A safety monitoring method and device, electronic equipment and storage medium

By dividing objects into groups based on location within a target area and combining category, situation, and environmental parameters, a threat assessment model is used to calculate the threat value of the object groups, thus solving the problem of inaccurate security monitoring in existing technologies and achieving accurate security monitoring in complex scenarios.

CN116824494BActive Publication Date: 2026-03-31CHINA ORDNANCE SCI INST
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-25
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In existing technologies, it is difficult to accurately monitor security based on object categories, especially in complex scenarios where security threats cannot be accurately identified.

Method used

By dividing objects in the target area into multiple object combinations based on their location, and comprehensively considering object category information, situational information, environmental parameters, and monitoring tasks, a preset threat assessment model is used to calculate the target threat value of the object combination for security monitoring.

Benefits of technology

It enables accurate assessment of the threat level of a single object or multiple aggregated objects under specific tasks and environments, improving the accuracy and efficiency of security monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116824494B_ABST
    Figure CN116824494B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a kind of security monitoring method, device, electronic equipment and storage medium, the method comprises: based on the position of each object in target area, all objects in target area are divided into multiple object combinations;For any object combination, based on the category information of each object in object combination, the situation information of each object in object combination, the environmental parameter corresponding to target area and the target monitoring task corresponding to target area, determine the target threat value of threat degree of object combination;Based on the target threat value corresponding to all object combinations in target area, the security of target area is monitored.Based on position, the object in target area is divided into multiple object combinations, and individual object and aggregated object are distinguished;By comprehensively considering multiple factors, the target threat value that accurately reflects the threat degree of single object or multiple aggregated objects in specific task and specific environment is obtained, so as to accurately monitor the security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security defense technology, and in particular to a security monitoring method, device, electronic device and storage medium. Background Technology

[0002] With increasing security awareness across various sectors, security monitoring is required in many scenarios. By identifying and analyzing security threats, appropriate measures can be taken for security defense.

[0003] In related technologies, objects in a specific area are identified and tracked, and security analysis is performed based on the object categories to identify objects that pose a security threat. For example, the presence of dangerous weapons such as knives or guns in the area indicates a security threat.

[0004] However, the scenarios involved in practical applications are complex, and it is difficult to accurately monitor security based solely on the category of the object. Summary of the Invention

[0005] This application provides a security monitoring method, apparatus, electronic device, and storage medium for accurate security monitoring.

[0006] In a first aspect, embodiments of this application provide a security monitoring method, including:

[0007] Based on the location of each object in the target area, all objects in the target area are divided into multiple object groups; wherein each object group includes one or more objects.

[0008] For any combination of objects, a target threat value characterizing the threat level of the combination of objects is determined based on the category information of each object in the combination, the situation information of each object in the combination, the environmental parameters corresponding to the target area, and the target monitoring task corresponding to the target area.

[0009] Security monitoring is performed on the target area based on the target threat value corresponding to all object combinations in the target area.

[0010] The above scheme addresses the issue that the threat level may differ depending on whether an object participates alone or in a cluster. By dividing objects in the target area into multiple object groups based on their location, it distinguishes between individual objects and aggregated objects. Since object category information is only one aspect of characterizing the threat level of an object, by comprehensively considering various factors such as the object's inherent attributes (category information), attributes formed during movement (situational information), the influence of the current environmental parameters of the target area, and the requirements of different monitoring tasks, a target threat value is obtained that accurately reflects the threat level of a single object or multiple aggregated objects in a specific task and environment. Therefore, based on this target threat value, security monitoring of the target area can be carried out more accurately.

[0011] In some optional implementations, a target threat value characterizing the threat level of the object combination is determined based on the category information of each object in the object combination, the situational information of each object in the object combination, the environmental parameters corresponding to the target area, and the target monitoring task corresponding to the target area, including:

[0012] If the object combination includes an object, then determine the first attribute value corresponding to the object's category information and the second attribute value corresponding to the object's situation information; or

[0013] If the object combination includes multiple objects, then based on the target category information and the first adjustment value, a first attribute value corresponding to the object combination is determined; and based on the target posture information and the second adjustment value, a second attribute value corresponding to the object combination is determined; wherein, the target category information is the most frequent category information in the object combination, and the target posture information is the most frequent posture information in the object combination;

[0014] Based on the first attribute value, the second attribute value, the environmental parameters, and the target monitoring task, the target threat value corresponding to the object combination is determined.

[0015] The above scheme, since category information is an inherent attribute of the object and situational information is an attribute formed during the object's movement (not a specific numerical value), quantifies these two pieces of information and incorporates them into subsequent calculations to accurately determine the target threat value.

[0016] In some optional implementations, the target threat value corresponding to the object combination is determined based on the first attribute value, the second attribute value, the environmental parameters, and the target monitoring task, including:

[0017] Select the target threat assessment model corresponding to the target monitoring task from the preset threat assessment models; wherein, different preset threat assessment models correspond to different monitoring tasks;

[0018] The first attribute value, the second attribute value, and the environmental parameters are input into the target threat assessment model, and the target threat value corresponding to the object combination is output by the target threat assessment model.

[0019] The above scheme trains different preset threat assessment models for different monitoring tasks. By using the target threat assessment models corresponding to the target monitoring tasks, the target threat values ​​corresponding to each combination of objects can be determined accurately and efficiently.

[0020] In some optional implementations, the target threat value corresponding to the object combination is determined based on the first attribute value, the second attribute value, the environmental parameters, and the target monitoring task, including:

[0021] Based on the weight coefficients corresponding to the target monitoring task, the first attribute value and the second attribute value are weighted and summed to obtain the initial threat value;

[0022] Based on the adjustment coefficients corresponding to the environmental parameters, the initial threat value is adjusted to obtain the target threat value corresponding to the object combination.

[0023] The above scheme obtains an initial threat value under the influence of the task (in conjunction with the specific monitoring task) by setting weight coefficients corresponding to different monitoring tasks and using the weight coefficients corresponding to the target monitoring task to perform a weighted sum of the first attribute value and the second attribute value; by setting adjustment coefficients corresponding to different environmental parameters and using the adjustment coefficients corresponding to the environmental parameters of the target area, the above initial threat value is adjusted to obtain a target threat value under the influence of the environment (in conjunction with the specific environment).

[0024] In some optional implementations, security monitoring of the target area is performed based on the target threat value corresponding to all object combinations in the target area, including:

[0025] The target threat value corresponding to each object combination in the target area is compared with a preset value.

[0026] If the target threat value corresponding to a combination of objects is greater than or equal to the preset value, then the information indicating that the combination of objects poses a security threat will be notified through the first preset notification method.

[0027] The above scheme compares the target threat value corresponding to each object combination with a preset value. If the target threat value corresponding to an object combination is greater than or equal to the preset value, it indicates that the threat level of the object combination is high. By notifying relevant personnel of the information indicating that the object combination has a security threat, the scheme enables them to promptly perceive the object combination with a high threat level in the target area, thereby achieving local security monitoring for each object combination.

[0028] In some optional implementations, security monitoring of the target area is performed based on the target threat value corresponding to all object combinations in the target area, including:

[0029] The target threat value distribution in the target area is compared with the preset threat value distribution corresponding to each preset event;

[0030] If the similarity between the preset threat value distribution corresponding to a preset event and the target threat value distribution is greater than or equal to the preset similarity, then the preset event and the corresponding security policy will be notified through the second preset notification method.

[0031] The above scheme establishes a preset threat value distribution for some representative preset events; then compares the target threat value distribution in the target area with the preset threat value distribution corresponding to each preset event to determine the similarity between the preset threat value distribution and the target threat value distribution; if the similarity between the preset threat value distribution and the target threat value distribution is greater than or equal to the preset similarity, it indicates that a preset event may have occurred in the target area; by identifying the preset event corresponding to the preset threat value as the current event in the target area, and notifying the corresponding security policy, relevant personnel can promptly perceive the current event in the target area and efficiently obtain the security policy to deal with the event, thus achieving overall security monitoring of the target area.

[0032] In some optional implementations, based on the position of each object in the target area, all objects in the target area are divided into multiple object groups, including:

[0033] Based on the location of each object in the target region, all objects in the target region are clustered to obtain a cluster set and outliers that are not in the cluster set;

[0034] Each cluster set is used as a first object combination, and each outlier is used as a second object combination; wherein, the first object combination includes multiple objects, and the second object combination includes one object.

[0035] The above scheme clusters objects in the target area, accurately classifying each object in the target area into different object groups according to its location.

[0036] Secondly, embodiments of this application provide a security monitoring device, including:

[0037] The object partitioning module is used to divide all objects in the target area into multiple object combinations based on the position of each object in the target area; wherein any object combination includes one or more objects;

[0038] The threat value determination module is used to determine a target threat value that characterizes the threat level of any object combination based on the category information of each object in the object combination, the situation information of each object in the object combination, the environmental parameters corresponding to the target area, and the target monitoring task corresponding to the target area.

[0039] The monitoring module is used to perform security monitoring on the target area based on the target threat value corresponding to all object combinations in the target area.

[0040] In some optional implementations, the threat value determination module is specifically used for:

[0041] If the object combination includes an object, then determine the first attribute value corresponding to the object's category information and the second attribute value corresponding to the object's situation information; or

[0042] If the object combination includes multiple objects, then based on the target category information and the first adjustment value, a first attribute value corresponding to the object combination is determined; and based on the target posture information and the second adjustment value, a second attribute value corresponding to the object combination is determined; wherein, the target category information is the most frequent category information in the object combination, and the target posture information is the most frequent posture information in the object combination;

[0043] Based on the first attribute value, the second attribute value, the environmental parameters, and the target monitoring task, the target threat value corresponding to the object combination is determined.

[0044] In some optional implementations, the threat value determination module is specifically used for:

[0045] Select the target threat assessment model corresponding to the target monitoring task from the preset threat assessment models; wherein, different preset threat assessment models correspond to different monitoring tasks;

[0046] The first attribute value, the second attribute value, and the environmental parameters are input into the target threat assessment model, and the target threat value corresponding to the object combination is output by the target threat assessment model.

[0047] In some optional implementations, the threat value determination module is specifically used for;

[0048] Based on the weight coefficients corresponding to the target monitoring task, the first attribute value and the second attribute value are weighted and summed to obtain the initial threat value;

[0049] Based on the adjustment coefficients corresponding to the environmental parameters, the initial threat value is adjusted to obtain the target threat value corresponding to the object combination.

[0050] In some alternative implementations, the monitoring module is specifically used for:

[0051] The target threat value corresponding to each object combination in the target area is compared with a preset value.

[0052] If the target threat value corresponding to a combination of objects is greater than or equal to the preset value, then the information indicating that the combination of objects poses a security threat will be notified through the first preset notification method.

[0053] In some alternative implementations, the monitoring module is specifically used for:

[0054] The target threat value distribution in the target area is compared with the preset threat value distribution corresponding to each preset event;

[0055] If the similarity between the preset threat value distribution corresponding to a preset event and the target threat value distribution is greater than or equal to the preset similarity, then the preset event and the corresponding security policy will be notified through the second preset notification method.

[0056] In some optional implementations, the object partitioning module is specifically used for:

[0057] Based on the location of each object in the target region, all objects in the target region are clustered to obtain a cluster set and outliers that are not in the cluster set;

[0058] Each cluster set is used as a first object combination, and each outlier is used as a second object combination; wherein, the first object combination includes multiple objects, and the second object combination includes one object.

[0059] Thirdly, embodiments of this application provide an electronic device, the electronic device including at least one processor and at least one memory, wherein the memory stores a computer program, and when the program is executed by the processor, the processor performs any of the security monitoring methods described in the first aspect above.

[0060] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program executable by an electronic device, which, when run on the electronic device, causes the electronic device to perform any of the security monitoring methods described in the first aspect above.

[0061] Furthermore, the technical effects of any of the implementation methods in aspects two to four can be found in the technical effects of different implementation methods in aspect one, and will not be repeated here. Attached Figure Description

[0062] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0063] Figure 1 A flowchart illustrating the first security monitoring method provided in this application embodiment;

[0064] Figure 2 This is a schematic diagram of the object distribution in the target area provided in an embodiment of this application;

[0065] Figure 3 A flowchart illustrating the second security monitoring method provided in this application embodiment;

[0066] Figure 4 A flowchart illustrating the third security monitoring method provided in this application embodiment;

[0067] Figure 5 A flowchart illustrating the fourth security monitoring method provided in this application embodiment;

[0068] Figure 6 A flowchart illustrating the fifth security monitoring method provided in this application embodiment;

[0069] Figure 7 This is a schematic diagram of the structure of a safety monitoring device provided in an embodiment of this application;

[0070] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0071] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0072] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0073] Security monitoring is required in many scenarios. By identifying and analyzing security threats, appropriate measures can be taken to defend against them.

[0074] In related technologies, objects in a specific area are identified and tracked, and security analysis is performed based on the object categories to identify objects that pose a security threat. For example, the presence of dangerous weapons such as knives or guns in the area indicates a security threat.

[0075] However, the scenarios involved in practical applications are complex, and it is difficult to accurately monitor security based solely on the category of the object.

[0076] In view of this, embodiments of this application propose a security monitoring method, device, electronic device, and storage medium. The method includes: dividing all objects in a target area into multiple object combinations based on the location of each object in the target area; wherein any object combination includes one or more objects; for any object combination, determining a target threat value characterizing the threat level of the object combination based on the category information of each object in the object combination, the situational information of each object in the object combination, the environmental parameters corresponding to the target area, and the target monitoring task corresponding to the target area; and performing security monitoring on the target area based on the target threat values ​​corresponding to all object combinations in the target area.

[0077] The above scheme addresses the issue that the threat level may differ depending on whether an object participates alone or in a cluster. By dividing objects in the target area into multiple object groups based on their location, it distinguishes between individual objects and aggregated objects. Since object category information is only one aspect of characterizing the threat level of an object, by comprehensively considering various factors such as the object's inherent attributes (category information), attributes formed during movement (situational information), the influence of the current environmental parameters of the target area, and the requirements of different monitoring tasks, a target threat value is obtained that accurately reflects the threat level of a single object or multiple aggregated objects in a specific task and environment. Therefore, based on this target threat value, security monitoring of the target area can be carried out more accurately.

[0078] The technical solution of this application and how it solves the above-mentioned technical problems will be described in detail below with reference to the accompanying drawings and specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0079] Figure 1 This is a flowchart illustrating the first security monitoring method provided in this application embodiment, applied to electronic devices, such as... Figure 1 As shown, it includes the following steps:

[0080] Step S101: Based on the position of each object in the target area, divide all objects in the target area into multiple object combinations.

[0081] Any combination of objects includes one or more objects.

[0082] In this embodiment, for target areas that require security monitoring, relevant information about objects in the target area is collected by acquisition devices (such as various sensors). For example, images of the target area are captured by an infrared camera or a red-green-blue (RGB) camera. Based on the captured images, the electronic device determines the location, category information, and situation information of each object in the target area.

[0083] Because within the target area, some objects may act as a group, such as gathering to dance in a park or engaging in group combat on a battlefield;

[0084] See Figure 2 As shown, each point represents an object. Objects A, B, and C are far from other objects and have not aggregated with other objects. Objects E, F, and G are very close and are likely to have aggregated together to participate in a common activity. Objects H, I, J, and K are also very close and are likely to have aggregated together to participate in a common activity.

[0085] For the same activity, the threat level can vary depending on whether there is only one object or multiple objects clustered together. Based on this, this embodiment divides these objects into multiple object groups based on the location of each object in the target area, thus distinguishing between individual objects and aggregated objects.

[0086] Step S102: For any object combination, based on the category information of each object in the object combination, the situation information of each object in the object combination, the environmental parameters corresponding to the target area, and the target monitoring task corresponding to the target area, determine the target threat value that characterizes the threat level of the object combination.

[0087] In practice, object category information is only one aspect of characterizing the threat level of an object. The object's situation (such as speed, posture, and direction of movement) also affects its threat level. The current environmental parameters of the target area (day and night, temperature, weather, etc.) also affect the threat level of the object. For example, the threat level of starting a fire during the day is different from that of starting a fire at night (at night it may only be used for lighting), and the threat level of starting a fire in the rain is different from that in the sunshine (it is difficult to ignite items in the rain, and it may only be used for smoking). The monitoring tasks of the target area also affect the threat level of the object. For example, the threat level of starting a fire in a forest is different from that of starting a fire in a park.

[0088] Based on this, this embodiment takes into account the inherent attributes of the object (category information) and the attributes formed during the movement (situational information); it also takes into account the influence of the current environmental parameters of the target area and the requirements in different monitoring tasks. By combining these multiple factors, a target threat value that accurately reflects the threat level of a single object or multiple aggregated objects in a specific task and under a specific environment is obtained.

[0089] Step S103: Based on the target threat value corresponding to all object combinations in the target area, perform security monitoring on the target area.

[0090] The above scheme addresses the issue that the threat level may differ depending on whether an object participates alone or in a cluster. By dividing objects in the target area into multiple object groups based on their location, it distinguishes between individual objects and aggregated objects. Since object category information is only one aspect of characterizing the threat level of an object, by comprehensively considering various factors such as the object's inherent attributes (category information), attributes formed during movement (situational information), the influence of the current environmental parameters of the target area, and the requirements of different monitoring tasks, a target threat value is obtained that accurately reflects the threat level of a single object or multiple aggregated objects in a specific task and environment. Therefore, based on this target threat value, security monitoring of the target area can be carried out more accurately.

[0091] Figure 3 A flowchart illustrating the second security monitoring method provided in this application embodiment is shown below. Figure 3 As shown, it includes the following steps:

[0092] Step S301: Based on the location of each object in the target region, cluster all objects in the target region to obtain a cluster set and outliers not in the cluster set.

[0093] In practice, by clustering objects in the target area, multiple aggregated objects in the cluster set are obtained, as well as outliers that are not in any cluster set, that is, single objects that do not participate in the aggregation.

[0094] This embodiment does not limit the specific clustering method. For example, a density-based clustering algorithm (Density-Based Spatial Clustering of Applications with Noise, DBSCAN) can be used to gradually aggregate and divide objects in the target area into multiple cluster sets.

[0095] Step S302: Combine each cluster set as a first object group and each outlier point as a second object group.

[0096] The first object combination includes multiple objects, and the second object combination includes one object.

[0097] In this embodiment, by clustering objects in the target area, multiple aggregated objects are obtained in the cluster set. Each cluster set can be determined as a first object combination, and any first object combination includes multiple aggregated objects.

[0098] Outliers that are not in any cluster set are identified as second object combinations, and each second object combination includes one object.

[0099] As mentioned above Figure 2 For example, objects E, F, and G are very close to each other, as are objects H, I, J, and K, while objects A, B, and C are relatively far from the other objects. By clustering these objects, we obtain cluster set 1 (including objects E, F, and G) and cluster set 2 (including objects H, I, J, and K). These two cluster sets are each considered as a first object group. Objects A, B, and C do not belong to any cluster set, and are each considered as a second object group.

[0100] Step S303: For any object combination, based on the category information of each object in the object combination, the situation information of each object in the object combination, the environmental parameters corresponding to the target area, and the target monitoring task corresponding to the target area, determine the target threat value that characterizes the threat level of the object combination.

[0101] Step S304: Based on the target threat value corresponding to all object combinations in the target area, perform security monitoring on the target area.

[0102] The specific implementation of steps S303 to S304 can be found in other embodiments, and will not be repeated here.

[0103] The above scheme clusters objects in the target area, accurately classifying each object in the target area into different object groups according to its location.

[0104] Figure 4 A flowchart illustrating the third security monitoring method provided in this application embodiment is shown below. Figure 4 As shown, it includes the following steps:

[0105] Step S401: Based on the position of each object in the target area, divide all objects in the target area into multiple object combinations.

[0106] Any combination of objects includes one or more objects.

[0107] The specific implementation of step S401 can be found in the above embodiments, and will not be repeated here.

[0108] Step S402: For any object combination, if the object combination includes one object, determine the first attribute value corresponding to the object's category information and the second attribute value corresponding to the object's situation information; if the object combination includes multiple objects, determine the first attribute value corresponding to the object combination based on the target category information and the first adjustment value; and determine the second attribute value corresponding to the object combination based on the target situation information and the second adjustment value.

[0109] The target category information is the most frequent category information in the object combination, and the target pose information is the most frequent pose information in the object combination.

[0110] In this embodiment, category information is the inherent attribute of the object itself, and situation information is the attribute formed during the movement of the object. Both of these information need to be quantified in order to accurately determine the target threat value.

[0111] In practice, for a combination of objects with only one object, it is only necessary to consider the category information and situation information of that one object. These two pieces of information are quantified separately to obtain the first attribute value and the second attribute value.

[0112] For a combination of objects with multiple objects, it is necessary to consider the overall category information and situation information within the combination. In this embodiment, the most frequent category information in the combination is selected as the target category information, and the most frequent pose information in the combination is selected as the target pose information. These two pieces of information are quantified and adjusted by a first adjustment value and a second adjustment value, respectively, to obtain the first attribute value and the second attribute value.

[0113] This embodiment does not specifically limit the quantization method, for example:

[0114] For a single object's object combination, the first attribute value is determined based on the first correspondence (the association between category information and attribute values), and the second attribute value is determined based on the second correspondence (the association between situation information and attribute values).

[0115] For a combination of multiple objects, a first initial attribute value is determined based on a first correspondence (association between category information and attribute values). The product of the first initial attribute value and a first adjustment value (greater than 1, the specific value can be determined according to the number of objects in the object combination) is used as the first attribute value. Based on a second correspondence (association between situation information and attribute values), a second initial attribute value is determined. The product of the second initial attribute value and a second adjustment value (greater than 1, the specific value can be determined according to the number of objects in the object combination) is used as the second attribute value.

[0116] Step S403: Based on the first attribute value, the second attribute value, the environmental parameters, and the target monitoring task, determine the target threat value corresponding to the object combination.

[0117] In practice, the first attribute value is obtained by quantifying the category information, and the second attribute value is obtained by quantifying the situation information. These two parameters can be used in subsequent calculations, and then combined with environmental parameters and target monitoring tasks, the target threat value corresponding to the object combination can be accurately determined.

[0118] Step S404: Based on the target threat value corresponding to all object combinations in the target area, perform security monitoring on the target area.

[0119] The specific implementation of step S404 can be found in the above embodiments, and will not be repeated here.

[0120] The above scheme, since category information is an inherent attribute of the object and situational information is an attribute formed during the object's movement (not a specific numerical value), quantifies these two pieces of information and incorporates them into subsequent calculations to accurately determine the target threat value.

[0121] In some optional implementations, step S403 above can be implemented in, but is not limited to, the following ways:

[0122] Select the target threat assessment model corresponding to the target monitoring task from the preset threat assessment models; wherein, different preset threat assessment models correspond to different monitoring tasks;

[0123] The first attribute value, the second attribute value, and the environmental parameters are input into the target threat assessment model, and the target threat value corresponding to the object combination is output by the target threat assessment model.

[0124] In this embodiment, different preset threat assessment models are trained for different monitoring tasks, and the target threat assessment model corresponding to the above-mentioned target monitoring task is selected; then the first attribute value, the second attribute value, and environmental parameters are input into the target threat assessment model, and the target threat value corresponding to the object combination is output through the target threat assessment model.

[0125] For example, for any preset monitoring task, multiple object combination samples under the preset monitoring task are obtained. The first attribute value, the second attribute value, the actual environmental parameters, and the corresponding calibrated threat value of the multiple object combination samples are used as the input of the initial model. The predicted threat value is used as the output of the initial model. The similarity between the calibrated threat value and the predicted threat value is used as the optimization condition to optimize the initial model, thereby obtaining the preset threat assessment model corresponding to the preset monitoring task.

[0126] The above scheme trains different preset threat assessment models for different monitoring tasks. By using the target threat assessment models corresponding to the target monitoring tasks, the target threat values ​​corresponding to each combination of objects can be determined accurately and efficiently.

[0127] In some optional implementations, step S403 above can be implemented in, but is not limited to, the following ways:

[0128] Based on the weight coefficients corresponding to the target monitoring task, the first attribute value and the second attribute value are weighted and summed to obtain the initial threat value;

[0129] Based on the adjustment coefficients corresponding to the environmental parameters, the initial threat value is adjusted to obtain the target threat value corresponding to the object combination.

[0130] In this embodiment, the first attribute value is obtained by quantifying the category information, and the second attribute value is obtained by quantifying the situation information. These two attribute values ​​characterize the threat characteristics of the object combination itself. As mentioned above, the monitoring task of the target area will also affect the threat level of the object. Based on this, this embodiment sets weight coefficients corresponding to different monitoring tasks. The first attribute value and the second attribute value are weighted and summed using the weight coefficients corresponding to the target monitoring task to obtain the initial threat value under the influence of the task (in combination with the specific monitoring task).

[0131] In addition, the current environmental parameters of the target area will affect the threat level of the object. Based on this, this embodiment also sets adjustment coefficients corresponding to different environmental parameters. The initial threat value is adjusted by using the adjustment coefficients corresponding to the environmental parameters of the target area to obtain the target threat value under environmental influence (in combination with the specific environment).

[0132] For example, the initial threat value A0 = (α*θ1 + β*θ2); where α is the weight coefficient corresponding to the first attribute value, θ1 is the first attribute value, β is the weight coefficient corresponding to the second attribute value, and θ2 is the second attribute value;

[0133] The target threat value A1 = γ * A0; where γ is the adjustment coefficient corresponding to the environmental parameters.

[0134] In practice, the sum of the weight coefficient corresponding to the first attribute value and the weight coefficient corresponding to the second attribute value can be greater than 1, equal to 1, or less than 1. The specific settings can be determined according to the monitoring task. This embodiment does not impose any specific limitations on this.

[0135] The above scheme obtains an initial threat value under the influence of the task (in conjunction with the specific monitoring task) by setting weight coefficients corresponding to different monitoring tasks and using the weight coefficients corresponding to the target monitoring task to perform a weighted sum of the first attribute value and the second attribute value; by setting adjustment coefficients corresponding to different environmental parameters and using the adjustment coefficients corresponding to the environmental parameters of the target area, the above initial threat value is adjusted to obtain a target threat value under the influence of the environment (in conjunction with the specific environment).

[0136] Figure 5 A flowchart illustrating the fourth security monitoring method provided in this application embodiment is shown below. Figure 5 As shown, it includes the following steps:

[0137] Step S501: Based on the position of each object in the target area, divide all objects in the target area into multiple object combinations.

[0138] Any combination of objects includes one or more objects.

[0139] Step S502: For any object combination, based on the category information of each object in the object combination, the situation information of each object in the object combination, the environmental parameters corresponding to the target area, and the target monitoring task corresponding to the target area, determine the target threat value that characterizes the threat level of the object combination.

[0140] The specific implementation of steps S501 to S502 can be referred to the above embodiments, and will not be repeated here.

[0141] Step S503: Compare the target threat value corresponding to each object combination in the target area with the preset value.

[0142] As mentioned above, the target threat value reflects the threat level of a single object or multiple aggregated objects in a specific task and environment. The higher the target threat value, the higher the threat level of the object combination.

[0143] Based on this, this embodiment sets a preset value to characterize the threat level limit. By comparing the target threat value corresponding to each object combination with the preset value, if the target threat value corresponding to the object combination is greater than or equal to the preset value, it indicates that the threat level of the object combination is high; if the target threat value corresponding to the object combination is less than the preset value, it indicates that the threat level of the object combination is low.

[0144] Step S504: If the target threat value corresponding to an object combination is greater than or equal to the preset value, then the information indicating that the object combination has a security threat is notified through the first preset notification method.

[0145] As mentioned above, if the target threat value corresponding to the object combination is greater than or equal to the preset value, it indicates that the threat level of the object combination is high. By notifying relevant personnel of the information that the object combination has a security threat, the relevant personnel can promptly perceive the object combination with a high threat level in the target area.

[0146] This embodiment does not specifically limit the first preset notification method. For example, after displaying the distribution of objects in the target area through the user interface, the combination of objects with security threats can be marked with special colors or special symbols; or, the location, type and other information of each object in the combination of objects with security threats can be broadcast by voice.

[0147] Based on the above Figure 2 For example, if object A poses a security threat, it will be marked in red or marked with a triangle symbol; if objects E, F, and G pose a security threat as a group, they will be enclosed in a red dashed box.

[0148] The first preset notification method described above is merely an illustrative example, and this embodiment does not impose any specific limitations on it.

[0149] The above scheme compares the target threat value corresponding to each object combination with a preset value. If the target threat value corresponding to an object combination is greater than or equal to the preset value, it indicates that the threat level of the object combination is high. By notifying relevant personnel of the information indicating that the object combination has a security threat, the scheme enables them to promptly perceive the object combination with a high threat level in the target area, thereby achieving local security monitoring for each object combination.

[0150] Figure 6 A flowchart illustrating the fifth security monitoring method provided in this application embodiment is shown below. Figure 6 As shown, it includes the following steps:

[0151] Step S601: Based on the position of each object in the target area, divide all objects in the target area into multiple object combinations.

[0152] Any combination of objects includes one or more objects.

[0153] Step S602: For any object combination, based on the category information of each object in the object combination, the situation information of each object in the object combination, the environmental parameters corresponding to the target area, and the target monitoring task corresponding to the target area, determine the target threat value that characterizes the threat level of the object combination.

[0154] The specific implementation of steps S601 to S602 can be referred to the above embodiments, and will not be repeated here.

[0155] Step S603: Compare the target threat value distribution in the target area with the preset threat value distribution corresponding to each preset event.

[0156] In some scenarios, the threat level may be increased by the special arrangement of objects; based on this, this embodiment also needs to analyze the distribution of target threat values ​​in the target area from a global perspective.

[0157] In this embodiment, some representative preset events are obtained, and their preset threat value distributions are obtained; then the target threat value distribution in the target area is compared with the preset threat value distributions corresponding to each preset event to determine the similarity between the target threat value distribution and the preset threat value distributions corresponding to each preset event.

[0158] For example, the target threat value distribution can be vectorized (e.g., feature extraction is performed using a feature extraction model to output a feature vector) to obtain the target vector; each preset threat value distribution can be vectorized to obtain a preset vector; and the similarity between the target vector and each preset vector can be determined based on the cosine similarity algorithm.

[0159] Step S604: If the similarity between the preset threat value distribution corresponding to a preset event and the target threat value distribution is greater than or equal to the preset similarity, then the preset event and the corresponding security policy are notified through the second preset notification method.

[0160] During implementation, if the similarity between the preset threat value distribution and the target threat value distribution is greater than or equal to the preset similarity, it indicates that a preset event may have occurred in the target area. Based on this, the preset event corresponding to the preset threat value is determined as the current event in the target area. By notifying the relevant personnel of the security policy corresponding to the preset event, the relevant personnel can promptly perceive the current event in the target area and efficiently obtain the security policy to deal with the event.

[0161] This embodiment does not specifically limit the second preset notification method. For example, preset events and corresponding security policies can be prompted through text on the user interface. If the similarity between multiple preset threat value distributions and the target threat value distribution is greater than or equal to the preset similarity, the preset events and related security policies corresponding to these preset threat values ​​will be displayed in descending order of similarity.

[0162] The above-described second preset notification method is merely an illustrative example, and this embodiment does not impose any specific limitations on it.

[0163] The above scheme establishes a preset threat value distribution for some representative preset events; then compares the target threat value distribution in the target area with the preset threat value distribution corresponding to each preset event to determine the similarity between the preset threat value distribution and the target threat value distribution; if the similarity between the preset threat value distribution and the target threat value distribution is greater than or equal to the preset similarity, it indicates that a preset event may have occurred in the target area; by identifying the preset event corresponding to the preset threat value as the current event in the target area, and notifying the corresponding security policy, relevant personnel can promptly perceive the current event in the target area and efficiently obtain the security policy to deal with the event, thus achieving overall security monitoring of the target area.

[0164] During implementation, the above Figure 5 The illustrated embodiments and Figure 6 The illustrated embodiments can be combined to simultaneously identify objects posing security threats in the target area and events currently occurring in the target area, enabling security analysis from both local and overall perspectives and providing more comprehensive security defense.

[0165] Based on the same inventive concept, this application provides a safety monitoring device, see reference. Figure 7 As shown, the safety monitoring device 700 includes:

[0166] The object partitioning module 701 is used to partition all objects in the target area into multiple object combinations based on the position of each object in the target area; wherein any object combination includes one or more objects;

[0167] Threat value determination module 702 is used to determine a target threat value that characterizes the threat level of the object combination for any object combination based on the category information of each object in the object combination, the situation information of each object in the object combination, the environmental parameters corresponding to the target area, and the target monitoring task corresponding to the target area.

[0168] The monitoring module 703 is used to perform security monitoring on the target area based on the target threat value corresponding to all object combinations in the target area.

[0169] In some optional implementations, the threat value determination module 702 is specifically used for:

[0170] If the object combination includes an object, then determine the first attribute value corresponding to the object's category information and the second attribute value corresponding to the object's situation information; or

[0171] If the object combination includes multiple objects, then based on the target category information and the first adjustment value, a first attribute value corresponding to the object combination is determined; and based on the target posture information and the second adjustment value, a second attribute value corresponding to the object combination is determined; wherein, the target category information is the most frequent category information in the object combination, and the target posture information is the most frequent posture information in the object combination;

[0172] Based on the first attribute value, the second attribute value, the environmental parameters, and the target monitoring task, the target threat value corresponding to the object combination is determined.

[0173] In some optional implementations, the threat value determination module 702 is specifically used for:

[0174] Select the target threat assessment model corresponding to the target monitoring task from the preset threat assessment models; wherein, different preset threat assessment models correspond to different monitoring tasks;

[0175] The first attribute value, the second attribute value, and the environmental parameters are input into the target threat assessment model, and the target threat value corresponding to the object combination is output by the target threat assessment model.

[0176] In some optional implementations, the threat value determination module 702 is specifically used for;

[0177] Based on the weight coefficients corresponding to the target monitoring task, the first attribute value and the second attribute value are weighted and summed to obtain the initial threat value;

[0178] Based on the adjustment coefficients corresponding to the environmental parameters, the initial threat value is adjusted to obtain the target threat value corresponding to the object combination.

[0179] In some optional implementations, the monitoring module 703 is specifically used for:

[0180] The target threat value corresponding to each object combination in the target area is compared with a preset value.

[0181] If the target threat value corresponding to a combination of objects is greater than or equal to the preset value, then the information indicating that the combination of objects poses a security threat will be notified through the first preset notification method.

[0182] In some optional implementations, the monitoring module 703 is specifically used for:

[0183] The target threat value distribution in the target area is compared with the preset threat value distribution corresponding to each preset event;

[0184] If the similarity between the preset threat value distribution corresponding to a preset event and the target threat value distribution is greater than or equal to the preset similarity, then the preset event and the corresponding security policy will be notified through the second preset notification method.

[0185] In some optional implementations, the object partitioning module 701 is specifically used for:

[0186] Based on the location of each object in the target region, all objects in the target region are clustered to obtain a cluster set and outliers that are not in the cluster set;

[0187] Each cluster set is used as a first object combination, and each outlier is used as a second object combination; wherein, the first object combination includes multiple objects, and the second object combination includes one object.

[0188] Since this device is the same as the device in the method of this application embodiment, and the principle of the device in solving the problem is similar to that of the method, the implementation of the device can be referred to the implementation of the method, and the repeated parts will not be described again.

[0189] Based on the same technical concept, this application also provides an electronic device 800, such as... Figure 8 As shown, it includes at least one processor 801 and a memory 802 connected to at least one processor. In this embodiment, the specific connection medium between the processor 801 and the memory 802 is not limited. Figure 8 Taking the connection between the processor 801 and the memory 802 via bus 803 as an example, the bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, Figure 8 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0190] The processor 801 is the control center of the electronic device. It can connect to various parts of the electronic device through various interfaces and lines, and performs data processing by running or executing instructions stored in the memory 802 and calling data stored in the memory 802. Optionally, the processor 801 may include one or more processing units. The processor 801 may integrate an application processor and a modem processor. The application processor mainly handles the operating system, user interface, and application programs, while the modem processor mainly handles issuing instructions. It is understood that the modem processor may not be integrated into the processor 801. In some embodiments, the processor 801 and the memory 802 may be implemented on the same chip; in some embodiments, they may also be implemented on separate chips.

[0191] The processor 801 can be a general-purpose processor, such as a central processing unit (CPU), digital signal processor, application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the security monitoring method can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.

[0192] Memory 802, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 802 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. Memory 802 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 802 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.

[0193] In this embodiment, the memory 802 stores a computer program, which, when executed by the processor 801, causes the processor 801 to perform the following:

[0194] Based on the location of each object in the target area, all objects in the target area are divided into multiple object groups; wherein each object group includes one or more objects.

[0195] For any combination of objects, a target threat value characterizing the threat level of the combination of objects is determined based on the category information of each object in the combination, the situation information of each object in the combination, the environmental parameters corresponding to the target area, and the target monitoring task corresponding to the target area.

[0196] Security monitoring is performed on the target area based on the target threat value corresponding to all object combinations in the target area.

[0197] In some alternative implementations, processor 801 specifically performs:

[0198] If the object combination includes an object, then determine the first attribute value corresponding to the object's category information and the second attribute value corresponding to the object's situation information; or

[0199] If the object combination includes multiple objects, then based on the target category information and the first adjustment value, a first attribute value corresponding to the object combination is determined; and based on the target posture information and the second adjustment value, a second attribute value corresponding to the object combination is determined; wherein, the target category information is the most frequent category information in the object combination, and the target posture information is the most frequent posture information in the object combination;

[0200] Based on the first attribute value, the second attribute value, the environmental parameters, and the target monitoring task, the target threat value corresponding to the object combination is determined.

[0201] In some alternative implementations, processor 801 specifically performs:

[0202] Select the target threat assessment model corresponding to the target monitoring task from the preset threat assessment models; wherein, different preset threat assessment models correspond to different monitoring tasks;

[0203] The first attribute value, the second attribute value, and the environmental parameters are input into the target threat assessment model, and the target threat value corresponding to the object combination is output by the target threat assessment model.

[0204] In some alternative implementations, processor 801 specifically performs:

[0205] Based on the weight coefficients corresponding to the target monitoring task, the first attribute value and the second attribute value are weighted and summed to obtain the initial threat value;

[0206] Based on the adjustment coefficients corresponding to the environmental parameters, the initial threat value is adjusted to obtain the target threat value corresponding to the object combination.

[0207] In some alternative implementations, processor 801 specifically performs:

[0208] The target threat value corresponding to each object combination in the target area is compared with a preset value.

[0209] If the target threat value corresponding to a combination of objects is greater than or equal to the preset value, then the information indicating that the combination of objects poses a security threat will be notified through the first preset notification method.

[0210] In some alternative implementations, processor 801 specifically performs:

[0211] The target threat value distribution in the target area is compared with the preset threat value distribution corresponding to each preset event;

[0212] If the similarity between the preset threat value distribution corresponding to a preset event and the target threat value distribution is greater than or equal to the preset similarity, then the preset event and the corresponding security policy will be notified through the second preset notification method.

[0213] In some alternative implementations, processor 801 specifically performs:

[0214] Based on the location of each object in the target region, all objects in the target region are clustered to obtain a cluster set and outliers that are not in the cluster set;

[0215] Each cluster set is used as a first object combination, and each outlier is used as a second object combination; wherein, the first object combination includes multiple objects, and the second object combination includes one object.

[0216] Since the electronic device is the same as the electronic device in the method of this application embodiment, and the principle of the electronic device in solving the problem is similar to that of the method, the implementation of the electronic device can refer to the implementation of the method, and the repeated parts will not be described again.

[0217] Based on the same technical concept, embodiments of this application also provide a computer-readable storage medium storing a computer program executable by an electronic device, which, when run on the electronic device, causes the electronic device to perform the steps of the above-described security monitoring method.

[0218] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0219] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0220] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0221] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0222] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.

[0223] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A safety monitoring method, characterized by, The method comprises the following steps: dividing all objects in a target region into a plurality of object combinations based on the positions of the objects in the target region; wherein any object combination comprises one or more objects; for any object combination, the following operations are respectively performed: if the object combination comprises one object, determining a first attribute value corresponding to the class information of the one object, and a second attribute value corresponding to the situation information of the one object, the situation information representing an attribute formed by the one object in the process of movement; or, if the object combination comprises a plurality of objects, determining a first attribute value corresponding to the object combination based on target class information and a first adjustment value, and determining a second attribute value corresponding to the object combination based on target situation information and a second adjustment value, wherein the target class information is the most common class information in the object combination, and the target situation information is the most common situation information in the object combination; weighting and summing the first attribute value and the second attribute value based on a weight coefficient corresponding to the target monitoring task to obtain an initial threat value; adjusting the initial threat value based on an adjustment coefficient corresponding to the environmental parameter to obtain a target threat value corresponding to the object combination; performing safety monitoring on the target region based on the target threat values corresponding to all object combinations in the target region.

2. The method of claim 1, wherein, Determining the target threat value corresponding to the object combination based on the first attribute value, the second attribute value, the environmental parameter and the target monitoring task comprises: selecting a target threat evaluation model corresponding to the target monitoring task from a plurality of preset threat evaluation models; wherein different preset threat evaluation models correspond to different monitoring tasks; inputting the first attribute value, the second attribute value and the environmental parameter into the target threat evaluation model, and outputting the target threat value corresponding to the object combination through the target threat evaluation model.

3. The method of claim 1, wherein, Performing safety monitoring on the target region based on the target threat values corresponding to all object combinations in the target region comprises: comparing the target threat values corresponding to the object combinations in the target region with a preset value respectively; if the target threat value corresponding to an object combination is greater than or equal to the preset value, informing the information representing that the object combination has a security threat through a first preset notification mode.

4. The method of claim 1, wherein, Performing safety monitoring on the target region based on the target threat values corresponding to all object combinations in the target region comprises: comparing the target threat value distribution in the target region with a preset threat value distribution corresponding to each preset event respectively; if the similarity between the preset threat value distribution corresponding to a preset event and the target threat value distribution is greater than or equal to a preset similarity, informing the preset event and the corresponding security strategy through a second preset notification mode.

5. The method of claim 1, wherein, Dividing all objects in a target region into a plurality of object combinations based on the positions of the objects in the target region comprises: clustering all objects in the target region based on the positions of the objects to obtain a clustering set and outliers not in the clustering set; Each cluster set is combined as a first object, and each outlier is combined as a second object; wherein the first object combination includes multiple objects, and the second object combination includes one object.

6. A safety monitoring device, characterized by Comprise: An object division module, configured to divide all objects in a target region into multiple object combinations based on positions of the objects in the target region; wherein any object combination includes one or more objects; A threat value determination module, configured to perform the following operations for any object combination: if the object combination includes one object, determine a first attribute value corresponding to category information of the one object, and a second attribute value corresponding to situation information of the one object, the situation information representing an attribute formed by the one object in a movement process; or, if the object combination includes multiple objects, determine a first attribute value corresponding to the object combination based on target category information and a first adjustment value, and determine a second attribute value corresponding to the object combination based on target situation information and a second adjustment value, wherein the target category information is the most common category information in the object combination, and the target situation information is the most common situation information in the object combination; weight and sum the first attribute value and the second attribute value based on a weight coefficient corresponding to the target monitoring task, to obtain an initial threat value; and adjust the initial threat value based on an adjustment coefficient corresponding to the environment parameter, to obtain a target threat value corresponding to the object combination; A monitoring module, configured to perform security monitoring on the target region based on target threat values corresponding to all object combinations in the target region.

7. An electronic device, comprising: The electronic device includes at least one processor and at least one memory, wherein the memory stores a computer program, and when the program is executed by the processor, the processor executes the method of any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, It stores a computer program executable by an electronic device, and when the program runs on the electronic device, the electronic device executes the method of any one of claims 1-5.

Citation Information

Patent Citations

  • Identifying security threats

    US20070222589A1