Method, system, device, and medium for dynamic intelligent safety railway controlling
The multi-agent railway control system addresses safety and regulatory challenges by integrating AI with SIL4-certifiable architecture, ensuring real-time adaptability and cost reductions through dynamic configuration management and transparent decision-making.
Patent Information
- Authority / Receiving Office
- HK · HK
- Patent Type
- Applications
- Current Assignee / Owner
- SIEMENS MOBILITY LIMITED
- Filing Date
- 2026-03-11
- Publication Date
- 2026-07-17
Smart Images

Figure 00000027_0000 
Figure 00000028_0000 
Figure 00000029_0000
Abstract
Description
1 METHOD, SYSTEM, DEVICE, AND MEDIUM FOR DYNAMIC INTELLIGENT SAFETY RAILWAY CONTROLLING TECHNICAL FIELD The present disclosure relates generally to railway transportation control systems, and particularly to intelligent safety control systems for railway operations using multi-objective optimization algorithms. BACKGROUND Railway control systems play a critical role in ensuring safe and efficient transportation operations. Traditional railway control systems typically rely on static scheduling and rule-based control mechanisms to manage train movements, resource allocation, and safety protocols. With the advancement of artificial intelligence and machine learning technologies, there has been growing interest in applying these technologies to railway control systems. However, conventional AI and ML approaches often prioritize operational efficiency and optimization objectives without adequately addressing the stringent safety requirements inherent in railway operations. Current AI-based railway control solutions face significant challenges in meeting safety-critical requirements. Many machine learning algorithms operate as "black boxes" with limited interpretability, making it difficult to ensure compliance with railway safety standards. Additionally, these systems may not provide sufficient real-time safety assurance when dealing with dynamic operational conditions such as varying passenger demand, unexpected delays, equipment failures, and changing environmental factors. There exists a need for intelligent railway control systems that can integrate artificial intelligence capabilities while maintaining strict safety standards, providing dynamic adaptation to changing conditions, and ensuring transparent and verifiable safety decision-making through advanced multi-objective optimization algorithms. SUMMARY To solve above listed problems, embodiments of the present disclosure propose a method, apparatus, system, electronic device and medium for dynamic intelligent safety railway controlling. HK 20135247 A 2 In a first aspect, a method for controlling railway operations using a multi-agent decision process with integrated neural network training is provided. The method comprises: generating multiple candidate route and train configuration allocations by a neural network generator, wherein the neural network generator has been pre-trained using operational SIL4 safety supervision; validating each candidate allocation by a SIL4 safety checker against deterministic formally verified safety rules to produce validated safe candidates, wherein the SIL4 safety checker is positioned logically between the neural network generator and optimization; optimizing selection of an optimal allocation by a multi-objective optimizer from the validated safe candidates by evaluating multiple operational objectives including configuration efficiency; executing the selected optimal allocation including autonomous coupling and decoupling operations under SIL4 supervision; collecting performance feedback from the execution including configuration performance metrics; updating the neural network generator through reinforcement learning using the collected performance feedback; and recording all decision stages in a distributed ledger with cryptographic signatures for regulatory transparency. With integrating AI within SIL4-certifiable architecture, the disclosure provides advantages over known solutions: the AI optimization capabilities can be deployed in safety-critical railway operations while maintaining CENELEC certification requirements. The novel architectural separation enables neural network learning while preserving deterministic safety validation. The system eliminates the traditional conflict between AI optimization and safety compliance that has prevented AI deployment in critical railway infrastructure. According to embodiments of the disclosure, the neural network generator is pre-trained using operational SIL4 safety checkers and multi-objective optimizers as training supervisors to teach safety-compliant allocation generation. With such embodiments, the neural network learns to internalize safety constraints during training, dramatically reducing safety validation rejections during operational deployment. The training pipeline establishes a bridge between AI learning capabilities and safety-critical system requirements. HK 20135247 A 3 According to embodiments of the disclosure, the method further comprises implementing autonomous coupling and decoupling operations including SIL4-supervised mechanical engagement, electrical connection, pneumatic connection, and passenger gangway management. Such dynamic configuration management enables real-time capacity optimization based on demand patterns while maintaining full safety supervision throughout all configuration changes. According to embodiments of the disclosure, wherein collecting performance feedback comprises analyzing actual coupling success rates, energy efficiency gains, capacity utilization improvements, and safety compliance metrics, wherein the performance feedback is processed by reinforcement learning algorithms to continuously improve neural network decision-making capabilities. In particular, large negative rewards are applied for candidates rejected by the SIL4 safety checker, effectively teaching the neural network the boundaries of safety constraints. The method according to embodiments further comprises transmitting operational metrics in real-time to enterprise business systems and receiving dynamic optimization weight adjustments based on business conditions. This allows the system to adapt to external factors such as energy price spikes or strategic business shifts by automatically adjusting the priority of optimization objectives. The method according to embodiments further comprises implementing prescriptive maintenance integration where component health predictions are coordinated with configuration management to enable individual unit servicing without complete service disruption. Specifically, degraded units can be decoupled for maintenance while healthy units continue operation, optimizing asset availability. By providing cryptographically verifiable audit trails, embodiments of the disclosure enable the foundation for regulatory-compliant AI deployment in critical infrastructure: the distributed ledger records complete decision chains enabling post-hoc explainability for neural network decisions while maintaining tamper-proof transparency through Byzantine fault-tolerant consensus. The multi-agent architecture enables unprecedented integration of fragmented railway subsystems. Traditional systems requiring 10+ separate subsystems with complex interfaces are unified into cooperative intelligent agents. The Central Agent integrates Operations Control Centre functionality, Automatic Train Supervision, demand responsive transport, timetable planning, revenue management, SCADA supervision, power optimization, interlocking safety, radio block control, and predictive maintenance analytics into one intelligent orchestration HK 20135247 A 4 layer. The disclosure provides not only operational optimization but also revolutionary safety integration allowing AI deployment in SIL4 environments previously prohibited by regulatory frameworks. The system enables 15-25% operational cost reduction, 25-40% energy consumption reduction, and 30-40% maintenance cost reduction while achieving industry-first SIL4-certified AI integration. In a second aspect, a method for training a neural network for railway allocation generation using operational safety supervision is provided. In a third aspect, a multi-agent railway control system is provided. In a fourth aspect, an electronic device is provided. In a fifth aspect, a computer-readable medium is provided. In a sixth aspect, a computer program product is provided.. Additional technical features and benefits may be realized through the techniques of the present disclosure. Embodiments and aspects of the disclosure are described in detail herein and are considered a part of the claimed subject matter. For a better understanding, refer to the detailed description and to the drawings. BRIEF DESCRIPTION OF THE DRAWINGS In order to make technical solutions of examples of the present disclosure clearer, accompanying drawings to be used in description of the examples will be simply introduced hereinafter. Obviously, the accompanying drawings to be described hereinafter are only some examples of the present disclosure. Those skilled in the art may obtain other drawings according to these accompanying drawings without creative labor. FIG. 1 illustrates a block diagram of a multi-agent railway control system including central agents, train agents, track agents, and distributed ledger components for dynamic intelligent safety railway controlling according to embodiments of the present disclosure. FIG. 2 illustrates a flowchart showing the six-stage central agent decision process including neural network generation, SIL4 safety checking, and multi-objective optimization for railway operations control according to embodiments of the present disclosure. FIG. 3 illustrates a flowchart showing the neural network pre-training process using operational safety HK 20135247 A 5 supervision for railway allocation generation according to embodiments of the present disclosure. FIG. 4 illustrates a flowchart showing the dynamic train configuration process including autonomous coupling and decoupling operations for demand-responsive railway operations according to embodiments of the present disclosure. FIG. 5 is a schematic diagram of electronic device according to embodiments of the present disclosure. List of reference numbers: Reference Numbers Meanings S210~S260 Controlling railway operations steps S310~S360 Neural network pre-training process steps S410~S460 Dynamic train configuration process steps 100 Multi-agent railway control system 110 Central Agent 112 Neural network generator 120 Maintenance Planner 130 Train Agents 140 Track Agents 150 Passenger Agents 160 Service Agents 170 Recorder Agents 172 Distributed ledger nodes 200 Method for controlling railway operations 600 Electronic device 601 Processor 602 Memory DETAILED DESCRIPTION In order to make the purpose, technical scheme and advantages of the disclosure clearer, the following examples are given to further explain the disclosure in detail. In order to be concise and intuitive in description, the scheme of the disclosure is described below by describing several representative embodiments. Many details in the embodiments are only used to help understand the scheme of the disclosure. However, it is obvious that the technical scheme of the disclosure can be realized without being limited to these details. In order to avoid unnecessarily blurring the scheme of the disclosure, some embodiments are not described in detail, but only the framework is given. Hereinafter, "including" refers to HK 20135247 A 6 "including but not limited to", "according to..." refers to "at least according to..., but not limited to...". Due to the language habits, when the number of an element is not specifically indicated below, it means that the element can be one or more, or can be understood as at least one. The present disclosure addresses fundamental technical challenges in modern railway operations where increasing traffic density, passenger expectations for reliability, and regulatory requirements for safety create complex optimization problems that traditional static control systems cannot adequately solve. Current railway control architectures suffer from architectural fragmentation requiring integration of 10+ separate subsystems including Operations Control Centre, Automatic Train Supervision, demand responsive transport, timetable planning, revenue management, SCADA supervision, power optimization, interlocking safety, radio block control, and predictive maintenance analytics. Traditional approaches face several critical limitations that prevent optimal system performance. First, safety regulatory frameworks for deploying AI optimization in safety-critical railway operations, as neural networks cannot easily achieve SIL4 certification required for critical safety functions. Second, conventional systems optimize single objectives rather than multiple competing objectives simultaneously, leading to suboptimal overall performance. Third, existing systems lack real-time adaptability to changing operational conditions such as demand fluctuations, equipment degradation, and environmental factors. The technical solution disclosed herein provides a novel multi-agent architecture that integrates machine learning optimization within SIL4-certifiable safety frameworks while maintaining complete regulatory transparency through blockchain audit trails. The core innovation involves architectural separation that enables AI optimization to operate within safety constraints without compromising the deterministic nature required for safety certification. System Architecture Overview As shown in FIG. 1, the multi-agent railway control system 100 comprises several interconnected intelligent agents that cooperatively manage railway operations while maintaining strict safety and regulatory compliance. The system architecture represents a paradigmatic shift from traditional monolithic control systems to a distributed intelligent architecture capable of real-time optimization across multiple objectives. The Central Agent 110 serves as the primary orchestration component implementing a sophisticated six-stage decision process that integrates neural network-based allocation generation within a SIL4-certifiable safety HK 20135247 A 7 framework. The Central Agent 110 comprises six key subsystems that work in coordinated sequence to generate, validate, and implement optimal operational decisions. Within the Central Agent 110, the neural network generator operates at SIL1 and employs deep reinforcement learning algorithms to generate multiple candidate route and train configuration allocations. The neural network architecture comprises multiple layers of interconnected nodes trained using operational data including historical demand patterns, asset performance metrics, energy consumption profiles, and maintenance schedules. The generator has been specifically pre-trained using operational SIL4 safety checkers and multi-objective optimizers as training supervisors, enabling it to learn safety-compliant behavior during the training phase rather than relying solely on external safety validation. The SIL4 safety checker represents a critical innovation positioned between the neural network generator and optimization processes. Operating at Safety Integrity Level 4 according to CENELEC EN 50128 standards, the safety checker implements formally verified safety rules including collision avoidance algorithms, speed limit enforcement, signal compliance verification, route conflict detection, minimal headway calculations, platform conflict prevention, geometric constraint validation, weather condition assessment, coupling / decoupling safety protocols, train composition limits, capacity-demand safety boundaries, and energy constraint verification. The safety checker employs mathematical proof techniques and model checking to ensure that all safety validations are deterministic and verifiable. The multi-objective optimizer evaluates validated safe candidates across seven weighted operational objectives. Demand response optimization minimizes passenger wait times and maximizes service quality through dynamic scheduling adjustments. Profitability optimization integrates dynamic pricing models with operational costs to maximize revenue while maintaining service quality. Asset utilization optimization ensures efficient use of rolling stock and infrastructure while considering maintenance requirements and equipment lifecycle management. Energy efficiency optimization reduces total system consumption while accounting for configuration-dependent efficiency gains from coupled operations. Maintenance preservation optimization extends equipment life by favoring allocations that reduce wear on assets with lower remaining useful life. Business target alignment integrates corporate KPIs and strategic objectives received from ERP systems. Configuration efficiency optimization maximizes capacity-demand matching through intelligent train coupling and decoupling strategies. The execution module implements selected optimal allocations while establishing comprehensive feedback loops for continuous system improvement. The module generates cryptographically signed control instructions for Train HK 20135247 A 8 Agents 130 and Track Agents 140, monitors actual execution performance against predicted outcomes, and collects detailed performance metrics including actual departure times, journey durations, energy consumption profiles, coupling / decoupling operation times, passenger satisfaction indicators, and safety compliance metrics. These metrics are processed through reinforcement learning algorithms that continuously update the neural network generator, creating a self-optimizing system that improves performance over time while maintaining safety guarantees. The prescriptive maintenance planner 120 integrates predictive maintenance algorithms with operational optimization to minimize service disruptions while maximizing asset availability. The planner receives component health predictions from Train Agents 130 and Track Agents 140, processes degradation models to forecast maintenance windows, and coordinates maintenance scheduling with operational planning to optimize resource utilization. The ERP interface provides bidirectional integration with enterprise business systems, enabling dynamic adjustment of optimization weights based on real-time business conditions, energy pricing fluctuations, carbon cost considerations, and evolving regulatory requirements. Train Agent Architecture The Train Agents 130 provide autonomous onboard intelligence with sophisticated health monitoring and operational optimization capabilities. Each Train Agent 130 operates as an intelligent autonomous system capable of local decision-making while coordinating with the broader multi-agent architecture. The movement authority execution capabilities operate at SIL4 to ensure safety-critical train control functions meet the highest safety standards. These capabilities include precise speed control, automatic train protection, emergency braking systems, and movement authority compliance verification. Local autonomous optimization operates at SIL1 to provide energy efficiency improvements and passenger comfort enhancement through intelligent acceleration profiles, dynamic braking optimization, and climate control management based on passenger loading and external conditions. Health monitoring and prediction systems employ machine learning models to continuously assess component condition and predict remaining useful life. Sensors monitor critical subsystems including traction motors, braking systems, door mechanisms, HVAC systems, and onboard computers. Machine learning algorithms process sensor HK 20135247 A 9 data to identify degradation patterns and predict component failures, enabling proactive maintenance scheduling. The autonomous coupling / decoupling control logic represents a significant innovation enabling dynamic train configuration management under full SIL4 supervision. The system manages precise positioning control with maximum approach speeds of 5 km / h during coupling operations, mechanical coupling engagement with force sensors and position verification systems, electrical and pneumatic connection establishment with comprehensive system testing protocols, passenger gangway deployment and retraction with safety sensors, and post-operation verification including brake system testing, communication verification, and consist integrity confirmation. Track Agent Integration Track Agents 140 provide intelligent trackside control with comprehensive infrastructure health monitoring. The wayside object control systems operate at SIL4 for safety-critical infrastructure including point machines, signals, track circuits, axle counters, and route setting systems. Infrastructure health prediction capabilities employ machine learning algorithms to process sensor data from track monitoring systems, point machines, signal equipment, and power supply systems to forecast component degradation and predict maintenance requirements. Dynamic availability reporting integrates predicted maintenance windows with operational planning to optimize infrastructure utilization. Passenger and Service Agent Coordination Passenger Agents 150 provide sophisticated multi-modal passenger interface capabilities with real-time optimization. Transport request handling processes passenger journey requests and integrates them with system capacity planning. Real-time journey optimization adapts to dynamic operational changes, service disruptions, and capacity constraints while providing passengers with updated travel information. Service Agents 160 revolutionize maintenance operations through AI-powered automation. Maintenance request processing receives and prioritizes maintenance needs based on operational impact and resource availability. AI-powered work order generation employs generative AI to create detailed maintenance instructions, parts lists, and safety protocols customized for specific maintenance tasks. Resource coordination optimizes depot scheduling, crew management, and parts availability to minimize service impact. Blockchain Transparency Architecture Recorder Agents 170 implement enterprise-grade blockchain functionality providing cryptographic transparency HK 20135247 A 10 and regulatory compliance for all autonomous decisions. The distributed ledger architecture comprises multiple nodes implementing Byzantine Fault Tolerant consensus algorithms ensuring system integrity even with node failures or malicious actors. Cryptographic signature verification ensures all agent decisions are tamper-proof and verifiable. Audit trail capabilities enable complete decision chain reconstruction for regulatory compliance, post-incident analysis, and system optimization. Central Agent Decision Process As shown in FIG. 2, the Central Agent implements a sophisticated six-stage decision process that represents the core innovation enabling AI optimization within safety-critical railway operations. This process executes continuously with decision cycles typically completing within seconds to ensure real-time responsiveness. Stage 1: Generation (S210) begins with the neural network generator analyzing current system state including transport demand patterns derived from passenger journey requests and boarding data, station occupancy sensors, special event forecasts, and weather data. Train agent status encompasses real-time position data, equipment health indicators, passenger loading, energy consumption, and coupling compatibility matrices. Track agent status includes infrastructure availability, maintenance windows, signal states, and capacity constraints. Environmental data incorporates weather conditions, energy pricing, carbon costs, and regulatory constraints. The neural network processes this multidimensional input space to generate multiple candidate allocations. Each candidate represents a complete operational plan including route assignments, train configurations, coupling / decoupling operations, timing constraints, and resource allocations. The neural network has been trained to generate diverse candidates exploring different regions of the optimization space while favoring solutions likely to pass safety validation. Stage 2: Safety Checking (S220) implements comprehensive SIL4 validation of all generated candidates. The safety checker applies formally verified safety rules including collision avoidance algorithms that ensure minimum separation distances between trains, speed limit compliance verification that checks all route segments against infrastructure constraints, signal compliance confirmation that validates all movement authorities, route conflict detection that prevents conflicting train movements, minimal headway enforcement that maintains safe following distances, platform conflict prevention that ensures adequate passenger safety clearances, geometric constraint verification that confirms train compositions can navigate all route segments, weather condition assessment that adjusts safety parameters for environmental conditions, coupling / decoupling safety validation that HK 20135247 A 11 verifies mechanical compatibility and operational feasibility, train composition limits that ensure platform length compliance, capacity-demand safety limits that prevent overcrowding beyond safe thresholds, and energy constraint verification that confirms adequate power supply availability. Candidates failing any safety validation are immediately rejected, ensuring that only provably safe allocations proceed to optimization. This architectural separation is crucial for maintaining SIL4 certification while enabling AI optimization. Stage 3: Optimization (S230) employs advanced multi-objective optimization algorithms to evaluate safe candidates across multiple competing objectives. The optimizer implements Non-dominated Sorting Genetic Algorithm II (NSGA-II) enhanced with problem-specific operators designed for railway allocation problems. The seven optimization objectives are dynamically weighted based on operational conditions and business priorities. Demand response optimization employs predictive algorithms to minimize passenger wait times while maximizing service quality. The objective function incorporates passenger arrival patterns, journey time preferences, and service frequency requirements to optimize passenger satisfaction metrics. Profitability optimization integrates dynamic pricing models with operational cost calculations. The system considers energy costs, crew costs, maintenance implications, and revenue optimization through demand-responsive pricing strategies. Real-time energy pricing and carbon cost fluctuations are incorporated to optimize financial performance. Asset utilization optimization ensures efficient use of rolling stock and infrastructure while considering maintenance schedules and equipment lifecycle management. The system balances asset productivity with maintenance requirements to maximize long-term asset value. Energy efficiency optimization reduces total system consumption while accounting for the complex relationships between train configurations, operational patterns, and energy consumption. Coupled operations typically achieve 15-25% energy savings compared to individual unit operations, but require careful optimization of coupling timing and route assignment. Maintenance preservation optimization extends equipment life by preferentially assigning assets with higher remaining useful life to demanding operations while scheduling maintenance-intensive operations for assets approaching maintenance windows. HK 20135247 A 12 Business target alignment integrates strategic objectives received from ERP systems including customer satisfaction targets, environmental goals, financial targets, and operational KPIs. The weighting of this objective adjusts dynamically based on current business priorities and performance against targets. Configuration efficiency optimization maximizes the match between passenger demand and train capacity through intelligent coupling and decoupling operations. The system considers passenger flow patterns, station dwell times, and operational constraints to optimize capacity utilization. Stage 4: Execution and Feedback (S240) ~ (S250) implements the selected optimal allocation while establishing comprehensive performance monitoring. The execution module generates detailed control instructions for all system agents, monitors execution progress in real-time, and collects performance feedback for continuous system improvement. Control instruction generation creates cryptographically signed commands specifying precise timing, routing, configuration changes, and coordination requirements. Instructions are transmitted to Train Agents 130 for movement authority execution and configuration changes, and to Track Agents 140 for infrastructure coordination. Performance monitoring tracks actual execution against predicted performance across multiple metrics. Timing accuracy measures adherence to planned schedules with typical accuracy within 30 seconds for normal operations. Energy consumption monitoring compares actual consumption against predicted values, enabling continuous refinement of energy efficiency models. Coupling operation performance tracks success rates, timing accuracy, and passenger impact metrics for configuration changes. Safety compliance monitoring ensures all operations maintain required safety margins and regulatory compliance. Reinforcement learning feedback processes collected performance metrics to compute rewards that update the neural network generator(S260). Positive rewards reinforce successful allocation strategies while negative rewards discourage unsuccessful approaches. The reward function balances multiple objectives while heavily weighting safety compliance and passenger service quality. Stage 5: Prescriptive Maintenance Planning integrates predicted health of assets with LLM generated maintenance instructions. The maintenance planner 120 processes component health predictions from Train Agents 130 and Track Agents 140 to identify optimal maintenance windows. HK 20135247 A 13 Component health analysis employs machine learning models processing sensor data to predict remaining useful life for critical components including traction motors, braking systems, door mechanisms, point machines, signal equipment, and track infrastructure. Degradation models incorporate operational history, environmental factors, and manufacturer specifications to forecast maintenance requirements. Maintenance window optimization coordinates predicted maintenance needs with operational planning to minimize passenger impact. The system identifies opportunities for maintenance during natural service gaps, coordinates multiple maintenance activities to maximize efficiency, and integrates configuration management to enable individual unit servicing without complete service disruption. Maintenance request generation creates detailed work orders for Service Agents 160 including component specifications, required parts, safety protocols, and scheduling constraints. AI-powered work order generation employs natural language processing and knowledge management systems to create comprehensive maintenance instructions tailored to specific equipment and operational context. Stage 6: ERP Integration provides dynamic business integration enabling real-time alignment between operational optimization and business objectives. The ERP interface maintains bidirectional communication with enterprise systems to ensure operational decisions support broader business goals. Business metrics reporting transmits operational performance data to enterprise systems including punctuality metrics, energy consumption, asset utilization, passenger satisfaction scores, and financial performance indicators. Data integration enables enterprise-level analytics and strategic planning based on real-time operational performance. Dynamic objective weighting receives business priority updates that adjust optimization parameters based on changing market conditions, regulatory requirements, financial targets, and strategic initiatives. For example, during carbon pricing fluctuations, energy efficiency weighting may be increased. During high-demand periods, profitability optimization may receive higher priority. Strategic planning integration enables long-term capacity planning and investment decisions based on operational analytics and performance trends identified through the multi-agent system's continuous operation. Neural Network Training Methodology As shown in FIG. 3, the neural network training process represents a breakthrough in safety-critical AI HK 20135247 A 14 development by employing operational safety systems as training supervisors. This approach enables the neural network to learn safety-compliant behavior during training rather than relying solely on external validation during operation. The neural network training employs Monte Carlo simulation-based self-play learning methodology that enables the neural network to develop optimal allocation strategies through systematic trial-and-error exploration rather than supervised learning from historical operational data. This approach allows the system to discover novel optimization strategies without being constrained by previous operational limitations. The Monte Carlo Tree Search implementation comprises state-space exploration through self-play simulation, neural network policy guidance for candidate generation, value estimation for long-term allocation consequences, and configuration-aware planning including coupling and decoupling strategies. The exploration strategies include epsilon-greedy exploration with initial epsilon value of 0.3 decaying to 0.05, confidence-based exploration balancing exploitation and exploration, novelty-based exploration encouraging diverse strategy discovery, and safety boundary exploration teaching precise constraint margins. The training process executes thousands of simulation iterations, enabling the neural network to develop sophisticated allocation strategies while maintaining safety compliance under operational safety checker supervision. This methodology ensures the neural network learns to generate candidates that consistently pass safety validation while optimizing multiple operational objectives. Training Environment Establishment (S310) configures operational SIL4 safety checking systems and multi-objective optimization systems to serve as training supervisors. This novel approach ensures continuity between training and operational environments, dramatically improving the reliability of neural network performance in operational deployment. The training environment shall not incorporate historical operational data spanning multiple years of railway operations including demand patterns, weather conditions, equipment performance, maintenance schedules, and incident reports. Synthetic scenario generation augments historical data with edge cases and rare operational conditions to ensure robust neural network performance across diverse situations. Training Pipeline Implementation (S320) establishes systematic processes for neural network learning using operational systems as supervisors. The neural network generates candidate allocations that are systematically evaluated by the same safety checking and optimization systems used in operational deployment. HK 20135247 A 15 The training pipeline implements curriculum learning strategies that gradually increase problem complexity as the neural network develops competency. Initial training focuses on simple operational scenarios with limited constraints. As the neural network demonstrates consistent safety compliance, training scenarios incorporate increasing complexity including multi-train operations, complex routing, configuration changes, and dynamic operational constraints. Safety-Aware Learning (S330) employs reinforcement learning algorithms specifically adapted for safety-critical applications. The reward function heavily weights safety compliance with large negative rewards applied to candidates rejected by the safety checker. This approach teaches the neural network to avoid unsafe regions of the action space without requiring explicit encoding of safety rules within the neural network architecture. Safety-aware learning employs conservative exploration strategies that limit the neural network's exploration to regions of the action space with high probability of safety compliance. As the neural network demonstrates consistent safety performance, exploration boundaries are gradually expanded to enable discovery of novel optimal solutions. Performance Optimization (S340) refines neural network parameters based on feedback from both safety checking and optimization systems. The training process employs advanced optimization algorithms including Proximal Policy Optimization (PPO) and Trust Region Policy Optimization (TRPO) adapted for the multi-objective optimization environment of railway operations. Performance optimization incorporates domain-specific knowledge including railway engineering principles, operational best practices, and regulatory requirements. This knowledge integration accelerates learning and ensures neural network decisions align with established railway operational principles. Configuration Strategy Development (S350) trains the neural network to develop sophisticated understanding of train coupling and decoupling operations. The neural network learns to identify optimal coupling opportunities during peak demand periods to maximize capacity and energy efficiency, and optimal decoupling timing during off-peak periods to provide operational flexibility and enable maintenance coordination. Configuration learning incorporates complex operational constraints including mechanical compatibility between train units, platform length limitations, crew availability, passenger transfer requirements, and maintenance scheduling. The neural network develops understanding of the interdependencies between configuration decisions and broader operational optimization. HK 20135247 A 16 Operational Integration (S360) validates trained neural network performance within the operational environment while maintaining continuous supervision by the same safety checking and optimization systems used during training. This integration approach ensures seamless transition from training to operational deployment while maintaining safety and performance guarantees. Integration validation includes extensive testing across diverse operational scenarios, performance benchmarking against historical operations, safety compliance verification, and regulatory approval processes required for deployment in safety-critical railway operations. Dynamic Configuration Management As shown in FIG. 4, the dynamic train configuration process enables real-time adaptation of train capacity and operational flexibility through autonomous coupling and decoupling operations. This capability represents a significant advancement in railway operational flexibility while maintaining full safety supervision. The dynamic train configuration process is coordinated by the Central Agent (110) with autonomous execution by Train Agents (130). The process comprises several distinct phases executed by different system components: Central Agent Coordination Phase: Real-time demand analysis (S410) and configuration optimization candidate generation (S420) are performed by the Central Agent neural network generator. SIL4 configuration validation and multi-objective optimization selection (S430) are executed by the Central Agent safety checker and optimizer modules. Train Agent Execution Phase: Autonomous coupling implementation (S440) and autonomous decoupling implementation (S450) are performed by individual Train Agents under SIL4 supervision with comprehensive safety verification and mechanical control. Performance Integration Phase: Performance monitoring and reinforcement learning feedback collection (S460) are processed by the Central Agent to continuously improve configuration strategies and operational efficiency. Real-Time Demand Analysis (S410) continuously monitors passenger demand patterns and system capacity to identify optimization opportunities. Demand monitoring incorporates multiple data sources including passenger boarding and alighting patterns measured through door sensors and platform monitoring systems, station occupancy levels tracked through video analytics and passenger counting systems, special event forecasts integrating calendar data and event management systems, ticket sales patterns indicating future demand trends, HK 20135247 A 17 and real-time passenger flow analysis identifying capacity constraints and optimization opportunities. Demand analysis employs predictive algorithms including time series forecasting, machine learning regression models, and passenger flow simulation to anticipate capacity requirements and identify optimal timing for configuration changes. The system considers passenger comfort, energy efficiency, operational flexibility, and maintenance coordination in configuration optimization decisions. Configuration Optimization (S420) employs the Central Agent neural network generator to produce configuration candidates that optimize multiple competing objectives. Configuration optimization balances capacity-demand matching to minimize overcrowding while avoiding underutilization, energy efficiency gains achieved through coupled operations, operational flexibility provided by decoupled units enabling independent routing and scheduling, and maintenance coordination enabling individual unit servicing without complete service disruption. Configuration candidates specify detailed operational plans including coupling and decoupling locations, timing constraints, unit compatibility requirements, crew coordination needs, and passenger impact mitigation strategies. The optimization process considers complex interdependencies between configuration decisions and broader operational efficiency. SIL4 Configuration Validation (S430) ensures all proposed configuration operations meet stringent safety requirements before implementation. Safety validation includes position verification confirming precise train locations and platform alignment, velocity limits ensuring safe approach speeds typically limited to 5 km / h for coupling operations, mechanical compatibility confirmation verifying coupling system compatibility between units, platform length constraint validation ensuring complete train compositions fit within station platforms, crew availability verification confirming qualified personnel for configuration operations, passenger clearance confirmation ensuring safe passenger conditions during operations, and mechanical system status verification confirming proper operation of coupling systems, brakes, and safety equipment. Configuration validation employs formal verification methods and mathematical proof techniques to ensure safety compliance. All validation processes operate at SIL4 integrity levels providing the highest safety assurance for configuration operations. Autonomous Coupling Implementation (S440) executes coupling operations under comprehensive SIL4 supervision with multiple layers of safety verification and control. Coupling operations begin with precise positioning control where trains approach coupling positions with maximum speeds of 5 km / h under continuous HK 20135247 A 18 monitoring of position accuracy, relative velocity, and alignment parameters. Mechanical coupling engagement employs force sensors and position verification systems to ensure proper coupling mechanism operation. The system monitors coupling forces, position alignment, and mechanical engagement confirmation through multiple sensor systems providing redundant safety verification. Electrical and pneumatic connection establishment includes systematic connection of power systems, communication networks, and pneumatic brake systems. Each connection undergoes comprehensive testing including voltage verification, communication protocol testing, and pneumatic pressure testing to ensure proper system integration. Passenger gangway deployment, where equipped, includes extension of inter-car connections with comprehensive safety monitoring including clearance sensors, deployment force monitoring, and passenger safety verification. Post-coupling verification provides comprehensive system testing including brake system functionality testing across the complete coupled consist, communication system verification ensuring proper operation of train control and passenger information systems, and consist integrity confirmation verifying proper mechanical, electrical, and pneumatic integration. Autonomous Decoupling Implementation (S450) executes separation operations with equivalent safety supervision and verification. Decoupling begins with passenger gangway retraction including clearance sensor verification, retraction force monitoring, and passenger safety confirmation. Pneumatic system isolation includes controlled pressure reduction, system separation verification, and independent system testing for each unit. Electrical disconnection includes systematic shutdown of shared systems, circuit separation verification, and independent electrical system testing. Mechanical release employs controlled separation with position monitoring, force verification, and release mechanism testing. Separation movement includes controlled unit separation with continuous distance monitoring and independent movement authority establishment. Independent unit verification confirms each separated unit maintains full operational capability including brake system functionality testing, communication system verification, and safety system confirmation for independent operation. HK 20135247 A 19 Performance Monitoring and Learning (S460) provides comprehensive tracking of configuration operation success and effectiveness. Performance metrics include coupling success rates typically exceeding 98% for properly maintained systems, timing accuracy with typical coupling operations completing within 3-5 minutes, energy efficiency gains measuring actual consumption improvements from coupled operations, capacity utilization improvements quantifying passenger service enhancements, and operational flexibility benefits measuring service improvement from configuration adaptability. Performance feedback integration employs reinforcement learning algorithms to continuously improve configuration strategies. The system learns optimal coupling timing, identifies successful configuration patterns, and adapts to changing operational conditions and passenger demand patterns. The dynamic configuration capability enables railways to achieve unprecedented operational flexibility while maintaining the highest safety standards. Configuration management integrates seamlessly with the broader multi-agent architecture providing system-wide optimization of passenger service, energy efficiency, and operational effectiveness. The embodiments of the present disclosure may be implemented with any combination of hardware and software. In addition, the embodiments of the present disclosure may be included in an article of manufacture (e.g., one or more computer program products) having, for example, a non-transitory computer-readable storage medium. The computer readable storage medium has embodied therein, for instance, computer readable program instructions for providing and facilitating the mechanisms of the embodiments of the present disclosure. The article of manufacture can be included as part of a computer system or sold separately. Electronic Device Implementation As shown in FIG. 5, the electronic device 600 comprises a processor 601, a memory 602, and a computer program stored in the memory 602 and executable on the processor 601. When the computer program is executed by the processor 601, any one of the above-mentioned methods for dynamic intelligent safety railway controlling is implemented. The memory 602 may specifically be implemented as various storage medium such as Electrically Erasable Programmable Read-Only Memory (EEPROM), Flash memory (Flash memory), Programmable Program Read-Only Memory (PROM). The processor 601 may be implemented to include one or more central processing units or one or more field programmable gate arrays, wherein the field programmable gate arrays integrate one or HK 20135247 A 20 more central processing unit cores. Specifically, the central processing unit or central processing unit core may be implemented as a CPU or MCU or DSP, and so on. In specific embodiments, the electronic device 600 can be implemented using multi-core server architecture with SIL4-certified runtime environment for safety-critical agent functions. The platform provides multi-core processing capabilities enabling parallel execution of neural network generation functions and safety checking functions, standardized hardware interfaces supporting flexible deployment, software-defined architecture enabling agent distribution across multiple computing nodes, and integrated security features supporting cryptographic signature verification for distributed ledger operations. The hardware platform implementation enables deployment of the multi-agent architecture while maintaining safety certification requirements for railway control systems. The platform supports real-time processing requirements with deterministic execution guarantees for safety-critical functions and scalable processing capacity for machine learning operations. The system and processes of the figures are not exclusive. Other systems, processes and menus may be derived in accordance with the principles of the disclosure to accomplish the same objectives. Although this disclosure has been described with reference to particular embodiments, it is to be understood that the embodiments and variations shown and described herein are for illustration purposes only. Modifications to the current design may be implemented by those skilled in the art, without departing from the scope of the appended claims. It should be noted that not all steps and modules in the above-mentioned processes and structural diagrams are necessary, and some steps or modules may be omitted according to actual needs. The execution logic of each step is not fixed and can be adjusted as needed. The division of each module is only to facilitate the description of the functional division used. In actual implementation, a module can be implemented by multiple modules, and the functions of multiple modules can also be implemented by the same module. These modules can be in the same device or in a different device. The hardware modules in various embodiments may be implemented mechanically or electronically. For example, a hardware module may include specially designed permanent circuits or logic devices (e.g., special-purpose processors, such as FPGAs or ASICs) to perform specific operations. Hardware modules may also include programmable logic devices or circuits temporarily configured by software (e.g., including general-purpose processors or other programmable processors) for performing operations. As for the specific mechanical method, HK 20135247 A 21 or a dedicated permanent circuit, or a temporarily configured circuit (e.g., configured by software) to realize the hardware module, it can be decided according to cost and time considerations. The above descriptions are merely preferred embodiments of the present disclosure and are not intended to limit the protection scope of the present disclosure. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present disclosure shall be included within the protection scope of the present disclosure. HK 20135247 A 1 WHAT IS CLAIMED IS: 1. A method (200) for controlling railway operations using a multi-agent decision process with integrated neural network training, the method comprising: generating (S210), by a neural network generator, multiple candidate route and train configuration allocations based on current railway demand and asset states, wherein the neural network generator has been pre-trained using operational SIL4 safety supervision; validating (S220), by a safety checker configured to operate at Safety Integrity Level 4 (SIL4), each candidate allocation against deterministic formally verified safety rules to produce validated safe candidates, wherein the SIL4 safety checker is positioned logically between the neural network generator and optimization processes; optimizing (S230), by a multi-objective optimizer, selection of an optimal allocation from the validated safe candidates by evaluating multiple operational objectives including configuration efficiency; executing (S240), by an execution module configured to operate at SIL 4, the selected optimal allocation including autonomous coupling and decoupling operations under SIL4 supervision; collecting (S250) performance feedback from the execution including configuration performance metrics; updating (S260) the neural network generator through reinforcement learning using the collected performance feedback; and recording (S270), in a distributed ledger (170), all decision stages with cryptographic signatures for regulatory transparency. 2. The method according to claim 1, wherein the pre-training of the neural network generator uses operational SIL4 safety checkers and multi-objective optimizers as training supervisors to teach safety-compliant allocation generation. 3. The method according to any one of claims 1 to 2, wherein the SIL4 safety checker validates candidates against deterministic formally verified safety rules comprising collision avoidance, route conflict detection, speed limit compliance, coupling / decoupling safety verification, and capacity-demand safety limits. 4.The method according to any one of claims 1 to 3, wherein the multi-objective optimizer evaluates candidates based on objectives comprising demand response, profitability, asset utilization, energy efficiency, maintenance preservation, business targets, and configuration efficiency; wherein the configuration efficiency objective balances capacity utilization against operational overhead of coupling and decoupling operations. 5. The method according to any one of claims 1 to 4, wherein the autonomous coupling and decoupling HK 20135247 A 2 operations include SIL4-supervised mechanical engagement, electrical connection, pneumatic connection, and passenger gangway management. 6. The method according to any one of claims 1 to 5, wherein the reinforcement learning feedback incorporates rewards based on safety compliance, performance achievement, and configuration success metrics; and wherein large negative rewards are applied for candidates rejected by the SIL4 safety checker to teach the neural network to internalize safety constraint boundaries. 7. The method according to any one of claim 1 to 6, wherein the reinforcement learning incorporates safety degradation safeguards comprising: monitoring secondary performance metrics with automated intervention triggers; detecting input data distribution changes indicating potential performance degradation; implementing validation protocols for neural network model updates; and applying automated rollback mechanisms when safety regression is detected. 8. The method according to any one of claims 1 to 7, wherein the neural network generator learns during operational deployment through: continuous performance monitoring including safety compliance tracking and multi-objective performance analysis; rejection pattern analysis identifying systematic neural network weaknesses; convergence detection monitoring neural network stability; and automated adaptation to changing operational conditions while maintaining safety guarantees. 9. The method according to any one of claims 1 to 8, wherein the distributed ledger (170) implements a Byzantine fault-tolerant consensus protocol across multiple distributed recorder agents to ensure audit trail integrity and prevent single points of failure. 10. A method for training a neural network for railway allocation generation using operational safety supervision, the method comprising: providing operational SIL4 safety checking systems and multi-objective optimization systems as training supervisors; establishing a training pipeline wherein the neural network generates candidate allocations validated by the operational SIL4 safety checking systems and evaluated by the multi-objective optimization systems; training the neural network to generate allocation candidates that consistently pass safety validation; optimizing neural network parameters based on feedback from both safety checking and optimization HK 20135247 A 3 systems; developing configuration strategies for coupling and decoupling operations based on demand patterns and operational efficiency; and integrating the trained neural network into operational railway control wherein the same safety checking and optimization systems continue supervision. 11. The method according to claim 10, wherein the training pipeline implements Monte Carlo simulation-based self-play learning comprising: generating multiple allocation scenarios through Monte Carlo tree search simulation; evaluating each scenario using the operational SIL4 safety checking systems and multi-objective optimization systems; training the neural network through trial-and-error learning without reliance on historical operational data; and employing exploration strategies including epsilon-greedy exploration, confidence-based exploration, and safety boundary exploration to ensure comprehensive learning coverage. 12. The method according to any one of claim 10 to 11, wherein the exploration strategies include configuration diversity enforcement requiring minimum percentages of coupling operations, decoupling operations, and standalone operations during training to ensure balanced learning across all operational modes. 13. The method according to any one of claim 10 to 12, wherein the training pipeline applies large negative rewards for safety validation failures to teach the neural network safety constraint boundaries. 14. The method according to any one of claims 10 to 13, wherein the configuration strategies include learning optimal coupling triggers for peak demand and energy efficiency and optimal decoupling triggers for off-peak flexibility and maintenance coordination. 15. The method according to any one of claims 10 to 14, wherein the neural network learns to predict coupling and decoupling operation success rates and timing requirements. 16. The method according to any one of claims 10 to 15, wherein the training incorporates historical performance data from actual coupling and decoupling operations to improve prediction accuracy. 17. The method according to any one of claims 10 to 16, wherein the integration includes validation that the trained neural network maintains consistent safety performance with operational systems. 18. The method according to any one of claims 10 to 17, wherein the training process includes synthetic scenario generation to enhance neural network robustness across diverse operational conditions. 19. The method according to claim 1, further comprising dynamically configuring train operations based on HK 20135247 A 4 real-time demand analysis by: monitoring real-time passenger demand data and railway system operational states; analyzing the monitored data using machine learning algorithms to identify optimal train configuration parameters; generating dynamic configuration adjustments comprising autonomous coupling and decoupling operations based on demand patterns; validating the configuration adjustments through the SIL4 safety checker including verification of mechanical compatibility, position verification, and crew availability; implementing the validated configuration adjustments through autonomous coupling and decoupling control systems; and continuously updating configuration strategies based on performance feedback and operational learning. 20. The method according to claim 15, wherein the configuration strategies include: coupling trigger identification based on demand thresholds and energy efficiency opportunities; decoupling trigger identification based on demand reduction and maintenance coordination needs; optimal train composition learning for different demand patterns through performance feedback; and timing optimization for configuration changes minimizing operational disruption. 21. The method according to any one of claim 19 to 20, wherein the autonomous coupling operations include precise positioning, mechanical engagement, electrical connection, pneumatic connection, and post-coupling verification. 22. The method according to any one of claims 19 to 21, wherein the autonomous decoupling operations include passenger clearance verification, system isolation, mechanical release, and independent unit verification. 23. The method according to any one of claims 19 to 22, wherein the configuration adjustments optimize capacity utilization while minimizing energy consumption through coupled operation benefits. 24. The method according to any one of claims 19 to 23, wherein the performance feedback includes actual coupling success rates, timing accuracy, energy efficiency gains, and capacity utilization improvements. 25. The method according to any one of claims 19 to 24, wherein the configuration strategies integrate maintenance scheduling to enable individual unit servicing without complete service disruption by decoupling degraded units for maintenance while healthy units continue operation. 26. The method according to any one of claims 1 to 9, further comprising receiving real-time business conditions from an Enterprise Resource Planning (ERP) system and dynamically adjusting weights of the multiple operational objectives in the multi-objective optimizer based on said business conditions. HK 20135247 A 5 27. A multi-agent railway control system (100) comprising: a Central Agent (110) including a neural network generator, a SIL4 safety checker, a multi-objective optimizer, an SIL4-certified execution module, a maintenance planner (120), and an ERP interface; multiple Train Agents (130) each including movement authority execution capabilities, health monitoring systems, and autonomous coupling / decoupling control logic; multiple Track Agents (140) each including wayside object control systems and infrastructure health prediction capabilities; Passenger Agents (150) including transport request handling and real-time journey optimization; Service Agents (160) including maintenance request processing and AI-powered work order generation; and Recorder Agents (170) including distributed ledger nodes and cryptographic signature verification; wherein the agents are configured to cooperatively execute the method according to any one of claims 1 to 21. 28. The system according to claim 27, wherein the Central Agent (110) implements a six-stage decision process comprising generation, safety checking, optimization, execution, planning, and ERP integration. 29. The system according to claim 27, wherein the Train Agents (130) provide autonomous coupling and decoupling capabilities with SIL4 supervision and real-time health monitoring. 30. The system according to claim 27, wherein the Recorder Agents (170) implement Byzantine fault-tolerant consensus across multiple distributed nodes for audit trail integrity. 31. The system according to claim 27, wherein the neural network generator has been pre-trained using the operational SIL4 safety checker and multi-objective optimizer as training supervisors. 32. The system according to claim 27, wherein the system integrates prescriptive maintenance planning with operational optimization to minimize service disruptions. 33. The system according to claim 27, wherein the ERP interface provides dynamic weight adjustment for optimization objectives based on real-time business conditions. 34. An electronic device (600), comprising a processor (601) and a memory (602), wherein an application program executable by the processor (601) is stored in the memory (602) for causing the processor (601) to execute a method for dynamic intelligent safety railway controlling according to any one of claims 1-26. 35. A computer-readable medium comprising computer-readable instructions stored thereon, wherein the computer-readable instructions, when executed by a processor, cause the processor to execute a method for dynamic intelligent safety railway controlling according to any one of claims 1-26. 36. A computer program product comprising a computer program which, when executed by a processor, HK 20135247 A 6 causes the processor to carry out a method for dynamic intelligent safety railway controlling according to any one of claims 1-26. HK 20135247 A FIG.1 100 110 140 170 130 130 130 120 140 140 140 150 112 1 HK 20135247 A FIG.2 S210 S220 S230 S240 S250 S260 2 HK 20135247 A FIG.3 S310 S320 S330 S340 S350 S360 3 HK 20135247 A FIG.4 S410 S420 S430 S440 S450 S460 4 HK 20135247 A FIG.5 601 600 602 5 HK 20135247 A