Risk behavior identification method and device, electronic equipment and storage medium
By employing a dual-model structure of supervised and unsupervised learning, and combining multi-source data to identify risky trading behavior, this approach addresses the issues of low accuracy and high false positive rate in existing technologies for identifying risky trading behavior in complex scenarios, achieving higher identification sensitivity and adaptability.
Patent Information
- Application Number
- CN202511444444.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-10
- Publication Date
- 2026-01-13
AI Technical Summary
Existing technologies struggle to identify risky trading behaviors that are covert, diverse, or sudden in complex scenarios, resulting in low accuracy, high false alarm rates, and delayed responses in risk behavior identification.
A dual-model structure of supervised and unsupervised approaches is adopted. By identifying objects within the fenced area to be processed, a supervised first behavior recognition model and an unsupervised second behavior recognition model are used, combined with multi-source data, to identify risky behaviors, including determining the fenced area to be processed, object type, and behavior pattern, and judging whether risky behaviors have occurred.
It improves the sensitivity, accuracy, and adaptability of risk behavior identification, reduces the false alarm rate, and has good applicability, especially in complex and dynamic scenarios.
Smart Images

Figure CN121329573A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, and in particular, to a risk behavior identification method and device, electronic equipment and a storage medium. BACKGROUND
[0002] In the field of financial security supervision, identifying and preventing risk transaction behaviors is an important issue to ensure financial security.
[0003] In the prior art, a preset static judgment rule is usually used as a judgment basis, such as "single-day high-frequency small amount cash withdrawal behavior", "intensive operation behavior during non-business hours", and the like, supplemented by a single-dimensional data source such as a monitoring camera screen, a transaction log or a base station signaling, to perform threshold trigger type risk behavior identification and alarm. However, the risk transaction behavior identification method of the prior art is difficult to identify risk transaction behaviors with concealment, diversity or suddenness in complex scenarios, and is also difficult to adapt to the dynamic evolution of risk scenarios, resulting in problems such as low risk behavior identification accuracy, even difficulty in identification, high false alarm rate, and delayed early warning and response. SUMMARY
[0004] The present application provides a risk behavior identification method, device, electronic equipment and storage medium to improve the sensitivity, accuracy and adaptability of risk behavior identification, and reduce the false alarm rate, especially for complex and dynamic scenarios.
[0005] In a first aspect, an embodiment of the present application provides a risk behavior identification method, which comprises:
[0006] determining a to-be-processed fence area;
[0007] determining a first risk behavior identification result based on a to-be-processed object in the to-be-processed fence area by using a supervised first behavior identification model, and / or determining a second risk behavior identification result based on the to-be-processed object in the to-be-processed fence area by using an unsupervised second behavior identification model;
[0008] judging whether a risk behavior occurs in the to-be-processed fence area based on the first risk behavior identification result and / or the second risk behavior identification result.
[0009] Optionally, the determination of the to-be-processed fence area comprises:
[0010] determining a region positioning error of the to-be-processed area;
[0011] determining a region type of the to-be-processed area, and determining the to-be-processed fence area according to the region positioning error, a fence area shape matched with the region type and a fence area size.
[0012] Optionally, the area positioning error of the to-be-processed area is determined, comprising:
[0013] An accuracy estimation area is determined with a center point of the to-be-processed area as a center and with a preset radius as a radius;
[0014] The number of base stations and the received signal strength indication value in the accuracy estimation area are determined;
[0015] The area positioning error of the to-be-processed area is determined according to the number of base stations and the received signal strength indication value.
[0016] Optionally, the area type is a point type, and the to-be-processed fence area is determined according to the area positioning error, a fence area shape matched with the area type, and a fence area size, comprising:
[0017] It is determined that the fence area shape matched with the to-be-processed area of the point type is a rectangle;
[0018] The fence area size is determined according to the size of the to-be-processed area and the area positioning error;
[0019] The to-be-processed fence area of the rectangle is determined according to the center point of the to-be-processed area and the fence area size.
[0020] Optionally, the area type is a linear type, and the to-be-processed fence area is determined according to the area positioning error, a fence area shape matched with the area type, and a fence area size, comprising:
[0021] It is determined that the fence area shape matched with the to-be-processed area of the linear type is a capsule shape;
[0022] The fence area width is determined according to the size of the to-be-processed area and the area positioning error;
[0023] The to-be-processed fence area of the capsule shape is determined according to the start point, the end point of the to-be-processed area, and the fence area width.
[0024] Optionally, the area type is a point type, and the to-be-processed fence area is determined according to the area positioning error, a fence area shape matched with the area type, and a fence area size, comprising:
[0025] It is determined that the fence area shape matched with the to-be-processed area of the point type is a circle;
[0026] The fence area radius is determined according to a preset radius matched with the to-be-processed area and the area positioning error;
[0027] The to-be-processed fence area of the circle is determined according to the center point of the to-be-processed area and the fence area radius.
[0028] Optionally, using a supervised first behavior recognition model, based on the object to be processed within the fenced area, the first risk behavior recognition result is determined, including:
[0029] Using a supervised first behavior recognition model, it is determined whether the object to be processed within the fenced area is a known object in a pre-set object database.
[0030] If the object to be processed within the fenced area is determined to be a known object, then the first risk behavior identification result is determined based on the current behavior of the object to be processed and the historical behavior of the known objects.
[0031] Optionally, using an unsupervised second behavior recognition model, based on the object to be processed within the fenced area, the second risk behavior recognition result is determined, including:
[0032] Using an unsupervised second behavior recognition model, the number of objects to be processed in the fenced area and the dwell time of the objects to be processed are determined based on the objects to be processed in the fenced area.
[0033] The activity value of the current object is determined based on the number of objects to be processed, the dwell time of the objects to be processed, and the time period risk coefficient at the current moment;
[0034] The results of the second risk behavior identification are determined based on the current activity value of the object, the historical average activity value of the object, and the volatility coefficient.
[0035] The average activity value of historical objects is calculated by averaging the activity values of each historical object within the same time interval before the current moment that matches the fenced area to be processed.
[0036] Optionally, the objects to be processed within the fenced area do not include the resident objects within the fenced area.
[0037] The resident objects are selected from among the historical objects based on their historical trajectories and behaviors in the historical period before the current time.
[0038] Optionally, based on the results of the first risk behavior identification and / or the second risk behavior identification, it is determined whether a risky behavior has occurred within the fenced area to be processed, including:
[0039] If a risky behavior is determined to have occurred based on at least the first risky behavior identification result, then a risky behavior is determined to have occurred within the fenced area to be processed.
[0040] Optionally, determining whether a risky behavior has occurred within the fenced area to be processed, based on the results of the first risk behavior identification and / or the second risk behavior identification, further includes:
[0041] If no risk behavior is identified based on the first risk behavior identification result, but a risk behavior is identified based on the second risk behavior identification result, then it is determined whether a risk behavior has occurred within the fenced area to be processed based on the historical trajectory and / or device fingerprint of the object to be processed within the fenced area to be processed.
[0042] Optionally, determining whether a risky behavior has occurred within the fenced area to be processed, based on the results of the first risk behavior identification and / or the second risk behavior identification, further includes:
[0043] Based on the results of the first risk behavior identification and / or the second risk behavior identification, and at least one warning intensity coefficient, determine the warning intensity of the fenced area to be treated;
[0044] Based on the warning intensity of the fenced area to be treated, determine whether to issue a risk behavior warning for the fenced area to be treated;
[0045] The warning intensity coefficient includes at least one of the following: the number of objects to be processed coefficient, the dwell time coefficient of the objects to be processed coefficient, the time period risk coefficient at the current moment, the abnormality coefficient of the behavior of the objects to be processed coefficient, and the risk weight coefficient of the fenced area to be processed.
[0046] Optionally, based on the warning intensity of the fenced area to be treated, it is determined whether to issue a risk behavior warning for the fenced area to be treated, including:
[0047] If the duration of the warning intensity for the fenced area to be processed is greater than or equal to the first threshold and less than or equal to the second threshold, and is greater than or equal to the preset time threshold, then a risk behavior warning is issued for the fenced area to be processed.
[0048] Secondly, embodiments of the present invention also provide a risk behavior identification device, the device comprising:
[0049] The module for determining the fenced area to be processed is used to determine the fenced area to be processed.
[0050] The risk behavior identification result determination module is used to determine the first risk behavior identification result based on the object to be processed within the fenced area by using a supervised first behavior identification model, and / or to determine the second risk behavior identification result based on the object to be processed within the fenced area by using an unsupervised second behavior identification model.
[0051] The risk behavior identification module for the fenced area to be processed is used to determine whether a risky behavior has occurred within the fenced area to be processed based on the first risk behavior identification result and / or the second risk behavior identification result.
[0052] Thirdly, embodiments of the present invention also provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the risk behavior identification method as described in any of the embodiments of the present invention.
[0053] Fourthly, embodiments of the present invention also provide a storage medium for storing computer-executable instructions, which, when executed by a computer processor, are used to perform the risk behavior identification method as described in any of the embodiments of the present invention.
[0054] The technical solution of this invention, through determining a fenced area to be processed, identifies objects within that area using a supervised first behavior recognition model to determine a first risk behavior identification result, and / or uses an unsupervised second behavior recognition model to determine a second risk behavior identification result. Based on the first and / or second risk behavior identification results, it is determined whether a risky behavior has occurred within the fenced area to be processed. This technical solution, by deploying a supervised and unsupervised dual-model structure, can integrate multi-source data to achieve risk perception and risk transaction behavior early warning for the fenced area to be processed. This improves the sensitivity, accuracy, and adaptability of risk behavior identification, reduces the false alarm rate of risk transaction behavior, and is particularly effective in complex and dynamic scenarios.
[0055] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0056] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0057] Figure 1 This is a flowchart of a risk behavior identification method provided in Embodiment 1 of the present invention;
[0058] Figure 2 This is a flowchart of a risk behavior identification method provided in Embodiment 2 of the present invention;
[0059] Figure 3 This is a schematic diagram of the structure of a risk behavior recognition system provided in Embodiment 2 of the present invention;
[0060] Figure 4This is a schematic diagram of the structure of a risk behavior identification device provided in Embodiment 3 of the present invention;
[0061] Figure 5 This is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. Detailed Implementation
[0062] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0063] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices. In the embodiments of this application, certain software, components, models, and other existing industry solutions may be mentioned. These should be considered exemplary, intended only to illustrate the feasibility of implementing the technical solutions of this application, and do not imply that the applicant has already used or necessarily used such solutions.
[0064] The acquisition, transmission, storage, use, and processing of data in this application all comply with the relevant provisions of national laws and regulations.
[0065] Example 1
[0066] Figure 1 The flowchart of a risk behavior identification method is provided in Embodiment 1 of the present invention. This embodiment is applicable to the identification and prevention of risky transaction behaviors. The method can be executed by a risk behavior identification device, which can be implemented in hardware and / or software and can be configured in a server.
[0067] like Figure 1 As shown, the method includes:
[0068] S110. Determine the fenced area to be processed.
[0069] Among them, the fenced area to be processed is the basis for subsequent risk behavior identification and early warning. It is an area constructed based on the fenced area to be processed for risk behavior identification.
[0070] The areas to be processed can be regions where historical risky behaviors have occurred, or high-risk areas automatically identified based on map systems, GIS (Geographic Information System), or clustering data of historical risky behavior trajectories, such as financial service venues, streets, and communities. After automatically identifying the areas to be processed, data such as risky behavior types and regional characteristics can be bound to these areas.
[0071] The area to be processed can also be a region generated by user-defined editing based on a map system or GIS system, combined with drawing tools, and responding to the interactive interface of the drawing tools. Precise positioning of the area to be processed based on a map system or GIS system ensures that the area to be processed is aligned with the actual scene.
[0072] It should be noted that the fenced area to be processed refers to the fenced area currently being processed. There can be one or more fenced areas. When there are multiple fenced areas, each fenced area can be processed separately. Furthermore, when there are multiple fenced areas, a fenced area database can be established for storage, and each fenced area can be dynamically associated with its historical risk behavior, regional characteristics, time period characteristics, and risk weights. This data will serve as data support for subsequent risk behavior identification, achieving intelligent linkage between spatial fencing and risk behavior.
[0073] In this embodiment, different shapes of fence areas can be set according to different area types of the area to be processed.
[0074] Specifically, the types of areas to be processed can include point-like, linear, and scattered types. Point-like areas typically represent enclosed areas with clear spatial structures, such as fixed buildings or facilities like financial service establishments, and are high-risk areas for transactions. For point-like areas to be processed, a minimum bounding rectangle can be defined around its center point as the fenced area for processing.
[0075] Linear areas typically manifest as long, narrow strips with high pedestrian or vehicular traffic flow, such as pedestrian streets, subway station exit passages, and sections of road densely populated with financial service establishments. Risk behaviors occurring within linear areas often exhibit characteristics of mobile execution and cross-point coordination. For linear areas, a central axis can be formed by connecting its two endpoints (start and end points). Based on this central axis and the width of the area, a strip-shaped enclosure can be established. The width of the area can be the actual width of the linear area, such as the width of a sidewalk, a subway station exit passage, or the spacing of financial service equipment, or it can be set based on empirical values, such as 5m-8m.
[0076] Scattered risk types typically manifest as areas with dispersed risk points and blurred boundaries, such as urban villages. Risk behaviors occurring within these scattered areas are often characterized by high concealment and flexible, shifting locations. For scattered areas, a radial fencing system can be constructed. A circular area is defined as the fenced region, centered on the center point of the scattered area and with the radius of influence of the risk behavior as its radius. The radius of influence of the risk behavior can be an empirical value for the radius of influence of the risk behavior within the scattered area, for example, it could be set to 20-30 meters.
[0077] The proposed method for setting up fenced areas in this embodiment maximizes the accuracy of location identification and early warning for high-risk areas without relying on high-precision positioning equipment. Furthermore, by setting up fenced areas of different shapes and sizes for different types of areas, comprehensive coverage of diverse scenarios is achieved. Point-type fenced areas enable dynamic monitoring of high-risk financial transactions; linear fenced areas effectively monitor highly liquid, cross-point coordinated risky behaviors; and scattered fenced areas effectively monitor and capture anomalies in sporadic, high-frequency, and highly mobile risky behaviors.
[0078] It should be noted that this embodiment only uses several common area types as examples. For new area types that appear in actual applications, corresponding fenced areas can be set according to their area characteristics and the types of risky behaviors that occur in that area type. The above implementation methods for setting fenced areas based on the area to be processed are all within the protection scope of this embodiment.
[0079] Furthermore, S110 may include:
[0080] S1. Determine the regional positioning error of the area to be processed;
[0081] S2. Determine the region type of the area to be processed, and determine the fence area to be processed based on the region positioning error, the fence area shape that matches the region type, and the fence area size.
[0082] Based on the above embodiments, the area positioning error is the area boundary error caused by mobile network positioning. In this embodiment, the area positioning error is introduced to solve the accuracy error problem of mobile network positioning, improve the setting accuracy of the fence area boundary range, and compensate for the positioning error.
[0083] Furthermore, S1 may include:
[0084] S10. Determine the precision estimation area with the center point of the area to be processed as the center and the preset radius as the radius;
[0085] S11. Determine the number of base stations and the received signal strength indication value within the accuracy estimation area;
[0086] S12. Determine the area positioning error of the area to be processed based on the number of base stations and the received signal strength indication value.
[0087] The preset radius can be set according to the size and shape of the area to be processed. For example, for a point-shaped area to be processed, the preset radius can be set according to its area. The accuracy estimation area is only used to estimate the area positioning error corresponding to the area to be processed. The number of base stations and the Received Signal Strength Indicator (RSSI) value in the accuracy estimation area can be determined using conventional methods, which will not be elaborated in this embodiment.
[0088] In this embodiment, a higher number of base stations indicates more comprehensive signal coverage in the area to be processed, resulting in a smaller regional positioning error. Similarly, a higher RSSI value indicates better wireless link quality and connection stability within the area to be processed, leading to a smaller regional positioning error. Therefore, the number of base stations and the received signal strength indication value are inversely proportional to the regional positioning error.
[0089] In an optional embodiment, determining the area positioning error of the area to be processed based on the number of base stations and the received signal strength index (RSSI) value may include: for different types of areas to be processed, establishing mapping tables between different value ranges and area positioning errors based on the number of base stations and the RSSI value within the area. For the currently processed area, the corresponding area positioning error is determined from the mapping table based on its area type, number of base stations, and RSSI value.
[0090] For example, for a fenced area of a point-like region to be processed, when the number of base stations n≥3 and the RSSI value S≤-85dBm, its regional positioning error can be set to 100m. Furthermore, based on the above, the range of regional positioning error can be set according to the different areas of the point-like region to be processed. For example, depending on the size of the point-like region to be processed, the range of regional positioning error can be set between 80-150.
[0091] In another optional embodiment, the area positioning error of the area to be processed is determined based on the number of base stations and the received signal strength indication value, and can be expressed by the following formula: Where e represents the regional positioning error, α and β represent constants obtained by fitting actual network tests to the region to be processed, n represents the number of base stations, S represents the RSSI value, and the absolute value is used to handle the characteristic of negative RSSI values.
[0092] In this embodiment, the regional positioning error of each region to be processed can be estimated separately, thereby improving the accuracy of the boundary range of each region to be processed and providing accurate data support for subsequent risk behavior identification.
[0093] Accordingly, this embodiment introduces area positioning error into the fence settings for different types of areas to be processed.
[0094] Specifically, when the region type is point-like, S2 can include:
[0095] S20. Determine that the shape of the fence area matching the dotted area to be processed is rectangular;
[0096] S21. Determine the size of the fenced area based on the size of the area to be processed and the area positioning error;
[0097] S22. Determine the rectangular fence area to be processed based on the center point of the area to be processed and the size of the fence area.
[0098] Specifically, since the fenced area of the point-type area to be processed is rectangular (usually represented by the smallest outer rectangle of the point-type area to be processed), the length and width of the fenced area to be processed are each doubled by the area positioning error, based on the original smallest outer rectangle. That is, the area positioning error e meters is extended in all directions from the original smallest outer rectangle to compensate for the positioning error of the motion signaling.
[0099] Specifically, the size of the fenced area can be expressed by the following formula: Where A and B represent the length and width of the original minimum bounding rectangle, respectively. and These represent the length and width of the fenced area to be processed, respectively. Ultimately, the final result can be determined based on the coordinates of the center point of the area to be processed. ,as well as and A rectangular area is generated to obtain the fenced area to be processed, which is used for dynamic monitoring.
[0100] Specifically, when the region type is linear, S2 can include:
[0101] S20 ' The shape of the fenced area that matches the linear region to be processed is determined to be capsule-shaped;
[0102] S21 ' Determine the width of the fence area based on the size of the area to be processed and the area positioning error;
[0103] S22. Determine the capsule-shaped fence area to be processed based on the starting point, ending point, and width of the fence area.
[0104] Because of the introduction of regional positioning error, based on the strip-shaped fence area to be processed in the above embodiment, this embodiment generates semi-circular heads at both ends of the area to be processed, with the width of the fence area, and combines them with the original strip to form a "capsule-shaped" fence area to be processed.
[0105] Specifically, based on the starting point P of the region to be processed a End point P b Connecting to form a central axis, the width of the fenced area can be expressed by the following formula: d represents the width affected by actual pedestrian or equipment activity. At the starting point P... a End point P b place, with Generate a semi-circular head with a radius of 1.
[0106] Furthermore, the region type can be scattered, and correspondingly, S2 can include:
[0107] S20 " The shape of the fence area that matches the scattered areas to be processed is determined to be circular;
[0108] S21 " The radius of the fenced area is determined based on a preset radius that matches the area to be processed and the area positioning error.
[0109] S22 " Based on the center point of the area to be processed and the radius of the fenced area, determine the circular fenced area to be processed.
[0110] Since the fenced area of the scattered unprocessed area is circular, the positioning error of the area is further extended outward by e meters based on the radius of influence of the risky behavior in the above embodiment. As the radius of the fenced area, This indicates the preset radius, which is also the radius of influence of risky behavior.
[0111] The fence construction mechanism based on regional positioning error in this embodiment can design corresponding rectangular, capsule-shaped, and circular fence structures for three types of high-risk scenarios: point-like, linear, and area-like. This mechanism achieves quantitative error compensation for the boundary of risk areas without relying on high-precision positioning equipment (such as GPS), ensuring real-time effective coverage of the fence and providing a solid spatial foundation for subsequent abnormal behavior detection. It significantly reduces the risk of missed and false alarms caused by positioning deviations. By expanding and compensating for the area boundary, it ensures real-time effective coverage of the monitoring boundary, fundamentally reducing the risk of missed alarms due to positioning deviations, and is particularly suitable for a wide range of scenarios without GPS equipment.
[0112] S120. Using a supervised first behavior recognition model, based on the object to be processed within the fenced area to be processed, determine the first risk behavior recognition result, and / or, using an unsupervised second behavior recognition model, based on the object to be processed within the fenced area to be processed, determine the second risk behavior recognition result.
[0113] The objects to be processed can be equipment, personnel, vehicles, etc. This embodiment does not limit the type of objects to be processed. Correspondingly, the objects to be processed within the fence to be processed can be identified through mobile terminal signaling, device fingerprints, transaction triggers, and other data, or through monitoring video recognition. This embodiment does not limit the data source or specific identification method for identifying the objects to be processed.
[0114] Supervised first-behavior recognition models are used to identify whether a known object is exhibiting abnormal behavior. They are suitable for scenarios where historical data about known objects has been stored. This historical data can include the object's identifier, characteristics, historical behavior records, and historical trajectories, such as historical employment records or employee databases of employers. Specifically, when a known object is detected within a fenced area, the supervised first-behavior recognition model analyzes its behavior patterns to determine the first risk behavior identification result.
[0115] The first risk behavior identification result can be represented by a score, with a higher score indicating a higher probability of risk behavior occurring within the fenced area to be addressed; it can also be represented by a level, with a higher level indicating a higher probability of risk behavior occurring within the fenced area to be addressed and a more urgent situation. This embodiment does not limit the form of the first risk behavior identification result, and the second risk behavior identification result is similar, and will not be elaborated further thereafter.
[0116] Specifically, supervised first-action recognition models can determine whether a known object has engaged in abnormal behavior by comparing the behavior of the object to be processed with the historical behavior of known objects, or by using logical rules, such as "concentrated operations outside of business hours" or "devices with no transactions but abnormal trajectories." Furthermore, they can also use combined logical rules for judgment, such as "the same device appearing in more than a preset number of different fenced areas within a preset time interval," "more than a preset number of devices simultaneously entering the same fenced area, accompanied by cash withdrawals," and "multiple savings cards corresponding to the same known object making concentrated small-amount cash withdrawals outside of business hours."
[0117] In this embodiment, a supervised first behavior recognition model is used to analyze whether a known object has engaged in abnormal behavior. This risk behavior recognition method has clear logic, a complete chain of evidence, and a low false alarm rate.
[0118] The unsupervised second behavior recognition model is used to identify abnormal behavior based on the feature information of the object to be processed. It is suitable for risk behavior analysis of objects with unknown identities or incomplete historical data, and such objects can be classified as "unknown objects". Furthermore, the object to be processed, which is the risk behavior recognition analysis object of the unsupervised second behavior recognition model, can be either all objects to be processed within the processing fence area, or other objects to be processed after filtering out the objects identified and analyzed by the first behavior recognition model—known objects.
[0119] Similarly, when analyzing whether risky behavior occurs in the fenced area to be processed, the unsupervised second behavior recognition model can be achieved by judging each object by a single logical rule or a combination of logical rules; or by extracting and analyzing the features of each object, especially the group clustering features of each object, such as the number of objects clustered and the clustering time.
[0120] Furthermore, to ensure the accuracy of group behavior analysis, it can be configured to perform risk behavior identification and analysis only when the number of objects to be processed within the fenced area is greater than or equal to a preset threshold. For example, the preset threshold could be 5, which can prevent false alarms caused by risky behaviors and reduce the false alarm rate.
[0121] In this embodiment, the judgment of risk behavior of unknown objects is made by using an unsupervised second behavior recognition model. This model is applicable to identifying new risk behavior patterns without prior features, such as "abnormal device aggregation", "trajectory drift after new card opening" and "multi-person collaborative wandering without transaction". It can achieve high-precision and real-time identification of unplanned, unregistered and highly concealed risk behaviors, effectively making up for the coverage blind spots of the supervised first behavior recognition model.
[0122] It should be noted that the training of both the first risk behavior recognition model and the second risk behavior recognition model can adopt conventional model training methods. At the same time, the principles by which the first risk behavior recognition model and the second risk behavior recognition model identify risk behaviors can both adopt existing risk behavior recognition principles, which will not be elaborated here in this embodiment.
[0123] In this embodiment, the first risk behavior identification model and the second risk behavior identification model can be applied separately or in combination to improve the coverage accuracy and identification accuracy of risk behavior identification. Furthermore, for different fenced areas to be processed, different application methods for the first and second risk behavior identification models can be set according to different applicable scenarios, fenced area types, or risk behavior types.
[0124] Existing technologies using static rules combined with single data sources for risk behavior identification struggle to adapt to dynamic changes in risk, such as regional shifts, time periods, and evolving risk behavior patterns. This embodiment addresses this by combining supervised and unsupervised intelligent early warning models for risk behavior identification. In scenarios where object identities are known and data is complete, the supervised first risk behavior identification model, based on a database of known objects, identifies highly interpretable abnormal behaviors of known objects. In scenarios where object identities are unknown or data is incomplete, the model identifies and analyzes the clustering characteristics of objects within the designated area to determine risk behavior. The two models operate collaboratively, balancing identification accuracy with expanding coverage of unknown risk behavior patterns, forming a comprehensive intelligent early warning system for risk behavior characterized by "tiered response, automatic optimization, and closed-loop feedback."
[0125] S130. Based on the results of the first risk behavior identification and / or the second risk behavior identification, determine whether a risk behavior has occurred within the fenced area to be processed.
[0126] In this embodiment, determining whether a risky behavior has occurred within the fenced area to be processed can be done by considering either the first risky behavior identification model or the second risky behavior identification model when either model is used alone. For example, if the risky behavior identification result is represented by a score, the determination can be made by checking whether the first or second risky behavior identification result is greater than or equal to a preset score threshold. Alternatively, if the risky behavior identification result is represented by a level, the determination can be made by checking whether the first or second risky behavior identification result reaches a preset level.
[0127] To determine whether a risky behavior has occurred within the fenced area to be processed, when the first and second risky behavior identification models are used in combination, the specific discrimination method based on the first and second risky behavior identification results can be flexibly set according to the security needs of the applicable scenario. For example, taking the risky behavior identification results as scores, it can be set that a risky behavior is determined to have occurred within the fenced area when at least one risky behavior identification result is greater than or equal to a preset score threshold; it can also be set that a risky behavior is determined to have occurred within the fenced area only when both the first and second risky behavior identification results are greater than or equal to the preset score threshold; alternatively, weights can be set for the first and second risky behavior identification results respectively, and a weighted sum of the first and second risky behavior identification results can be performed based on these weights. If the weighted sum is greater than or equal to a preset score threshold, a risky behavior is determined to have occurred within the fenced area to be processed.
[0128] In this embodiment, real-time deep fusion of multi-source heterogeneous data, including mobile terminal signaling, device fingerprints, transaction triggers, surveillance video recognition, and comparison with known object databases, enables collaborative analysis and cross-validation of cross-modal information. This significantly improves the detection sensitivity and recognition accuracy for unregistered, highly concealed risk behaviors, as well as liquid and collaborative risk behaviors. The fusion of multimodal data, combined with both supervised and unsupervised risk behavior recognition, enhances sensitivity and response speed in high-risk spatiotemporal scenarios. It maintains high-performance risk behavior recognition in dynamic adversarial environments, thereby improving financial security and public security prevention and control capabilities.
[0129] The technical solution of this invention, through determining a fenced area to be processed, identifies objects within that area using a supervised first behavior recognition model to determine a first risk behavior identification result, and / or uses an unsupervised second behavior recognition model to determine a second risk behavior identification result. Based on the first and / or second risk behavior identification results, it is determined whether a risky behavior has occurred within the fenced area to be processed. This technical solution, by deploying a supervised and unsupervised dual-model structure, can integrate multi-source data to achieve risk perception and risk transaction behavior early warning for the fenced area to be processed. This improves the sensitivity, accuracy, and adaptability of risk behavior identification, reduces the false alarm rate of risk transaction behavior, and is particularly effective in complex and dynamic scenarios.
[0130] Example 2
[0131] Figure 2 This is a flowchart of a risk behavior identification method provided in Embodiment 2 of the present invention. Based on the above embodiments, the present invention further specifies the process of obtaining a first risk behavior identification result by a supervised first behavior identification model, the process of obtaining a second risk behavior identification result by an unsupervised first behavior identification model, and the process of determining whether a risk behavior has occurred within the fenced area to be processed based on the first risk behavior identification result and / or the second risk behavior identification result.
[0132] like Figure 2 As shown, the method includes:
[0133] S210. Determine the fenced area to be processed.
[0134] S220. Using a supervised first behavior recognition model, determine whether the object to be processed within the fenced area is a known object in a pre-set object database.
[0135] In this embodiment, a supervised first behavior recognition model is used to analyze and identify abnormal behaviors of known objects.
[0136] Determining whether an object within a fenced area is a known object in a pre-defined object database can be achieved in different ways depending on the type of the object. Specifically, when the object is a device, its device fingerprint can be compared with the device fingerprints of known objects in the object database. When the object is a person or vehicle, features can be extracted from the object in the video feed and compared with the features of known objects in the object database. This embodiment does not limit the specific implementation method for determining whether an object is a known object.
[0137] It should also be noted that when at least one object to be processed exists within the fenced area, a determination is triggered to determine whether the object to be processed is a known object. When at least one known object exists within the fenced area, an abnormal behavior recognition of the known object based on a supervised first behavior recognition model is triggered.
[0138] S230. If the object to be processed within the fenced area is determined to be a known object, then the first risk behavior identification result is determined based on the current behavior of the object to be processed and the historical behavior of the known object.
[0139] Understandably, the better the consistency between the current behavior of the object to be processed and the historical behavior of known objects, the lower the probability of risky behavior occurring within the fenced area to be processed; conversely, the lower the consistency between the current behavior of the object to be processed and the historical behavior of known objects, that is, the more abnormal the current behavior of the object to be processed, the higher the probability of risky behavior occurring within the fenced area to be processed.
[0140] In this embodiment, a consistency analysis is performed between the current behavior of the object to be processed and the historical behavior of the known object, and the first risk behavior identification result is output. The first behavior identification model can be based on conventional behavior pattern analysis and identification principles, which will not be elaborated in this embodiment.
[0141] S240. Using an unsupervised second behavior recognition model, determine the number of objects to be processed in the fenced area and the dwell time of the objects to be processed based on the objects to be processed in the fenced area.
[0142] The number of pending objects refers to the number of pending objects within the pending fence area at the current moment, and the dwell time of pending objects refers to the average dwell time of each pending object within the pending fence area at the current moment.
[0143] In this embodiment, the number of objects to be processed and the dwell time of the objects to be processed can reflect the clustering characteristics of the group behavior in the fenced area to be processed.
[0144] S250. Determine the current activity value of an object based on the number of objects to be processed, the dwell time of the objects to be processed, and the time period risk coefficient at the current moment.
[0145] The time-period risk coefficient is used to represent the probability of a risky behavior occurring in the current time period. For example, a day can be divided into business hours and non-business hours, or a month can be divided into weekday hours and holiday hours. Higher time-period risk coefficients can be assigned to non-business hours and holiday hours.
[0146] The current activity value of an object can be represented by the product of the number of objects to be processed, the dwell time of the objects to be processed, and the time period risk coefficient at the current moment.
[0147] S260. Based on the current object activity value, the historical object activity average value, and the volatility coefficient, determine the second risk behavior identification result.
[0148] The average activity of historical objects is calculated by averaging the activity values of all historical objects within the same historical time interval preceding the current moment that match the fenced area to be processed. The fluctuation coefficient can be set to a range, such as 10%-20%, and can be flexibly determined based on the current time period, the type of fenced area to be processed, etc.
[0149] Specifically, if the current activity value of an object is greater than or equal to the product of the historical average activity value of objects and the volatility coefficient, it can be determined that the probability of risky behavior occurring within the fenced area to be processed is relatively high. The second risky behavior identification result can be set to the first level or set to a higher score, etc.
[0150] The principle of unsupervised second behavior recognition model can be expressed by the following formula: ,in, Indicates the number of objects to be processed. Indicates the dwell time of the object to be processed. This indicates the time-period risk coefficient at the current moment. This represents the average activity level of historical objects. This represents the volatility coefficient.
[0151] In this embodiment, the historical average activity value of objects can be used to dynamically and in real time reflect the activity of objects in the same period, similar sites, and the same time period. At the same time, dynamic threshold determination is achieved by dynamically adjusting the fluctuation coefficient.
[0152] Furthermore, S220-S230 and S240-S260 only represent the processing procedures of the supervised first behavior recognition model and the unsupervised second behavior recognition model, respectively, and are not used to indicate the order of priority. In practical application scenarios, when the first behavior recognition model and the second behavior recognition model are used together, they play their roles separately and simultaneously.
[0153] Furthermore, the objects to be processed within the fenced area do not include the resident objects within the fenced area.
[0154] The resident objects are selected from among the historical objects based on their historical trajectories and behaviors in the historical period before the current time.
[0155] Understandably, in real-world applications, there may be active objects such as nearby residents, regular high-frequency users, or merchants in the fenced area to be processed. To avoid misjudging them as risky objects, this embodiment also provides an implementation method for identifying and intelligently filtering resident objects.
[0156] The historical period can be 15 days, one month, etc. Taking 15 days as an example, the historical trajectory and behavior of each historical object within 15 days are clustered and analyzed. Historical objects with fixed historical trajectory location and time and regular behavior are marked as permanent objects.
[0157] In this embodiment, whether it is the object to be processed as the monitoring object of the first behavior recognition model or the object to be processed as the monitoring object of the second behavior recognition model, resident objects are screened out. This method of screening out resident objects can eliminate their interference with risk behavior recognition. Especially in complex environments with mixed crowds and equipment, it can significantly reduce the false alarm rate of risk behavior, improve the accuracy of risk behavior recognition, and increase the utilization efficiency of computing resources.
[0158] Furthermore, when determining the monitoring objects of the first behavior recognition model and / or the second behavior recognition model, in addition to filtering out the resident objects in the objects to be processed, the dwell time of other objects to be processed after filtering out the resident objects can be further counted. If the dwell time is greater than or equal to the preset time threshold, it will be used as the monitoring object of the first behavior recognition model and / or the second behavior recognition model for subsequent behavior recognition.
[0159] S270. Based on the results of the first risk behavior identification and / or the second risk behavior identification, determine whether a risk behavior has occurred within the fenced area to be processed.
[0160] In this embodiment, the first behavior recognition model and the second behavior recognition model can run independently or be used in combination to comprehensively judge risky behaviors.
[0161] In an optional embodiment, S270 may include: if it is determined that a risky behavior has occurred based at least on the first risky behavior identification result, then determine that a risky behavior has occurred within the fenced area to be processed.
[0162] Furthermore, if both the first and second risk behavior identification results confirm the occurrence of a risky behavior, then the probability of such a behavior occurring within the designated fenced area is highest, and the risk behavior warning level can be adjusted to the highest level. Different risk behavior warning levels can be flexibly set according to the applicable scenario.
[0163] If a risky behavior is identified based on the first risk behavior identification result, but not based on the second risk behavior identification result, it indicates that the behavior may be an abnormal action performed by a known object, or it could be determined that a risky behavior has occurred within the fenced area to be processed. However, in this case, a risk behavior warning format with a level lower than or equal to the above situations can be set.
[0164] In another optional embodiment, S270 may further include: if a risky behavior is not determined to have occurred based on the first risky behavior identification result, and a risky behavior is determined to have occurred based on the second risky behavior identification result, then determine whether a risky behavior has occurred within the fenced area to be processed based on the historical trajectory and / or device fingerprint of the object to be processed within the fenced area to be processed.
[0165] If the first risk behavior identification result does not confirm the occurrence of a risky behavior, but the second risk behavior identification result confirms its occurrence, it indicates that there may be a group risky behavior involving an unknown group. In this case, historical trajectory backtracking of each object within the fenced area to be processed, and / or device fingerprint comparison of each object, can be performed to determine whether a risky behavior has occurred within the fenced area. Furthermore, manual verification can be used to determine the risky behavior.
[0166] In an optional embodiment, S270 may further include:
[0167] S271. Based on the results of the identification of the first risk behavior and / or the identification of the second risk behavior, and at least one warning intensity coefficient, determine the warning intensity of the fenced area to be treated;
[0168] S272. Based on the warning intensity of the fenced area to be treated, determine whether to issue a risk behavior warning for the fenced area to be treated.
[0169] The warning intensity coefficient includes at least one of the following: the number of objects to be processed coefficient, the dwell time coefficient of the objects to be processed coefficient, the time period risk coefficient at the current moment, the abnormality coefficient of the behavior of the objects to be processed coefficient, and the risk weight coefficient of the fenced area to be processed.
[0170] The warning intensity indicates the urgency of issuing risk behavior warnings for a fenced area. The higher the warning intensity, the more urgent the need for risk behavior warnings for the fenced area to be addressed. Furthermore, when multiple fenced areas exist, multiple areas may trigger risk behavior warnings simultaneously. In this case, the warning intensity can be used to prioritize warnings, handle them with care, and allocate resources, thus achieving unified management of risk behavior warnings for all fenced areas.
[0171] Understandably, the more objects to be processed, the more serious the clustering situation in the fenced area, and the higher the warning intensity. Therefore, the number coefficient of objects to be processed should be proportional to the warning intensity.
[0172] The "pending object" in the "pending object dwell time" can refer to all pending objects within the pending fence area, or specifically to known objects identified as exhibiting abnormal behavior by the first behavior recognition model. A longer pending object dwell time indicates a higher probability that the pending object will perform risky behavior within the pending fence area, or a potentially longer duration of abnormal risky behavior. Therefore, the pending object dwell time coefficient should be proportional to the warning intensity.
[0173] The higher the time period risk coefficient at the current moment, the higher the probability of risky behavior occurring during that time period. Therefore, the time period risk coefficient should be proportional to the warning intensity.
[0174] The anomaly coefficient of the object to be processed can be determined by comparing the current behavior pattern of the object with the historical behavior patterns of known objects (for supervised first behavior recognition models); it can also be determined based on the results of logical rule judgments on the object to be processed (for unsupervised second behavior recognition models). The higher the anomaly coefficient of the object to be processed, the higher the probability of risky behavior occurring. Therefore, the anomaly coefficient of the object to be processed should be proportional to the warning intensity.
[0175] The risk weight coefficient for the fenced area to be processed can be predetermined based on factors such as the area type, frequency of historical risky behaviors, and types of historical risky behaviors when setting up the fenced area. Furthermore, when managing each fenced area, a lower risk weight coefficient can be set for fenced areas that have not triggered a risky behavior warning for more than a preset time interval. The risk weight coefficient should be proportional to the warning intensity.
[0176] Furthermore, when the first behavior recognition model and the second behavior recognition model are used in combination, the corresponding warning intensity can be calculated for the first and second risk behavior recognition results based on their respective warning intensity coefficients. For the fenced area to be processed, it can be determined whether to issue a risk behavior warning or to determine its warning priority in each fenced area based on the maximum value of the warning intensity corresponding to the first and second risk behavior recognition results.
[0177] Furthermore, S272 may include: if the duration of the warning intensity of the fenced area to be processed is greater than or equal to the first threshold and less than or equal to the second threshold, and is greater than or equal to the preset time threshold, then a risk behavior warning is issued for the fenced area to be processed.
[0178] Specifically, the second threshold is greater than the first threshold. For example, if the warning intensity is represented by a score, and the first threshold is 60, then the second threshold can be 65. For cases where the warning intensity exceeds 60 but does not exceed 65, in order to avoid the warning intensity exceeding the first threshold being caused by instantaneous fluctuations or occasional false alarms, this embodiment also provides a secondary triggering mechanism for weak signal warnings.
[0179] Specifically, for situations where the warning intensity is greater than or equal to the first threshold but less than or equal to the second threshold, a time delay window is set. The duration of the warning intensity being greater than or equal to the first threshold but less than or equal to the second threshold is recorded, and the warning is escalated to a formal risk behavior warning if the abnormality persists.
[0180] It should be noted that during the duration statistics process, once the warning intensity exceeds the second threshold, a risk behavior warning can be issued directly without further duration statistics.
[0181] The technical solution in this embodiment, based on multi-source data fusion, combines supervised and unsupervised risk behavior identification models and constructs a false alarm correction and adaptive adjustment mechanism, forming a complete intelligent early warning decision system for risk behavior, which improves the adaptability, accuracy and interpretability of risk behavior identification and early warning.
[0182] Furthermore, this embodiment adopts a five-layer architecture of "data layer → perception layer → analysis layer → decision layer → application layer" to achieve modular deployment and closed-loop linkage.
[0183] Figure 3 A schematic diagram of the structure of a risk behavior recognition system is provided, such as... Figure 3 As shown, the data layer comprises three modules: a fenced area management module, a known object database, and a transaction and case plan module. The fenced area management module completes the data archiving, fence drawing, and dynamic maintenance of fenced areas, ensuring real-time synchronization and closed-loop management of fenced area data (such as spatial location, responsible parties, historical risk behavior data, and early warning strategies). Specifically, the fenced area management module creates new fenced areas, including automatically identifying and parsing the address of the new fenced area, associating the address with POI (Point of Interest) coordinates and fence templates, and automatically generating the fenced area. It can also be integrated with a GIS system, responding to the editing operations of the user interface of the drawing tools, to realize the customized drawing of fenced areas.
[0184] The known object database contains information on all entered personnel, vehicles, and equipment. This data can be imported through integration with external third-party management systems via the risk behavior identification system. Structured form records support modification, fuzzy searching, and batch export operations.
[0185] The Transaction and Case Planning module is used to register, query, and analyze risk behavior transaction logs and control plans. Specifically, it can interface with external third-party systems to import data such as device identifiers, transaction logs, transaction types, and IP addresses. Simultaneously, it can obtain information on key monitoring targets, characteristic descriptions, associated devices, and warning levels for risk behaviors.
[0186] The perception layer comprises a risk electronic fence construction module, a multi-source data real-time acquisition module, and a fence-behavior linkage module. The risk electronic fence construction module constructs fence areas of different shapes and sizes based on point-like, linear, and area-like scattered structures. The multi-source data real-time acquisition module collects signaling, transaction logs, device data, video surveillance, historical models, and network log data in real time, providing data support for subsequent analysis and decision-making. The fence-behavior linkage module detects objects entering and leaving the fence boundary within the fence area and perceives the spatial behavior of objects.
[0187] The analysis layer includes a supervised behavior identification module, an unsupervised behavior identification module, and a resident object exclusion module. The supervised behavior identification module identifies anomalous behaviors of known objects within the fenced area based on a known object database. The unsupervised behavior identification module identifies clustered risk behaviors of non-known objects based on group behavior clustering of objects within the fenced area and dynamic threshold determination of group characteristics. The resident object exclusion module identifies resident objects based on historical trajectory clustering and behavior analysis of historical objects within the past 15 days, and excludes resident objects from the risk behavior identification object to avoid false alarms.
[0188] The decision-making layer includes a multi-model fusion strategy module, an early warning intensity scoring module, and a false alarm correction module. The multi-model fusion strategy module performs cross-validation (determining a risky behavior occurs when both modules simultaneously identify it) or complementary triggering (verifying when only one module identifies a risky behavior) based on the risk behavior identification results from the supervised and unsupervised behavior identification modules. The early warning intensity scoring module scores the early warning intensity of each fenced area based on different types of early warning intensity coefficients, thereby determining the early warning priority of each fenced area. The false alarm correction module reduces false alarms of risky behaviors by setting a secondary trigger mechanism for weak signals and by reducing the risk weight of low-risk fenced areas.
[0189] The application layer includes a tiered early warning push module, a heatmap display module, and a case analysis report module. The tiered early warning push module can push different levels of warnings based on different warning intensities. The heatmap display module supports list-style display of fenced areas, and also supports multi-condition filtering and retrieval (by region, risk level, risk behavior type, active time period, etc.), and supports management functions such as "export, delete, view details, and set sensitive time periods". Each fenced area record will dynamically display the current risk status (such as "active", "controlled", "low risk"), and link it to display recent early warning events, a list of associated devices, and a heatmap trend map. The case analysis report module supports spatiotemporal cross-comparison of transaction data with signaling trajectories, fence entry and exit records, device fingerprints, etc., and automatically generates a "suspicious behavior analysis report".
[0190] The five-layer architecture in this embodiment integrates subsystems such as fenced area registration, fenced area drawing, risk behavior identification plan management, known object database, and behavior identification model management. Through a fenced area data entry process that combines automatic synchronization with manual verification, it ensures real-time linkage between spatial fenced areas, object behavior data, risk behaviors, and early warning tags within the early warning system. This forms an end-to-end closed loop from pre-event risk behavior prediction and in-event risk behavior monitoring to post-event traceability, greatly improving the system's scalability, deployment flexibility, and operational efficiency. Furthermore, the risk behavior identification system supports flexible deployment in various scenarios such as financial risk control, smart cities, and secure payments, demonstrating broad applicability, scalability, and social benefits. It is suitable for large-scale promotion and application, contributing to the construction of a modern security and prevention system.
[0191] Example 3
[0192] Figure 4 This is a schematic diagram of a risk behavior identification device provided in Embodiment 3 of the present invention. Figure 4 As shown, the device includes:
[0193] The module 310 for determining the fence area to be processed is used to determine the fence area to be processed.
[0194] The risk behavior identification result determination module 320 is used to determine the first risk behavior identification result based on the object to be processed within the fenced area by using a supervised first behavior identification model, and / or to determine the second risk behavior identification result based on the object to be processed within the fenced area by using an unsupervised second behavior identification model.
[0195] The risk behavior identification module 330 for the fenced area to be processed is used to determine whether a risk behavior has occurred within the fenced area to be processed based on the first risk behavior identification result and / or the second risk behavior identification result.
[0196] The technical solution of this invention, through determining a fenced area to be processed, identifies objects within that area using a supervised first behavior recognition model to determine a first risk behavior identification result, and / or uses an unsupervised second behavior recognition model to determine a second risk behavior identification result. Based on the first and / or second risk behavior identification results, it is determined whether a risky behavior has occurred within the fenced area to be processed. This technical solution, by deploying a supervised and unsupervised dual-model structure, can integrate multi-source data to achieve risk perception and risk transaction behavior early warning for the fenced area to be processed. This improves the sensitivity, accuracy, and adaptability of risk behavior identification, reduces the false alarm rate of risk transaction behavior, and is particularly effective in complex and dynamic scenarios.
[0197] Based on the above embodiments, optionally, the fence area determination module 310 includes:
[0198] The area positioning error determination unit is used to determine the area positioning error of the area to be processed.
[0199] The unit for determining the fenced area to be processed is used to determine the area type of the area to be processed, and to determine the fenced area to be processed based on the area positioning error, the shape of the fenced area matching the area type, and the size of the fenced area.
[0200] Based on the above embodiments, optionally, the area positioning error determination unit is specifically used for:
[0201] Determine the precision estimation area with the center point of the area to be processed as the center and a preset radius as the radius;
[0202] Determine the number of base stations and the received signal strength indication value within the accuracy estimation area;
[0203] The regional positioning error of the area to be processed is determined based on the number of base stations and the received signal strength indication value.
[0204] Based on the above embodiments, optionally, the area type is a point-like type, and the unit for determining the fenced area to be processed is specifically used for:
[0205] The shape of the fence area that matches the dotted area to be processed is determined to be rectangular;
[0206] The size of the fenced area is determined based on the size of the area to be processed and the area positioning error;
[0207] Determine the rectangular fenced area to be processed based on the center point of the area to be processed and the size of the fenced area.
[0208] Based on the above embodiments, optionally, the region type is linear, and the unit for determining the fenced region to be processed is specifically used for:
[0209] The shape of the fenced area that matches the linear region to be processed is determined to be capsule-shaped;
[0210] The width of the fence area is determined based on the size of the area to be processed and the area positioning error.
[0211] The capsule-shaped fenced area to be processed is determined based on the starting point and ending point of the area to be processed and the width of the fenced area.
[0212] Based on the above embodiments, optionally, the area type is scattered, and the unit for determining the fenced area to be processed is specifically used for:
[0213] The shape of the fence area that matches the scattered areas to be processed is determined to be circular;
[0214] The radius of the fenced area is determined based on a preset radius that matches the area to be processed and the area positioning error.
[0215] The circular fenced area to be processed is determined based on the center point of the area to be processed and the radius of the fenced area.
[0216] Based on the above embodiments, optionally, the risk behavior identification result determination module 320 includes:
[0217] The known object judgment unit is used to determine whether the object to be processed within the fenced area is a known object in the pre-set object database through a supervised first behavior recognition model.
[0218] The first risk behavior identification result determination unit is used to determine the first risk behavior identification result based on the current behavior of the object to be processed and the historical behavior of the known object if the object to be processed within the fenced area to be processed is determined to be a known object.
[0219] Based on the above embodiments, optionally, the risk behavior identification result determination module 320 includes:
[0220] The data determination unit for objects to be processed is used to determine the number of objects to be processed in the fenced area and the dwell time of the objects to be processed based on the objects to be processed in the fenced area, using an unsupervised second behavior recognition model.
[0221] The current object activity value determination unit is used to determine the current object activity value based on the number of objects to be processed, the dwell time of the objects to be processed, and the time period risk coefficient at the current moment.
[0222] The second risk behavior identification result determination unit is used to determine the second risk behavior identification result based on the current object activity value, the historical object activity average value, and the volatility coefficient.
[0223] The average activity value of historical objects is calculated by averaging the activity values of each historical object within the same time interval before the current moment that matches the fenced area to be processed.
[0224] Based on the above embodiments, optionally, the objects to be processed within the fenced area do not include the resident objects within the fenced area.
[0225] The resident objects are selected from among the historical objects based on their historical trajectories and behaviors in the historical period before the current time.
[0226] Based on the above embodiments, optionally, the risk behavior identification module 330 for the fenced area to be processed includes:
[0227] The first judgment unit is used to determine that a risky behavior has occurred within the fenced area to be processed if a risky behavior is determined to have occurred based at least on the first risky behavior identification result.
[0228] Based on the above embodiments, optionally, the risk behavior identification module 330 for the fenced area to be processed includes:
[0229] The second judgment unit is used to determine whether a risky behavior has occurred in the fenced area to be processed, based on the historical trajectory and / or device fingerprint of the object to be processed in the fenced area to be processed, if the risky behavior is not determined to have occurred based on the first risky behavior identification result, but is determined to have occurred based on the second risky behavior identification result.
[0230] Based on the above embodiments, optionally, the risk behavior identification module 330 for the fenced area to be processed includes:
[0231] The warning intensity determination unit is used to determine the warning intensity of the fenced area to be treated based on the first risk behavior identification result and / or the second risk behavior identification result, and at least one warning intensity coefficient.
[0232] The risk behavior warning judgment unit is used to determine whether to issue a risk behavior warning for the fenced area to be treated based on the warning intensity of the fenced area to be treated.
[0233] The warning intensity coefficient includes at least one of the following: the number of objects to be processed coefficient, the dwell time coefficient of the objects to be processed coefficient, the time period risk coefficient at the current moment, the abnormality coefficient of the behavior of the objects to be processed coefficient, and the risk weight coefficient of the fenced area to be processed.
[0234] Based on the above embodiments, optionally, the risk behavior early warning judgment unit is specifically used for:
[0235] If the duration of the warning intensity for the fenced area to be processed is greater than or equal to the first threshold and less than or equal to the second threshold, and is greater than or equal to the preset time threshold, then a risk behavior warning is issued for the fenced area to be processed.
[0236] The risk behavior identification device provided in the embodiments of the present invention can execute the risk behavior identification method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method execution.
[0237] Example 4
[0238] Figure 5 A schematic diagram of an electronic device 10, which can be used to implement embodiments of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0239] like Figure 5 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0240] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0241] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as risk behavior recognition methods.
[0242] In some embodiments, the risk behavior identification method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the risk behavior identification method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the risk behavior identification method by any other suitable means (e.g., by means of firmware).
[0243] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0244] Computer programs used to implement the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable risk behavior identification device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The computer programs can be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0245] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0246] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0247] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0248] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0249] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0250] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for identifying risky behaviors, characterized in that, include: Identify the fenced area to be addressed; The first risk behavior identification result is determined by a supervised first behavior identification model based on the object to be processed within the fenced area to be processed, and / or the second risk behavior identification result is determined by an unsupervised second behavior identification model based on the object to be processed within the fenced area to be processed. Based on the results of the first risk behavior identification and / or the second risk behavior identification, determine whether a risk behavior has occurred within the fenced area to be processed.
2. The method according to claim 1, characterized in that, The process of determining the fenced area to be processed includes: Determine the regional positioning error of the area to be processed; Determine the region type of the area to be processed, and determine the fence area to be processed based on the region positioning error, the fence area shape that matches the region type, and the fence area size.
3. The method according to claim 2, characterized in that, The regional positioning error for determining the area to be processed includes: Determine the precision estimation area with the center point of the area to be processed as the center and a preset radius as the radius; Determine the number of base stations and the received signal strength indication value within the accuracy estimation area; The regional positioning error of the area to be processed is determined based on the number of base stations and the received signal strength indication value.
4. The method according to claim 2, characterized in that, The area type is dot-shaped. Determining the fence area to be processed based on the area positioning error, the shape of the fence area matching the area type, and the fence area size includes: The shape of the fence area that matches the dotted area to be processed is determined to be rectangular; The size of the fenced area is determined based on the size of the area to be processed and the area positioning error; Determine the rectangular fenced area to be processed based on the center point of the area to be processed and the size of the fenced area.
5. The method according to claim 2, characterized in that, The region type is linear. Determining the fenced region to be processed based on the region positioning error, the shape of the fenced region matching the region type, and the fenced region size includes: The shape of the fenced area that matches the linear region to be processed is determined to be capsule-shaped; The width of the fence area is determined based on the size of the area to be processed and the area positioning error. The capsule-shaped fenced area to be processed is determined based on the starting point and ending point of the area to be processed and the width of the fenced area.
6. The method according to claim 2, characterized in that, The region type is scattered. The process of determining the fenced region to be processed based on the region positioning error, the shape of the fenced region matching the region type, and the fenced region size includes: The shape of the fence area that matches the scattered areas to be processed is determined to be circular; The radius of the fenced area is determined based on a preset radius that matches the area to be processed and the area positioning error. The circular fenced area to be processed is determined based on the center point of the area to be processed and the radius of the fenced area.
7. The method according to claim 1, characterized in that, The process of determining the first risk behavior identification result based on the object to be processed within the fenced area using a supervised first behavior identification model includes: Using a supervised first behavior recognition model, it is determined whether the object to be processed within the fenced area is a known object in a pre-set object database. If the object to be processed within the fenced area is determined to be a known object, then the first risk behavior identification result is determined based on the current behavior of the object to be processed and the historical behavior of the known objects.
8. The method according to claim 1, characterized in that, The second risk behavior identification result is determined based on the object to be processed within the fenced area using an unsupervised second behavior identification model, including: Using an unsupervised second behavior recognition model, the number of objects to be processed in the fenced area and the dwell time of the objects to be processed are determined based on the objects to be processed in the fenced area. The activity value of the current object is determined based on the number of objects to be processed, the dwell time of the objects to be processed, and the time period risk coefficient at the current moment; The results of the second risk behavior identification are determined based on the current activity value of the object, the historical average activity value of the object, and the volatility coefficient. The average activity value of historical objects is calculated by averaging the activity values of each historical object within the same time interval before the current moment that matches the fenced area to be processed.
9. The method according to claim 7 or 8, characterized in that, The objects to be processed within the fenced area do not include the resident objects within the fenced area. The resident objects are selected from among the historical objects based on their historical trajectories and behaviors in the historical period before the current time.
10. The method according to claim 1, characterized in that, The step of determining whether a risky behavior has occurred within the fenced area to be processed, based on the first risk behavior identification result and / or the second risk behavior identification result, includes: If a risky behavior is determined to have occurred based on at least the first risky behavior identification result, then a risky behavior is determined to have occurred within the fenced area to be processed.
11. The method according to claim 1, characterized in that, The step of determining whether a risky behavior has occurred within the fenced area to be processed, based on the first risk behavior identification result and / or the second risk behavior identification result, further includes: If no risk behavior is identified based on the first risk behavior identification result, but a risk behavior is identified based on the second risk behavior identification result, then it is determined whether a risk behavior has occurred within the fenced area to be processed based on the historical trajectory and / or device fingerprint of the object to be processed within the fenced area to be processed.
12. The method according to claim 1, characterized in that, The step of determining whether a risky behavior has occurred within the fenced area to be processed, based on the first risk behavior identification result and / or the second risk behavior identification result, further includes: Based on the results of the first risk behavior identification and / or the second risk behavior identification, and at least one warning intensity coefficient, determine the warning intensity of the fenced area to be treated; Based on the warning intensity of the fenced area to be treated, determine whether to issue a risk behavior warning for the fenced area to be treated; The warning intensity coefficient includes at least one of the following: the number of objects to be processed coefficient, the dwell time coefficient of the objects to be processed coefficient, the time period risk coefficient at the current moment, the abnormality coefficient of the behavior of the objects to be processed coefficient, and the risk weight coefficient of the fenced area to be processed.
13. The method according to claim 12, characterized in that, The step of determining whether to issue a risk behavior warning for the fenced area to be treated based on the warning intensity of the fenced area to be treated includes: If the duration of the warning intensity for the fenced area to be processed is greater than or equal to the first threshold and less than or equal to the second threshold, and is greater than or equal to the preset time threshold, then a risk behavior warning is issued for the fenced area to be processed.
14. A risk behavior identification device, characterized in that, include: The module for determining the fenced area to be processed is used to determine the fenced area to be processed. The risk behavior identification result determination module is used to determine the first risk behavior identification result based on the object to be processed within the fenced area by using a supervised first behavior identification model, and / or to determine the second risk behavior identification result based on the object to be processed within the fenced area by using an unsupervised second behavior identification model. The risk behavior identification module for the fenced area to be processed is used to determine whether a risky behavior has occurred within the fenced area to be processed based on the first risk behavior identification result and / or the second risk behavior identification result.
15. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the risk behavior identification method as described in any one of claims 1-13.
16. A storage medium for storing computer-executable instructions, characterized in that, The computer-executable instructions, when executed by a computer processor, are used to perform the risk behavior identification method as described in any one of claims 1-13.