3. Verification on a Benchmark Feeder
The central spanning-tree and sector identities used in
Section 4,
Section 5,
Section 6 and
Section 7 concern finite objects and can be independently checked by exhaustive enumeration on a feeder small enough to enumerate. We do this once, here, before the statements are used, so that the reader may take the remaining sections as computation rather than as assertion; the planning sensitivity is checked against finite differences and the dynamical statements by exact master-equation computation, the latter in
Section 8.
3.1. The Benchmark Feeder
The benchmark has
nodes and
line sections: 32 forming the built-out branches and 5 tie sections, normally open, joining branches to one another. It is the standard 33-node distribution test system of Baran and Wu [
1], used here with its own published resistances; the complete section list is given in
Appendix A. The head section leaves the substation bus, which has a degree of one, so that section is the only bridge; the remaining 36 sections each lie on at least one loop and are therefore switchable.
We use a published benchmark deliberately. The purpose of this section is verification of exact identities, for which a fully specified and reproducible network is worth more than a proprietary one; validation against measured outage data is a separate task, noted among the limitations in
Section 10.
3.2. Enumeration of Admissible Configurations
Exhaustive search over the ways of leaving five sections open, retaining those whose complement is connected and spanning, yields . As an independent check of both the topology and the enumeration code, Kirchhoff’s matrix-tree theorem applied to the weighted Laplacian gives the same weighted total to ten significant digits, and the unweighted determinant returns 50,751 exactly.
This network is close to the practical ceiling for enumeration: with five independent loops the search is instantaneous, but the count grows multiplicatively with the number of tie sections. That asymmetry is the point of the paper: Y is a single matrix obtained from one pseudoinverse, and its cost does not grow combinatorially with the number of loops.
3.3. The Kernel
Assembling
Y gives a matrix symmetric and idempotent to machine precision, of rank 32, with
, which is Proposition 1(ii). Exactly one diagonal entry equals one, the head section, confirming Proposition 1(iv).
Table 3 lists the six sections whose energisation is least certain.
The second entry of
Table 2 deserves comment: T1 and T3 are two distinct tie sections, on different branches, that compete with one another more strongly than either competes with its own neighbours. Such pairs are not apparent from the single-line diagram and are exactly what the kernel is for.
3.4. The Determinantal Law
Table 4 compares the enumerated probability that a set of sections is energised with the determinant of (
3) for subsets of up to eight sections.
All discrepancies are at the level of double-precision round-off (
Figure 3). We stress that this is a genuine check and not a tautology: the left-hand side is a combinatorial sum over 50,751 enumerated configurations and the right-hand side is a determinant of a matrix built from a pseudoinverse; the two computations share no code path.
3.5. The Electrical Readings, the Sector Family and the Restoration Weights
Computing from the Laplacian pseudoinverse, and separately computing the self transfer-current factor of each section by injecting a unit current at its terminals, reproduces the diagonal of Y with maximum discrepancy . The equivalent form , with the equilibrium current share across the section and the commute time between its terminals, agrees to the same precision, and .
De-energising one uniformly chosen section of a configuration drawn from the ensemble and computing the exact resulting law over 31-section forests reproduces
of (
4) with a maximum relative error of
; two independent faults reproduce
to the same precision. For partial configurations with
energised sections both sides of (
5) agree to
, and the consistency check of Corollary 1 holds to
. A quantity defined through the determinantal ensemble is thus computed correctly by a purely electrical procedure that involves no probability at all.
Increasing the conductance of a section and recomputing the kernel by finite differences reproduces Corollary 6 with maximum error at a step of , and the sum of the predicted changes over all sections vanishes to .
3.6. Robustness to the Weighting Convention
Replacing
by
, the convention of the direct-current power-flow approximation, leaves
and changes the entries modestly: the least certain section is still T1, with probability
instead of
;
gives
.
Section 2 explains why
is the convention we adopt and
Section 10 records how far the ranking moves under the others. Raising the conductances to a power
as in (
1) tightens the ensemble as expected: the smallest diagonal entry falls from
at
to
,
and
at
, while the number of sections energised in essentially every configuration rises from 1 to 4 and then to 16. The parameter
therefore controls how much switching freedom the ensemble ascribes to the feeder, and the identities hold along the whole family.
The central spanning-tree and sector identities have thus been verified against exhaustive enumeration of 50,751 configurations, with discrepancies at double-precision round-off; the planning sensitivity was checked against finite differences here, and the dynamical statements are checked separately, by exact master-equation computation, in
Section 8. From this point on we use the kernel and dispense with enumeration, which for feeders of realistic size is not merely expensive but impossible.
4. Random Outages and the Restoration Order
4.1. Partially Energised Feeders
A sequence of faults leaves the feeder with fewer than energised sections. Write and, for , let be the k-section configurations that are electrically admissible, that is, contain no closed loop. A configuration splits the feeder into islands, exactly one of which contains the substation bus. We call the vacant rank.
The natural family of laws on partially energised feeders is
At
this is the operating ensemble (
1). For
it is a determinantal law on
k-edge spanning forests; the normalisation is
, which holds because
Y is a projection of rank
r. For
the kernel is a weight matrix in the fixed-size law (
4), not a correlation kernel.
The question of this section is whether (
4) is preserved by the two elementary mechanisms a feeder is subject to, random faults and repair, and if so what the preserving repair mechanism is. The answers are sharply asymmetric.
4.2. A Ladder Identity
Lemma 1. Let with . Then .
Proof. Electrical. Divide by
. By (
3),
is the conditional probability that
e is energised given that all of
B is. Summing over
gives the conditional expectation of the number of energised sections outside
B, which is
for every conditioning event.
Algebraic, valid for any projection. Assume and let . Then , so the sum equals . The block of gives , whence . If both sides vanish by Fischer’s inequality. □
The first proof explains the identity; the second shows it is a property of the projection alone, and therefore survives to the generator layer of
Section 6, where the kernel is not electrical.
4.3. Random Faults Preserve the Model Class
Theorem 2 (blind de-energisation is exact). Let de-energise one uniformly chosen section. Then for every feeder and every . Consequently, after any number m of independent random faults the surviving configuration is distributed exactly as , and .
Proof. For the mass arriving at C is , which by Lemma 1 and equals . Iterating gives the multi-step statement, since a composition of uniform single deletions yields a uniformly chosen subset. The marginal follows from the ladder identity applied to . □
Random faults never take the feeder out of its model class. Whatever sequence of independent failures occurs, the surviving configuration is again a determinantal forest with the same kernel, so every quantity computed in
Section 2 remains available in closed form after the event, with no re-derivation and no simulation; the energisation profile is simply rescaled. Here “blind” means uniformly at random and independent of the layout; correlated events are not covered, and
Section 10 quantifies the departure. Theorem 2 also propagates the ensemble rather than creating it: it assumes the pre-fault configuration is distributed as
, and
Section 10 is explicit about which results need that and which do not.
4.4. No Restoration Rule Can Ignore the Resistances
Theorem 3 (no blind restoration). Let G be connected with nontrivial cycle space, let b be the number of its bridges, and let . There is no Markov kernel U from to , chosen once for the skeleton and independent of the conductances, such that for every assignment of positive conductances.
Proof. Suppose such a U exists. The bridges of a connected graph form a forest, so, since , there is a configuration containing all of them; fix one such B and let be arbitrary. The set is non-empty because , and none of its elements is a bridge because B already contains every bridge; pick . Let decrease to zero with the other conductances fixed. Since f is not a bridge, stays bounded and . By Fischer’s inequality for every , so for all such D, in particular ; whereas converges to the corresponding quantity for , which is positive because B is a forest of and is connected. From we conclude , and since U does not depend on the conductances, . As C was arbitrary, the row of U at B has total mass zero, contradicting stochasticity. □
Two features of the argument are worth naming. It applies to an arbitrary Markov kernel and not only to kernels supported on single-section additions: all it uses is that some section of
C lies outside
B. And the hypothesis
is mild. A two-edge-connected feeder has
and the statement holds for every
k; the benchmark feeder of
Section 3 has
, its head section, so the statement holds for every
and the only excluded case is the empty configuration. What the hypothesis asks is that the feeder be carrying at least as many energised sections as it has structural bridges, and those bridges carry restoration weight one in any case, being mandatory reconnections.
Theorem 3 is stronger than the corresponding statement for abstract determinantal families, and the strengthening is the practically relevant one. The rule U is allowed to know the single-line diagram in full and is denied only the numerical values of the conductances, and even so, no such rule exists. Knowing the topology is not enough to restore the feeder correctly; the resistances enter irreducibly.
4.5. The Canonical Restoration Rule
One upward mechanism stands out, is computable, and Proposition 2 says in what sense it is singled out.
Stated as a procedure before it is stated as a determinant: take the post-fault network, short-circuit every section that is still energised, measure the resistance seen across the terminals of a candidate section, and multiply by the candidate’s conductance. The number so obtained is the candidate’s own transfer-current factor in the shorted network. Theorem 4 says that these numbers are exactly the restoration probabilities of the mechanism that reverses the random fault, and Algorithm 1 is nothing more than this procedure.
Theorem 4 (determinant-ratio restoration)
. For with define . Then U is a stochastic kernel from to , , andwhere is the feeder with every energised section of B contracted. Proof. Stochasticity is Lemma 1, and
so no mass reaches inadmissible configurations. For
the arriving mass is
, using
. For (
5), the ratio equals
by (
3); the conditional law of the ensemble given
B is the ensemble of
(Lemma A1), and Proposition 1(i) applied there evaluates it as
. □
Proposition 2 (the rule is the time reversal of the fault). For every , , both sides equalling when and zero otherwise. Consequently U is the unique Markov kernel reversing uniform blind de-energisation with respect to .
Corollary 1 (total restoration pressure). , whatever the feeder and whatever the fault pattern.
Remark 3 (in what sense the rule is unique)
. Theorem 3 excludes conductance-independent restoration; it does not say that the conductance-aware intertwiner is unique, and it is not. Take the triangle with equal conductances, so and both and are uniform, and for let the kernel send to with probability a and to with probability , to with probability and to with probability a, and to with probability a and to with probability . Then for every a, and the determinant-ratio rule is the case . Upward intertwiners therefore form a family. What singles out (5) is Proposition 2: among all of them it is the unique kernel that reverses blind de-energisation. Every statement in this paper about the rule being canonical is to be read in that sense and in no other. Three properties make (
5) usable rather than merely canonical.
Radiality is automatic: if a de-energised section joins two nodes already connected through energised ones, its terminals are identified in
, the effective resistance is zero and so is the weight.
Bridges of the post-fault network get weight one: if
e is the only remaining connection between two islands then
. And Corollary 1 is a free consistency check: any implementation error is detected by the weights failing to sum to the island count minus one.
4.6. Computing the Weights
We record how the weights are obtained, and then what they do and do not tell an operator. The reader should note now that Theorem 4 is a statement about which mechanism reverses the fault, not a claim that the weights rank repairs by operational value;
Section 4.8 establishes that they do not.
| Algorithm 1 Restoration weights |
Input: feeder graph G with conductances g; set B of energised sections; set F of faulted or open sections.
- 1:
Contract every section of B, merging its terminals, to obtain on nodes. - 2:
Assemble the Laplacian of from the sections not in B and factorise it. - 3:
For each compute between the contracted terminals and set . - 4:
Check ; abort on mismatch. - 5:
Report the weights; after any restoration move that section to B and return to step 1. Cost: per iteration, or per candidate with a rank-one update.
|
The weights are sequential and must be recomputed after each restoration: the value of a candidate depends on what is energised, not only on the feeder. In particular a section with weight zero at one step may acquire a positive weight at the next.
4.7. Worked Example: Three Faulted Sections
Sections L04, L05 and L06 are lost, leaving four islands. Algorithm 1 gives the weights of
Table 5, summing to
as Corollary 1 requires. Note that L07 and L28 are ordinary built-out sections that happen to stand open in the configuration the faults struck; they are not tie sections.
Figure 4 shows the islands and the weights before and after the first restoration.
The list is read as a structural diagnostic, and three features of it are worth naming. The zero weights are actionable and exact: every section outside the five listed has weight zero, meaning its terminals are already joined through energised sections, so restoring it would close a loop and cannot reduce the island count at this step. The weights say how replaceable each restoration is: weight on L06 means a large share of the admissible completions pass through it, and a weight approaching one would mean it is the only remaining connection between two islands; in this scenario no candidate is unavoidable, which is itself information. The weights do not point at the substation: the section with the largest weight reconnects no load at all, while the largest load is reconnected by L28 with weight . The kernel is built from a symmetric network and contains no distinguished node, so it cannot and does not rank restorations by load recovered.
4.8. The Weights Are Not a Dispatch Order
Because (
5) is canonical it is tempting to read it as a repair priority. We tested that reading and it fails, and we report the failure because the temptation is strong and the consequence of yielding to it is a worse restoration sequence.
Over 250 episodes, with faults drawn uniformly from a configuration of the operating ensemble and nodal demands as in
Appendix A, we compared four policies: ordering by the weights; greedy service, restoring the section that reconnects the most load; working outward from the substation; and random order. The metric is the fraction of feeder load connected to the substation after
j restorations.
Table 6 reports the mean over the episodes with the standard error of the mean; the four policies are run on the same 250 episodes, so the differences between rows are paired. The dispersion across episodes is large, of the order of
, because the episodes differ in how much load the three faults cut off.
Ordering by the weights recovers load more slowly than greedy service and more slowly than working outward from the substation, by margins of many standard errors, and no faster than random order: the paired difference between random order and the weights is after one restoration and after two, so the weights are indistinguishable from random order at the first step and behind it thereafter. The reason is structural and visible in the definition: the kernel is built from a symmetric network with no distinguished node, so the weights know nothing about where the substation is, and a mechanism blind to the source cannot prioritise service to it.
Nor do the weights maximise the feeder’s remaining freedom. Writing
for the weighted number of spanning trees of
H, the weight admits the third form
verified numerically to
, so the weight is the share of admissible completions passing through
e, a share carrying the factor
and therefore pulled towards low-resistance sections. In our episodes random order retains marginally more freedom than the weights do.
What the comparison establishes is a division of roles.
For deciding where to send a crew, use a service-based ordering; nothing in this paper improves on greedy service for that purpose.
For the model, the mechanism (
5) is a canonical representative rather than a necessity. By Proposition 3 the determinantal form and the per-section statements of
Section 5 hold for
any repair that intertwines the sectors at the same total rate, and other conductance-aware intertwiners exist, as Remark 3 shows. What (
5) alone does is reverse the fault, which makes it the unique member of that class with a reversible stationary law. By Proposition 4 the occupancy indices survive even repair policies that do not intertwine the sectors, provided the total rate is the same.
For diagnosis, the weights carry information no service ordering contains which restorations are unavoidable, which are redundant at the current step, and how much of the completion mass each candidate carries.
Section 6 exhibits a milder case. In the generator layer the same determinant ratio measures novelty of a unit’s output profile relative to what is running, which is at least a quantity an operator might care about, whereas here it measures nothing the utility wants. Even there the alignment is empirical rather than proved. Whether a canonical mechanism is also a useful rule is never settled by the algebra alone.
5. Availability and Reliability in Closed Form
5.1. The Maintained Feeder
Section 4 treated a single fault event. A feeder in service is subject to a stream of them. We model this as a continuous-time Markov process on
. Fix a fault intensity
per energised section and a restoration intensity
, and let the generator act on functions of
by
By Lemma 1 the total restoration rate out of a
k-section configuration is
, independent of which sections have failed: the crew effort deployed is proportional to the number of islands to be reconnected. We return in Proposition 5 to a fixed crew.
The state of the process is the set of energised sections. A de-energised section may be faulted and awaiting repair, or healthy and open by switching; the two are different actions on different time scales, and the process does not distinguish them. What is modelled is energised-section occupancy, not component availability: is the rate at which an energised section ceases to carry load, and the rate at which a de-energised one is brought back, whether by a repair or by a switching operation.
Faults strike energised sections at a common rate
. In a real feeder the rate depends on section length, construction, age, condition and exposure, and the assumption is not a notational simplification: uniformity is what makes de-energisation exchangeable, and with section-specific rates
the sector family is no longer mapped onto itself, so neither Theorem 2 nor the closure of Theorem 5 survives, and the occupancy chain ceases to be autonomous. A weighted analogue would require a deletion mechanism whose rates are matched to the ensemble, and we do not have one;
Section 10 returns to this.
5.2. Exact Solvability
Theorem 5 (closure and explicit law)
. Let be the law of the process generated by (7) and any mixture of sectors. Then for all , wherethe equations of r independent two-state units. If is binomial with parameter then is binomial withand for all . The stationary law is and the occupancy relaxes at rate . Proof. The death part applied to
has exit rate
and post-jump law
by Theorem 2; the birth part has the configuration-independent exit rate
by Lemma 1 and post-jump law
by Theorem 4. Hence the span of the sectors is invariant and the coefficients obey (
8), whose rates are those of
r independent binary units, so a binomial initial condition propagates as binomial with
. It remains to identify the binomial mixture as a determinantal law, which is Proposition A1 of
Appendix B. □
The case is the one an engineer starts from: a fully commissioned, radially complete feeder.
The proof used two properties of the upward mechanism and no others: that the total rate out of a configuration in sector k is , the same for every configuration in that sector, and that the post-jump law is . Neither is peculiar to the determinant-ratio kernel, and it is worth recording what that implies.
Proposition 3 (the closure does not need the canonical repair). For each let be any Markov kernel from to , supported on single-section additions, with , and let the upward rates be for . Then every statement of Theorem 5 remains valid verbatim, including and the stationarity of .
Proof. Immediate from the proof of Theorem 5, which uses only the two properties just named. □
The determinant-ratio kernel is therefore not distinguished by making the dynamics exactly solvable; the whole class of sector intertwiners does that. It is distinguished by Proposition 2, as the unique time reversal of uniform deletion, and consequently as the unique member of the class for which the stationary law is reversible in the sense of Corollary 4. On the triangle of Remark 3, with and , every member of the one-parameter family reproduces to in total variation and leaves stationary to , while the detailed-balance residual is at , at and exactly zero only at , the determinant-ratio rule.
5.3. Structural Availability Measures
Corollary 2. Under with :
- (i)
The number of energised sections is ;
- (ii)
The number of islands is , with stationary mean ;
- (iii)
The feeder is radially complete with probability ;
- (iv)
Section e is energised with probability ;
- (v)
The joint law of any k switching states is .
Item (ii) is the simplest of these measures: the expected number of islands is one plus the number of switchable sections times the fault duty cycle , and it involves no topology beyond N. Topology enters (iii) and (iv).
These are structural availability measures. They are not the customer-based indices utilities report—SAIFI, SAIDI, CAIDI, EENS—which depend on which sections are de-energised and on how many customers sit behind them. The exact sampler of Corollary 3 supplies the configurations needed to evaluate those by simulation; deriving them in closed form from the kernel is left for future work.
Proposition 4 (the occupancy indices do not depend on the repair policy). Replace the repair mechanism by any allocation of the same total rate among the admissible candidates, in particular by service priority, which places the whole rate on the candidate reconnecting the most load. Then the number of energised sections evolves exactly as before, so (i), (ii) and (iii) of Corollary 2 continue to hold. Statements (iv) and (v) need not hold; by Proposition 3 they do hold whenever the allocation intertwines the sectors, and service priority is not such an allocation.
Proof. Out of any configuration in sector
k the total exit rates are
downwards and
upwards, whatever the allocation. The occupancy is therefore an autonomous Markov chain with the rates of (
8), and (i)–(iii) are functions of it alone. □
We verified this on a network small enough to enumerate its 194 admissible partial configurations and compute the stationary law of both mechanisms exactly. Under service-priority repair the stationary law lies at total-variation distance
from
, with per-section probabilities departing from
by as much as
; yet the occupancy law reproduces the binomial to
, the expected island count is
against the formula
, and the probability of radial completeness is
against
. Service-priority repair also delivers the higher served load,
against
, consistent with
Section 4.8.
The division is sharp. The occupancy measures of Corollary 2(i)–(iii) are robust to how the crew is dispatched; the determinantal form and the per-section profile are not.
Corollary 3 (exact sampling). A sample of is obtained by drawing an admissible configuration from the operating ensemble and de-energising each of its sections independently with probability . The model class is closed under independent thinning, and quantities not available in closed form, such as the number of served nodes, are obtained by cheap exact sampling.
5.4. Reversibility, and What the Determinantal Form Costs
Corollary 4 (detailed balance). Let , the mass function of . Then for , which reduces to . The process is reversible with respect to .
Proposition 5 (fixed crew)
. Replace the birth part of (7) by a total restoration rate β independent of the configuration, allocated in proportion to the weights. Then the sector closure still holds, but the occupancy chain has birth rates β and death rates , with stationary law the truncated Poisson on . The stationary configuration law is the corresponding mixture of sectors, which is not determinantal. The contrast is informative rather than a defect. Determinantal form at all times is bought by the assumption that repair capacity follows damage; if capacity is capped, the feeder still stays within the sector family, so the restoration weights, the ladder identity and the exactness of blind faults all survive, but occupancy concentrates differently. Both cases are one-dimensional and solvable; only the first is determinantal.
Corollary 5 (seasonal and campaign maintenance)
. Let and be piecewise continuous. Then the closure remains valid with (9) replaced by the solution of . A feeder started from and maintained under any schedule is a determinantal feeder with kernel at every instant. No stationary law and no uniform relaxation rate are claimed in this case. Planning availability thus reduces to a one-dimensional deterministic control problem for , around which the realised number of energised sections fluctuates with binomial statistics.
5.5. Numerical Illustration and Scope
Table 7 sets the closed forms of Corollary 2 beside Monte Carlo estimates at four values of the per-section availability.
The Monte Carlo columns rest on 60,000 independent draws of the exact sampler, and their standard errors are reported in the table; the exact columns carry none. The section and island counts are reproduced by the formulas to sampling accuracy; the served-node column uses the exact sampler of Corollary 3, since it depends on which sections are energised and not only on how many. At a per-section availability of
the feeder is fully connected less than one-fifth of the time, while the expected number of islands is still under three.
Figure 5 shows the island-count distribution at that availability and the recovery of the section count after a storm.
Theorem 5 rests on two assumptions.
Repair intertwines the sectors at total rate : by Proposition 3 any such repair, canonical or not, gives the determinantal form and (iv) and (v) of Corollary 2, while (i)–(iii) need only the total rate, by Proposition 4.
Faults strike energised sections independently and uniformly: this is the appropriate model for the accumulation of unrelated defects and not for a single event damaging several adjacent sections, and
Section 10 quantifies the departure and sets out the three levels at which the results of this paper assert anything about a real feeder.
6. Distributed Generators: The Same Calculus on a Different Ground Set
6.1. A Second Failure Layer
A feeder carrying distributed generation fails in a second, independent way: the generators themselves drop out through converter trips, protection operations, mechanical faults or maintenance, while the network remains intact. The ground set is now the n generators, and substitutability is not topological: two units are substitutes when their output profiles are alike. The entire calculus transfers without modification, because the algebraic proof of Lemma 1 used only that Y is an orthogonal projection.
6.2. The Generation-Mode Projection, and What It Is Not
Let
X be the
matrix of measured output, each column divided by the installed capacity of its unit. Centre
X, compute its singular value decomposition, retain the
r leading right singular vectors as the rows of an
matrix
with orthonormal rows, and set
The rows of
are the generation modes; the
jth column is the loading vector of unit
j; and
is the squared
r-dimensional volume spanned by the loadings in
B, as in volume sampling [
37,
38].
Two properties of this geometry must be stated at once, because they bound what the calculus may claim. First, the construction is whitened: has orthonormal rows, so the singular values of the output matrix have been divided out. The physical profile of unit j restricted to the retained subspace is and not , so a determinant ratio built from P is not a marginal gain in output variance. Second, in the whitened geometry the natural coverage functional is degenerate: writing for the orthogonal projection onto the span of the loading vectors indexed by B, one has for every independent B, because . Whichever k units are running, the whitened coverage is the same number. We therefore call the quantity below a geometric novelty score, not a coverage gain, and we claim no output-variance optimality for it anywhere.
The rank r is the number of independent generation regimes the fleet can distinguish. The sector laws are .
Proposition 6. Lemma 1 holds verbatim for P, and equals the squared norm of the component of the loading vector of unit j orthogonal to the span of the loading vectors of the units in B.
Proof. The first statement is the algebraic proof of Lemma 1, which used only and . For the second, is the Schur complement , and is the Gram matrix of the loading vectors indexed by B. □
So is the squared residual novelty of unit j in the whitened retained-mode geometry—the part of its loading vector , not of its physical profile , that the running units do not span. Summed over the failed units these residuals give , the number of generation regimes not currently covered; when the running loadings are linearly independent this is .
6.3. Blind Loss, Blind Repair, and the Repair Rule
Theorem 6. Let generators fail independently and uniformly at random. Then the surviving fleet is distributed exactly as the sector law of the corresponding size, for any number of failures; and no repair rule chosen independently of P can return the fleet to the sector family for all rank-r projections P with . The rule is stochastic and satisfies ; upward intertwiners are not unique, by Remark 3, and what singles this one out is that it is the unique kernel reversing uniform blind loss.
Remark 4. The witnesses in the impossibility argument (Appendix B) are degenerate fleets. The obstruction is not an artefact of that degeneracy: the set of projections for which a given candidate rule fails is open, so failure persists on a neighbourhood of each witness. Two distinct objects share this score and should not be conflated. Theorem 6 describes a stochastic kernel: it restores unit j with probability proportional to , and it is that randomised mechanism which reverses blind loss and carries one sector onto the next. Algorithm 2 restores instead the maximiser of . Greedy selection reverses nothing, does not map the sector family onto itself, and inherits none of the exactness statements of this section; it is a heuristic suggested by the same geometry, and we present it as one.
The parallel with the network layer is exact. There, the repair weight is the resistance seen across a section once everything still energised has been shorted; here, it is the residual of an output profile once everything still running has been projected out. In both cases the weights sum to the number of gaps: islands minus one there, uncovered modes here.
| Algorithm 2 Fleet repair by novelty score |
Offline, once: from the output history compute and P.- 1:
Let B be the units currently running and F the failed units. - 2:
Form and compute a QR factorisation of . - 3:
For each compute . - 4:
Check , which the QR of step 2 supplies; abort on mismatch. When the running loadings are independent this reads , but the rank form is the one to implement, since a running fleet may well contain redundant units. - 5:
Dispatch to ; on repair move j to B and return to step 2.
|
6.4. Worked Example: The Model Fleet
The model fleet has twelve units in three clusters, each with two morning-weighted and two evening-weighted profiles,
generation modes and capacities between 5 and 15 MW; four units are running and eight are down.
Table 8 ranks the failed units by novelty score and, beside it, by installed capacity.
The two orders are almost reversed at the top, and the reason is structural. Unit #4 is the largest at 15 MW and carries the lowest score: it shares a cluster and a duty profile with unit #3, which is running, so its profile is already reproduced and restoring it adds capacity but no new regime. Unit #8, at 8 MW, covers a regime nothing running covers.
The normalised determinantal restoration kernel applies only below the rank, since its factor is undefined at ; on this fleet that leaves the first repairs. The geometric score itself remains defined throughout and simply vanishes once the running units span the retained mode space, which is what happens here after two repairs. Beyond the rank, by Proposition 7, blind addition is exact and the projection-geometric criterion ceases to distinguish candidates at all. It does not follow that no ordering can beat any other: capacity, energy, location and any regime outside the retained rank continue to distinguish them, and only this criterion falls silent. The curves show the criterion falling silent: they separate sharply over the two score-governed repairs and then converge. After those two repairs the variance not reproducible from the running units is times larger under capacity ranking and times larger under random order. The trade-off is explicit: over the same two repairs the score recovers 13 MW against 29 MW for the capacity policy.
The metric plotted in
Figure 6d is the physical one, and we define it explicitly because it is not the quantity the score optimises. Writing
X for the centred, capacity-normalised output matrix and
for its columns indexed by the running units, the
reproducible output variance is
the fraction of the fleet’s output variance recoverable by least squares from the units that are running. Unlike the whitened coverage of
Section 6, this quantity does depend on which units are running, because it carries the singular values that the whitening divides out.
6.5. Which Objective This Serves, and Above the Rank
We state the boundary plainly, because the temptation here is the mirror image of the one resisted in
Section 4.8. There the determinant ratio optimises nothing the utility wants; here it optimises something geometric, and the question is whether that something is what an operator wants. It is not the same thing as output variance, for the reason given above, and the two orderings genuinely differ: on the model fleet the novelty score ranks unit 8 first while the marginal gain in
of (
11) ranks unit 12 first, though the leading four units are the same set and their variance gains are within four per cent of one another. What can be said is that the score and the physical gain are aligned in this example, not that one optimises the other.
If the objective is recovered energy, the correct dispatch is by lost capacity and no calculus is needed. The score measures novelty of a unit’s profile relative to what is running, which matters when the feeder carries a firm-capacity or ramp obligation, when forecast quality is contractually relevant, or when the exposure of concern is correlated shortfall rather than annual yield. In practice a planner often wants both, and the natural compromise is to rank by the product of installed capacity and novelty score; we note explicitly that this hybrid is a heuristic to which none of the exactness statements apply.
Proposition 7 (the mirror)
. For let the fleet law above the rank bethe two forms agreeing by Cauchy–Binet, where is the submatrix of loading vectors indexed by S; this is the squared r-dimensional volume of the frame carried by S, which is the right generalisation once makes an s-dimensional volume meaningless. Then S has the law of a core together with a padding of units chosen uniformly among the rest; blind addition maps the law of size s onto that of size exactly, and blind removal does not. In an over-provisioned fleet the geometric criterion is silent on restoration order, while the decisions it does speak to are the ones that take units out of service: planned outages, curtailment allocation and maintenance scheduling should be made with the residuals in hand. Theorem 5 applies verbatim with Y replaced by P, so the fleet has the determinantal law with kernel at every instant and the expected number of covered modes is .
The construction needs an output history long enough to estimate r modes stably, in practice one to two years of sub-hourly data, together with a reliable capacity normalisation. Three cautions apply: the modes must be estimated on outage-free periods, or the outages will be fitted as modes; ageing and seasonal drift move the loadings slowly, so P should be re-estimated on a rolling window; and the failure model is independent failure, which excludes exactly the events that strike neighbouring units together.
9. Implementation
9.1. Inputs and Cost
For the network layer: the node list; the section list with terminal nodes and resistance, or length, cross-section and conductor material; the switching inventory, and which devices are remotely operable; and the current switching and fault state for online use. For the generator layer: per-unit output at sub-hourly resolution over at least one and preferably two years, installed capacity per unit, and the outage log. Nothing else is required: the restoration weights need no load-flow solution, no weather data, no protection settings and no failure statistics, and and enter only in the reliability indices.
Offline, once per commissioned topology: assemble ; factorise it grounded at the substation bus, at cost dense and far less with a sparse factorisation, feeders being sparse and close to planar; read off the effective resistances and hence the diagonal of Y; and, if the full kernel is wanted, assemble it from four look-ups per entry at cost . Online, per fault event: a union-find contraction, a factorisation of the reduced Laplacian on nodes, and one effective resistance per candidate. Contraction should be implemented by union-find on node labels, never by matrix surgery on L.
Two identities should be asserted in code. is Foster’s rule, and it is worth being precise about what it validates: the identity holds for every assignment of positive conductances, so it does not detect a mis-entered resistance, but it does detect a duplicated section, a node with no connection, a wrong terminal or an incidence matrix built from a stale asset register. The restoration weights summing to the island count minus one validates the contraction and the bookkeeping of the switching state, which are the parts of the online path most likely to drift out of step with reality.
9.2. Sampling, Attachment and Scale
Indices depending only on how many sections are energised are formulas, by Corollary 2; indices depending on which ones require the configuration and are obtained by exact sampling: draw an admissible configuration by Wilson’s algorithm [
17,
18] rooted at the substation bus, then de-energise each of its sections independently with probability
; by Corollary 3 the result is an exact draw from
. The procedure is exact rather than asymptotic: no burn-in, no convergence diagnostics, no dependence between draws.
Three attachment points, in increasing order of effort. The asset register feeds a kernel service recomputing
Y whenever a commissioning changes the topology, whose output is a static per-section table of self transfer-current factor, vacancy factor and strongest substitutes. The outage management system calls Algorithm 1 and returns the restoration weights, which are a structural diagnostic and not a dispatch order, for the reasons of
Section 4.8; they should be displayed beside the service-based ordering the utility already uses, which remains the correct basis for deciding where to send a crew. The planning tool integrates (
12) along a candidate reinforcement path and reports the configurational cost of each candidate alongside its loss reduction.
The relevant comparison for scale is with enumeration, the only alternative way to obtain the same quantities exactly. Enumeration grows multiplicatively with the number of independent loops and is out of reach at a dozen ties; the cost of the kernel does not grow combinatorially with the number of loops, though it does grow with the size of the network, through m in the storage of the full kernel and N in the factorisation.
The timings of
Table 10 were obtained on one core of an Intel Xeon processor at 2.10 GHz with 4 GB of memory under Linux, with Python 3.12.3, NumPy 2.4.4, SciPy 1.17.1 and networkx 3.6.1; each entry is wall-clock time, the best of seven repetitions for the factorisation and of three for the other two columns. The scripts are provided as
Supplementary Materials.
The full
kernel costs a dense pseudoinverse:
s and 1 MB for the medium network,
s and 35 MB for the large one. As a check at scale,
for the large network. Two features of
Table 10 are worth naming: the configuration counts come from the matrix-tree determinant, not from enumeration, and are of order
for the large network while being obtained in a millisecond; and the per-event column is the cheapest of the three, because the contracted post-fault network is far smaller than the feeder.
9.3. Using This Alongside Existing Tools
The calculus does not replace the power-flow and reliability tools a utility already runs; it answers questions those tools do not pose.
Table 11 sets it beside the two traditional approaches, and
Table 12 states the division of labour question by question.
The workflow follows from the table. The kernel service runs off the asset register and updates only when a commissioning changes the topology or a resistance; it needs no load data. When a fault occurs, the outage management system calls Algorithm 1 on the current switching state and displays the weights, which are a structural diagnostic, in addition to the service-based ordering it already uses; the crew is sent by the latter. Any configuration the operator intends to close is passed through the alternating-current load flow, which decides voltages, ratings and protection; the kernel cannot and does not do this. For planning, the transport equation is integrated along a candidate reinforcement path in the same tool that already evaluates its loss reduction, and the two figures are reported side by side. Nothing in this chain requires the existing tools to be modified.
10. Limitations
The electrical model. The feeder is treated as a linear resistive network with prescribed current injections. That is a description of the loss-relevant physics and not of the operating point: it carries no reactance, no voltage magnitudes, no reactive power, no transformer taps, no conductor temperature dependence and no protection settings. It therefore cannot say whether a topologically radial configuration is operationally feasible—voltages within limits, sections within rating, protection still coordinated and selective with distributed generation connected. The consequence is a division of labour rather than a defect: the kernel decides how much configurational freedom the feeder retains and how it degrades; an alternating-current load-flow or branch-flow solution decides whether a configuration is operable at all, and a candidate list produced by Algorithm 1 must be filtered through that check before it is acted on.
The ensemble weighting. The measure (
1) is a modelling choice with a stated justification, not a description of how an operator selects a configuration. The identities do not depend on the choice: Lemma 1, Theorems 2, 4 and 5, Proposition 2 and Corollaries 1, 2 and 6 hold for any positive conductance weighting. What depends on it is the numerical output. Within the tempered
-weighting family, that is across
, the ranking is stable where it matters: over 300 random three-fault scenarios the leading candidate is unchanged in 82 to 87 per cent of cases, the base leader lies within the top three in at least
per cent, and the mean Kendall correlation with the base ranking is between
and
. The reporting unit we recommend is therefore the leading pair, invariant in more than 94 per cent of scenarios, rather than a single value. The
and
conventions are a different matter: under
the leading section changes in 31 per cent of scenarios. That sensitivity is a reason to fix the convention on physical grounds, which
Section 2 does, and not a licence to treat it as free.
Independence of failures. Every distributional statement assumes that faults strike energised sections independently and uniformly. That is the right model for the accumulation of unrelated defects and the wrong one for a single event damaging several neighbouring sections: a trench failure, a storm along one branch, a common-mode protection operation. The departure is large rather than marginal: a double outage restricted to adjacent sections produces a surviving configuration whose probability departs from (
4) by factors ranging from
to
, whereas an independent double outage reproduces the sector law to
. Two things follow. The sector law is a testable null hypothesis: since the departure is measurable and the null is exact, the likelihood ratio of an observed surviving configuration against (
4) is a statistic for whether an outage was independent, computable from the switching state alone and without weather input; we do not develop this here. And the weights do not require independence: Theorem 4 and Algorithm 1 are statements about the post-fault network and make no reference to how the current state arose, so a utility may use the weights and decline the indices. Uniformity of the fault rate across sections is the second assumption of this paragraph, and it is load-bearing rather than cosmetic: section-specific rates
break the exchangeability on which Theorem 2 and the closure of Theorem 5 rest, and the total exit rate out of a configuration then depends on which sections are energised, so the occupancy chain is no longer autonomous; the exact results of Levels 2 and 3 in Section Three Levels of Assertion do not extend to section-specific rates as they stand, while the weights of Algorithm 1, which refer to the post-fault network only, are unaffected.
The generator layer. The projection P is estimated from a finite output history, so a generation regime absent from the estimation window is invisible to the calculus, and the rank r is an estimate with its own uncertainty. The capacity normalisation affects the loadings and hence the scores. And correlated outage is more rather than less likely here: a weather front, a common-mode converter fault or a protection operation upstream of several units strike neighbouring generators together by construction.
The maintenance model. Repair durations are exponential, faults are Poisson, and the restoration effort is either proportional to the number of islands or capped at a fixed crew (Proposition 5); real maintenance has travel times, spare-part lead times, shift patterns and access windows, none of which appear, and switching costs are ignored. One assumption that might have been expected here is not a limitation:
Section 5 builds its process on the canonical repair while
Section 4.8 recommends a service-based ordering, and by Proposition 4 the occupancy measures are exact under either.
The slow layer. Estimate 1 is a scaling statement whose constant is not tracked, and a sharp adiabatic result for this family remains open. Commissioning events are jumps rather than drifts, with a transient not available in closed form.
Symmetry and radiality. The construction requires symmetric conductances and radial operation. Symmetry holds for passive line sections and fails wherever the network contains directional elements: unidirectional protection, series power-electronic devices, or any component whose impedance depends on the direction of flow. Distributed generation does not by itself break the symmetry—a passive section carries current in either direction with the same resistance—but a feeder whose protection or control makes a section usable in only one direction falls outside the model. For such networks the matrix-tree machinery must be replaced by its directed counterpart, and the electrical readings of Proposition 1 do not survive in the same form; this is the most substantial extension we leave open. Radiality is assumed throughout, so feeders operated under a weak meshed fall outside the model, a connected spanning subgraph with more than edges not being the basis family of a matroid.
Validation. All numerical results are computed on a published benchmark specified in full in
Appendix A. This is appropriate for verifying exact identities and is not a validation against practice. What would constitute validation is an outage log from an operating utility together with the realised restoration sequences and durations, against which the diagnostic of Algorithm 1 and the indices of Corollary 2 could be compared.
Three Levels of Assertion
The results of this paper do not all require the same thing of the feeder, and conflating them is the misreading we most want to prevent. They fall into three levels, in decreasing order of robustness.
Level 1: structural quantities of the ensemble. The kernel
Y and everything read off it—
as a self transfer-current factor, the substitution map
, the trace identity, the bridges, the restoration weights and their sum rule, the sensitivities of
Section 7—are properties of the network and of the space of admissible configurations. They assume nothing whatever about how the feeder chooses a configuration or about what has happened to it. A feeder that has always operated one fixed radial configuration still has these quantities, and they still mean what they mean.
Level 2: occupancy quantities. The number of energised sections, the number of islands and the probability of radial completeness require that faults strike the energised sections independently and that the total restoration rate out of a
k-section configuration be
, or its time-dependent counterpart. They do not require the ensemble distribution of configurations, and by Proposition 4 they do not require any particular allocation of that rate among the candidates. They do not require the pre-fault configuration to be drawn from the ensemble: any spanning tree has exactly
sections, so independent thinning gives
energised sections and
islands whichever tree the feeder happened to be operating. By Proposition 4 they do not require the canonical repair either. These are structural availability measures rather than customer-based indices (
Section 5), and they are the most robust results in the paper.
Level 3: the full configuration-level law. The statement , the sector identities of Theorem 2, and the per-section and joint statements of Corollary 2 do require the initial configuration to be distributed as the operating ensemble, and they require a repair that intertwines the sectors. They do not require the canonical repair specifically: by Proposition 3 any sector intertwiner will do, and the canonical rule of Theorem 4 is the distinguished reversible member of that class. A feeder sitting in a fixed tree that loses one energised section is left with a uniformly chosen subset of , not with a sample of : Theorem 2 propagates the ensemble, it does not create it.
The ensemble is thus a description of the space of admissible configurations at Level 1, a harmless bookkeeping device at Level 2, and a genuine modelling assumption at Level 3. It never asserts that the feeder selects its configuration at random. Readers who reject the ensemble as a description of utility behaviour may still use everything at Levels 1 and 2, which is most of what an operator asks for.
11. Conclusions
A distribution feeder operates one configuration at a time but lives in a space of them. This paper describes that space exactly. The admissible radial configurations form a determinantal ensemble whose kernel is the transfer-current matrix, so that every joint statistic of the switching devices is a small determinant rather than a sum over a combinatorial family; on the benchmark feeder this replaces an enumeration of 50,751 configurations by a single matrix, and for networks of realistic size it replaces a computation that cannot be performed at all.
Three statements summarise what the description buys, and each is exact.
Random faults never take the feeder out of its model class: after any number of independent faults the surviving configuration is again a determinantal forest with the same kernel, and the relative importance profile of the sections is merely rescaled.
Restoration cannot be blind, and among the mechanisms that are not blind one is canonical: no policy chosen without knowledge of the section resistances returns the feeder to its class, not even one that knows the single-line diagram in full, while conductance-aware upward intertwiners form a family of which exactly one reverses the random fault, weighting each de-energised section by its own transfer-current factor in the post-fault network with everything still energised shorted, the weights summing to the island count minus one. Its practical content is twofold and should not be overstated: it is the distinguished reversible member of the class of sector-intertwining mechanisms under which the determinantal form and the per-section indices remain exact, and the weights themselves are a structural diagnostic computed from the single-line diagram and the resistances alone. It is not a service-restoration heuristic, and
Section 4.8 shows that it should not be used as one.
Reinforcement redistributes redundancy rather than creating it: the total participation is pinned at
, the leverage of an investment is largest where the feeder is least certain, and sizing driven purely by loading spends the feeder’s switching freedom while, on the benchmark feeder, a modest redundancy term buys it back at a cost of under two per cent in loss; the threshold and the size of that penalty are properties of that network and its loading, not a general planning conclusion.
The same calculus governs a second failure layer, a fleet of distributed generators, with the projection onto the generation modes in place of the transfer-current kernel; there the restoration score of a failed unit is the residual novelty of its whitened retained-mode loading, not a gain in output variance. The contrast with the network layer is one of degree rather than of kind: the algebra alone never decides whether a canonical mechanism is also a useful rule.
What is exact and what is not should not be conflated. Everything above holds for a frozen geometry and independent faults, and the central identities were verified against exhaustive enumeration at double-precision round-off. The coupling of the two time scales is a quasi-static estimate whose constant we do not track, and the correlated events a feeder genuinely faces lie outside the distributional apparatus, though not outside the weights themselves. Section Three Levels of Assertion states which results depend on the ensemble and which do not.
Five directions follow. Validation against an operating utility’s outage log, comparing realised restoration sequences with the diagnostic of Algorithm 1, is the necessary next step and the one we have not taken. Section-specific fault rates are the assumption the model most visibly does not relax: exactness rests on uniform, blind de-energisation, and a weighted analogue would need a deletion mechanism matched to the ensemble, which we do not have. The departure from the sector law under correlated outage is measurable and exact under the null, which makes it a test statistic for whether an event was independent, computable from the switching state alone. A sharp adiabatic theorem with explicit constants would upgrade the two-scale estimate to a bound. And feeders containing directional elements require the directed counterpart of the whole construction, in which the electrical readings of Proposition 1 do not survive unchanged.