Real-time Early Warning Method and System for Abnormal Behaviors Based on Intelligent Security

By obtaining real-time video streams, analyst behavior and environmental data in the intelligent security system, calculating behavioral risk entropy value and monitoring adaptation, and formulating and implementing abnormal behavior warning strategies, the problem of inefficient early warning in traditional security systems is solved, and more efficient and accurate security risk identification and early warning is achieved.

CN119672933BActive Publication Date: 2025-05-27深圳市五兴科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510149894.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-05-27
Estimated Expiration
2045-02-11

AI Technical Summary

Technical Problem

Traditional early warning methods for security abnormal behavior rely on manual monitoring or simple rule matching systems, making it difficult to effectively identify potential security risks in complex public places, and the system adjustment is cumbersome, resulting in insufficient timeliness and accuracy of early warnings.

Method used

By obtaining the real-time video stream of the security monitoring area, determining the monitoring environment feature set, formulating behavioral warning thresholds; collecting dynamic behavior information of personnel, analyzing behavioral modal analysis dimensions, and calculating threshold trigger factors; combining human image data and action trajectory, calculate behavioral risk entropy; analyzing environmental electromagnetic spectrum data, evaluating monitoring adaptability, formulating abnormal behavioral warning strategies and implementing real-time warnings.

Benefits of technology

It improves the efficiency of real-time early warning of abnormal behaviors under intelligent security, enhances the ability to identify security risks in complex places, and improves the pertinence and accuracy of early warnings.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119672933B_ABST
    Figure CN119672933B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of artificial intelligence technology, and discloses an abnormal behavior real-time early warning method and system based on intelligent security, including: determining a monitoring environment feature set corresponding to a security monitoring area, and formulating a behavior early warning threshold corresponding to a security monitoring device; collecting dynamic behavior information of personnel in the security monitoring area, analyzing a behavior mode analysis dimension corresponding to the security monitoring device, and evaluating the regional security situation corresponding to the security monitoring area; analyzing the physical feature attributes of personnel in the security monitoring area, analyzing the action mode features corresponding to the personnel in the security monitoring area, and calculating the behavior risk entropy value corresponding to the personnel in the security monitoring area; analyzing the monitoring adaptability of the security monitoring device in the security monitoring area; formulating an abnormal behavior early warning strategy corresponding to the security monitoring area, performing real-time early warning of abnormal behaviors in the security monitoring area, and obtaining an early warning result. The present invention improves the real-time early warning efficiency of abnormal behaviors under intelligent security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a real-time early warning method and system for abnormal behavior based on intelligent security, belonging to the technical field of artificial intelligence. Background Art

[0002] In modern society, with the acceleration of urbanization and the increase in population mobility, the demand for security protection in various public places and residential areas is growing. As a key technical means to protect people's lives and property, the importance of intelligent security is becoming more and more prominent. Real-time warning of abnormal behavior, as one of the core functions of intelligent security, can detect abnormalities in time before danger occurs, providing key support for safety prevention.

[0003] At present, traditional security abnormal behavior warning methods mainly rely on manual monitoring or simple rule matching systems. Manual monitoring requires security personnel to stare at the monitoring screen for a long time, which not only consumes a lot of manpower, but also easily leads to negligence due to fatigue, and fails to detect some subtle or complex abnormal behaviors in time. Simple rule matching systems usually make judgments based on pre-set fixed behavior patterns, such as setting no-entry rules for specific areas, rules for the appearance of abnormal personnel at specific times, etc. When the behavior of personnel does not match the preset rules, an early warning is triggered. However, this method is too rigid and difficult to adapt to complex and changeable actual scenarios.

[0004] In complex public places, such as large shopping malls and railway stations, people's behavior patterns are rich and varied, and are affected by multiple factors such as environment, time, and activities. Traditional rule-matching systems cannot effectively identify abnormal behaviors that are not within the preset range but actually pose security risks, such as slow-moving but potentially threatening individual behaviors in the crowd, or seemingly casual but dangerous interactions between multiple people. Moreover, once the scene changes, such as promotional activities in the mall that lead to changes in personnel density and behavior patterns, the traditional system needs to manually adjust the rules again. The process is cumbersome and inefficient, which greatly reduces the timeliness and accuracy of the warning, and in turn leads to low efficiency in real-time warning of abnormal behaviors under intelligent security. Summary of the invention

[0005] The present invention provides a method and system for real-time early warning of abnormal behavior under intelligent security, the main purpose of which is to improve the efficiency of real-time early warning of abnormal behavior under intelligent security.

[0006] To achieve the above purpose, the present invention provides a real-time early warning method for abnormal behavior based on intelligent security, comprising:

[0007] Obtain security monitoring equipment and real-time video streams of a security monitoring area, determine a monitoring environment feature set corresponding to the security monitoring area based on the real-time video stream, and formulate a behavior warning threshold corresponding to the security monitoring equipment based on the monitoring environment feature set;

[0008] Collecting dynamic behavior information of personnel in the security monitoring area, analyzing the behavior mode analysis dimension corresponding to the security monitoring equipment based on the dynamic behavior information of personnel, calculating the threshold trigger factor corresponding to the behavior warning threshold based on the behavior mode analysis dimension, and evaluating the regional security situation corresponding to the security monitoring area based on the threshold trigger factor;

[0009] Collecting human image data and personnel movement trajectories in the security monitoring area, analyzing the physical characteristics of the personnel in the security monitoring area based on the human image data, analyzing the action pattern characteristics of the personnel in the security monitoring area based on the movement trajectories of the personnel, and calculating the behavior risk entropy value corresponding to the personnel in the security monitoring area by combining the action pattern characteristics and the physical characteristics;

[0010] Collecting environmental electromagnetic spectrum data corresponding to the security monitoring area, analyzing environmental interference factors corresponding to the environmental electromagnetic spectrum data, and analyzing the monitoring adaptability of the security monitoring device in the security monitoring area based on the environmental interference factors;

[0011] Based on the security situation of the area, the behavior risk entropy value, and the monitoring adaptability, an abnormal behavior warning strategy corresponding to the security monitoring area is formulated. Based on the abnormal behavior warning strategy, real-time warning of abnormal behavior in the security monitoring area is executed to obtain a warning result.

[0012] Optionally, determining the monitoring environment feature set corresponding to the security monitoring area based on the real-time video stream includes:

[0013] Performing frame processing on the real-time video stream to obtain a frame-based video stream;

[0014] Performing target detection on the frame-by-frame video stream to obtain a video detection target;

[0015] Based on the video detection target, determining the monitoring target and scene elements within the security monitoring area;

[0016] Extracting features corresponding to the monitoring target and the scene elements respectively to obtain a target feature subset and an environment feature subset;

[0017] Performing behavior tracking processing on the monitored target to obtain a behavior feature subset;

[0018] The monitoring environment feature set corresponding to the security monitoring area is determined by combining the target feature subset, the environment feature subset and the behavior feature subset.

[0019] Optionally, formulating a behavior warning threshold corresponding to the security monitoring device based on the monitoring environment feature set includes:

[0020] Identify the feature identifier corresponding to each feature in the monitoring environment feature set, and extract the key feature identifier from the feature identifiers;

[0021] Querying the regional monitoring criteria of the security monitoring area, and analyzing the correlation between the regional monitoring criteria and the key feature identifier;

[0022] Based on the correlation, selecting target environment features from the monitoring environment feature set;

[0023] Collecting feature history data corresponding to the target environment feature, and determining the abnormal behavior type and abnormal behavior threshold corresponding to the target environment feature based on the feature history data;

[0024] In combination with the target environment characteristics, the abnormal behavior type and the abnormal behavior threshold, a behavior warning threshold corresponding to the security monitoring device is formulated.

[0025] Optionally, analyzing the behavioral modal analysis dimension corresponding to the security monitoring device based on the dynamic behavior information of the personnel includes:

[0026] Performing noise reduction processing on the personnel dynamic behavior information to obtain noise-reduced dynamic behavior information;

[0027] Performing behavior analysis on the noise reduction dynamic behavior information to obtain a dynamic behavior label;

[0028] Calculating the spatiotemporal distribution intensity of each tag in the dynamic behavior tag, and filtering out characteristic dynamic information in the noise reduction dynamic behavior information based on the spatiotemporal distribution intensity;

[0029] Performing behavior attribute analysis on the characteristic dynamic information to obtain information behavior attributes;

[0030] Dimension mapping is performed on the information behavior attribute to obtain the behavior mode analysis dimension corresponding to the security monitoring device.

[0031] Optionally, the calculating the spatiotemporal distribution intensity of each tag in the dynamic behavior tag includes:

[0032] Analyze the behavior events in the dynamic behavior tags, and count the number of events corresponding to the behavior events;

[0033] Extracting a location descriptor corresponding to the behavior event from the dynamic behavior tag, and determining the event spatiotemporal location corresponding to the behavior event based on the location descriptor;

[0034] Based on the spatiotemporal position of the event, calculating the spatiotemporal centroid of the dynamic behavior label;

[0035] Combining the event spatiotemporal position, the event quantity and the tag spatiotemporal centroid, the spatiotemporal distribution intensity of each tag in the dynamic behavior tag is calculated by the following formula:

[0036] ;

[0037] Among them, A represents the spatiotemporal distribution intensity of each label in the dynamic behavior label, Indicates the spatial bandwidth parameter corresponding to the ath label in the dynamic behavior label. Indicates the number of behavior events corresponding to the a-th label in the dynamic behavior label, and Indicates the spatiotemporal position of the behavior of the ath label in the dynamic behavior label, and represents the spatiotemporal centroid of the tag, a represents the serial number of the dynamic behavior tag, q represents the number of dynamic behavior tags, is the Gaussian kernel function.

[0038] Optionally, the calculating, based on the behavior modality analysis dimension, a threshold trigger factor corresponding to the behavior warning threshold includes:

[0039] Normalizing the behavioral modal analysis dimension to obtain a normalized dimension value;

[0040] Calculating the dimensional information gain corresponding to the behavioral modal analysis dimension, and assigning the dimensional weight corresponding to the behavioral modal analysis dimension according to the dimensional information gain;

[0041] Querying the dimension safety threshold corresponding to the behavior mode analysis dimension;

[0042] In combination with the dimension security threshold, the normalized dimension value and the dimension weight, the threshold trigger factor corresponding to the behavior warning threshold can be calculated by the following formula:

[0043] ;

[0044] Among them, G represents the threshold trigger factor corresponding to the behavior warning threshold, Indicates the dimension weight corresponding to the bth dimension in the behavioral mode analysis dimension, Indicates the normalized dimension value corresponding to the bth dimension in the behavioral mode analysis dimension. It represents the dimension safety threshold corresponding to the b-th dimension in the behavioral modal analysis dimension, b represents the serial number of the behavioral modal analysis dimension, and r represents the number of behavioral modal analysis dimensions.

[0045] Optionally, analyzing the physical features of people in the security monitoring area based on the human image data includes:

[0046] Performing image preprocessing on the human body image data to obtain a target human body image;

[0047] Performing main body image segmentation processing on the target human body image to obtain a main body image of the human body;

[0048] Extracting a plurality of human appearance features of the human subject image, and constructing a fusion appearance feature vector of the plurality of human appearance features;

[0049] Calculating the cosine similarity between the fused appearance feature vector and each physical feature in a pre-constructed physical feature database;

[0050] Based on the cosine similarity, the physical features of the people in the security monitoring area are analyzed.

[0051] Optionally, analyzing the action pattern characteristics corresponding to the personnel in the security monitoring area based on the personnel action trajectory includes:

[0052] Performing data cleaning on the movement trajectory of the personnel to obtain the target movement trajectory;

[0053] Identifying a trajectory timestamp corresponding to the target action trajectory, and performing time slicing processing on the target action trajectory based on the trajectory timestamp to obtain a sliced ​​trajectory segment;

[0054] Performing pattern analysis on the slice trajectory segments to obtain trajectory behavior patterns;

[0055] Counting the pattern feature descriptions corresponding to the trajectory behavior patterns, and analyzing the interaction mechanism between the pattern feature descriptions;

[0056] In combination with the pattern feature description and the interaction mechanism, the action pattern features corresponding to the personnel in the security monitoring area are analyzed.

[0057] Optionally, analyzing the monitoring suitability of the security monitoring device in the security monitoring area based on the environmental interference factor includes:

[0058] Querying the electromagnetic compatibility parameters of the security monitoring equipment, and analyzing the electromagnetic adaptability characteristics of the electromagnetic compatibility parameters of the equipment;

[0059] Analyzing the electromagnetic frequency band index in the electromagnetic adaptability characteristic, and extracting the associated interference factor corresponding to the security monitoring device from the environmental interference factor based on the electromagnetic frequency band index;

[0060] A matching coefficient between the electromagnetic adaptability characteristic and the associated interference element is calculated, and based on the matching coefficient, a monitoring adaptability of the security monitoring device in the security monitoring area is analyzed.

[0061] In order to solve the above problems, the present invention also provides a real-time warning system for abnormal behavior based on intelligent security, the system comprising:

[0062] A behavior warning threshold setting module is used to obtain security monitoring equipment and real-time video streams in a security monitoring area, determine a monitoring environment feature set corresponding to the security monitoring area based on the real-time video stream, and formulate a behavior warning threshold corresponding to the security monitoring equipment based on the monitoring environment feature set;

[0063] A regional security situation assessment module is used to collect dynamic behavior information of personnel in the security monitoring area, analyze the behavior mode analysis dimension corresponding to the security monitoring equipment based on the dynamic behavior information of personnel, calculate the threshold trigger factor corresponding to the behavior warning threshold based on the behavior mode analysis dimension, and evaluate the regional security situation corresponding to the security monitoring area based on the threshold trigger factor;

[0064] A behavior risk entropy value calculation module is used to collect human image data and personnel movement trajectories in the security monitoring area, analyze the physical characteristics of the personnel in the security monitoring area based on the human image data, analyze the action pattern characteristics of the personnel in the security monitoring area based on the movement trajectories of the personnel, and calculate the behavior risk entropy value corresponding to the personnel in the security monitoring area by combining the action pattern characteristics and the physical characteristics;

[0065] A monitoring adaptability analysis module, used to collect environmental electromagnetic spectrum data corresponding to the security monitoring area, analyze environmental interference factors corresponding to the environmental electromagnetic spectrum data, and analyze the monitoring adaptability of the security monitoring device in the security monitoring area based on the environmental interference factors;

[0066] The abnormal behavior real-time warning module is used to formulate an abnormal behavior warning strategy corresponding to the security monitoring area based on the security situation of the area, the behavior risk entropy value, and the monitoring adaptability, and based on the abnormal behavior warning strategy, execute real-time warning of abnormal behavior in the security monitoring area to obtain a warning result.

[0067] Compared with the problems described in the background technology, the present invention determines the monitoring environment feature set corresponding to the security monitoring area based on the real-time video stream, so as to fully grasp the real-time status of the security monitoring area, provide a rich and accurate data basis for the subsequent formulation of accurate behavior warning thresholds, and greatly improve the pertinence and effectiveness of security monitoring. Furthermore, the present invention analyzes the behavior modal analysis dimension corresponding to the security monitoring equipment based on the dynamic behavior information of the personnel, so as to fully and deeply understand the various patterns and characteristics of the behavior of the personnel in the security monitoring area, thereby improving the accuracy of calculating the threshold trigger factor corresponding to the behavior warning threshold. The present invention analyzes the physical feature attributes corresponding to the personnel in the security monitoring area based on the human image data, so as to quickly grasp the key information of the personnel's appearance, assist in identifying suspicious personnel, and provide a reference for combining behavior with human image data. The dynamic pattern characteristics provide an important basis for evaluating the behavior risk entropy value, and improve the early warning ability of security monitoring for potential risks. Furthermore, the present invention analyzes the monitoring adaptability of the security monitoring equipment in the security monitoring area based on the environmental interference factors, and can effectively evaluate the performance and reliability of the security monitoring equipment in a specific electromagnetic environment, and provide a basis for the subsequent optimization and maintenance of the security monitoring equipment. Furthermore, the present invention formulates an abnormal behavior early warning strategy corresponding to the security monitoring area based on the security situation of the area, the behavior risk entropy value, and the monitoring adaptability. The comprehensive multi-dimensional information can improve the scientificity and accuracy of the early warning strategy, and based on the abnormal behavior early warning strategy, execute the real-time early warning of abnormal behavior in the security monitoring area, thereby improving the real-time early warning efficiency of abnormal behavior in the security monitoring area. Therefore, the real-time early warning method and system for abnormal behavior based on intelligent security provided in the embodiment of the present invention can improve the real-time early warning efficiency of abnormal behavior under intelligent security. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] Figure 1 A flow chart of a method for real-time early warning of abnormal behavior based on intelligent security provided by an embodiment of the present invention;

[0069] Figure 2 A schematic diagram of a module for implementing the method for real-time warning of abnormal behavior based on intelligent security provided by an embodiment of the present invention.

[0070] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings in conjunction with the embodiments. DETAILED DESCRIPTION

[0071] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.

[0072] The embodiment of the present application provides a real-time early warning method for abnormal behavior based on intelligent security. The execution subject of the real-time early warning method for abnormal behavior based on intelligent security includes but is not limited to at least one of the electronic devices such as a server and a terminal that can be configured to execute the method provided by the embodiment of the present application. In other words, the real-time early warning method for abnormal behavior based on intelligent security can be executed by software or hardware installed on a terminal device or a server device. The server includes but is not limited to: a single server, a server cluster, a cloud server or a cloud server cluster, etc.

[0073] Embodiment 1:

[0074] Reference Figure 1 FIG. 1 is a flow chart of a method for real-time warning of abnormal behavior based on intelligent security provided by an embodiment of the present invention. In this embodiment, the method for real-time warning of abnormal behavior based on intelligent security includes:

[0075] S1. Obtain security monitoring equipment and real-time video streams of a security monitoring area, determine a monitoring environment feature set corresponding to the security monitoring area based on the real-time video stream, and formulate a behavior warning threshold corresponding to the security monitoring equipment based on the monitoring environment feature set.

[0076] The present invention determines the monitoring environment feature set corresponding to the security monitoring area based on the real-time video stream, so as to fully grasp the real-time status of the security monitoring area, provide a rich and accurate data basis for the subsequent formulation of precise behavior warning thresholds, and greatly improve the pertinence and effectiveness of security monitoring. It should be explained that the security monitoring equipment includes various hardware facilities for monitoring such as cameras and sensors. The real-time video stream is the dynamic image information collected by the monitoring equipment in real time; the monitoring environment feature set is a feature description of the comprehensive situation such as the environmental characteristics of the monitoring area, the activity patterns of personnel, and the distribution of objects. Furthermore, the acquisition of the security monitoring equipment and the real-time video stream in the security monitoring area can be achieved by connecting to the network interface of the monitoring system, calling the device management API, and using hardware devices such as video capture cards.

[0077] In detail, the determining of the monitoring environment feature set corresponding to the security monitoring area based on the real-time video stream includes:

[0078] Performing frame processing on the real-time video stream to obtain a frame-based video stream;

[0079] Performing target detection on the frame-by-frame video stream to obtain a video detection target;

[0080] Based on the video detection target, determining the monitoring target and scene elements within the security monitoring area;

[0081] Extracting features corresponding to the monitoring target and the scene elements respectively to obtain a target feature subset and an environment feature subset;

[0082] Performing behavior tracking processing on the monitored target to obtain a behavior feature subset;

[0083] The monitoring environment feature set corresponding to the security monitoring area is determined by combining the target feature subset, the environment feature subset and the behavior feature subset.

[0084] It should be explained that the framed video stream is a sequence of single-frame images divided into a time sequence by the real-time video stream, the video detection target is an object identified by a target detection algorithm in the framed video stream, the monitoring target and the scene element are respectively the monitored objects and environmental components in the security monitoring area, the target feature subset and the environmental feature subset are respectively the sets of attributes and characteristics corresponding to the monitoring target and the scene element, and the behavior feature subset is a set of behavior information such as the movement trajectory, speed, and direction change of the monitoring target in continuous frames.

[0085] Furthermore, the real-time video stream can be framed by a video processing library (such as OpenCV) to obtain a framed video stream; a target detection model based on deep learning (such as YOLO, Faster R-CNN) can be used to detect the real-time video stream. ) perform target detection on the framed video stream to obtain a video detection target; based on the video detection target, determine the monitoring target and scene elements in the security monitoring area according to preset target screening rules and scene element recognition algorithms. For example, the preset target screening rule is to determine the target with a detection confidence higher than 90% and a size larger than a certain pixel area as a valid monitoring target, such as identified pedestrians, vehicles, etc., and use the scene element recognition algorithm to identify the school classroom scene by analyzing the elements such as tables, chairs, podiums, and blackboards in the video, or identify the commercial street scene according to elements such as store signs and crowd density; the attribute features corresponding to the monitoring target and the scene element can be respectively extracted by the attribute recognition algorithm to obtain a target feature subset and an environmental feature subset; the monitoring target can be subjected to behavior tracking processing by a target tracking algorithm (such as Kalman filtering and Hungarian algorithm) to obtain a behavior feature subset; the target feature subset, the environmental feature subset, and the behavior feature subset can be subjected to dimensionality reduction processing by a dimensionality reduction algorithm, and the obtained dimensionality reduction feature subsets are merged to obtain a monitoring environment feature set corresponding to the security monitoring area.

[0086] Based on the monitoring environment feature set, the present invention formulates the behavior warning threshold value corresponding to the security monitoring device, and can obtain the abnormal behavior judgment standard of the device in different monitoring environments, thereby providing a basis for timely discovery and warning of potential security threats. It should be explained that the behavior warning threshold value is a quantitative standard for judging whether the behavior in the monitoring screen is abnormal.

[0087] In detail, formulating the behavior warning threshold corresponding to the security monitoring device based on the monitoring environment feature set includes:

[0088] Identify the feature identifier corresponding to each feature in the monitoring environment feature set, and extract the key feature identifier from the feature identifiers;

[0089] Querying the regional monitoring criteria of the security monitoring area, and analyzing the correlation between the regional monitoring criteria and the key feature identifier;

[0090] Based on the correlation, selecting target environment features from the monitoring environment feature set;

[0091] Collecting feature history data corresponding to the target environment feature, and determining the abnormal behavior type and abnormal behavior threshold corresponding to the target environment feature based on the feature history data;

[0092] In combination with the target environment characteristics, the abnormal behavior type and the abnormal behavior threshold, a behavior warning threshold corresponding to the security monitoring device is formulated.

[0093] It should be explained that the feature identifier is a representative mark corresponding to each feature in the monitoring environment feature set that can distinguish different features. The key feature identifier is a mark in the feature identifier that plays a key role in determining the security monitoring target and is closely related to the core elements of security. The area monitoring criteria are rules for the security monitoring area to regulate monitoring behavior, clarify safety standards and operating requirements. The correlation degree indicates the closeness between the area monitoring criteria and the key feature identifier in terms of security monitoring targets, rule constraints, etc. The target environment feature is a feature in the monitoring environment feature set that is directly related to the core security target (such as preventing intrusion, protecting key facilities, etc.) and is the focus of the monitoring criteria. The feature historical data is the actual data record generated by the target environment feature in the past period of time. The abnormal behavior type and the abnormal behavior threshold are respectively determined based on the feature historical data to determine the different abnormal behavior manifestations corresponding to the target environment feature and the numerical limits for triggering abnormal warnings.

[0094] Furthermore, the feature identifier corresponding to each feature in the monitoring environment feature set can be identified by OCR recognition technology, and the key feature identifiers in the feature identifiers can be extracted by evaluating the importance of the feature identifiers and screening them; the regional monitoring criteria of the security monitoring area can be queried through the database of the security monitoring system, and the correlation between the regional monitoring criteria and the key feature identifiers can be analyzed by establishing a mapping relationship between the feature identifiers and the criteria clauses and quantitatively analyzing them; the correlation degree is compared with a preset correlation degree, and when the correlation degree is greater than the preset correlation degree, the target environment feature is screened out from the monitoring environment feature set; the feature historical data corresponding to the target environment feature can be collected by reading data from a historical monitoring data storage medium, and based on the feature historical data, the abnormal behavior type and abnormal behavior threshold corresponding to the target environment feature are determined by cluster analysis and statistical methods; in combination with the target environment feature, the abnormal behavior type and the abnormal behavior threshold, the behavior warning threshold corresponding to the security monitoring device is formulated, and the target environment feature can be matched one-to-one with the abnormal behavior type, such as the target environment feature of "personnel breaking into a restricted area" corresponds to the abnormal behavior type of "illegal intrusion". Based on the abnormal behavior threshold, when a person is detected entering a restricted area and staying there for more than 5 seconds (abnormal behavior threshold), the security monitoring equipment is set to trigger an early warning, thereby formulating the behavior early warning threshold.

[0095] S2. Collect dynamic behavior information of personnel in the security monitoring area, analyze the behavior modal analysis dimension corresponding to the security monitoring equipment based on the dynamic behavior information of personnel, calculate the threshold trigger factor corresponding to the behavior warning threshold based on the behavior modal analysis dimension, and evaluate the regional security situation corresponding to the security monitoring area based on the threshold trigger factor.

[0096] By analyzing the behavioral modal analysis dimensions corresponding to the security monitoring equipment based on the dynamic behavior information of the personnel, the present invention can comprehensively and deeply understand the various patterns and characteristics of human behavior in the security monitoring area, thereby improving the accuracy of calculating the threshold trigger factor corresponding to the behavior warning threshold.

[0097] It should be explained that the dynamic behavior information of personnel refers to the data such as the movement trajectory, speed, residence time, and aggregation of personnel in the area collected by security monitoring equipment. The behavioral modality analysis dimension is a descriptive dimension obtained by analyzing and classifying the dynamic behavior of personnel from multiple angles, such as spatial dimension, temporal dimension, behavioral category dimension, etc. Furthermore, the dynamic behavior information of personnel in the security monitoring area can be collected through video image analysis technology and sensor networks (such as infrared sensors, Bluetooth beacons, etc.).

[0098] In detail, the analysis of the behavioral modal analysis dimension corresponding to the security monitoring equipment based on the dynamic behavior information of the personnel includes:

[0099] Performing noise reduction processing on the personnel dynamic behavior information to obtain noise-reduced dynamic behavior information;

[0100] Performing behavior analysis on the noise reduction dynamic behavior information to obtain a dynamic behavior label;

[0101] Calculating the spatiotemporal distribution intensity of each tag in the dynamic behavior tag, and filtering out characteristic dynamic information in the noise reduction dynamic behavior information based on the spatiotemporal distribution intensity;

[0102] Performing behavior attribute analysis on the characteristic dynamic information to obtain information behavior attributes;

[0103] Dimension mapping is performed on the information behavior attribute to obtain the behavior mode analysis dimension corresponding to the security monitoring device.

[0104] It should be explained that the noise-reduced dynamic behavior information is obtained after the personnel dynamic behavior information is subjected to noise reduction processing to remove erroneous or abnormal data; the dynamic behavior label is a classification identifier assigned to the noise-reduced dynamic behavior information after analyzing different behavior categories through a behavior recognition algorithm; the spatiotemporal distribution intensity is a reflection of the distribution density and activity level of each label in the dynamic behavior label in the time and space dimensions; the characteristic dynamic information is the corresponding data extracted after the noise-reduced dynamic behavior information is filtered out based on the spatiotemporal distribution intensity for key labels; the information behavior attribute is the specific behavior attribute presented by the characteristic dynamic information after feature extraction.

[0105] Furthermore, the dynamic behavior information of the personnel can be denoised by a filtering algorithm such as Kalman filtering to obtain the denoised dynamic behavior information; the denoised dynamic behavior information can be behaviorally analyzed by a convolutional neural network (CNN) model based on deep learning to obtain a dynamic behavior label; based on the spatiotemporal distribution intensity, the characteristic dynamic information in the denoised dynamic behavior information can be screened out by an association rule algorithm in data mining; the characteristic dynamic information can be analyzed for behavioral attributes by combining principal component analysis (PCA) with wavelet transform to obtain information behavior attributes; the information behavior attributes can be dimensionally mapped by a custom mapping function to obtain the behavioral modal analysis dimension corresponding to the security monitoring device.

[0106] Further, as an optional embodiment of the present invention, the calculating the spatiotemporal distribution intensity of each tag in the dynamic behavior tag includes:

[0107] Analyze the behavior events in the dynamic behavior tags, and count the number of events corresponding to the behavior events;

[0108] Extracting a location descriptor corresponding to the behavior event from the dynamic behavior tag, and determining the event spatiotemporal location corresponding to the behavior event based on the location descriptor;

[0109] Based on the spatiotemporal position of the event, calculating the spatiotemporal centroid of the dynamic behavior label;

[0110] Combining the event spatiotemporal position, the event quantity and the tag spatiotemporal centroid, the spatiotemporal distribution intensity of each tag in the dynamic behavior tag is calculated by the following formula:

[0111] ;

[0112] Among them, A represents the spatiotemporal distribution intensity of each label in the dynamic behavior label, Indicates the spatial bandwidth parameter corresponding to the ath label in the dynamic behavior label, Indicates the number of behavior events corresponding to the a-th label in the dynamic behavior label, and Indicates the spatiotemporal position of the behavior of the ath label in the dynamic behavior label, and represents the spatiotemporal centroid of the tag, a represents the serial number of the dynamic behavior tag, q represents the number of dynamic behavior tags, is the Gaussian kernel function.

[0113] It should be explained that the behavioral event refers to a specific activity that is assigned a specific dynamic behavior label; the location descriptor is a statement about the location of the behavioral event in the dynamic behavior label; the event spatiotemporal location is a general term for the time and spatial location of the behavioral event; the label spatiotemporal centroid is the average position of all behavioral events corresponding to the dynamic behavior label in the spatiotemporal dimension; the spatial bandwidth parameter is a parameter that controls the degree of "diffusion" of the Gaussian kernel function in space, which can be set based on the data distribution feature method, such as analyzing the spatial distribution characteristics of the behavioral event data, such as the degree of discreteness and aggregation of the data. If the behavioral events are relatively concentrated in space, the spatial bandwidth parameter can be appropriately smaller; if the distribution is relatively dispersed, the spatial bandwidth parameter needs to be larger, for example, by calculating the standard deviation of the behavioral event location data to measure its discreteness. If the standard deviation is small, it means that the behavioral events are relatively concentrated in space. At this time, a smaller spatial bandwidth parameter can be selected, such as determining the initial spatial bandwidth parameter based on multiples of the standard deviation (such as the standard deviation), and then adjusting it according to the actual effect.

[0114] Furthermore, the behavior events in the dynamic behavior tag can be analyzed by a machine learning algorithm, such as a hidden Markov model; the number of events corresponding to the behavior event can be counted by a counter; the location descriptor corresponding to the behavior event can be extracted from the dynamic behavior tag by a data analysis module, and the data analysis module is compiled by a programming language, such as a JS scripting language; based on the location descriptor, the event spatiotemporal position corresponding to the behavior event is determined using a coordinate conversion algorithm, such as a geographic coordinate conversion algorithm; based on the event spatiotemporal position, the spatiotemporal centroid of the dynamic behavior tag can be calculated using an average function.

[0115] The present invention calculates the threshold trigger factor corresponding to the behavior warning threshold based on the behavior mode analysis dimension, and can judge whether the current personnel behavior is close to or exceeds the warning threshold through the threshold trigger factor, thereby providing a key basis for regional security situation assessment. For example, the closer the threshold trigger factor is to 1, the closer the current personnel behavior is to the warning threshold, and the higher the potential risk.

[0116] Specifically, the calculation of the threshold trigger factor corresponding to the behavior warning threshold based on the behavior mode analysis dimension includes:

[0117] Normalizing the behavioral modal analysis dimension to obtain a normalized dimension value;

[0118] Calculating the dimensional information gain corresponding to the behavioral modal analysis dimension, and assigning the dimensional weight corresponding to the behavioral modal analysis dimension according to the dimensional information gain;

[0119] Querying the dimension safety threshold corresponding to the behavior mode analysis dimension;

[0120] In combination with the dimension security threshold, the normalized dimension value and the dimension weight, the threshold trigger factor corresponding to the behavior warning threshold can be calculated by the following formula:

[0121] ;

[0122] Among them, G represents the threshold trigger factor corresponding to the behavior warning threshold, Indicates the dimension weight corresponding to the bth dimension in the behavioral mode analysis dimension, Indicates the normalized dimension value corresponding to the bth dimension in the behavioral mode analysis dimension. It represents the dimension safety threshold corresponding to the b-th dimension in the behavioral modal analysis dimension, b represents the serial number of the behavioral modal analysis dimension, and r represents the number of behavioral modal analysis dimensions.

[0123] It should be explained that the dimension information gain is the amount of information provided by the behavioral modal analysis dimension for distinguishing different behavior categories (such as safe behavior and abnormal behavior), reflecting the value of this dimension in behavior classification; the dimension weight is a numerical value assigned based on factors such as dimension information gain to measure the relative importance of different behavioral modal analysis dimensions in the overall behavior analysis, and its size reflects the degree of influence of this dimension on the behavior analysis results; the dimension safety threshold is a reasonable numerical range limit set for each behavioral modal analysis dimension based on historical data, business experience and safety requirements, which is used to determine whether the current behavior is in a safe state in this dimension.

[0124] Furthermore, the behavioral modal analysis dimension can be normalized by a minimum-maximum normalization algorithm to obtain a normalized dimension value; the dimensional information gain corresponding to the behavioral modal analysis dimension can be calculated by an information entropy formula, and the ratio of each information gain in the dimensional information gain to the total information gain is calculated; according to the obtained gain ratio, the dimensional weight corresponding to the behavioral modal analysis dimension is allocated; the dimensional safety threshold corresponding to the behavioral modal analysis dimension can be queried in a database of pre-built dimensional safety thresholds, and the database of pre-built dimensional safety thresholds is obtained by collecting a large amount of historical behavior data, combining expert experience and safety specifications, setting reasonable safety threshold ranges for different behavioral modal analysis dimensions, and storing these data in an orderly manner for subsequent rapid query and call of the storage system.

[0125] The present invention evaluates the regional security situation corresponding to the security monitoring area based on the threshold trigger factor, so as to intuitively understand the current security status of the area, and provide strong support for the subsequent formulation of abnormal behavior warning strategies corresponding to the security monitoring area. For example, when the threshold trigger factor is less than 0.5, it is considered that the regional security situation is good and the behavior of personnel is within the normal range; when the threshold trigger factor is between 0.5 and 0.8, it indicates that there are certain security risks in the area and monitoring needs to be strengthened; when the threshold trigger factor is greater than 0.8, it indicates that the regional security situation is severe, abnormal events may occur, and countermeasures need to be taken immediately.

[0126] S3. Collect human image data and movement trajectories of personnel in the security monitoring area, analyze the physical characteristics of the personnel in the security monitoring area based on the human image data, analyze the action pattern characteristics of the personnel in the security monitoring area based on the movement trajectories of the personnel, and calculate the behavior risk entropy value corresponding to the personnel in the security monitoring area by combining the action pattern characteristics and the physical characteristics.

[0127] The present invention analyzes the physical characteristics of people in the security monitoring area based on the human image data, can quickly grasp the key information of people's appearance, assist in identifying suspicious people, provide an important basis for evaluating the behavior risk entropy value in combination with action pattern characteristics, and enhance the early warning ability of security monitoring for potential risks.

[0128] It should be explained that the human image data is image data obtained by shooting people in the security monitoring area with high-definition cameras at different angles and time periods, covering multi-directional images such as the front and side of the people. The movement trajectory of the people is data obtained by real-time recording of the movement path of the people in the security monitoring area using positioning equipment (such as GPS, Bluetooth positioning, etc.), including the location coordinates of the people, movement time and other information. The physical feature attributes refer to the attributes extracted from the human image data that can reflect the appearance and physical characteristics of the people.

[0129] In detail, the analyzing the physical characteristics of the people in the security monitoring area based on the human image data includes:

[0130] Performing image preprocessing on the human body image data to obtain a target human body image;

[0131] Performing main body image segmentation processing on the target human body image to obtain a main body image of the human body;

[0132] Extracting a plurality of human appearance features of the human subject image, and constructing a fusion appearance feature vector of the plurality of human appearance features;

[0133] Calculating the cosine similarity between the fused appearance feature vector and each physical feature in a pre-constructed physical feature database;

[0134] Based on the cosine similarity, the physical features of the people in the security monitoring area are analyzed.

[0135] It should be explained that the target human image is an image containing a specific person obtained after target detection, screening and other processing from the human image data; the human body image is an image containing only the main part of the human body obtained by further processing the target human image and removing irrelevant information such as the background; the multiple human appearance features are features that can reflect the external characteristics of the human body extracted from the human body image, such as facial features, hairstyle features, body shape features, etc.; the fused appearance feature vector is a vector formed by integrating and digitally processing the multiple human appearance features, which is used to comprehensively describe the appearance of the human body; the pre-constructed physical feature database is a database established by collecting a large number of physical feature data of different people, and sorting, labeling and other processing, which is used to store various physical feature information; the cosine similarity represents the similarity between the fused appearance feature vector and the vector corresponding to each physical feature in the pre-constructed physical feature database, which is used to measure the correlation and matching between the two.

[0136] Furthermore, the human image data can be preprocessed by Gaussian filtering, histogram equalization and other image processing algorithms to remove noise and enhance contrast to obtain a target human image; the target human image can be segmented by a semantic segmentation algorithm based on deep learning, such as a U-Net network, to separate the human body from the background to obtain a human body main image; multiple human appearance features of the human body main image can be extracted by models such as a convolutional neural network (CNN), such as ResNet; a fused appearance feature vector of the multiple human appearance features can be constructed by operations such as feature splicing and dimensionality reduction; the cosine similarity between the fused appearance feature vector and each physical feature in the pre-constructed physical feature database can be calculated by a vector dot product operation combined with a vector modulus calculation; based on the cosine similarity, the physical feature attributes corresponding to the personnel in the security monitoring area can be determined and analyzed by comparative analysis and setting a similarity threshold.

[0137] The present invention analyzes the corresponding action pattern characteristics of the personnel in the security monitoring area based on the action trajectory of the personnel, so as to clearly understand the movement and behavior rules of the personnel in the security monitoring area, and calculates the behavior risk entropy value corresponding to the personnel in the security monitoring area by combining the action pattern characteristics and the physical feature attributes, so as to quantify the risk degree of the personnel behavior and provide a scientific reference for security decision-making. It should be explained that the action pattern characteristics refer to the pattern characteristics of the personnel movement and behavior analyzed from the action trajectory of the personnel, and the behavior risk entropy value is a quantitative indicator for measuring the uncertainty and risk degree of personnel behavior. The higher the entropy value, the greater the uncertainty of the personnel behavior and the higher the potential risk.

[0138] In detail, the analysis of the action pattern characteristics of the personnel in the security monitoring area based on the personnel action trajectory includes:

[0139] Performing data cleaning on the movement trajectory of the personnel to obtain the target movement trajectory;

[0140] Identifying a trajectory timestamp corresponding to the target action trajectory, and performing time slicing processing on the target action trajectory based on the trajectory timestamp to obtain a sliced ​​trajectory segment;

[0141] Performing pattern analysis on the slice trajectory segments to obtain trajectory behavior patterns;

[0142] Counting the pattern feature descriptions corresponding to the trajectory behavior patterns, and analyzing the interaction mechanism between the pattern feature descriptions;

[0143] In combination with the pattern feature description and the interaction mechanism, the action pattern features corresponding to the personnel in the security monitoring area are analyzed.

[0144] It should be explained that the target action trajectory is the trajectory obtained by removing repeated, erroneous and obviously abnormal trajectory point data from the personnel action trajectory; the trajectory timestamp is the time information corresponding to each trajectory point in the target action trajectory; the sliced ​​trajectory segment is the trajectory sub-part with relatively independent behavior characteristics divided after the target action trajectory is time-sliced ​​according to the preset time granularity (such as 10 minutes, 30 minutes, etc.) based on the trajectory timestamp; the trajectory behavior pattern is the behavior category determined by the sliced ​​trajectory segment after calculating key parameters (such as average moving speed, number and amplitude of changes in moving direction, acceleration and other dynamic characteristics, as well as spatial characteristics such as area and centroid position), such as normal walking, fast running, etc.; the pattern feature description is the quantitative and characterization description of the behavior pattern corresponding to the trajectory behavior pattern from the aspects of time characteristics (frequency of occurrence in different time periods), spatial characteristics (spatial distribution in the security monitoring area and association with regional functions), and behavior combination characteristics (conversion and combination between different behavior patterns); the interaction mechanism is the internal mechanism for the interaction and mutual influence between the pattern feature descriptions in the dimensions of time, space and behavior combination.

[0145] Furthermore, the data of the person's action trajectory can be cleaned by an outlier detection algorithm to obtain the target action trajectory;

[0146] The trajectory timestamp corresponding to the target action trajectory can be identified by a text parsing tool (such as the regular expression library re in Python), and based on the trajectory timestamp, the target action trajectory can be time-sliced ​​by using the Python Pandas library to obtain a sliced ​​trajectory segment;

[0147] The key parameters of each slice trajectory segment (such as average moving speed, number and amplitude of moving direction changes, acceleration and other dynamic features, and spatial features such as area, center of mass position, etc.) can be calculated first, and then these feature vectors can be classified by using machine learning algorithms such as support vector machine (SVM), K nearest neighbor algorithm (KNN) or recurrent neural network (RNN) and its variants (such as long short-term memory network LSTM) in deep learning to perform pattern analysis on the slice trajectory segment to obtain the trajectory behavior pattern;

[0148] The pattern feature description corresponding to the trajectory behavior pattern can be statistically analyzed by writing a script program to quantify the trajectory behavior pattern in dimensions such as time, space, and behavior combination. For example, the trajectory data can be read using the pandas library and grouped by behavior pattern. For the time dimension, the frequency of occurrence of each behavior pattern in different time periods can be calculated by timestamp. In the spatial dimension, the coordinates of the trajectory points can be parsed with the help of the geopandas library to count the number of occurrences of each behavior pattern in different areas. For the behavior combination dimension, the state transition matrix can be constructed to analyze the conversion frequency between different behavior patterns, thereby completing the quantitative statistics of the trajectory behavior pattern in each dimension. The causal inference algorithm can be used for analysis. The interaction mechanism between the pattern feature descriptions and the causal inference algorithm can clarify the causal relationship between the pattern features, such as judging the causal influence of the time feature on the behavior combination feature; combining the pattern feature descriptions and the interaction mechanism, the action pattern features corresponding to the personnel in the security monitoring area can be analyzed through the decision tree algorithm. The decision tree algorithm is adopted, and the pattern feature descriptions such as time features, space features, and behavior combination features are used as input variables. The key correlation relationship obtained from the interaction mechanism analysis is used as the decision basis to construct a decision tree model. The action pattern category of the personnel behavior is judged according to the output results of the model, thereby analyzing the action pattern features corresponding to the personnel in the security monitoring area.

[0149] Furthermore, the behavior risk entropy value corresponding to the personnel in the security monitoring area is calculated by combining the action mode characteristics and the physical characteristics attributes. Assuming that in the security monitoring area, the action mode characteristics are divided into three types: normal walking, abnormal running, and long-term stay, and the physical characteristics attributes are carrying large packages and not carrying packages. After statistical analysis of the data, the probability of normal walking and carrying large packages is 0.15, and the probability of normal walking and not carrying packages is 0.25. Other combination probabilities are also derived accordingly. Substitute these joint probabilities into the behavior risk entropy value formula for calculation. The specific risk entropy value formula can refer to this formula: , The joint probability of the i-th action mode and the j-th physical characteristic attribute is represented. The larger the risk entropy value is, the greater the uncertainty of the person's behavior is and the higher the potential risk is.

[0150] S4. Collect environmental electromagnetic spectrum data corresponding to the security monitoring area, analyze environmental interference factors corresponding to the environmental electromagnetic spectrum data, and analyze the monitoring adaptability of the security monitoring equipment in the security monitoring area based on the environmental interference factors.

[0151] The present invention analyzes the monitoring adaptability of the security monitoring equipment in the security monitoring area based on the environmental interference factors, so as to effectively evaluate the performance and reliability of the security monitoring equipment in a specific electromagnetic environment, and provide a basis for the subsequent optimization and maintenance of the security monitoring equipment. It should be explained that the security monitoring area is the physical space where the security monitoring equipment is deployed, and the environmental electromagnetic spectrum data is the frequency and intensity distribution information of the electromagnetic signals in the area. The environmental interference factors are the parts of the environmental electromagnetic spectrum data that may interfere with the security monitoring equipment, such as high-intensity electromagnetic signals in a specific frequency band. The monitoring adaptability indicates the adaptability and performance matching degree of the security monitoring equipment in the security monitoring area. Furthermore, the environmental electromagnetic spectrum data corresponding to the security monitoring area can be obtained by real-time acquisition through the electromagnetic spectrum monitoring equipment deployed in the area; the analysis of the environmental interference factors corresponding to the environmental electromagnetic spectrum data can be achieved through signal processing algorithms, and these algorithms can perform feature extraction and interference source location on the collected spectrum data, such as Fourier transform algorithms.

[0152] In detail, the analyzing the monitoring adaptability of the security monitoring device in the security monitoring area based on the environmental interference factor includes:

[0153] Querying the electromagnetic compatibility parameters of the security monitoring equipment, and analyzing the electromagnetic adaptability characteristics of the electromagnetic compatibility parameters of the equipment;

[0154] Analyzing the electromagnetic frequency band index in the electromagnetic adaptability characteristic, and extracting the associated interference factor corresponding to the security monitoring device from the environmental interference factor based on the electromagnetic frequency band index;

[0155] A matching coefficient between the electromagnetic adaptability characteristic and the associated interference element is calculated, and based on the matching coefficient, a monitoring adaptability of the security monitoring device in the security monitoring area is analyzed.

[0156] It should be explained that the electromagnetic compatibility parameters of the equipment are the electromagnetic compatibility standards and indicators based on which the security monitoring equipment is designed and manufactured; the electromagnetic adaptability characteristics are the adaptability to different electromagnetic environments corresponding to the electromagnetic compatibility parameters of the equipment, such as the ability to resist interference in a specific frequency band, the ability to protect against strong electromagnetic pulses, etc. The electromagnetic frequency band indicator is the frequency band range in the electromagnetic adaptability characteristics; the associated interference factors are the interference frequency band information in the environmental interference factors that is relevant to the security monitoring equipment; and the matching coefficient represents the degree of matching between the electromagnetic adaptability characteristics and the associated interference factors.

[0157] Furthermore, the query of the electromagnetic compatibility parameters of the security monitoring equipment corresponding to the equipment can be achieved through the equipment technical manual; the electromagnetic adaptability characteristics corresponding to the electromagnetic compatibility parameters of the equipment can be obtained by analyzing the electromagnetic compatibility test report of the equipment; the corresponding matching coefficient can be obtained by calculating the absolute value of the difference between the value corresponding to the electromagnetic adaptability characteristic and the value of the associated interference factor. For example, in terms of electromagnetic adaptability characteristics, the anti-interference threshold of the device for signals in the 5GHz frequency band is -60dBm, and the associated interference factor is the interference signal strength of the frequency band in the security monitoring area is -40 dBm, then the matching coefficient = |(-60dBm)-(-40dBm)|=20dBm; perform weighted summation on the matching coefficients (different weights are assigned according to the importance of different frequency bands) to obtain a total matching coefficient value, and analyze the monitoring adaptability of the security monitoring equipment in the security monitoring area according to the total matching coefficient value. If the total matching coefficient value is lower than 10dBm, it means that the monitoring adaptability is high; if the total matching coefficient value is between 10dBm and 20dBm, it means that the monitoring adaptability is medium; if the total matching coefficient value exceeds 20dBm, it means that the monitoring adaptability is low.

[0158] S5. Based on the security situation of the area, the behavior risk entropy value, and the monitoring adaptability, formulate an abnormal behavior warning strategy corresponding to the security monitoring area, and based on the abnormal behavior warning strategy, perform real-time warning of abnormal behavior in the security monitoring area to obtain a warning result.

[0159] The present invention formulates an abnormal behavior warning strategy corresponding to the security monitoring area based on the security situation of the area, the behavior risk entropy value, and the monitoring adaptability. The comprehensive multi-dimensional information can improve the scientificity and accuracy of the warning strategy, and based on the abnormal behavior warning strategy, executes real-time warning of abnormal behavior in the security monitoring area, thereby improving the efficiency of real-time warning of abnormal behavior in the security monitoring area. It should be explained that the abnormal behavior warning strategy is a specific method and rule for warning abnormal behavior in the security monitoring area.

[0160] Based on the security situation of the area, the behavioral risk entropy value, and the monitoring adaptability, the steps of formulating the abnormal behavior warning strategy corresponding to the security monitoring area are: if the security situation of the area is good, the behavioral risk entropy value is low, and the monitoring adaptability is high, a normalized warning mechanism is adopted at this time, and a lower warning threshold is set. The warning is triggered only when the personnel behavior data deviates significantly from the normal range. For example, during the daytime period of a normal working day, the personnel action patterns are regular, the behavioral risk entropy value is stable at a low level, the monitoring equipment operates stably and has a high degree of adaptability. At this time, warnings are only issued for some situations that seriously deviate from the normal behavior pattern, such as sudden large-scale gatherings accompanied by abnormal behavior combinations such as fast running. At the same time, the security monitoring system is regularly inspected and optimized to ensure the continuous and stable operation of the system, but frequent warning actions are not performed to avoid false alarms interfering with normal monitoring work.

[0161] If the security situation in the area is tense, the behavioral risk entropy is high, and the monitoring adaptability is low, a highly sensitive early warning strategy will be immediately activated to lower the warning threshold and issue an early warning for any signs of abnormal behavior. For example, during special events or when there are unstable factors in the surrounding area, the regional security situation is tense, and the behavior of people is complex and changeable, resulting in an increase in the behavioral risk entropy. At the same time, the monitoring equipment is affected by factors such as electromagnetic interference, resulting in a decrease in the monitoring adaptability. At this time, as long as there is a slight abnormality in the behavior of the person, such as a single person staying in a restricted area for a long time, or a sudden and drastic change in the speed of movement of the person, an early warning will be issued immediately, and the maintenance and adjustment of the monitoring equipment will be strengthened. By adding spare monitoring equipment, optimizing signal transmission lines, etc., the adaptability and stability of the monitoring equipment can be improved. At the same time, a dedicated person will be arranged to pay real-time attention to the early warning information, respond to and handle abnormal behavior in a timely manner, and ensure the safety of the security monitoring area.

[0162] If the security situation in the area is general, the behavioral risk entropy value is medium, and the monitoring adaptability is medium, a moderately sensitive early warning strategy is adopted, and a moderate early warning threshold is set. A comprehensive judgment is made based on the behavioral pattern characteristics and the risk entropy value. For example, during daily non-peak hours, the regional security situation is relatively stable, the risk entropy value of personnel behavior is at a medium level, and the monitoring equipment is basically operating normally. At this time, for some behavioral patterns with potential risks, such as wandering behavior in a specific area lasting more than a certain threshold, and multiple people continuously entering and exiting sensitive areas in a short period of time, early warnings are issued, and the performance of monitoring equipment is regularly evaluated and calibrated. The early warning strategy is adjusted according to actual conditions to ensure that abnormal behavior can be discovered in a timely manner and excessive warnings can be avoided.

[0163] In combination with the above content, an abnormal behavior warning strategy corresponding to the security monitoring area is generated. Based on the abnormal behavior warning strategy, a real-time monitoring system and a data analysis platform are used to execute real-time warning of abnormal behavior in the security monitoring area to obtain a warning result.

[0164] Compared with the problems described in the background technology, the present invention determines the monitoring environment feature set corresponding to the security monitoring area based on the real-time video stream, so as to fully grasp the real-time status of the security monitoring area, provide a rich and accurate data basis for the subsequent formulation of accurate behavior warning thresholds, and greatly improve the pertinence and effectiveness of security monitoring. Furthermore, the present invention analyzes the behavior modal analysis dimension corresponding to the security monitoring equipment based on the dynamic behavior information of the personnel, so as to fully and deeply understand the various patterns and characteristics of the behavior of the personnel in the security monitoring area, thereby improving the accuracy of calculating the threshold trigger factor corresponding to the behavior warning threshold. The present invention analyzes the physical feature attributes corresponding to the personnel in the security monitoring area based on the human image data, so as to quickly grasp the key information of the personnel's appearance, assist in identifying suspicious personnel, and provide a reference for combining behavior with human image data. The dynamic pattern characteristics provide an important basis for evaluating the behavior risk entropy value, and improve the early warning ability of security monitoring for potential risks. Furthermore, the present invention analyzes the monitoring adaptability of the security monitoring equipment in the security monitoring area based on the environmental interference factors, and can effectively evaluate the performance and reliability of the security monitoring equipment in a specific electromagnetic environment, and provide a basis for the subsequent optimization and maintenance of the security monitoring equipment. Furthermore, the present invention formulates an abnormal behavior early warning strategy corresponding to the security monitoring area based on the security situation of the area, the behavior risk entropy value, and the monitoring adaptability. The comprehensive multi-dimensional information can improve the scientificity and accuracy of the early warning strategy, and based on the abnormal behavior early warning strategy, execute the real-time early warning of abnormal behavior in the security monitoring area, thereby improving the real-time early warning efficiency of abnormal behavior in the security monitoring area. Therefore, the real-time early warning method and system for abnormal behavior based on intelligent security provided in the embodiment of the present invention can improve the real-time early warning efficiency of abnormal behavior under intelligent security.

[0165] Embodiment 2:

[0166] like Figure 2 The figure shows a functional module diagram of a real-time warning system for abnormal behavior based on intelligent security in the present invention.

[0167] The real-time warning system 200 for abnormal behavior based on intelligent security described in the present invention can be installed in an electronic device. According to the functions implemented, the real-time warning system for abnormal behavior based on intelligent security can include a behavior warning threshold setting module 201, a regional security situation assessment module 202, a behavior risk entropy value calculation module 203, a monitoring fitness analysis module 204 and an abnormal behavior real-time warning module 205. The module described in the present invention can also be called a unit, which refers to a series of computer program segments that can be executed by an electronic device processor and can complete fixed functions, which are stored in the memory of the electronic device.

[0168] In the embodiment of the present invention, the functions of each module / unit are as follows:

[0169] The behavior warning threshold setting module 201 is used to obtain the security monitoring equipment and real-time video stream of the security monitoring area, determine the monitoring environment feature set corresponding to the security monitoring area based on the real-time video stream, and formulate the behavior warning threshold corresponding to the security monitoring equipment based on the monitoring environment feature set;

[0170] The regional security situation assessment module 202 is used to collect dynamic behavior information of personnel in the security monitoring area, analyze the behavior mode analysis dimension corresponding to the security monitoring device based on the dynamic behavior information of personnel, calculate the threshold trigger factor corresponding to the behavior warning threshold based on the behavior mode analysis dimension, and evaluate the regional security situation corresponding to the security monitoring area based on the threshold trigger factor;

[0171] The behavior risk entropy value calculation module 203 is used to collect human image data and personnel movement trajectories in the security monitoring area, analyze the physical characteristics of the personnel in the security monitoring area based on the human image data, analyze the action pattern characteristics of the personnel in the security monitoring area based on the movement trajectories of the personnel, and calculate the behavior risk entropy value corresponding to the personnel in the security monitoring area by combining the action pattern characteristics and the physical characteristics;

[0172] The monitoring adaptability analysis module 204 is used to collect environmental electromagnetic spectrum data corresponding to the security monitoring area, analyze environmental interference factors corresponding to the environmental electromagnetic spectrum data, and analyze the monitoring adaptability of the security monitoring device in the security monitoring area based on the environmental interference factors;

[0173] The abnormal behavior real-time warning module 205 is used to formulate an abnormal behavior warning strategy corresponding to the security monitoring area based on the security situation of the area, the behavior risk entropy value, and the monitoring adaptability, and based on the abnormal behavior warning strategy, execute real-time warning of abnormal behavior in the security monitoring area to obtain a warning result.

[0174] In detail, each module in the abnormal behavior real-time warning system 200 based on intelligent security in the embodiment of the present invention is used in the same manner as above. Figure 1 The same technical means are used as the real-time early warning method for abnormal behavior based on intelligent security, and can produce the same technical effects, so they will not be repeated here.

[0175] It is obvious to those skilled in the art that the present invention is not limited to the details of the above exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0176] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solution of the present invention can be modified or replaced by equivalents without departing from the spirit and scope of the technical solution of the present invention.

Claims

1. A real-time warning method for abnormal behavior based on intelligent security, characterized in that: The method comprises: Obtain security monitoring equipment and real-time video streams of a security monitoring area, determine a monitoring environment feature set corresponding to the security monitoring area based on the real-time video stream, and formulate a behavior warning threshold corresponding to the security monitoring equipment based on the monitoring environment feature set; Collecting dynamic behavior information of personnel in the security monitoring area, analyzing the behavior mode analysis dimension corresponding to the security monitoring equipment based on the dynamic behavior information of personnel, calculating the threshold trigger factor corresponding to the behavior warning threshold based on the behavior mode analysis dimension, and evaluating the regional security situation corresponding to the security monitoring area based on the threshold trigger factor; Collecting human image data and personnel movement trajectories in the security monitoring area, analyzing the physical characteristics of the personnel in the security monitoring area based on the human image data, analyzing the action pattern characteristics of the personnel in the security monitoring area based on the movement trajectories of the personnel, and calculating the behavior risk entropy value corresponding to the personnel in the security monitoring area by combining the action pattern characteristics and the physical characteristics; Collecting environmental electromagnetic spectrum data corresponding to the security monitoring area, analyzing environmental interference factors corresponding to the environmental electromagnetic spectrum data, and analyzing the monitoring adaptability of the security monitoring device in the security monitoring area based on the environmental interference factors; Based on the security situation of the area, the behavior risk entropy value, and the monitoring adaptability, an abnormal behavior warning strategy corresponding to the security monitoring area is formulated. Based on the abnormal behavior warning strategy, real-time warning of abnormal behavior in the security monitoring area is executed to obtain a warning result.

2. The real-time warning method for abnormal behavior based on intelligent security as claimed in claim 1 is characterized in that: The step of determining a monitoring environment feature set corresponding to the security monitoring area based on the real-time video stream includes: Performing frame processing on the real-time video stream to obtain a frame-based video stream; Performing target detection on the frame-by-frame video stream to obtain a video detection target; Based on the video detection target, determining the monitoring target and scene elements within the security monitoring area; Extracting features corresponding to the monitoring target and the scene elements respectively to obtain a target feature subset and an environment feature subset; Performing behavior tracking processing on the monitored target to obtain a behavior feature subset; The target feature subset, the environment feature subset and the behavior feature subset are combined to determine a monitoring environment feature set corresponding to the security monitoring area.

3. The real-time warning method for abnormal behavior based on intelligent security as claimed in claim 1 is characterized in that: The step of formulating a behavior warning threshold value corresponding to the security monitoring device based on the monitoring environment feature set includes: Identify the feature identifier corresponding to each feature in the monitoring environment feature set, and extract the key feature identifier from the feature identifiers; Querying the regional monitoring criteria of the security monitoring area, and analyzing the correlation between the regional monitoring criteria and the key feature identifier; Based on the correlation, selecting target environment features from the monitoring environment feature set; Collecting feature history data corresponding to the target environment feature, and determining the abnormal behavior type and abnormal behavior threshold corresponding to the target environment feature based on the feature history data; In combination with the target environment characteristics, the abnormal behavior type and the abnormal behavior threshold, a behavior warning threshold corresponding to the security monitoring device is formulated.

4. The real-time warning method for abnormal behavior based on intelligent security as claimed in claim 1 is characterized in that: The analyzing the behavioral modal analysis dimension corresponding to the security monitoring device based on the dynamic behavior information of the personnel includes: Performing noise reduction processing on the personnel dynamic behavior information to obtain noise-reduced dynamic behavior information; Performing behavior analysis on the noise reduction dynamic behavior information to obtain a dynamic behavior label; Calculating the spatiotemporal distribution intensity of each tag in the dynamic behavior tag, and filtering out characteristic dynamic information in the noise reduction dynamic behavior information based on the spatiotemporal distribution intensity; Performing behavior attribute analysis on the characteristic dynamic information to obtain information behavior attributes; Dimension mapping is performed on the information behavior attribute to obtain the behavior mode analysis dimension corresponding to the security monitoring device.

5. The real-time warning method for abnormal behavior based on intelligent security as claimed in claim 4 is characterized in that: The calculating the spatiotemporal distribution intensity of each tag in the dynamic behavior tag comprises: Analyze the behavior events in the dynamic behavior tags, and count the number of events corresponding to the behavior events; Extracting a location descriptor corresponding to the behavior event from the dynamic behavior tag, and determining the event spatiotemporal location corresponding to the behavior event based on the location descriptor; Based on the spatiotemporal position of the event, calculating the spatiotemporal centroid of the dynamic behavior label; Combining the event spatiotemporal position, the event quantity and the tag spatiotemporal centroid, the spatiotemporal distribution intensity of each tag in the dynamic behavior tag is calculated by the following formula: ; Among them, A represents the spatiotemporal distribution intensity of each label in the dynamic behavior label, Indicates the spatial bandwidth parameter corresponding to the ath label in the dynamic behavior label, Indicates the number of behavior events corresponding to the a-th label in the dynamic behavior label, and Indicates the spatiotemporal position of the behavior of the ath label in the dynamic behavior label, and represents the spatiotemporal centroid of the tag, a represents the serial number of the dynamic behavior tag, q represents the number of dynamic behavior tags, is the Gaussian kernel function.

6. The real-time warning method for abnormal behavior based on intelligent security as claimed in claim 1 is characterized in that: The calculating, based on the behavior mode analysis dimension, a threshold trigger factor corresponding to the behavior warning threshold, includes: Normalizing the behavioral modal analysis dimension to obtain a normalized dimension value; Calculating the dimensional information gain corresponding to the behavioral modal analysis dimension, and assigning the dimensional weight corresponding to the behavioral modal analysis dimension according to the dimensional information gain; Querying the dimension safety threshold corresponding to the behavior mode analysis dimension; In combination with the dimension security threshold, the normalized dimension value and the dimension weight, the threshold trigger factor corresponding to the behavior warning threshold can be calculated by the following formula: ; Among them, G represents the threshold trigger factor corresponding to the behavior warning threshold, Indicates the dimension weight corresponding to the bth dimension in the behavioral mode analysis dimension, Indicates the normalized dimension value corresponding to the bth dimension in the behavioral mode analysis dimension. It represents the dimension safety threshold corresponding to the b-th dimension in the behavioral modal analysis dimension, b represents the serial number of the behavioral modal analysis dimension, and r represents the number of behavioral modal analysis dimensions.

7. The real-time warning method for abnormal behavior based on intelligent security as claimed in claim 1 is characterized in that: The analyzing the physical features of the people in the security monitoring area based on the human image data includes: Performing image preprocessing on the human body image data to obtain a target human body image; Performing main body image segmentation processing on the target human body image to obtain a main body image of the human body; Extracting a plurality of human appearance features of the human subject image, and constructing a fusion appearance feature vector of the plurality of human appearance features; Calculating the cosine similarity between the fused appearance feature vector and each physical feature in a pre-constructed physical feature database; Based on the cosine similarity, the physical features of the people in the security monitoring area are analyzed.

8. The real-time warning method for abnormal behavior based on intelligent security as claimed in claim 1 is characterized in that: The analyzing the action pattern characteristics of the personnel in the security monitoring area based on the personnel action trajectory includes: Performing data cleaning on the movement trajectory of the personnel to obtain the target movement trajectory; Identifying a trajectory timestamp corresponding to the target action trajectory, and performing time slicing processing on the target action trajectory based on the trajectory timestamp to obtain a sliced ​​trajectory segment; Performing pattern analysis on the slice trajectory segments to obtain trajectory behavior patterns; Counting the pattern feature descriptions corresponding to the trajectory behavior patterns, and analyzing the interaction mechanism between the pattern feature descriptions; In combination with the pattern feature description and the interaction mechanism, the action pattern features corresponding to the personnel in the security monitoring area are analyzed.

9. The real-time warning method for abnormal behavior based on intelligent security as claimed in claim 1, characterized in that: The analyzing the monitoring adaptability of the security monitoring device in the security monitoring area based on the environmental interference factor includes: Querying the electromagnetic compatibility parameters of the security monitoring equipment, and analyzing the electromagnetic adaptability characteristics of the electromagnetic compatibility parameters of the equipment; Analyzing the electromagnetic frequency band index in the electromagnetic adaptability characteristics, and extracting the associated interference factors corresponding to the security monitoring equipment from the environmental interference factors based on the electromagnetic frequency band index; A matching coefficient between the electromagnetic adaptability characteristic and the associated interference element is calculated, and based on the matching coefficient, a monitoring adaptability of the security monitoring device in the security monitoring area is analyzed.

10. A real-time warning system for abnormal behavior based on intelligent security, characterized in that: The system comprises: A behavior warning threshold setting module is used to obtain security monitoring equipment and real-time video streams in a security monitoring area, determine a monitoring environment feature set corresponding to the security monitoring area based on the real-time video stream, and formulate a behavior warning threshold corresponding to the security monitoring equipment based on the monitoring environment feature set; A regional security situation assessment module is used to collect dynamic behavior information of personnel in the security monitoring area, analyze the behavior mode analysis dimension corresponding to the security monitoring equipment based on the dynamic behavior information of personnel, calculate the threshold trigger factor corresponding to the behavior warning threshold based on the behavior mode analysis dimension, and evaluate the regional security situation corresponding to the security monitoring area based on the threshold trigger factor; A behavior risk entropy value calculation module is used to collect human image data and personnel movement trajectories in the security monitoring area, analyze the physical characteristics of the personnel in the security monitoring area based on the human image data, analyze the action pattern characteristics of the personnel in the security monitoring area based on the movement trajectories of the personnel, and calculate the behavior risk entropy value corresponding to the personnel in the security monitoring area by combining the action pattern characteristics and the physical characteristics; A monitoring adaptability analysis module, used to collect environmental electromagnetic spectrum data corresponding to the security monitoring area, analyze environmental interference factors corresponding to the environmental electromagnetic spectrum data, and analyze the monitoring adaptability of the security monitoring device in the security monitoring area based on the environmental interference factors; The abnormal behavior real-time warning module is used to formulate an abnormal behavior warning strategy corresponding to the security monitoring area based on the security situation of the area, the behavior risk entropy value, and the monitoring adaptability, and based on the abnormal behavior warning strategy, execute real-time warning of abnormal behavior in the security monitoring area to obtain a warning result.

Citation Information

Patent Citations

  • Fire scene intelligent monitoring method and system

    CN112312081A

  • Intelligent security management system based on behavior big data analysis

    CN116823529A