Systems and methods for sensor response management

A DI-based framework with AI/ML algorithms dynamically manages zone sensor responses, addressing the inflexibility of traditional systems by reducing false alarms and enhancing security through personalized, contextually aware responses.

WO2026112660A1PCT designated stage Publication Date: 2026-05-28RESIDEO LLC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
RESIDEO LLC
Filing Date
2025-11-25
Publication Date
2026-05-28

Smart Images

  • Figure US2025057157_28052026_PF_FP_ABST
    Figure US2025057157_28052026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are systems and methods that provide a novel security framework for a dynamic, intelligent approach to location protection through flexible zone management. Each location or entry point can be treated as a configurable "zone" with multiple layers of customizable security parameters. The framework goes beyond traditional armed / disarmed states via alarm profiles that can computationally, dynamically and / or automatically control, manage, modify and / or trigger sensor response to particular types of events detected or not detected at a location. The framework's ability to learn, adapt and respond contextually transforms security from a passive, alarm-driven model to an active, intelligent protection ecosystem.
Need to check novelty before this filing date? Find Prior Art

Description

Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WOElectronically Filed: November 25, 2025SYSTEMS AND METHODS FOR SENSOR RESPONSE MANAGEMENTCROSS REFERENCE TO RELATED APPLICATIONS

[0001] This application claims the benefit of, and priority to, U.S. Provisional Patent Application No. 63 / 724,438 filed November 25, 2024, the entire contents of which are incorporated herein by reference.FIELD OF THE DISCLOSURE

[0002] The present disclosure is generally related to a location monitoring and control system, and more particularly, to a decision intelligence (Dl)-based computerized framework for automatically and / or dynamically controlling and managing zone sensor responses and activities based on detected events.SUMMARY OF THE DISCLOSURE

[0003] According to some embodiments, as discussed herein, the disclosed systems and methods provide a novel security system framework that centers on a modular, intelligent zone management approach that allows granular control over sensor awareness, response types and scheduling. As discussed herein, for example, the disclosed framework can function to manage each defined location or entry point at a location as a configurable ‘'zone” with multiple layers of customizable security parameters.

[0004] According to some embodiments, as discussed herein, a security7system can include a unit that is a ‘‘zone”, which is a logical representation of a physical area or entry point within a protected space of the location. Each zone can be associated with multiple sensors, which can include, for example, motion detectors, magnetic contact sensors, glass break sensors, camera systems, environmental monitoring devices, and the like. The framework includes innovative technology that enables the ability to dynamically adjust the sensitivity7, awareness and response mechanisms for such sensors based on contextual parameters. For example, a front door zone can have different configurations during daytime hours, nighttime hours, when the homeowner is on vacation, or during specific scheduled events. Such configurations can involve, for example, changing sensor sensitivity7, modifying response protocols, integrating with broader home automation systems, and the like, or some combination thereof. In another non-limiting example, a bedroom window zone can have different monitoring protocols when occupants are sleeping versus when the room is unoccupied.1ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WO Electronically Filed: November 25, 2025

[0005] According to some embodiments, the disclosed framework can include an “awareness profile’7for each zone, which as provided herein, goes beyond traditional binary armed / disarmed states. Such profile can incorporate artificial intelligence / machine learning (AI / ML) algorithms that understand typical behavioral patterns, allowing for more nuanced security responses. For example, the framework can leam that certain sensor triggers during specific times are more likely to be false alarms versus genuine security threats. Indeed, such awareness mechanisms can enable capabilities for graduated response levels. For example, instead of a single alarm state, the framework can function to first initiate soft alerts, perform additional verification through secondary7sensors or cameras, and then escalate to more aggressive response protocols if initial checks confirm a potential threat. Such approach, inclusive of other similar modified sensor responses, can reduce unnecessary panic responses while maintaining robust security coverage.

[0006] According to some embodiments, the disclosed framework provides advanced scheduling and dynamic response management capabilities for a security system. That is, in some embodiments, for example, the framework can enable users to pre-configure zone responses and / or enable dynamic, Al-driven scheduling based on learned behavioral patterns. In some embodiments, user-based scheduling can involve setting specific times when certain zones have heightened or reduced monitoring sensitivity. In some embodiments, dynamic scheduling can involve automatically adjusting zone parameters based on observed household routines, occupancy patterns, external factors (e.g., local crime statistics, for example), and the like, or some combination thereof.

[0007] In some embodiments, such scheduling mechanisms within the disclosed framework can support complex, multi-layered rules. For example, a vacation mode can simultaneously activate perimeter monitoring for street-facing entrances while creating more nuanced monitoring for internal and rear-facing zones. In some embodiments, the framework can progressively adjust monitoring intensity based on, but not limited to, time of day, external environmental conditions, detected anomalies, and the like, or some combination thereof.

[0008] According to some embodiments, the framework can provide capabilities for response type customization. That is, beyond traditional alarm mechanisms, the framework can provide functionality for highly customized response types. For example, such response types can range from silent alerts sent to mobile devices, automated local sound / light warnings, direct emergency serv ice notifications, and / or integration with broader home automation systems that can simulate occupancy or deter potential intruders. In some embodiments, response types can2ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WOElectronically Filed: November 25, 2025 be conditionally configured based on, but not limited to, zone, time, detected threat level, user- defined preferences, and the like, or some combination thereof. For example, for high-risk zones such primary entrances, responses can be more immediate and comprehensive, while secondary internal zones can have more graduated alert mechanisms.

[0009] Accordingly, as discussed herein, the disclosed security system framework provides a significant evolution from traditional, rigid security approaches. By treating security as a dynamic, intelligent and personalized sendee, the disclosed framework provides functionality for unprecedented flexibility7in protecting living and / or working spaces. As discussed herein, the framework’s ability7to learn, adapt and respond contextually transforms security from a passive, alarm-driven model to an active, intelligent protection ecosystem.

[0010] Thus, as discussed herein, the disclosed systems and methods can provide novel mechanisms for use in climate control (“comfort”) systems, security systems, smoke / fire systems, and the like, for which a location (e.g., house, building, office, patio, and the like) can be equipped with to ensure its occupants comfort, security7and safety.

[0011] According to embodiments of the instant disclosure, it should be understood that the discussion herein that references a location can correspond to, but not be limited to, a home, office, building and / or any other ty pe of definable structure and / or geographic location for which a control system (e.g., comfort / climate control and / or security system, for example) can be provided.

[0012] According to some embodiments, it should be understood that while the discussion herein may7focus on a specific ty pe of event, but it should not be construed as limiting, as such event can include activity7at a location related to, but not limited to, a security7breach (e.g., glass break, unsolicited motion, door break and the like), a fire, carbon monoxide, carbon dioxide, flooding, and the like, or some combination thereof, without departing from the scope of the instant disclosure. For example, a glass break at a home, via a glass break sensor, can be audited and a sensor response can be curated via the disclosed systems and methods (e.g., a security7panel or another sensor or user equipment, for example) via similar protocols outlined in the instant disclosure.

[0013] According to some embodiments, a method is disclosed for a Dl-based computerized framework for automatically7and / or dynamically7controlling and managing zone sensor responses and activities based on detected events. In accordance with some embodiments, the present disclosure provides a non-transitory computer-readable storage medium for carrying out the above-mentioned technical steps of the framework’s functionality. The non-transitory3ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WO Electronically Filed: November 25, 2025 computer-readable storage medium has tangibly stored thereon, or tangibly encoded thereon, computer readable instructions that when executed by a device cause at least one processor to perform a method for automatically and / or dynamically controlling and managing zone sensor responses and activities based on detected events.

[0014] In accordance with one or more embodiments, a system is provided that includes one or more processors and / or computing devices configured to provide functionality in accordance with such embodiments. In accordance with one or more embodiments, functionality is embodied in steps of a method performed by at least one computing device. In accordance with one or more embodiments, program code (or program logic) executed by a processor(s) of a computing device to implement functionality in accordance with one or more such embodiments is embodied in, by and / or on a non-transitory computer-readable medium.DESCRIPTIONS OF THE DRAWINGS

[0015] The features, and advantages of the disclosure will be apparent from the following description of embodiments as illustrated in the accompanying drawings, in which reference characters refer to the same parts throughout the various views. The drawings are not necessarily to scale, emphasis instead being placed upon illustrating principles of the disclosure:

[0016] FIG. 1 is a block diagram of an example configuration within which the systems and methods disclosed herein could be implemented according to some embodiments of the present disclosure;

[0017] FIG. 2 is a block diagram illustrating components of an exemplary' system according to some embodiments of the present disclosure;

[0018] FIG. 3 illustrates an exemplary workflow according to some embodiments of the present disclosure;

[0019] FIG. 4 depicts an exemplary implementation of an architecture according to some embodiments of the present disclosure;

[0020] FIG. 5 depicts an exemplary implementation of an architecture according to some embodiments of the present disclosure; and

[0021] FIG. 6 is a block diagram illustrating a computing device showing an example of a client or server device used in various embodiments of the present disclosure.4ACTIVE 716851642v1Attorney Docket No. 203863-013401 / PCTResideo Ref. No. R214345-WOElectronically Filed: November 25, 2025DETAILED DESCRIPTION

[0022] The present disclosure will now be described more fully hereinafter with reference to the accompanying drawings, which form a part hereof, and which show, by way of non-limiting illustration, certain example embodiments. Subject matter may, however, be embodied in a variety of different forms and, therefore, covered or claimed subject matter is intended to be construed as not being limited to any example embodiments set forth herein; example embodiments are provided merely to be illustrative. Likewise, a reasonably broad scope for claimed or covered subject matter is intended. Among other things, for example, subject matter may be embodied as methods, devices, components, or systems. Accordingly, embodiments may, for example, take the form of hardware, softw are, firmware or any combination thereof (other than software per se). The following detailed description is, therefore, not intended to be taken in a limiting sense.

[0023] Throughout the specification and claims, terms may have nuanced meanings suggested or implied in context beyond an explicitly stated meaning. Likewise, the phrase “in one embodiment’" as used herein does not necessarily refer to the same embodiment and the phrase “in another embodiment” as used herein does not necessarily refer to a different embodiment. It is intended, for example, that claimed subject matter include combinations of example embodiments in whole or in part.

[0024] In general, terminology’ may be understood at least in part from usage in context. For example, terms, such as “and”, “or”, or “and / or,” as used herein may include a variety of meanings that may depend at least in part upon the context in which such terms are used. Typically, “or” if used to associate a list, such as A, B or C, is intended to mean A, B, and C, here used in the inclusive sense, as well as A, B or C, here used in the exclusive sense. In addition, the term “one or more” as used herein, depending at least in part upon context, may be used to describe any feature, structure, or characteristic in a singular sense or may be used to describe combinations of features, structures or characteristics in a plural sense. Similarly, terms, such as “a,” “an,” or “the,” again, may be understood to convey a singular usage or to convey a plural usage, depending at least in part upon context. In addition, the term “based on” may be understood as not necessarily intended to convey an exclusive set of factors and may, instead, allow for existence of additional factors not necessarily expressly described, again, depending at least in part on context.

[0025] The present disclosure is described below with reference to block diagrams and operational illustrations of methods and devices. It is understood that each block of the block5ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WO Electronically Filed: November 25, 2025 diagrams or operational illustrations, and combinations of blocks in the block diagrams or operational illustrations, can be implemented by means of analog or digital hardware and computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer to alter its function as detailed herein, a special purpose computer, ASIC, or other programmable data processing apparatus, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, implement the functions / acts specified in the block diagrams or operational block or blocks. In some alternate implementations, the functions / acts noted in the blocks can occur out of the order noted in the operational illustrations. For example, two blocks shown in succession can in fact be executed substantially concurrently or the blocks can sometimes be executed in the reverse order, depending upon the funclionality / acts involved.

[0026] For the purposes of this disclosure a non-transitory computer readable medium (or computer-readable storage medium / media) stores computer data, which data can include computer program code (or computer-executable instructions) that is executable by a computer, in machine readable form. By way of example, and not limitation, a computer readable medium may include computer readable storage media, for tangible or fixed storage of data, or communication media for transient interpretation of code-containing signals. Computer readable storage media, as used herein, refers to physical or tangible storage (as opposed to signals) and includes without limitation volatile and non-volatile, removable and nonremovable media implemented in any method or technology for the tangible storage of information such as computer-readable instructions, data structures, program modules or other data. Computer readable storage media includes, but is not limited to, RAM, ROM, EPROM, EEPROM, flash memory or other solid state memory technology, optical storage, cloud storage, magnetic storage devices, or any’ other physical or material medium which can be used to tangibly store the desired information or data or instructions and which can be accessed by a computer or processor.

[0027] For the purposes of this disclosure the term “server’' should be understood to refer to a service point which provides processing, database, and communication facilities. By way of example, and not limitation, the term “server” can refer to a single, physical processor with associated communications and data storage and database facilities, or it can refer to a networked or clustered complex of processors and associated network and storage devices, as well as operating software and one or more database systems and application software that support the services provided by the server. Cloud servers are examples.6ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WO Electronically Filed: November 25, 2025

[0028] For the purposes of this disclosure a “network’" should be understood to refer to a network that may couple devices so that communications may be exchanged, such as between a server and a client device or other types of devices, including between wireless devices coupled via a wireless network, for example. A network may also include mass storage, such as network attached storage (NAS), a storage area network (SAN), a content delivery' network (CDN) or other forms of computer or machine-readable media, for example. A network may include the Internet, one or more local area networks (LANs), one or more wide area networks (WANs), wire-line type connections, wireless type connections, cellular or any combination thereof. Likewise, sub-networks, which may employ differing architectures or may be compliant or compatible with differing protocols, may interoperate within a larger network.

[0029] For purposes of this disclosure, a “wireless network” should be understood to couple client devices with a network. A wireless network may employ stand-alone ad-hoc networks, mesh networks, Wireless LAN (WLAN) networks, cellular networks, or the like. A wireless network may further employ a plurality of network access technologies, including Wi-Fi, Long Term Evolution (LTE), WLAN, Wireless Router mesh, or 2nd, 3rd, 4thor 5thgeneration (2G, 3G, 4G or 5G) cellular technology', mobile edge computing (MEC), Bluetooth, 802.1 Ib / g / n, or the like. Network access technologies may enable wide area coverage for devices, such as client devices with varying degrees of mobility, for example.

[0030] In short, a wireless network may include virtually any ty pe of wireless communication mechanism by which signals may' be communicated between devices, such as a client device or a computing device, between or within a network, or the like.

[0031] A computing device may be capable of sending or receiving signals, such as via a wired or wireless network, or may be capable of processing or stonng signals, such as in memory as physical memory states, and may, therefore, operate as a server. Thus, devices capable of operating as a server may include, as examples, dedicated rack-mounted servers, desktop computers, laptop computers, set top boxes, integrated devices combining various features, such as two or more features of the foregoing devices, or the like.

[0032] For purposes of this disclosure, a client (or user, entity', subscriber or customer) device may include a computing device capable of sending or receiving signals, such as via a wired or a wireless network. A client device may, for example, include a desktop computer or a portable device, such as a cellular telephone, a smart phone, a display pager, a radio frequency (RF) device, an infrared (IR) device a Near Field Communication (NFC) device, a Personal Digital Assistant (PDA), a handheld computer, a tablet computer, a phablet, a laptop computer,7ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WOElectronically Filed: November 25, 2025 a set top box, a wearable computer, smart watch, an integrated or distributed device combining various features, such as features of the forgoing devices, or the like.

[0033] A client device may vary in terms of capabilities or features. Claimed subject matter is intended to cover a wide range of potential variations, such as a web-enabled client device or previously mentioned devices may include a high-resolution screen (HD or 4K for example), one or more physical or virtual keyboards, mass storage, one or more accelerometers, one or more gyroscopes, global positioning system (GPS) or other location-identifying type capability, or a display with a high degree of functionality, such as a touch-sensitive color 2D or 3D display, for example.

[0034] Certain embodiments and principles will be discussed in more detail with reference to the figures. With reference to FIG. 1, system 100 is depicted which includes user equipment (UE) 102 (e.g., a client device, as mentioned above and discussed below in relation to FIG. 6), network 104, cloud system 106, database 108, sensors 110 and control engine 200. It should be understood that while system 100 is depicted as including such components, it should not be construed as limiting, as one of ordinary' skill in the art would readily understand that varying numbers of UEs, peripheral devices, sensors, cloud systems, databases and networks can be utilized; however, for purposes of explanation, system 100 is discussed in relation to the example depiction in FIG. 1.

[0035] According to some embodiments, UE 102 can be any type of device, such as, but not limited to, a mobile phone, tablet, laptop, sensor, smart television (TV) Internet of Things (loT) device, autonomous machine, wearable device, and / or any other device equipped with a cellular or wireless or wired transceiver. For example, UE 102 can be a security' control panel.

[0036] In some embodiments, a peripheral device (not shown) can be connected to UE 102, and can be any type of peripheral device, such as, but not limited to, a wearable device (e.g., smart ring or smart watch), printer, speaker, sensor, and the like. In some embodiments, a peripheral device can be any type of device that is connectable to UE 102 via any type of known or to be known pairing mechanism, including, but not limited to, WiFi, Bluetooth™, Bluetooth Low Energy (BLE), NFC, and the like.

[0037] According to some embodiments, sensors 1 10 (or sensor devices 1 1 ) can correspond to any type of device, component and / or sensor associated with a location of system 100 (referred to, collectively, as “sensors”). In some embodiments, the sensors 110 can be any type of device that is capable of sensing and capturing data / metadata related to a user and / or activity of the location. For example, the sensors 110 can include, but not be limited to, cameras, motion8ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WOElectronically Filed: November 25, 2025 detectors, door and window contacts, temperature, heat and smoke detectors, carbon dioxide and / or carbon monoxide detectors, passive infrared (PIR) sensors, time-of-flight (ToF) sensors, and the like. In some embodiments, the sensors 110 can be associated with devices associated with the location of system 100, such as, for example, lights, smart locks, garage doors, smart appliances (e.g., thermostat, refrigerator, television, personal assistants (e.g., Alexa®, Nest®, for example)), smart rings, smart phones, smart watches or other wearables, tablets, personal computers, and the like, and some combination thereof. For example, the sensors 110 can include the sensors on UE 102 (e.g., smart phone) and / or peripheral device (e.g., a paired smart watch).

[0038] In some embodiments, network 104 can be any t pe of network, such as, but not limited to, a wireless network, cellular network, the Internet, and the like (as discussed above). Network 104 facilitates connectivity of the components of system 100, as illustrated in FIG. 1.

[0039] According to some embodiments, cloud system 106 may be any type of cloud operating platform and / or network based system upon which applications, operations, and / or other fornis of network resources may be located. For example, system 106 may be a service provider and / or network provider from where services and / or applications may be accessed, sourced or executed from. For example, system 106 can represent the cloud-based architecture associated with a location monitoring and control system provider (e.g., climate and / or security system provided by Resideo®). which has associated network resources hosted on the internet or private network (e.g., network 104), which enables (via engine 200) the location management discussed herein.

[0040] In some embodiments, cloud system 106 may include a server(s) and / or a database of information which is accessible over network 104. In some embodiments, a database 108 of cloud system 106 may store a dataset of data and metadata associated with local and / or network information related to a user(s) of the components of system 100 and / or each of the components of system 100 (e.g., UE 102, sensors 110, and the services and applications provided by cloud system 106 and / or control engine 200).

[0041] In some embodiments, for example, cloud system 106 can provide a private / proprietary management platform, whereby engine 200, discussed infra, corresponds to the novel functionality system 106 enables, hosts and provides to a network 104 and other devices / platforms operating thereon.

[0042] Turning to FIG. 4 and FIG. 5. in some embodiments, the exemplary computer-based systems / platforms, the exemplary computer-based devices, and / or the exemplary computer-9ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WO Electronically Filed: November 25, 2025 based components of the present disclosure may be specifically configured to operate in a cloud computing / architecture 106 such as. but not limiting to: infrastructure as a service (laaS) 510, platform as a service (PaaS) 508, and / or software as a service (SaaS) 506 using a web browser, mobile app, thin client, terminal emulator or other endpoint 504. FIG. 4 and FIG. 5 illustrate schematics of non-limiting implementations of the cloud computing / architecture(s) in which the exemplary computer-based systems for administrative customizations and control of network-hosted application program interfaces (APIs) of the present disclosure may be specifically configured to operate.

[0043] Turning back to FIG. 1, according to some embodiments, database 108 may correspond to a data storage for a platform (e.g., a network hosted platform, such as cloud system 106, as discussed supra) or a plurality of platforms. Database 108 may receive storage instructions / requests from, for example, engine 200 (and associated microsendees), which may be in any type of know n or to be known format, such as, for example, standard query7language (SQL). According to some embodiments, database 108 may correspond to any ty pe of known or to be known storage, for example, a memory or memory stack of a device, a distributed ledger of a distributed network (e.g., blockchain, for example), a look-up table (LUT), and / or any other type of secure data repository.

[0044] Control engine 200, as discussed above and further below7in more detail, can include components for the disclosed functionality. According to some embodiments, control engine 200 may be a special purpose machine or processor, and can be hosted by a device on network 104, within cloud system 106, on UE 102 and / or sensor(s) 110. In some embodiments, engine 200 may be hosted by a server and / or set of servers associated with cloud system 106.

[0045] According to some embodiments, as discussed in more detail below, control engine 200 may be configured to implement and / or control a plurality of services and / or microservices, where each of the plurality of services / microservices are configured to execute a plurality of workflow's associated with performing the disclosed device management. Non-limiting embodiments of such workflows are provided below7.

[0046] According to some embodiments, as discussed above, control engine 200 may function as an application provided by cloud system 106. In some embodiments, engine 200 may function as an application installed on a server(s), network location and / or other type of network resource associated with system 106. In some embodiments, engine 200 may function as an application installed and / or executing on UE 102 and / or sensors 110. In some embodiments, such application may be a web-based application accessed by UE 102 and / or10ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WO Electronically Filed: November 25, 2025 devices associated with sensors 110 over network 104 from cloud system 106. In some embodiments, engine 200 may be configured and / or installed as an augmenting script, program or application (e.g., a plug-in or extension) to another application or program provided by cloud system 106 and / or executing on UE 102 and / or sensors 110.

[0047] As illustrated in FIG. 2, according to some embodiments, control engine 200 includes identification module 202, analysis module 204. determination module 206 and output module 208. It should be understood that the engine(s) and modules discussed herein are non- exhaustive, as additional or fewer engines and / or modules (or sub-modules) may be applicable to the embodiments of the frameworks and methods discussed. More detail of the operations, configurations and functionalities of engine 200 and each of its modules, and their role within embodiments of the present disclosure will be discussed below.

[0048] Turning to FIG. 3, Process 300 provides non-limiting example embodiments for the disclosed sensor management framework (e.g., executable via engine, discussed infra). According to some embodiments, Process 300 provides non-limiting embodiments for automatically and / or dynamically controlling and managing zone sensor responses and activities based on detected events.

[0049] According to some embodiments, Steps 302-308 of Process 300 can be performed by identification module 202 of control engine 200; Step 310 can be performed by analysis module 204; Steps 312 and 314 can be performed by determination module 204; and Step 316 can be performed by output module 208.

[0050] According to some embodiments, Process 300 begins with Step 302 where engine 200 can perform data collection and sensor integration operations. Such collection can be performed according to a detected event, and / or monitoring of a location, which can be based on, but not limited to, time, location, a request, type of data / activity, a schedule, and the like. As discussed herein, the foundational stage of a security system involves comprehensive data collection across multiple sensor types and communication protocols. Such initial phase creates a rich, multi-dimensional sensor netw ork that captures granular environmental information.

[0051] According to some embodiments, each sensor type contributes unique data streams: motion sensors provide movement patterns, magnetic contact sensors monitor entry point status, glass break sensors detect acoustic signatures of potential intrusions, thermal imaging sensors measure temperature variations, and environmental sensors track humidity, air pressure, and other contextual parameters.11ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WOElectronically Filed: November 25, 2025

[0052] According to some embodiments, sensor placement can create detection zones, providing multiple verification points and reducing potential blind spots. Advanced sensors incorporate AI / ML capabilities, allowing them to distinguish between routine movements and potential security threats. For example, a motion sensor near a front door can leam to differentiate between expected household member movements and unfamiliar intrusion patterns.

[0053] In Step 304, engine 200 can perform zone definition and contextual mapping. That is, according to some embodiments, following data collection, engine 200 can enter a sophisticated zone definition process. As discussed above, a “zone” transcends traditional security demarcations, representing a dynamically configurable security space with unique behavioral characteristics. Each zone receives a comprehensive profile incorporating physical location, sensor types, historical behavior patterns, and potential interaction scenarios.

[0054] In some embodiments, engine 200 can perform zone mapping, which involves creating multi-dimensional representations that extend beyond physical boundaries. A bedroom zone, for example, can include not just window and door sensors, but also incorporate data from smart lighting, climate control systems, and personal devices to create a holistic understanding of ty pical occupancy and movement patterns.

[0055] In some embodiments, engine 200 can perform a contextual mapping process that generates a baseline behavioral model for each zone, establishing what constitutes “normal" versus “anomalous” activity. AI / ML algorithms can be called and executed to analyze historical data to create increasingly refined zone profiles, enabling the system to adapt to changing household dynamics and individual resident behaviors.

[0056] In some embodiments, such AI / ML analysis can involve engine 200 executing any type of known or to be known computational analysis technique, algorithm, mechanism or technology to analyze the collected data (e.g., historical data and / or data collected in Step 302).

[0057] In some embodiments, engine 200 may execute and / or include a specific trained AI / ML model, a particular machine learning model architecture, a particular machine learning model type (e.g., convolutional neural network (CNN), recurrent neural network (RNN). autoencoder, support vector machine (SVM), and the like), or any other suitable definition of a machine learning model or any suitable combination thereof.

[0058] In some embodiments, engine 200 may leverage a large language model (LLM), whether known or to be known. An LLM is a type of Al system designed to understand and generate human-like text based on the input it receives. The LLM can implement technology12ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WO Electronically Filed: November 25, 2025 that involves deep learning, training data, statistical language models (SLMs) and natural language processing (NLP). As discussed herein, such known or to be known SLMs and / or NLPs can be utilized for, but not limited to, machine translation, speech recognition, text / speech generation, sentiment analysis, conversational dialog, and the like, or some combination thereof, as is capable with LLMs. Large language models are built using deep learning techniques, specifically using a type of neural network called a transformer. These networks have many layers and millions or even billions of parameters. LLMs can be trained on vast amounts of text data from the internet, books, articles, and other sources to learn grammar, facts, and reasoning abilities. The training data helps them understand context and language patterns. LLMs can use NLP techniques to process and understand text. This includes tasks like tokenization, part-of-speech tagging, and named entity recognition.

[0059] LLMs can include functionality related to, but not limited to, text generation, language translation, text summarization, question answering, conversational Al, text classification, language understanding, content generation, and the like. Accordingly, LLMs can generate, comprehend, analyze and output human-like outputs (e.g., text, speech, audio, video, and the like) based on a given input, prompt or context. Accordingly, LLMs, which can be characterized as transformer-based LLMs, involve deep learning architectures that utilizes self-attention mechanisms and massive-scale pre-training on input data to achieve NLP understanding and generation. Such current and to-be-developed models can aid Al systems in handling human language and human interactions therefrom.

[0060] In some embodiments, engine 200 may be configured to utilize one or more AI / ML techniques chosen from, but not limited to, computer vision, feature vector analysis, decision trees, boosting, support-vector machines, neural networks, nearest neighbor algorithms, Naive Bayes, bagging, random forests, logistic regression, and the like. By way of a non-limiting example, engine 200 can implement an XGBoost algorithm for regression and / or classification to analyze the sensor data, as discussed herein.

[0061] In some embodiments and, optionally, in combination of any embodiment described above or below, a neural network technique may be one of. without limitation, feedforward neural network, radial basis function network, recunent neural network, convolutional network (e.g., U-net) or other suitable network. In some embodiments and, optionally, in combination of any embodiment described above or below, an implementation of Neural Network may be executed as follows: a. define Neural Network architecture / model,13ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WOElectronically Filed: November 25, 2025 b. transfer the input data to the neural network model, c. train the model incrementally, d. determine the accuracy for a specific number of timesteps, e. apply the trained model to process the newly -received input data, f. optionally and in parallel, continue to train the trained model with a predetermined periodicity’.

[0062] In some embodiments and, optionally, in combination of any embodiment described above or below, the trained neural network model may specify a neural network by at least a neural network topology, a series of activation functions, and connection yveights. For example, the topology of a neural netyvork may include a configuration of nodes of the neural network and connections between such nodes. In some embodiments and, optionally, in combination of any embodiment described above or below, the trained neural netyvork model may also be specified to include other parameters, including but not limited to, bias values / functions and / or aggregation functions. For example, an activation function of a node may be a step function, sine function, continuous or piecewise linear function, sigmoid function, hyperbolic tangent function, or other type of mathematical function that represents a threshold at which the node is activated. In some embodiments and, optionally, in combination of any embodiment described above or below, the aggregation function may be a mathematical function that combines (e.g.. sum, product, and the like) input signals to the node. In some embodiments and. optionally, in combination of any embodiment described above or beloyv, an output of the aggregation function may be used as input to the activation function. In some embodiments and, optionally, in combination of any embodiment described above or beloyv, the bias may be a constant value or function that may be used by the aggregation function and / or the activation function to make the node more or less likely to be activated.

[0063] In Step 306, engine 200 can perform operations for schedule and response profile generation. In some embodiments, yvith zones defined, engine 200 can generate sophisticated scheduling and response profiles. As discussed herein, Step 306's operation transforms static security’ configurations into dynamic, intelligent response mechanisms. Scheduling goes beyond simple time-based rules, incorporating contextual intelligence that considers multiple variables simultaneously.

[0064] In some embodiments, response profiles are multi-layered constructs allowing granular customization of system behavior. A profile can include primary and secondary response protocols, escalation mechanisms, and conditional triggers based on detected environmental14ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WOElectronically Filed: November 25, 2025 and behavioral variables. For example, a nighttime zone profile for a bedroom might have different sensitivity’ levels depending on whether occupants are sleeping, traveling, or the room is unoccupied.

[0065] According to some embodiments, engine 200 can support both manual user-defined configurations and autonomous AI / ML-driven adaptations. For example, users can establish baseline rules while allowing the system to refine and optimize these configurations based on continuous learning and observed patterns.

[0066] In Step 308, engine 200 can perform operations for continuous monitoring and data stream analysis. According to some embodiments, such monitoring stage represents the framework’s active surveillance phase, where collected sensor data is continuously processed and analyzed in real-time. Unlike traditional security systems that rely on simplistic tugger mechanisms, the disclosed framework performs sophisticated multi-variable analysis, comparing incoming data against established zone profiles and behavioral baselines.

[0067] According to some embodiments, such monitoring involves complex algorithmic processing that simultaneously evaluates multiple data streams. The framework does not just detect movement or entry point status, but interprets these signals within a broader contextual framework. For example, engine 200 can utilize any of the above mentioned AI / ML models to assess the probability of genuine security' threats versus benign environmental changes, reducing false alarm rates and increasing system reliability.

[0068] Moreover, in some embodiments, continuous monitoring extends beyond immediate threat detection, incorporating predictive analysis that can identify potential security’ vulnerabilities or emerging behavioral anomalies. In some embodiments, the framework can maintain a dynamic risk assessment model, continuously adjusting threat evaluation parameters based on evolving data insights.

[0069] In Step 310, engine 200 can perform anomaly detection and threat assessment operations to manage a location. According to some embodiments, anomaly detection represents a crucial evolutionary' step in security system intelligence. Rather than relying on rigid, predefined threat criteria, engine 200 employs advanced AI / ML algorithms (as discussed supra) to dynamically assess potential security risks. Step 310 can involve sophisticated pattern recognition techniques that go beyond traditional binary' threat classification.

[0070] In some embodiments, the threat assessment process employed by engine 200 can consider multiple variables simultaneously: sensor data integrity, historical behavioral patterns, time of day, external environmental conditions, detected movement characteristics, and the like.15ACTIVE 716851642v1Attorney Docket No. 203863-013401 / PCTResideo Ref. No. R214345-WOElectronically Filed: November 25, 2025AI / ML models generate probabilistic threat scores, enabling nuanced response mechanisms that can distinguish between minor irregularities and genuine security breaches.

[0071] Accordingly, in some embodiments, anomaly detection operations performed by engine 200 can incorporate both local zone-specific analysis and broader systemic threat evaluation. Thus, for example, engine 200 can identify not just immediate physical threats but also potential emerging risk patterns that might indicate future security challenges.

[0072] In Step 312, engine 200 can perform response protocol activation. According to some embodiments, upon detecting a potential security event, engine 200 can enter a carefully orchestrated response activation stage. Unlike traditional alarm systems that rely on uniform, aggressive responses, engine 200 can provide graduated, contextually intelligent reaction mechanisms.

[0073] In some embodiments, response protocols can be dynamically selected based on the detected threat’s characteristics, incorporating multiple potential intervention strategies. Such protocols can range from silent mobile alerts and localized warning signals to direct emergency service notifications or automated home defense mechanisms like strategic lighting activation or simulated occupancy generation.

[0074] Thus, as discussed herein, engine 200’s performance of Step 312 can involve response activation mechanisms that include sophisticated decision trees that evaluate multiple variables before triggering specific interventions. In some embodiments, AI / ML models can continuously refine these decision processes, improving response accuracy and reducing unnecessary escalations.

[0075] In Step 314, engine 200 can perform adaptive learning and system optimization operations. That is, for example, in some embodiments, following each security event or monitoring cycle, engine 200 can enter an adaptive learning phase designed to continuously improve its operational intelligence. This operational stage can involve comprehensive analysis of system performance, detected events, response effectiveness, and environmental variables.

[0076] According to some embodiments, AI / ML algorithms can process extensive data sets, identifying patterns, refining zone profiles, and optimizing future response mechanisms. In some embodiments, engine 200 can develop an increasingly sophisticated understanding of location dynamics, individual behavioral patterns, and potential security' challenges. Accordingly, such adaptive learning extends beyond immediate security optimization, supporting broader location automation and lifestyle integration. The framework can, therefore, progressively understand and anticipate resident needs, creating more intuitive and personalized16ACTIVE 716851642v1Attorney Docket No. 203863-013401 / PCTResideo Ref. No. R214345-WOElectronically Filed: November 25, 2025 security experiences, which can include zone determinations, scheduling and profile generation, protocol activation, and the like, as discussed above.

[0077] And, in Step 316, engine 200 can generate and provide a user interaction and control mechanisms based on operations of the preceding steps. As discussed above, unlike traditional security interfaces that offer limited configuration options, the disclosed framework provides computerized operations for deep customization and real-time system management.

[0078] According to some embodiments, engine 200 can provide a user interface (UI), which can be provided on a display screen of a UE, which as discussed above, can be a security panel, user device, and the like. Such UI can represent a sophisticated control center, offering multiple interaction modalities including mobile applications, web portals, and potential voice-activated or augmented reality interfaces. Users can access real-time zone status, configure complex rule sets, review historical performance data, and dynamically adjust system parameters. Thus, such UI and control mechanisms can enable the security system to be managed and secured via the zone determinations, scheduling and profile generation, protocol activation, and the like, as discussed above.

[0079] By way of a non-limiting example, according to some embodiments, engine 200 can provide functionality via the steps of Process 300, discussed supra, to perform sound output zone awareness modifications.

[0080] According to some embodiments, for example, engine 200 can enable dynamic modification of audio feedback for a specific zone without fully arming the security panel. For example, by changing the sound output from a simple chime to a continuous beep or full alarm, engine 200 creates an elevated awareness state that provides additional security alerting. Such operations can enable homeowners to maintain a heightened monitoring status for a particular area without triggering a complete system lockdown. The zone remains in a semi-active state, where any detected movement or sensor breach immediately generates a more aggressive auditory response, drawing immediate attention to potential security risks. This flexibility allows residents to customize their security' monitoring based on specific location needs or temporary risk assessments.

[0081] In another non-limiting example, in some embodiments, engine 200 can provide entry / exit zone conversion to perimeter zone during vacation operations. For example, during an extended absence, a homeowner can strategically reconfigure zone classifications to optimize security coverage. By maintaining the main front door as an entry / exit zone while converting other less-visible doors (back and side entrances) to perimeter zones, engine 20017ACTIVE 716851642v1Attorney Docket No. 203863-013401 / PCTResideo Ref. No. R214345-WOElectronically Filed: November 25, 2025 creates a nuanced security approach. Perimeter zones typically have more stringent monitoring protocols, with sensor breaches triggering immediate high-priority alerts. This configuration ensures that while the primary street-facing entrance maintains standard entry / exit monitoring, secondary and less-observ able entry points receive more aggressive security tracking. The approach recognizes that different location points have vary ing visibility' and risk profiles, allowing for intelligent, targeted security management that adapts to specific environmental contexts.

[0082] And, in yet another non-limiting example, in some embodiments, engine 200 can provide restricted area immediate alert configuration operations / functionality.

[0083] This configuration enables immediate notification for a specific zone without requiring the entire security system to be armed. For example, by designating a restricted area with an instantaneous alert mechanism, engine 200 can provide real-time notifications the moment any' sensor in that zone is triggered. Unlike traditional security' setups that require full system activation, this approach allows for granular, targeted monitoring of sensitive locations. For example, a homeowner can set up immediate alerts for a home office, gun safe, or medication storage area, ensuring instant notification of any unauthorized access attempts, regardless of the security system’s armed status. As provided above, such functionalities can provide an additional layer of security for high-value or potentially dangerous areas, offering peace of mind and rapid response capabilities.

[0084] Accordingly, as discussed herein, the disclosed systems and methods provide transformative mechanisms to security system design. By integrating advanced AI / ML capabilities, sophisticated sensor technologies and adaptive intelligence, the disclosed security' framework transcends traditional security' models by providing a dynamic, intelligent protection ecosystem that learns, adapts and responds with unprecedented precision and contextual awareness. Moreover, the framework’s modular design ensures scalability and future adaptability, providing a security' system with next-generation intelligent security solutions for how a location’s security strategies can be conceptualized and implemented.

[0085] FIG. 6 is a schematic diagram illustrating a client device showing an example embodiment of a client device that may be used within the present disclosure. Client device 600 may include many more or less components than those shown in FIG. 6. However, the components shown are sufficient to disclose an illustrative embodiment for implementing the present disclosure. Client device 600 may represent, for example, UE 102 discussed above at least in relation to FIG. 1.18ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WOElectronically Filed: November 25, 2025

[0086] As shown in the figure, in some embodiments, Client device 600 includes a processing unit (CPU) 622 in communication with a mass memory 630 via a bus 624. Client device 600 also includes a power supply 626, one or more network interfaces 650, an audio interface 652, a display 654, a keypad 656, an illuminator 658, an input / output interface 660, a haptic interface 662, an optional global positioning systems (GPS) receiver 664 and a camera(s) or other optical, thermal or electromagnetic sensors 666. Device 600 can include one camera / sensor 666, or a plurality of cameras / sensors 666, as understood by those of skill in the art. Power supply 626 provides power to Client device 600.

[0087] Client device 600 may optionally communicate with a base station (not shown), or directly with another computing device. In some embodiments, network interface 650 is sometimes known as a transceiver, transceiving device, or network interface card (NIC).

[0088] Audio interface 652 is arranged to produce and receive audio signals such as the sound of a human voice in some embodiments. Display 654 may be a liquid crystal display (LCD), gas plasma, light emitting diode (LED), or any other ty pe of display used with a computing device. Display 654 may also include a touch sensitive screen arranged to receive input from an object such as a stylus or a digit from a human hand.

[0089] Keypad 656 may include any input device arranged to receive input from a user. Illuminator 658 may provide a status indication and / or provide light.

[0090] Client device 600 also includes input / output interface 660 for communicating with external. Input / output interface 660 can utilize one or more communication technologies, such as USB, infrared, Bluetooth™, or the like in some embodiments. Haptic interface 662 is arranged to provide tactile feedback to a user of the client device.

[0091] Optional GPS transceiver 664 can determine the physical coordinates of Client device 600 on the surface of the Earth, which typically outputs a location as latitude and longitude values. GPS transceiver 664 can also employ other geo-positioning mechanisms, including, but not limited to, triangulation, assisted GPS (AGPS), E-OTD, CI, SAI, ETA, BSS or the like, to further determine the physical location of client device 600 on the surface of the Earth. In one embodiment, however, Client device 600 may through other components, provide other information that may be employed to determine a physical location of the device, including for example, a MAC address, Internet Protocol (IP) address, or the like.

[0092] Mass memory7630 includes a RAM 632, a ROM 634, and other storage means. Mass memory 630 illustrates another example of computer storage media for storage of information such as computer readable instructions, data structures, program modules or other data. Mass19ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WOElectronically Filed: November 25, 2025 memory 630 stores a basic input / output system (“BIOS”) 640 for controlling low-level operation of Client device 600. The mass memory also stores an operating system 641 for controlling the operation of Client device 600.

[0093] Memory 630 further includes one or more data stores, which can be utilized by Client device 600 to store, among other things, applications 642 and / or other information or data. For example, data stores may be employed to store information that describes various capabilities of Client device 600. The information may then be provided to another device based on any of a variety of events, including being sent as part of a header (e.g., index file of the HLS stream) during a communication, sent upon request, or the like. At least a portion of the capability information may also be stored on a disk drive or other storage medium (not shown) within Client device 600.

[0094] Applications 642 may include computer executable instructions which, when executed by Client device 600, transmit, receive, and / or otherwise process audio, video, images, and enable telecommunication with a server and / or another user of another client device. Applications 642 may further include a client that is configured to send, to receive, and / or to otherwise process gaming, goods / services and / or other forms of data, messages and content hosted and provided by the platform associated with engine 200 and its affiliates.

[0095] As used herein, the terms “computer engine” and “engine” identify at least one software component and / or a combination of at least one software component and at least one hardware component which are designed / programmed / configured to manage / control other software and / or hardware components (such as the libraries, software development kits (SDKs), objects, and the like).

[0096] Examples of hardware elements may include processors, microprocessors, circuits, circuit elements (e.g.. transistors, resistors, capacitors, inductors, and so forth), integrated circuits, application specific integrated circuits (ASIC), programmable logic devices (PLD), digital signal processors (DSP), field programmable gate array (FPGA), logic gates, registers, semiconductor device, chips, microchips, chip sets, and so forth. In some embodiments, the one or more processors may be implemented as a Complex Instruction Set Computer (CISC) or Reduced Instruction Set Computer (RISC) processors; x86 instruction set compatible processors, multi-core, or any other microprocessor or central processing unit (CPU). In various implementations, the one or more processors may be dual-core processor(s), dual-core mobile processor(s), and so forth.20ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WO Electronically Filed: November 25, 2025

[0097] Computer-related systems, computer systems, and systems, as used herein, include any combination of hardware and software. Examples of software may include software components, programs, applications, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, procedures, software interfaces, application program interfaces (API), instruction sets, computer code, computer code segments, words, values, symbols, or any combination thereof. Determining whether an embodiment is implemented using hardware elements and / or software elements may vary in accordance with any number of factors, such as desired computational rate, power levels, heat tolerances, processing cycle budget, input data rates, output data rates, memory resources, data bus speeds and other design or performance constraints.

[0098] For the purposes of this disclosure a module is a software, hardware, or firmware (or combinations thereof) system, process or functionality, or component thereof, that performs or facilitates the processes, features, and / or functions described herein (with or without human interaction or augmentation). A module can include sub-modules. Software components of a module may be stored on a computer readable medium for execution by a processor. Modules may be integral to one or more servers, or be loaded and executed by one or more servers. One or more modules may be grouped into an engine or an application.

[0099] One or more aspects of at least one embodiment may be implemented by representative instructions stored on a machine-readable medium which represents various logic within the processor, which when read by a machine causes the machine to fabricate logic to perform the techniques described herein. Such representations, known as “IP cores,” may be stored on a tangible, machine readable medium and supplied to various customers or manufacturing facilities to load into the fabrication machines that make the logic or processor. Of note, various embodiments described herein may, of course, be implemented using any appropriate hardware and / or computing software languages (e.g., C++, Objective-C, Swift, Java, JavaScript, Python, Perl, QT, and the like).

[0100] For example, exemplary software specifically programmed in accordance with one or more principles of the present disclosure may be downloadable from a network, for example, a website, as a stand-alone product or as an add-in package for installation in an existing software application. For example, exemplary software specifically programmed in accordance with one or more principles of the present disclosure may also be available as a client-server software application, or as a web-enabled software application. For example,21ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WO Electronically Filed: November 25, 2025 exemplary software specifically programmed in accordance with one or more principles of the present disclosure may also be embodied as a software package installed on a hardware device.

[0101] For the purposes of this disclosure the term “user”, “subscriber” “consumer” or “customer” should be understood to refer to a user of an application or applications as described herein and / or a consumer of data supplied by a data provider. By way of example, and not limitation, the term “user” or “subscriber” can refer to a person who receives data provided by the data or service provider over the Internet in a browser session, or can refer to an automated software application which receives the data and stores or processes the data. Those skilled in the art will recognize that the methods and systems of the present disclosure may be implemented in many manners and as such are not to be limited by the foregoing exemplary embodiments and examples. In other words, functional elements being performed by single or multiple components, in various combinations of hardware and software or firmware, and individual functions, may be distributed among software applications at either the client level or server level or both. In this regard, any number of the features of the different embodiments described herein may be combined into single or multiple embodiments, and alternate embodiments having fewer than, or more than, all of the features described herein are possible.

[0102] Functionality may also be, in whole or in part, distributed among multiple components, in manners now known or to become known. Thus, myriad software / hardware / firmware combinations are possible in achieving the functions, features, interfaces and preferences described herein. Moreover, the scope of the present disclosure covers conventionally known manners for carrying out the described features and functions and interfaces, as well as those variations and modifications that may be made to the hardw are or software or firmware components described herein as would be understood by those skilled in the art now and hereafter.

[0103] Furthermore, the embodiments of methods presented and described as flow-charts in this disclosure are provided by way of example in order to provide a more complete understanding of the technology. The disclosed methods are not limited to the operations and logical flow presented herein. Alternative embodiments are contemplated in w hich the order of the various operations is altered and in which sub-operations described as being part of a larger operation are performed independently.

[0104] While various embodiments have been described for purposes of this disclosure, such embodiments should not be deemed to limit the teaching of this disclosure to those embodiments. Various changes and modifications may be made to the elements and operations22ACTIVE 716851642v1Attorney Docket No. 203863-013401 / PCTResideo Ref. No. R214345-WO Electronically Filed: November 25, 2025 described above to obtain a result that remains within the scope of the systems and processes described in this disclosure.23ACTIVE 716851642v1

Claims

Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WOElectronically Filed: November 25, 2025CLAIMSWhat is claimed is:

1. A method comprising: receiving, by a device, information related to a zone of a location, the zone corresponding an area of the location, the area associated with a sensor of a security' system for the location; identifying, by the device, schedule information for the zone, the schedule information comprising executable instructions for the sensor to perform during a time period; monitoring, by the device, via the schedule information, the location and collecting data; detecting, by the device, based on the schedule information-based monitoring, an anomaly, the anomaly corresponding to a presence or non-presence of an activity at the location as detected via the sensor; and performing, by the device, in accordance with the schedule information, sensor-based response activation, the sensor-based response activation providing an output at least at the location related to the anomaly as dictated by the schedule information.

2. The method of claim 1, further comprising: modifying, based on the schedule information, preset configuration of the sensor for the zone; and causing the sensor-based response activation to operate based on the modified preset configuration.

3. The method of claim 1, further comprising the schedule information further comprising controls for output of at least one of the device or sensor.

4. The method of claim 1, further comprising the schedule information further comprising modified protocols for responding to a ty pe of detected activity', wherein the performance response activation is based on the modified protocols.

5. The method of claim 1, further comprising: analyzing the collected data; and24ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WO Electronically Filed: November 25, 2025 determining, based on the analysis of the collected data, the instructions of the schedule information for the time period.

6. The method of claim 5, further comprising the analysis and determination being performed via a machine learning (ML) model executed by the device.

7. The method of claim 1, further comprising the schedule information being provided as input to the device.

8. The method of claim 1, wherein the device is a security panel of the security system.

9. A device comprising: a processor configured to: receive information related to a zone of a location, the zone corresponding an area of the location, the area associated with a sensor of a security system for the location; identify schedule information for the zone, the schedule information comprising executable instructions for the sensor to perform during a time period; monitor, via the schedule information, the location and collect data; detect, based on the schedule information-based monitoring, an anomaly, the anomaly corresponding to a presence or non-presence of an activity at the location as detected via the sensor; and perform, in accordance with the schedule information, sensor-based response activation, the sensor-based response activation providing an output at least at the location related to the anomaly as dictated by the schedule information.

10. The device of claim 9, wherein the processor is further configured to: modify, based on the schedule information, preset configuration of the sensor for the zone; and cause the sensor-based response activation to operate based on the modified preset configuration.25ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WO Electronically Filed: November 25, 202511. The device of claim 9, wherein the processor is further configured such that the schedule information further comprises controls for output of at least one of the device or sensor.

12. The device of claim 9, wherein the processor is further configured such that the schedule information further comprises modified protocols for responding to a type of detected activity, wherein the performance response activation is based on the modified protocols.

13. The device of claim 9, wherein the processor is further configured to: analyze, via a machine learning (ML) model, the collected data: and determine, based on the ML-analysis of the collected data, the instructions of the schedule information for the time period.

14. The device of claim 9, wherein the processor is further configured such that the schedule information is provided as input to the device.

15. The device of claim 9, wherein the processor is further configured such that the device is a security panel of the security system.

16. A non-transitory computer-readable storage medium tangibly encoded with computer-executable instructions that when executed by a device, perform a method comprising: receiving, by the device, information related to a zone of a location, the zone corresponding an area of the location, the area associated with a sensor of a security system for the location; identifying, by the device, schedule information for the zone, the schedule information comprising executable instructions for the sensor to perform during a time period; monitoring, by the device, via the schedule information, the location and collecting data; detecting, by the device, based on the schedule information-based monitoring, an anomaly, the anomaly corresponding to a presence or non-presence of an activity' at the location as detected via the sensor; and26ACTIVE 716851642v1Attorney Docket No. 203863-013401ZPCTResideo Ref. No. R214345-WO Electronically Filed: November 25, 2025 performing, by the device, in accordance with the schedule information, sensor-based response activation, the sensor-based response activation providing an output at least at the location related to the anomaly as dictated by the schedule information.

17. The non-transitory computer-readable storage medium of claim 16, further comprising: modifying, based on the schedule information, preset configuration of the sensor for the zone; and causing the sensor-based response activation to operate based on the modified preset configuration.

18. The non-transitory computer-readable storage medium of claim 16, further comprising the schedule information further comprising controls for output of at least one of the device or sensor.

19. The non-transitory computer-readable storage medium of claim 16, further comprising the schedule information further comprising modified protocols for responding to a type of detected activity7, wherein the performance response activation is based on the modified protocols.

20. The non-transitory computer-readable storage medium of claim 16, further comprising: analyzing, via a machine learning (ML) model, the collected data; and determining, based on the ML-analysis of the collected data, the instructions of the schedule information for the time period.27ACTIVE 716851642v1

Citation Information

Patent Citations

  • Home automation system determining deviated operation device pattern and related methods

    US20200294380A1

  • Non-intrusive monitoring system

    US20230263393A1