An intelligent anomaly detection system for evaluating field management

By collecting facial feature information to generate check-in events, dynamically generating anomaly judgment thresholds, constructing behavioral time-series chains and performing matching analysis, the system solves the problems of misjudgment and manual dependence in existing on-site assessment management systems, and achieves automated and accurate anomaly detection and management.

CN122155211APending Publication Date: 2026-06-05NANTONG SHENGHUI FUTURE SCI & TECH TRADING CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NANTONG SHENGHUI FUTURE SCI & TECH TRADING CO LTD
Filing Date
2026-02-26
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

Existing on-site assessment management systems suffer from misjudgments or omissions in anomaly detection, are difficult to adapt to complex and ever-changing on-site assessment environments, lack the ability to model the continuous behavior of assessment personnel, and lack clear interpretation of anomaly detection results, requiring managers to rely on manual analysis, which is inefficient.

Method used

By collecting facial feature information of the test takers, check-in events are generated, an anomaly judgment threshold set is dynamically generated, a behavior time sequence chain is constructed, and anomaly judgment results are generated by matching and analyzing the anomaly judgment threshold set with preset rules. An anomaly evidence chain is then constructed and stored.

Benefits of technology

It enables automatic identification and recording of assessment personnel behavior, improves the accuracy and adaptability of anomaly detection, provides quantitative and interpretable anomaly results, enhances the standardization and transparency of management, and supports real-time monitoring and anomaly review.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122155211A_ABST
    Figure CN122155211A_ABST
Patent Text Reader

Abstract

The application discloses an intelligent abnormality detection system for evaluation site management, and relates to the technical field of evaluation management. The method comprises the following steps: a clock-in event generation module collects face feature information of an evaluation personnel and compares the face feature information with a pre-stored identity template to generate a clock-in event; a rhythm abnormality judgment module analyzes project rhythm parameters to generate an abnormality judgment threshold set; a behavior time sequence construction module aggregates multiple clock-in events of the same evaluation personnel under the same evaluation project to construct a behavior time sequence chain; an abnormality judgment module matches and analyzes the behavior time sequence chain with an abnormality detection rule to generate an abnormality judgment result; an abnormality cause explanation module extracts rule identification and time offset information triggering the abnormality judgment to generate abnormality cause explanation data; and an abnormality detection result module constructs an abnormality evidence chain to generate an abnormality detection result and stores the abnormality detection result for evaluation site management. The application significantly improves the intelligent level and data reliability of evaluation site management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of assessment management technology, and in particular to an intelligent anomaly detection system for on-site assessment management. Background Technology

[0002] In on-site work such as cybersecurity assessment and information system security level protection assessment, assessment personnel are typically required to arrive at the designated project site within a limited time and complete the corresponding tasks. During on-site assessment management, it is usually necessary to record the entry, presence, and departure of assessment personnel. This serves as crucial evidence for the compliance of the assessment process, personnel attendance, and the validity of the results. Therefore, accurately recording personnel entry and exit behavior and promptly identifying abnormal situations has become a key technical issue in on-site assessment management.

[0003] In related technologies, existing assessment site management systems typically judge personnel behavior based on simple time rules or fixed thresholds for anomaly detection. However, assessment projects often have different organizational rhythms and personnel activity characteristics at different stages. Using uniform, static anomaly judgment standards is prone to misjudgment or omission, making it difficult to adapt to the complex and ever-changing assessment site environment. Furthermore, existing anomaly detection methods mostly analyze single attendance events, lacking the ability to model the continuous behavioral processes of assessment personnel. This makes it difficult to identify complex abnormal behavior patterns such as lateness, early departure, abnormal stays, and frequent entry and exit from a time-series perspective. Additionally, some anomaly detection methods, after providing anomaly judgment results, do not explain the specific reasons for the anomalies. Managers still need to rely on manual analysis during anomaly review and handling, resulting in low efficiency and the judgment criteria are not intuitive enough, indicating room for improvement. Summary of the Invention

[0004] The purpose of this invention is to provide an intelligent anomaly detection system for on-site management of testing and evaluation, so as to solve the problems mentioned in the background art.

[0005] This application provides an intelligent anomaly detection system for on-site management of testing, which adopts the following technical solution:

[0006] When the evaluators enter or leave the venue, their facial features are collected and compared with a pre-stored identity template to generate a corresponding check-in event.

[0007] Obtain the project stage status of the evaluation project, parse the corresponding project rhythm parameters, and dynamically generate an anomaly judgment threshold set for anomaly detection based on the project rhythm parameters;

[0008] Aggregate multiple check-in events of the same evaluator under the same evaluation project in chronological order to construct the behavioral sequence chain of the evaluator;

[0009] Based on the set of anomaly determination thresholds, the behavioral time sequence chain is matched and analyzed with preset anomaly detection rules to generate anomaly determination results;

[0010] Based on the anomaly determination results, the rule identifier that triggered the anomaly determination and the corresponding time offset information are extracted to generate anomaly cause explanation data.

[0011] The abnormality cause explanation data is associated with the corresponding check-in events to construct an abnormality evidence chain arranged in chronological order. The abnormality judgment result, abnormality cause explanation data and abnormality evidence chain are combined to generate an abnormality detection result and store it for on-site evaluation management.

[0012] Preferably, the steps for collecting facial feature information of evaluators and comparing it with a pre-stored identity template to generate a corresponding check-in event when evaluators enter or leave the venue are as follows:

[0013] When the evaluators enter or leave the venue, their facial image data is collected, and the validity of the facial image data is verified to determine whether the facial image data meets the preset requirements for facial integrity and clarity.

[0014] After the face image data passes the validity verification, face features are extracted from the face image data to generate corresponding face feature information;

[0015] The facial feature information is compared with the pre-stored identity template to calculate the facial matching degree parameter, and the facial matching degree parameter is compared with the preset identity consistency threshold.

[0016] Once the face matching parameter reaches the preset identity consistency threshold, it is determined that the evaluator has passed the identity verification and a corresponding check-in event is generated. The check-in event includes the evaluator's identity identifier, check-in timestamp, check-in type, and evaluation item identifier.

[0017] Preferably, the steps of obtaining the project stage status of the evaluation project, parsing the corresponding project rhythm parameters, and dynamically generating an anomaly judgment threshold set for anomaly detection based on the project rhythm parameters are as follows:

[0018] Based on the evaluation item identifier in the check-in event, the project stage status of the corresponding evaluation item is obtained, the validity of the project stage status is verified, and it is confirmed that the project stage status is within the preset valid evaluation period.

[0019] Based on the project stage status, the stage rhythm mapping rule corresponding to the project stage status is invoked to parse the project stage status and obtain the project rhythm parameters that characterize the time characteristics of the project stage.

[0020] Obtain preset anomaly judgment benchmark parameters, dynamically adjust the anomaly judgment benchmark parameters based on the project rhythm parameters, and generate anomaly judgment threshold set for anomaly detection based on the adjusted anomaly judgment benchmark parameters.

[0021] Preferably, the steps of obtaining preset anomaly judgment benchmark parameters, dynamically adjusting the anomaly judgment benchmark parameters based on the project rhythm parameters, and generating anomaly judgment threshold set for anomaly detection based on the adjusted anomaly judgment benchmark parameters are as follows:

[0022] Obtain preset anomaly judgment benchmark parameters, which are used to characterize the basic time deviation range and anomaly judgment sensitivity of the evaluation personnel's check-in behavior;

[0023] Extract the project rhythm parameters corresponding to the project stage status, map the project rhythm parameters, and generate parameter adjustment factors;

[0024] Based on the parameter adjustment factor, the anomaly judgment benchmark parameter is dynamically adjusted to obtain the adjusted anomaly judgment parameter that matches the project stage status.

[0025] Based on the adjusted anomaly detection parameters, an anomaly detection threshold set is generated. The validity of the anomaly detection threshold set is then verified to confirm that the anomaly detection threshold set is within a preset reasonable parameter range.

[0026] Preferably, the steps for aggregating multiple check-in events of the same assessor under the same assessment project in chronological order to construct the assessor's behavioral time sequence chain are as follows:

[0027] Based on the evaluator's identity and the evaluation item's identifier, the generated check-in events are filtered to obtain a set of check-in events for the same evaluator under the same evaluation item;

[0028] Perform an integrity check on each check-in event in the set of check-in events to confirm that each check-in event contains a valid check-in timestamp;

[0029] According to the check-in timestamp, the check-in events that have passed the integrity check are sorted in chronological order, and the sorted check-in events are labeled with event type according to the check-in type to obtain the check-in event type. The check-in event type includes entry check-in event and exit check-in event.

[0030] Perform correlation analysis on adjacent check-in events, calculate the time interval between adjacent check-in events, and obtain the time interval between adjacent events;

[0031] The check-in event type, check-in timestamp, and time interval between adjacent events are encapsulated as time sequence nodes, and the time sequence nodes are connected in chronological order to generate the behavior time sequence chain of the evaluator.

[0032] Preferably, the step of matching and analyzing the behavioral time sequence chain with preset anomaly detection rules based on the anomaly determination threshold set to generate anomaly determination results specifically includes:

[0033] Retrieve the preset anomaly detection rules corresponding to the current evaluation item, and map and associate the anomaly detection rules with each anomaly judgment threshold in the anomaly judgment threshold set;

[0034] Based on the behavioral temporal sequence, behavioral feature parameters for anomaly detection are extracted. Matching analysis is performed on each behavioral feature parameter according to the anomaly detection rules, and it is determined whether the behavioral feature parameter exceeds the corresponding anomaly judgment threshold in the anomaly judgment threshold set.

[0035] When the behavioral feature parameters exceed the corresponding anomaly determination threshold, an abnormal behavior is determined to exist. The anomaly detection rule identifier that triggered the anomaly and the corresponding behavioral feature parameters are recorded, and an anomaly determination result containing anomaly triggering rule information is generated.

[0036] Preferably, the step of extracting the rule identifier that triggered the anomaly determination and the corresponding time offset information based on the anomaly determination result, and generating anomaly cause explanation data, specifically includes:

[0037] Based on the anomaly determination result, the anomaly detection rule identifier that triggered the anomaly determination is extracted, the behavior feature parameter type corresponding to the anomaly detection rule identifier is determined, and the occurrence time of the abnormal behavior that matches the behavior feature parameter type is retrieved from the behavior time sequence chain.

[0038] Obtain the standard time reference information associated with the anomaly detection rule identifier, calculate the time offset between the anomaly event and the standard time reference information, and generate anomaly cause explanation data.

[0039] Preferably, the steps of obtaining standard time reference information associated with the anomaly detection rule identifier, calculating the time offset between the anomaly occurrence event and the standard time reference information, and generating anomaly cause explanation data are as follows:

[0040] Obtain the standard time reference information associated with the anomaly detection rule identifier, wherein the standard time reference information is used to represent the reference time range that the behavioral characteristic parameters should meet under normal circumstances;

[0041] Based on the abnormal behavior occurrence time information and the standard time reference information, calculate the time offset of the abnormal behavior occurrence time relative to the standard time reference;

[0042] The anomaly detection rule identifier is associated and integrated with the time offset to generate anomaly cause explanation data that characterizes the cause of anomalies.

[0043] Preferably, the steps of associating the anomaly cause explanation data with the corresponding check-in events to construct an anomaly evidence chain arranged in chronological order, and generating and storing an anomaly detection result by combining the anomaly judgment result, the anomaly cause explanation data, and the anomaly evidence chain for use in on-site evaluation management are as follows:

[0044] The abnormality cause explanation data is associated with the corresponding abnormality judgment results to determine the set of check-in events that trigger the abnormality judgment;

[0045] The time information of each check-in event in the set of check-in events is uniformly aligned, and a corresponding evidence node is constructed for each check-in event based on the aligned time information.

[0046] The evidence nodes are sorted in chronological order, and the evidence nodes are sequentially associated according to the sorting results to construct an abnormal evidence chain that represents the order of occurrence and evolution of abnormal behavior.

[0047] The anomaly determination results, anomaly cause explanation data, and anomaly evidence chain are integrated to generate an anomaly detection result containing anomaly type information, anomaly formation cause information, and anomaly evidence chain information. The anomaly detection result is stored for on-site evaluation management.

[0048] In summary, this application includes at least one of the following beneficial technical effects:

[0049] 1. By collecting facial feature information of assessment personnel and comparing it with pre-stored identity templates, the system automatically generates corresponding check-in events, enabling automatic identification and recording of personnel's entry and exit behaviors. This effectively avoids issues such as proxy check-ins, missed registrations, and human tampering, ensuring the authenticity and uniqueness of check-in data. Simultaneously, it transforms personnel entry and exit behaviors into standardized check-in events, providing structurally consistent and time-accurate foundational data for subsequent behavior analysis and anomaly detection. By analyzing the project rhythm parameters of the assessment projects, it dynamically generates a set of anomaly judgment thresholds, allowing the anomaly judgment criteria to adaptively adjust with the operational rhythm of different project stages. This avoids misjudgments caused by differences in personnel activity rhythms, thereby improving the accuracy and adaptability of anomaly detection in complex assessment scenarios. By aggregating multiple check-in events of the same assessment personnel in chronological order, it constructs a behavioral time-series chain, enabling the system to analyze personnel presence from the perspective of the overall behavioral process. This provides support for identifying complex abnormal behaviors such as lateness, early departure, abnormal stays, and frequent entry and exit, significantly improving the analytical depth of anomaly detection. By performing matching analysis based on behavioral time-series chains, dynamic thresholds, and anomaly rules, objective and automated judgment of personnel behavior is achieved, avoiding inconsistencies caused by manual judgment. Further, rule identifiers and time offset information triggering anomalies are extracted, transforming anomaly judgment results into quantifiable and interpretable data, enhancing the understandability and credibility of anomaly results. By associating anomaly cause explanation data with relevant check-in events, an anomaly evidence chain is constructed, and anomaly detection results are structured and stored, providing reliable support for real-time monitoring, anomaly review, and audit traceability at the assessment site, improving the standardization and transparency of assessment site management.

[0050] 2. By configuring corresponding standard time bases for each type of anomaly detection rule, the reasonable range of normal behavior in the time dimension is clearly distinguished, avoiding reliance on empirical or vague standards for anomaly judgment. The anomaly detection process has a clear time reference, laying the foundation for the subsequent quantitative calculation of the degree of deviation of abnormal behavior and improving the objectivity and consistency of anomaly analysis. By comparing the occurrence time of abnormal behavior with the reference time range of normal behavior, it is possible to accurately characterize whether the abnormal behavior occurs early, late, or exceeds the reasonable time interval, thus providing a quantitative basis for anomaly cause analysis. The calculation of time offset transforms anomaly analysis from qualitative description to quantitative evaluation, helping the system to make fine distinctions under different anomaly scenarios and improving the accuracy and interpretability of anomaly detection results. By integrating the anomaly detection rule identifier with the corresponding time offset, the anomaly cause explanation data can simultaneously reflect the anomaly triggering rule and the degree of anomaly deviation, providing clear and complete explanatory information for anomaly detection results. By generating structured anomaly cause explanation data, reliable data support is provided for subsequent anomaly evidence chain construction, anomaly review, and management decisions, significantly improving the practicality and credibility of the anomaly detection solution in on-site assessment management.

[0051] 3. By correlating and analyzing the anomaly cause explanation data with the anomaly judgment results, it is possible to accurately identify which check-in events directly or indirectly led to the anomaly judgment results. This avoids anomaly analysis remaining at the level of abstract rules, providing a clear event basis for subsequent evidence node construction and evidence chain generation, and improving the pertinence and traceability of anomaly analysis. By uniformly aligning the time information of check-in events, time deviations caused by differences in equipment, network latency, or inconsistent data collection timing are eliminated, ensuring the accuracy of subsequent evidence chain sequencing. By constructing evidence nodes containing time information, event attributes, and identity information, each anomaly-related check-in event possesses an independent and complete form of evidence expression, providing fundamental support for the evidentiary analysis of abnormal behavior. By chaining evidence nodes in chronological order, abnormal behavior is no longer an isolated event but is restored to a behavioral process with causal and temporal relationships. The anomaly evidence chain can intuitively reflect the occurrence sequence, duration, and changing trends of abnormal behavior, providing clear and verifiable evidence for anomaly review, responsibility determination, and management decisions, significantly enhancing the transparency and credibility of anomaly management. By comprehensively integrating the results of multi-source anomaly analysis, the anomaly detection results include not only the judgment conclusions but also the causes and complete evidence chains, forming structured and traceable anomaly management data. The system can continuously support real-time anomaly handling, post-event review, and audit traceability in the assessment site management, realizing the explainable, verifiable, and traceable management of abnormal behaviors at the assessment site, and effectively improving the standardization and intelligence level of assessment site management. Attached Figure Description

[0052] Figure 1 This is a schematic diagram of the module connections of an embodiment of an intelligent anomaly detection system for on-site management of evaluation according to the present invention.

[0053] Figure 2 This is a flowchart illustrating the specific steps of an embodiment of an intelligent anomaly detection system for on-site management of evaluation according to the present invention.

[0054] Attached image labels: 1. Check-in event generation module. 2. Rhythm anomaly detection module. 3. Behavior sequence construction module. 4. Anomaly detection module. 5. Anomaly cause explanation module. 6. Anomaly detection result module. Detailed Implementation

[0055] The following examples and... Figures 1-2 The present invention will be described in further detail, but the embodiments of the present invention are not limited thereto.

[0056] This invention discloses an intelligent anomaly detection system for on-site management of testing, specifically including the following steps:

[0057] The check-in event generation module 1 collects the facial feature information of the evaluators when they enter or leave the venue and compares it with the pre-stored identity template to generate the corresponding check-in event.

[0058] The rhythm anomaly determination module 2 obtains the project stage status of the evaluation project, parses the corresponding project rhythm parameters, and dynamically generates an anomaly determination threshold set for anomaly detection based on the project rhythm parameters.

[0059] Behavior sequence construction module 3 aggregates multiple check-in events of the same assessor under the same assessment project in chronological order to construct the behavior sequence chain of the assessor.

[0060] The anomaly determination module 4, based on the set of anomaly determination thresholds, performs matching analysis between the behavior time sequence chain and the preset anomaly detection rules to generate anomaly determination results;

[0061] The anomaly cause explanation module 5 extracts the rule identifier that triggered the anomaly judgment and the corresponding time offset information based on the anomaly judgment result, and generates anomaly cause explanation data.

[0062] The anomaly detection result module 6 associates the anomaly cause explanation data with the corresponding check-in event, constructs an anomaly evidence chain arranged in chronological order, and generates and stores anomaly detection results by combining the anomaly judgment result, anomaly cause explanation data and anomaly evidence chain for on-site evaluation management.

[0063] In practical applications, by collecting facial feature information of assessment personnel and comparing it with pre-stored identity templates, corresponding check-in events are generated. This allows for the automatic identification and recording of assessment personnel's entry and exit behaviors without manual intervention, effectively avoiding issues such as proxy check-ins, missed registrations, and human tampering, ensuring the authenticity and uniqueness of the check-in data. Simultaneously, by transforming entry and exit behaviors into standardized check-in events, a unified and time-accurate foundation of data is provided for subsequent behavior analysis and anomaly detection. By parsing the corresponding project rhythm parameters, an anomaly judgment threshold set is generated, enabling the anomaly judgment criteria to adaptively adjust to different stages and rhythms of the assessment project. This avoids misjudgments caused by differences in personnel activity rhythms during the project preparation, implementation, or closing stages, making anomaly judgments more closely aligned with the actual operational status of the assessment site. This improves the accuracy and adaptability of anomaly detection results, thereby enhancing the system's practical value in complex assessment scenarios. Multiple attendance events are aggregated and processed chronologically to construct a behavioral timeline chain for the assessors. This allows the system to analyze personnel presence from the perspective of the overall behavioral process, rather than relying solely on single attendance results. This provides a foundation for identifying complex abnormal behaviors such as lateness, early departure, abnormal stays, and frequent entry / exit, significantly improving the analytical depth and discriminative ability of anomaly detection. By combining the behavioral timeline chain with dynamic thresholds and anomaly rules, objective judgment of personnel behavior is achieved, avoiding inconsistencies and lags caused by subjective human judgment. The rule identifiers triggering anomaly judgments and their corresponding time offset information are extracted. By quantifying the time offset of abnormal behavior relative to the normal behavior baseline, the anomaly judgment results are transformed into interpretable data, effectively solving the problem of traditional anomaly detection systems only providing results without explanation of the reasons. This helps managers quickly understand the essence of anomalies, improving the efficiency and accuracy of anomaly handling, and also enhancing the persuasiveness of anomaly judgment results during review and auditing processes. By linking the data explaining the causes of anomalies with corresponding check-in events and processing the evidence chain, the system organically integrates the check-in events, cause explanations, and judgment conclusions related to the anomalies. This not only clearly presents the occurrence process and evolution path of abnormal behavior but also provides reliable data support for anomaly review, responsibility determination, and post-event auditing. Through structured storage of anomaly detection results, the system can continuously serve real-time monitoring and historical traceability in assessment site management, significantly improving the standardization and transparency of assessment site management.

[0064] The steps involved in collecting facial feature information of evaluators during entry or exit operations and comparing it with a pre-stored identity template to generate a corresponding check-in event are as follows:

[0065] When the evaluators enter or leave the venue, their facial image data is collected, and the validity of the facial image data is verified to determine whether the facial image data meets the preset requirements for facial integrity and clarity.

[0066] After the face image data passes the validity verification, face features are extracted from the face image data to generate corresponding face feature information;

[0067] The facial feature information is compared with the pre-stored identity template to calculate the facial matching degree parameter, and the facial matching degree parameter is compared with the preset identity consistency threshold.

[0068] Once the face matching parameter reaches the preset identity consistency threshold, it is determined that the evaluator has passed the identity verification and a corresponding check-in event is generated. The check-in event includes the evaluator's identity identifier, check-in timestamp, check-in type, and evaluation item identifier.

[0069] In practical applications, by introducing integrity and clarity verification mechanisms during the data acquisition stage, it is possible to determine whether the facial image data meets the preset requirements for facial integrity and clarity. This effectively filters out low-quality facial images caused by insufficient lighting, severe occlusion, abnormal posture, or device vibration, preventing low-quality data from directly entering the feature extraction and identity comparison process and causing misidentification or rejection. By performing pre-emptive quality control on facial image data, not only is the accuracy and stability of identity verification improved, but the ineffective consumption of subsequent computing resources is also reduced, providing reliable data support for high-frequency, rapid check-in scenarios at the evaluation site. Through facial feature extraction processing, high-dimensional, redundant image information is mapped into discriminative facial feature vectors. Compared to directly using the original image for comparison, feature processing can significantly reduce computational complexity, improve comparison efficiency, and enhance robustness to non-critical factors such as lighting changes and facial expression differences, enabling the system to maintain stable identity recognition performance even in complex evaluation environments. By quantitatively evaluating the similarity between currently collected facial features and pre-stored identity templates, and introducing an identity consistency threshold as a criterion, the identity verification process has a clear numerical standard, avoiding the uncertainty caused by subjective judgment or fuzzy matching. The system can achieve a balance between security and pass rate, effectively preventing unauthorized personnel from impersonating others to enter the assessment site. By processing the identity verification results as events, the actual entry and exit behavior of assessment personnel is accurately and in real time recorded as traceable data objects, providing a unified data entry point for subsequent behavior sequence chain construction, anomaly detection, and evidence chain analysis. By integrating personnel identity information, time information, and project context information into the same check-in event, refined management of personnel behavior at the assessment site is achieved, significantly improving the automation level and data reliability of on-site attendance and anomaly monitoring.

[0070] The steps of obtaining the project stage status of the evaluation project, parsing the corresponding project rhythm parameters, and dynamically generating anomaly judgment threshold set for anomaly detection based on the project rhythm parameters are as follows:

[0071] Based on the evaluation item identifier in the check-in event, the project stage status of the corresponding evaluation item is obtained, the validity of the project stage status is verified, and it is confirmed that the project stage status is within the preset valid evaluation period.

[0072] Based on the project stage status, the stage rhythm mapping rule corresponding to the project stage status is invoked to parse the project stage status and obtain the project rhythm parameters that characterize the time characteristics of the project stage.

[0073] Obtain preset anomaly judgment benchmark parameters, dynamically adjust the anomaly judgment benchmark parameters based on the project rhythm parameters, and generate anomaly judgment threshold set for anomaly detection based on the adjusted anomaly judgment benchmark parameters.

[0074] In practical applications, by introducing a validity verification mechanism after acquiring the project stage status, the misuse of abnormal parameters caused by projects not yet started, already completed, or outside the evaluation cycle can be effectively avoided. This prevents the introduction of inapplicable rhythm rules or anomaly judgment criteria into the anomaly detection process. By ensuring the timeliness and legality of the project stage status, a reliable prerequisite for the accurate generation of anomaly judgment thresholds is provided, improving the stability and security of the entire anomaly detection solution in multi-project, multi-stage parallel scenarios. By introducing stage rhythm mapping rules, the rhythm of personnel activities, time arrangements, and behavioral expectations corresponding to different project stages are modeled in a rule-based manner, accurately identifying the differences in time dimension of each stage. By parsing the project stage status into project rhythm parameters, anomaly detection no longer relies on a single, fixed time assumption, but can dynamically adapt according to the actual running rhythm of the project, thereby significantly improving the scenario adaptability and accuracy of anomaly judgment. By incorporating project rhythm parameters into the anomaly detection threshold generation process, the anomaly detection threshold becomes dynamic and contextualized, avoiding the problem of insufficient applicability of traditional fixed thresholds at different project stages. By generating anomaly detection threshold sets that match the current project rhythm, the system can more accurately distinguish between normal and abnormal behaviors, reducing false alarms and missed alarms, and providing more reliable and refined anomaly detection support for on-site assessment management.

[0075] The steps of obtaining preset anomaly judgment benchmark parameters, dynamically adjusting the anomaly judgment benchmark parameters based on the project rhythm parameters, and generating anomaly judgment threshold set for anomaly detection based on the adjusted anomaly judgment benchmark parameters are as follows:

[0076] Obtain preset anomaly judgment benchmark parameters, which are used to characterize the basic time deviation range and anomaly judgment sensitivity of the evaluation personnel's check-in behavior;

[0077] Extract the project rhythm parameters corresponding to the project stage status, map the project rhythm parameters, and generate parameter adjustment factors;

[0078] Based on the parameter adjustment factor, the anomaly judgment benchmark parameter is dynamically adjusted to obtain the adjusted anomaly judgment parameter that matches the project stage status.

[0079] Based on the adjusted anomaly detection parameters, an anomaly detection threshold set is generated. The validity of the anomaly detection threshold set is then verified to confirm that the anomaly detection threshold set is within a preset reasonable parameter range.

[0080] In practical applications, by introducing anomaly judgment benchmark parameters, these parameters reflect the reasonable fluctuation range of normal attendance behavior of assessors over time, providing a controllable basis for subsequent dynamic adjustments and effectively avoiding instability caused by anomaly detection standards relying entirely on experience or temporary configuration. By mapping and modeling project rhythm parameters, the abstract project stage rhythm is transformed into adjustment factors that can directly affect anomaly judgment parameters, enabling anomaly detection to perceive differences in time allocation and personnel activity intensity across project stages. Introducing parameter adjustment factors allows for fine-tuning of anomaly judgment sensitivity across different project stages, thereby enhancing the adaptability and discriminative ability of anomaly detection in complex assessment scenarios. Quantifying and integrating the impact of project rhythm on anomaly judgment parameters achieves a shift from static configuration to dynamic generation, avoiding misjudgments caused by using the same judgment scale across different project stages. Through dynamically adjusted anomaly judgment parameters, the system can reasonably balance anomaly detection sensitivity and stability while ensuring accuracy in anomaly identification, providing a parameter basis that better reflects actual operating conditions for subsequent threshold generation. By converting the adjusted anomaly judgment parameters into a specific executable threshold set, the anomaly detection rules can directly call the thresholds to make behavior judgments. At the same time, by validating the threshold set, the system can prevent threshold distortion caused by abnormal parameters, configuration errors, or extreme rhythm conditions, thereby avoiding a large number of false alarms or missed alarms and effectively improving the stability and controllability of the anomaly detection system in actual evaluation field operation.

[0081] The steps for aggregating multiple check-in events of the same assessor under the same assessment project in chronological order, and constructing the behavioral sequence chain of the assessor, are as follows:

[0082] Based on the evaluator's identity and the evaluation item's identifier, the generated check-in events are filtered to obtain a set of check-in events for the same evaluator under the same evaluation item;

[0083] Perform an integrity check on each check-in event in the set of check-in events to confirm that each check-in event contains a valid check-in timestamp;

[0084] According to the check-in timestamp, the check-in events that have passed the integrity check are sorted in chronological order, and the sorted check-in events are labeled with event type according to the check-in type to obtain the check-in event type. The check-in event type includes entry check-in event and exit check-in event.

[0085] Perform correlation analysis on adjacent check-in events, calculate the time interval between adjacent check-in events, and obtain the time interval between adjacent events;

[0086] The check-in event type, check-in timestamp, and time interval between adjacent events are encapsulated as time sequence nodes, and the time sequence nodes are connected in chronological order to generate the behavior time sequence chain of the evaluator.

[0087] In practical applications, the dual filtering of personnel identification and assessment project identification effectively prevents check-in events from being mixed into the analysis process, ensuring that subsequent behavior analysis focuses solely on the behavioral trajectory of a single assessor within a specific project. Aggregating check-in events provides a complete and unified data set for constructing the behavioral timeline, a fundamental step in ensuring the accuracy of behavior analysis. Verifying the validity of the timestamp field in check-in events allows for the timely detection and removal of invalid events with missing or abnormal time information, preventing incomplete data from entering subsequent sorting and time interval calculation processes and causing logical errors or analytical biases. This upfront data integrity control enhances the stability and reliability of the behavioral timeline construction process. Time sorting transforms the originally disordered check-in events into a sequence structure with clear temporal logic. Furthermore, event type labeling distinguishes between entry and exit check-in events, enabling the system to accurately identify the start, end, and direction of personnel behavior. By calculating the time intervals between adjacent events, the system characterizes the duration of personnel's stay at the assessment site, their departure intervals, and the continuity of their behavior from a temporal perspective. This provides key feature indicators for identifying behaviors such as abnormal stays, frequent entry and exit, or abnormal intervals. The quantification of time intervals provides a directly usable basis for anomaly detection rules, significantly enhancing the precision of anomaly analysis. By encapsulating multidimensional behavioral elements into unified temporal nodes and connecting them in a chain structure, the system fully and continuously represents the behavioral process of assessment personnel in the assessment project. This not only reflects the characteristics of individual behaviors but also demonstrates the temporal relationships and evolutionary trends between behaviors, providing a core data structure for subsequent anomaly determination, causal explanation, and evidence chain construction.

[0088] The steps for matching and analyzing the behavioral time-series chain with preset anomaly detection rules based on the anomaly determination threshold set to generate anomaly determination results are as follows:

[0089] Retrieve the preset anomaly detection rules corresponding to the current evaluation item, and map and associate the anomaly detection rules with each anomaly judgment threshold in the anomaly judgment threshold set;

[0090] Based on the behavioral temporal sequence, behavioral feature parameters for anomaly detection are extracted. Matching analysis is performed on each behavioral feature parameter according to the anomaly detection rules, and it is determined whether the behavioral feature parameter exceeds the corresponding anomaly judgment threshold in the anomaly judgment threshold set.

[0091] When the behavioral feature parameters exceed the corresponding anomaly determination threshold, an abnormal behavior is determined to exist. The anomaly detection rule identifier that triggered the anomaly and the corresponding behavioral feature parameters are recorded, and an anomaly determination result containing anomaly triggering rule information is generated.

[0092] In practical applications, by mapping anomaly detection rules to dynamically generated anomaly judgment thresholds, the system can adopt differentiated judgment standards for different projects and stages, providing a clear and executable judgment basis for anomaly detection and improving the standardization and consistency of the anomaly judgment process. By extracting discriminative behavioral feature parameters from the behavioral time-series chain, the system can conduct multi-dimensional analysis of personnel behavior from the perspective of the overall behavioral process, rather than relying solely on single attendance records. Through rule-driven matching analysis and threshold comparison mechanisms, the system accurately identifies whether behavioral feature parameters deviate from the normal range, providing objective and quantitative evidence for anomaly judgment and significantly improving the accuracy and interpretability of anomaly detection. By recording anomaly trigger rule identifiers and behavioral feature parameters, the anomaly judgment results not only include the conclusion of whether an anomaly exists but also clarify the specific judgment basis for the anomaly. By generating structured anomaly judgment results, the system provides clear data support for subsequent anomaly cause explanation, anomaly evidence chain construction, and anomaly management decisions, enhancing the credibility and practical value of anomaly detection results in the review and auditing process.

[0093] Based on the anomaly determination result, the steps of extracting the rule identifier that triggered the anomaly determination and the corresponding time offset information to generate anomaly cause explanation data are as follows:

[0094] Based on the anomaly determination result, the anomaly detection rule identifier that triggered the anomaly determination is extracted, the behavior feature parameter type corresponding to the anomaly detection rule identifier is determined, and the occurrence time of the abnormal behavior that matches the behavior feature parameter type is retrieved from the behavior time sequence chain.

[0095] Obtain the standard time reference information associated with the anomaly detection rule identifier, calculate the time offset between the anomaly event and the standard time reference information, and generate anomaly cause explanation data.

[0096] In practical applications, by reverse-analyzing the anomaly detection results, it is possible to accurately identify which anomaly detection rule was triggered and the specific behavioral characteristic parameter type that the rule focuses on. This allows anomaly detection to go beyond the result level and delve into the specific behavioral dimension of the anomaly occurrence. By retrieving the corresponding occurrence time of the abnormal behavior from the behavioral time-series chain, time data support is provided for subsequent anomaly offset calculations, effectively enhancing the pertinence and traceability of the anomaly analysis process. By comparing the occurrence time of the abnormal behavior with a standard time benchmark, the degree of deviation of the abnormal behavior from the expected normal behavior can be intuitively reflected. This transforms the anomaly cause from an abstract description into quantifiable data results, generating anomaly cause explanation data containing time offsets. This not only explains what happened during the anomaly but also how much the anomaly deviated, providing clearer and more reliable technical evidence for anomaly review, management decisions, and responsibility determination, significantly improving the interpretability and management value of anomaly detection results.

[0097] The steps of obtaining standard time reference information associated with the anomaly detection rule identifier, calculating the time offset between the anomaly occurrence event and the standard time reference information, and generating anomaly cause explanation data are as follows:

[0098] Obtain the standard time reference information associated with the anomaly detection rule identifier, wherein the standard time reference information is used to represent the reference time range that the behavioral characteristic parameters should meet under normal circumstances;

[0099] Based on the abnormal behavior occurrence time information and the standard time reference information, calculate the time offset of the abnormal behavior occurrence time relative to the standard time reference;

[0100] The anomaly detection rule identifier is associated and integrated with the time offset to generate anomaly cause explanation data that characterizes the cause of anomalies.

[0101] In practical applications, by configuring corresponding standard time bases for each type of anomaly detection rule, the reasonable range of normal behavior in the time dimension is clearly distinguished, avoiding reliance on empirical or vague standards for anomaly judgment. The anomaly detection process has a clear time reference, laying the foundation for the subsequent quantitative calculation of the degree of deviation of abnormal behavior and improving the objectivity and consistency of anomaly analysis. By comparing the occurrence time of abnormal behavior with the reference time range of normal behavior, it is possible to accurately characterize whether the abnormal behavior occurs early, late, or exceeds the reasonable time interval, thus providing a quantitative basis for anomaly cause analysis. The calculation of time offset transforms anomaly analysis from qualitative description to quantitative evaluation, helping the system to make fine distinctions under different anomaly scenarios and improving the accuracy and interpretability of anomaly detection results. By integrating the anomaly detection rule identifier with the corresponding time offset, the anomaly cause explanation data can simultaneously reflect the anomaly triggering rule and the degree of anomaly deviation, providing clear and complete explanatory information for anomaly detection results. By generating structured anomaly cause explanation data, reliable data support is provided for subsequent anomaly evidence chain construction, anomaly review, and management decisions, significantly improving the practicality and credibility of the anomaly detection solution in on-site assessment management.

[0102] The steps of associating the anomaly cause explanation data with the corresponding check-in events to construct an anomaly evidence chain arranged in chronological order, and generating and storing anomaly detection results by combining the anomaly judgment results, anomaly cause explanation data, and anomaly evidence chain for use in on-site assessment management are as follows:

[0103] The abnormality cause explanation data is associated with the corresponding abnormality judgment results to determine the set of check-in events that trigger the abnormality judgment;

[0104] The time information of each check-in event in the set of check-in events is uniformly aligned, and a corresponding evidence node is constructed for each check-in event based on the aligned time information.

[0105] The evidence nodes are sorted in chronological order, and the evidence nodes are sequentially associated according to the sorting results to construct an abnormal evidence chain that represents the order of occurrence and evolution of abnormal behavior.

[0106] The anomaly determination results, anomaly cause explanation data, and anomaly evidence chain are integrated to generate an anomaly detection result containing anomaly type information, anomaly formation cause information, and anomaly evidence chain information. The anomaly detection result is stored for on-site evaluation management.

[0107] In practical applications, by correlating and analyzing the data explaining the causes of anomalies with the results of anomaly determinations, it is possible to accurately identify which check-in events directly or indirectly led to the anomaly determinations, preventing anomaly analysis from remaining merely at the level of abstract rules. By clearly defining the set of check-in events associated with anomalies, a clear event foundation is provided for subsequent evidence node construction and evidence chain generation, improving the targeting and traceability of anomaly analysis. By uniformly aligning the time information of check-in events, time deviations caused by differences in equipment, network latency, or inconsistent data collection timing are eliminated, ensuring the accuracy of subsequent evidence chain sequencing. By constructing evidence nodes containing time information, event attributes, and identity information, each anomaly-related check-in event possesses an independent and complete form of evidence expression, providing fundamental support for the evidentiary analysis of abnormal behavior. By chaining evidence nodes in chronological order, abnormal behavior is no longer an isolated event but is restored to a behavioral process with causal and temporal relationships. The anomaly evidence chain can intuitively reflect the occurrence sequence, duration, and changing trends of abnormal behavior, providing clear and verifiable evidence for anomaly review, responsibility determination, and management decisions, significantly enhancing the transparency and credibility of anomaly management. By comprehensively integrating the results of multi-source anomaly analysis, the anomaly detection results include not only the judgment conclusions but also the causes and complete evidence chains, forming structured and traceable anomaly management data. The system can continuously support real-time anomaly handling, post-event review, and audit traceability in the assessment site management, realizing the explainable, verifiable, and traceable management of abnormal behaviors at the assessment site, and effectively improving the standardization and intelligence level of assessment site management.

[0108] The above are all preferred embodiments of this application, and are not intended to limit the scope of protection of this application. Therefore, all equivalent changes made in accordance with the structure, shape and principle of this application should be covered within the scope of protection of this application.

Claims

1. An intelligent anomaly detection system for on-site management of testing, characterized in that, Includes the following steps: The check-in event generation module (1) collects the facial feature information of the evaluators when they enter or leave the venue and compares it with the pre-stored identity template to generate the corresponding check-in event. The rhythm anomaly determination module (2) obtains the project stage status of the evaluation project, parses the corresponding project rhythm parameters, and dynamically generates an anomaly determination threshold set for anomaly detection based on the project rhythm parameters. The behavior sequence construction module (3) aggregates multiple check-in events of the same evaluator under the same evaluation project according to the time sequence, and constructs the behavior sequence chain of the evaluator. The anomaly determination module (4) matches and analyzes the behavior time sequence chain with the preset anomaly detection rules based on the anomaly determination threshold set, and generates anomaly determination results; The anomaly cause explanation module (5) extracts the rule identifier that triggers the anomaly judgment and the corresponding time offset information based on the anomaly judgment result, and generates anomaly cause explanation data. The anomaly detection result module (6) associates the anomaly cause explanation data with the corresponding check-in event, constructs an anomaly evidence chain arranged in chronological order, and generates and stores the anomaly detection result by combining the anomaly judgment result, the anomaly cause explanation data and the anomaly evidence chain for on-site evaluation management.

2. The intelligent anomaly detection system for on-site management of testing according to claim 1, characterized in that, The check-in event generation module (1) collects the facial feature information of the evaluators and compares it with the pre-stored identity template to generate the corresponding check-in event when the evaluators enter or leave the venue. The specific steps are as follows: When the evaluators enter or leave the venue, their facial image data is collected, and the validity of the facial image data is verified to determine whether the facial image data meets the preset requirements for facial integrity and clarity. After the face image data passes the validity verification, face features are extracted from the face image data to generate corresponding face feature information; The facial feature information is compared with the pre-stored identity template to calculate the facial matching degree parameter, and the facial matching degree parameter is compared with the preset identity consistency threshold. Once the face matching parameter reaches the preset identity consistency threshold, it is determined that the evaluator has passed the identity verification and a corresponding check-in event is generated. The check-in event includes the evaluator's identity identifier, check-in timestamp, check-in type, and evaluation item identifier.

3. The intelligent anomaly detection system for on-site management of testing according to claim 2, characterized in that, The rhythm anomaly determination module (2) acquires the project stage status of the evaluation project, parses the corresponding project rhythm parameters, and dynamically generates an anomaly determination threshold set for anomaly detection based on the project rhythm parameters. Specifically, the steps are as follows: Based on the evaluation item identifier in the check-in event, the project stage status of the corresponding evaluation item is obtained, the validity of the project stage status is verified, and it is confirmed that the project stage status is within the preset valid evaluation period. Based on the project stage status, the stage rhythm mapping rule corresponding to the project stage status is invoked to parse the project stage status and obtain the project rhythm parameters that characterize the time characteristics of the project stage. Obtain preset anomaly judgment benchmark parameters, dynamically adjust the anomaly judgment benchmark parameters based on the project rhythm parameters, and generate anomaly judgment threshold set for anomaly detection based on the adjusted anomaly judgment benchmark parameters.

4. The intelligent anomaly detection system for on-site management of testing according to claim 3, characterized in that, The steps of obtaining preset anomaly judgment benchmark parameters, dynamically adjusting the anomaly judgment benchmark parameters based on the project rhythm parameters, and generating anomaly judgment threshold set for anomaly detection based on the adjusted anomaly judgment benchmark parameters are as follows: Obtain preset anomaly judgment benchmark parameters, which are used to characterize the basic time deviation range and anomaly judgment sensitivity of the evaluation personnel's check-in behavior; Extract the project rhythm parameters corresponding to the project stage status, map the project rhythm parameters, and generate parameter adjustment factors; Based on the parameter adjustment factor, the anomaly judgment benchmark parameter is dynamically adjusted to obtain the adjusted anomaly judgment parameter that matches the project stage status. Based on the adjusted anomaly detection parameters, an anomaly detection threshold set is generated. The validity of the anomaly detection threshold set is then verified to confirm that the anomaly detection threshold set is within a preset reasonable parameter range.

5. The intelligent anomaly detection system for on-site management of testing according to claim 2, characterized in that, The behavior sequence construction module (3) aggregates multiple check-in events of the same assessor under the same assessment project according to the time sequence to construct the behavior sequence chain of the assessor. The specific steps are as follows: Based on the evaluator's identity and the evaluation item's identifier, the generated check-in events are filtered to obtain a set of check-in events for the same evaluator under the same evaluation item; Perform an integrity check on each check-in event in the set of check-in events to confirm that each check-in event contains a valid check-in timestamp; According to the check-in timestamp, the check-in events that have passed the integrity check are sorted in chronological order, and the sorted check-in events are labeled with event type according to the check-in type to obtain the check-in event type. The check-in event type includes entry check-in event and exit check-in event. Perform correlation analysis on adjacent check-in events, calculate the time interval between adjacent check-in events, and obtain the time interval between adjacent events; The check-in event type, check-in timestamp, and time interval between adjacent events are encapsulated as time sequence nodes, and the time sequence nodes are connected in chronological order to generate the behavior time sequence chain of the evaluator.

6. The intelligent anomaly detection system for on-site management of testing according to claim 5, characterized in that, The anomaly determination module (4), based on the anomaly determination threshold set, performs matching analysis between the behavior time sequence chain and preset anomaly detection rules to generate anomaly determination results, specifically includes the following steps: Retrieve the preset anomaly detection rules corresponding to the current evaluation item, and map and associate the anomaly detection rules with each anomaly judgment threshold in the anomaly judgment threshold set; Based on the behavioral temporal sequence, behavioral feature parameters for anomaly detection are extracted. Matching analysis is performed on each behavioral feature parameter according to the anomaly detection rules, and it is determined whether the behavioral feature parameter exceeds the corresponding anomaly judgment threshold in the anomaly judgment threshold set. When the behavioral feature parameters exceed the corresponding anomaly determination threshold, an abnormal behavior is determined to exist. The anomaly detection rule identifier that triggered the anomaly and the corresponding behavioral feature parameters are recorded, and an anomaly determination result containing anomaly triggering rule information is generated.

7. The intelligent anomaly detection system for on-site management of testing according to claim 1, characterized in that, The anomaly cause explanation module (5), based on the anomaly determination result, extracts the rule identifier that triggered the anomaly determination and the corresponding time offset information, and generates anomaly cause explanation data, specifically as follows: Based on the anomaly determination result, the anomaly detection rule identifier that triggered the anomaly determination is extracted, the behavior feature parameter type corresponding to the anomaly detection rule identifier is determined, and the occurrence time of the abnormal behavior that matches the behavior feature parameter type is retrieved from the behavior time sequence chain. Obtain the standard time reference information associated with the anomaly detection rule identifier, calculate the time offset between the anomaly event and the standard time reference information, and generate anomaly cause explanation data.

8. The intelligent anomaly detection system for on-site management of testing according to claim 7, characterized in that, The steps of obtaining the standard time reference information associated with the anomaly detection rule identifier, calculating the time offset between the abnormal behavior event and the standard time reference information, and generating anomaly cause explanation data are as follows: Obtain the standard time reference information associated with the anomaly detection rule identifier, wherein the standard time reference information is used to represent the reference time range that the behavioral characteristic parameters should meet under normal circumstances; Based on the abnormal behavior occurrence time information and the standard time reference information, calculate the time offset of the abnormal behavior occurrence time relative to the standard time reference; The anomaly detection rule identifier is associated and integrated with the time offset to generate anomaly cause explanation data that characterizes the cause of anomalies.

9. The intelligent anomaly detection system for on-site management of testing according to claim 6, characterized in that, The anomaly detection result module (6) associates the anomaly cause explanation data with the corresponding check-in event, constructs an anomaly evidence chain arranged in chronological order, and generates and stores anomaly detection results by combining the anomaly judgment result, anomaly cause explanation data, and anomaly evidence chain for use in on-site assessment management. The specific steps are as follows: The abnormality cause explanation data is associated with the corresponding abnormality judgment results to determine the set of check-in events that trigger the abnormality judgment; The time information of each check-in event in the set of check-in events is uniformly aligned, and a corresponding evidence node is constructed for each check-in event based on the aligned time information. The evidence nodes are sorted in chronological order, and the evidence nodes are sequentially associated according to the sorting results to construct an abnormal evidence chain that represents the order of occurrence and evolution of abnormal behavior. The anomaly determination results, anomaly cause explanation data, and anomaly evidence chain are integrated to generate an anomaly detection result containing anomaly type information, anomaly formation cause information, and anomaly evidence chain information. The anomaly detection result is stored for on-site evaluation management.