GIS-based position flow anomaly detection method and device, and medium
By using GIS-based quadtree grid coding and time window queuing technology, the high complexity and single-dimensionality of location flow anomaly detection are solved, achieving low-complexity multi-dimensional real-time detection, which is suitable for security monitoring scenarios.
Patent Information
- Application Number
- CN202511358567.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-23
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2045-09-23
AI Technical Summary
In existing technologies, location flow anomaly detection has high computational complexity and a single detection dimension, making it difficult to meet the requirements of real-time processing and comprehensive security monitoring.
The system employs GIS-based quadtree grid coding technology to convert latitude and longitude coordinates into decimal numbers. It also combines time window queues to detect anomalies in dwell time and trajectory deviation. The system supports multi-protocol data access through the Netty platform, reducing computational complexity and enabling multi-dimensional anomaly detection.
It achieves low-complexity real-time location stream anomaly detection, which can comprehensively cover security monitoring needs, support real-time reception and extended adaptation of multi-source data, and improve detection efficiency and system scalability.
Smart Images

Figure CN120873692A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of location stream data anomaly detection technology, and in particular to a location stream anomaly detection method, device and medium based on GIS. Background Technology
[0002] Streaming data is a continuously generated, real-time, and dynamically changing collection of data, characterized by real-time arrival, temporal order, infinity, and adaptability.
[0003] Location streams are data streams that describe changes in a user's location; they are themselves streaming data. They record a user's location information over a period of time, used to analyze user movement patterns and behavioral characteristics, and to provide personalized services. Location streams can be acquired in various ways, including GPS positioning, Wi-Fi signal positioning, and cell tower triangulation. After acquiring location information, data cleaning, data mining, and visualization processes are typically required to extract useful information.
[0004] The sliding time window algorithm is a commonly used method for streaming data analysis to handle trends in time-series data. This algorithm maintains a fixed-size time window, continuously sliding and updating the data within the window, and calculating relevant statistical indicators in real time to detect changes and anomalies in the data.
[0005] GIS grid systems typically employ Earth subdivision techniques to divide the Earth's surface, creating multi-layered grids that are approximately identical in shape, spatially seamless and non-overlapping, and scale-continuous. Common examples include GARS grids, Google Earth grids, and the domestic GeoSOT grid (isotropic latitude and longitude coded grid). In Geographic Information Systems (GIS), grid coding systems are used for efficient storage, retrieval, and management of spatial data, enabling precise subdivision and rapid positioning of the Earth's surface, and supporting various spatial analyses and applications.
[0006] In existing technologies, location flow anomaly detection mostly relies on traditional spatial geometric calculations or single-dimensional time-series analysis, which has two major pain points: First, the computational complexity is high. When performing operations such as determining the area range or matching trajectories directly based on latitude and longitude coordinates, complex geometric calculations need to be performed frequently, which is difficult to meet the real-time processing requirements. Second, the detection dimension is single. It often only focuses on whether the location exceeds a fixed area, ignoring multi-dimensional anomaly scenarios such as excessive dwell time, trajectory deviation from the predetermined path, and abnormal movement speed, and cannot fully cover the security monitoring needs in practical applications.
[0007] Therefore, how to integrate the temporal analysis capabilities of sliding time windows with the spatial computing advantages of GIS grid coding to construct a low-complexity, multi-dimensional real-time location stream anomaly detection scheme has become a technical problem that urgently needs to be solved in the current fields of stream data processing and geographic information applications. Summary of the Invention
[0008] To address the aforementioned problems, the present invention aims to provide a GIS-based method, device, and medium for detecting location flow anomalies, thereby solving the problems of high computational complexity and limited detection dimensions in existing technologies.
[0009] First aspect: A GIS-based method for detecting location flow anomalies, including:
[0010] S1. Receive location stream data, grid the location stream data based on a quadtree grid, and convert latitude and longitude coordinates into decimal numbers;
[0011] S2. Detect the position of the position stream data in the quadtree grid region based on the decimal number of the position stream data;
[0012] S3. Combine time window queues to detect abnormal dwell time of gridded location stream data;
[0013] S4. Combine time window queues to perform trajectory deviation anomaly detection on gridded location stream data;
[0014] S5. Send the anomaly detection to the early warning center.
[0015] In one embodiment of the present invention, when receiving location stream data in S1, the Netty platform is used, which is compatible with HTTP, HTTPS, TCP and UDP network transmission protocols.
[0016] In one embodiment of the present invention, the quadtree mesh in S1 adopts a GeoSOT mesh with a depth of 32 levels.
[0017] In one embodiment of the present invention, the conversion of latitude and longitude coordinates to decimal numbers in step S1 includes:
[0018] The received location stream data latitude and longitude are encoded in binary according to a 32-level GeoSOT grid, and then converted into decimal numbers.
[0019] In one embodiment of the present invention, detecting the location of the location stream data in the grid region in step S2 includes the following steps:
[0020] S21. Determine the location stream data grid hierarchy;
[0021] S22. Calculate the binary number of the position stream data grid code in reverse Z order.
[0022] S23. Perform a bitwise AND operation between the binary number and the high-order bits of the grid level encoding.
[0023] S24. Convert the calculation result into the corresponding position stream data decimal number;
[0024] S25. Compare the decimal number of the position stream data with the numerical value of the grid region to determine the position of the grid region of the position stream data.
[0025] In one embodiment of the present invention, step S3, which involves detecting residence time anomalies in the gridded location stream data, includes the following steps:
[0026] S31. Determine the grid corresponding to the location stream data residence area;
[0027] S32. Merge the location stream data of the new receiving point into grid data of the same level;
[0028] S33. Continuously record the dwell time of location stream data within the same grid area in the window;
[0029] S34. When the dwell time exceeds the set threshold, a dwell time abnormality is triggered.
[0030] In one embodiment of the present invention, step S4, which involves detecting trajectory deviation anomalies in the gridded location stream data, includes the following steps:
[0031] S41. Save the position stream data as a trajectory grid using a trajectory queue;
[0032] S42. Generate an approximate trajectory by simulating the trajectory grid using non-Bezier curves;
[0033] S43. Determine whether the location stream data is within the predetermined trajectory grid;
[0034] S44. For position stream data that deviates from the predetermined trajectory grid, trigger trajectory deviation anomaly.
[0035] In one embodiment of the present invention, the trajectory deviation anomaly detection includes velocity anomaly detection.
[0036] Second aspect: An electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, performs the steps of the method provided in the first aspect.
[0037] Third aspect: A non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method provided in the first aspect.
[0038] The beneficial effects of this invention are:
[0039] 1. This invention employs GeoSOT grid encoding technology to convert latitude and longitude coordinates into decimal values. It simplifies traditional operations such as region range judgment and trajectory matching, which rely on complex spatial geometric calculations, into efficient numerical comparison. At the same time, it combines dynamic sliding time windows for lightweight processing of gridded trajectory data, significantly reducing the computational load of location flow data. This effectively solves the problem of insufficient real-time performance caused by cumbersome geometric calculations in traditional methods, enabling rapid response detection of location flow anomalies and significantly reducing computational complexity.
[0040] 2. This invention addresses the shortcomings of traditional detection methods that rely on a single dimension by integrating area detection, dwell time anomaly detection, trajectory deviation detection, and speed anomaly detection. Through gridded trajectory queue storage and time-series correlation analysis, it can determine whether a location has crossed boundaries, and monitor in real time whether the dwell time within the grid exceeds the limit, whether the actual trajectory deviates from the preset path, and whether the movement speed exceeds the device threshold. This forms a multi-dimensional collaborative anomaly detection closed loop, fully adapting to security monitoring scenarios in practical applications, constructing a multi-dimensional collaborative detection system, and achieving comprehensive coverage of monitoring needs.
[0041] 3. This invention's platform is based on the Spring Cloud framework and a B / S architecture. At the algorithm layer, it reduces computational complexity through grid coding while leveraging the Netty high-performance communication framework to improve the efficiency of multi-protocol data access. It supports real-time reception of location stream data from multiple sources such as GPS, WiFi, and base stations. Furthermore, it optimizes trajectory queue storage through quadtree grid merging to avoid memory overflow issues. The collaborative optimization of the algorithm and architecture not only ensures real-time detection efficiency but also enhances the system's scalability and adaptability to multi-source data and multi-scenario applications, achieving collaborative optimization of the algorithm and architecture. Attached Figure Description
[0042] Figure 1 This is a schematic flowchart of the method of the present invention;
[0043] Figure 2 This is a flowchart illustrating the principle of the method of the present invention;
[0044] Figure 3 This is a schematic diagram of the location stream data access of the present invention;
[0045] Figure 4 This is a schematic diagram of the GeoSOT mesh Z-order inverted arrangement of the present invention;
[0046] Figure 5 This is a schematic diagram of the sliding window t0 to t1 of the present invention;
[0047] Figure 6 This is a schematic diagram of the stack and corresponding mesh of the present invention;
[0048] Figure 7 This is a schematic diagram of the resident timeout stack cleanup in this invention;
[0049] Figure 8 This is a schematic diagram illustrating the update of data stream records within the same grid according to the present invention;
[0050] Figure 9 This is a schematic diagram of the grid and corresponding trajectory queue of the present invention.
[0051] Figure 10 This is a schematic diagram of the trajectory queue corresponding to adjacent grids in this invention;
[0052] Figure 11 This is a schematic diagram of the trajectory queue corresponding to non-adjacent grids in this invention;
[0053] Figure 12 This is a schematic diagram of the trajectory queue quadtree merging method of the present invention;
[0054] Figure 13 This is a schematic diagram of the structure of the electronic device of the present invention. Detailed Implementation
[0055] Embodiments of the present invention are described in detail below. Examples of these embodiments are illustrated in the accompanying drawings, wherein the same or similar symbols denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.
[0056] In existing technologies, location flow anomaly detection often relies on traditional spatial geometric calculations or single-dimensional time-series analysis, which has the following drawbacks: high computational complexity, as operations such as determining the area range and matching trajectories based directly on latitude and longitude coordinates require frequent execution of complex geometric calculations, making it difficult to meet real-time processing requirements; and a single detection dimension, often focusing only on whether the location exceeds a fixed area, ignoring multi-dimensional anomaly scenarios such as excessively long dwell time, trajectory deviation from the predetermined path, and abnormal movement speed, thus failing to comprehensively cover the security monitoring needs of practical applications.
[0057] Example 1:
[0058] To address the aforementioned issues, this embodiment provides a GIS-based method for detecting location flow anomalies. Figure 1 This is a schematic flowchart of the method according to an embodiment of the present invention. Figure 2 This is a flowchart illustrating the principle of the method, which includes:
[0059] S1. Receive location stream data, encode the location stream data into a grid based on a quadtree grid, and convert latitude and longitude coordinates into decimal numbers.
[0060] like Figure 3As shown, this invention is based on the Spring Cloud framework to develop a location stream data anomaly detection platform. It adopts a B / S network architecture and uses the Netty platform to improve the efficiency of interface access. The Netty platform supports socket, HTTP, HTTPS, TCP or UDP network transmission protocols and can realize functions such as reporting data in different formats, data querying, area detection, trajectory anomaly detection and dwell point analysis.
[0061] Furthermore, in terms of data processing, it can efficiently store and manage massive amounts of location stream data, and use distributed file systems and database technologies to ensure data security and integrity.
[0062] Furthermore, for data reports in different formats, the platform will conduct strict format verification and data cleaning to remove invalid or erroneous data and ensure the accuracy of subsequent analysis.
[0063] The latitude and longitude location stream data received by the Netty platform is binary encoded according to a quadtree grid and then converted into decimal numbers.
[0064] For example, location stream data with latitude and longitude (120.34, 23.23) is converted to the corresponding 32-level GeoSOT grid (global isotropic grid) in binary as 0000010111011010100001101100101011010000000000000000000000000000, which corresponds to the decimal number 421797720743739392.
[0065] S2. Based on the decimal representation of the location stream data, detect the position of the location stream data within the quadtree grid region. Specifically:
[0066] First, determine the location stream data grid hierarchy.
[0067] Choose an appropriate grid level based on the required data accuracy and the actual application scenario. Different grid levels correspond to different spatial resolutions. The higher the level, the finer the grid division and the more accurate the location representation, but the amount of data and computational complexity will also increase accordingly.
[0068] Then, the binary number of the location stream data grid code is calculated by sorting it in reverse Z order.
[0069] Inverted Z-sort is a special sorting method that effectively encodes positional information in two-dimensional space, ensuring that adjacent positions have a certain correlation in their encoding. The binary code calculated using this sorting method can more accurately reflect the positional relationships of location stream data within a quadtree grid.
[0070] Then, perform a bitwise AND operation between the binary number and the high-order bits of the grid level encoding.
[0071] The result of the AND operation further determines the specific sub-region of the location stream data within the quadtree grid. This is because the high-order bits of the grid hierarchy represent the basic grid division information at a specific level. By performing an AND operation with the binary number, some unnecessary low-order bits can be filtered out, focusing on the key corresponding parts of the hierarchy.
[0072] Then, the calculation result is converted into the corresponding position stream data decimal number.
[0073] For example, a grid at level 25, with row number 7885184 and column number 1521408, corresponds to a longitude range of (120.34~120.340017) and a latitude range of (23.23~23.230017). The high-order byte encoding of this level is 11111111111111111111111110000000, and the binary encoding of the dimension is 000010111001100000000. The binary code for longitude is 0011110000101000110000000000000. The binary code for latitude and longitude is 000001011101101010000110110010101101000000000000000000000000. The decimal code for latitude and longitude is 421797720743739392.
[0074] After padding the lattice code with zeros, the binary range corresponding to the lattice is 0000010111011010100001101100101011010000000000000000000000000~000010111011010101000011011001010110100000000000001111111111111, which corresponds to the decimal range of 421797720743739392~421797720743755775.
[0075] In this way, the decimal number becomes a unique identifier for the location stream data within the quadtree grid at that level. Using this unique identifier, the device can quickly and accurately pinpoint the specific location of the location stream data within the quadtree grid. When performing location stream anomaly detection, this unique identifier can be used to efficiently compare location stream data from different time points.
[0076] Finally, the position of the position stream data grid region is determined by comparing the decimal number of the position stream data with the numerical value of the grid region.
[0077] Compare the decimal number of the position stream data with the numerical value range of the grid area to determine whether the position stream data of the point is within the grid area range.
[0078] For example, for the judgment of the position stream data (120.34, 23.23) and the grid area range (longitude: 120.34~120.340017, latitude: 23.23~23.230017), after being gridified by GeoSOT, it is transformed into a decimal number judgment. Since 421797720743739392 ≤ 421797720743739392 <4217977>20743755775, the position stream data is within the area range and is normal data. Otherwise, it is abnormal data and an alarm is triggered.
[0079] S3. Combine with the time window queue to perform abnormal detection of the residence time for the gridified position stream data.
[0080] As Figure 5 shown, by dynamically sliding the time window, record the gridified trajectory data to provide abnormal detection of the residence time, and complete the detection by recording the residence time within the grid. Specifically:
[0081] First, determine the grid corresponding to the residence area of the position stream data. Convert the position stream data into the corresponding grid number to accurately identify the specific grid where the position stream data resides.
[0082] Then, merge the position stream data of the newly received point upward into grid data of the same level to uniformly process and analyze position information with different precisions. Through this merging operation, the scattered position stream data can be integrated into representative grid data, reducing the complexity of the data.
[0083] Then, continuously record the residence time of the position stream data within the same grid area in the window. The start time (the moment when the first one enters this grid) and the end time (the moment when the last one leaves this grid) of the same area (grid) within the window can be continuously recorded to calculate the residence time.
[0084] Finally, when the residence time exceeds the set threshold, an abnormal residence time is triggered.
[0085] Compare the calculated residence time with the preset normal residence time threshold. If the residence time exceeds the normal threshold range, it is determined that there is an abnormal residence time for the position stream data within this grid area, and an alarm is triggered.
[0086] Application example:
[0087] As Figure 5 and Figure 6As shown, within the sliding window period t0, p0 and p1 are two data points within t0. When p0 and p1 are placed into the dwell point stack, p0 and p1 form a grid g0.
[0088] like Figure 5 As shown, when the window slides to the right once, there are two data points, p1 and p2, within the window period t1. p2 is the newly received data. p2 is coded into a grid, and based on the area range detection, it is determined whether p2 is within the grid g0.
[0089] like Figure 7 As shown, if p2 is not within grid g0, p2 will form a new dwelling region grid g1. The grid g0 containing p0 and p1 will form a dwelling point record. The dwelling time from p0 to p1 will be calculated. If the dwelling time exceeds the set threshold, an alert will be triggered. The dwelling stack will be cleared, and p2 will be added.
[0090] like Figure 8 As shown, if p2 is in grid g0, the last record (p1) in grid g0 is popped and placed into p2. That is, the current residence point start time record of grid g0 is updated to p0 to p2, and the residence time of grid g0 is updated. When the residence time exceeds the set threshold, an alarm is triggered.
[0091] Then slide the window to the right and process it backwards using the method described above.
[0092] S4. Combine time window queues to perform trajectory deviation anomaly detection on gridded location stream data.
[0093] The trajectory deviation detection algorithm supports both speed anomaly detection and trajectory deviation detection. A trajectory queue is used to store the driving trajectory. Considering the infinite nature of the position stream, the trajectory queue does not store individual incoming position stream data, but rather a trajectory grid. The final trajectory will be composed of grid cells, and a rough trajectory is generated through non-Bezier curve simulation. Therefore, real-time trajectory deviation detection involves creating a gridded trajectory path from a pre-defined path. When position stream data is received sequentially from the device, it is converted into a grid and checked against the pre-defined trajectory grid. If not, the device is considered to have deviated from the predetermined trajectory, triggering an alert. Furthermore, the pre-defined gridded trajectory path is ordered; if the device's path order is incorrect, an alert will also be triggered. Specifically:
[0094] First, location stream data is stored as a trajectory grid using a trajectory queue. Then, grid coding technology is used to convert the location stream data into corresponding trajectory grid identifiers, enabling efficient abstraction and organization of location information. Next, the trajectory grid is analyzed and processed according to preset rules and algorithms.
[0095] Then, a rough trajectory is generated by simulating the trajectory grid using non-Bezier curves. This simulation method can reduce the computational complexity and time cost while ensuring the basic shape of the trajectory.
[0096] Then, it is determined whether the location stream data is within the predetermined trajectory grid. The generated approximate trajectory is compared with the preset gridded trajectory setting path. During the comparison process, the key nodes and overall direction of the trajectory are analyzed in detail.
[0097] Finally, for position stream data that deviates from the predetermined trajectory grid, a trajectory deviation anomaly is triggered.
[0098] If the grid corresponding to the location stream data is within the preset gridded trajectory setting path, and the trajectory order is consistent with the preset order, the device is determined to be operating normally and no warning is triggered; if the grid corresponding to the location stream data is not within the preset gridded trajectory setting path, or the trajectory order is inconsistent with the preset order, the device is determined to have deviated from the predetermined trajectory and the warning mechanism is immediately triggered.
[0099] Application examples:
[0100] like Figure 9 As shown, within the sliding window period t0, the position stream data p0 and p1 form the corresponding grid g0. The grid g0 is encoded and put into the trajectory queue.
[0101] like Figure 10 As shown, the sliding window is moved to the right to obtain t1, which contains p1 and p2. It is then determined whether the grid where p2 is located is adjacent to grid g0 or whether p2 is inside grid g0.
[0102] like Figure 10 As shown, if grid g1 containing p2 is adjacent to g0, and the current trajectory is formed from g0 to g1, it is necessary to determine whether g1 is within the set trajectory. If not, an alert is triggered. Simultaneously, the relative order of g0 and g1 should also follow the order within the set trajectory. Otherwise, an alert is triggered. Grid g1 is added to the trajectory queue, and the window is slid backward to process subsequent position stream data in a loop.
[0103] Furthermore, such as Figure 11 As shown, if the grid g1 containing p2 is not adjacent to g0, the grid offset L can be quickly obtained through grid division, and the distance from g0 to g1 is in the range of L~. L, time interval t, calculation velocity range L / t~ L / t, combined with the actual equipment type, determines whether to trigger a speed anomaly warning based on the relationship between the calculated speed range and the equipment's set threshold speed.
[0104] If the current trajectory is g0 to g1, it is necessary to determine whether g1 is in the set trajectory. If not, an alert is triggered. At the same time, the relative order of g0 and g1 should also follow the order in the set trajectory. Otherwise, an alert is triggered. The g1 grid is added to the trajectory queue.
[0105] When p2 is inside grid g0, no new grid is formed, that is, no new trajectory points are generated, and no operation is performed.
[0106] Finally, slide the window backward to process subsequent position stream data in a loop.
[0107] Furthermore, such as Figure 12 As shown, as the sliding window moves backward, when the number of grids formed by the trajectory becomes too large, a certain strategy is needed to avoid the problem of insufficient memory caused by an excessively large trajectory queue. When a specified number (e.g., 5000 grids) or a specified time interval (e.g., one day, one hour, etc.) is reached, the grids in the queue are merged into an upward quadtree. The top-level root node is the level 1 grid. After merging, the trajectory queue is cleared, the merged grids are stored, and the trajectory is generated cyclically.
[0108] S5. Send the anomaly detection to the early warning center.
[0109] After receiving abnormal data pushed by the anomaly detection module, the early warning center first standardizes the abnormal information and encapsulates it into structured data containing core fields such as anomaly type (area boundary crossing, dwell timeout, trajectory deviation, speed anomaly, etc.), abnormal device ID, anomaly occurrence time, anomaly location (original latitude and longitude and corresponding grid code), and anomaly details (such as dwell timeout duration, trajectory deviation distance, speed exceeding threshold value).
[0110] Then, the early warning center classifies the abnormal data according to the preset early warning level rules.
[0111] For example, crossing the boundary of a high-risk area or exceeding the speed limit by more than 50% is considered a Level 1 warning, while staying in an ordinary area for more than 30 minutes is considered a Level 3 warning.
[0112] For different levels of alerts, the system triggers corresponding response mechanisms: for a level 1 alert, it immediately sends the alert to relevant personnel through multiple channels such as pop-up windows on the platform's web interface, push notifications on the mobile app, or SMS notifications, and automatically links the historical trajectory and recent activity records of the abnormal device for quick verification.
[0113] Level 2 warnings are issued via web-based message centers and app push notifications, requiring relevant personnel to report on the progress of their actions within a specified timeframe (e.g., within one hour).
[0114] Level 3 warnings are only recorded in the system warning log for subsequent periodic statistical analysis.
[0115] Meanwhile, the early warning center persistently stores all abnormal early warning information in the abnormal log database of the data layer, and supports querying, filtering and exporting by dimensions such as device ID, abnormality type and time range.
[0116] In addition, the early warning center will automatically generate abnormal early warning statistical reports, displaying information such as the distribution of abnormal types, high-frequency abnormal equipment, and key abnormal areas within a certain period (day, week, month). These reports are displayed on the platform's UI through visual charts (bar charts, pie charts, heat maps) to provide data support for management decisions.
[0117] The present invention also provides an electronic device, Figure 13 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention, such as... Figure 13 As shown, the electronic device may include a processor, a communications interface, memory, and a communication bus, wherein the processor, communications interface, and memory communicate with each other via the communication bus. The processor can invoke logical instructions from the memory, for example, to execute the following method:
[0118] S1. Receive location stream data, grid the location stream data based on a quadtree grid, and convert latitude and longitude coordinates into decimal numbers;
[0119] S2. Detect the position of the position stream data in the quadtree grid region based on the decimal number of the position stream data;
[0120] S3. Combine time window queues to detect abnormal dwell time of gridded location stream data;
[0121] S4. Combine time window queues to perform trajectory deviation anomaly detection on gridded location stream data;
[0122] S5. Send the anomaly detection to the early warning center.
[0123] Furthermore, the logical instructions in the aforementioned memory can be implemented as software functional units and sold or used as independent products, and can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0124] This invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, is implemented to perform the methods provided in the above embodiments, including, for example:
[0125] S1. Receive location stream data, grid the location stream data based on a quadtree grid, and convert latitude and longitude coordinates into decimal numbers;
[0126] S2. Detect the position of the position stream data in the quadtree grid region based on the decimal number of the position stream data;
[0127] S3. Combine time window queues to detect abnormal dwell time of gridded location stream data;
[0128] S4. Combine time window queues to perform trajectory deviation anomaly detection on gridded location stream data;
[0129] S5. Send the anomaly detection to the early warning center.
[0130] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0131] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0132] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A location flow anomaly detection method based on GIS, characterized in that, include: S1. Receive location stream data, grid the location stream data based on a quadtree grid, and convert latitude and longitude coordinates into decimal numbers; S2. Detect the position of the position stream data in the quadtree grid region based on the decimal number of the position stream data; S3. Combine time window queues to detect abnormal dwell time of gridded location stream data; S4. Combine time window queues to perform trajectory deviation anomaly detection on gridded location stream data; S5. Send the anomaly detection to the early warning center.
2. The method according to claim 1, characterized in that, When receiving location stream data in S1, the Netty platform is used, which is compatible with HTTP, HTTPS, TCP, and UDP network transmission protocols.
3. The method according to claim 1, characterized in that, The quadtree mesh in S1 uses a GeoSOT mesh with a depth of 32 levels.
4. The method according to claim 3, characterized in that, The conversion of latitude and longitude coordinates to decimal numbers in S1 includes: The received location stream data latitude and longitude are encoded in binary according to a 32-level GeoSOT grid, and then converted into decimal numbers.
5. The method according to claim 1, characterized in that, The step S2, detecting the location of the location stream data within the grid region, includes the following steps: S21. Determine the location stream data grid hierarchy; S22. Calculate the binary number of the position stream data grid code in reverse Z order. S23. Perform a bitwise AND operation between the binary number and the high-order bits of the grid level encoding. S24. Convert the calculation result into the corresponding position stream data decimal number; S25. Compare the decimal number of the position stream data with the numerical value of the grid region to determine the position of the grid region of the position stream data.
6. The method according to claim 1, characterized in that, In step S3, the residence time anomaly detection of the gridded location stream data includes the following steps: S31. Determine the grid corresponding to the location stream data residence area; S32. Merge the location stream data of the new receiving point into grid data of the same level; S33. Continuously record the dwell time of location stream data within the same grid area in the window; S34. When the dwell time exceeds the set threshold, a dwell time abnormality is triggered.
7. The method according to claim 1, characterized in that, In step S4, trajectory deviation anomaly detection is performed on the gridded location stream data, including the following steps: S41. Save the position stream data as a trajectory grid using a trajectory queue; S42. Generate an approximate trajectory by simulating the trajectory grid using non-Bezier curves; S43. Determine whether the location stream data is within the predetermined trajectory grid; S44. For position stream data that deviates from the predetermined trajectory grid, trigger trajectory deviation anomaly.
8. The method according to claim 7, characterized in that, The trajectory deviation anomaly detection includes speed anomaly detection.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method as described in any one of claims 1 to 8.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Population abnormal information detection method and system based on big data
CN110059919A
Order service security detection method and device, and computer readable storage medium
CN111105243A
Safety management early warning method, system and device for dynamic assets
CN114996599A
Space-time grid index query method and system based on degraded quadtree
CN116775971A
Method, device and equipment for judging deviation of vehicle driving route and medium
CN119705464A