Archive management and risk detection processing method based on AI element reading
By adopting real-time monitoring and risk assessment technology based on AI in the archive management system, the problem of fast locking of servers to be damaged during human sabotage is solved, and efficient and secure management of archives and timely backup of data is achieved.
Patent Information
- Application Number
- CN202510060311.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
When facing human damage, it is difficult for the existing archive management system to quickly lock the server to be destroyed, resulting in too low data backup speed and limited data recovery.
Using AI-based feature reading technology, real-time monitoring of user identity, host panel and security management programs in the server, risk identification and level assessment, and real-time monitoring and backup priority adjustments are carried out through RFID tags and high-definition cameras.
It improves the security level and management efficiency of archives, ensures timely backup and security management of data, and avoids data leakage, tampering, loss and replacement.
Smart Images

Figure CN119990167A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of archive management risk detection, and in particular, relates to an archive management and risk detection processing method based on AI element reading. Background Art
[0002] User files are usually stored in servers. Different users usually have their own file storage servers, which are usually installed in the same computer room by file storage service providers. In order to save space, a large number of servers are usually arranged in a way that Figure 1 The server is installed in the computer room in a matrix arrangement, with rows and columns of servers on the same side of the entrance corridor aligned, and the spacing between rows and columns is the same. For easy identification, archive storage service providers usually attach exclusive labels to the cabinets of dedicated servers. When the server needs to be maintained, these attached labels can be used to quickly find the server to be maintained.
[0003] In archive management, the biggest risk is human damage. The most direct way to cause human damage is to physically damage the server to be damaged in the computer room. The possibility of repairing a physically damaged server is lower than that of an online attack. When the detection system detects that the archive data stored in the server is at risk of being damaged, the disposal method is usually to perform an emergency backup of the archive data stored in the server. However, in the case of physical damage to the server by the intruder in the computer room, how to quickly lock the server object to be damaged by the intruder so that the archive data backup of the damaged object can be accessed as early as possible and as much archive data as possible can be recovered. This has become a technical problem in the field of archive management security detection technology.
[0004] In addition, under normal circumstances, the computing power of the emergency backup platform that communicates with each server is limited. When it is determined that the number of suspected objects to be destroyed is large, if the computing power is allocated in an even distribution manner, the emergency backup platform may not allocate enough computing power to the servers that unauthorized personnel really want to destroy, resulting in too low a data backup speed for the servers that may really be wanted to be destroyed, and a limited amount of data recovered. Summary of the invention
[0005] The purpose of the present invention is to provide an archive management and risk detection processing method based on AI element reading, which solves the problems of low security and limited amount of data recovery in existing archive management by real-time monitoring of user identity, host panel and security management program in the server, risk identification and risk level assessment of monitoring, and timely backup of archives.
[0006] In order to solve the above technical problems, the present invention is achieved through the following technical solutions:
[0007] The present invention is a file management and risk detection processing method based on AI element reading, comprising the following steps:
[0008] Step S1: Each server in the computer room stores files according to a preset plan, and an RFID tag storing specific file information is attached to the cabinet;
[0009] Step S2: Setting a monitoring area in front of the server and enabling risk detection for people entering the monitoring area;
[0010] Step S3: pre-processing the collected video images in the monitoring area;
[0011] Step S4: extracting information from the processed image and determining whether the extracted information exceeds a threshold;
[0012] Step S5: If the threshold is exceeded, an alarm message is issued to notify the backend server;
[0013] Step S6: After receiving the alarm information, the backend server matches the host number with the emergency backup object to find the emergency backup object;
[0014] Step S7: The emergency backup object updates the data backup computing power from large to small according to the risk of file damage from heavy to light.
[0015] As a preferred technical solution, in step S1, a system backup program, an application program, a monitoring and logging program, a security management program, a storage management program and a performance optimization program are deployed in the server; the security management program includes authority management, process management and operation management; the authority management is used to store user authority information to ensure that different users' access rights to resources are reasonably controlled; the process management is used to manage the circulation process of archives, including the application, approval, borrowing and return of archives; the operation management is used to restrict user operations according to user authority. Specifically: the system backup program is the operating system files and configuration files stored in the server, which are used to recover when the system fails; the application program is the application-related files stored in the server, which facilitates the deployment and updating of the application; the monitoring and logging program is the log file stored in the server, which records the system's operating status and error information, and is used to monitor the health of the server and troubleshoot problems; the security management program is the security-related files stored in the server, such as SSL certificates, key files, etc., which are used to ensure the security of data transmission;
[0016] The server also includes archive statistics and reporting functions and archive destruction and archiving functions; archive statistics and reporting are used to provide various statistical and reporting functions to help managers understand and analyze the archive management situation; archive destruction and archiving are used to destroy archives that do not need to be retained, and archive and preserve archives that need to be retained for a long time.
[0017] As a preferred technical solution, in step S2, the risk detection process is as follows:
[0018] Step S21: A high-definition camera above the server cabinet collects video images in the monitoring area;
[0019] Step S22: Recognize the face in the video image to determine whether it is a staff member;
[0020] If not, the alarm procedure is started directly;
[0021] If yes, then obtain the user's operation authority and execute step S23;
[0022] Step S23: Process the images captured by the high-definition camera to determine whether the user has abnormal behavior;
[0023] Step S24: The server monitors the user operation to determine whether the user operation exceeds the authority or violates the regulations;
[0024] Step S25: If yes, start the alarm procedure.
[0025] As a preferred technical solution, in step S3, the process of preprocessing the video image is as follows:
[0026] Step S31, grayscale processing: convert the color video image into a grayscale image; simplify the image representation by reducing the color information of the image and retaining only the brightness information, thereby reducing the complexity and computational complexity of image processing. In the field of image processing and computer vision, grayscale processing is a basic and commonly used operation that can simplify image information, reduce data dimensions and increase processing speed. Common grayscale algorithms include the average method, weighted average method, maximum method and minimum method. Among them, the weighted average method is one of the most commonly used methods. It assigns different weights to the three RGB channels according to the sensitivity of the human eye to different colors, and then calculates the weighted average as the grayscale value;
[0027] Step S32, binarization: an image processing method that converts a grayscale image into black and white by setting a threshold; sets the grayscale value of a pixel to 0 (black) or 255 (white) to simplify the image information, specifically by reducing the color information of the image to highlight key features such as the shape and edge of the image, which can not only improve the efficiency of image processing, but also make subsequent image analysis, target detection, and feature extraction operations simpler and faster; commonly used binarization methods include the global threshold method, the adaptive threshold method, and the Otsu threshold method. The global threshold method selects a fixed threshold, compares the grayscale values of all pixels with the threshold, and sets the pixel to black or white based on the comparison result. The adaptive threshold rule dynamically determines the threshold based on the local area around each pixel, so that each pixel has its own threshold. This method can better adapt to local changes in the image; the Otsu threshold method is a method for automatically determining the optimal threshold. It selects the optimal threshold by optimizing the inter-class variance so that the binarized image has the largest inter-class variance;
[0028] Step S33, filtering, smoothing and noise reduction processing: remove random noise in the image, and improve the quality and visual effect of the image by reducing the noise and detail information in the image; commonly used filtering methods include linear filtering and nonlinear filtering. Linear filters such as the neighborhood averaging method remove noise by averaging neighboring pixels, but may make the image blurry. Nonlinear filters such as median filtering replace the value of the central pixel with the median of the pixels in the neighborhood, which can better retain the edge information of the image while removing noise;
[0029] Step S34, image tilt correction processing: correcting the tilted image; adjusting the tilted image to an upright and aligned state through mathematical transformation to ensure that the image content can be accurately aligned;
[0030] As a preferred technical solution, in step S33, the specific formula for removing random noise in the image is as follows:
[0031]
[0032] Where T is the given edge detection threshold, D(f) is the original image, G(x,y) is the image outside the edge, and G x ,G y They are the convolution of the edge detection operators in the horizontal and vertical directions of the pixel point (x, y).
[0033] As a preferred technical solution, in step S4, the image needs to be segmented before information extraction is performed on the image. The specific steps are as follows:
[0034] Step S41: using an edge detection operator to perform a convolution operation on the image, and performing a binarization process on the image, and using a Hough algorithm to detect straight line segments on the edge;
[0035] Step S42: correcting the image by rotating the image according to the calculated inclination angle of the straight line segment relative to the horizontal direction;
[0036] Step S43: retaining the straight line segments in the vertical and horizontal directions, calculating the distance between the endpoints of different straight line segments, and if the distance between them is less than a set threshold, connecting the straight line segments to obtain the external contour of the server host;
[0037] Step S44: after determining the external outline of the server host, determine the positions of the interfaces, buttons, and indicator lights on the server host panel according to the proportions;
[0038] Step S45: Monitor the interfaces, buttons, and indicator lights on the panel to determine the user operation and the working status of the current server host.
[0039] As a preferred technical solution, in step S4, when extracting information from the processed image, the statistical features of the server host panel image are analyzed, the grid features are abstracted using a local grayscale algorithm, and the feature vector output is provided to classification recognition; the classification recognition uses a classifier trained by a neural network, calculates whether the nonlinear activation function is greater than a threshold by setting the connection weights, and outputs classification information. The specific calculation formula is as follows:
[0040]
[0041] In the formula, x j Input information to the neuron, ω kj is the weight of the neuron k connection, θ k is the threshold value, is the activation function, y k is the output of neuron k.
[0042] As a preferred technical solution, in step S6, when an emergency backup object is matched, it is necessary to check whether the backed up host has sufficient disk space, memory and processor resources to back up the data in the server; when the risk host produces a public operating system image plus an independent incremental file, the information stored in the local agent is compressed and sorted in descending order according to the risk of file damage, and added to the backup queue for backing up in sequence.
[0043] As a preferred technical solution, the degree of the risk of archive damage from severe to mild is expressed by the formula: R=P×F; wherein R, P, and F represent archive risk, possibility of archive damage, and consequence of archive damage, respectively; wherein, possibility of archive damage is divided into five levels: frequent, regular, possible, impossible, and very unlikely, prefixed with numbers 5 to 1; the consequence of archive damage includes archive leakage, archive loss, archive tampering, and archive exchange, which are also divided into five levels: not serious, not too serious, general, relatively serious, and very serious, replaced by letters A to E.
[0044] The present invention has the following beneficial effects:
[0045] (1) The present invention sets up a monitoring area in front of the server to perform facial recognition to determine the identity of users entering the area, and at the same time performs real-time monitoring of the host panel and the security management program in the server, thereby improving the security level of the files and the efficiency of file management.
[0046] (2) The present invention monitors user operations, identifies risks and assesses risk levels of operations, and backs up and destroys archives in a timely manner to prevent documents from being leaked, tampered with, lost, and replaced, thereby ensuring the safe management of archives.
[0047] Of course, any product implementing the present invention does not necessarily need to achieve all of the advantages described above at the same time. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for describing the embodiments are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0049] Figure 1 This is a flow chart of the archive management and risk detection processing method based on AI element reading of the present invention. DETAILED DESCRIPTION
[0050] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0051] In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0052] In order to make the purpose, technical solution and advantages of this application clearer, the following Figure 1 The implementation methods of the present application are described in further detail.
[0053] Before introducing the embodiments of the present application, the server intrusion detection technology is first described.
[0054] 1. Log monitoring and analysis
[0055] (1) System log check: The server will record important data such as user login information and system activities. By monitoring and analyzing these logs, any abnormal activities can be discovered in a timely manner. For example, multiple consecutive login failures and frequent system restarts may be signs of intrusion.
[0056] (2) Log analysis tools: With the help of tools such as ELK Stack and Splunk, logs can be automatically processed and relevant reports can be generated to help administrators quickly detect abnormal behavior.
[0057] 2. Abnormal behavior detection
[0058] (1) Network traffic monitoring: By monitoring the server's network traffic, malicious intrusions can be discovered and prevented. Commonly used network traffic monitoring tools include Snort, Suricata, etc.
[0059] (2) Process and service monitoring: Check the processes and services running on the server. If any unknown or abnormal processes are found, they may be backdoor programs left by intruders.
[0060] 3. File integrity check
[0061] (1) Hash value comparison: The hash value of the file on the server is calculated regularly and compared with the hash value of the original file to detect whether the file has been tampered with.
[0062] (2) Use file integrity checking tools such as Tripwire and AIDE to help administrators quickly identify file changes.
[0063] 4. Vulnerability scanning and security assessment
[0064] (1) Regular vulnerability scanning: Use vulnerability scanning tools (such as Nessus, OpenVAS, etc.) to perform a comprehensive scan of the server to identify potential security vulnerabilities and patch them in a timely manner.
[0065] (2) Security configuration review: Regularly review the server's security configuration to ensure that there are no unnecessary open ports and services.
[0066] 5. Detection System (IDS) and Intrusion Prevention System (IPS)
[0067] (1) IDS / IPS deployment: Install intrusion detection system (IDS) and intrusion prevention system (IPS) to monitor the server's network activities and system logs in real time, and detect and alert any abnormal behavior.
[0068] (2) Configure rules: Configure IDS / IPS rules based on the actual situation of the enterprise to detect and prevent various known intrusion behaviors.
[0069] 6. Honeypot Technology
[0070] Set up a honeypot: A honeypot is a virtual or physical simulated system designed to attract attackers so that their behavior can be analyzed and relevant information can be collected. Honeypots can be used to detect attack types, attacker techniques and methods, and provide a deeper understanding of the server system.
[0071] 7. Strengthen access control
[0072] (1) Multi-factor authentication: Use multi-factor authentication, access control lists and other technologies to limit illegal access.
[0073] (2) Account and permission management: Strictly manage accounts and permissions, and regularly audit user accounts and permission settings to ensure the reasonable allocation and use of permissions.
[0074] 8. Real-time alarm mechanism
[0075] Set up alert rules: Set up a real-time alert mechanism on the server to notify the administrator immediately when an intrusion is discovered so that timely countermeasures can be taken. The alert mechanism can be used to notify via email, SMS, etc.
[0076] In order to make the purpose, technical solutions and advantages of this application more clear, the following Figure 1 It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0077] See also Figure 1 As shown, the present invention is a file management and risk detection processing method based on AI element reading, comprising the following steps:
[0078] Step S1: Each server in the computer room stores files according to a preset plan, and an RFID tag storing specific file information is attached to the cabinet;
[0079] Step S2: Setting a monitoring area in front of the server and enabling risk detection for people entering the monitoring area;
[0080] Step S3: pre-processing the collected video images in the monitoring area;
[0081] Step S4: extracting information from the processed image and determining whether the extracted information exceeds a threshold;
[0082] Step S5: If the threshold is exceeded, an alarm message is issued to notify the backend server;
[0083] Step S6: After receiving the alarm information, the backend server matches the host number with the emergency backup object to find the emergency backup object;
[0084] Step S7: The emergency backup object updates the data backup computing power from large to small according to the risk of file damage from heavy to light.
[0085] In step S1, the server is deployed with system backup programs, applications, monitoring and logging programs, security management programs, storage management programs, and performance optimization programs; the security management program includes authority management, process management, and operation management; authority management is used to store user authority information to ensure that different users' access rights to resources are reasonably controlled; process management is used to manage the circulation of archives, including the application, approval, borrowing, and return of archives; operation management is used to restrict user operations according to user authority. Specifically: the system backup program is the operating system files and configuration files stored by the server, which are used to recover when the system fails; the application is the application-related files stored in the server, which facilitates the deployment and updating of the application; the monitoring and logging program is the log file stored by the server, which records the system's operating status and error information, and is used to monitor the health of the server and troubleshoot problems; the security management program is the security-related files stored by the server, such as SSL certificates, key files, etc., which are used to ensure the security of data transmission;
[0086] The server also includes file statistics and reporting functions and file destruction and archiving functions; file statistics and reporting are used to provide various statistics and reporting functions to help managers understand and analyze the status of file management. File destruction and archiving are used to destroy files that do not need to be retained, and to archive and preserve files that need to be retained for a long time.
[0087] In step S2, the risk detection process is as follows:
[0088] Step S21: A high-definition camera above the server cabinet collects video images in the monitoring area;
[0089] Step S22: Recognize the face in the video image to determine whether it is a staff member;
[0090] If not, the alarm procedure is started directly;
[0091] If yes, then obtain the user's operation authority and execute step S23;
[0092] Step S23: Process the images captured by the high-definition camera to determine whether the user has abnormal behavior;
[0093] Step S24: The server monitors the user operation to determine whether the user operation exceeds the authority or violates the regulations;
[0094] Step S25: If yes, start the alarm procedure.
[0095] In step S3, the process of preprocessing the video image is as follows:
[0096] Step S31, grayscale processing: convert the color video image into a grayscale image; simplify the image representation by reducing the color information of the image and retaining only the brightness information, thereby reducing the complexity and computational complexity of image processing. In the field of image processing and computer vision, grayscale processing is a basic and commonly used operation that can simplify image information, reduce data dimensions and increase processing speed. Common grayscale algorithms include the average method, weighted average method, maximum method and minimum method. Among them, the weighted average method is one of the most commonly used methods. It assigns different weights to the three RGB channels according to the sensitivity of the human eye to different colors, and then calculates the weighted average as the grayscale value;
[0097] Step S32, binarization: an image processing method that converts a grayscale image into black and white by setting a threshold; sets the grayscale value of a pixel to 0 (black) or 255 (white) to simplify the image information, specifically by reducing the color information of the image to highlight key features such as the shape and edge of the image, which can not only improve the efficiency of image processing, but also make subsequent image analysis, target detection, and feature extraction operations simpler and faster; commonly used binarization methods include the global threshold method, the adaptive threshold method, and the Otsu threshold method. The global threshold method selects a fixed threshold, compares the grayscale values of all pixels with the threshold, and sets the pixel to black or white based on the comparison result. The adaptive threshold rule dynamically determines the threshold based on the local area around each pixel, so that each pixel has its own threshold. This method can better adapt to local changes in the image; the Otsu threshold method is a method for automatically determining the optimal threshold. It selects the optimal threshold by optimizing the inter-class variance so that the binarized image has the largest inter-class variance;
[0098] Step S33, filtering, smoothing and noise reduction processing: remove random noise in the image, and improve the quality and visual effect of the image by reducing the noise and detail information in the image; commonly used filtering methods include linear filtering and nonlinear filtering. Linear filters such as the neighborhood averaging method remove noise by averaging neighboring pixels, but may make the image blurry. Nonlinear filters such as median filtering replace the value of the central pixel with the median of the pixels in the neighborhood, which can better retain the edge information of the image while removing noise;
[0099] Step S34, image tilt correction processing: correcting the tilted image; adjusting the tilted image to an upright and aligned state through mathematical transformation to ensure that the image content can be accurately aligned;
[0100] In step S33, the specific formula for removing random noise in the image is as follows:
[0101]
[0102] Where T is the given edge detection threshold, D(f) is the original image, G(x,y) is the image outside the edge, and G x ,G y They are the convolution of the edge detection operators in the horizontal and vertical directions of the pixel point (x, y).
[0103] In step S4, the image needs to be segmented before information extraction is performed on the image. The specific steps are as follows:
[0104] Step S41: using an edge detection operator to perform a convolution operation on the image, and performing a binarization process on the image, and using a Hough algorithm to detect straight line segments on the edge;
[0105] Step S42: correcting the image by rotating the image according to the calculated inclination angle of the straight line segment relative to the horizontal direction;
[0106] Step S43: retaining the straight line segments in the vertical and horizontal directions, calculating the distance between the endpoints of different straight line segments, and if the distance between them is less than a set threshold, connecting the straight line segments to obtain the external contour of the server host;
[0107] Step S44: after determining the external outline of the server host, determine the positions of the interfaces, buttons, and indicator lights on the server host panel according to the proportions;
[0108] Step S45: Monitor the interfaces, buttons, and indicator lights on the panel to determine the user operation and the working status of the current server host.
[0109] In step S4, when extracting information from the processed image, the statistical features of the server host panel image are analyzed, the grid features are abstracted using a local grayscale algorithm, and the feature vector output is provided to classification recognition; classification recognition uses a classifier trained with a neural network, calculates whether the nonlinear activation function is greater than a threshold by setting the connection weights, and outputs classification information. The specific calculation formula is as follows:
[0110]
[0111] In the formula, x j Input information to the neuron, ω kj is the weight of the neuron k connection, θ k is the threshold value, is the activation function, y k is the output of neuron k.
[0112] In step S6, when the emergency backup object is matched, it is necessary to check whether the backed up host has sufficient disk space, memory and processor resources to back up the data in the server; when the risk host produces a public operating system image plus an independent incremental file, the information stored in the local agent is compressed and sorted in descending order according to the risk of file damage, and added to the backup queue for backing up in sequence.
[0113] The degree of risk of archive damage from severe to mild is expressed by the formula: R=P×F; where R, P, and F represent archive risk, possibility of archive damage, and consequence of archive damage, respectively; among them, possibility of archive damage is divided into five levels: frequent, regular, possible, impossible, and very unlikely, and prefixed with numbers 5 to 1; the consequences of archive damage include archive leakage, archive loss, archive tampering, and archive exchange, which are also divided into five levels: not serious, not too serious, general, relatively serious, and very serious, and are represented by letters A to E.
[0114] It is worth noting that in the above system embodiment, the various units included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the present invention.
[0115] In addition, those skilled in the art can understand that all or part of the steps in the above-mentioned embodiments can be completed by instructing related hardware through a program, and the corresponding program can be stored in a computer-readable storage medium.
[0116] The preferred embodiments of the present invention disclosed above are only used to help illustrate the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to the specific implementation methods described. Obviously, many modifications and changes can be made according to the content of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can understand and use the present invention well. The present invention is limited only by the claims and their full scope and equivalents.
Claims
1. A file management and risk detection processing method based on AI element reading, characterized in that: The steps include: Step S1: Each server in the computer room stores files according to a preset plan, and an RFID tag storing specific file information is attached to the cabinet; Step S2: Setting a monitoring area in front of the server and enabling risk detection for people entering the monitoring area; Step S3: pre-processing the collected video images in the monitoring area; Step S4: extracting information from the processed image and determining whether the extracted information exceeds a threshold; Step S5: If the threshold is exceeded, an alarm message is issued to notify the backend server; Step S6: After receiving the alarm information, the backend server matches the host number with the emergency backup object to find the emergency backup object; Step S7: The emergency backup object updates the data backup computing power from large to small according to the risk of file damage from heavy to light.
2. According to the AI element reading-based archive management and risk detection processing method of claim 1, it is characterized in that: In step S1, a system backup program, an application program, a monitoring and logging program, a security management program, a storage management program, and a performance optimization program are deployed in the server; the security management program includes authority management, process management, and operation management; the authority management is used to store user authority information; The process management is used to manage the circulation process of archives; The operation management is used to restrict user operations according to user rights.
3. The method for file management and risk detection based on AI element reading according to claim 1 is characterized in that: In step S2, the risk detection process is as follows: Step S21: A high-definition camera above the server cabinet collects video images in the monitoring area; Step S22: Recognize the face in the video image to determine whether it is a staff member; If not, the alarm procedure is started directly; If yes, then obtain the user's operation authority and execute step S23; Step S23: Process the images captured by the high-definition camera to determine whether the user has abnormal behavior; Step S24: The server monitors the user operation to determine whether the user operation exceeds the authority or violates the regulations; Step S25: If yes, start the alarm procedure.
4. The method for file management and risk detection based on AI element reading according to claim 1 is characterized in that: In step S3, the process of preprocessing the video image is as follows: Step S31, grayscale processing: converting the color video image into a grayscale image; Step S32, binarization processing: an image processing method of converting a grayscale image into black and white by setting a threshold; Step S33, filtering, smoothing and noise reduction processing: removing random noise in the image; Step S34, image tilt correction processing: correcting the tilted image.
5. The method for file management and risk detection based on AI element reading according to claim 4 is characterized in that: In step S33, the specific formula for removing random noise in the image is as follows: D(f)=∑ y ∑ x |G(x,y)|(G(x,y)>T) Where T is the given edge detection threshold, D(f) is the original image, G(x,y) is the image outside the edge, and G x ,G y They are the convolution of the edge detection operators in the horizontal and vertical directions of the pixel point (x, y).
6. The method for file management and risk detection based on AI element reading according to claim 1 is characterized in that: In step S4, the image needs to be segmented before information is extracted from the image. The specific steps are as follows: Step S41: using an edge detection operator to perform a convolution operation on the image, and performing a binarization process on the image, and using a Hough algorithm to detect straight line segments on the edge; Step S42: correcting the image by rotating the image according to the calculated inclination angle of the straight line segment relative to the horizontal direction; Step S43: retain the straight line segments in the vertical and horizontal directions, calculate the distance between the endpoints of different straight line segments, and if the distance between them is less than a set threshold, connect the straight line segments to obtain the external contour of the server host; Step S44: after determining the external outline of the server host, determine the positions of the interfaces, buttons, and indicator lights on the server host panel according to the proportions; Step S45: Monitor the interfaces, buttons, and indicator lights on the panel to determine the user operation and the working status of the current server host.
7. The method for file management and risk detection based on AI element reading according to claim 1, characterized in that: In step S4, when extracting information from the processed image, the statistical features of the server host panel image are analyzed, the grid features are abstracted using a local grayscale algorithm, and the feature vector output is provided to classification recognition; the classification recognition uses a classifier trained with a neural network, calculates whether the nonlinear activation function is greater than a threshold by setting the connection weights, and outputs classification information. The specific calculation formula is as follows: In the formula, x j Input information to the neuron, ω kj is the weight of the neuron k connection, θ k is the threshold value, is the activation function, y k is the output of neuron k.
8. The method for file management and risk detection based on AI element reading according to claim 1 is characterized in that: In step S6, when the emergency backup object is matched, it is necessary to check whether the backed up host has sufficient disk space, memory and processor resources to back up the data in the server; When the risk host produces a public operating system image plus independent incremental files, the information stored by the local agent is compressed and sorted in descending order according to the risk of file damage, and it is added to the backup queue and backed up in sequence.
9. The method for file management and risk detection based on AI element reading according to claim 1, characterized in that: The degree of the risk of archive damage from severe to mild is expressed by the formula: R=P×F; wherein R, P, and F represent archive risk, possibility of archive damage, and consequence of archive damage, respectively; wherein, possibility of archive damage is divided into five levels: frequent, regular, possible, impossible, and very unlikely, prefixed with numbers 5 to 1; the consequence of archive damage includes archive leakage, archive loss, archive tampering, and archive exchange, which are also divided into five levels: not serious, not too serious, general, relatively serious, and very serious, represented by letters A to E.