A security method and system for urban high-rise building physical examination unmanned aerial vehicle

By employing Kalman filtering algorithm and dual-decision mechanism for fault diagnosis, combined with dual-level protection and redundancy design, the safety and fault tolerance issues of UAVs in urban high-rise building inspection tasks are resolved, achieving efficient fault identification and emergency response, and improving the safety and reliability of UAVs in complex environments.

CN122284423APending Publication Date: 2026-06-26BEIJING SINO-CAN TECHNOLOGY LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING SINO-CAN TECHNOLOGY LTD
Filing Date
2026-03-24
Publication Date
2026-06-26

AI Technical Summary

Technical Problem

Existing drones used in urban high-rise building structural health monitoring tasks suffer from problems such as insufficient redundancy in power and flight control systems, limited emergency protection measures, lack of passive safety protection for ground personnel, and insufficient mobility, resulting in poor safety and fault tolerance.

Method used

By employing the Kalman filter algorithm to fuse flight parameters and combining a dual judgment mechanism of threshold and trend analysis, a fault level classification emergency handling system is achieved. This system integrates structural innovation, fault prevention, intelligent decision-making, and ultimate protection, constructing a full-chain safety system through dual-level protection measures and redundant design.

Benefits of technology

It improves the safety performance of drones in high-rise building inspection tasks, ensures the accuracy of fault identification and the timeliness of emergency response, reduces the risk of crashes and secondary injuries to ground personnel, and is suitable for urban operating environments with dense high-rise buildings and turbulent airflow.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122284423A_ABST
    Figure CN122284423A_ABST
Patent Text Reader

Abstract

This invention provides a safety assurance method and system for unmanned aerial vehicles (UAVs) used for medical examinations of high-rise buildings in cities. The method includes: continuously monitoring the flight parameters of the UAV, sampling the flight parameter data at a frequency of ≥100Hz, and performing fusion processing using a Kalman filter algorithm; employing a fault diagnosis algorithm, based on a dual judgment mechanism of threshold and trend analysis, to analyze the collected flight parameter data in real time; comparing power redundancy and attitude stability indicators with preset thresholds to determine the fault level, and performing graded emergency handling according to the fault level, triggering corresponding handling and response strategies for non-catastrophic or catastrophic faults; after the UAV lands, confirming the safety of the landing point through visual SLAM or GPS positioning, and initiating onboard communication to report the status. This invention provides a complete solution from fault prevention to collision buffering through redundant design, graded emergency response, and dual-level protection, maximizing the protection effect and facilitating industrial implementation and verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of unmanned aerial vehicle (UAV) safety protection technology, and in particular, to safety assurance technology for UAVs performing structural health monitoring tasks in complex urban environments; and to a safety assurance method and system for UAVs used for medical examinations of urban high-rise buildings. Background Technology

[0002] The application of drones in the field of structural health monitoring of urban high-rise buildings (commonly known as "building checkups") is becoming increasingly widespread. Such tasks require drones to be equipped with sophisticated testing equipment and to operate in airspace with dense buildings and frequent human activity, which places extremely high demands on safety.

[0003] However, existing security solutions for drones have the following systemic flaws: First, the redundancy design of the power and flight control systems is often insufficient, and a single point of failure can easily lead to overall loss of control. Secondly, the emergency protection measures are limited, with most solutions only equipped with parachutes. However, in the event of a low-altitude malfunction, the parachutes cannot function effectively due to insufficient deployment altitude, and the rotating rotors generate downwash airflow, which seriously interferes with the normal deployment and operation of the parachutes. More importantly, existing solutions generally lack passive safety protection for ground personnel (such as impact cushioning), and the consequences of a crash would be unimaginable. Finally, the emergency response procedures lack an intelligent tiered assessment mechanism, making it impossible to accurately trigger corresponding response strategies based on the severity of the fault.

[0004] Meanwhile, existing multi-rotor drones (such as quadcopters, hexacopters, and octocopters) have inherent limitations in their structural design. All engines provide only vertical upward thrust, with no horizontal power output. When flying forward or avoiding obstacles, they must generate horizontal propulsion by tilting the fuselage, resulting in low maneuverability and weak overload capacity. The normal overload of ordinary multi-rotor drones is typically only 1. In densely populated urban environments with tall buildings, their insufficient maneuverability makes it difficult to quickly escape dangerous areas, further amplifying operational safety risks. Summary of the Invention

[0005] Therefore, the purpose of this invention is to propose a safety assurance method and system for urban high-rise building medical examination drones, specifically for high-rise building medical examination drone operations. This method continuously monitors the drone's flight parameters, samples the flight parameter data, and fuses it using a Kalman filter algorithm. Based on a dual judgment mechanism of threshold and trend analysis, it performs real-time analysis of the collected flight parameter data and implements graded emergency handling according to fault levels. The system integrates structural innovation, fault prevention, intelligent decision-making, and ultimate protection. Through the collaborative work of four levels—structural optimization, reliability assurance, intelligent decision-making, and ultimate protection—a full-chain safety system is constructed to address the insufficient safety protection and poor fault tolerance of existing drones in urban operations, achieving the design goal of failure safety and improving the safety assurance performance of urban high-rise building medical examination drones.

[0006] This invention provides a safety assurance method for unmanned aerial vehicles (UAVs) used for medical examinations in high-rise buildings in cities, comprising the following steps: S1. Continuously monitor the flight parameters of the UAV, including acceleration, altitude, attitude angle, battery voltage and motor speed. Sample the flight parameter data at a frequency of ≥100Hz and perform fusion processing through Kalman filtering algorithm. It collects multi-dimensional flight parameters such as acceleration, altitude, attitude, battery, and motor speed at a high frequency of ≥100Hz, and performs data fusion through Kalman filtering algorithm, which greatly reduces noise interference and measurement error. It can reflect the real-time flight status of UAV in a true and stable manner, and provide a reliable data foundation for safety judgment in complex environments such as high-rise buildings.

[0007] S2. A fault diagnosis algorithm is adopted, based on a dual judgment mechanism of threshold and trend analysis, to perform real-time analysis on the collected flight parameter data; the key indicators of power redundancy and attitude stability are compared with preset thresholds to determine the fault level: the fault level includes: non-catastrophic fault and catastrophic fault. The dual fault diagnosis mechanism of threshold judgment + trend analysis can quickly identify sudden severe faults and capture gradual potential faults. Compared with single threshold judgment, it can detect hidden dangers earlier, has fewer false triggers, and is more adaptable to the complex airflow and electromagnetic environment of urban buildings.

[0008] S3. Implement graded emergency response based on the fault level, triggering the corresponding response strategies for non-catastrophic or catastrophic faults. Faults are classified into non-catastrophic and catastrophic faults, and a tiered response strategy is implemented. Non-catastrophic faults can be prioritized to ensure the mission is maintained and the situation is stabilized. Catastrophic faults should be immediately addressed with the highest priority safety measures (such as forced landing, obstacle avoidance, and cutting off dangerous outputs). This approach avoids minor faults from directly interrupting the building inspection mission and maximizes the safety of personnel, buildings, and equipment in the event of major risks.

[0009] S4. After the drone lands, it confirms the safety of the landing point through visual SLAM or GPS positioning and initiates onboard communication to report the status.

[0010] After landing, the system actively confirms the safety of the landing point through visual SLAM or GPS positioning, avoiding landing in dangerous areas such as rooftops, narrow passages, and densely populated areas. At the same time, it reports the status in real time through airborne communication, realizing a closed-loop safety process of flight-failure-emergency-landing-reporting, meeting the high safety and compliance requirements of urban high-rise building inspection operations.

[0011] The entire method of this invention is designed for medical examination scenarios in urban high-rise buildings with dense high-rise buildings, turbulent airflow, easily blocked signals, and high risk of crashes. It has controllable computational load, strong real-time performance, and is easy to deploy on airborne embedded platforms, which can significantly improve the survivability and mission reliability of UAVs in high-risk operating environments.

[0012] Furthermore, the fault diagnosis algorithm employed in step S2, based on a dual-judgment mechanism of threshold and trend analysis, includes the following method for real-time analysis of the collected flight parameter data: real-time calculation of key indicators of power redundancy and attitude stability, and comparison with preset thresholds; the preset thresholds include a first threshold and a second threshold corresponding to non-catastrophic faults and catastrophic faults, respectively; when the indicators deviate from the normal range, the fault level is determined, triggering graded responses for non-catastrophic and catastrophic faults, and the method for determining the fault level includes: The remaining power capacity is calculated based on the drone's motor speed and battery voltage data; flight stability is assessed by attitude angle deviation and angular velocity based on the drone's flight altitude / speed and attitude angle data. Specifically, when the attitude angle deviation is >15° and lasts for >200ms, it is judged as a slight anomaly; when the power output decreases by >30% and the descent rate is >2m / s, it is judged as a moderate anomaly. When the indicator falls below the first threshold, an alarm is triggered and the system automatically switches to the backup redundant unit. When the indicator falls below the second threshold and the duration exceeds the set value, it is determined to be a catastrophic failure, and the dual-level protection device is immediately activated. When it is determined to be a non-catastrophic failure, the system executes commands for automatic return to home, forced landing in a safe area, or hovering and waiting. The motor speed is adjusted through PID control to achieve attitude correction. When it is determined to be a catastrophic failure, the dual-level protection device is directly triggered, and the parachute system and emergency airbag are activated simultaneously. At the same time, the rotor release mechanism separates the rotor to eliminate interference.

[0013] This invention clearly defines the calculation basis for power redundancy and attitude stability. Power redundancy is calculated based on motor speed and battery voltage to determine remaining power capacity, while attitude stability is based on flight altitude / speed and attitude angle data. It avoids abstract indicator definitions by evaluating attitude angle deviation and angular velocity. At the same time, it provides clear quantitative judgment criteria (attitude angle deviation >15° and lasting >200ms is considered mild anomaly, and power output decrease >30% and descent rate >2m / s is considered moderate anomaly), so that fault identification has clear basis, avoids ambiguous judgment, reduces the probability of misjudgment and missed judgment, and is suitable for the high-precision and high-reliability fault monitoring needs in the inspection of high-rise buildings.

[0014] By pre-setting first and second thresholds for non-catastrophic and catastrophic faults, and combining these with gradient judgments for minor and moderate anomalies, a refined classification of fault levels is achieved, rather than a single fault definition. This grading method aligns with the risk gradient of actual drone flight, progressively escalating the judgment criteria from minor attitude deviations and power loss to severe power deficiency and uncontrolled descent. This approach avoids over-treating minor faults or delaying the handling of major faults, balancing the sensitivity and rationality of fault identification.

[0015] The combination of threshold judgment and trend analysis can quickly capture sudden faults (such as a sudden drop in power output or a sharp deviation in attitude angle) by comparing thresholds (first and second thresholds) to achieve rapid response. On the other hand, trend analysis (the duration and trend of indicators deviating from the normal range) can capture gradual hidden dangers (such as a slow drop in battery voltage or a continuous increase in attitude angle deviation) to identify potential faults in advance and prevent faults from escalating into catastrophic risks. It is especially suitable for various gradual and sudden fault scenarios caused by airflow turbulence and signal interference in the inspection of urban high-rise buildings.

[0016] Differentiated response strategies are developed for different fault levels and anomaly severity to achieve precise handling and tiered protection. For non-catastrophic faults (indicators below the first threshold, mild / moderate anomalies), alarms are triggered, backup redundant units are switched, PID attitude correction is performed, or return to home, hovering, or safe emergency landing is executed to prioritize mission continuity and avoid interrupting building inspection operations due to minor faults. At the same time, attitude correction and backup unit switching reduce the risk of further escalation of faults. For catastrophic faults (indicators below the second threshold and continuously exceeding the timeout), dual-level protection (parachute, emergency airbag) is immediately activated and rotor decoupling is performed to minimize the risk of drone crash damage and prevent secondary injuries to high-rise buildings and ground personnel caused by crashed drones. This approach is suitable for operation scenarios with dense urban high-rise buildings and high population mobility.

[0017] The entire fault diagnosis and response process forms a closed loop: real-time calculation of indicators → comparison with thresholds → determination of anomaly / fault level → triggering corresponding actions. It is based on real-time collected flight parameters for analysis, with no significant response delay. At the same time, operations such as PID attitude correction, backup unit switching, and dual-level protection activation are all airborne instructions that can be executed quickly. The computational load is controllable and adaptable to the real-time processing capabilities of the UAV's airborne embedded platform. It does not rely on ground remote control, which improves the independence and reliability of fault handling and avoids delays caused by signal obstruction from tall buildings.

[0018] The system features dual-level protection (parachute and emergency airbag) for catastrophic failures, along with a rotor release mechanism. This not only addresses the issue of buffer protection during drone crashes but also eliminates secondary interference caused by rotor rotation during crashes (such as scratching buildings or injuring people) by separating the rotors. Compared to single protective measures, this provides more comprehensive protection and further reduces the safety risk of drone crashes during inspections of high-rise buildings in cities, meeting the safety and compliance requirements for high-altitude operations.

[0019] Furthermore, the fault diagnosis algorithm includes: battery voltage fault diagnosis and determination, motor speed fault diagnosis and determination, attitude angle threshold diagnosis and determination, intermediate trend diagnosis and determination, and advanced model diagnosis and determination. The method for diagnosing and determining battery voltage faults includes: real-time monitoring of battery voltage; when the battery voltage exceeds a threshold range, determining a battery voltage fault and outputting a speed reduction and battery warning command; specifically, the formula for diagnosing and determining battery voltage faults is: ; in, Let t be the real-time output voltage (V) of the drone battery at time t. This is the minimum operating voltage threshold for the battery (determined by the battery model, such as Vmin=3.2V for a single lithium polymer battery cell). This is the maximum operating voltage threshold of the battery (e.g., Vmax = 4.2V for a single lithium polymer battery cell). When the real-time output voltage exceeds [ , If the voltage is within the specified range, it is determined to be a battery voltage fault (Level II), and a speed reduction + battery warning command is immediately output; The method for diagnosing and determining motor speed faults includes: real-time monitoring of motor speed; when the difference between the real-time speed of one motor in the UAV and the average speed of the multiple motors in the UAV exceeds a speed deviation threshold, the motor speed is determined to be abnormal, and hovering and power system fault warning commands are output; specifically, the formula for diagnosing and determining motor speed faults is: ; in, for t Time of the firsti The real-time rotational speed (r / min) of each motor for a quadcopter drone, i =1,2,3,4; for t The average speed (r / min) of the four motors at any given time. ; The motor speed deviation threshold is set according to the UAV power system calibration, such as 15% of the average speed. When the deviation of a single motor speed from the average speed exceeds the threshold, it is judged as abnormal motor speed (Level III), and the hover + power system fault warning command is immediately output. The method for diagnosing and determining the attitude angle threshold includes: real-time monitoring of the UAV's attitude angles; when any of the pitch, roll, or yaw angles exceeds the corresponding maximum safety threshold, an attitude control failure (Level IV) is determined, and an emergency return-to-home or forced landing command is output. Specifically, the attitude angle threshold diagnosis and determination formula is: ; in, θ ( t ), , ψ ( t They are respectively t The pitch angle, roll angle, and yaw angle (°) of the UAV at all times; θ max , , ψ max These are the maximum safety thresholds for pitch angle, roll angle, and yaw angle (in the case of high-rise building inspection, the pitch angle / roll angle is set to ≤30° and the yaw angle to ≤±180°).

[0020] This invention's fault diagnosis algorithm covers the three key systems for UAV flight safety: the power system (battery voltage, motor speed) and the attitude control system (attitude angle). It also supplements these with intermediate trend and advanced model-based judgment methods, forming a multi-level diagnostic system of basic threshold judgment + trend prediction + advanced verification. This system covers common basic faults such as battery undervoltage / overvoltage, motor speed imbalance, and attitude control failure, while also capturing potential gradual and complex faults through trend diagnosis and advanced model diagnosis. This avoids missed faults caused by single-dimensional monitoring, comprehensively ensuring the flight safety of UAVs in high-rise building inspections.

[0021] Furthermore, the method for determining the intermediate trend diagnosis includes: For drone parameters exhibiting gradual anomalies (such as a slow decrease in battery voltage or continuous fluctuations in motor speed), linear trend fitting is used to calculate the rate of change of parameters, predict potential faults, and issue early warnings. Least squares is used to linearly fit time-series parameters; when the rate of change of voltage is below a preset threshold (e.g., voltage change rate...),... k If the predicted remaining voltage reaches the battery's minimum operating voltage threshold (Vmin) in a time less than -0.01V / s and the time it takes for the remaining voltage to reach this threshold is less than a preset threshold (e.g., T < 60s), a potential low battery fault is identified, and a return-to-home warning command is output; if the motor speed change rate is greater than a preset threshold (e.g., | k If the speed exceeds 5r / (min·s) and the duration exceeds the preset time (e.g., 3s), a potential motor wear fault is determined, and a speed reduction and motor maintenance warning command is output.

[0022] Specifically, the least squares method is used to analyze the time series parameters. Perform a linear fit, and the fitting formula is: ; Among them, slope k is the rate of change of the parameter, such as the rate of change of voltage (V / s) or the rate of change of rotational speed (r / (min·s)); b is the intercept of the linear fit. k The calculation formula is: ; in, n The number of time series data points to fit (e.g., set to 50, corresponding to 5 seconds of sampling data); ti For the first i Sampling time (s) for each data point; xi For the parameter value of the i-th data point (such as battery voltage, motor speed); When the rate of change of voltage k If the voltage drops continuously to -0.01V / s and the predicted time for the remaining voltage to reach Vmin is T<60s, it is determined to be a potential low battery fault (Level I), and a return-to-home warning command is output. When the rate of change of motor speed | k If the speed fluctuates continuously for more than 3 seconds, it is determined to be a potential motor wear fault (Level II), and a speed reduction and motor maintenance warning command will be output.

[0023] This invention's intermediate trend diagnosis and judgment method overcomes the limitation of basic threshold judgment, which can only identify established faults. It is specifically designed for gradual anomalies such as slow battery voltage decline and gradual motor speed deviation. By fitting time series parameters using the least squares method, it quantifies the rate of parameter change and predicts development trends. Compared to the traditional mode that only alarms when a threshold is reached, it can identify potential faults such as low battery power and motor wear in advance, shifting the fault handling point from after the fault occurs to the nascent stage of the problem. This fundamentally prevents gradual faults from escalating into non-catastrophic or even catastrophic faults, significantly improving the foresight of UAV flight safety.

[0024] Furthermore, the advanced model diagnostic judgment method includes: For complex faults such as perception module failure and obstacle avoidance system malfunction, a support vector machine classification model is used to achieve accurate fault classification. Twelve features are selected to form the feature vector: mean, variance, bias, mean-bias ratio, variance change rate, bias change rate, visual ranging error, lidar ranging error, obstacle avoidance response time, flight speed variance, altitude change rate, and motor current variance. x Feature vectors from four states of the UAV—normal operation, visual module failure, LiDAR failure, and obstacle avoidance system malfunction—were collected to construct a labeled training set, which was then used with a radial basis function kernel. The kernel parameter γ was determined through cross-validation. x i , x j The Support Vector Machine (SVM) classification model is trained using the feature vectors in the training set. The real-time feature vectors are input into the trained SVM model, which outputs the corresponding fault type, determining it as a perception or obstacle avoidance fault, and outputting commands to switch to a backup perception module or to hover or decelerate. Specifically, this includes the following steps: a. Fault Feature Vector Construction: Twelve features are selected to form a feature vector: mean, variance, deviation, mean-deviation, variance change rate, deviation change rate, visual ranging error, lidar ranging error, obstacle avoidance response time, flight speed variance, altitude change rate, and motor current variance. x ; b. Collect feature vectors under four states of the UAV: ​​normal state, vision module failure, lidar failure, and obstacle avoidance system malfunction. Construct a labeled dataset as a training set and train the SVM model for fault classification. c. Input the feature vector extracted in real time into the trained SVM model, output the fault type (normal / vision module failure / LiDAR failure / obstacle avoidance system abnormality), and determine the corresponding perception or obstacle avoidance fault (Level II-III), and output the corresponding command to switch to the backup perception module or hover / decelerate.

[0025] The advanced model diagnostic judgment method of this invention is specifically designed for complex and compound faults such as perception module failure and obstacle avoidance system anomaly. Such faults cannot be identified by basic threshold judgment (single parameter exceeding the standard) or intermediate trend diagnosis (linear gradual change). However, the support vector machine classification model has a powerful ability to recognize complex patterns and can accurately distinguish between four states: normal, vision module failure, lidar failure, and obstacle avoidance system anomaly. It completely solves the technical pain points of difficult identification of complex faults and high misjudgment rate, and fills the gap in complex fault identification in the three-level diagnostic system.

[0026] Twelve core features, including mean, variance, and bias, are selected to form the feature vector. x It covers three dimensions of UAV perception, obstacle avoidance, and flight status, including statistical characteristics of flight parameters (such as flight speed variance and altitude change rate), error characteristics of perception modules (such as visual ranging error and lidar ranging error), and response characteristics of the obstacle avoidance system (such as obstacle avoidance response time). This multi-dimensional feature collaboration comprehensively captures the characteristic differences of complex faults, avoiding missed or false positives caused by single features, ensuring the accuracy of fault classification, and making it suitable for scenarios with high obstacle avoidance requirements, such as the inspection of high-rise buildings.

[0027] Furthermore, the method for fusion processing using the Kalman filter algorithm in step S1 includes: A 12-dimensional state vector of the UAV is selected, which includes three-dimensional position, three-dimensional velocity, pitch angle, roll angle, yaw angle and corresponding angular velocity in the geodetic coordinate system. Nonlinear state equations and observation equations are established, and prediction and updating are performed after linearization by first-order Taylor expansion. Construct the initial state vector and covariance matrix at takeoff time, predict the current prior state and prior covariance based on the posterior state at the previous time, and solve the state transition Jacobian matrix; calculate the observation matrix, residuals and residual covariance to obtain the Kalman gain; update the posterior state estimate and posterior covariance matrix accordingly. The optimal posterior state estimate obtained after fusion, including position, velocity, attitude angle and angular velocity, is used as the input parameters of the fault diagnosis algorithm and the fusion result is output.

[0028] Specifically, the position, velocity, attitude angle, and angular velocity of the UAV are selected as the state vector. The state vector has 12 dimensions and is expressed as follows: ; in, x , y , z It is the three-dimensional position (m) of the UAV in the geodetic coordinate system. It is the three-dimensional velocity of the drone (m / s); These are the pitch rate, roll rate, and yaw rate of the UAV (rad / s). θ , , ψ These are the drone's pitch angle, roll angle, and yaw angle (rad). The state update of the UAV is determined by the kinematic model, and the state equation (nonlinear) is: ; in, It is a nonlinear state transition function (derived from the dynamic equations of the quadcopter UAV). yes k Control input at time -1 (motor speed, r / min); It is process noise (following a Gaussian distribution with mean 0 and covariance Qk-1); the relationship between the sensor measurements and the UAV state vector is: ; in, h (·) is a nonlinear observation function (such as GPS measuring position x, y, z, IMU measuring angular velocity). ); yes k Sensor observations at any given time (measurement vector after multi-sensor fusion); It is the observation noise (following a mean of 0 and a covariance of ). R k Gaussian distribution); The nonlinear system is converted to linearity through a first-order Taylor expansion, and then state estimation is performed according to the prediction → update steps of the standard Kalman filter, including: At the time of drone takeoff ( k =0), initialize the state vector and covariance matrix: ; in, It is the initial state estimate (determined by calibration data before the UAV takes off, such as the position being the coordinates of the takeoff point, and the velocity and angular velocity being 0); It is the initial covariance matrix (representing the uncertainty of the initial state estimate, set as a diagonal matrix, with diagonal elements being the initial variances of each state variable); according to k State estimate at time -1, prediction k The prior state and prior covariance at time t, the prediction expression for the prior state is: ;in, for k The prior state estimate at time t; Calculate the state transition matrix (linearization) for nonlinear state transition functions. exist Performing a first-order Taylor expansion at the given point yields the state transition matrix. : ;in: It is a 12×12 Jacobian matrix, describing the rate of change of the state vector; The prediction expression for the prior covariance is: ;in, for k The prior covariance matrix at time t; The process noise covariance matrix (based on sensor accuracy calibration, such as setting the angular velocity noise variance of an IMU to 0.01 rad² / s²). Calculate the observation matrix (linearization core) for nonlinear observation functions. h (·)exist Perform a first-order Taylor expansion at the point to obtain the observation matrix. : ;in, It is an m×12 Jacobian matrix (m is the dimension of the observation vector, such as m=9 when GPS+IMU is fused). Calculate the residuals: ;in, The residual between the observed value and the prior state prediction reflects the deviation between the prediction and the actual measurement. Calculate residual covariance: ;in, The residual covariance matrix; To observe the noise covariance matrix (based on sensor accuracy calibration, such as setting the GPS position measurement noise variance to 0.1m²). The Kalman gain is calculated by weighing the prior state estimate and the observations, using the following formula: ;in: Given a 12×m Kalman gain matrix, if the observation noise is small: Small, then Larger values ​​have higher weights; if the process noise is small: Small, then Smaller values ​​result in higher weighting for prior state estimation; Update based on Kalman gain and residual. k The posterior state estimate and posterior covariance matrix at time t are used to obtain the final fused estimate: The expression for estimating the posterior state (fusion result) is: ; In the formula, for k The optimal state estimate at a given time is the flight parameters (position, velocity, attitude angle, angular velocity) after the fusion of multi-sensor parameters. The updated posterior covariance is expressed as follows: ;in, I It is a 12×12 identity matrix. for k The posterior covariance matrix at time t reflects the uncertainty of the fused state estimate; The posterior state estimate after fusing the extended Kalman filter algorithm The input parameters for the fault diagnosis algorithm include: Location: ,speed: Attitude angle: Angular velocity: The fused parameters eliminate the measurement noise of a single sensor, improving accuracy by more than 30%, and providing data assurance for the accuracy of fault diagnosis.

[0029] This invention also provides a safety assurance system for a medical examination drone used in urban high-rise buildings, which implements the safety assurance method for the medical examination drone used in urban high-rise buildings as described above. The system includes: a reliability assurance subsystem, which is configured with a power unit and a flight control unit connected to each other. The flight control unit is signal-connected to a graded emergency procedure module, which has a built-in fault diagnosis algorithm unit. The fault diagnosis algorithm unit is signal-connected to a sensor for monitoring the power redundancy and attitude stability indicators of the drone.

[0030] The reliability assurance subsystem, through a hard connection between the power unit and the flight control unit, combined with the soft logic of the tiered emergency response module, directly integrates sensor monitoring, fault diagnosis algorithms, and the power actuators. Compared to traditional UAVs that rely solely on a single flight control unit for obstacle avoidance, this system achieves a closed-loop end-to-end process: raw sensor data → Kalman filter fusion → fault diagnosis → tiered emergency response → power redundancy switching. Even in the complex electromagnetic interference and airflow disturbances of high-rise buildings, real-time monitoring of power redundancy and attitude stability indicators ensures that the UAV will not lose control and crash due to a single point of failure. This system-level solution addresses the challenges of high-risk operations in urban high-rise building health check scenarios.

[0031] Preferably, the tiered emergency procedure module also supports communication with the ground control station, supports manual intervention and takeover by the ground control station, and allows operators to manually take over and trigger emergency operations.

[0032] Furthermore, the power unit is driven by a dual-stage protection actuator, which is equipped with a parachute system, an emergency airbag system, and a rotor release mechanism. In the initial state, the parachute system and the emergency airbag system are installed inside the UAV. The rotor release mechanism is connected to the UAV's rotor via a detachable connector.

[0033] Specifically, the parachute system is responsible for mid-to-high altitude protection. Its triggering is based on precise sensor thresholds (height ≥ 60 meters and vertical descent speed ≥ 8 m / s). The specially designed canopy ensures rapid deployment within 3 seconds, enabling the drone to achieve a soft landing at a speed not exceeding 3 m / s. The rotor release mechanism is triggered in conjunction with the parachute system; at the moment the parachute deploys, all rotors are disengaged from the motor drive shaft through electromagnetic clutches and other means, and the rotors enter a free-rotating state; this completely eliminates the interference of the rotor downwash airflow on the parachute and significantly reduces the rotational kinetic energy of the falling object, reducing the risk of secondary injury. The emergency airbag system serves as supplementary protection at low altitudes (≥10 meters) and before ground impact. It is triggered by an altimeter, accelerometer, or contact sensor and is required to inflate rapidly within 0.8 seconds to form a buffer layer, ensuring that the impact acceleration of the falling drone on the ground simulating a human body does not exceed the safety limit of 20g.

[0034] The parachute system, emergency airbag system, and rotor release mechanism are designed in a coordinated manner to effectively solve protection problems in complex scenarios such as high and low altitudes and with or without rotor interference. The dual-level protection actuator integrates the parachute system and emergency airbag system as two major protective components, forming a layered protection closed loop of high-altitude deceleration and low-altitude buffering, which is suitable for high-altitude operations, dense buildings, and high-risk crash scenarios in high-rise building inspections. Compared to traditional drone protection schemes that rely on a single parachute, this design can flexibly trigger corresponding protective measures based on the fault level (determined by the fault diagnosis algorithm unit): When the drone experiences severe attitude instability, power failure, and is at a high altitude (≥10 meters above the ground), the power unit drives the parachute system to deploy, rapidly reducing the drone's descent speed and preventing equipment damage or casualties on the ground due to a high-speed crash; when the drone falls to a low altitude (<10 meters above the ground) or the parachute system fails to deploy properly, the emergency airbag system is triggered simultaneously. Through airbag inflation and cushioning, the impact of the fall is further absorbed, protecting not only the drone's onboard medical equipment (such as high-definition cameras and detection sensors) from damage, but also preventing the drone from crashing onto the exterior of high-rise buildings, windowsills, or other locations, thus avoiding secondary hazards. This achieves full-process protection under extreme fault scenarios, overcoming the limitations of traditional single-protection methods.

[0035] Furthermore, the power unit is equipped with multiple sets of batteries, multiple sets of motors, and multiple sets of electronic speed controllers with redundant design. The batteries are electrically connected to the motors, and the electronic speed controllers are electrically connected to the motors. The flight control unit is equipped with redundant backup inertial measurement units, global positioning system receivers, and main processors. The main processors are respectively connected to the batteries, electronic speed controllers, inertial measurement units, and global positioning system receivers.

[0036] In one embodiment of the invention, the system is implemented on a quadcopter (expandable to a hexacopter or octocopter) high-rise building inspection UAV. The redundant power unit of the reliability assurance subsystem uses four smart batteries and six brushless motors (providing power redundancy), and the redundant flight control unit uses two independent IMU and GPS modules.

[0037] Preferably, the inertial measurement unit is a six-axis IMU.

[0038] The redundant design of the power unit enables multiple backups and automatic switching of the battery, motor, and electronic speed controller, avoiding power failure caused by the failure of a single power component. This solves the technical defects of insufficient power reliability in traditional UAVs and provides stable power support for high-altitude operations such as physical examinations of high-rise buildings. The redundant backup of the flight control unit ensures the stable operation of the inertial measurement unit, GPS receiver, and main processor, avoiding attitude data distortion, positioning loss, or flight control paralysis caused by the failure of a single component. This improves the control accuracy and perception reliability of the UAV in complex environments and ensures the accuracy of physical examination operations. The full signal connection between the main processor and all components establishes a collaborative link between power redundancy and flight control redundancy, realizing automated linkage of fault monitoring, redundancy switching, and emergency response. This shortens response time and improves the system's emergency response efficiency and fault tolerance.

[0039] Furthermore, the parachute system is located at the center of the upper part of the drone fuselage. The parachute system is connected to a gunpowder launcher and deploys using a gunpowder ejection method. The emergency airbag system is folded and stored at the bottom of the drone fuselage and the ends of the four arms. The emergency airbag system is connected to a high-pressure nitrogen generator and inflated using the high-pressure nitrogen generator. The triggering conditions for the parachute system are: the drone's flight altitude is not less than 60 meters and the vertical descent speed continuously exceeds 8 meters per second; the time from triggering to full deployment is less than 3 seconds; and after deployment, the vertical landing speed of the entire drone is controlled to within 3 meters per second. The triggering conditions for the emergency airbag system are: the drone's flight altitude is not less than 10 meters; the time from triggering to full inflation is less than 0.8 seconds; and the maximum impact acceleration transmitted when the airbag touches a simulated human body does not exceed 20g. The rotor release mechanism is linked to the parachute system, causing all rotors to separate from the power unit simultaneously with the parachute trigger signal.

[0040] The rotor unhooking mechanism is equipped with an electromagnetic clutch, and the trigger signal of the electromagnetic clutch and the trigger signal of the parachute system originate from the same cascaded control circuit to ensure synchronized operation.

[0041] Preferably, the rotor unhooking mechanism adopts a normally closed electromagnetic clutch, which engages and transmits torque during normal flight, and disconnects when a trigger signal is received.

[0042] The flight control unit is also equipped with a laser altimeter and a barometric altimeter for real-time monitoring of flight status. It collects flight parameters such as UAV acceleration, altitude, and attitude in real time, and completes data fusion through Kalman filtering algorithm. The sampling frequency is ≥100Hz and the data transmission delay is <10ms.

[0043] The present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the safety assurance method for a medical examination drone for urban high-rise buildings as described above.

[0044] The present invention also provides a computer device, the computer device including a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the safety assurance method for medical examination drones for urban high-rise buildings as described above.

[0045] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention provides a safety assurance method and system for drones used in urban high-rise building health checks. For the first time, it systematically applies the fail-safe concept to urban drone operations. Through the organic combination of redundant design, tiered emergency response, and dual-level protection, it offers a complete solution from fault prevention to collision buffering. It proposes a collaborative protection mechanism involving a parachute-rotor decoupling-emergence airbag linkage, solving industry challenges related to high- and low-altitude protection integration and rotor interference through precise trigger timing control, thus maximizing the protective effect. Closely integrated with the actual operational scenario of high-rise building health checks, it effectively addresses the shortcomings in safety protection and poor fault tolerance of existing drones in urban operations. The technical parameters are clearly defined (such as altitude, speed, and acceleration thresholds), and the testing methods are clear, facilitating industrial implementation and verification, and possessing extremely high market promotion value. Attached Figure Description

[0046] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention.

[0047] In the attached diagram: Figure 1This is a block diagram of the triggering process of a safety assurance system for a medical examination drone used in urban high-rise buildings, according to an embodiment of the present invention. Figure 2 This is a schematic diagram of the linkage structure of the parachute-rotor unhooking mechanism according to an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of the emergency airbag after inflation according to an embodiment of the present invention; Figure 4 This is a schematic diagram illustrating a catastrophic failure protection scenario in which the parachute system and emergency airbag operate simultaneously, according to an embodiment of the present invention. Figure 5 This is a basic step diagram of the safety assurance method for a medical examination drone used in urban high-rise buildings according to an embodiment of the present invention; Figure 6 This is a flowchart of a safety assurance method for a medical examination drone used in urban high-rise buildings, according to an embodiment of the present invention. Figure 7 This is a schematic diagram of the configuration of a computer device according to an embodiment of the present invention. Detailed Implementation

[0048] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and products consistent with some aspects of this disclosure as detailed in the appended claims.

[0049] The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the disclosure. The singular forms “a,” “the,” and “the” as used in this disclosure and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.

[0050] It should be understood that although the terms first, second, third, etc., may be used in this disclosure to describe various information, such information should not be limited to these terms. These terms are used only to distinguish information of the same type from one another. For example, without departing from the scope of this disclosure, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."

[0051] The embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.

[0052] This invention provides a safety assurance method for unmanned aerial vehicles (UAVs) used for medical examinations in urban high-rise buildings. (See also...) Figure 6 As shown, it includes the following steps: S1. Continuously monitor the flight parameters of the UAV, including acceleration, altitude, attitude angle, battery voltage and motor speed. Sample the flight parameter data at a frequency of ≥100Hz and perform fusion processing through Kalman filtering algorithm. In this embodiment, a 12-dimensional state vector of the UAV is selected. The 12-dimensional state vector includes the three-dimensional position, three-dimensional velocity, pitch angle, roll angle, yaw angle and corresponding angular velocity in the geodetic coordinate system. Nonlinear state equations and observation equations are established, and prediction and updating are performed after linearization by first-order Taylor expansion. Construct the initial state vector and covariance matrix at takeoff time, predict the current prior state and prior covariance based on the posterior state at the previous time, and solve the state transition Jacobian matrix; calculate the observation matrix, residuals and residual covariance to obtain the Kalman gain; update the posterior state estimate and posterior covariance matrix accordingly. The optimal posterior state estimate obtained after fusion, including position, velocity, attitude angle and angular velocity, is used as the input parameters of the fault diagnosis algorithm and the fusion result is output.

[0053] The position, velocity, attitude angle, and angular velocity of the UAV are selected as the state vector. The state vector has 12 dimensions and is expressed as follows: ; in, x , y , z It is the three-dimensional position (m) of the UAV in the geodetic coordinate system. It is the three-dimensional velocity of the drone (m / s); These are the pitch rate, roll rate, and yaw rate of the UAV (rad / s). θ , , ψ These are the drone's pitch angle, roll angle, and yaw angle (rad). The state update of the UAV is determined by the kinematic model, and the state equation (nonlinear) is: ; in, It is a nonlinear state transition function (derived from the dynamic equations of the quadcopter UAV). yes k Control input at time -1 (motor speed, r / min); It is process noise (following a Gaussian distribution with mean 0 and covariance Qk-1); the relationship between the sensor measurements and the UAV state vector is: ; in, h (·) is a nonlinear observation function (such as GPS measuring position x, y, z, IMU measuring angular velocity). ); yes k Sensor observations at any given time (measurement vector after multi-sensor fusion); It is the observation noise (following a mean of 0 and a covariance of ). R k Gaussian distribution); The nonlinear system is converted to linearity through a first-order Taylor expansion, and then state estimation is performed according to the prediction → update steps of the standard Kalman filter, including: At the time of drone takeoff ( k =0), initialize the state vector and covariance matrix: ; in, It is the initial state estimate (determined by calibration data before the UAV takes off, such as the position being the coordinates of the takeoff point, and the velocity and angular velocity being 0); It is the initial covariance matrix (representing the uncertainty of the initial state estimate, set as a diagonal matrix, with diagonal elements being the initial variances of each state variable); according to k State estimate at time -1, prediction k The prior state and prior covariance at time t, the prediction expression for the prior state is: ;in, for k The prior state estimate at time t; Calculate the state transition matrix (linearization) for nonlinear state transition functions. exist Performing a first-order Taylor expansion at the given point yields the state transition matrix. : ;in: It is a 12×12 Jacobian matrix, describing the rate of change of the state vector; The prediction expression for the prior covariance is: ;in, for k The prior covariance matrix at time t; The process noise covariance matrix (based on sensor accuracy calibration, such as setting the angular velocity noise variance of an IMU to 0.01 rad² / s²). Calculate the observation matrix (linearization core) for nonlinear observation functions. h(·)exist Perform a first-order Taylor expansion at the point to obtain the observation matrix. : ;in, It is an m×12 Jacobian matrix (m is the dimension of the observation vector, such as m=9 when GPS+IMU is fused). Calculate the residuals: ;in, The residual between the observed value and the prior state prediction reflects the deviation between the prediction and the actual measurement. Calculate residual covariance: ;in, The residual covariance matrix; To observe the noise covariance matrix (based on sensor accuracy calibration, such as setting the GPS position measurement noise variance to 0.1m²). The Kalman gain is calculated by weighing the prior state estimate and the observations, using the following formula: ;in: Given a 12×m Kalman gain matrix, if the observation noise is small: Small, then Larger values ​​have higher weights; if the process noise is small: Small, then Smaller values ​​result in higher weighting for prior state estimation; Based on the Kalman gain and residuals, the posterior state estimate and posterior covariance matrix at time k are updated to obtain the final fused estimate: The expression for estimating the posterior state (fusion result) is: ; In the formula, for k The optimal state estimate at a given time is the flight parameters (position, velocity, attitude angle, angular velocity) after the fusion of multi-sensor parameters. The updated posterior covariance is expressed as follows: ;in, I It is a 12×12 identity matrix. for k The posterior covariance matrix at time t reflects the uncertainty of the fused state estimate; The posterior state estimate after fusing the extended Kalman filter algorithm The input parameters for the fault diagnosis algorithm include: Location: ,speed: Attitude angle: Angular velocity: The fused parameters eliminate the measurement noise of a single sensor, improving accuracy by more than 30%, and providing data assurance for the accuracy of fault diagnosis.

[0054] S2. A fault diagnosis algorithm is adopted, based on a dual judgment mechanism of threshold and trend analysis, to perform real-time analysis on the collected flight parameter data; the key indicators of power redundancy and attitude stability are compared with preset thresholds to determine the fault level: the fault level includes: non-catastrophic fault and catastrophic fault. Real-time calculation of key indicators of dynamic redundancy and attitude stability is performed and compared with preset thresholds. These preset thresholds include a first threshold and a second threshold corresponding to non-catastrophic and catastrophic failures, respectively. When an indicator deviates from the normal range, the fault level is determined, triggering a graded response for non-catastrophic and catastrophic failures. The method for determining the fault level includes: The remaining power capacity is calculated based on the drone's motor speed and battery voltage data; flight stability is assessed by attitude angle deviation and angular velocity based on the drone's flight altitude / speed and attitude angle data. Specifically, when the attitude angle deviation is >15° and lasts for >200ms, it is judged as a slight anomaly; when the power output decreases by >30% and the descent rate is >2m / s, it is judged as a moderate anomaly. When the indicator falls below the first threshold, an alarm is triggered and the system automatically switches to the backup redundant unit. When the indicator falls below the second threshold and the duration exceeds the set value, it is determined to be a catastrophic failure, and the dual-level protection device is immediately activated. When it is determined to be a non-catastrophic failure, the system executes commands for automatic return to home, forced landing in a safe area, or hovering and waiting. The motor speed is adjusted through PID control to achieve attitude correction. When it is determined to be a catastrophic failure, the dual-level protection device is directly triggered, and the parachute system and emergency airbag are activated simultaneously. At the same time, the rotor release mechanism separates the rotor to eliminate interference.

[0055] The system monitors battery voltage in real time. When the battery voltage exceeds a threshold range, a battery voltage fault is identified, and a speed reduction and battery warning command are output. Specifically, the battery voltage fault diagnosis and determination formula is as follows: ; in, for t Real-time output voltage (V) of the drone battery. This is the minimum operating voltage threshold for the battery (Vmin = 3.2V for a single lithium polymer battery cell). This is the maximum operating voltage threshold of the battery (Vmax = 4.2V for a single lithium polymer battery cell). When the real-time output voltage exceeds [ , If the voltage is within the specified range, it is determined to be a battery voltage fault (Level II), and a speed reduction + battery warning command is immediately output; Real-time monitoring of motor speed is performed. When the difference between the real-time speed of one motor and the average speed of all motors in the drone exceeds a speed deviation threshold, an abnormal motor speed is determined, and hovering and power system fault warning commands are output. Specifically, the formula for diagnosing motor speed faults is as follows: ; in, for t Time of the first i The real-time rotational speed (r / min) of each motor for a quadcopter drone, i =1,2,3,4; for t The average speed (r / min) of the four motors at any given time. ; The motor speed deviation threshold is set according to the UAV power system calibration, such as 15% of the average speed. When the deviation of a single motor speed from the average speed exceeds the threshold, it is judged as abnormal motor speed (Level III), and the hover + power system fault warning command is immediately output. The system monitors the UAV's attitude angles in real time. When any of the pitch, roll, or yaw angles exceeds the corresponding maximum safety threshold, an attitude control failure (Level IV) is identified, and an emergency return-to-home or forced landing command is output. Specifically, the attitude angle threshold diagnosis formula is as follows: ; in, θ ( t ), , ψ ( t They are respectively t The pitch angle, roll angle, and yaw angle (°) of the UAV at all times; θ max , , ψ max These are the maximum safety thresholds for pitch angle, roll angle, and yaw angle (in the case of high-rise building inspection, the pitch angle / roll angle is set to ≤30° and the yaw angle to ≤±180°).

[0056] The fault diagnosis algorithm in this embodiment covers common basic faults such as battery undervoltage / overvoltage, motor speed imbalance, and attitude loss of control. It also captures potential gradual faults and complex faults through trend diagnosis and advanced model diagnosis, avoiding fault omissions caused by single-dimensional monitoring, and comprehensively ensuring the flight safety of UAVs in high-rise building inspections.

[0057] For drone parameters exhibiting gradual anomalies (slowly decreasing battery voltage, continuous fluctuations in motor speed), linear trend fitting is used to calculate the rate of change of these parameters, predict potential faults, and issue early warnings. Least squares is employed to linearly fit the time-series parameters; when the rate of voltage change falls below a preset threshold (voltage change rate...),... k If the predicted remaining voltage reaches the battery's minimum operating voltage threshold (Vmin) in a time less than -0.01V / s and the time it takes for the remaining voltage to reach the battery's minimum operating voltage threshold (T<60s) is less than the preset threshold, a potential low battery fault is identified, and a return-to-home warning command is output; if the motor speed change rate is greater than the preset threshold, a low battery potential fault is identified, and a return-to-home warning command is output. k If the speed exceeds 5r / (min·s) and the duration exceeds the preset time (3s), a potential motor wear fault is determined, and a speed reduction and motor maintenance warning command is output.

[0058] Using the least squares method to analyze time series parameters Perform a linear fit, and the fitting formula is: ; Among them, slope k denoted by , where is the rate of change of the parameters, including the rate of change of voltage (V / s) and the rate of change of rotational speed (r / (min·s)); b is the intercept of the linear fit. k The calculation formula is: ; in, n The number of time series data points to fit (set to 50, corresponding to 5 seconds of sampling data); ti For the first i Sampling time (s) for each data point; xi For the parameter values ​​(battery voltage, motor speed) of the i-th data point; When the rate of change of voltage k If the voltage drops continuously to -0.01V / s and the predicted time for the remaining voltage to reach Vmin is T<60s, it is determined to be a potential low battery fault (Level I), and a return-to-home warning command is output. When the rate of change of motor speed | k If the speed fluctuates continuously for more than 3 seconds, it is determined to be a potential motor wear fault (Level II), and a speed reduction and motor maintenance warning command will be output.

[0059] The intermediate trend diagnosis and judgment method in this embodiment is specifically designed for gradual anomalies such as slow battery voltage drop and gradual motor speed deviation. By fitting time series parameters using the least squares method, it quantifies the rate of parameter change and predicts the development trend. It can identify potential faults such as low battery power and motor wear in advance, shifting the fault handling point from after the fault occurs to the budding stage of the hidden danger. This fundamentally prevents gradual faults from escalating into non-catastrophic or even catastrophic faults, significantly improving the foresight of UAV flight safety.

[0060] For complex faults such as perception module failure and obstacle avoidance system malfunction, a support vector machine classification model is used to achieve accurate fault classification. Twelve features are selected to form the feature vector: mean, variance, bias, mean-bias ratio, variance change rate, bias change rate, visual ranging error, lidar ranging error, obstacle avoidance response time, flight speed variance, altitude change rate, and motor current variance. x Feature vectors from four states of the UAV—normal operation, visual module failure, LiDAR failure, and obstacle avoidance system malfunction—were collected to construct a labeled training set, which was then used with a radial basis function kernel. The kernel parameter γ was determined through cross-validation. x i , x j The Support Vector Machine (SVM) classification model is trained using the feature vectors in the training set. The real-time feature vectors are input into the trained SVM model, which outputs the corresponding fault type, determining it as a perception or obstacle avoidance fault, and outputting commands to switch to a backup perception module or to hover or decelerate. The specific steps include: a. Fault Feature Vector Construction: Twelve features are selected to form a feature vector: mean, variance, deviation, mean-deviation, variance change rate, deviation change rate, visual ranging error, lidar ranging error, obstacle avoidance response time, flight speed variance, altitude change rate, and motor current variance. x ; b. Collect feature vectors under four states of the UAV: ​​normal state, vision module failure, lidar failure, and obstacle avoidance system malfunction. Construct a labeled dataset as a training set and train the SVM model for fault classification. c. Input the feature vector extracted in real time into the trained SVM model, output the fault type (normal / vision module failure / LiDAR failure / obstacle avoidance system abnormality), and determine the corresponding perception or obstacle avoidance fault (Level II-III), and output the corresponding command to switch to the backup perception module or hover / decelerate.

[0061] The advanced model diagnostic judgment method in this embodiment is specifically designed for complex and compound faults such as perception module failure and obstacle avoidance system anomaly. Such faults cannot be identified by basic threshold judgment (single parameter exceeding the standard) or intermediate trend diagnosis (linear gradual change). However, the support vector machine classification model has a powerful ability to recognize complex patterns and can accurately distinguish between four states: normal, vision module failure, lidar failure, and obstacle avoidance system anomaly. This completely solves the technical pain points of difficult identification of complex faults and high misjudgment rate, and fills the gap in complex fault identification in the three-level diagnostic system.

[0062] Twelve core features, including mean, variance, and bias, are selected to form the feature vector. x It covers three dimensions of UAV perception, obstacle avoidance, and flight status, including statistical characteristics of flight parameters (such as flight speed variance and altitude change rate), error characteristics of perception modules (such as visual ranging error and lidar ranging error), and response characteristics of the obstacle avoidance system (such as obstacle avoidance response time). This multi-dimensional feature collaboration comprehensively captures the characteristic differences of complex faults, avoiding missed or false positives caused by single features, ensuring the accuracy of fault classification, and making it suitable for scenarios with high obstacle avoidance requirements, such as the inspection of high-rise buildings.

[0063] S3. Implement graded emergency response based on the fault level, triggering the corresponding response strategies for non-catastrophic or catastrophic faults. Non-catastrophic failures can prioritize ensuring the mission and maintaining stability; catastrophic failures should immediately initiate the highest priority safety procedures (such as forced landing, obstacle avoidance, and cutting off dangerous outputs) to avoid minor failures directly interrupting the building inspection mission and to maximize the safety of personnel, buildings, and equipment in the event of major risks.

[0064] S4. After the drone lands, it confirms the safety of the landing point through visual SLAM or GPS positioning and initiates onboard communication to report the status.

[0065] After landing, the system actively confirms the safety of the landing point through visual SLAM or GPS positioning, avoiding landing in dangerous areas such as rooftops, narrow passages, and densely populated areas. At the same time, it reports the status in real time through airborne communication, realizing a closed-loop safety process of flight-failure-emergency-landing-reporting, meeting the high safety and compliance requirements of urban high-rise building inspection operations.

[0066] Figure 5 The basic steps of the safety assurance method for medical examination drones used in urban high-rise buildings in this embodiment are shown.

[0067] This invention also provides a safety assurance system for a medical examination drone used in urban high-rise buildings, which implements the safety assurance method for the medical examination drone used in urban high-rise buildings as described above. The system includes: a reliability assurance subsystem, which is configured with a power unit and a flight control unit connected to each other. The flight control unit is signal-connected to a graded emergency procedure module, which has a built-in fault diagnosis algorithm unit. The fault diagnosis algorithm unit is signal-connected to a sensor for monitoring the power redundancy and attitude stability indicators of the drone.

[0068] The reliability assurance subsystem, through a hard connection between the power unit and the flight control unit, combined with the soft logic of the tiered emergency procedure module, directly integrates sensor monitoring, fault diagnosis algorithms, and power actuators. Even in the complex electromagnetic interference and airflow disturbance environment of high-rise buildings, real-time monitoring of power redundancy and attitude stability indicators ensures that the UAV will not lose control and crash due to a single point of failure, thus solving the high-risk operational challenges in urban high-rise building health check scenarios at the system level.

[0069] The power unit is connected to a dual-stage protection actuator, which is equipped with a parachute system, an emergency airbag system, and a rotor release mechanism. In the initial state, the parachute system and the emergency airbag system are installed inside the UAV. The rotor release mechanism is connected to the UAV's rotor via a detachable connector.

[0070] The parachute system provides protection at mid-to-high altitudes. Its triggering is based on precise sensor thresholds (altitude ≥ 60 meters and vertical descent speed ≥ 8 m / s). A specially designed canopy ensures rapid deployment within 3 seconds, allowing the drone to achieve a soft landing at a speed not exceeding 3 m / s. The rotor release mechanism is triggered in conjunction with the parachute system. At the moment of parachute deployment, electromagnetic clutches or other methods disengage all rotors from the motor drive shafts, allowing the rotors to enter a free-rotating state. This completely eliminates the interference of the rotor downwash airflow on the parachute and significantly reduces the rotational kinetic energy of the falling object, lowering the risk of secondary injury. The emergency airbag system serves as supplementary protection at low altitudes (≥ 10 meters) and before ground impact. Triggered by an altimeter, accelerometer, or contact sensor, it is required to inflate rapidly within 0.8 seconds, forming a buffer layer to ensure that the impact acceleration of the falling drone on the ground, simulating a human body, does not exceed the safety limit of 20g. The parachute system, emergency airbag system, and rotor release mechanism work together to effectively solve protection problems in complex scenarios, including high and low altitudes and situations with and without rotor interference.

[0071] When a drone crashes at low altitude (less than 10 meters from the ground) or the parachute system fails to deploy properly, the emergency airbag system is triggered simultaneously. By inflating the airbags, the impact of the fall is further absorbed. This not only protects the medical equipment carried by the drone (such as high-definition cameras and detection sensors) from damage, but also prevents the drone from crashing onto the exterior of high-rise buildings, windowsills, or other locations, thus avoiding secondary hazards. This provides full-process protection in extreme failure scenarios and overcomes the limitations of traditional single protection methods. Figure 1 The triggering process of the security system is shown.

[0072] The power unit is equipped with redundantly designed multiple sets of batteries, motors, and electronic speed controllers. The batteries are electrically connected to the motors, and the electronic speed controllers are electrically connected to the motors. The flight control unit is equipped with redundant backup inertial measurement units (IMUs), GPS receivers, and a main processor. The main processor is connected to the batteries, electronic speed controllers, IMUs, and GPS receivers. In this embodiment, the system is implemented on a quadcopter (expandable to hexacopter or octocopter) high-rise building inspection UAV. The redundant power unit of the reliability assurance subsystem uses four smart batteries and six brushless motors (providing power redundancy), and the redundant flight control unit uses two independent IMU and GPS modules. The inertial measurement unit is a six-axis IMU. The parachute system is located at the center of the upper part of the UAV fuselage and is connected to a propellant launcher, deploying via propellant ejection. The emergency airbag system folds and is stored at the bottom of the UAV fuselage and the ends of the four arms. The emergency airbag system is connected to a high-pressure nitrogen generator; it is inflated using the high-pressure nitrogen generator (inflation process as follows). Figure 3 As shown, the airbag i is folded and stored in the mounting position h of the fuselage g. After triggering, it inflates and deploys rapidly, covering the parts of the fuselage that are likely to come into contact with people on the ground. The triggering conditions for the parachute system are that the drone flies at an altitude of not less than 60 meters and the vertical descent speed is continuously greater than 8 meters per second, the time from triggering to full deployment is less than 3 seconds, and after deployment, it can control the vertical landing speed of the entire drone to within 3 meters per second; the triggering conditions for the emergency airbag system are that the drone flies at an altitude of not less than 10 meters, the time from triggering to full inflation is less than 0.8 seconds, and the maximum impact acceleration transmitted when it touches the simulated human body after inflation does not exceed 20g. Figure 4 This illustrates a catastrophic failure protection scenario where the parachute system and emergency airbags operate simultaneously.

[0073] The rotor release mechanism is linked to the parachute system (e.g.) Figure 2As shown, upon receiving the parachute trigger signal, all rotors are separated from the power unit. The rotor release mechanism is equipped with an electromagnetic clutch, whose trigger signal and the parachute system's trigger signal originate from the same cascaded control circuit to ensure synchronized operation. The rotor release mechanism uses a normally closed electromagnetic clutch, which engages to transmit torque during normal flight and de-energizes upon receiving the trigger signal. The flight control unit is equipped with a laser altimeter and a barometric altimeter for real-time monitoring of flight status, collecting flight parameters such as UAV acceleration, altitude, and attitude in real time. Data fusion is performed using a Kalman filter algorithm, with a sampling frequency ≥100Hz and a data transmission delay <10ms. During normal flight, electromagnetic clutch c engages, and motor b drives rotor d to rotate; when parachute f is triggered, electromagnetic clutch c de-energizes, rotor d separates from motor b, and parachute f ejects and deploys from parachute pack e.

[0074] This embodiment describes a safety assurance method and system for unmanned aerial vehicles (UAVs) used for medical examinations of urban high-rise buildings. By continuously monitoring the UAV's flight parameters, sampling the flight parameter data, and fusing it using a Kalman filter algorithm, the system employs a dual-judgment mechanism based on threshold and trend analysis to perform real-time analysis of the collected flight parameter data and implement graded emergency response according to fault levels. The system integrates structural innovation, fault prevention, intelligent decision-making, and ultimate protection. Through the collaborative work of four levels—structural optimization, reliability assurance, intelligent decision-making, and ultimate protection—a full-chain safety system is constructed, achieving the design goal of failure safety and improving the safety assurance performance of unmanned aerial vehicles (UAVs) used for medical examinations of urban high-rise buildings.

[0075] This invention also provides a computer device. Figure 7 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present invention; see the accompanying drawings. Figure 7 As shown, the computer device includes: an input device 23, an output device 24, a memory 22, and a processor 21; the memory 22 is used to store one or more programs; when the one or more programs are executed by the one or more processors 21, the one or more processors 21 implement the safety assurance method for urban high-rise building physical examination drones provided in the above embodiments; wherein the input device 23, the output device 24, the memory 22, and the processor 21 can be connected via a bus or other means. Figure 7 Taking the example of a connection between China and Israel via a bus.

[0076] The memory 22, as a read / write storage medium for a computing device, can be used to store software programs and computer-executable programs, such as the program instructions corresponding to the safety assurance method for a drone used for physical examinations of high-rise buildings in urban areas as described in this embodiment of the invention. The memory 22 may mainly include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a function; the data storage area may store data created based on the use of the device. Furthermore, the memory 22 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some instances, the memory 22 may further include memory remotely located relative to the processor 21, and these remote memories can be connected to the device via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0077] Input device 23 can be used to receive input digital or character information, and generate key signal inputs related to user settings and function control of the device; output device 24 may include display devices such as a display screen.

[0078] The processor 21 executes various functional applications and data processing of the device by running software programs, instructions and modules stored in the memory 22, thereby realizing the above-mentioned safety assurance method for medical examination drones used in urban high-rise buildings.

[0079] The computer equipment provided above can be used to execute the safety assurance method for medical examination drones in urban high-rise buildings provided in the above embodiments, and has corresponding functions and beneficial effects.

[0080] This invention also provides a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform the safety assurance method for urban high-rise building health check drones provided in the above embodiments. The storage medium can be any type of memory device or storage device, including: mounting media such as CD-ROM, floppy disk, or magnetic tape; computer system memory or random access memory such as DRAM, DDRRAM, SRAM, EDORAM, Rambus RAM, etc.; non-volatile memory such as flash memory, magnetic media (e.g., hard disk or optical storage); registers or other similar types of memory components; the storage medium may also include other types of memory or combinations thereof; furthermore, the storage medium may reside in a first computer system in which the program is executed, or it may reside in a different second computer system connected to the first computer system via a network (such as the Internet); the second computer system can provide program instructions to the first computer for execution. The storage medium includes two or more storage media that can reside in different locations (e.g., in different computer systems connected via a network). The storage medium can store program instructions (e.g., specifically implemented as a computer program) executable by one or more processors.

[0081] Of course, the computer-executable instructions provided in the embodiments of the present invention are not limited to the safety assurance method for medical examination drones for urban high-rise buildings as described in the above embodiments, but can also perform related operations in the safety assurance method for medical examination drones for urban high-rise buildings provided in any embodiment of the present invention.

[0082] The technical solution of the present invention has been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the scope of protection of the present invention.

[0083] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A safety assurance method for unmanned aerial vehicles (UAVs) used for medical examinations in urban high-rise buildings, characterized in that, Includes the following steps: S1. Continuously monitor the flight parameters of the UAV, including acceleration, altitude, attitude angle, battery voltage and motor speed. Sample the flight parameter data at a frequency of ≥100Hz and perform fusion processing through Kalman filtering algorithm. S2. Employ a fault diagnosis algorithm and a dual judgment mechanism based on threshold and trend analysis to perform real-time analysis of the collected flight parameter data; The key indicators of power redundancy and attitude stability are compared with preset thresholds to determine the fault level: the fault level includes: non-catastrophic fault and catastrophic fault. S3. Implement graded emergency response based on the fault level, triggering the corresponding response strategies for non-catastrophic or catastrophic faults. S4. After the drone lands, it confirms the safety of the landing point through visual SLAM or GPS positioning and initiates onboard communication to report the status.

2. The safety assurance method for unmanned aerial vehicles used for physical examinations in urban high-rise buildings according to claim 1, characterized in that, The fault diagnosis algorithm employed in step S2, based on a dual-judgment mechanism of threshold and trend analysis, performs real-time analysis of the collected flight parameter data. This includes: real-time calculation of power redundancy and key attitude stability indicators, comparing them with preset thresholds; the preset thresholds include a first threshold and a second threshold corresponding to non-catastrophic and catastrophic faults, respectively; when an indicator deviates from the normal range, the fault level is determined, triggering graded responses for non-catastrophic and catastrophic faults; the method for determining the fault level includes: calculating remaining power capacity based on the UAV's motor speed and battery voltage data; and assessing flight stability through attitude angle deviation and angular velocity based on the UAV's flight altitude / speed and attitude angle data. When the indicator falls below the first threshold, an alarm is triggered and the system automatically switches to the backup redundant unit. When the indicator falls below the second threshold and the duration exceeds the set value, it is determined to be a catastrophic failure, and the dual-level protection device is immediately activated. When it is determined to be a non-catastrophic failure, the system executes commands to automatically return to base, make an emergency landing in a safe area, or hover and wait. Attitude correction is achieved by adjusting the motor speed through PID control. When it is determined to be a catastrophic failure, the dual-level protection device is directly triggered, and the parachute system and emergency airbag are activated simultaneously, while the rotor release mechanism separates the rotor.

3. The safety assurance method for unmanned aerial vehicles used for physical examinations in urban high-rise buildings according to claim 2, characterized in that, The fault diagnosis algorithm includes: battery voltage fault diagnosis and determination, motor speed fault diagnosis and determination, attitude angle threshold diagnosis and determination, intermediate trend diagnosis and determination, and advanced model diagnosis and determination. The method for diagnosing and determining battery voltage faults includes: real-time monitoring of battery voltage; when the battery voltage exceeds the threshold range, determining a battery voltage fault and outputting a speed reduction and battery warning command. The method for diagnosing and determining motor speed faults includes: real-time monitoring of motor speed; when the difference between the real-time speed of one motor in the UAV and the average speed of the multiple motors in the UAV is greater than the speed deviation threshold, the motor speed is determined to be abnormal, and hovering and power system fault warning commands are output. The method for diagnosing and determining the attitude angle threshold includes: real-time monitoring of the attitude angle of the UAV; when any of the pitch angle, roll angle, or yaw angle exceeds the corresponding maximum safety threshold, an attitude control failure is determined, and an emergency return or forced landing command is output.

4. The safety assurance method for unmanned aerial vehicles used for physical examinations in urban high-rise buildings according to claim 3, characterized in that, The method for determining intermediate-level trends includes: To address the gradual anomalies in UAV parameters, a linear trend fitting method is used to calculate the rate of change of parameters to predict potential faults and provide early warnings. The least squares method is used to perform linear fitting on the time series parameters. When the rate of change of voltage is lower than a preset threshold and the time for the predicted remaining voltage to reach the minimum operating voltage threshold of the battery is less than the preset threshold, a potential low battery fault is identified, and a return-to-home warning command is output. When the rate of change of motor speed is greater than a preset threshold and the duration exceeds a preset time, a potential motor wear fault is identified, and a speed reduction and motor maintenance warning command is output.

5. The safety assurance method for unmanned aerial vehicles used for physical examinations in urban high-rise buildings according to claim 3, characterized in that, The advanced model diagnostic method includes: for complex faults such as perception module failure and obstacle avoidance system anomalies, a support vector machine classification model is used to achieve accurate fault classification; 12 features are selected to form a feature vector: mean, variance, bias, mean-bias, variance change rate, bias change rate, visual ranging error, lidar ranging error, obstacle avoidance response time, flight speed variance, altitude change rate, and motor current variance. x Feature vectors from four states of the UAV—normal operation, visual module failure, LiDAR failure, and obstacle avoidance system malfunction—were collected to construct a labeled training set, which was then used with a radial basis function kernel. The kernel parameter γ was determined through cross-validation. x i , x j The support vector machine classification model is trained using the feature vectors in the training set; the real-time feature vectors are input into the trained support vector machine classification model, the corresponding fault type is output, and it is determined to be a perception or obstacle avoidance fault, and a switch to the backup perception module or hovering or deceleration command is output.

6. The safety assurance method for unmanned aerial vehicles used for physical examinations in urban high-rise buildings according to claim 3, characterized in that, The method for fusion processing using the Kalman filter algorithm in step S1 includes: A 12-dimensional state vector of the UAV is selected, which includes three-dimensional position, three-dimensional velocity, pitch angle, roll angle, yaw angle and corresponding angular velocity in the geodetic coordinate system. Nonlinear state equations and observation equations are established, and prediction and updating are performed after linearization by first-order Taylor expansion. Construct the initial state vector and covariance matrix at takeoff time, predict the current prior state and prior covariance based on the posterior state at the previous time, and solve the state transition Jacobian matrix; calculate the observation matrix, residuals and residual covariance to obtain the Kalman gain; update the posterior state estimate and posterior covariance matrix accordingly. The optimal posterior state estimate obtained after fusion, including position, velocity, attitude angle and angular velocity, is used as the input parameters of the fault diagnosis algorithm and the fusion result is output.

7. A safety assurance system for unmanned aerial vehicles (UAVs) used for medical examinations in urban high-rise buildings, used to implement the safety assurance method for unmanned aerial vehicles used for medical examinations in urban high-rise buildings as described in any one of claims 1-6, characterized in that, include: The reliability assurance subsystem is configured with an interconnected power unit and a flight control unit. The flight control unit is signal-connected to a graded emergency procedure module, which has a built-in fault diagnosis algorithm unit. The fault diagnosis algorithm unit is signal-connected to a sensor for monitoring the power redundancy and attitude stability indicators of the UAV.

8. The safety assurance system for unmanned aerial vehicles used for medical examinations in urban high-rise buildings according to claim 7, characterized in that, The power unit is connected to a dual-stage protection actuator, which is equipped with a parachute system, an emergency airbag system, and a rotor release mechanism. In the initial state, the parachute system and the emergency airbag system are installed inside the UAV. The rotor release mechanism is connected to the UAV's rotor via a detachable connector.

9. The safety assurance system for unmanned aerial vehicles used for physical examinations in urban high-rise buildings according to claim 7, characterized in that, The power unit is equipped with multiple sets of batteries, multiple sets of motors, and multiple sets of electronic speed controllers with redundant design. The batteries are electrically connected to the motors, and the electronic speed controllers are electrically connected to the motors. The flight control unit is equipped with redundant backup inertial measurement units, global positioning system receivers, and main processors. The main processors are respectively connected to the batteries, electronic speed controllers, inertial measurement units, and global positioning system receivers.

10. The safety assurance system for unmanned aerial vehicles used for physical examinations in urban high-rise buildings according to claim 8, characterized in that, The parachute system is located at the center of the upper part of the UAV fuselage and is connected to a gunpowder launcher; the emergency airbag system is folded and stored at the bottom of the UAV fuselage and the ends of the four arms, and is connected to a high-pressure nitrogen generator; the rotor release mechanism is equipped with an electromagnetic clutch, and the trigger signal of the electromagnetic clutch and the trigger signal of the parachute system originate from the same cascaded control circuit; the flight control unit is also equipped with a laser altimeter and a barometric altimeter for real-time monitoring of flight status.