Method for operating a fuel cell system, control device
Patent Information
- Application Number
- PCT/EP2026/055108
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-26
- Filing Date
- 2026-02-25
- Publication Date
- 2026-09-03
Smart Images

Figure EP2026055108_03092026_PF_FP_ABST
Abstract
Description
[0001] R.414548
[0002] - 1 -
[0003] Description
[0004] Title:
[0005] Method for operating a fuel cell system, control unit
[0006] The present invention relates to a method for operating a fuel cell system in a vehicle according to the preamble of claim 1. The invention also relates to a control unit.
[0007] State of the art
[0008] To continuously develop the technology in fuel cell systems, particularly in the automotive sector, and to gain a deeper understanding of the underlying physical principles, these systems continuously record operating data on various channels. The data is recorded in a fixed grid and transmitted via data loggers to an external computing center, such as a cloud or an on-premises big data system. Due to the limited data rate of the mostly wireless transfer, typically via the public mobile network, there is a strong incentive to reduce the amount of data transmitted. Sometimes, human aggregation of the data is employed, for example, through stationary point or cycle detection, which reduces the data to average values or similar metrics.
[0009] In the current state of development of fuel cell systems, however, these aggregations cannot usually be performed because the underlying physical relationships are not fully understood. Particularly in dynamic operating ranges of a fuel cell, it is impossible to establish rules for aggregating or compressing data to reduce its volume without incurring a significant loss of knowledge.
[0010] However, completeness of information is essential not only due to limited bandwidth during data transfer. The collected data is used to train anomaly detection systems based on machine learning, or R.414548.
[0011] - 2 -
[0012] Artificial intelligence systems, such as car encoders, are used in this context. Due to energy and hardware requirements, training these systems cannot be performed locally on the vehicle but must be carried out externally using data from a large number of vehicles. The information contained in the training data must be comprehensive enough to distinguish an anomaly—that is, a malfunction or unexpected system behavior—from data drift. Data drift occurs when the pattern of the system's typically visited operating points changes without any technical fault. Such data drift can be caused, for example, by wear and tear, a different operating mode, a changed load, a new driver with a different driving style, operating the vehicle in a different climate zone, or similar factors.In some cases, data drift can render previously used machine learning systems within the fuel cell system unusable, requiring retraining. Consequently, if information is incomplete, data drift may go undetected and be incorrectly interpreted as malfunctions.
[0013] The invention therefore aims to enable the compression of operating data for low-volume data transmission while simultaneously minimizing information loss. To solve this problem, a method with the features of claim 1 is proposed. Further preferred embodiments are described in the dependent claims. A control unit is also proposed.
[0014] Disclosure of the invention
[0015] A method for operating a fuel cell system in a vehicle is proposed, wherein, during operation, raw operating data is read out for evaluation at a decentralized computing center and stored at a temporary storage location. According to the invention, an encoder and a decoder are used for data processing on the vehicle side, and an identical decoder is operated on the decentralized computing center side, wherein the following steps are executed partly sequentially and partly in parallel: R.414548
[0016] - 3 -
[0017] Vehicle-side generation of compressed data by compressing the raw data using the encoder,
[0018] Transmitting the compressed data to the decentralized computing center, reconstructing the raw data from the compressed data on the vehicle side using the decoder,
[0019] Detecting compression errors based on reconstruction errors, and
[0020] If a compression error is detected: Read the raw data from the temporary storage location and store the raw data in a designated long-term storage location.
[0021] The invention enables the compression of recorded raw data, thereby reducing the data volume of a data transmission. Simultaneously, data that was not compressed correctly is identified and stored, thus preserving its informational content. Furthermore, the invention also provides encryption of the raw data, as its correct reconstruction requires knowledge of the encoder parameters. Transmitting the data to an external computing unit, such as a cloud service, also creates the possibility of operationally monitoring and, if necessary, validating entire vehicle fleets. Data collected centrally in this way can also be used to train future encoders.
[0022] The raw data is typically recorded as time-lapse sequences at an appropriate sampling rate on different channels. The raw data typically originates directly from sensors installed on the fuel cell system. What constitutes an appropriate sampling rate depends on the specific case, the sensor source of the raw data, and similar factors. Recording preferably occurs in short time interval blocks, so that encoding and decoding always involve only recorded data from a small time period. The smaller this time period, the more accurately compression errors can be determined afterward; however, the potential savings in data volume decrease with the size of the time period. The encoder is preferably designed as an autoencoder. R.414548
[0023] - 4 -
[0024] Data reconstruction is performed via the decoder on the vehicle side. It should be noted that minor reconstruction errors cannot be entirely ruled out. Therefore, some minor reconstruction errors are generally to be expected. If the reconstruction errors exceed the expected level by a predetermined amount, a compression error is present.
[0025] If a compression error is detected, the raw data for the relevant time period is read from a temporary storage location, such as a ring buffer system, and written to a non-volatile long-term storage location. A memory card, for example, would serve as such a long-term storage location. This would then be read during a service visit and transferred to the decentralized data center via another method. This way, the decentralized data center receives a compressed data set, reconstructible by its decoder, via wireless transmission, as well as raw data for data that cannot be reconstructed by the encoder at a later time. This prevents any loss of information during compression.
[0026] It is also proposed that a neural network, preferably a convolutional LSTM, be used as an encoder. Preferably, this would be an autoencoder designed accordingly. Neural networks are capable of accurately representing complex behavior without requiring an understanding of causal relationships.
[0027] In a further development of the invention, it is proposed that, to detect compression errors, a loss value is compared with an expected loss value. The quality of the reconstruction is preferably measured channel-wise via the loss function, with a higher loss value preferably indicating a less accurate reconstruction; a loss value of zero (only theoretically possible) would then represent an exact and error-free reconstruction of the raw data on that channel. To detect compression errors, distinguishing them from smaller reconstruction errors that typically occur, the loss value for each recorded channel is compared with an expected loss value.
[0028] - 5 -
[0029] The loss value is compared. If the loss value deviates by more than a predetermined amount, a compression error is present.
[0030] It is further proposed that the loss value and / or its deviation from the expected loss value be transmitted to the decentralized computing unit. With this preferred embodiment, the decentralized computing unit receives information about the compression quality and the reconstructibility of the received compressed data. Since the raw data associated with a compression error arrives at the decentralized computing unit only with a time delay, this prevents the unit from drawing incorrect conclusions from the transmitted data containing compression errors. In a modification of this preferred embodiment, the loss value and / or its deviation from the expected loss value are only transmitted if the deviation exceeds a predefined value, for example, if a compression error has been detected.
[0031] Furthermore, it is proposed that data containing compression errors should not be used when processing the compressed data transmitted to the decentralized data center. This will prevent erroneous conclusions and the subsequent implementation of errors in data processing.
[0032] Furthermore, it is proposed that the raw data be stored at recurring intervals in a long-term storage location, read out at a suitable time, for example during a workshop visit, and used to check the compression and / or to train the encoder. This preferred embodiment enables regular quality control of the compression as well as the generation of training data for future encoder training.
[0033] It is further proposed that the raw data be statistically processed, for example by means of stationary point detection, before being fed to the encoder. This preferred embodiment contributes to a possible reduction in data volume with minimal loss of knowledge, R.414548
[0034] - 6 -
[0035] for example by reducing known minor fluctuations to an average value.
[0036] It is also proposed that the reconstructed data be compared with the raw data and / or a parameter space known from encoder training to determine whether there is a data drift in the raw data or an anomaly in the raw data. With this preferred embodiment, anomalies and data drifts can be detected, and the use of another anomaly detection system can be avoided.
[0037] An anomaly is understood to be unexpected system behavior. This is typically due to an undesirable or malfunctioning function. A characteristic of an anomaly is, in particular, when only one or a small number of channels exhibit compression errors, while the raw data recorded via the other channels is within the normal range.
[0038] In contrast, data drift is a shift in data trends that is to be expected due to a changed circumstance and is not necessarily caused by a technical defect. It occurs, for example, when the pattern of the system's typically visited operating points changes without this being directly attributable to technical errors. Examples of such changes include wear and tear, a different operating mode, a changed load, a new driver with a different driving style, operating the vehicle in a different climate zone, or similar factors.
[0039] Furthermore, it is proposed that the raw data be stored in a designated long-term storage location when a data drift and / or an anomaly is detected. This ensures that raw data from an anomaly or data drift is available for subsequent analysis. A suitable long-term storage location could be, for example, a memory card that can be read during the next service visit. Four anomaly detection scenarios are possible. R.414548
[0040] - 7 -
[0041] First, consider the scenario in which no anomaly is correctly detected. In this case, the compressed data is successfully reconstructed on the vehicle side and sent to the decentralized computing center. It is also possible that an anomaly exists but is incorrectly not detected. In this case, the decentralized computing center performs an incorrect reconstruction of the raw data without detecting it. This typically comes to light when evaluating workshop data from the vehicle. Ideally, if this scenario occurs, the encoder should be retrained or re-trained.
[0042] In the third and fourth scenarios, an anomaly is detected. To distinguish a correct anomaly detection from a false positive, it is proposed that a special operating mode of the fuel cell system be triggered upon detection of an anomaly. This mode maintains an operating point that triggered the anomaly for a predetermined period. For example, actuators are controlled to maintain this operating point in order to collect further raw data to confirm the actual presence of an anomaly. If the anomaly is confirmed, the raw data is collected and stored in a long-term storage location. It is then retrieved from this storage location at a later time and processed for further analysis. Preferably, the data is labeled for later identification.An error can also be triggered in a monitoring system or control software.
[0043] If it is detected that the anomaly was incorrectly identified, the raw data is preferably sent to the decentralized computing unit and used to retrain the encoder. Here, too, the data is preferably labeled for later identification.
[0044] Building on this, it is proposed that, upon detection and / or occurrence of an anomaly, a warning be issued to the driver of the vehicle and / or a message be sent via a data logger. This preferred embodiment addresses the need to be able to react promptly to the occurrence of an anomaly. R.414548
[0045] - 8 -
[0046] Furthermore, it is proposed that the encoder be retrained if data drift is measured across a predetermined number of vehicles. Data drift across a larger number of vehicles indicates normal system behavior. This preferred embodiment enables the encoder to handle data drift.
[0047] Furthermore, it is proposed that, upon request from the decentralized computing center, the raw data be collected and stored in a long-term storage location and / or transferred to the decentralized computing center. With this preferred embodiment, the collection of raw data can be ordered centrally on demand, data that might otherwise not be available. Such a demand could, for example, be the determination that a specific situation is underrepresented in the training data of the autoencoder.
[0048] Furthermore, a control unit is proposed which is configured to perform steps of a method according to one of the preceding claims. Such a control unit has the aforementioned technical effects and advantages.
[0049] It is also proposed that the procedure be implemented in a shadow mode of the control unit. Shadow mode refers to a separate area within the control unit that has read access to the fuel cell system's control software and all the sensors supplying it, but not write access or the ability to issue control commands. This preferred embodiment primarily reduces verification and documentation requirements because the control components that actually influence the behavior of a fuel cell system with control commands are typically subject to increased documentation, verification, acceptance, and certification requirements (e.g., TÜV). Modifying the encoder, for example, by retraining it, could invalidate previously granted certifications. This typically does not apply if the encoder is implemented in a shadow mode. R.414548
[0050] - 9 -
[0051] The invention is explained in more detail below with reference to figures. They show
[0052] Figure 1 shows a schematic representation of a process sequence according to the invention and
[0053] Figure 2 shows a schematic representation of data compression and reconstruction.
[0054] Character description
[0055] Fig. 1 schematically illustrates a process sequence according to the invention. In a first step S1, raw data from sensors of the fuel cell system are read on the vehicle A side. In an optional step 01, this data can be checked for plausibility, whereby a subsequent monitoring step S6 can be deactivated if the data is implausible. In a next step S2, the raw data is statistically processed and then, in a subsequent step S3, fed into an encoder 1, preferably an automotive encoder. This compresses the raw data and forwards it for transmission, typically to a designated location such as a data client 3. From there, the data is sent via a transmitter 4 to a decentralized computing center B. On the vehicle A side, the compressed data is simultaneously transferred from the encoder 1 to a decoder 2, which reconstructs the raw data from it.If reconstruction errors occur that are due to compression errors, the raw data is read from a ring buffer system 5 and stored in a long-term storage location, for example by transmission to the data client 3, which then saves it, for example, on a memory card. The data reconstructed by decoder 2 is examined in a post-processing step S4 for the presence of anomalies or data drift. If an anomaly is identified, a special operating mode of the fuel cell system is activated in a subsequent step S5 to distinguish an actual anomaly from a false positive. If the anomaly is confirmed, a warning signal is issued to a driver of vehicle A in a monitoring step S6, and a message is sent via a data logger, for example by sending a corresponding command to the R.414548.
[0056] - 10 -
[0057] Data Client 3. If the anomaly is not confirmed or no anomaly is detected in step S4, no warning signal or message is set via a data logger. The result of monitoring step S6 is transmitted to Data Client 3. In a preferred embodiment, the raw data from step S1 is occasionally transmitted directly to the decentralized computing unit B, for example, to monitor the reliability of the process or to train encoder 1.
[0058] On the side of the decentralized computing center B, the transmitted data is assigned to either reconstruction or further processing in step S7. If compressed data without anomaly detection is received, it is reconstructed in a subsequent step S8 and then further processed in a further step S9. If necessary, previously undetected anomalies are identified by later incorporating data obtained during a workshop visit or by evaluating raw data transmitted for verification. In this case, troubleshooting is performed in step S10, and the autoencoder is retrained if necessary.
[0059] If an anomaly was previously detected, the raw data transmitted or stored in a long-term storage location and retrieved at a later time are analyzed in step S11 and used in step S12 to improve the understanding of the internal processes of the fuel cell system. If necessary, the autoencoder is retrained in a further step S13. A request to collect raw data in a long-term storage location can also be issued from the decentralized computing center B if required.
[0060] Preferably, in cases where encoder 1 is retrained, for example when executing steps S10 and / or S13, step S3 is executed in shadow mode on some vehicles. Shadow mode is a separate storage or processing unit that has full read access and no write access to the control unit or control software. In the described case, these vehicles send both the compressed data as R.414548
[0061] - 11 -
[0062] The raw data, for example read from the ring buffer system 5, is also sent to computing center B. This validates the retrained encoder 1 based on the transmitted data pairs – compressed data and associated raw data. After validation, the new encoder 1 is rolled out to all vehicles in a fleet.
[0063] Fig. 2 schematically shows the compression and reconstruction of operational data. For simplicity, the representation is limited to a single channel. On this channel, a time series is divided into short time windows a. Depending on whether the data profile within each time window a is stationary b or dynamic c, the data can be processed differently. An encoder 1, for example an LSTM convolutional autoencoder, reads the raw data of each time window a and displays it as compressed data d. In particular, stationary data profiles b can be represented in a simplified manner.
[0064] The compressed data d is fed to a decoder for reconstruction. Ideally, this decoder can correctly reconstruct the data histories (b, c) within the time windows a from the compressed data d.
Claims
R.414548 - 12 - Claims 1. Method for operating a fuel cell system in a vehicle (A), wherein during operation, operating data is read out as raw data for evaluation at a decentralized computing center (B) and stored at a temporary storage location, characterized in that an encoder (1) and a decoder (2) are used for data processing on the vehicle side and an identical decoder (2) is operated on the side of the decentralized computing center (B), wherein the following steps are carried out partly sequentially and partly in parallel: Vehicle-side generation of compressed data by compressing the raw data using the encoder (1), Transmitting the compressed data to the decentralized computing center (B) Vehicle-side reconstruction of the raw data from the compressed data using the decoder (2), Detecting compression errors based on reconstruction errors, and If a compression error is detected: Read the raw data from a temporary storage location and store the raw data in a designated long-term storage location.
2. Method according to claim 1, characterized in that a neural network, preferably convolutional LSTM, is used as the encoder (1).
3. Method according to one of the preceding claims, characterized in that a loss value is compared with an expected loss value to detect compression errors.
4. Method according to claim 3, characterized in that the loss value and / or its deviation from the expected loss value is transmitted to the decentralized computing center (B).
5. Method according to one of the preceding claims, characterized in that, in the case of data processing, the data sent to the decentralized R.414548 - 13 - Data transmitted to the computing center (B) containing compression errors will not be used.
6. Method according to one of the preceding claims, characterized in that the raw data are stored at a long-term storage location at recurring intervals, read out at a suitable time, for example during a workshop visit and used to check the compression and / or to train the encoder (1).
7. Method according to one of the preceding claims, characterized in that the raw data are statistically processed, for example by means of stationary point detection, before being fed to the encoder (1).
8. Method according to one of the preceding claims, characterized in that the reconstructed data are compared with the raw data and / or a parameter space known from a training of the encoder (1) to determine whether there is a data drift of the raw data or an anomaly in the raw data.
9. Method according to claim 8, characterized in that the raw data are stored at a long-term storage location provided for this purpose when a data drift and / or an anomaly is detected.
10. Method according to claim 8 or 9, characterized in that, upon detection of an anomaly, a special operating mode of the fuel cell system is triggered, wherein an operating point that caused the detection of the anomaly is maintained for a predetermined time.
11. Method according to any one of the preceding claims 8 to 10, characterized in that, upon detection and / or presence of an anomaly, a warning is issued to a driver of the vehicle (A) and / or a message is sent via a data logger. R.414548 - 14 - 12. Method according to any of the preceding claims 8 to 11, characterized in that the encoder (1) is retrained when a data drift is measured on a predetermined number of vehicles.
13. Method according to one of the preceding claims, characterized in that, upon request of the decentralized computing center (B), the raw data are collected and stored at a long-term storage location and / or transferred to the decentralized computing center (B).
14. Control unit configured to perform steps of a method according to any of the preceding claims.
15. Control unit according to claim 14, characterized in that an implementation of the method is carried out in a shadow mode of the control unit.