Context-aware-driven multi-dimensional anomaly detection early warning method
By generating an initial feature set containing environmental parameter sequences and behavioral pattern maps, building an adaptive detection model and triggering dynamic warning instructions, the problems of lag and false alarms and missed warnings of traditional anomaly detection methods in complex scenarios are solved, and efficient and accurate anomaly detection and warning are achieved.
Patent Information
- Application Number
- CN202511261277.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-05
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-09-05
AI Technical Summary
Traditional anomaly detection methods rely on single-dimensional feature data and are unable to cope with dynamic changes in context in complex scenarios, resulting in delayed warnings, false alarms or missed alarms. In addition, the model has insufficient generalization capabilities when applied across scenarios, lacks dynamic perception of context deviation and feature fluctuation coefficients, and cannot flexibly switch detection models based on real-time monitoring data.
Collect real-time context data of the target monitoring scenario, generate an initial feature set including environmental parameter sequences and behavior pattern maps, build the first detection model and the second detection model adapted to the scenario type, trigger dynamic warning instructions based on real-time monitoring data, and adjust the trigger threshold of the abnormal response strategy and the priority of the risk disposal process.
It realizes the comprehensive detection of environmental parameters and behavioral patterns, improves the accuracy and real-time performance of anomaly detection, dynamically adjusts the response strategy to adapt to complex scenarios, avoids missed or false alarms, and improves the operating efficiency of the monitoring system.
Smart Images

Figure CN120748147A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of anomaly detection technology, and in particular to a context-aware driven multi-dimensional anomaly detection and early warning method. Background Art
[0002] With the rapid development of the Internet of Things and artificial intelligence (AI) technologies, the requirements for real-time and accurate anomaly detection are increasing across various monitoring scenarios. Traditional anomaly detection methods in industrial production, intelligent security, environmental monitoring, and other fields often rely on single-dimensional feature data. For example, they identify anomalies based solely on fixed thresholds for environmental parameters or assess risk based solely on static features of behavioral patterns. This single-dimensional approach struggles to address the challenges posed by dynamic context changes in complex scenarios.
[0003] In industrial production scenarios, the operating status of equipment is not only affected by environmental parameters such as temperature and pressure, but is also closely related to the operator's operating procedures and the collaborative behavior between equipment. Traditional methods only issue early warnings by setting fixed environmental parameter thresholds. When environmental parameters fluctuate slightly around the threshold but abnormal trends are already showing in combination with operational behavior, they are often unable to be identified in a timely manner, resulting in delayed early warnings. In the field of intelligent security, the behavioral patterns of personnel flow are highly dynamic, and normal behavioral characteristics vary significantly in different time periods and different areas. Traditional detection models based on static behavioral feature libraries are difficult to adapt to such dynamic changes and are prone to false alarms or missed alarms. For example, temporarily adjusted patrol routes may be misjudged as abnormal behavior, or sudden group gatherings may be unable to be responded to in a timely manner.
[0004] The field of environmental monitoring faces similar challenges. In the natural environment, changes in parameters such as temperature, humidity, and pollutant concentrations are closely linked to contextual factors such as biological activity and meteorological conditions. Traditional methods issue warnings based solely on whether pollutant concentrations exceed standards, ignoring the impact of biological activity on pollutant diffusion in different seasons and time periods. As a result, in some cases, when pollutant concentrations do not exceed standards but there is a potential risk associated with abnormal biological activity, effective warnings cannot be issued. In addition, the response strategies of traditional anomaly detection models are mostly fixed. Once an alert is triggered, the execution module proceeds according to a preset process, making it difficult to adjust the response priority based on the real-time risk level. When multiple anomalies occur simultaneously, it is easy to cause irrational resource allocation and affect the efficiency of the response.
[0005] In existing technologies, some improved detection methods attempt to incorporate multi-dimensional data, but fail to fully consider the adaptability of scenario types when building models, resulting in insufficient generalization capabilities when the models are applied across scenarios. Furthermore, these methods lack dynamic awareness of contextual deviations and feature fluctuation coefficients, making it impossible to flexibly switch detection models based on real-time monitoring data, limiting the adaptability and flexibility of anomaly detection. After the warning instructions are generated, the response strategy adjustments of the execution module are mostly static, making it impossible to optimize the trigger threshold and handling process priority in real time based on dynamic warning results, making it difficult to meet the needs of accurate and efficient anomaly detection in complex scenarios. Summary of the Invention
[0006] The purpose of the present invention is to provide a context-aware driven multi-dimensional anomaly detection and early warning method to solve the problems raised in the above background technology.
[0007] To achieve the above objectives, the present invention provides a context-aware driven multi-dimensional anomaly detection and early warning method, the method comprising:
[0008] Collecting real-time context data in the target monitoring scene to generate an initial feature set, the initial feature set including an environmental parameter sequence and a behavior pattern map;
[0009] Constructing a first detection model adapted to the scene type based on the environmental parameter sequence in the initial feature set, wherein the first detection model includes a dynamic correlation function between environmental indicators and abnormality probabilities;
[0010] Constructing a second detection model adapted to the scenario type based on the behavior pattern map in the initial feature set, wherein the second detection model includes a nonlinear mapping rule between behavior features and risk levels;
[0011] Based on the context deviation data and the characteristic fluctuation coefficient data during the real-time monitoring process, triggering the target model in the first detection model or the second detection model, and generating a dynamic warning instruction through the target model;
[0012] The dynamic warning instruction is pushed to the execution module of the monitoring system to adjust the trigger threshold of the abnormal response strategy or the priority of the risk disposal process.
[0013] Preferably, the collecting of real-time context data in the target monitoring scene to generate an initial feature set includes:
[0014] Synchronously collect environmental status data of the target scene within the monitoring period through multi-source sensing devices, wherein the environmental status data includes a physical parameter time sequence stream and a logical state code set;
[0015] Dividing the target scene into at least two sub-scene units according to the characteristic interval in the physical parameter time series stream, and assigning a corresponding initial monitoring threshold range and risk assessment benchmark value to each sub-scene unit;
[0016] Extract historical environment correction parameters and behavioral feature compensation coefficients that match each sub-scene unit from the preset feature library;
[0017] Performing spatiotemporal alignment processing on the historical environmental correction parameters to generate an optimized environmental parameter sequence corresponding to each sub-scene unit;
[0018] Performing trend smoothing processing on the behavioral feature compensation coefficient to generate an optimized behavioral pattern map corresponding to each sub-scene unit;
[0019] The initial feature set is generated by fusing the optimized environmental parameter sequence and the optimized behavior pattern map of each sub-scene unit.
[0020] Preferably, constructing the first detection model and the second detection model includes:
[0021] Inputting the optimized environmental parameter sequence into a preset rule inference engine, iteratively updating the rule weights through multiple rounds of condition matching, and generating an abnormality probability calculation function in the first detection model, wherein the abnormality probability calculation function is the target model in the first detection model;
[0022] Inputting the optimized behavior pattern map into a statistical feature extraction module, screening key behavior indicators through a feature dimensionality reduction algorithm, and generating a risk level division matrix in the second detection model; the risk level division matrix is the target model in the second detection model;
[0023] After the rule inference engine and the statistical feature extraction module are running stably, the core parameter vectors in the abnormal probability calculation function and the risk level division matrix are extracted respectively;
[0024] Performing a correlation analysis between the core parameter vector and the environmental status data collected in real time to verify the applicability of the first detection model and the second detection model;
[0025] When the correlation analysis result is lower than a preset threshold, the matching conditions of the rule inference engine and the dimension reduction parameters of the statistical feature extraction module are readjusted until the core parameter vector meets the applicability condition.
[0026] Preferably, triggering a target model in the first detection model or the second detection model based on the context deviation data and the characteristic fluctuation coefficient data in the real-time monitoring process, and generating a dynamic warning instruction through the target model includes:
[0027] Real-time tracking of context deviation change curve and characteristic fluctuation coefficient amplitude during monitoring process;
[0028] When the context deviation change curve exceeds a first trigger threshold and the characteristic fluctuation coefficient amplitude is within a preset safety range, triggering an abnormality probability calculation function in the first detection model;
[0029] Generate a dynamic threshold adjustment instruction for an abnormal response strategy according to the probability distribution rule in the abnormal probability calculation function;
[0030] When the amplitude of the characteristic fluctuation coefficient exceeds a second trigger threshold and the context deviation change curve is in a preset stable range, triggering the risk level division matrix in the second detection model;
[0031] Generating dynamic priority adjustment instructions for the risk handling process according to the level determination rules in the risk level classification matrix;
[0032] If the context deviation change curve and the characteristic fluctuation coefficient amplitude both exceed the trigger threshold, the dynamic threshold adjustment instruction generated by the first detection model will be executed first, and the adjustment instruction of the second detection model will be delayed until the abnormal response strategy completes the threshold update.
[0033] Preferably, the step of pushing the dynamic warning instruction to the execution module of the monitoring system and adjusting the triggering threshold of the abnormal response strategy or the priority of the risk handling process includes:
[0034] According to the threshold compensation value in the dynamic threshold adjustment instruction, the determination threshold of each warning level in the abnormal response strategy is updated in stages;
[0035] After each threshold update, real-time abnormal probability data is collected and deviation analysis is performed with the predicted value of the abnormal probability calculation function;
[0036] If the deviation value continues to decrease, the current threshold adjustment direction is maintained until the target probability interval is reached;
[0037] If the deviation value shows an upward trend, the judgment threshold is adjusted in the opposite direction and the parameter optimization of the abnormal probability calculation function is re-triggered;
[0038] Dynamically configure the execution order of the risk disposal process in different scenarios according to the priority parameters in the dynamic priority adjustment instruction;
[0039] During the priority adjustment process, the risk treatment effect is monitored in real time through the status feedback mechanism, and the level weights in the risk level classification matrix are dynamically updated according to the monitoring results.
[0040] Preferably, the method further includes an effect calibration stage after the dynamic warning instruction is executed, including the following operations:
[0041] Collect final anomaly mitigation data and risk level retest results after early warning and disposal are completed;
[0042] comparing the final anomaly mitigation data with the predicted mitigation range of the first detection model to generate an anomaly detection error signal;
[0043] Performing consistency analysis on the risk level retest result and the expected level standard of the second detection model to generate a risk assessment error signal;
[0044] adjusting a probability distribution rule in the first detection model according to a system deviation component in the abnormality detection error signal;
[0045] optimizing a grade weight coefficient in the second detection model according to a random fluctuation component in the risk assessment error signal;
[0046] The adjusted probability distribution rules and grade weight coefficients are synchronously updated to the historical feature library of the initial feature set.
[0047] Preferably, the process of adjusting the probability distribution rule and the grade weight coefficient includes:
[0048] Identifying a static deviation component in the abnormality detection error signal and calculating a static compensation value by a sliding average filtering method;
[0049] Adjusting the baseline probability threshold in the abnormal probability calculation function according to the static compensation value;
[0050] Identifying dynamic interference components in the risk assessment error signal and extracting effective correction parameters through an adaptive filtering algorithm;
[0051] Adjusting the level determination threshold in the risk level classification matrix according to the effective correction parameter;
[0052] The updated abnormal probability calculation function and risk level division matrix replace the original model parameters.
[0053] Preferably, the method further comprises performing the following initialization operations before the system is started, including:
[0054] Parse the environmental feature identifier and behavior pattern encoding segment in the scene type code corresponding to the target scene to generate a scene feature description vector;
[0055] Inputting the scene feature description vector into a preloaded scene configuration database for multi-dimensional matching retrieval, and screening out candidate benchmark configuration sets whose matching degree with the current scene type code exceeds an adaptation threshold;
[0056] For each candidate benchmark configuration in the candidate benchmark configuration set, the following operations are performed: extracting the average anomaly detection rate and risk level accuracy rate in its historical application records, and calculating a comprehensive configuration effectiveness score;
[0057] Prioritizing the candidate benchmark configuration sets according to the comprehensive configuration effectiveness scores, and selecting the candidate benchmark configuration with the highest score as the optimal benchmark environment parameter template;
[0058] Extracting a reference set of behavior patterns that have configuration relevance to the optimal benchmark environment parameter template from a scenario configuration database;
[0059] Verify the synergy between pattern features and environmental parameters for each pattern data in the behavior pattern reference set, eliminate abnormal patterns with conflicting features or contradictory parameters, and generate an optimized behavior pattern benchmark set;
[0060] According to the historical operation stability index of each optimized behavior pattern benchmark in the optimized behavior pattern benchmark set, the optimized behavior pattern benchmark with the smallest volatility index is selected as the optimal behavior pattern benchmark;
[0061] The optimal benchmark environment parameter template and the optimal behavior pattern benchmark are configured in time sequence alignment to generate a benchmark parameter configuration of an initial feature set.
[0062] Preferably, the verifying the synergy between the pattern characteristics and the environmental parameters for each pattern data in the behavior pattern reference set includes:
[0063] Extracting characteristic data of a single pattern to be verified from the behavioral pattern reference set, and synchronously obtaining an environmental parameter sequence in the optimal baseline environmental parameter template that is time-aligned with the pattern to be verified;
[0064] According to the change nodes of the environmental parameter sequence, corresponding collaborative time marks are marked on the pattern to be verified to generate a pattern characteristic curve with a time sequence mark;
[0065] Traversing each collaborative time marker in the pattern characteristic curve with a time sequence identifier, detecting whether the characteristic change rate in its adjacent time window exceeds a preset mutation threshold, and identifying abnormal time windows with characteristic mutations;
[0066] When an abnormal time window is identified, the environmental parameter value of the corresponding time node in the optimal benchmark environmental parameter template is traced back to determine whether the change direction of the environmental parameter value has an adverse effect on the characteristic mutation direction;
[0067] If the adverse impact intensity exceeds the conflict threshold, the abnormal time window is marked as a parameter conflict area, and the starting position and duration of the parameter conflict area in the pattern characteristic curve are calculated;
[0068] Defining a feature correction window on the to-be-verified pattern according to the starting position and duration of the parameter conflict region, and generating an alternative feature smoothing segment based on correction records of similar conflicts in a historical feature library;
[0069] Inserting the replacement feature smooth segment into the feature correction window to generate an optimized behavior pattern curve, and deleting abnormal data points in the original pattern feature curve that overlap with the parameter conflict area;
[0070] Performing integrity check on all optimized behavior pattern curves that have completed the substitution insertion operation in the behavior pattern reference set, and removing residual curves that still contain uncorrected conflict areas;
[0071] The optimized behavior pattern curves that have passed the verification are merged into the optimized behavior pattern benchmark set.
[0072] Preferably, the stepwise updating of the determination thresholds of each warning level in the abnormal response strategy includes:
[0073] Determining the stage interval of threshold value update based on the rate of change of the environmental parameter sequence, and dividing the total adjustment interval into at least three consecutive sub-adjustment stages;
[0074] Allocate a corresponding threshold adjustment step length to each sub-adjustment stage, and the threshold adjustment step length increases according to a preset ratio as the stage progresses;
[0075] After each sub-adjustment phase is completed, the deviation rate between the mean abnormal probability of the current phase and the target probability interval is collected;
[0076] If the deviation rate is less than the stage threshold, the next sub-adjustment stage is entered; if the deviation rate is greater than or equal to the stage threshold, the current update process is suspended and the parameter recalibration of the abnormal probability calculation function is triggered;
[0077] After all sub-adjustment stages are completed, a final check is performed on the judgment thresholds of each warning level to ensure that the difference between adjacent level thresholds meets the preset gradient requirements.
[0078] Compared with the prior art, the present invention has the following beneficial effects:
[0079] By collecting real-time contextual data from the target monitoring scene, an initial feature set consisting of sequences of environmental parameters and behavioral pattern maps is generated, overcoming the limitations of traditional anomaly detection, which relies on single-dimensional data. This multi-dimensional data collection method can fully capture dynamic changes in the monitoring scene, effectively incorporating subtle fluctuations in environmental parameters and complex correlations in behavioral patterns into the detection scope, making the basic data for anomaly detection richer and more comprehensive.
[0080] In terms of model construction, a primary detection model and a secondary detection model are constructed based on the environmental parameter sequence and behavioral pattern map, respectively, to better adapt the models to the characteristics of different scenarios. The primary detection model includes a dynamic correlation function between environmental indicators and anomaly probabilities, while the secondary detection model includes nonlinear mapping rules between behavioral characteristics and risk levels. This targeted model design ensures that different types of feature data are processed in the most appropriate manner, avoiding the poor adaptability of traditional general models in specific scenarios and improving the model's accuracy in identifying abnormal features.
[0081] Based on contextual deviation data and characteristic fluctuation coefficient data from real-time monitoring, the corresponding target model is triggered and dynamic warning instructions are generated, enabling flexible switching of detection models. When the deviation of environmental parameters in the monitoring data exceeds the normal range, the first detection model is accurately triggered; when the characteristic fluctuation coefficient of the behavioral pattern is abnormal, the second detection model responds promptly. This dynamic triggering mechanism enables anomaly detection to adjust its detection focus based on real-time conditions, avoiding the omissions or false alarms that occur with traditional fixed models in complex scenarios, and enhancing the real-time and targeted nature of anomaly detection.
[0082] Dynamic warning instructions are pushed to the execution module, adjusting the trigger threshold of the exception response strategy or the priority of the risk disposal process, thus achieving dynamic optimization of the exception response. At different warning levels, the execution module can flexibly adjust the response strategy according to the instructions. When the warning level is high, the trigger threshold is lowered and the priority of the disposal process is increased to speed up the response. When the warning level is low, the trigger threshold is appropriately raised and the order of the disposal process is adjusted to avoid unnecessary resource consumption. This dynamic adjustment mechanism makes the exception response more closely aligned with the actual risk situation and improves the operational efficiency of the entire monitoring system.
[0083] Driven by contextual awareness, this approach incorporates the association between environmental parameters and behavioral patterns into detection logic. This enables anomaly detection to move beyond isolated parameter judgment or behavior identification, and instead comprehensively considers the interplay of various factors within a scenario. In industrial production, this approach can simultaneously monitor changes in equipment environments and operational behavior specifications. In intelligent security, it can combine human behavior with environmental changes to assess risks. In environmental monitoring, it can correlate natural factors with human activity to assess anomalies, enabling more accurate anomaly detection and early warning in a variety of scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0084] Figure 1 This is a working principle diagram of the context-aware driven multi-dimensional anomaly detection and early warning method of the present invention;
[0085] Figure 2 Flowchart generated for the initial feature set;
[0086] Figure 3 Flowchart for early warning effect calibration and model optimization;
[0087] Figure 4 Flowchart for probability distribution rules and grade weight coefficient adjustment;
[0088] Figure 5 Flowchart generated for system initialization and baseline configuration. DETAILED DESCRIPTION
[0089] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0090] See also Figure 1-Figure 5 The present invention provides a context-aware driven multi-dimensional anomaly detection and early warning method, the method comprising:
[0091] Collecting real-time context data in the target monitoring scene to generate an initial feature set, the initial feature set including an environmental parameter sequence and a behavior pattern map;
[0092] Constructing a first detection model adapted to the scene type based on the environmental parameter sequence in the initial feature set, wherein the first detection model includes a dynamic correlation function between environmental indicators and abnormality probabilities;
[0093] Constructing a second detection model adapted to the scenario type based on the behavior pattern map in the initial feature set, wherein the second detection model includes a nonlinear mapping rule between behavior features and risk levels;
[0094] Based on the context deviation data and the characteristic fluctuation coefficient data during the real-time monitoring process, triggering the target model in the first detection model or the second detection model, and generating a dynamic warning instruction through the target model;
[0095] The dynamic warning instruction is pushed to the execution module of the monitoring system to adjust the trigger threshold of the abnormal response strategy or the priority of the risk disposal process.
[0096] Example 1:
[0097] Multi-source sensing devices synchronously collect environmental status data for the target scene during the monitoring period. This environmental status data consists of a time-series stream of physical parameters and a set of logical state codes. Multi-source sensing devices include temperature sensors, humidity sensors, infrared detectors, and motion capture devices. These devices work together at a preset sampling frequency to ensure comprehensive capture of dynamic changes in the target scene during the monitoring period. The time-series stream of physical parameters consists of continuously acquired physical quantities, such as a temperature time-series stream formed by temperature values at different times or a humidity time-series stream formed by humidity values at different times. These data are indexed by timestamps and form a continuous data stream. The logical state code set encodes discrete events or states in the scene. For example, the operating state of a device can be encoded as "001" for normal operation, "010" for standby, and "100" for fault. The occupancy status of an area can be encoded as "1" for occupied and "0" for unoccupied. These codes are arranged in chronological order to form a logical state sequence corresponding to the time-series stream of physical parameters.
[0098] During the synchronous collection process of multi-source sensing devices, a distributed file system is used to store massive environmental state data (including physical parameter time series streams and logical state code sets). Stream processing frameworks such as Spark Streaming are used to achieve real-time reception and preliminary processing of high-concurrency data. Data sharding technology is used to split the continuous physical parameter time series streams into parallel-processable data sets according to time windows. Batch processing is combined with preset data cleaning rules (such as eliminating abnormal sensor drift data and completing missing logical state codes). At the same time, distributed computing nodes are used to extract feature data of different sub-scene units in parallel, greatly improving the processing efficiency of massive contextual data and providing efficient data support for the subsequent generation of initial feature sets.
[0099] Based on the characteristic intervals in the physical parameter time series, the target scene is divided into at least two sub-scene units. Each sub-scene unit is assigned a corresponding initial monitoring threshold range and risk assessment baseline value. The characteristic interval division is based on the distribution characteristics of the physical parameters. For example, in a large warehouse, based on the temperature parameter distribution, the temperature range of 25°C-30°C can be divided into one characteristic interval, and the temperature range of 30°C-35°C can be divided into another characteristic interval, with each characteristic interval corresponding to a sub-scene unit. After the division is completed, the initial monitoring threshold range is determined for each sub-scene unit based on its functional attributes and historical monitoring data. For example, for a sub-scene unit storing flammable items in the warehouse, the initial temperature monitoring threshold range might be set to 20°C-28°C, while for general cargo storage areas, the initial temperature monitoring threshold range might be set to 18°C-32°C. The risk assessment baseline value is determined based on factors such as the value of the items in the sub-scene unit and the scope of impact of an anomaly. Sub-scene units with higher value and larger impact areas are assigned lower risk assessment baseline values to increase attention to the area.
[0100] The historical environmental correction parameters and behavioral characteristic compensation coefficients that match each sub-scene unit are extracted from the preset feature library. The preset feature library stores historical data for different scenes and different time periods, including environmental correction parameters and behavioral characteristic compensation coefficients of the same or similar sub-scene units in various situations in the past. During the extraction process, by comparing the characteristic interval, functional attributes and other information of the current sub-scene unit with the information recorded in the preset feature library, the historical data with the highest similarity is screened out, and the corresponding historical environmental correction parameters and behavioral characteristic compensation coefficients are extracted from them. For example, for the sub-scene unit with a temperature characteristic interval of 25℃-30℃ in the current warehouse, the historical environmental correction parameters of the sub-scene units with the same temperature interval in the same type of warehouse in the past are found from the preset feature library, such as the temperature correction value caused by seasonal changes, and the behavioral characteristic compensation coefficients, such as the behavioral correction coefficients of people's activities in the area.
[0101] The historical environmental correction parameters are subjected to spatiotemporal alignment to generate an optimized environmental parameter sequence corresponding to each sub-scene unit. The spatiotemporal alignment process includes two parts: time alignment and spatial alignment. Time alignment is to calibrate the historical environmental correction parameters collected at different times according to the time axis to eliminate time deviations. For example, the correction parameters collected in the same time period on different dates in the past are adjusted to the same time dimension for processing. Spatial alignment is to map the parameters collected at different locations to the corresponding spatial coordinates according to the spatial layout of the sub-scene unit to ensure the spatial consistency of the parameters. For example, the environmental correction parameters for different shelf areas in the warehouse are integrated according to the spatial position relationship of the shelves, so that the parameters can accurately reflect the environmental correction conditions of different spatial points within the sub-scene unit. After the spatiotemporal alignment process, the historical environmental correction parameters are consistent with the real-time environmental data of the current sub-scene unit in time and space, and then integrated to generate an optimized environmental parameter sequence. This sequence can more accurately reflect the environmental characteristics of the sub-scene unit.
[0102] The behavioral feature compensation coefficients are trend-smoothed to generate an optimized behavioral pattern map corresponding to each sub-scene unit. The behavioral feature compensation coefficients may be affected by various random factors and have certain fluctuations. Trend smoothing is to eliminate these random fluctuations and highlight the overall trend of the behavioral features. During the processing, a sliding average method can be used to select a certain time window and average the behavioral feature compensation coefficients within the window to obtain smoothed coefficient values. These smoothed coefficient values are arranged in chronological order to form a preliminary behavioral pattern map. Afterwards, the abnormal points in the map are corrected. For example, when the coefficient value at a certain moment differs too much from the coefficient value at the adjacent moment and there is no reasonable explanation, the abnormal point is replaced with the average value of the coefficient value at the adjacent moment. Finally, an optimized behavioral pattern map is generated, which can clearly show the changing trend of the behavioral features within the sub-scene unit.
[0103] Based on the optimized environmental parameter sequence and optimized behavior pattern map of each sub-scene unit, an initial feature set is generated by fusion. During the fusion process, the optimized environmental parameter sequence and optimized behavior pattern map of each sub-scene unit are used as basic elements and integrated according to the spatial position relationship and logical association of the sub-scene units in the target scene. For example, in a warehouse scene, the optimized environmental parameter sequence and optimized behavior pattern map of each shelf area are combined according to the arrangement order of the shelves, while considering the mutual influence between different sub-scene units. For example, changes in environmental parameters of adjacent shelf areas may affect each other, and this influence relationship needs to be taken into consideration during fusion. Through such fusion processing, the scattered sub-scene unit features are integrated into a unified whole to form an initial feature set that can comprehensively and accurately reflect the initial state of the target monitoring scene. This set contains all the key feature information of the target scene in terms of environment and behavior, providing basic data for subsequent model construction and anomaly detection.
[0104] Example 2:
[0105] The optimized environmental parameter sequence is input into a pre-set rule-based inference engine. This engine contains multiple sets of initial rules, each corresponding to the relationship between an environmental parameter and anomalies. Through multiple rounds of condition matching, the rule weights are iteratively updated. In each round, the data in the optimized environmental parameter sequence is compared with the rules in the rule-based inference engine, and the weight of the corresponding rule is adjusted based on the degree of match. The higher the match, the greater the weight, and vice versa. After multiple rounds of iteration, the anomaly probability calculation function in the first detection model is generated. This function becomes the target model in the first detection model.
[0106] The optimized behavior pattern graph is fed into the statistical feature extraction module, which processes the behavioral features in the graph using a feature dimensionality reduction algorithm. This algorithm reduces feature dimensions while retaining key information. By screening out key behavioral indicators that significantly impact risk levels, it generates a risk classification matrix for the second detection model, which serves as the target model in the second detection model.
[0107] After the rule inference engine and statistical feature extraction modules are running stably, the core parameter vectors from the anomaly probability calculation function and the risk level classification matrix are extracted. The core parameter vector is a set of key parameters that determine the model's output and includes the most representative parameters from the function and matrix.
[0108] The core parameter vector is analyzed for correlation with the real-time collected environmental status data. The applicability of the first and second detection models is verified by calculating the correlation between the two. If the correlation analysis result falls below a preset threshold, the matching conditions of the rule inference engine are readjusted, such as modifying the trigger threshold of the rule, adding or deleting some rules, and adjusting the dimensionality reduction parameters of the statistical feature extraction module, such as changing the number of iterations of the dimensionality reduction algorithm and adjusting the feature screening threshold, until the core parameter vector meets the applicability conditions.
[0109] The process of triggering the target model in the first detection model or the second detection model and generating a dynamic warning instruction based on the context deviation data and feature fluctuation coefficient data during real-time monitoring is as follows:
[0110] Real-time tracking and monitoring of the context deviation curve and characteristic fluctuation coefficient amplitude. The context deviation curve is calculated by calculating the degree of deviation between real-time context data and normal context data, and can intuitively reflect the changing trend of context. The characteristic fluctuation coefficient amplitude quantifies the magnitude of the fluctuation in characteristic data.
[0111] When the context deviation curve exceeds the first trigger threshold and the characteristic fluctuation coefficient amplitude is within the preset safety range, it indicates that the current anomaly is primarily caused by abnormal environmental parameters. At this time, the anomaly probability calculation function in the first detection model is triggered. Based on the probability distribution rules in the anomaly probability calculation function and the real-time environmental parameter data, the probability of the anomaly occurring is calculated. This in turn generates dynamic threshold adjustment instructions for the anomaly response strategy. These instructions are used to adjust the judgment thresholds for each warning level in the anomaly response strategy.
[0112] When the characteristic fluctuation coefficient amplitude exceeds the second trigger threshold and the context deviation curve is within the preset stable range, indicating that the anomaly is primarily due to behavioral pattern anomalies, the risk level classification matrix in the second detection model is triggered. Based on the level determination rules in the risk level classification matrix, real-time behavioral characteristic data is analyzed to determine the corresponding risk level. Dynamic priority adjustment instructions for the risk handling process are generated, which are used to adjust the execution order of the risk handling process.
[0113] If the context deviation change curve and the characteristic fluctuation coefficient amplitude both exceed the trigger threshold, it indicates that abnormalities have occurred in both the environment and the behavior. At this time, the dynamic threshold adjustment instructions generated by the first detection model will be executed first. After the abnormal response strategy completes the threshold update, the adjustment instructions of the second detection model will be executed to ensure the orderliness and effectiveness of abnormal handling.
[0114] Example 3:
[0115] The interval between threshold updates is determined based on the rate of change of the environmental parameter sequence. The rate of change is calculated as the amount of change in the environmental parameter per unit time. The greater the rate of change, the shorter the interval is set to quickly adapt to dramatic environmental changes. For example, if the ambient temperature rises by 5°C in 1 minute, the interval might be set to 10 seconds; if the temperature rises by only 1°C in 1 minute, the interval might be set to 30 seconds. Based on the determined intervals, the total adjustment interval is divided into at least three consecutive sub-adjustment stages. The total adjustment interval is the range of thresholds to be adjusted. For example, if adjusting from an initial threshold of 50 to a target threshold of 70, the total adjustment interval is 20 seconds. If divided into three sub-adjustment stages, the adjustment interval of each sub-adjustment stage can be further allocated based on the interval and rate of change.
[0116] Each sub-adjustment stage is assigned a corresponding threshold adjustment step size, which increases according to a preset ratio as the stage progresses. The preset ratio can be determined based on historical adjustment data. For example, if the ratio increases by 1.2 times, the step size of the first sub-adjustment stage is 2, the step size of the second sub-adjustment stage is 2.4, and the step size of the third sub-adjustment stage is 2.88. After each sub-adjustment stage is completed, the deviation rate between the mean abnormal probability of the current stage and the target probability interval is collected. The deviation rate is calculated as follows:
[0117]
[0118] in, represents the deviation rate, represents the mean abnormal probability of the current stage, Represents the middle value of the target probability interval.
[0119] If the deviation rate is less than the stage threshold, the next sub-adjustment stage is entered. If the deviation rate is greater than or equal to the stage threshold, the current update process is suspended and the parameter recalibration of the anomaly probability calculation function is triggered. During the parameter recalibration process, the weight coefficients and baseline parameters in the anomaly probability calculation function are readjusted to improve the function's predictive accuracy. After all sub-adjustment stages are completed, a final check is performed on the judgment thresholds for each warning level to check whether the difference between adjacent level thresholds meets the preset gradient requirements. For example, the difference between two adjacent level thresholds must be maintained at least 5 to ensure clear warning level divisions and avoid confusion.
[0120] After each threshold update, real-time anomaly probability data is collected and analyzed for deviations from the predicted value of the anomaly probability calculation function. Deviation analysis is performed by calculating the difference between the real-time anomaly probability data and the predicted value. If the deviation value continues to decrease, it indicates that the current threshold adjustment direction is correct and this direction should be maintained until the target probability range is reached. If the deviation value shows an upward trend, it indicates that there is a problem with the current adjustment direction and the judgment threshold needs to be adjusted in the opposite direction. This also triggers parameter optimization of the anomaly probability calculation function. Parameter optimization involves adjusting the feature weights and threshold coefficients in the function to reduce prediction deviation.
[0121] According to the priority parameters in the dynamic priority adjustment instructions, the execution order of the risk disposal process in different scenarios is dynamically configured. The priority parameters are determined according to the risk level division matrix. The higher the risk level, the larger the corresponding priority parameter, and the higher the execution order of its disposal process. During the priority adjustment process, the risk disposal effect is monitored in real time through the status feedback mechanism. The status feedback mechanism evaluates whether the risk is effectively controlled by collecting environmental parameters and behavioral pattern data after the disposal. The level weights in the risk level division matrix are dynamically updated according to the monitoring results. The update of the level weights is based on the comparison results of the disposal effect and the expected effect. If the disposal effect of a certain risk level is better than expected, its level weight will be appropriately increased, otherwise the level weight will be reduced.
[0122] Through the above process, the trigger threshold of the abnormal response strategy and the priority of the risk disposal process can be adjusted in time according to the dynamic early warning instructions, so that the monitoring system can respond to different types of abnormal situations quickly and accurately, and improve the effectiveness of abnormal detection and early warning.
[0123] Example 4:
[0124] Collect final anomaly mitigation data and risk level retest results after the early warning and response are complete. For example, in a smart factory's production workshop, when the system issues an early warning for an abnormal temperature in a certain area and implements cooling measures, the final anomaly mitigation data includes the area's temperature recovery value after the measures are taken, the time required for temperature stabilization, and other information. The risk level retest results are obtained by reassessing the area's risk level after the measures are taken, such as reducing it from high risk to medium or low risk.
[0125] The final anomaly mitigation data is compared with the predicted mitigation range from the first detection model to generate an anomaly detection error signal. For example, if the first detection model predicts that the temperature in the area will return to 25°C-28°C after treatment, but the actual final temperature stabilizes at 29°C, the difference between the two will be recorded as part of the anomaly detection error signal, which contains information about the deviation between the model prediction and the actual result.
[0126] The retested risk level results are analyzed for consistency with the expected level standard of the second detection model to generate a risk assessment error signal. If the second detection model predicts a low risk level after treatment, but the retest result is medium risk, it indicates an assessment bias, which is quantified as a specific value in the risk assessment error signal.
[0127] The probability distribution rules in the first detection model are adjusted based on the systematic bias component in the anomaly detection error signal. Systematic bias refers to long-standing, regular deviations. For example, if the first detection model consistently underestimates the temperature after the anomaly has resolved, the temperature-related parameters in the probability distribution rules need to be corrected to make the model's predictions more accurate.
[0128] The grade weight coefficients in the second detection model are optimized based on the random fluctuation component in the risk assessment error signal. Random fluctuation components refer to accidental, irregular deviations. For example, during a retest, a deviation in the risk grade assessment may be caused by temporary personnel manipulation. In this case, the grade weight coefficients are adjusted to reduce the impact of accidental factors on the risk grade classification.
[0129] The adjusted probability distribution rules and grade weight coefficients are synchronously updated to the historical feature library of the initial feature set, so that subsequent model construction can be based on the updated historical data to maintain the adaptability of the model.
[0130] The process of adjusting the probability distribution rules and grade weight coefficients includes:
[0131] Identify the static deviation component in the anomaly detection error signal and calculate the static compensation value using a sliding average filter. This method averages the error signal over a period of time, filtering out short-term fluctuations and extracting the static deviation component. For example, if the model's predicted value is consistently 2°C lower than the actual value over multiple consecutive detections, the static deviation component is 2°C, and the corresponding static compensation value is also 2°C.
[0132] Adjust the baseline probability threshold in the anomaly probability calculation function based on the static compensation value. If the static compensation value is positive, it means that the model tends to underestimate the anomaly probability, and the baseline probability threshold needs to be increased. If the static compensation value is negative, the baseline probability threshold should be lowered to balance the model's prediction results.
[0133] Identify dynamic interference components in the risk assessment error signal and extract effective correction parameters using an adaptive filtering algorithm. This algorithm automatically adjusts filtering parameters based on changes in the interference signal, effectively isolating dynamic interference components, such as risk assessment deviations caused by temporary equipment failures, and extracting the corresponding correction parameters.
[0134] Adjust the level determination thresholds in the risk classification matrix based on the effective correction parameters. If the effective correction parameters indicate that the risk level corresponding to a behavioral feature is overestimated, the level determination threshold corresponding to that feature is increased to reduce misjudgments; if it is underestimated, the level determination threshold is lowered to improve detection sensitivity.
[0135] The updated anomaly probability calculation function and risk level division matrix replace the original model parameters to complete the instant update of the model, ensuring that subsequent anomaly detection and risk assessment can be based on a more accurate model.
[0136] Example 5:
[0137] The target scenario's corresponding scene type code is parsed to identify the environmental feature identifiers and behavioral pattern encoding segments to generate a scene feature description vector. The scene type code is a character sequence containing key scene information. The environmental feature identifiers record the scene's physical attributes, such as space size, ventilation conditions, and equipment density. The behavioral pattern encoding segments record common behavioral entities and patterns within the scene, such as personnel turnover and equipment operation cycles. During the parsing process, these identifiers and encoding segments are converted into quantifiable values and arranged according to pre-set dimensions to form a scene feature description vector. Each dimension corresponds to the quantified value of a specific feature.
[0138] The scene feature description vector is input into the preloaded scene configuration database for multi-dimensional matching retrieval, and the candidate baseline configuration set whose matching degree with the current scene type code exceeds the adaptation threshold is screened out. The scene configuration database stores a large amount of configuration information of historical scenes. Each configuration information contains the corresponding scene feature description vector and complete parameter configuration. During multi-dimensional matching retrieval, the similarity between the current scene feature description vector and the historical scenes in the database is calculated from multiple dimensions such as environmental characteristics, behavior patterns, and scene scale. The historical configuration information with similarity higher than the adaptation threshold is included in the candidate baseline configuration set.
[0139] For each candidate benchmark configuration in the candidate benchmark configuration set, the following operations are performed: the average anomaly detection rate and risk level accuracy rate from its historical application records are extracted to calculate a comprehensive configuration effectiveness score. The average anomaly detection rate is the ratio of the number of anomalies successfully detected by the configuration in historical applications to the number of anomalies that actually occurred, while the risk level accuracy rate is the proportion of the risk level determined by the configuration that matches the actual risk level. The comprehensive configuration effectiveness score is calculated by weighting these two indicators, with the weights set based on the scenario's emphasis on anomaly detection and risk assessment.
[0140] The candidate benchmark configuration sets are prioritized based on their comprehensive configuration effectiveness scores, and the highest-scoring candidate is selected as the optimal benchmark environment parameter template. The optimal benchmark environment parameter template includes key parameters such as the baseline value, fluctuation range, and monitoring frequency of the environmental parameters in this scenario.
[0141] A reference set of behavioral patterns that are configurationally correlated with the optimal baseline environmental parameter template is extracted from the scenario configuration database. Configuration correlation refers to the synergistic relationship between behavioral patterns and environmental parameters in historical applications, such as common human behavior patterns and equipment operation modes under specific environmental parameters.
[0142] For each pattern data in the behavior pattern reference set, the synergy between the pattern characteristics and the environmental parameters is verified as follows:
[0143] Extract the feature data of a single pattern to be verified from the behavioral pattern reference set, and simultaneously obtain a sequence of environmental parameters from the optimal baseline environmental parameter template that is time-aligned with the pattern to be verified. Time alignment ensures that the occurrence time of the behavioral pattern is consistent with the collection time of the corresponding environmental parameters. For example, the behavioral pattern data of a person entering a certain area must correspond to the environmental parameters such as temperature and humidity at the same time.
[0144] Based on the change nodes in the environmental parameter sequence, the corresponding collaborative time markers are annotated on the pattern to be verified, generating a pattern characteristic curve with a time series identifier. The change node of the environmental parameter sequence is the time point when the environmental parameter changes significantly, such as when the temperature suddenly rises by 5°C. The collaborative time marker is annotated on the corresponding behavior pattern curve at this moment to clarify the temporal relationship between environmental changes and behavioral pattern changes.
[0145] The system traverses each collaborative time marker in the time-series-identified pattern feature curve and checks whether the feature change rate within the adjacent time window exceeds a preset mutation threshold. This identifies abnormal time windows with feature mutations. The adjacent time window is a fixed period of time before and after the collaborative time marker, such as 10 seconds before to 10 seconds after the marker. The feature change rate is the ratio of the change amplitude of the behavioral feature within this window to the time. The preset mutation threshold is set based on the fluctuation range of the historical behavioral feature.
[0146] When an abnormal time window is identified, the environmental parameter values at the corresponding time point in the optimal baseline environmental parameter template are reviewed to determine whether the direction of change in the environmental parameter values has an adverse effect on the direction of the characteristic mutation. An adverse effect occurs when the trend of environmental parameter changes should suppress the mutation of behavioral characteristics but actually promotes it, or when it should promote it but actually suppresses it. For example, when the ambient temperature rises, people should reduce their stay in high-temperature areas, but if the behavioral pattern shows that the stay time increases, it is determined to be an adverse effect.
[0147] If the adverse impact intensity exceeds the conflict threshold, the abnormal time window is marked as a parameter conflict region, and the starting position and duration of the parameter conflict region in the pattern characteristic curve are calculated. The adverse impact intensity is determined by quantifying the degree to which changes in environmental parameters affect the sudden change in behavioral characteristics. The conflict threshold is set based on the scenario's requirements for parameter coordination.
[0148] Based on the starting location and duration of the parameter conflict region, a feature correction window is defined on the pattern to be verified. Alternative feature smoothing segments are generated based on the correction records of similar conflicts in the historical feature library. The duration of the feature correction window matches the duration of the parameter conflict region. Alternative feature smoothing segments are generated based on historical correction methods for similar conflicts, such as correcting sudden behavioral feature values to smooth curves that conform to the changing trends of environmental parameters.
[0149] The alternative feature smooth segment is inserted into the feature correction window to generate an optimized behavior pattern curve, and the abnormal data points in the original pattern feature curve that overlap with the parameter conflict area are deleted.
[0150] A complete integrity check is performed on all optimized behavior pattern curves in the behavior pattern reference set that have completed substitution insertion operations, and residual curves that still contain uncorrected conflict regions are eliminated. The completeness check is achieved by checking whether there are unlabeled abnormal time windows or parameter conflict regions in the curves.
[0151] The optimized behavior pattern curves that have passed the verification are merged into the optimized behavior pattern benchmark set.
[0152] Based on the historical stability indicators of each optimized behavior model in the set, the optimized behavior model with the smallest volatility index is selected as the optimal behavior model. Historical stability indicators include the fluctuation amplitude and duration stability of the model curve. The volatility index is a comprehensive quantitative value of these indicators. A smaller volatility index indicates a more stable model.
[0153] The optimal baseline environmental parameter template and the optimal behavioral model benchmark are time-aligned to generate the baseline parameter configuration for the initial feature set. This configuration time alignment ensures the temporal synchronization of environmental parameters and behavioral models by adjusting the time axis of the parameters, ensuring that the baseline parameter configuration accurately reflects the synergistic relationship between the environment and behavior in the initial state of the scenario.
[0154] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.
[0155] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A context-aware driven multi-dimensional anomaly detection and early warning method, characterized in that: The method comprises: Collecting real-time context data in the target monitoring scene to generate an initial feature set, the initial feature set including an environmental parameter sequence and a behavior pattern map; Constructing a first detection model adapted to the scene type based on the environmental parameter sequence in the initial feature set, wherein the first detection model includes a dynamic correlation function between environmental indicators and abnormality probabilities; Constructing a second detection model adapted to the scenario type based on the behavior pattern map in the initial feature set, wherein the second detection model includes a nonlinear mapping rule between behavior features and risk levels; Based on the context deviation data and the characteristic fluctuation coefficient data during the real-time monitoring process, triggering the target model in the first detection model or the second detection model, and generating a dynamic warning instruction through the target model; The dynamic warning instruction is pushed to the execution module of the monitoring system to adjust the trigger threshold of the abnormal response strategy or the priority of the risk disposal process.
2. The context-aware multi-dimensional anomaly detection and early warning method according to claim 1 is characterized in that: The collecting of real-time context data in the target monitoring scene to generate an initial feature set includes: Synchronously collect environmental status data of the target scene within the monitoring period through multi-source sensing devices, wherein the environmental status data includes a physical parameter time sequence stream and a logical state code set; Dividing the target scene into at least two sub-scene units according to the characteristic interval in the physical parameter time series stream, and assigning a corresponding initial monitoring threshold range and risk assessment benchmark value to each sub-scene unit; Extract historical environment correction parameters and behavioral feature compensation coefficients that match each sub-scene unit from the preset feature library; Performing spatiotemporal alignment processing on the historical environmental correction parameters to generate an optimized environmental parameter sequence corresponding to each sub-scene unit; Performing trend smoothing processing on the behavioral feature compensation coefficient to generate an optimized behavioral pattern map corresponding to each sub-scene unit; The initial feature set is generated by fusing the optimized environmental parameter sequence and the optimized behavior pattern map of each sub-scene unit.
3. The context-aware driven multi-dimensional anomaly detection and early warning method according to claim 2 is characterized in that: Constructing a first detection model and a second detection model includes: Inputting the optimized environmental parameter sequence into a preset rule inference engine, iteratively updating the rule weights through multiple rounds of condition matching, and generating an abnormality probability calculation function in the first detection model, wherein the abnormality probability calculation function is the target model in the first detection model; Inputting the optimized behavior pattern map into a statistical feature extraction module, screening key behavior indicators through a feature dimensionality reduction algorithm, and generating a risk level division matrix in the second detection model; the risk level division matrix is the target model in the second detection model; After the rule inference engine and the statistical feature extraction module are running stably, the core parameter vectors in the abnormal probability calculation function and the risk level division matrix are extracted respectively; Performing a correlation analysis between the core parameter vector and the environmental status data collected in real time to verify the applicability of the first detection model and the second detection model; When the correlation analysis result is lower than a preset threshold, the matching conditions of the rule inference engine and the dimension reduction parameters of the statistical feature extraction module are readjusted until the core parameter vector meets the applicability condition.
4. The context-aware driven multi-dimensional anomaly detection and early warning method according to claim 3 is characterized in that: The triggering of the target model in the first detection model or the second detection model based on the context deviation data and the characteristic fluctuation coefficient data in the real-time monitoring process, and generating a dynamic warning instruction through the target model, includes: Real-time tracking of context deviation change curve and characteristic fluctuation coefficient amplitude during monitoring process; When the context deviation change curve exceeds a first trigger threshold and the characteristic fluctuation coefficient amplitude is within a preset safety range, triggering an abnormality probability calculation function in the first detection model; Generate a dynamic threshold adjustment instruction for an abnormal response strategy according to the probability distribution rule in the abnormal probability calculation function; When the amplitude of the characteristic fluctuation coefficient exceeds a second trigger threshold and the context deviation change curve is in a preset stable range, triggering the risk level division matrix in the second detection model; Generating dynamic priority adjustment instructions for the risk handling process according to the level determination rules in the risk level classification matrix; If the context deviation change curve and the characteristic fluctuation coefficient amplitude both exceed the trigger threshold, the dynamic threshold adjustment instruction generated by the first detection model will be executed first, and the adjustment instruction of the second detection model will be delayed until the abnormal response strategy completes the threshold update.
5. The context-aware driven multi-dimensional anomaly detection and early warning method according to claim 4 is characterized in that: The step of pushing the dynamic warning instruction to the execution module of the monitoring system and adjusting the triggering threshold of the abnormal response strategy or the priority of the risk handling process includes: According to the threshold compensation value in the dynamic threshold adjustment instruction, the determination threshold of each warning level in the abnormal response strategy is updated in stages; After each threshold update, real-time abnormal probability data is collected and deviation analysis is performed with the predicted value of the abnormal probability calculation function; If the deviation value continues to decrease, the current threshold adjustment direction is maintained until the target probability interval is reached; If the deviation value shows an upward trend, the judgment threshold is adjusted in the opposite direction and the parameter optimization of the abnormal probability calculation function is re-triggered; Dynamically configure the execution order of the risk disposal process in different scenarios according to the priority parameters in the dynamic priority adjustment instruction; During the priority adjustment process, the risk treatment effect is monitored in real time through the status feedback mechanism, and the level weights in the risk level classification matrix are dynamically updated according to the monitoring results.
6. The context-aware driven multi-dimensional anomaly detection and early warning method according to claim 3 is characterized in that: The method further includes an effect calibration phase after the dynamic warning instruction is executed, including the following operations: Collect final anomaly mitigation data and risk level retest results after early warning and disposal are completed; comparing the final anomaly mitigation data with the predicted mitigation range of the first detection model to generate an anomaly detection error signal; Performing consistency analysis on the risk level retest result and the expected level standard of the second detection model to generate a risk assessment error signal; adjusting a probability distribution rule in the first detection model according to a system deviation component in the abnormality detection error signal; optimizing a grade weight coefficient in the second detection model according to a random fluctuation component in the risk assessment error signal; The adjusted probability distribution rules and grade weight coefficients are synchronously updated to the historical feature library of the initial feature set.
7. The context-aware driven multi-dimensional anomaly detection and early warning method according to claim 6 is characterized in that: The process of adjusting the probability distribution rules and grade weight coefficients includes: Identifying a static deviation component in the abnormality detection error signal and calculating a static compensation value by a sliding average filtering method; Adjusting the baseline probability threshold in the abnormal probability calculation function according to the static compensation value; Identifying dynamic interference components in the risk assessment error signal and extracting effective correction parameters through an adaptive filtering algorithm; Adjusting the level determination threshold in the risk level classification matrix according to the effective correction parameter; The updated abnormal probability calculation function and risk level division matrix replace the original model parameters.
8. The context-aware driven multi-dimensional anomaly detection and early warning method according to claim 1 is characterized in that: The method further includes performing the following initialization operations before the system is started, including: Parse the environmental feature identifier and behavior pattern encoding segment in the scene type code corresponding to the target scene to generate a scene feature description vector; Inputting the scene feature description vector into a preloaded scene configuration database for multi-dimensional matching retrieval, and screening out candidate benchmark configuration sets whose matching degree with the current scene type code exceeds an adaptation threshold; For each candidate benchmark configuration in the candidate benchmark configuration set, the following operations are performed: extracting the average anomaly detection rate and risk level accuracy rate in its historical application records, and calculating a comprehensive configuration effectiveness score; Prioritizing the candidate benchmark configuration sets according to the comprehensive configuration effectiveness scores, and selecting the candidate benchmark configuration with the highest score as the optimal benchmark environment parameter template; Extracting a reference set of behavior patterns that have configuration relevance to the optimal benchmark environment parameter template from a scenario configuration database; Verify the synergy between pattern features and environmental parameters for each pattern data in the behavior pattern reference set, eliminate abnormal patterns with conflicting features or contradictory parameters, and generate an optimized behavior pattern benchmark set; According to the historical operation stability index of each optimized behavior pattern benchmark in the optimized behavior pattern benchmark set, the optimized behavior pattern benchmark with the smallest volatility index is selected as the optimal behavior pattern benchmark; The optimal benchmark environment parameter template and the optimal behavior pattern benchmark are configured in time sequence alignment to generate a benchmark parameter configuration of an initial feature set.
9. The context-aware driven multi-dimensional anomaly detection and early warning method according to claim 8 is characterized in that: The verifying the synergy between the pattern features and the environmental parameters for each pattern data in the behavior pattern reference set includes: Extracting characteristic data of a single pattern to be verified from the behavioral pattern reference set, and synchronously obtaining an environmental parameter sequence in the optimal baseline environmental parameter template that is time-aligned with the pattern to be verified; According to the change nodes of the environmental parameter sequence, corresponding collaborative time marks are marked on the pattern to be verified to generate a pattern characteristic curve with a time sequence mark; Traversing each collaborative time marker in the pattern characteristic curve with a time sequence identifier, detecting whether the characteristic change rate in its adjacent time window exceeds a preset mutation threshold, and identifying abnormal time windows with characteristic mutations; When an abnormal time window is identified, the environmental parameter value of the corresponding time node in the optimal benchmark environmental parameter template is traced back to determine whether the change direction of the environmental parameter value has an adverse effect on the characteristic mutation direction; If the adverse impact intensity exceeds the conflict threshold, the abnormal time window is marked as a parameter conflict area, and the starting position and duration of the parameter conflict area in the pattern characteristic curve are calculated; Defining a feature correction window on the to-be-verified pattern according to the starting position and duration of the parameter conflict region, and generating an alternative feature smoothing segment based on correction records of similar conflicts in a historical feature library; Inserting the replacement feature smooth segment into the feature correction window to generate an optimized behavior pattern curve, and deleting abnormal data points in the original pattern feature curve that overlap with the parameter conflict area; Performing integrity check on all optimized behavior pattern curves that have completed the substitution insertion operation in the behavior pattern reference set, and removing residual curves that still contain uncorrected conflict areas; The optimized behavior pattern curves that have passed the verification are merged into the optimized behavior pattern benchmark set.
10. The context-aware driven multi-dimensional anomaly detection and early warning method according to claim 5, characterized in that: The determination thresholds for each warning level in the phased update abnormal response strategy include: Determining the stage interval of threshold value update based on the rate of change of the environmental parameter sequence, and dividing the total adjustment interval into at least three consecutive sub-adjustment stages; Allocate a corresponding threshold adjustment step length to each sub-adjustment stage, and the threshold adjustment step length increases according to a preset ratio as the stage progresses; After each sub-adjustment phase is completed, the deviation rate between the mean abnormal probability of the current phase and the target probability interval is collected; If the deviation rate is less than the stage threshold, the next sub-adjustment stage is entered; if the deviation rate is greater than or equal to the stage threshold, the current update process is suspended and the parameter recalibration of the abnormal probability calculation function is triggered; After all sub-adjustment stages are completed, a final check is performed on the judgment thresholds of each warning level to ensure that the difference between adjacent level thresholds meets the preset gradient requirements.
Citation Information
Patent Citations
Airport boundary intrusion detection and alarm linkage system
CN119007417A
Optical cable routing anti-intrusion method and system
CN119628935A
Forest fire prevention early warning method and system based on multi-source sensor
CN120048096A
Oil depot safety risk intelligent early warning method and system based on data fusion
CN120067877A
Steel production risk dynamic early warning method, device, equipment and medium
CN120579824A
Cited By
Online analysis system for dynamic flow abnormity of plastic check valve
CN120927278A
Pepper breeding isolation shed control system based on Internet of Things
CN120935230A
APT organization infrastructure hunting method based on IOC recursive extension
CN121173578A
Data processing method and system for chemical production informatization management platform
CN121234271A
Intelligent security access control system
CN121415495A