1. Introduction
Water stations, being a part of water distribution networks, contain many sensors and actuators, guaranteeing safe and desired functionality [
1,
2]. Moreover, chlorinated water stations serve as the main water treatment system of the water distribution networks, ensuring effective microbial disinfection [
3,
4]. The use of automation systems and equipment in complex and large-scale systems like water distribution networks has been established for quite a long time [
5,
6,
7]. Thus, Programmable Logic Controllers (PLCs) units for local control of devices and Supervisory Control and Data Acquisition (SCADA) systems are used for global monitoring and supervisor control [
1,
8,
9,
10].
Discrete Event Systems (DESs) and Supervisory Control Theory (SCT) are established systemic tools for modeling, control, and fault diagnosis for large scale and complex systems [
11,
12,
13,
14,
15]. SCT is offered to guarantee safe and desired functionality by restricting unsafe behaviors through control of controllable events [
11,
12]. On the other hand, diagnosis systems, based on DES models of the devices, are used for fault detection of devices [
13,
14,
15]. The implementation of supervisor control [
16,
17,
18,
19,
20] and diagnosis systems [
21,
22,
23] is still a challenging topic. In [
24], a neural-network-based fault detection method for water distribution networks was developed and implemented in a hybrid PLC/cloud architecture. In addition, refs [
22,
23] presented PLC implementations of DES-based supervisory control and fault diagnosis schemes for small-scale water distribution network testbeds. Therefore, despite the increasing interest in formal methods for DES-based supervisor and diagnosis approaches, only a limited number of works address the practical PLC implementation for water distribution systems.
Alternative architectures for smart water systems have been studied using IIoT [
25], edge computing [
26], cloud platforms [
22], and AI-enabled analytics [
27]. IoT-enabled PLC and SCADA and IoT platforms integration has been proposed to improve real-time monitoring, interoperability, and predictive maintenance in water infrastructures [
28]. IoT- and cloud-based platforms have been developed for real-time water treatment monitoring [
22,
28]. Some Water Distribution Network (WDN) applications using IoT-based architecture include predictive maintenance of pipelines and devices, real-time data analysis for fault detection, software tools for monitoring water consumption, etc. [
29,
30].
It is important to mention that WDNs actuators have fast dynamic behavior, which can lead to fast changes in the measured signals. Therefore, the reliability of the sensor models depends on the availability of measurements with a sufficiently high sampling rate. In IIoT-based solutions, however, measurement samples may be lost or delayed due to longer sampling periods, communication latency, or network interruptions. Moreover, SCADA architectures with PLCs as nodes are already installed in the majority of water stations. For this reason, the proposed supervisors and diagnosers were implemented using the SCADA/PLC infrastructure, which provides reliable real-time operation and high sampling rates while avoiding the need for additional communication layers.
As already mentioned, control and monitoring algorithms, implemented in PLC and SCADA, are widely used in water stations [
1,
2]. However, the design of these algorithms is based on threshold rules and limits concerning each device. These approaches offer basic protection for each single device. However, they may be insufficient when the safe operation of the station depends on the coordination of several devices. For instance, a command to a pump that changes the operating mode of the pump also influences the measurements of the water level of the tank fed by the pump. In such cases, local rules may fail to detect undesired behavior.
Supervisor control and diagnosis methods based on DES and Ramadge–Wonham frameworks are an effective design method for control and monitoring. Their practical application in real water stations still faces important issues. First, faults are events that are rarely observable from the local control station. Second, the large-scale nature of water stations and water distribution networks involves a large number of devices operating simultaneously and interacting with each other. Therefore, DES supervisor control and diagnosis must address not only the isolated behavior of each device but also operational interaction among devices.
In the present research, a chlorinated water station in Delfino, Greece, was studied. The DES models of the devices of the station are presented. The DES models of the flow, pressure, and level sensors are presented based on the DES models of [
22,
23,
26,
31]. Validation of the DES models through field data of the station is provided. In addition, the DES model of the pumps is presented and described through two distinct models. The first model captures the pump activation and deactivation functionality (see also [
23,
26,
31]), while the second one, first introduced here, describes the regulation of the pump output flow. A set of rules and their corresponding regular languages are applied to prevent tank overflow (see also [
23,
26,
31]) and dry running of the pumps (see also [
32]). Following the design procedure of [
23,
26,
31], a set of supervisors in the form of automata is designed, realizing the regular languages of the desired functionality. An additional rule and its corresponding supervisors are introduced to prevent simultaneous activation of two pumps used to outflow water from the same tank. Next, a modular fault diagnosis system is implemented for all the pumps of the water station, aiming to diagnose the faulty case of pump having stuck open despite deactivation command. The diagnosis is based on the signals of the level sensors according to the diagnosis systems proposed in [
23,
26]. For the flow sensors, a fault diagnosis system based on pressure sensor data is developed here for the first time. The sensor fault diagnosers presented in the paper were validated using the field data of the Delfino water station. The structured language code for the PLC implementation of the diagnoser automaton is presented. Overall, the efficiency of the present approach is based on the interaction of the devices installed in the station as well as the rules resulting from the physical characteristics of the station.
Τhe contribution of the present work, as compared to [
23,
26,
31], concerns the DES model describing the regulation of the pump’s output flow, the supervisor preventing simultaneous activation of two pumps, the flow sensor fault diagnoser, the configuration of the rules, the supervisors and the pumps’ diagnosers for the water station in Delfino (Greece), as well as the validation of the modeling, supervisor, and diagnosis scheme based on Delfino’s station field data.
In
Section 2, the chlorinated water station of Delfino is presented. In
Section 3, the DES models of sensors and their field data validation are presented. In
Section 4, the DES models of the pumps are given. In
Section 5, the safety rules of the station are provided, and the corresponding regular languages are formed. Also, the realization of the regular languages using supervisor automata are given. Verification of the influence of the supervisor through field data closes the section. In
Section 6, modular actuator fault diagnosis systems are given in the form of automata. In
Section 7, the sensor fault diagnosis system is presented, also in the form of an automaton. Finally, the diagnosis is tested through field data.
2. Water Station of Delfino
As already mentioned, in the present work, the chlorinated water station of Delfino located in Greece is studied. In
Figure 1, the diagram of the water station in the local SCADA system is presented. In
Figure 2, photographs of the real water station in Delfino are shown. The station has two water tanks: the low-level tank at 526 m from the sea level and the high-level tank at 600 m from the sea level. The water is transferred from various water sources to both tanks through two different pipes. A pump controls the incoming water flow from the sources to the low-level tank. Two controlled pumps, installed downstream of the low-level tank and connected in parallel, supply the high-level tank with water and potentially a secondary demand. The high-level tank mainly supports with water the demand through three separate pipes. Moreover, a small chlorine tank is installed near the high-level tank and provides chlorinated water (sodium hypochlorite solution) to this tank through a dosing chlorine pump. Each pump is controlled by a respective local PLC (Siemens Simatic S7-1200 and S7-1500, Siemens AG, Munich, Germany, were used).
The two pumps of the low-level tank, supplying the high-level tank and the secondary demand, are denoted as P-Z27.1 and P-Z27.2. The pump controlling the incoming water from the sources to the low-level tank is denoted as P-Z27.3. Finally, the pump providing high-chlorinated water to the high-level tank is denoted as PCL-Z28.1.
Assumption 1. Four manually controlled gate valves are installed in the system after the two pumps (see Figure 1). The first two valves after the pumps, being the lower valves, are always open, and they are used only for equipment maintenance. Regarding the next two valves, namely the upper valves, the right one controls the water flow towards the high-level tank, while the other valve controls the water flow towards a secondary demand, which is required only in exceptional cases. In normal conditions, the right upper valve is always open, while the second upper valve is always closed. This configuration of the manual valves is considered to hold for the rest of the present paper. The two water tanks and the chlorine tank are equipped with appropriate level sensors. The water level sensor of the low-level tank is denoted as LIT-Z27.1. The water level sensor of the high-level tank is denoted as LIT-Z28.1. The level sensor of the chlorine tank is denoted as LIT CL-Z28.1. After the pumps P-27.1 and P-27.2, a pressure sensor, denoted as PIT-Z27.1, and a flow sensor (flowmeter), denoted as FIT-Z27.1, are installed. In the high-level tank, three flow sensors are installed in the three pipes, feeding the demand and denoted as FIT-Z28.1, FIT-Z28.2, and FIT-Z28.3. After the pump of the chlorine tank, a chlorine flow sensor, denoted as CL-Z28.1, is installed. Finally, a SCADA system is used to monitor and control the water station. The SCADA system is SIMATIC WinCC [
33]. It is noted that all sensor measurements as well as the status of the pumps are acquired by the SCADA system, with a sampling period of 1 min. However, the PLCs acquire measurements from the sensors with a significantly higher rate, with a typical magnitude of order about 20 ms.
3. Model of the Sensors
Next, generic DES models of the sensors of the water station, as well as the model specifications for each of the four sensor types, are presented. Finally, the DES sensor models are validated using real data extracted from the station’s SCADA system.
3.1. Generic DES Model of the Sensors
As already mentioned, in Delfino’s water station, there are four types of sensors: level sensors, flow meter sensors, pressure sensors, and chlorine flow sensors. In [
23,
31], the DES models of the level sensors were presented for the case of a parametric number of water levels (expressed as water level zones). In [
26], the flow, the pressure, and the chlorine flow signals were quantified in zones, resulting in similar DES models. Following [
26], a generic DES model of all types of sensors is herein presented. To this end, the index “L” will correspond to water level sensors measured in cm, the index “F” will correspond to flow sensors measured in m
3/h, the index “P” will correspond to pressure sensors measured in bar, and the index “CL” will correspond to high chlorine water flow sensors measured in ml/h.
Let
be the number of sensors of type
, where
. Let
be the number of zones of each sensor, where
and
. Thus, the DES model of each sensor is
where ([
23,
26,
31])
State
, where
, corresponds to measured value lying within the lower and upper bounds of the
-th zone, including the upper limit. Hence, each state is assigned with a small value area of the sensor’s measurements. State
corresponds to measured value higher than the upper limit of the
zone. Event
, where
, indicates that the sensor measurement has just crossed the upper boundary of the
-th zone. Thus, each event is associated with the upper boundary of a measurement zone. It should be noted that event
occurs whenever the sensor measurement crosses the boundary of the
-th zone, either increasing or decreasing. Thus, event
provokes either a transition to state
in the decreasing direction or to state
in the increasing direction. All events are uncontrollable. The marked behavior [
11] of
is
Its closed behavior [
7] is
. Clearly,
is nonblocking [
11]. The state diagram of
is in
Figure 3.
The aforementioned sensor model aims to represent sufficiently the continuous time variations of the WDN’s measured variables, using a discrete event model. To achieve that, it requires a subtle partition of the range of measurements to corresponding zones as well as high-frequency sampling. Thus, the control and diagnosis design schemes that exploit such sensor models should be implemented by the local PLCs, which have significantly larger sampling rates as compared to SCADA systems. Moreover, local PLCs may achieve more successfully uninterrupted communication with the sensors. A different DES sensor model that is more suitable for SCADA-based implementations, with higher sampling rates and increased probability of communication loss, was presented in [
32].
The event
is produced at the time instant
by the logic expression
where
is the continuous-time measurement of the sensor
,
and
are any two consecutive sampling instants,
is the upper limit of the
-th zone, and
denotes exclusive disjunction of variable logic propositions.
Figure 3 shows the generic DES model used to describe the behavior of all sensors. The circles correspond to states and the arrows to transitions triggered by events. The double circle denotes a marked state. The initial state is indicated by an arrow without event. Each state
corresponds to a measurement area, while each event
denotes the transition between neighboring areas. The bidirectional transitions, with the same event, show that the measured variable may cross the boundary between two areas, either increasing or decreasing.
3.2. Models of the Four Type of Sensors
As already mentioned, in Delfino’s water station, there are three level sensors, one for each of the two tanks and one sensor for the chlorine tank; i.e., it holds that . The automata and model the level sensors LIT-Z27.1 and LIT-Z28.1 of the two tanks, respectively. The automaton models the level sensor LIT CL-Z28.1 of the chlorine tank. Also, in the station, there are four flow sensors, i.e., . The automaton models the flow sensor FIT-Z27.1 of the low-level tank. The automata , , and model the flow sensors FIT-Z28.1, FIT-Z28.2, and FIT-Z28.3 of the high-level tank, respectively. Furthermore, in the station, there is one pressure sensor, i.e., . The automaton models the pressure sensor PIT-Z27.1 of the low-level tank. Finally, in the station, there is one chlorine flow sensor, i.e., . The automaton models the chlorine flow sensor CL-Z28.1 of the chlorine tank.
3.3. Validation of the DES Model with Field Data
An important aspect is the validation of the sensor models presented in the previous section, using field data from the PLC acquiring the measurements of Delfino’s water station. To this end, the model and the data of the level sensor LIT-Z27.1 of the low-level tank are compared. According to the parameters of the monitoring system, the resolution of the level sensor is 1 cm, with a maximum range value of 420 cm. Hence, a model with
is proposed. The first zone, namely the state
, is from 0 cm to 1 cm. The second zone, namely the state
, is from 1 cm to 2 cm. This correspondence continues until the final zone, namely the state
, which is from 419 cm to 420 cm. Note that the measurements of the water level are expected to remain in a narrower range through the application of the appropriate safety rules presented in
Section 5.
In order to express the state sequence for a set of field data, the data of LIT-Z27.1 from 7 January 2026 at 02:40 to 8 January 2026 at 02:40 (see
Figure 4) are used.
From
Figure 4, it is observed that from 7 January 2026 at 2:40:00.000 to 3:25:59.980, the height is at 40 cm, and so
is in
. From 7 January 2026 at 3:26:00.000 to 7:31:59.980, the height is at 41 cm, and so
is in
. From 7 January 2026 at 7:32 to 7:33:15.540, the height is 42 cm, and so
is in
. From 7 January 2026 at 7:33:15.560 to 7:33:29.980, the height is 43 cm, and so
is in
. From 7 January 2026 at 7:33:30.000 to 7:33:44.460, the height is 44 cm and thus is in
. From 7 January 2026 at 7:33:44.480 to 7:35:09.020, the height is at 45 cm, and so
is in
. At 7:35:09.040, the height reaches 46 cm, and so
is in
. Following this procedure, the DES models of the rest level sensors were validated by choosing
and
.
6. Modular Actuator Fault Diagnosis
Actuator faults may significantly affect hydraulic operation or the water quality in a WDN. Moreover, the commands sent to the WDN’s actuators by the operator (automatically or manually) are based on the information provided by the sensors and on the previously applied actuator commands. Consequently, a fault in the sensor measurements or an undetected actuator fault, where a previous command has not been executed in the physical layer, can affect the performance of the decision-making process, even concerning the next commands. This is due to the fact that a command based on faulty information or on a previous command alleged to be executed may drive the water station toward undesired operating conditions, affecting both the safety and the functionality of the total system. The next section proposes diagnosers in the form of automata that detect a pump’s stuck-open faulty state of operation. Finally, the implementation of the proposed actuator diagnosers in Structured Text language for PLC use is presented.
6.1. Actuator Faults
The three pumps of the station supply the two tanks with water, and the fourth pump supplies chlorine to the second tank. The occurrence of a fault in the actuators of the station may cause severe problems with the performance of the water station. A common fault is for the pump to stay open although a deactivation command has been sent from the PLC. For example, a stuck-open fault in P-Z27.3 may cause overflow to the low-level tank. Also, a stuck-open fault in PCL-Z28.1 may cause hyperchlorination of the water in the output of the high-level tank and consequently affect the demand. Hence, an alarm system must be developed based on the available data of the pumps and the sensors, informing the user about possible faults in the closing procedure of the pumps. In what follows, three diagnosis systems are developed for pumps P-Z27.1, P-Z27.2, P-Z27.3, and PCL-Z28.1 based on the diagnosis method proposed in [
22].
6.2. Fault Diagnosis of Pump P-Z27.3
For pump P-Z27.3, the diagnosis method proposed in [
22] is used taking into account only the case where the pump stays opened despite deactivation command (stuck open). The case where the pump is stuck closed is not examined because the diagnoser in [
22] is based on a water flow balance assumption that cannot be verified here, namely the flow rate feeding the tank to be greater than the flow rate of the output pumps. For the diagnosis system, data from level sensor LIT-Z27.1 are used. A modular diagnosis system is developed where a set of
diagnosers, one for each of the lower water levels, is designed.
Actuator Fault Detection Procedure for P-Z27.3: If pump P-Z27.3 is deactivated, then the zone of sensor LIT-Z27.1 must not increase. If the above normal operating procedure is violated, a stuck-open fault is detected in pump P-Z27.3.
The automata of the diagnoser are presented analytically in [
22]. The 6-tuple automata of the diagnosers are of the form
where
. In
Figure 9 and
Figure 10, the state diagrams of the automata of diagnosers
are depicted for the cases
and
, respectively. Note that the state in red indicates that a fault took place, i.e., the pump stayed open.
Remark 6. The signal that commands deactivation of the pump is introduced to the diagnoser with a configurable transient delay time. During this delay, the diagnoser does not reach the alarm state, thus allowing the pump outflow, pressure, and tank level to reach their post-deactivation behavior. Moreover, an alarm is generated only when the diagnoser stays in an undesired (faulty) state for a sufficient number of consecutive PLC cycles or SCADA samples. This way, the diagnoser can distinguish between normal hydraulic transients and actual actuator or sensor faults, reducing the possibility of false alarms.
6.3. Fault Diagnosis of Pumps P-Z27.1 and P-Z27.2
As already mentioned in
Section 2, the four manual valves after the pumps P-Z27.1 and P-Z27.2 allow the water flow from the low-level tank towards the high-level tank. Also, in
Section 5, a supervisor was developed and implemented in the station, obstructing the two pumps P-Z27.1 and P-Z27.2 from being active at the same time. Hence, following the diagnosis method proposed in [
22], a fault diagnosis system is developed for both pumps based on data from the level sensor LIT-Z27.1.
Actuator Fault Detection Procedure for P-Z27.1 and P-Z27.2: If both pumps P-Z27.1 and P-Z27.2 are deactivated, then the zone of the level sensor LIT-Z27.1 must not decrease. If the above normal operating procedure is violated, a stuck-open fault is detected in pump P-Z27.1 or P-Z27.2.
The 6-tuple automata of the diagnosers for pumps P-Z27.1 and P-Z27.2 are of the form
where
. In
Figure 11 and
Figure 12, the state diagrams of the automata of diagnosers
are depicted for the cases
and
, respectively. Note that the states in red indicate that a fault took place, i.e., the pump stayed open. Moreover, note that Remark 6 is also valid for diagnosers
.
6.4. Fault Diagnosis of Pump PCL-Z28.1
Similarly to the diagnosis system proposed in [
22], a fault diagnosis system is developed for PCL-Z28.1 based on data from the chlorine-level sensor LIT CL-Z28.1.
Actuator Fault Detection Procedure of PCL-Z28.1: Ιf PCL-Z28.1 is deactivated, then the zone of the chlorine-level sensor LIT CL-Z28.1 must not decrease. If the above normal operating procedure is violated, then a stuck-open fault in pump PCL-Z28.1 is detected.
The 6-tuple automaton of the diagnoser is of the form
where
. In
Figure 13 and
Figure 14, the state diagrams of the automata of diagnosers
are depicted for the cases
and
, respectively. Note that the states in red color indicate that a fault took place, i.e., the pump stayed open.
Moreover, note that Remark 6 is also valid for diagnosers .
6.5. Fault Diagnosis of Pumps—Implementation in PLC
In the present subsection, the diagnosers implementation in ST language for PLCs is presented. In the following ST code (
Box 1), the implementation of diagnoser
for
is given. The diagnosers
for
and
for
follow directly the implementation of
.
Box 1. Program of Diagnoser .
TYPE
E_State : (
q_D1_mu_1,
q_D1_mu_2,
q_D1_mu_3,
q_D1_mu_4,
q_D1_mu_5
);
END_TYPE
VAR
currentState : E_State := q_D1_mu_1;
e_L_1_mu_1 : BOOL;
e_L_1_mu : BOOL;
e_P_A_3_1 : BOOL;
e_P_A_3_2 : BOOL;
ALARM_D1_mu : BOOL :=FALSE;
ALARM_MSG : STRING[50] := '';
END_VAR
CASE currentState OF
q_D1_mu_1:
IF e_L_1_mu_1 THEN
currentState := q_D1_mu_2;
END_IF;
q_D1_mu_2:
IF e_P_A_3_2 THEN
currentState := q_D1_mu_4;
ELSIF e_L_1_mu_1 THEN
currentState := q_D1_mu_1;
ELSIF e_L_1_mu THEN
currentState := q_D1_mu_3;
END_IF;
q_D1_mu_3:
IF e_L_1_mu THEN
currentState := q_D1_mu_2;
END_IF;
q_D1_mu_4:
IF e_P_A_3_1 THEN
currentState := q_D1_mu_2;
ELSIF e_L_1_mu_1 THEN
currentState := q_D1_mu_1;
ELSIF e_L_1_mu THEN
currentState := q_D1_mu_5;
ALARM_D1_mu := TRUE;
ALARM_MSG := 'Fault Detected';
END_IF;
q_D1_mu_5:
END_CASE;
END_PROGRAM
The diagnoser receives as Boolean inputs the events generated from the level sensor and the pump command/status signals. More specifically, “e_L_1_mu” and “e_L_1_mu_1” represent level measurement events, while “e_P_A_3_1” and “e_P_A_3_2” represent the corresponding pump events. Namely, each of the events “e_L_1_mu”, “e_L_1_mu_1”, “e_P_A_3_1”, and “e_P_A_3_2” gets its true value when the corresponding event , , , and has occurred at the current reading PLC cycle. The variable “currentState” stores the active state of the diagnoser automaton, whereas “ALARM_D1_mu” and “ALARM_MSG” are used to activate and communicate the fault indication. The enumerated type E_State here defines the five possible states of the diagnoser: “q_D1_mu_1”, “q_D1_mu_2”, “q_D1_mu_3”, “q_D1_mu_4”, and “q_D1_mu_5”. Depending on the occurrence of a level sensor event or pump event, the diagnoser moves to states q_D1_mu_1”, “q_D1_mu_2”, “q_D1_mu_3”, “q_D1_mu_4”, and “q_D1_mu_5”. If “e_L_1_mu” is true while the diagnoser is in “q_D1_mu_4”, then the diagnoser reaches state “q_D1_mu_5”, which corresponds to the fault-detected state. At this point, the alarm variable “ALARM_D1_mu” is activated, and the message Fault Detected is assigned to “ALARM_MSG”.
In the present subsection, the diagnosers implementation in ST language for PLCs is presented. In the following ST code (
Box 2), the implementation of diagnoser
is given. A quite similar implementation may be used for diagnosers
and
.
Box 2. Program of Diagnoser_.
TYPE
E_State : (
q_D1_1_1,
q_D1_1_2,
q_D1_1_3,
q_D1_1_4
);
END_TYPE
VAR
currentState : E_State := q_D1_1_1;
e_L_1_1 : BOOL;
e_P_A_3_1 : BOOL;
e_P_A_3_2 : BOOL;
ALARM_D1_1 : BOOL:=FALSE;
ALARM_MSG : STRING[50] := '';
END_VAR
CASE currentState OF
q_D1_1_1:
IF e_L_1_1 THEN
currentState := q_D1_1_2;
ELSIF e_P_A_3_2 THEN
currentState := q_D1_1_3;
END_IF;
q_D1_1_2:
IF e_L_1_1 THEN
currentState := q_D1_1_1;
END_IF;
q_D1_1_3:
IF e_P_A_3_1 THEN
currentState := q_D1_1_1;
ELSIF e_L_1_1 THEN
currentState := q_D1_1_4;
ALARM_D1_1 := TRUE;
ALARM_MSG := 'Fault Detected';
END_IF;
q_D1_1_4:
END_CASE;
END_PROGRAM
The structure of the ST code of is similar with the one of , where there are three Boolean variables representing the occurrence of events and four variables representing the possible states of the diagnoser.
7. Sensor Fault Diagnosis
A set of rules used for flow sensor fault diagnosis is first determined. Then, a fault diagnosis method is provided for all flow sensors in the form of diagnosis automata. The implementation of the proposed flow sensor diagnosers in Structured Text language for PLC use is presented. Finally, the behavior of the sensor diagnosers is demonstrated using field data.
7.1. Sensor Fault Diagnoser Design
In
Figure 1, it can be observed that after P-Z27.1 and P-Z27.2, there are two types of sensors installed: the pressure sensor PIT-Z27.1 and the flow sensor FIT-Z27.1. Since flow sensors are more sensitive to faults and malfunctions, the data coming from the pressure sensor are considered as more reliable [
36]. Hence, a sensor fault diagnosis system is developed for the flow sensor based on the data from the pressure sensor PIT-Z27.1 as well as data about activation/deactivation of the pumps.
Sensor Fault Detection Procedure for FIT-Z27.1:
If the measurement of the flow sensor FIT-Z27.1 is zero, then pressure sensor PIT-Z27.1 must not increase;
If the pumps P-Z27.1 and P-Z27.2 are deactivated, then the measurement of the flow sensor FIT-Z27.1 must become zero (after a short transient period).
The 6-tuple automaton of the diagnoser, for the first proposition of the procedure, is of the form
In
Figure 15, the state diagram of the automaton of diagnoser
is depicted. The diagnoser exploits the signals
and
that are produced by the PLC and denote that the pressure measurements increase or decrease, respectively. These signals should not be sensitive to small instant measurement variations but identify only clear upward or downward trends.
The 6-tuple automaton of the diagnoser, for the second proposition of the procedure, is of the form
In
Figure 16, the state diagram of the automaton of diagnoser
is depicted. The diagnoser exploits the activation/deactivation signals of the two pumps. Note that states 1 and 3 are normal states. State 1 corresponds to zero flow and deactivated pumps, while state 3 corresponds to non-zero flow and activated pumps. The state in red (state 4) indicates that either the flow sensor erroneously measures flow values greater than zero or that a pump has stuck open (type 1 fault). The state in yellow (state 2) indicates that either the flow sensor erroneously measures flow values equal to zero or that a pump has stuck closed (type 2 fault). In both cases, the fault is identified provided that the diagnoser remains in the faulty state.
The fault identified by state 2 is valid provided that the corresponding automaton of the activated pump is not at its first state, namely if either is at a state with or is at a state with .
7.2. Fault Diagnosis of Sensors—Implementation in PLC
In the present subsection, the sensor diagnosers implementation in ST language for PLCs is presented. In the following ST code (
Box 3), the implementation of diagnoser
is given.
Box 3. Program of Diagnoser_.
TYPE
E_State : (
q_D4_1,
q_D4_2,
q_D4_3,
);
END_TYPE
VAR
currentState : E_State := q_D4_1;
e_F_1_1 : BOOL;
e_P_1_I : BOOL;
e_P_1_D : BOOL;
ALARM_D4 : BOOL:=FALSE;
ALARM_MSG : STRING[50] := '';
END_VAR
CASE currentState OF
q_D4_1:
IF e_F_1_1 THEN
currentState := q_D4_2;
ELSIF e_P_1_I THEN
currentState := q_D4_3;
ALARM_D4 := TRUE;
ALARM_MSG := 'Fault Detected';
END_IF;
q_D4_2:
IF e_F_1_1 THEN
currentState := q_D4_1;
END_IF;
q_D4_3:
ALARM_D4 := TRUE;
ALARM_MSG := 'Fault Detected';
IF e_F_1_1 THEN
currentState := q_D4_2;
ALARM_D4 := FALSE;
ALARM_MSG := '';
ELSIF e_P_1_D THEN
currentState := q_D4_1;
ALARM_D4 := FALSE;
ALARM_MSG := '';
END_IF;
END_CASE;
END_PROGRAM
The structure of the ST code of is similar with the one of , where there are three Boolean variables representing the occurrence of events and three variables representing the possible states of the diagnoser.
In the following ST code (
Box 4), the implementation of diagnoser
is given.
Box 4. Program of Diagnoser_.
TYPE
E_State : (
q_D5_1,
q_D5_2,
q_D5_3,
q_D5_4
);
END_TYPE
VAR
currentState : E_State := q_D5_1;
e_F_1_1 : BOOL;
e_P_A_1_1 : BOOL;
e_P_A_1_2 : BOOL;
e_P_A_2_1 : BOOL;
e_P_A_2_2 : BOOL;
ALARM_D5 : BOOL:=FALSE;
ALARM_MSG : STRING[50] := '';
END_VAR
CASE currentState OF
q_D5_1:
IF e_F_1_1 THEN
currentState := q_D5_4;
ALARM_D5 := TRUE;
ALARM_MSG := 'Fault 1 Detected';
ELSIF e_P_A_1_1 OR e_P_A_2_1 THEN
currentState := q_D5_2;
ALARM_D5 := TRUE;
ALARM_MSG := 'Fault 2 Detected';
END_IF;
q_D5_2:
IF e_F_1_1 THEN
currentState := q_D5_3;
ALARM_D5 := FALSE;
ALARM_MSG := '';
ELSIF e_P_A_1_2 OR e_P_A_2_2 THEN
currentState := q_D5_1;
ALARM_D5 := FALSE;
ALARM_MSG := '';
END_IF;
q_D5_3:
IF e_F_1_1 THEN
currentState := q_D5_2;
ALARM_D5 := TRUE;
ALARM_MSG := 'Fault 2 Detected';
ELSIF e_P_A_1_2 OR e_P_A_2_2 THEN
currentState := q_D5_4;
ALARM_D5 := TRUE;
ALARM_MSG := 'Fault 1 Detected';
END_IF;
q_D5_4:
IF e_F_1_1 THEN
currentState := q_D5_1;
ALARM_D5 := FALSE;
ALARM_MSG := '';
ELSIF e_P_A_1_1 OR e_P_A_2_1 THEN
currentState := q_D5_3;
ALARM_D5 := FALSE;
ALARM_MSG := '';
END_IF;
END_CASE;
END_PROGRAM
The structure of the ST code of is similar with the one of , where there are five Boolean variables representing the occurrence of events and four variables representing the possible states of the diagnoser.
7.3. Diagnoser and Field Data
According to the parameters of the SCADA system, the resolution of the pressure sensor is 0.1 bar, and the range of the values of the sensor is from 0 bar to 25 bar. The resolution of the flow sensor is 0.1 m3/h, and the range of the values of the sensor is from 0 m3/h to 30 m3/h. Hence, for the two DES models, it holds that , and , with the 1st zone of the flow sensor corresponding to zero value.
The field data of the pressure sensor PIT-Z27.1 are presented in
Figure 17 for the time interval starting at 9:30 and ending at 10:00. The data of the flow sensor FIT-27.1 are equal to 0 m
3/h during this time interval. Initially, pumps P-Z27.1 and P-Z27.2 are deactivated. Hence, the value of the flow sensor is 0 m
3/h, and the value of the pressure is about 12 bar. At 9:42, pump P-Z27.2 is activated. The outflow rate of this pump is regulated to 80% of its maximum value. The value of the pressure sensor starts to increase above 12 bar, but the value of the flow sensor remains 0 m
3/h. Thus, the flow sensor is in faulty mode. In
Figure 18, the diagnoser is presented where an alarm system has been created. It is observed that the fault was detected successfully in 9:43.
Remark 7. Each diagnoser is designed independently to cover diagnosis of particular devices in a specific condition of operation. In other words, the proposed diagnosis scheme has modular architecture, not requiring interaction among the diagnosers. According to this analysis, the experimental validation covers both the overall system operation and the performance of the individual diagnosers.
The proposed modular diagnosis scheme was also compared with a baseline diagnosis method (low level) where the stuck=open faulty case may be only indirectly detected when it results in tank overflow. In this baseline approach, an overflow alarm is generated only when the water level reaches the corresponding predefined overflow threshold. Therefore, if an actuator fault occurs, for example, when a pump remains active although a deactivation command has been applied, the operator does not detect the fault and thus cannot physically stop the faulty actuator until the system is informed about the hazardous condition, which happens only when the tank level approaches the overflow limit. On the other hand, the proposed modular diagnosis method can detect possible faults at earlier stages. More specifically, when a command to deactivate the pump takes place but the water level continues to increase, the corresponding diagnoser identifies the fault before the overflow threshold is reached. The proposed diagnosis scheme is a medium-level method. Higher-level methods include machine learning or grey box modeling. However, the proposed medium-level diagnosis method has several practical advantages, as machine learning and grey box modeling methods usually require increased computational resources, extended communication infrastructure, and integration of IoT/cloud computing. These additional resources may introduce communication delays, instability, data loss, and additional cost.
Remark 8. Even though fault diagnosis is performed locally and quickly at the local level, the operator is informed at the SCADA sampling rate.
8. Conclusions
The chlorinated water station of the Delfino community, Greece, was studied. The DES models of all the devices (flow sensors, pressure sensors, level sensors, and pumps) were presented. Regarding the DES model of the pumps, both activation/deactivation functionality and regulation of the output flow of the pump were modeled. The DES models were validated using field data extracted from the station’s monitoring system. Safety requirements for protecting the pump from dry running and the tanks from overflowing, expressed as corresponding rules and translated to a set of regular languages, were implemented as supervisor automata. The field data of the controlled automaton of the pumps showed the effect of the supervisors on the performance of the station. A modular fault diagnosis system for the pumps was developed and validated using the field data of the level sensors. Finally, a flow sensor fault diagnosis system was developed and validated using field data of the sensors and the pumps’ activation/deactivation data. The implementation of the diagnosers automata in ST language for PLC was shown.
In many real water stations, pumps operate through conventional ON/OFF commands generated by PLC systems. This architecture remains attractive because of its simplicity, robustness, low implementation cost, and direct compatibility with supervisor control and fault diagnosis algorithms. Other architectures may integrate PLCs with variable-frequency drives (VFDs), enabling variable-speed pump operation instead of simple transitions between fully activated and deactivated states. Toward this direction, the present paper puts forward a DES model that represents different operating ranges of the pump output flow, providing a first basis for modeling variable flow behavior within the proposed discrete event framework. Although the present work focuses mainly on the ON/OFF operation, the proposed supervisor and diagnosis framework can be extended in future work to include VFD-driven pumps. In addition, application of the proposed supervisor control and fault diagnosis method to more complex chlorinated water stations with more tanks and sensors is under study. Finally, the influence of the proposed supervisor control and fault diagnosis scheme to large-scale water networks is also under investigation.