multiple processors, such as... Figure 3 The first processor 701 and the second processor 707 are described. Each of these processors may be a single-core processor or a multi-core processor. A processor here may refer to one or more devices, circuits, and / or processing cores used to process data (such as computer program instructions).
[0140] The controller is as follows Figure 3 The diagram shows a first processor 701 and a memory 703 for storing executable instructions of the first processor 701. The first processor 701 is configured to execute the executable instructions to implement a security domain determination method for a device assembly process as described in any of the possible embodiments above. Since the same technical effects can be achieved, further details are omitted here to avoid repetition.
[0141] This application also provides a computer-readable storage medium, which, when executed by a processor of a device assembly process security domain determination device or electronic device, enables the device assembly process security domain determination device or electronic device to perform the device assembly process security domain determination method as described in any of the above possible embodiments. And it achieves the same technical effect; to avoid repetition, it will not be described again here.
[0142] This application also provides a computer program product, including a computer program or instructions, which are executed by a processor as a security domain determination method for a device assembly process as described in any of the possible embodiments above. Since it achieves the same technical effects, it will not be repeated here to avoid repetition.
[0143] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0144] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope.
Claims
1. A method for determining the safety domain in an equipment assembly process, characterized in that, The method includes: The multi-channel observation signals during the equipment assembly process are acquired, and the target state that cannot be directly observed is inverted and estimated based on the multi-channel observation signals to obtain the target state estimate and the corresponding state estimation error bound; the state estimation error bound represents the maximum possible deviation between the target state estimate and the true target state during the inversion estimation process. Based on the target state estimate, the nominal safety margins of various failure modes are determined, and the nominal safety margins are reduced using the state estimation error bound to obtain the conservative safety margins of each failure mode. Obtain coupling correlation parameters among multiple failure modes, and perform linkage correction on the conservative safety margin based on the coupling correlation parameters to obtain the corrected safety margin; Based on the modified safety margin, a state-space safety domain that satisfies all the failure mode constraints is determined.
2. The method according to claim 1, characterized in that, The process of inverting and estimating the target state that cannot be directly observed based on the multi-channel observation signals to obtain the target state estimate and the corresponding state estimation error bound includes: The target state estimate is determined based on the state estimation function and the multi-channel observation signal; The state estimation error bound is determined based on the observation noise of the multi-channel observation signal, the inversion model error, and the partial derivative of the state estimation function with respect to the multi-channel observation signal; the partial derivative characterizes the sensitivity of the state estimation function to the multi-channel observation signal. The step of reducing the nominal safety margin using the state estimation error bound to obtain the conservative safety margin for each failure mode includes: Based on the state estimation error bound and the gradient of the constraint function of the failure mode with respect to the target state, the risk reduction amount is determined, and the risk reduction amount is subtracted from the nominal safety margin to obtain the conservative safety margin, wherein the gradient characterizes the sensitivity of the constraint function to each state variable.
3. The method according to claim 2, characterized in that, The step of reducing the nominal safety margin using the state estimation error bound to obtain the conservative safety margin for each failure mode includes: When the state variables of the target state satisfy the first state condition, the conservative safety margin is determined using the following worst-case algorithm formula: ; in, For the first Conservative safety margin for each failure mode in the worst-case scenario. For the nominal safety margin, For the first Constraint functions for various failure modes Regarding the target state vector The target state estimate The gradient vector at that point, Let be the state estimation error bound vector. This indicates that the absolute value of each element of the vector is taken and then transposed; the first state condition includes one or two of the following: the distribution of the observation noise is uncertain, and the superposition degree of the error between any two state variables is greater than the preset superposition degree; When the state variables of the target state satisfy the second state condition, the conservative safety margin is determined using the following confidence level formula: ; in, For the first Conservative safety margins for each failure mode at the confidence level. For the corresponding confidence level Standard normal quantiles The second state condition is a diagonal matrix composed of the squares of the elements of the state estimation error boundary vector. The second state condition includes one or both of the following: the observation noise follows a known probability distribution, and the error correlation between state variables is lower than a preset threshold.
4. The method according to claim 1, characterized in that, The step of obtaining coupling correlation parameters between multiple failure modes and performing a linked correction on the conservative safety margin based on the coupling correlation parameters to obtain a corrected safety margin includes: Based on the safety margin time series of different failure modes, calculate the real-time correlation coefficient between any two failure modes as the coupling correlation parameter. When the safety margin of the first failure mode decreases, the conservative safety margin of the second failure mode, which is positively correlated with the first failure mode, is proportionally reduced based on the real-time correlation coefficient to obtain the corrected safety margin.
5. The method according to claim 4, characterized in that, Based on the real-time correlation coefficient, the conservative safety margin of the second failure mode, which is positively correlated with the first failure mode, is proportionally reduced to obtain the corrected safety margin. The formula for calculating the corrected safety margin is as follows: ; in, For the first The corrected safety margin after coupling correction of the failure modes, For the first The conservative safety margin for each failure mode, This is the coupling reduction factor; The formula for calculating the coupling reduction factor is as follows: ; in, The coupling strength coefficient is... Failure mode and The real-time correlation coefficient between them Failure mode The reference margin level, Failure mode The current safety margin; Furthermore, the state-space safety domain that satisfies all failure mode constraints, based on the modified safety margin, is obtained by the construction conditions of the state-space safety domain expressed by the following formula; ; in, This is the state space security domain. Let be the state vector in the state space. Failure mode constraint functions, The risk reduction amount is determined by the state estimation error bound. For the first The corrected safety margin for each failure mode, For the first The conservative safety margin for each failure mode, This represents the total number of failure modes.
6. The method according to claim 5, characterized in that, The method further includes: Obtain the gradient information of the corrected safety margin with respect to the control action; From the set of feasible control actions, the control action that maximizes the gradient information that minimizes all the failure modes is selected as the recommended control instruction.
7. The method according to claim 6, characterized in that, The method further includes: A soft warning threshold and a hard red line threshold are set for the conservative safety margin of each failure mode, wherein the soft warning threshold is greater than the hard red line threshold; When the conservative safety margin reaches the soft warning threshold, an early warning is triggered and the recommended control command is output. When the conservative safety margin reaches the hard red line threshold, emergency shutdown protection is triggered.
8. The method according to claim 7, characterized in that, The method further includes: After the equipment assembly process is completed, the measured values of the failure modes and the estimated values of the target state at the final assembly state are obtained. Based on the deviation between the measured value and the target state estimate after mapping by the performance function, and combined with the preset learning rate, the limit threshold parameter of the failure mode is iteratively updated to narrow the state estimation error bound. The calculation formula for the iterative update is: ; in, For the first The first update after the second assembly The limit threshold parameters for each failure mode For the first Limit threshold parameters during the second assembly. The preset learning rate, For the first Measured values from the second assembly For the first The target state estimate of the final state of the second assembly is obtained by the first... Performance function of various failure modes The output after mapping.
9. A safety domain determination device for equipment assembly process, characterized in that, The apparatus employs the method as described in any one of claims 1 to 8, the apparatus comprising: The state inversion module is used to acquire multi-channel observation signals during the equipment assembly process, and to perform inversion estimation on the target state that cannot be directly observed based on the multi-channel observation signals, so as to obtain the target state estimate and the corresponding state estimation error bound. The margin calculation module is used to determine the nominal safety margin of each of the various failure modes based on the target state estimate, and to reduce the nominal safety margin using the state estimation error bound to obtain the conservative safety margin of each failure mode. The coupling correction module is used to obtain coupling correlation parameters between multiple failure modes, and to perform linkage correction on the conservative safety margin based on the coupling correlation parameters to obtain the corrected safety margin. The security domain construction module is used to construct a state-space security domain that satisfies all the failure mode constraints based on the modified security margin.
10. An equipment assembly system, characterized in that, include: A multi-channel sensing unit is configured to acquire multi-channel observation signals during the equipment assembly process; A controller, communicatively connected to the multi-channel sensing unit, is configured to perform a security domain determination method for the equipment assembly process as described in any one of claims 1 to 8.