Behavior analysis early warning method and system based on AI situation awareness
By constructing a dynamic spatiotemporal graph and a deep reinforcement learning (DRL) model, and dynamically adjusting weights and thresholds, the feature representation problem of multi-source heterogeneous data is solved, enabling adaptive threat assessment and response for multi-source data, and improving the accuracy of early warning and the efficiency of response.
Patent Information
- Application Number
- CN202511316510.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-16
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2045-09-16
AI Technical Summary
In existing technologies, the lack of unified feature representation for multi-source heterogeneous data leads to the loss of cross-modal correlation, the inability to dynamically update spatiotemporal correlation, the fixed weights of multimodal feature fusion affecting the effectiveness of fusion, the lack of adaptability in threat assessment, and the lag in model parameter updates leading to long-term performance degradation.
By collecting multi-source sensing data such as video, sensors, and network traffic, the system extracts target spatiotemporal features, equipment operation features, and operation sequence features, constructs a dynamic spatiotemporal graph, and performs edge correlation self-learning. It then combines a deep reinforcement learning (DRL) model to perform threat assessment and response strategy generation, and dynamically adjusts weights and thresholds to optimize the feature extraction and fusion process.
It enables dynamic correlation of multi-source data and adaptive threat assessment, improves the accuracy of early warning and response efficiency, solves the problems of cross-modal correlation loss, inability to dynamically update spatiotemporal correlation and model parameter update lag, and improves the long-term performance of the system.
Smart Images

Figure CN120805088A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data recognition, in particular to a behavior analysis and early warning method and system based on AI situational awareness. BACKGROUND
[0002] In the prior art, the behavior analysis and early warning method based on data recognition and processing still has deficiencies in multi-source information fusion, dynamic correlation analysis and adaptive decision-making. For heterogeneous data such as video, sensor, network traffic and behavior log, the feature extraction process is mostly independent processing, lacking a unified feature representation framework, and the correlation relationship of cross-modal information is difficult to fully reflect; in the spatio-temporal correlation analysis, the traditional method mostly relies on fixed rules to construct the relationship between nodes, which is difficult to reflect the dynamic changes of spatio-temporal features in real time, and cannot realize the dynamic screening of effective edges; in the multi-modal feature fusion, the weight setting is mostly a preset fixed value, without dynamic adjustment combined with real-time quality indicators (such as integrity, accuracy, scene adaptation) of each modal data, affecting the reliability of the fusion result; in the threat assessment link, the existing method often relies on artificial rules or static models, lacking adaptability to complex scenes and resource occupation, and it is difficult to output accurate threat risk value and response strategy; in the model optimization aspect, the correlation threshold, fusion weight and strategy parameter are updated with lag, and cannot be dynamically adjusted according to the feedback of early warning accuracy, threat interception success rate, etc., leading to a decline in long-term performance.
[0003] Therefore, there is an urgent need for a behavior analysis and early warning technology that can realize dynamic correlation of multi-source data, real-time weight adjustment, adaptive threat assessment and closed-loop optimization, in order to improve the early warning accuracy and response efficiency in complex scenarios. SUMMARY
[0004] The purpose of the present application is to provide a behavior analysis and early warning method and system based on AI situational awareness, to solve the technical problems in the prior art that the lack of unified feature representation of multi-source heterogeneous data leads to loss of cross-modal correlation, the spatio-temporal correlation relationship cannot be dynamically updated to capture real-time changes, the fixed fusion weight of multi-modal features affects the effectiveness of fusion, the threat assessment lacks adaptability to adapt to complex scenarios, and the model parameter update lags, leading to long-term performance degradation.
[0005] In view of the above technical problems, the present application provides a behavior analysis and early warning method and system based on AI situational awareness.
[0006] In a first aspect of the embodiments of the present application, a behavior analysis and early warning method based on AI situational awareness is provided, the method comprising: acquiring multi-source perception data including video, sensor, network traffic and behavior log through a collection device, respectively extracting corresponding target spatio-temporal features, device running features, transmission features and operation sequence features, and converting them into numerical feature vectors; The feature vector is taken as a graph node, real-time space-time correlation degrees between nodes are calculated, and valid edges are screened based on the real-time space-time correlation degrees by using an edge correlation degree dynamic threshold self-learning algorithm to construct a dynamic space-time graph, and space-time correlation features are extracted based on the valid edges, the edge correlation degree dynamic threshold self-learning algorithm comprises obtaining a historical valid edge set, calculating a historical observation correlation degree based on the historical valid edge set, constructing a loss function through the real-time space-time correlation degree and the historical observation correlation degree, iteratively updating a dynamic weight coefficient based on a gradient descent method, and generating an edge correlation degree dynamic threshold based on the updated dynamic weight coefficient and a correlation degree distribution of the historical valid edge set; Based on the historical detection accuracy, the current data integrity, and the scene adaptation degree of each modality data, a modality weight coefficient is calculated, the space-time correlation features are weighted and fused to obtain a multi-modality comprehensive feature, the calculation of the modality weight coefficient is that the historical detection accuracy and the scene adaptation degree are multiplied to obtain a first factor, the arithmetic square root of the current data integrity is taken as a second factor, the first factor and the second factor are multiplied, and then normalized processing is performed so that the sum of all modality weight coefficients is 1; Based on the multi-modality comprehensive feature, the historical detection accuracy, and the real-time resource occupation rate of each modality data, a threat assessment is performed through a deep reinforcement learning (DRL) model containing a strategy parameter, a threat risk value and a corresponding security response strategy are output, when the threat risk value reaches a preset judgment condition, the corresponding security response strategy is triggered, the DRL model combines the multi-modality comprehensive feature, the historical detection accuracy of each modality data, and the real-time resource occupation rate into a multi-dimensional state vector, calculates the threat risk value based on the multi-dimensional state vector and the strategy parameter, the strategy parameter is used to control the feature selection weight, the state transition probability, and the action decision rule in the threat risk value calculation process, and iteratively updates the strategy parameter through a time difference algorithm based on the threat interception success rate and the early warning accuracy, and generates the corresponding security response strategy according to the threat risk value; Based on the threat risk value, the early warning accuracy after the execution of the security response strategy, and the threat interception success rate, the dynamic weight coefficient, the edge correlation degree dynamic threshold, and the strategy parameter are updated through the edge correlation degree dynamic threshold self-learning algorithm and the time difference algorithm of the DRL model, and an updated parameter group is output, the parameter group is used to optimize the feature extraction, fusion, and threat assessment process of the next round of multi-source perception data.
[0007] In a second aspect, the embodiment of the present application provides a behavior analysis and early warning system based on AI situational awareness, the system comprises: A multi-source data collection and feature extraction module is configured to acquire multi-source perception data including videos, sensors, network traffic and behavior logs through a collection device, extract corresponding target spatio-temporal features, device operation features, transmission features and operation sequence features respectively, and convert them into a numerical feature vector; A dynamic spatio-temporal graph construction and spatio-temporal correlation feature extraction module is configured to take the feature vector as a graph node, calculate real-time spatio-temporal correlation degrees between nodes, filter effective edges based on the real-time spatio-temporal correlation degrees using a dynamic edge correlation degree threshold self-learning algorithm, construct a dynamic spatio-temporal graph, and extract spatio-temporal correlation features based on the effective edges. The dynamic edge correlation degree threshold self-learning algorithm includes obtaining a historical effective edge set, calculating a historical observation correlation degree based on the historical effective edge set, constructing a loss function through the real-time spatio-temporal correlation degree and the historical observation correlation degree, iteratively updating a dynamic weight coefficient based on a gradient descent method, and generating an edge correlation degree dynamic threshold based on the updated dynamic weight coefficient and the correlation degree distribution of the historical effective edge set; A multi-modal feature fusion module is configured to calculate a modal weight coefficient based on the historical detection accuracy, current data integrity and scene adaptability of each modal data, weight and fuse the spatio-temporal correlation features to obtain a multi-modal comprehensive feature. The calculation of the modal weight coefficient is to multiply the historical detection accuracy and the scene adaptability to obtain a first factor, take the arithmetic square root of the current data integrity as a second factor, multiply the first factor and the second factor, and then normalize the result so that the sum of all modal weight coefficients is 1; A threat assessment and response strategy generation module is configured to perform threat assessment through a deep reinforcement learning (DRL) model containing strategy parameters based on the multi-modal comprehensive feature, the historical detection accuracy of each modal data and real-time resource occupancy rate, output a threat risk value and a corresponding security response strategy, and trigger the corresponding security response strategy when the threat risk value reaches a preset judgment condition. The DRL model combines the multi-modal comprehensive feature, the historical detection accuracy of each modal data and the real-time resource occupancy rate into a multi-dimensional state vector, calculates a threat risk value based on the multi-dimensional state vector and strategy parameters, and iteratively updates the strategy parameters based on the threat interception success rate and the early warning accuracy rate through a time difference algorithm. The corresponding security response strategy is generated according to the threat risk value. A parameter dynamic optimization module is configured to update a dynamic weight coefficient and an edge correlation dynamic threshold by using the edge correlation dynamic threshold self-learning algorithm based on the threat risk value, the pre-warning accuracy rate after the security response strategy is executed, and the threat interception success rate, update a strategy parameter by using a time difference algorithm of a deep reinforcement learning (DRL) model, and output an updated parameter group, which is used for optimizing feature extraction, fusion, and threat evaluation of multi-source perception data in a next round.
[0008] One or more technical solutions provided in the application have at least the following technical effects or advantages: The multi-source perception data including videos, sensors, network traffic and behavior logs are acquired through acquisition equipment, and the corresponding target spatiotemporal features, equipment operation features, transmission features and operation sequence features are extracted respectively, and converted into numerical feature vectors; the feature vectors are used as graph nodes, and the real-time spatiotemporal correlation between nodes is calculated. Based on the real-time spatiotemporal correlation, the edge correlation dynamic threshold self-learning algorithm is used to screen the effective edges, construct a dynamic spatiotemporal graph, and extract spatiotemporal correlation features based on the effective edges. The edge correlation dynamic threshold self-learning algorithm includes obtaining a historical effective edge set, calculating the historical observation correlation based on the historical effective edge set, and filtering the effective edges through the real-time spatiotemporal correlation. A loss function is constructed with the historical observation correlation, and the dynamic weight coefficient is iteratively updated based on the gradient descent method. The edge correlation dynamic threshold is generated based on the updated dynamic weight coefficient and the correlation distribution of the historical valid edge set; based on the historical detection accuracy of each modal data, the current data integrity and the scene adaptability, the modal weight coefficient is calculated, and the spatiotemporal correlation features are weighted and fused to obtain multimodal comprehensive features. The modal weight coefficient is calculated by multiplying the historical detection accuracy and the scene adaptability to obtain the first factor, and the arithmetic square root of the current data integrity is used as the second factor. After multiplying the first factor and the second factor, the normalization process is performed to make all modalities The sum of the state weight coefficients is 1; based on the multimodal comprehensive features, the historical detection accuracy of each modal data and the real-time resource occupancy rate, a threat assessment is performed through a deep reinforcement learning DRL model containing strategy parameters, and a threat risk value and a corresponding security response strategy are output. When the threat risk value reaches a preset judgment condition, a corresponding security response strategy is triggered. The deep reinforcement learning DRL model combines the multimodal comprehensive features, the historical detection accuracy of each modal data and the real-time resource occupancy rate into a multidimensional state vector, and calculates the threat risk value based on the multidimensional state vector and the strategy parameters. The strategy parameters are used to control the calculation of the threat risk value. The feature selection weights, state transition probabilities, and action decision rules in the process are iteratively updated through the temporal difference algorithm based on the threat interception success rate and warning accuracy, and a corresponding security response strategy is generated according to the threat risk value; based on the threat risk value, the warning accuracy after the execution of the security response strategy, and the threat interception success rate, the dynamic weight coefficient and the dynamic threshold of the edge correlation are updated through the self-learning algorithm of the edge correlation dynamic threshold, and the strategy parameters are updated through the temporal difference algorithm of the deep reinforcement learning DRL model, and the updated parameter group is output. The parameter group is used to optimize the feature extraction, fusion, and threat assessment process of the next round of multi-source perception data. The technical problems in the existing technology of lack of unified feature representation of multi-source heterogeneous data leading to loss of cross-modal correlation, inability to dynamically update spatiotemporal correlation relationships to capture real-time changes, fixed multimodal feature fusion weights affecting fusion effectiveness, lack of adaptability of threat assessment to complex scenarios, and lagging model parameter updates leading to long-term performance degradation are solved.
[0009] The above description is only a summary of the technical solutions of the present application. In order to more clearly illustrate the technical means of the present application, and then can be implemented according to the content of the specification, and in order to make the above and other purposes, characteristics and advantages of the present application more obvious and easy to understand, the following specific embodiments of the present application are described. BRIEF DESCRIPTION OF DRAWINGS
[0010] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings of the embodiments of the present application will be briefly introduced below. The flowchart is used to illustrate the operations performed by the system according to the embodiments of the present application in the present application. It should be understood that the foregoing or the following operations are not necessarily performed in sequence. On the contrary, according to the needs, various steps can be processed in reverse order or at the same time. At the same time, other operations can be added to these processes, or one or more steps of operation can be removed from these processes.
[0011] Figure 1 The flowchart of the behavior analysis and early warning method based on AI situational awareness provided by the embodiments of the present application; Figure 2 The structural diagram of the behavior analysis and early warning system based on AI situational awareness provided by the embodiments of the present application.
[0012] Explanation of reference signs: multi-source data acquisition and feature extraction module 1, dynamic space-time graph construction and space-time correlation feature extraction module 2, multi-modal feature fusion module 3, threat assessment and response strategy generation module 4, parameter dynamic optimization module 5. DETAILED DESCRIPTION
[0013] The present application provides a behavior analysis and early warning method and system based on AI situational awareness, which solves the technical problems in the prior art that the lack of unified feature representation of multi-source heterogeneous data leads to the loss of cross-modal correlation, the dynamic update of space-time correlation relationship is difficult to capture real-time changes, the fixed fusion weight of multi-modal feature fusion affects the effectiveness of fusion, the threat assessment lacks adaptability and is difficult to adapt to complex scenes, and the long-term performance decay caused by the lag of model parameter update.
[0014] The technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.
[0015] It is to be understood that the terms "including", "comprising", "having" and their conjugates mean "including without limitation" and encompass the more limited "consisting" and "consisting essentially of".
[0016] In one embodiment, as shown in FIG. 1, the present application provides an AI situational awareness-based behavior analysis and early warning method, wherein the method comprises: Figure 1 Through acquisition equipment, multi-source perception data including video, sensor, network traffic and behavior log are obtained, and corresponding target space-time features, device running features, transmission features and operation sequence features are extracted and converted into numerical feature vectors.
[0017] Specifically, through camera, temperature and humidity sensor, network traffic analyzer and operation audit tool, multi-source perception data such as video data, device running sensor data, network transmission traffic data and user operation behavior log are obtained; for video data, target detection and tracking algorithm based on deep learning is used to extract target space-time features such as target position coordinates, motion speed and appearance duration; for sensor data, device running features such as running temperature, vibration frequency and energy consumption value are extracted through signal analysis; for network traffic data, transmission features such as source IP, destination IP, transmission rate and packet size distribution are extracted through protocol analysis; for behavior log, operation sequence features such as user operation type, execution time and operation object are extracted through instruction analysis; and through Min-Max normalization processing (mapping feature values to the interval [0, 1]) and one-hot encoding (for category type features), the above features are uniformly converted into numerical feature vectors.
[0018] The feature vectors are taken as graph nodes, real-time space-time correlation degrees between nodes are calculated, effective edges are screened based on the real-time space-time correlation degrees using edge correlation degree dynamic threshold self-learning algorithm, a dynamic space-time graph is constructed, and space-time correlation features are extracted based on the effective edges.
[0019] Further, the construction of the dynamic space-time graph comprises: The feature vectors of multi-source perception data at the same observation time or within a preset time window are taken as graph nodes, the spatial coordinate difference of the nodes is taken as the spatial distance, the timestamp difference is taken as the time interval, and the cosine similarity of the feature vectors is taken as the feature similarity, and the real-time space-time correlation degrees between the nodes are calculated through a dynamic weight fusion function ; The dynamic weight fusion function is: ; wherein is the normalized spatial distance, is the normalized time interval, is the feature similarity, is the dynamic weight coefficient, which is updated by the edge correlation dynamic threshold self-learning algorithm to meet ; Adopting the edge correlation dynamic threshold self-learning algorithm, we select node pairs whose real-time spatiotemporal correlation is not less than the edge correlation dynamic threshold and whose historical effective edge accuracy is not less than the preset accuracy threshold as the effective edges of the current cycle; The historical effective edge accuracy is the ratio of the number of times the threat interception behavior in which the edge participated was confirmed to be effective to the total number of times the edge was determined to be effective within the preset evaluation period; Constructing a dynamic spatiotemporal graph based on the nodes corresponding to the feature vectors and the filtered valid edges; Furthermore, the edge correlation dynamic threshold self-learning algorithm includes: Get the historical valid edge set The historical valid edge set is an edge set whose historical valid edge accuracy is not less than a preset accuracy threshold within a preset evaluation period; Based on the original multi-source perception data of the corresponding time period of the historical valid edge set, the historical observation correlation is calculated through the dynamic weight fusion function ; To minimize the real-time spatiotemporal correlation Correlation with historical observations The difference between them is the target, the loss function is constructed, and the dynamic weight coefficient is iteratively updated based on the gradient descent method. Until the loss function converges to the preset convergence threshold; The loss function for: ; in, is the historical valid edge set The number of samples; Based on the updated dynamic weight coefficient and the correlation distribution of the historical valid edge set, the dynamic threshold of the edge correlation of the current period is generated.
[0020] Furthermore, the generation of the edge relevance dynamic threshold of the current period based on the updated dynamic weight coefficient and the relevance distribution of the historical valid edge set includes: Performing weighted processing on the association degree distribution of the historical valid edge set, where the weight is obtained by combining the dynamic weight coefficient and the historical observation association degree; generating an initial edge correlation threshold according to the weighted correlation distribution and the historical effective edge accuracy; The initial threshold is adjusted based on the real-time threat false alarm rate of the current period to obtain a dynamic threshold for edge correlation. The real-time threat false alarm rate is the proportion of instances determined by the system to be threats in the current period that are confirmed to be non-threats after manual review or subsequent analysis. The edge correlation dynamic threshold is used to screen valid edges in the current cycle.
[0021] Furthermore, the extraction of spatiotemporal correlation features includes: Taking the node feature vectors in the dynamic spatiotemporal graph as input, weighted fusion is performed on the features of each node and its neighboring nodes connected by valid edges to obtain dynamic weighted fusion features, where the fusion weight is determined by the normalized real-time spatiotemporal correlation of the corresponding edges; Calculate the edge weight mean change rate, which is the relative change rate of the mean of the weights of all valid edges of the node in the current time window and the corresponding mean in the previous time window; The dynamic weighted fusion feature, the edge weight mean change rate, and the node position information encoding vector are combined to generate the spatiotemporal correlation feature vector.
[0022] Specifically, the feature vectors are used as graph nodes to calculate the real-time spatiotemporal correlation between nodes, and based on the real-time spatiotemporal correlation, the edge correlation dynamic threshold self-learning algorithm is used to screen effective edges, construct a dynamic spatiotemporal graph, and extract spatiotemporal correlation features based on effective edges. The process of constructing a dynamic spatiotemporal graph includes: using the feature vectors of multi-source perception data within the same observation moment or preset time window (10 seconds) as nodes, using the spatial coordinate difference of the nodes as the spatial distance, the timestamp difference as the time interval, and the cosine similarity of the feature vectors as the feature similarity, and calculating the real-time spatiotemporal correlation between nodes through a dynamic weight fusion function; the dynamic weight fusion function is ;in For nodes and nodes The normalized spatial distance between them is calculated as follows: ,in is a node The spatial coordinates of is a node The spatial coordinates are determined by the coordinate system of the actual application scenario, such as meters. is the normalized time interval, and the calculation formula is ,in is a node The time of data collection, is a node The data collection time, in seconds or other time units. :For nodes and nodes The similarity of the feature vectors is calculated using cosine similarity, with the formula wherein is the feature vector of node , is the feature vector of node . is a dynamic weight coefficient, with initial values of 0.3, 0.25, and 0.45, respectively, satisfying = 1, and each coefficient has a lower limit of 0.05, with initial values calculated based on the average contribution of each modality feature in threat interception success cases in historical similar scenarios; the dynamic weight coefficient is updated through an edge correlation degree dynamic threshold self-learning algorithm. The edge correlation degree dynamic threshold self-learning algorithm includes: obtaining a historical effective edge set from a system threat interception record database, wherein the historical effective edge set is a set of edges with an accuracy rate not less than a preset accuracy rate threshold (0.8) within a preset evaluation period (the past 7 days), and is paired with the original multi-source perception data in the corresponding time period; calculating the historical observation correlation degree based on the dynamic weight fusion function; minimizing the difference between the real-time spatio-temporal correlation degree and the historical observation correlation degree as the target, constructing a loss function as follows: ; wherein, is the historical effective edge set, is the number of samples in the historical effective edge set ; and the dynamic weight coefficient is iteratively updated based on the gradient descent method until the loss function converges to a preset convergence threshold (0.001). The gradient descent method updates the partial derivative of according to a preset learning rate , stops when is less than the preset convergence threshold or the maximum number of iterations is reached, is the sign of the partial derivative; based on the updated dynamic weight coefficient and the correlation degree distribution of the historical effective edge set, the edge correlation degree dynamic threshold of the current period is generated, wherein the correlation degree distribution is obtained by dividing the historical effective edge set into intervals with a step size of 0.05, calculating the sample proportion in the interval and normalizing it into a probability distribution. The generation process includes: weighted processing of the correlation degree distribution of the historical effective edge set, with the weighted formula being ; wherein, is the mean of the historical observation correlation degree, is the maximum value of the mean of the historical observation correlation degree, corresponding to the edge; generating an initial edge correlation degree threshold value according to the weighted correlation degree distribution and the historical effective edge accuracy, and adjusting the initial threshold value in combination with a real-time threat false alarm rate (statistic in the past 1 hour) of the current period to obtain an edge correlation degree dynamic threshold value, the real-time threat false alarm rate being a proportion of instances determined as threats by the system and confirmed as non-threats through manual review or subsequent analysis in the current period. The edge correlation degree dynamic threshold value is used to screen effective edges in the current period. Based on the nodes corresponding to the feature vectors and the screened effective edges, a dynamic space-time graph is constructed. The extraction of the space-time correlation features includes: taking the node feature vectors in the dynamic space-time graph as input, weighting and fusing each node and the feature of the neighbor node connected through the effective edge to obtain a dynamic weighted fusion feature, and the fusion weight being determined by the real-time space-time correlation degree of the corresponding edge after normalization processing; calculating an edge weight mean rate of change, the edge weight mean rate of change being a relative change rate of the weight mean of all effective edges of the node in the current time window and the corresponding mean of the previous time window; encoding the dynamic weighted fusion feature (extended from 128 dimensions of the original feature to 256 dimensions by a graph convolution network), the edge weight mean rate of change (1 dimension), and the position information encoding vector (255 dimensions) of the node to obtain a space-time correlation feature vector, the position information encoding vector of the node being obtained in the following manner: first, obtaining the physical position information corresponding to the node from the collection metadata of the multi-source perception data, including longitude, latitude, installation height, orientation angle, and region number; normalizing the longitude, latitude, and installation height to [0, 1] [0, 1] [0, 1], wherein the highest installation height in the system deployment environment; normalizing the orientation angle to [0, 1] [0, 1] [0, 1], and representing the region number by One-Hot Encoding; then performing sine-cosine position encoding on the four continuous fields of longitude, latitude, installation height, and orientation angle, with an encoding dimension of 51, and splicing the encoding results of each field to form a 204-dimensional vector; splicing the One-Hot Encoding vector (51 dimensions) of the region number to the above vector to obtain a position information encoding vector with a total of 255 dimensions; the vector is used to retain the relative relationship and distribution characteristics of the node in the spatial layout. Splicing in order generates a space-time correlation feature vector with a dimension of 512, which is used as input for the subsequent threat assessment and response decision module.
[0023] Based on the historical detection accuracy, current data integrity, and scene adaptation degree of each modality data, a modality weight coefficient is calculated, and the space-time correlation features are weighted and fused to obtain a multi-modal comprehensive feature, the calculation of the modality weight coefficient being that a first factor is obtained by multiplying the historical detection accuracy and the scene adaptation degree, an arithmetic square root of the current data integrity is taken as a second factor, the first factor and the second factor are multiplied, and then normalized processing is performed so that the sum of all modality weight coefficients is 1.
[0024] Further, the method further comprises: Based on the video, sensor, network traffic and behavior log modal data in the multi-source perception data, the historical detection accuracy thereof is obtained respectively, the historical detection accuracy being the proportion of the number of true threat events corresponding to each modal data being correctly identified in a preset historical evaluation period to the total number of all detection events of the modal in the period; Based on the historical detection accuracy, the current data integrity and the scene adaptation degree, a weighted fusion is performed to obtain a normalized modal weight coefficient; The scene adaptation degree is obtained by evaluating the applicability indicators of each modal data in the current environment and application scene, and the applicability indicators include environmental light, device installation position, signal quality, sensor state and other factors; The data integrity is obtained by detecting the missing proportion of each modal data, and the missing proportion is the proportion of the amount of unavailable or abnormal data to the total amount of data that should be collected in the current collection period; Based on the modal weight coefficient, the spatio-temporal correlation features are weighted and fused, and the spatio-temporal correlation features corresponding to each modal are multiplied by the modal weight coefficient thereof to obtain multi-modal comprehensive features.
[0025] Specifically, based on the historical detection accuracy of each modal data, the current data integrity and the scene adaptation degree, the modal weight coefficient is calculated, the spatio-temporal correlation features are weighted and fused to obtain the multi-modal comprehensive features as follows: First, the historical detection accuracy of each modal data is counted from the video, sensor, network traffic and behavior log modal data of multi-source perception data. The calculation method of the historical detection accuracy is as follows: in a preset historical evaluation period (the past 7 days), the number of times that the real threat event corresponding to each modal data is correctly identified is divided by the total number of all detection events of the modal in the period, to obtain a proportion value and keep four decimal places. Secondly, the integrity of the multi-source perception data in the current collection period is evaluated, specifically to detect the missing proportion of each modal data, the calculation method of the missing proportion is as follows: the amount of unavailable or abnormal data in the current collection period is divided by the total amount of data that should be collected, and the result is kept to four decimal places; the judgment basis of data missing includes data packet loss, video frame damage, sensor reading exceeding physical threshold range, log record timestamp anomaly, etc. Then, the adaptation degree of the current scene is quantitatively evaluated, and the scene adaptation degree is calculated by a preset applicability index, and the applicability index includes environmental light intensity (unit lux), device installation position and monitoring area coverage (percentage), signal quality (signal-to-noise ratio dB value) and sensor state (working / abnormal mark), etc. Each index is normalized according to the range of 0~1 and weighted average to obtain the scene adaptation degree value. Next, the historical detection accuracy, the current data integrity (1 minus the missing proportion) and the scene adaptation degree are input into the weighted fusion calculation module, the historical detection accuracy is multiplied by the scene adaptation degree to obtain the first factor, the current data integrity is taken as the arithmetic square root to obtain the second factor, the first factor and the second factor are multiplied and then normalized to generate the normalized modal weight coefficient, and the sum of all modal weight coefficients is 1. Finally, based on the modal weight coefficient, the spatio-temporal correlation features are weighted and fused, specifically: the spatio-temporal correlation feature vector corresponding to each modal is multiplied by the modal weight coefficient of the modal element by element, and then the weighted results of all modes are summed according to the vector dimension to obtain the multi-modal comprehensive features, which are called by the subsequent threat evaluation and response strategy generation module.
[0026] Based on the multi-modal comprehensive feature, the historical detection accuracy of each modal data and the real-time resource occupation rate, a deep reinforcement learning DRL model containing a strategy parameter is used for threat assessment, and a threat risk value and a corresponding security response strategy are output. When the threat risk value reaches a preset judgment condition, the corresponding security response strategy is triggered. The deep reinforcement learning DRL model combines the multi-modal comprehensive feature, the historical detection accuracy of each modal data and the real-time resource occupation rate into a multi-dimensional state vector. Based on the multi-dimensional state vector and the strategy parameter, the threat risk value is calculated. The strategy parameter is used to control the feature selection weight, state transition probability and action decision rule in the threat risk value calculation process. The threat risk value is iteratively updated based on the threat interception success rate and the early warning accuracy rate through a time difference algorithm. The corresponding security response strategy is generated according to the threat risk value.
[0027] Further, comprising: The multi-modal comprehensive feature, the historical detection accuracy of each modal data and the real-time resource occupation rate are combined into a multi-dimensional state vector input into a deep reinforcement learning DRL model. The real-time resource occupation rate includes processor occupation rate, memory occupation rate and bandwidth usage rate. Based on the multi-dimensional state vector and the current strategy parameter, the threat risk value is calculated. The strategy parameter is used to control the feature selection weight, state transition probability and action decision rule in the threat risk value calculation process. According to the threat risk value, a corresponding security response strategy is generated. The security response strategy includes at least one of early warning, threat blocking or access control instruction. When the threat risk value reaches a preset judgment condition, the security response strategy is executed.
[0028] Specifically, based on the multi-modal comprehensive feature, the historical detection accuracy of each modal data and the real-time resource occupation rate, threat assessment is performed through a deep reinforcement learning (DRL) model containing strategy parameters, and a threat risk value and a corresponding security response strategy are output. When the threat risk value reaches a preset judgment condition, the corresponding security response strategy is triggered. The specific process is as follows: first, the multi-modal comprehensive feature, the historical detection accuracy of each modal data statistically calculated in the current period, and the real-time resource occupation rate (including processor occupation rate, memory occupation rate, and bandwidth usage rate) collected and calculated in a 1-minute sliding window are spliced in a predetermined order to form a multi-dimensional state vector. The historical detection accuracy of each modal data is obtained by summarizing the preset historical evaluation period (7 days) from the system labeling and review database, and is normalized to the [0, 1] interval by the minimum-maximum normalization. The real-time resource occupation rate is reported by the resource monitoring agent deployed in the edge node and the center node in real time and is normalized in the same time window to ensure dimensional consistency. Second, the multi-dimensional state vector is input into the deep reinforcement learning (DRL) model containing strategy parameters. The DRL model includes a policy network for mapping the multi-dimensional state vector to a risk score and an evaluation network for evaluating the current state-action value. The strategy parameters are used to control the feature selection weight, state transition probability, and action decision rule in the threat risk value calculation process. The feature selection weight is initialized by normalizing the historical detection accuracy of each modal data as a positive factor and the real-time resource occupation rate as a negative factor, and is solidified as the parameter set used in the current period through historical data playback and online incremental training in the training stage. In the inference stage, the policy network performs feature weighting and non-linear mapping on the multi-dimensional state vector based on the strategy parameters, and outputs a threat risk value normalized to [0, 1]. The evaluation network is used to assist in stabilizing the policy output and constrain the state transition probability, so that high-risk states under resource constraints have higher action priority. Third, the corresponding security response strategy is generated according to the threat risk value and the preset action decision rule in the strategy parameters. The security response strategy includes warning, threat blocking, and access control instructions. The execution intensity and execution order are dynamically adjusted according to the real-time resource occupation rate to meet the resource constraints. Finally, the preset judgment condition is set as the trigger threshold (the threshold is given by the system parameter table and is bound to the business scenario). When the threat risk value reaches the preset judgment condition, the security response strategy is immediately executed and the execution log (including risk value, multi-dimensional state vector summary, strategy parameter version number, and execution result) is recorded for subsequent evaluation and traceability, thereby forming a closed-loop processing process of calculating the threat risk value through the deep reinforcement learning (DRL) model containing strategy parameters and generating the security response strategy based on the multi-modal comprehensive feature, the historical detection accuracy of each modal data, and the real-time resource occupation rate, and triggering the execution when the preset judgment condition is met.
[0029] Based on the threat risk value, the early warning accuracy rate after the security response strategy is executed, the threat interception success rate, the dynamic weight coefficient, the edge correlation degree dynamic threshold are updated through the edge correlation degree dynamic threshold self-learning algorithm, the policy parameters are updated through the time difference algorithm of the deep reinforcement learning DRL model, and the updated parameter group is output. The parameter group is used for optimizing the feature extraction, fusion and threat evaluation process of the next round of multi-source perception data.
[0030] Further, based on the threat risk value, the early warning accuracy rate after the security response strategy is executed, the threat interception success rate, the dynamic weight coefficient, the edge correlation degree dynamic threshold are updated through the edge correlation degree dynamic threshold self-learning algorithm, the policy parameters are updated through the time difference algorithm of the deep reinforcement learning DRL model, and the updated parameter group is output. The parameter group is used for optimizing the feature extraction, fusion and threat evaluation process of the next round of multi-source perception data. Based on the early warning accuracy rate, the threat interception success rate and the threat risk value, a comprehensive evaluation index is calculated. The early warning accuracy rate is the proportion of real threat events correctly identified in total early warning events. The threat interception success rate is the proportion of successfully blocked or contained threat events. When the deviation of the comprehensive evaluation index from the preset performance target exceeds the deviation threshold, the parameter adjustment is started. Based on the effective edge number change trend and the threat detection effect, the dynamic weight coefficient and the edge correlation degree dynamic threshold are updated. Based on the contribution of each modal data to the early warning accuracy rate and the threat interception success rate in the current period, the modal weight coefficient is adjusted. The weight proportion of the modal with high contribution is increased, and the weight proportion of the modal with low contribution is reduced. After adjustment, the weight sum is kept as 1 through normalization processing. Based on the reward signal change and the comprehensive evaluation index deviation of the DRL model in the current period, the policy parameters are updated through the time difference algorithm. Based on the adjusted edge correlation degree dynamic threshold, modal weight coefficient and policy parameters, the adjusted parameter group is formed.
[0031] Specifically, based on the threat risk value, the early warning accuracy rate after the security response strategy is executed, the threat interception success rate, the edge correlation degree dynamic threshold self-learning algorithm is used to update the dynamic weight coefficient and the edge correlation degree dynamic threshold, the policy parameters are updated through the time difference algorithm of the deep reinforcement learning DRL model, and the updated parameter group is output. The parameter group is used to optimize the feature extraction, fusion and threat evaluation process of the next round of multi-source perception data. The specific process is as follows: first, after the current detection period (set to 10 minutes) ends, the system calls the threat evaluation and response execution record module, reads the threat risk value, the security response strategy execution result and the corresponding real threat event label (generated by manual review and annotation) of the current period, calculates the early warning accuracy rate (the proportion of the number of correctly identified real threat events in the total number of early warning events) and the threat interception success rate (the proportion of the number of successfully blocked or contained threat events in the total number of threat events); then, the early warning accuracy rate, the threat interception success rate and the threat risk value are calculated according to the weight coefficients α1, α2 and α3, and α1+α2+α3=1, and the initial values are set to α1=0.4, α2=0.4 and α3=0.2 based on the historical 30-day evaluation results). The comprehensive evaluation index (comprehensive evaluation index = α1×early warning accuracy rate + α2×threat interception success rate + α3×(1- threat risk value deviation), wherein the threat risk value deviation is the absolute difference between the predicted value and the real risk value) is calculated and compared with the system preset performance target (early warning accuracy rate ≥ 90%, threat interception success rate ≥ 85%). When the absolute value of the deviation exceeds the preset deviation threshold δ (δ = 5%), the parameter adjustment process is started. Secondly, based on the correlation between the current period effective edge number change trend (output every 5 minutes by the dynamic spatiotemporal graph construction module) and the threat detection effect (calculated by the Pearson correlation coefficient, and when the correlation coefficient ≥ 0.6, it is determined to be strongly correlated), the edge correlation degree dynamic threshold self-learning algorithm is called to update the dynamic weight coefficient and the edge correlation degree dynamic threshold. Among them, the adjustment of the dynamic weight coefficient is calculated according to the contribution of each modal data to the early warning accuracy rate and the threat interception success rate in the current period (contribution = 0.5×early warning accuracy rate improvement + 0.5×interception success rate improvement, improvement = the difference between the index when the modal participates and when it does not participate). The top 20% of the contribution degree ranks increase the weight proportion (the increase range is 5%-15%, and the contribution degree is linearly distributed), and the last 20% of the contribution degree ranks decrease the weight proportion (the decrease range is 5%-15%, and the contribution degree is linearly distributed). After adjustment, the weight coefficients of all modes are normalized to maintain the total weight sum to 1.Again, for the strategy optimization part, the system updates the policy parameters based on the reward signal change curve (reward signal = 0.6 x threat interception success rate - 0.3 x false alarm rate - 0.1 x resource occupancy rate) obtained by the DRL model in the current period and the deviation value of the comprehensive evaluation index, using the time difference algorithm (TD(λ), λ value 0.8-0.95, where λ = 0.95 in high-risk scenarios to focus on long-term returns, and λ = 0.8 in regular scenarios to focus on short-term response). The state value estimation update rate is proportional to the reward signal change amplitude (update rate = 0.1 x reward signal change amplitude, change amplitude is the difference between the current period and the last period), which ensures that the model can quickly converge to a new strategy when the performance decline trend appears (the comprehensive evaluation index is lower than the preset target for two consecutive periods). Finally, the system combines the updated edge correlation dynamic threshold, modal weight coefficient and policy parameters to form an adjusted parameter group, stores it in the parameter management module and immediately applies it to the next round of detection period, while writing parameter update records (including adjustment reason, parameter adjustment amplitude, comparison of warning accuracy / interception success rate before and after adjustment, timestamp and version number) into the log database, providing traceable basis for subsequent backtracking and model retraining, thereby realizing the closed-loop mechanism of parameter self-adaptive iterative optimization.
[0032] In summary, the embodiments of the present application have at least the following technical effects: The multi-source perception data including video, sensors, network traffic and behavior logs are acquired by a collection device, corresponding target space-time features, device operation features, transmission features and operation sequence features are extracted respectively, and are converted into numerical feature vectors; the feature vectors are taken as graph nodes, real-time space-time correlation degrees between nodes are calculated, and valid edges are screened based on the real-time space-time correlation degrees by using an edge correlation degree dynamic threshold self-learning algorithm, a dynamic space-time graph is constructed, and space-time correlation features are extracted based on the valid edges; based on the historical detection accuracy, current data integrity and scene adaptation degree of each modality data, a modality weight coefficient is calculated, the space-time correlation features are weighted and fused to obtain multi-modal comprehensive features, the calculation of the modality weight coefficient is that a first factor is obtained by multiplying the historical detection accuracy and the scene adaptation degree, an arithmetic square root of the current data integrity is taken as a second factor, the first factor and the second factor are multiplied, and then normalized processing is performed, so that the sum of all modality weight coefficients is 1; based on the multi-modal comprehensive features, the historical detection accuracy and real-time resource occupation rate of each modality data, threat assessment is performed through a deep reinforcement learning (DRL) model containing strategy parameters, a threat risk value and a corresponding security response strategy are output, when the threat risk value reaches a preset judgment condition, the corresponding security response strategy is triggered, the deep reinforcement learning (DRL) model combines the multi-modal comprehensive features, the historical detection accuracy and real-time resource occupation rate of each modality data into a multi-dimensional state vector, calculates a threat risk value based on the multi-dimensional state vector and strategy parameters, the strategy parameters are used to control feature selection weight, state transition probability and action decision rule in the threat risk value calculation process, and the strategy parameters are iteratively updated based on threat interception success rate and early warning accuracy through a time difference algorithm, the corresponding security response strategy is generated according to the threat risk value; based on the threat risk value, the early warning accuracy and threat interception success rate after execution of the security response strategy, the dynamic weight coefficient, edge correlation degree dynamic threshold are updated through the edge correlation degree dynamic threshold self-learning algorithm, the strategy parameters are updated through the time difference algorithm of the deep reinforcement learning (DRL) model, and an updated parameter group is output, the parameter group is used to optimize the feature extraction, fusion and threat assessment process of the next round of multi-source perception data.
[0033] In the second embodiment, based on the same inventive concept as the behavior analysis and early warning method based on AI situational awareness in the foregoing embodiments, as shown in Figure 2 The application provides a behavior analysis and early warning system based on AI situational awareness, and the system and method embodiments in the application are based on the same inventive concept. The system includes: A multi-source data collection and feature extraction module 1 is configured to acquire multi-source perception data including videos, sensors, network traffic and behavior logs through a collection device, extract corresponding target spatio-temporal features, device operation features, transmission features and operation sequence features respectively, and convert them into a numerical feature vector; A dynamic spatio-temporal graph construction and spatio-temporal correlation feature extraction module 2 is configured to take the feature vector as a graph node, calculate real-time spatio-temporal correlation degrees between nodes, filter effective edges based on the real-time spatio-temporal correlation degrees using a dynamic edge correlation degree threshold self-learning algorithm, construct a dynamic spatio-temporal graph, and extract spatio-temporal correlation features based on the effective edges. The dynamic edge correlation degree threshold self-learning algorithm includes obtaining a historical effective edge set, calculating a historical observation correlation degree based on the historical effective edge set, constructing a loss function through the real-time spatio-temporal correlation degree and the historical observation correlation degree, iteratively updating a dynamic weight coefficient based on a gradient descent method, and generating an edge correlation degree dynamic threshold based on the updated dynamic weight coefficient and the correlation degree distribution of the historical effective edge set; A multi-modal feature fusion module 3 is configured to calculate a modal weight coefficient based on the historical detection accuracy, current data integrity and scene adaptation degree of each modal data, weight and fuse the spatio-temporal correlation features to obtain a multi-modal comprehensive feature. The calculation of the modal weight coefficient is to multiply the historical detection accuracy and the scene adaptation degree to obtain a first factor, take the arithmetic square root of the current data integrity as a second factor, multiply the first factor and the second factor, and then normalize the product so that the sum of all modal weight coefficients is 1. A threat assessment and response strategy generation module 4 is configured to perform threat assessment through a deep reinforcement learning (DRL) model containing strategy parameters based on the multi-modal comprehensive feature, the historical detection accuracy of each modal data and the real-time resource occupancy rate, output a threat risk value and a corresponding security response strategy, and trigger the corresponding security response strategy when the threat risk value reaches a preset judgment condition. The DRL model combines the multi-modal comprehensive feature, the historical detection accuracy of each modal data and the real-time resource occupancy rate into a multi-dimensional state vector, calculates a threat risk value based on the multi-dimensional state vector and strategy parameters, and iteratively updates the strategy parameters based on the threat interception success rate and the early warning accuracy through a time difference algorithm. The corresponding security response strategy is generated according to the threat risk value. A parameter dynamic optimization module 5 is configured to update a dynamic weight coefficient, an edge correlation dynamic threshold value based on the threat risk value, the pre-warning accuracy rate after the security response strategy is executed, and a threat interception success rate, update a policy parameter through a time difference algorithm of a deep reinforcement learning (DRL) model, and output an updated parameter group, which is used for optimizing feature extraction, fusion, and threat evaluation of next-round multi-source perception data.
[0034] It should be noted that the above-mentioned sequence of the embodiments of the present application is only for description, and does not represent the advantages and disadvantages of the embodiments. Moreover, the above-mentioned embodiments are described in the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be executed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multi-task processing and parallel processing are possible or can be advantageous.
[0035] The above-mentioned is only the preferred embodiment of the present application, and does not limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
[0036] The specification and drawings are merely exemplary of the present application, and any and all modifications, variations, combinations or equivalents that are within the scope of the present application should be considered. Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application belong to the scope of the present application and its equivalents, the present application is intended to include these modifications and variations.
Claims
1. A behavior analysis and early warning method based on AI situational awareness, characterized in that: The following steps are involved: Acquire multi-source perception data including videos, sensors, network traffic, and behavior logs through acquisition devices, extract the corresponding target spatiotemporal features, device operation features, transmission features, and operation sequence features, and convert them into numerical feature vectors; The feature vector is used as a graph node, the real-time spatiotemporal correlation between the nodes is calculated, and based on the real-time spatiotemporal correlation, an edge correlation dynamic threshold self-learning algorithm is used to screen valid edges, a dynamic spatiotemporal graph is constructed, and spatiotemporal correlation features are extracted based on the valid edges. The edge correlation dynamic threshold self-learning algorithm includes obtaining a historical valid edge set, calculating a historical observation correlation based on the historical valid edge set, constructing a loss function through the real-time spatiotemporal correlation and the historical observation correlation, iteratively updating a dynamic weight coefficient based on a gradient descent method, and generating an edge correlation dynamic threshold based on the updated dynamic weight coefficient and the correlation distribution of the historical valid edge set; Based on the historical detection accuracy, current data integrity and scene adaptability of each modal data, the modal weight coefficient is calculated, and the spatiotemporal correlation features are weighted and fused to obtain a multimodal comprehensive feature. The modal weight coefficient is calculated by multiplying the historical detection accuracy and the scene adaptability to obtain a first factor, and the arithmetic square root of the current data integrity is used as a second factor. After multiplying the first factor and the second factor, the first factor and the second factor are normalized so that the sum of all modal weight coefficients is 1; Based on the multimodal comprehensive features, the historical detection accuracy of each modal data and the real-time resource occupancy rate, a threat assessment is performed through a deep reinforcement learning (DRL) model including strategy parameters, and a threat risk value and a corresponding security response strategy are output. When the threat risk value reaches a preset judgment condition, a corresponding security response strategy is triggered. The deep reinforcement learning (DRL) model combines the multimodal comprehensive features, the historical detection accuracy of each modal data and the real-time resource occupancy rate into a multidimensional state vector, and calculates the threat risk value based on the multidimensional state vector and strategy parameters. The strategy parameters are used to control the feature selection weight, state transition probability and action decision rules in the threat risk value calculation process, and are iteratively updated through a temporal difference algorithm based on the threat interception success rate and the warning accuracy, and a corresponding security response strategy is generated according to the threat risk value; Based on the threat risk value, the warning accuracy after the execution of the security response strategy, and the threat interception success rate, the dynamic weight coefficient and the edge correlation dynamic threshold are updated through the edge correlation dynamic threshold self-learning algorithm, and the strategy parameters are updated through the temporal difference algorithm of the deep reinforcement learning DRL model, and the updated parameter group is output. The parameter group is used to optimize the feature extraction, fusion and threat assessment process of the next round of multi-source perception data.
2. The behavior analysis and early warning method based on AI situational awareness according to claim 1, characterized in that: The constructing of the dynamic space-time graph includes: The feature vectors of multi-source perception data at the same observation moment or within a preset time window are used as graph nodes. The spatial coordinate difference of the nodes is used as the spatial distance, the timestamp difference is used as the time interval, and the cosine similarity of the feature vectors is used as the feature similarity. The real-time spatiotemporal correlation between the nodes is calculated through a dynamic weight fusion function. ; The dynamic weight fusion function is: ; in is the normalized spatial distance, is the normalized time interval, is the feature similarity, is the dynamic weight coefficient, which is updated by the edge correlation dynamic threshold self-learning algorithm to meet ; Adopting the edge correlation dynamic threshold self-learning algorithm, we select node pairs whose real-time spatiotemporal correlation is not less than the edge correlation dynamic threshold and whose historical effective edge accuracy is not less than the preset accuracy threshold as the effective edges of the current cycle; The historical effective edge accuracy is the ratio of the number of times the threat interception behavior in which the edge participated was confirmed to be effective to the total number of times the edge was determined to be effective within the preset evaluation period; A dynamic spatiotemporal graph is constructed based on the nodes corresponding to the feature vectors and the filtered valid edges.
3. The behavior analysis and early warning method based on AI situational awareness according to claim 2, characterized in that: The edge correlation dynamic threshold self-learning algorithm includes: Get the historical valid edge set The historical valid edge set is an edge set whose historical valid edge accuracy is not less than a preset accuracy threshold within a preset evaluation period; Based on the original multi-source perception data of the corresponding time period of the historical valid edge set, the historical observation correlation is calculated through the dynamic weight fusion function ; To minimize the real-time spatiotemporal correlation Correlation with historical observations The difference between them is the target, the loss function is constructed, and the dynamic weight coefficient is iteratively updated based on the gradient descent method. Until the loss function converges to the preset convergence threshold; The loss function for: ; in, is the historical valid edge set The number of samples; Based on the updated dynamic weight coefficient and the correlation distribution of the historical valid edge set, the dynamic threshold of the edge correlation of the current period is generated.
4. The behavior analysis and early warning method based on AI situational awareness according to claim 3, characterized in that: The step of generating a dynamic edge relevance threshold for the current period based on the updated dynamic weight coefficient and the relevance distribution of the historical valid edge set includes: Performing weighted processing on the association degree distribution of the historical valid edge set, where the weight is obtained by combining the dynamic weight coefficient and the historical observation association degree; generating an initial edge correlation threshold according to the weighted correlation distribution and the historical effective edge accuracy; The initial threshold is adjusted based on the real-time threat false alarm rate of the current period to obtain a dynamic threshold for edge correlation. The real-time threat false alarm rate is the proportion of instances determined by the system to be threats in the current period that are confirmed to be non-threats after manual review or subsequent analysis. The edge correlation dynamic threshold is used to screen valid edges in the current cycle.
5. The behavior analysis and early warning method based on AI situational awareness according to claim 1, characterized in that: The extracting of spatiotemporal correlation features includes: Taking the node feature vectors in the dynamic spatiotemporal graph as input, weighted fusion is performed on the features of each node and its neighboring nodes connected by valid edges to obtain dynamic weighted fusion features, where the fusion weight is determined by the normalized real-time spatiotemporal correlation of the corresponding edges; Calculate the edge weight mean change rate, which is the relative change rate of the mean of the weights of all valid edges of the node in the current time window and the corresponding mean in the previous time window; The dynamic weighted fusion feature, the edge weight mean change rate, and the node position information encoding vector are combined to generate the spatiotemporal correlation feature vector.
6. The behavior analysis and early warning method based on AI situational awareness according to claim 1, characterized in that: The modal weight coefficient is calculated based on the historical detection accuracy of each modal data, the current data integrity and the scene adaptability, and the spatiotemporal correlation features are weighted and fused to obtain multimodal comprehensive features, including: Based on the video, sensor, network traffic, and behavior log modal data in the multi-source perception data, respectively, the historical detection accuracy is obtained, where the historical detection accuracy is the ratio of the number of real threat events corresponding to each modal data that are correctly identified to the total number of all detected events of the modality in the period within a preset historical evaluation period; Perform weighted fusion based on the historical detection accuracy, current data integrity and scene adaptability to obtain a normalized modal weight coefficient; The scenario adaptability is evaluated by pre-set applicability indicators of each modal data in the current environment and application scenario. The applicability indicators include factors such as ambient lighting, device installation location, signal quality, and sensor status; The data integrity is obtained by detecting the missing ratio of each modality data, where the missing ratio is the ratio of the amount of unavailable or abnormal data to the total amount of data that should be collected in the current collection cycle; Based on the modal weight coefficient, the spatiotemporal correlation features are weightedly fused, and the spatiotemporal correlation features corresponding to each modality are multiplied by their modal weight coefficients to obtain multimodal comprehensive features.
7. The behavior analysis and early warning method based on AI situational awareness according to claim 1, characterized in that: Based on the multimodal comprehensive features, the historical detection accuracy of each modal data, and the real-time resource occupancy rate, a deep reinforcement learning (DRL) model including strategy parameters is used to perform threat assessment, output a threat risk value and a corresponding security response strategy, and trigger a corresponding security response strategy when the threat risk value reaches a preset judgment condition, including: Combining the multimodal comprehensive features, the historical detection accuracy of each modal data, and the real-time resource occupancy rate into a multidimensional state vector and inputting it into a deep reinforcement learning (DRL) model, wherein the real-time resource occupancy rate includes processor occupancy rate, memory occupancy rate, and bandwidth occupancy rate; Calculating a threat risk value based on the multidimensional state vector and current strategy parameters, wherein the strategy parameters are used to control feature selection weights, state transition probabilities, and action decision rules during the threat risk value calculation process; Generate a corresponding security response strategy based on the threat risk value, wherein the security response strategy includes at least one of an early warning, a threat blocking, or an access control instruction; When the threat risk value reaches a preset determination condition, the security response strategy is executed.
8. The behavior analysis and early warning method based on AI situational awareness according to claim 1, characterized in that: Based on the threat risk value, the warning accuracy rate after the execution of the security response strategy, and the threat interception success rate, the dynamic weight coefficient and the edge correlation dynamic threshold are updated through the edge correlation dynamic threshold self-learning algorithm, and the strategy parameters are updated through the temporal difference algorithm of the deep reinforcement learning (DRL) model, and the updated parameter group is output, including: Based on the warning accuracy rate, threat interception success rate, and threat risk value, a comprehensive evaluation index is calculated, wherein the warning accuracy rate is the proportion of correctly identified real threat events among the warning events to the total warning events, and the threat interception success rate is the proportion of successfully blocked or contained threat events; When the deviation between the comprehensive evaluation index and the preset performance target exceeds a deviation threshold, parameter adjustment is initiated; Based on the changing trend of the number of effective edges and the threat detection effect, the dynamic weight coefficient and the dynamic threshold of edge correlation are updated; Based on the contribution of each modal data to the warning accuracy and threat interception success rate in the current cycle, the modal weight coefficient is adjusted, the weight ratio of the modal with high contribution is increased, and the weight ratio of the modal with low contribution is reduced. After the adjustment, the total weight is kept at 1 through normalization; Based on the reward signal changes and comprehensive evaluation index deviations of the DRL model in the current cycle, the strategy parameters are updated using the temporal difference algorithm; Based on the adjusted edge correlation dynamic threshold, modal weight coefficient and strategy parameters, an adjusted parameter group is formed.
9. Behavior analysis and early warning system based on AI situational awareness, characterized by: The system is used to implement the behavior analysis and early warning method based on AI situational awareness as described in any one of claims 1 to 8, and the system includes: A multi-source data acquisition and feature extraction module is used to acquire multi-source perception data including video, sensors, network traffic, and behavior logs through acquisition devices, extract corresponding target spatiotemporal features, device operation features, transmission features, and operation sequence features, and convert them into numerical feature vectors; A dynamic spatiotemporal graph construction and spatiotemporal correlation feature extraction module, which is used to use the feature vector as a graph node, calculate the real-time spatiotemporal correlation between nodes, and use an edge correlation dynamic threshold self-learning algorithm based on the real-time spatiotemporal correlation to screen valid edges, construct a dynamic spatiotemporal graph, and extract spatiotemporal correlation features based on the valid edges. The edge correlation dynamic threshold self-learning algorithm includes obtaining a historical valid edge set, calculating a historical observation correlation based on the historical valid edge set, constructing a loss function through the real-time spatiotemporal correlation and the historical observation correlation, iteratively updating a dynamic weight coefficient based on a gradient descent method, and generating an edge correlation dynamic threshold based on the updated dynamic weight coefficient and the correlation distribution of the historical valid edge set; A multimodal feature fusion module is used to calculate the modal weight coefficient based on the historical detection accuracy, current data integrity and scene adaptability of each modal data, and weightedly fuse the spatiotemporal correlation features to obtain a multimodal comprehensive feature. The modal weight coefficient is calculated by multiplying the historical detection accuracy by the scene adaptability to obtain a first factor, and the arithmetic square root of the current data integrity as a second factor. After multiplying the first factor by the second factor, the first factor and the second factor are normalized so that the sum of all modal weight coefficients is 1; A threat assessment and response strategy generation module, which is used to perform threat assessment based on the multimodal comprehensive features, the historical detection accuracy of each modal data, and the real-time resource occupancy rate, using a deep reinforcement learning (DRL) model containing strategy parameters, and output a threat risk value and a corresponding security response strategy. When the threat risk value reaches a preset judgment condition, the corresponding security response strategy is triggered. The deep reinforcement learning (DRL) model combines the multimodal comprehensive features, the historical detection accuracy of each modal data, and the real-time resource occupancy rate into a multidimensional state vector, and calculates the threat risk value based on the multidimensional state vector and strategy parameters. The strategy parameters are used to control the feature selection weights, state transition probabilities, and action decision rules in the threat risk value calculation process, and are iteratively updated using a temporal difference algorithm based on the threat interception success rate and warning accuracy, and a corresponding security response strategy is generated according to the threat risk value; A parameter dynamic optimization module is used to update the dynamic weight coefficient and the edge correlation dynamic threshold through the edge correlation dynamic threshold self-learning algorithm based on the threat risk value, the warning accuracy after the execution of the security response strategy, and the threat interception success rate, and to update the strategy parameters through the temporal difference algorithm of the deep reinforcement learning (DRL) model, and output the updated parameter group. The parameter group is used to optimize the feature extraction, fusion and threat assessment process of the next round of multi-source perception data.
Citation Information
Patent Citations
Network information security protection method and system based on artificial intelligence dynamic defense
CN120165968A
Multi-channel video stream cooperative transmission method based on dynamic priority
CN120264049A
Self-adaptive data security management and risk early warning system based on intelligent analysis under cloud platform
CN120358082A
5G network slice dynamic scheduling method and system based on multi-modal space-time perception and event knowledge graph
CN120358158A
Thermal power plant environment monitoring and early warning method and system based on Internet of Things
CN120472601A
Cited By
Multi-modal target fusion and evaluation method
CN121211368A
A Multimodal Target Fusion and Evaluation Method
CN121211368B
Multi-mode short message drainage number intelligent identification and interception system
CN121357544A
Building fire intelligent detection and positioning method based on multi-source data fusion
CN121434641A
Method and system for adjusting vibration optical fiber alarm threshold
CN121482981A