Intrusion detection method, device and equipment based on vibration optical fiber
By using timing statistical parameters in the vibrating fiber intrusion detection system to determine the confidence of false alarms, the problem of high false alarm rate in the system is solved, and higher detection accuracy and stability are achieved.
Patent Information
- Application Number
- CN202510511439.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-04-22
AI Technical Summary
Intrusion detection systems based on vibrating fibers are susceptible to environmental interference, resulting in a high false alarm rate.
When the target fiber unit triggers a vibration alarm, the false alarm confidence is determined by obtaining timing statistical parameters (immediate parameters, correlation parameters and historical parameters), and the false alarm is determined as a false alarm or a valid alarm based on the false alarm confidence.
It effectively reduces the false alarm rate and improves the accuracy, stability and environmental adaptability of vibrating fiber intrusion detection.
Smart Images

Figure CN120048051A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of vibrating optical fiber sensing, and in particular to an intrusion detection method, device and equipment based on vibrating optical fiber. Background Art
[0002] Ordinary optical fibers achieve optical signal transmission through total internal reflection of light, while vibrating optical fibers achieve optical signal transmission through minute vibrations inside the optical fiber. A vibrating optical fiber (such as a distributed vibrating optical fiber) is an intelligent sensing technology that uses the optical fiber as both a sensor and a transmission channel at the same time. The vibrating optical fiber works based on the principle of optical time domain reflectometry, and realizes full-range vibration monitoring by analyzing the scattering characteristics of optical signals. The vibrating optical fiber can be used to measure signals such as temperature, pressure, acceleration, and vibration, and has the characteristics of high sensitivity, strong anti-interference ability, and high reliability. The vibrating optical fiber has been widely used in various fields.
[0003] With its advantages such as distributed sensing and high-precision positioning, the vibrating optical fiber shows great application potential in the security field. For example, vibrating optical fibers can be deployed on the perimeter walls of a park. If a person passes through the vibrating optical fiber into the park, the vibrating optical fiber can sense the vibration caused by the person and then issue a vibration alarm, and the vibration alarm is used to inform that a person has passed through the vibrating optical fiber into the park.
[0004] However, when issuing a vibration alarm based on the vibration sensed by the vibrating optical fiber, it is easily affected by environmental interference. Environments such as rain and passing trains will cause the vibrating optical fiber to sense vibration and then issue a false vibration alarm, that is, there is a problem of alarm error, resulting in a high false alarm rate. Summary of the Invention
[0005] The present application provides an intrusion detection method based on vibrating optical fiber, which is applied to a management device of the vibrating optical fiber. The vibrating optical fiber includes a plurality of optical fiber units. The method includes: When a target optical fiber unit triggers a vibration alarm, obtaining timing statistical parameters based on the target alarm data of the target optical fiber unit. The target optical fiber unit is any optical fiber unit, and the timing statistical parameters include at least one of an immediacy parameter, a correlation parameter, and a historicity parameter; wherein, the immediacy parameter represents multi-dimensional parameters of the target alarm data, the correlation parameter represents the correlation parameter between the target alarm data and the alarms in adjacent areas, and the historicity parameter represents the correlation parameter between the target alarm data and the historical alarm data; Determining a false alarm confidence level corresponding to the vibration alarm based on the timing statistical parameters; Determining the vibration alarm as a false alarm or a valid alarm based on the false alarm confidence level.
[0006] The present application provides an intrusion detection device based on a vibrating optical fiber, which is applied to a management device of the vibrating optical fiber. The vibrating optical fiber includes a plurality of optical fiber units, and the device includes: An acquisition module, configured to obtain a timing statistical parameter based on target alarm data of a target optical fiber unit when the target optical fiber unit triggers a vibration alarm. The target optical fiber unit is any one of the plurality of optical fiber units, and the timing statistical parameter includes at least one of an immediacy parameter, a correlation parameter, and a historical parameter. Wherein, the immediacy parameter represents a multi-dimensional parameter of the target alarm data, the correlation parameter represents a correlation parameter between the target alarm data and an alarm in an adjacent area, and the historical parameter represents a correlation parameter between the target alarm data and historical alarm data; A determination module, configured to determine a false alarm confidence level corresponding to the vibration alarm based on the timing statistical parameter; A decision module, configured to determine whether the vibration alarm is a false alarm or a valid alarm based on the false alarm confidence level.
[0007] The present application provides an electronic device, including: a processor and a machine-readable storage medium. The machine-readable storage medium stores machine-executable instructions that can be executed by the processor; the processor is configured to execute the machine-executable instructions to implement the above-mentioned intrusion detection method based on a vibrating optical fiber.
[0008] The present application provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the above-mentioned intrusion detection method based on a vibrating optical fiber is implemented.
[0009] The present application provides a machine-readable storage medium, and the machine-readable storage medium stores machine-executable instructions that can be executed by a processor; wherein, the processor is configured to execute the machine-executable instructions to implement the above-mentioned intrusion detection method based on a vibrating optical fiber.
[0010] As can be seen from the above technical solutions, in the embodiments of the present application, when a target optical fiber unit triggers a vibration alarm, instead of directly sending out the vibration alarm, the false alarm confidence level is determined based on the immediacy parameter, the correlation parameter, and the historical parameter of the target optical fiber unit, and the vibration alarm is determined as a false alarm or a valid alarm based on the false alarm confidence level. If the vibration alarm is determined as a false alarm, the vibration alarm is not sent out, thereby avoiding sending out a false vibration alarm and reducing the false alarm rate. If the vibration alarm is determined as a valid alarm, the vibration alarm is sent out, thereby informing that someone has passed by the vibrating optical fiber, and realizing intrusion detection based on the vibrating optical fiber. It can improve the accuracy, stability, and environmental adaptability of the vibrating optical fiber intrusion detection, improve the detection rate, and reduce the false alarm rate. Description of the Drawings
[0011] Figure 1AIt is a flowchart of an intrusion detection method based on vibration optical fiber in an embodiment of the present application; Figure 1B It is a flowchart of an intrusion detection method based on vibration optical fiber in an embodiment of the present application; Figure 1C It is a flowchart of an intrusion detection method based on vibration optical fiber in an embodiment of the present application; Figure 2 It is a schematic structural diagram of a vibration optical fiber intrusion detection system in an embodiment of the present application; Figure 3 It is a schematic structural diagram of a feature extraction process in an embodiment of the present application; Figure 4 It is a schematic diagram of converting DSP parameters into a color grid image in an embodiment of the present application; Figure 5A It is a schematic diagram of time frame processing in an embodiment of the present application; Figure 5B It is a schematic diagram of parameter extraction in an embodiment of the present application; Figure 5C It is a schematic diagram of matrix organization in an embodiment of the present application; Figure 5D It is a schematic diagram of grid division in an embodiment of the present application; Figure 5E It is a schematic diagram of a grid image in an embodiment of the present application; Figure 5F It is a schematic diagram of a color grid image of a ladder climbing scenario in an embodiment of the present application; Figure 5G It is a schematic diagram of a color grid image of a vehicle passing scenario in an embodiment of the present application; Figure 5H It is a schematic diagram of a color grid image of a heavy rain scenario in an embodiment of the present application; Figure 6A It is a schematic diagram of multi-source heterogeneous data or multi-modal data fusion in an embodiment of the present application; Figure 6B It is a schematic network structure diagram of an anomaly detection model in an embodiment of the present application; Figure 6C It is a schematic network structure diagram of an anomaly detection model in an embodiment of the present application; Figure 6D It is a schematic diagram of feature alignment in an embodiment of the present application; Figure 7 It is a schematic diagram of a false alarm determination process in an embodiment of the present application; Figure 8AIt is a schematic diagram of a progressive inhibition process in an embodiment of the present application; Figure 8B It is a schematic structural diagram of a result fusion decision maker in an embodiment of the present application; Figure 9A It is a structural diagram of an intrusion detection device based on a vibrating optical fiber in an embodiment of the present application; Figure 9B It is a hardware structural diagram of an electronic device in an embodiment of the present application. Specific embodiments
[0012] In an embodiment of the present application, an intrusion detection method based on a vibrating optical fiber is proposed, which is applied to a management device of a vibrating optical fiber. The vibrating optical fiber (such as a distributed vibrating optical fiber) may include a plurality of optical fiber units. Refer to Figure 1A As shown, it is a schematic flowchart of an intrusion detection method based on a vibrating optical fiber. The method may include: Step 111, when a vibration alarm is triggered in a target optical fiber unit, obtain time series statistical parameters based on the target alarm data of the target optical fiber unit. The target optical fiber unit may be any optical fiber unit, and the time series statistical parameters include at least one of an immediacy parameter, a correlation parameter, and a historical parameter. Among them, the immediacy parameter represents the multi-dimensional parameter of the target alarm data, the correlation parameter represents the correlation parameter between the target alarm data and the alarms in adjacent areas, and the historical parameter represents the correlation parameter between the target alarm data and the historical alarm data.
[0013] Step 112, determine the false alarm confidence level corresponding to the vibration alarm based on the time series statistical parameters.
[0014] Step 113, determine whether the vibration alarm is a false alarm or a valid alarm based on the false alarm confidence level.
[0015] For example, if the false alarm confidence level is not less than a threshold (which can be configured according to experience), the vibration alarm can be determined as a false alarm, that is, the vibration alarm is an incorrect alarm result and does not need to trigger a vibration alarm. Or, if the false alarm confidence level is less than the threshold, the vibration alarm can be determined as a valid alarm, that is, the vibration alarm is a correct alarm result and needs to trigger a vibration alarm.
[0016] As can be seen from the above technical solutions, in the embodiments of the present application, when a target optical fiber unit triggers a vibration alarm, instead of directly sending out a vibration alarm, the false alarm confidence is determined based on the instantaneous parameters, correlation parameters, and historical parameters of the target optical fiber unit, and the vibration alarm is determined as a false alarm or a valid alarm based on the false alarm confidence. If the vibration alarm is determined as a false alarm, the vibration alarm is not sent out, thereby avoiding sending out false vibration alarms and reducing the false alarm rate. If the vibration alarm is determined as a valid alarm, the vibration alarm is sent out, thereby informing that someone has passed by the vibration optical fiber, realizing intrusion detection based on the vibration optical fiber. It can improve the accuracy, stability, and environmental adaptability of vibration optical fiber intrusion detection, improve the detection rate, and reduce the false alarm rate.
[0017] In the embodiments of the present application, an intrusion detection method based on a vibration optical fiber is proposed, which is applied to a management device of the vibration optical fiber. The vibration optical fiber (such as a distributed vibration optical fiber) may include a plurality of optical fiber units. Refer to Figure 1B As shown, it is a schematic flowchart of the intrusion detection method based on the vibration optical fiber. The method may include: Step 121, when a target optical fiber unit triggers a vibration alarm, obtain the phase data and power spectrum data corresponding to the target optical fiber unit. The target optical fiber unit may be any optical fiber unit.
[0018] Step 122, determine the Mel spectrogram based on the phase data, determine the waterfall plot based on the power spectrum data, obtain the DSP parameters based on the phase data and the power spectrum data, and convert the DSP parameters into a color grid image.
[0019] Step 123, perform channel dimension splicing on the Mel spectrogram, the waterfall plot, and the color grid image to obtain a spliced image; input the spliced image into an anomaly detection model to obtain an initial anomaly score.
[0020] Step 124, determine the vibration alarm as a false alarm or a valid alarm based on the initial anomaly score.
[0021] For example, if the initial anomaly score is not greater than a threshold (which can be configured according to experience), the vibration alarm can be determined as a false alarm, that is, the vibration alarm is a false alarm result and does not need to trigger the vibration alarm. Or, if the initial anomaly score is greater than the threshold, the vibration alarm can be determined as a valid alarm, that is, the vibration alarm is a correct alarm result and needs to trigger the vibration alarm.
[0022] As can be seen from the above technical solutions, in the embodiments of the present application, when a target optical fiber unit triggers a vibration alarm, instead of directly sending out a vibration alarm, a spliced image is obtained by splicing the Mel spectrogram, the waterfall diagram, and the color grid image in the channel dimension, and the spliced image is input into an anomaly detection model to obtain an initial anomaly score. Then, based on the initial anomaly score, the vibration alarm is determined as a false alarm or a valid alarm. If the vibration alarm is determined as a false alarm, no vibration alarm is sent, thereby avoiding sending out false vibration alarms and reducing the false alarm rate. If the vibration alarm is determined as a valid alarm, a vibration alarm is sent, thereby informing that someone has passed by the vibrating optical fiber, realizing intrusion detection based on the vibrating optical fiber. It can improve the accuracy, stability, and environmental adaptability of vibrating optical fiber intrusion detection, improve the detection rate, and reduce the false alarm rate.
[0023] In the embodiments of the present application, an intrusion detection method based on a vibrating optical fiber is proposed, which is applied to a management device of the vibrating optical fiber. The vibrating optical fiber (such as a distributed vibrating optical fiber) may include multiple optical fiber units. Refer to Figure 1C As shown in the flowchart of the intrusion detection method based on the vibrating optical fiber, the method may include: Step 131, when a target optical fiber unit triggers a vibration alarm, obtain timing statistical parameters based on the target alarm data of the target optical fiber unit. The target optical fiber unit may be any optical fiber unit, and the timing statistical parameters include at least one of an immediacy parameter, a correlation parameter, and a historical parameter. Among them, the immediacy parameter represents the multi-dimensional parameters of the target alarm data, the correlation parameter represents the correlation parameter between the target alarm data and the alarms in adjacent areas, and the historical parameter represents the correlation parameter between the target alarm data and the historical alarm data.
[0024] Step 132, determine the false alarm confidence corresponding to the vibration alarm based on the timing statistical parameters.
[0025] Step 133, obtain the phase data and power spectrum data corresponding to the target optical fiber unit, determine the Mel spectrogram based on the phase data, determine the waterfall diagram based on the power spectrum data, obtain DSP parameters based on the phase data and the power spectrum data, and convert the DSP parameters into a color grid image.
[0026] Step 134, splice the Mel spectrogram, the waterfall diagram, and the color grid image in the channel dimension to obtain a spliced image; input the spliced image into an anomaly detection model to obtain an initial anomaly score.
[0027] Step 135, determine a target anomaly score based on the false alarm confidence and the initial anomaly score, and determine the vibration alarm as a false alarm or a valid alarm based on the target anomaly score.
[0028] For example, if the target anomaly score is not greater than the threshold (which can be configured based on experience), the vibration alarm can be determined as a false alarm, that is, the vibration alarm is an incorrect alarm result and does not need to trigger the vibration alarm. Or, if the target anomaly score is greater than the threshold, the vibration alarm can be determined as a valid alarm, that is, the vibration alarm is a correct alarm result and needs to trigger the vibration alarm.
[0029] As can be seen from the above technical solutions, in the embodiments of the present application, when a vibration alarm is triggered by a target optical fiber unit, instead of directly issuing a vibration alarm, the false alarm confidence is determined based on the instantaneity parameters, correlation parameters, and historical parameters of the target optical fiber unit, and the initial anomaly score is obtained based on the Mel spectrogram, waterfall plot, and color grid image. The target anomaly score is determined based on the false alarm confidence and the initial anomaly score, and then the vibration alarm is determined as a false alarm or a valid alarm based on the target anomaly score. If the vibration alarm is determined as a false alarm, the vibration alarm is not issued, thus avoiding issuing incorrect vibration alarms and reducing the false alarm rate. If the vibration alarm is determined as a valid alarm, the vibration alarm is issued, thus informing that someone has passed by the vibrating optical fiber, realizing intrusion detection based on the vibrating optical fiber. It can improve the accuracy, stability, and environmental adaptability of vibrating optical fiber intrusion detection, improve the detection rate, and reduce the false alarm rate.
[0030] Exemplarily, the instantaneity parameters may include at least one of the signal dimension matching degree, environmental correlation dimension matching degree, and spatio-temporal consistency dimension matching degree. Among them, the acquisition process of the signal dimension matching degree may include, but is not limited to: extracting features from the target alarm data to obtain the current signal features; determining the first similarity between the current signal features and the sample signal features, and determining the signal dimension matching degree based on the first similarity; where the sample signal features are obtained by extracting features from the alarm data in a non-intrusion scenario.
[0031] The acquisition process of the environmental correlation dimension matching degree may include, but is not limited to: if the target alarm data includes the target environmental data corresponding to the target optical fiber unit, extracting features from the target environmental data to obtain the current environmental features; determining the second similarity between the current environmental features and the sample environmental features, and determining the environmental correlation dimension matching degree based on the second similarity; the sample environmental features are obtained by extracting features from the environmental data in a non-intrusion scenario. The acquisition process of the spatio-temporal consistency dimension matching degree may include, but is not limited to: if the target alarm data includes the target alarm time and the target alarm location, determining the first false alarm probability corresponding to the target alarm time, determining the second false alarm probability corresponding to the target alarm location, and performing a weighted operation on the first false alarm probability and the second false alarm probability to obtain the spatio-temporal consistency dimension matching degree; multiple times in the time dimension respectively correspond to false alarm probabilities, and multiple positions in the space dimension respectively correspond to false alarm probabilities.
[0032] Exemplarily, the process of obtaining the correlation parameter may include, but is not limited to: determining a plurality of associated optical fiber units corresponding to the target optical fiber unit, where the distance between each associated optical fiber unit and the target optical fiber unit is less than a distance threshold, and each associated optical fiber unit triggers a vibration alarm; if the target alarm data includes the vibration intensity of the target optical fiber unit, then based on the vibration intensity of the target optical fiber unit, the vibration intensity of each associated optical fiber unit, the distance attenuation coefficient corresponding to each associated optical fiber unit, and the total number of associated optical fiber units, determine the correlation parameter. Among them, for each associated optical fiber unit, the distance attenuation coefficient may be determined based on the linear attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit, or the distance attenuation coefficient may be determined based on the exponential attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit.
[0033] Exemplarily, the historical parameter may include at least one of a time pattern matching degree, a space pattern matching degree, and an environment pattern matching degree. Among them, the process of obtaining the time pattern matching degree may include, but is not limited to: if the target alarm data includes the target alarm time, then based on the target alarm data and the historical alarm data, determine the first statistical feature of the target alarm time and the second statistical feature of the historical false alarm time, and determine the time pattern matching degree based on the first statistical feature and the second statistical feature; where the historical false alarm time is the alarm time indicating the existence of a vibration alarm false alarm in the historical alarm data.
[0034] The process of obtaining the space pattern matching degree may include, but is not limited to: if the target alarm data includes the target alarm location, then based on the target alarm data and the historical alarm data, determine the target alarm location and a plurality of historical false alarm locations, where each historical false alarm location is the alarm location indicating the existence of a vibration alarm false alarm in the historical alarm data; determine the space pattern matching degree based on the spatial overlap degree between the target alarm location and each historical false alarm location. The process of obtaining the environment pattern matching degree may include, but is not limited to: if the target alarm data includes the target environment data, then based on the target alarm data and the historical alarm data, determine the current environment feature corresponding to the target environment data and the historical false alarm environment feature, where the historical false alarm environment feature is the environment feature indicating the existence of a vibration alarm false alarm in the historical alarm data; the environment pattern matching degree may be determined based on the current environment feature and the historical false alarm environment feature.
[0035] Exemplarily, determining the false alarm confidence corresponding to the vibration alarm based on the timing statistical parameters may include, but is not limited to: determining a comprehensive false alarm score based on the timing statistical parameters; wherein, if the timing statistical parameters include an immediacy parameter, a relevance parameter, and a historicity parameter, a weighted operation is performed on the immediacy score, the relevance score, and the historicity score to obtain the comprehensive false alarm score; wherein, if the immediacy parameter includes a signal dimension matching degree, an environmental relevance dimension matching degree, and a spatio-temporal consistency dimension matching degree, a weighted operation is performed on the signal dimension matching degree, the environmental relevance dimension matching degree, and the spatio-temporal consistency dimension matching degree to obtain the immediacy score; determining the relevance score based on the relevance parameter; if the historicity parameter includes a time pattern matching degree, a space pattern matching degree, and an environmental pattern matching degree, a weighted operation is performed on the time pattern matching degree, the space pattern matching degree, and the environmental pattern matching degree to obtain the historicity score. Then, determining the false alarm confidence based on the comprehensive false alarm score; wherein, the false alarm confidence may be directly proportional to the comprehensive false alarm score.
[0036] Exemplarily, the following formula may be used to determine the false alarm confidence: ; wherein, C may represent the false alarm confidence, λ may represent the configured adjustment coefficient, FS may represent the comprehensive false alarm score, C The value range of may be [0, 1], C The closer it is to 1, the greater the possibility of false alarm.
[0037] Exemplarily, the DSP parameters may include, but are not limited to, time energy dimension parameters and / or space dimension parameters. The time energy dimension parameters are used to characterize the characteristics of the signal in the time domain and the energy domain, and the space dimension parameters are used to characterize the characteristics of the signal in the space domain. For example, the time energy dimension parameters may include, but are not limited to: at least one of energy feature class parameters, time domain feature class parameters, frequency domain feature class parameters, and morphological feature class parameters; the energy feature class parameters are used to reflect the signal energy level, the time domain feature class parameters are used to reflect the statistics of the signal time domain characteristics, the frequency domain feature class parameters are used to reflect the signal frequency domain distribution characteristics, and the morphological feature class parameters are used to reflect the indicators of the signal waveform characteristics. For example, the space dimension parameters may include, but are not limited to: at least one of statistical feature class parameters, morphological feature class parameters, and spectral domain feature class parameters; the statistical feature class parameters are used to reflect the statistics of the signal spatial distribution characteristics, the morphological feature class parameters are used to reflect the signal spatial morphological characteristics, and the spectral domain feature class parameters are used to reflect the signal spectral spatial characteristics.
[0038] Exemplarily, converting DSP parameters into a color grid image may include, but is not limited to: converting DSP parameters into a parameter matrix, which may include multiple parameter values. Generating a grid image, which may include multiple grids; wherein, the height dimension of the grid may be determined based on the height of the color grid image and the number of horizontal elements of the parameter matrix, and the width dimension of the grid may be determined based on the width of the color grid image and the number of vertical elements of the parameter matrix. For each parameter value in the parameter matrix, determining the grid corresponding to the parameter value in the grid image, normalizing the parameter value to a specified numerical range, and filling the normalized parameter value into the grid; wherein, multiple parameter values in the parameter matrix correspond one-to-one with multiple grids in the grid image. Performing a visualization conversion on the grayscale image to obtain a color grid image; wherein, after filling all the normalized parameter values into the grid image, a grayscale image may be obtained.
[0039] Exemplarily, converting DSP parameters into a parameter matrix may include, but is not limited to: for each of the continuous N frames, obtaining the DSP parameters of the frame, where the DSP parameters of the frame are obtained based on the phase data and power spectrum data of the frame, and the DSP parameters of the frame include m parameter values; taking the m parameter values of each frame as a row of the parameter matrix to obtain the parameter matrix; wherein, the parameter matrix is a matrix of N rows and m columns; or, taking the m parameter values of each frame as a column of the parameter matrix to obtain the parameter matrix; wherein, the parameter matrix is a matrix of N columns and m rows; wherein, N is a positive integer, and m is a positive integer.
[0040] Exemplarily, normalizing the parameter value to a specified numerical range may include, but is not limited to: if the specified numerical range is [0, 255], the following formula may be used to normalize the parameter value to the specified numerical range: ; wherein, G ij represents the normalized parameter value, P ij represents the parameter value, P min represents the minimum parameter value in the parameter matrix, P max represents the maximum parameter value in the parameter matrix.
[0041] Exemplarily, performing a visualization conversion on the grayscale image to obtain a color grid image may include, but is not limited to: performing a smoothing operation on the grayscale image using a configured smoothing kernel to obtain a smoothed grayscale image, and performing a visualization conversion on the smoothed grayscale image to obtain a color grid image.
[0042] Exemplarily, inputting the spliced image into the anomaly detection model to obtain an initial anomaly score may include, but is not limited to: inputting the spliced image into the anomaly detection model to obtain a reconstructed image corresponding to the spliced image, and determining the initial anomaly score based on the difference between the reconstructed image and the spliced image.
[0043] Exemplarily, based on the configured initial detection model, the training process of the anomaly detection model includes, but is not limited to: obtaining a sample Mel spectrogram, a sample waterfall diagram, and a sample color grid image, performing channel dimension splicing on the sample Mel spectrogram, the sample waterfall diagram, and the sample color grid image to obtain a sample spliced image; inputting the sample spliced image into the initial detection model to obtain a first sample reconstructed image and a predicted label, inputting the sample spliced image into the trained classroom detection model corresponding to the initial detection model to obtain a second sample reconstructed image. Determining a reconstruction loss value based on the difference between the first sample reconstructed image and the sample spliced image, determining a knowledge distillation loss value based on the difference between the first sample reconstructed image and the second sample reconstructed image, and determining a classification loss value based on the difference between the predicted label and the true label of the sample spliced image. Determining a target loss value based on the reconstruction loss value, the knowledge distillation loss value, and the classification loss value, and adjusting the parameters of the initial detection model based on the target loss value to obtain an adjusted model. If the adjusted model has converged, determining the adjusted model as the anomaly detection model; if the adjusted model has not converged, determining the adjusted model as the initial detection model, and returning to execute the operation of inputting the sample spliced image into the initial detection model.
[0044] Exemplarily, determining the target anomaly score based on the false alarm confidence and the initial anomaly score may include, but is not limited to: determining a target suppression coefficient based on the false alarm confidence, and adjusting the initial anomaly score based on the target suppression coefficient and the configured dynamic influence factor to obtain the target anomaly score.
[0045] Exemplarily, determining the target suppression coefficient based on the false alarm confidence may include, but is not limited to: determining a first suppression coefficient based on the false alarm confidence, and the first suppression coefficient is proportional to the false alarm confidence; determining a second suppression coefficient based on the first suppression coefficient, the configured time adjustment factor, the configured space adjustment factor, and the configured environment adjustment factor; determining a third suppression coefficient based on the second suppression coefficient and the configured attenuation coefficient; determining a target gain adjustment factor corresponding to the target alarm time of the vibration alarm, and determining the target suppression coefficient based on the third suppression coefficient and the target gain adjustment factor.
[0046] The first suppression coefficient can be determined by the following formula: ; where x can represent the false alarm confidence, T 1, T 2, T3 represents a segmentation threshold, and satisfies 0 < T 1 < T 2 < T 3 < 1, k 1. k 2. k 3 can represent the slope, S 1 = k 1×( T 2 − T 1), S 2 = S 1 + k 2×( T 3 − T 2).
[0047] The third suppression coefficient can be determined by the following formula: ; where adjusted_ confidence can represent the third suppression coefficient, base_confidence can represent the second suppression coefficient, α can represent the attenuation coefficient, t can represent the time interval.
[0048] Exemplarily, determining the target suppression coefficient based on the third suppression coefficient and the target gain adjustment factor may include, but is not limited to: if the product value between the third suppression coefficient and the target gain adjustment factor is less than a fixed value, then the product value is determined as the target suppression coefficient; if the product value is not less than the fixed value, then the fixed value is determined as the target suppression coefficient; where, if the target alarm time is within the configured night time interval, the target gain adjustment factor is the first factor value, and if the target alarm time is within the configured day time interval, the target gain adjustment factor is the second factor value, and the first factor value is greater than the second factor value.
[0049] Exemplarily, adjusting the initial anomaly score based on the target suppression coefficient and the configured dynamic impact factor to obtain the target anomaly score may include, but is not limited to: the target anomaly score can be determined by the following formula: final_ score = dl_score×(1−final_confidence)×factor . Where final_score can represent the target anomaly score, dl_score can represent the initial anomaly score, final_confidence can represent the target suppression coefficient, factor can represent the dynamic impact factor. For example, if the initial anomaly score is not greater than the threshold, the dynamic impact factor can be the third factor value, and if the initial anomaly score is greater than the threshold, the dynamic impact factor can be the fourth factor value; where the third factor value is less than the fourth factor value.
[0050] The above technical solutions of the embodiments of the present application will be described below in combination with specific application scenarios.
[0051] Vibrating optical fibers (such as distributed vibrating optical fibers) exhibit great application potential in the security field due to their advantages such as distributed sensing and high-precision positioning. For example, vibrating optical fibers can be deployed on the perimeter walls of a campus scenario. If a person passes through the vibrating optical fiber into the campus, the vibrating optical fiber can sense the vibration caused by the person and then issue a vibration alarm, and the vibration alarm is used to inform that a person has passed through the vibrating optical fiber into the campus. However, when issuing a vibration alarm based on the vibration sensed by the vibrating optical fiber, it is easily affected by environmental interference. Environments such as rain and passing trains will cause the vibrating optical fiber to sense vibration and then issue a false vibration alarm, that is, there is a problem of alarm error, resulting in a relatively high false alarm rate.
[0052] In response to the above findings, the embodiments of the present application propose a vibrating optical fiber intrusion detection system and method for multi-source heterogeneous data fusion, which can integrate four types of complementary heterogeneous data, namely phase data and its Mel spectrogram, power spectrum data and its waterfall plot, multi-dimensional DSP (Digital Signal Processing) parameters and its color card diagram (color grid image), and alarm data. By constructing a unified data expression method, the deep fusion of structured data and unstructured data is realized, the characteristics of various data sources are fully utilized, the reliability and environmental adaptability of the system are significantly improved. The amount of data required for model training is greatly reduced, and the generalization ability of the system is significantly improved. It can improve the accuracy, stability and environmental adaptability of vibrating optical fiber intrusion detection.
[0053] In the embodiments of the present application, a vibrating optical fiber intrusion detection system for multi-source heterogeneous data fusion is proposed. Refer to Figure 2 As shown in the figure, it is a schematic structural diagram of the vibrating optical fiber intrusion detection system. The vibrating optical fiber intrusion detection system may include a data input layer, a signal processing layer, a feature generation layer, and a fusion detection layer.
[0054] In the data input layer, a vibrating optical fiber (the vibrating optical fiber can be, for example, a distributed vibrating optical fiber, such as a distributed optical fiber vibration sensing system) can collect alarm data, phase data, and power spectrum data, and send the alarm data, phase data, and power spectrum data to the management device of the vibrating optical fiber. The management device obtains the alarm data, phase data, and power spectrum data and performs subsequent processing based on the alarm data, phase data, and power spectrum data.
[0055] In the signal processing layer, data processing can be performed based on alarm data, phase signal processing can be performed based on phase data, power spectrum processing can be performed based on power spectrum data, and DSP parameter extraction can be performed based on phase data and power spectrum data. In the feature generation layer, statistical feature extraction can be performed based on alarm data, and time-series statistical parameters can be generated. High-pass filtering and short-time Fourier transform can be performed based on phase data, and a Mel spectrogram can be generated. Power spectrum normalization can be performed based on power spectrum data, and a waterfall plot can be generated. Normalization and grid mapping transformation can be performed on DSP parameters, and a color card map can be generated.
[0056] In the fusion detection layer, feature fusion can be performed on the Mel spectrogram, waterfall plot, and color card map to obtain a fused image. Anomaly detection can be performed based on the fused image, and the model result can be output. Multi-level false alarm determination can be performed based on the time-series statistical parameters, and the model result can be adjusted based on a progressive suppressor and a dynamic adjustment factor, and the final result (the result of whether the vibration alarm is a false alarm or a valid alarm) can be output.
[0057] Based on the data input layer, signal processing layer, feature generation layer, and fusion detection layer, through the gradual transmission of the data flow, intrusion detection and alarm output are finally realized. This hierarchical architecture can ensure the modularity and scalability of the vibration optical fiber intrusion detection system, and at the same time improve the detection accuracy and reliability.
[0058] Exemplarily, statistical feature extraction can be performed based on alarm data to obtain time-series statistical parameters. A Mel spectrogram can be generated based on phase data, a waterfall plot can be generated based on power spectrum data, and feature extraction can be performed based on phase data and power spectrum data to obtain DSP parameters. For example, referring to Figure 3 As shown, it is a schematic structural diagram of the feature extraction process. In the feature extraction process, a multi-dimensional feature extraction function can be realized, which is used to extract rich multi-dimensional features from alarm data and real-time vibration signals (such as phase data and power spectrum data), providing a data basis for subsequent event recognition and decision-making.
[0059] The input data of the feature extraction process can include alarm data, phase data, and power spectrum data. Based on the alarm data, statistical feature extraction can be performed to obtain time-series statistical parameters. The time-series statistical parameters can include at least one of an immediacy parameter, a correlation parameter, and a historicity parameter, and the immediacy parameter, the correlation parameter, and the historicity parameter can be output. Based on the phase data, a Mel spectrogram can be generated, and the Mel spectrogram can be output. Based on the power spectrum data, a waterfall plot can be generated, and the waterfall plot can be output. Based on the phase data and the power spectrum data, spatial dimension feature extraction and time-energy dimension feature extraction can be performed to obtain DSP parameters, and the DSP parameters can be output. The processing process of feature extraction will be described below in combination with the following steps.
[0060] Step S11: When a vibration alarm is triggered by a target optical fiber unit, obtain the phase data and power spectrum data corresponding to the target optical fiber unit. The target optical fiber unit can be any optical fiber unit of the vibration optical fiber.
[0061] For example, when a certain optical fiber unit of the vibration optical fiber triggers a vibration alarm, use this optical fiber unit as the target optical fiber unit and perform an intrusion detection method for the target optical fiber unit. Or, when multiple optical fiber units of the vibration optical fiber trigger vibration alarms, use each optical fiber unit that triggers the vibration alarm as the target optical fiber unit, and perform an intrusion detection method for each target optical fiber unit respectively. For the convenience of description, in this embodiment, the processing process of one target optical fiber unit is taken as an example to perform an intrusion detection method for the target optical fiber unit.
[0062] When a vibration alarm is triggered by the target optical fiber unit, obtain the phase data corresponding to the target optical fiber unit. The phase data is used to describe the vibration situation. For example, the phase data can include phase angle, vibration amplitude, and frequency, etc. The phase angle represents the offset situation of the vibration waveform, the vibration amplitude represents the intensity of the vibration, which can be represented by displacement, velocity, or acceleration, and the frequency represents the periodic change rate of the vibration, with the unit of Hertz (Hz).
[0063] When a vibration alarm is triggered by the target optical fiber unit, obtain the power spectrum data (abbreviation: power spectrum) corresponding to the target optical fiber unit. The power spectrum is the abbreviation of power spectral density, which is defined as the signal power within a unit frequency band. The power spectrum represents the variation of the signal power with frequency, that is, the distribution of the signal power in the frequency domain.
[0064] Step S12: Generate a Mel spectrogram based on the phase data. The Mel spectrogram can be a frequency domain feature, that is, obtain more detailed three-dimensional features of time, frequency, and energy based on the phase data at the alarm moment, and the three-dimensional features can be characterized by the Mel spectrogram. The generation method of this Mel spectrogram is not limited.
[0065] Of course, in addition to the Mel spectrogram, other types of spectrograms can also be generated based on the phase data, that is, generate a spectrogram based on the phase data. In this embodiment, the spectrogram is taken as the Mel spectrogram as an example.
[0066] Step S13: Determine a waterfall plot based on the power spectrum data. The waterfall plot can be a spatio-temporal feature, that is, obtain the joint features of time, space, and energy based on the power spectrum data (spatial power spectrum) at the alarm moment, and the joint features can be characterized by the waterfall plot. The generation method of this waterfall plot is not limited.
[0067] Step S14: Obtain DSP parameters based on the phase data and the power spectrum data.
[0068] Exemplarily, the DSP parameters are multi-dimensional and scalable signal features. Any type of parameter can be used as a DSP parameter. For example, DSP parameters can be constructed based on feature significance, computational efficiency, and complementarity. By carefully selecting and combining various DSP parameters, a comprehensive characterization of distributed fiber optic vibration signals can be achieved.
[0069] Exemplarily, to ensure that the generated color card map can effectively and comprehensively reflect the characteristics of distributed fiber optic vibration signals, the selection of DSP parameters can follow the following principles: the principle of feature significance, selecting DSP parameters that can effectively reflect signal features, have good discrimination ability, and are stable. The principle of computational efficiency: preferentially select DSP parameters with low computational complexity, less resource occupancy, and easy implementation. The principle of complementarity: ensure that DSP parameters can describe signal features from different dimensions and form a complementary synergistic effect.
[0070] For example, the DSP parameters can include but are not limited to: time-energy dimension parameters and / or space dimension parameters, and the type of these DSP parameters is not restricted. Among them, the time-energy dimension parameters are used to characterize the features of the signal in the time domain and energy domain, and the space dimension parameters are used to characterize the features of the signal in the space domain.
[0071] For example, the time-energy dimension parameters can include but are not limited to at least one of the following: Energy feature type parameters, which are used to reflect the signal energy level, that is, select parameters that reflect the signal energy level as DSP parameters. This type of parameter includes various energy ratio indicators. For example, the energy feature type parameters can include the root mean square value (RMS) and the absolute peak value (Absolute Peak), etc. The root mean square value can be determined based on the phase data at multiple moments, and the absolute peak value can be determined based on the phase data and the power spectrum data. The determination process of these energy feature type parameters is not restricted in this embodiment.
[0072] Time domain feature type parameters, which are used to reflect the statistics of the signal time domain features, that is, select various statistics that include the signal time domain features as DSP parameters. This type of parameter can characterize the frequency of signal changes. For example, the time domain feature type parameters can include the zero crossing rate (Zero Crossing Rate), etc. The zero crossing rate can be determined based on the phase data at multiple moments, and the determination process is not restricted.
[0073] Frequency domain feature class parameters are used to reflect the frequency domain distribution characteristics of a signal. That is, parameters that reflect the frequency domain distribution characteristics of the signal are selected as DSP parameters, and such parameters can characterize the signal complexity. For example, frequency domain feature class parameters can include spectral entropy and band energy ratio, etc. The spectral entropy can be determined based on the phase data at multiple moments, and the band energy ratio can be determined based on the phase data at multiple moments. The determination process of such frequency domain feature class parameters is not restricted.
[0074] Morphological feature class parameters are indicators used to reflect the waveform characteristics of a signal. That is, various indicators that describe the waveform characteristics of the signal are selected as DSP parameters, and such parameters can reflect the pulse characteristics of the signal. For example, morphological feature class parameters can include impulse indicator, shape indicator, and main impact strength, etc. The impulse indicator, shape indicator, and main impact strength can all be determined based on the phase data at multiple moments, and this is not restricted.
[0075] For example, the spatial dimension parameters can include but are not limited to at least one of the following: Statistical feature class parameters are statistics used to reflect the spatial distribution characteristics of a signal. That is, various statistics that describe the spatial distribution characteristics of the signal are selected as DSP parameters, and such parameters reflect the spatial aggregation degree of the signal. For example, statistical feature class parameters can include kurtosis and frame mean, etc. The kurtosis and frame mean can be determined based on the power spectrum data at multiple moments, and this is not restricted.
[0076] Morphological feature class parameters are used to reflect the spatial morphological characteristics of a signal. That is, parameters that describe the spatial morphological characteristics of the signal are selected as DSP parameters, and such parameters reflect various indicators of the signal spatial continuity. For example, morphological feature class parameters can include the maximum connected area, and the maximum connected area can be determined based on the power spectrum data at multiple moments.
[0077] Spectral domain feature class parameters are used to reflect the spectral spatial characteristics of a signal. That is, parameters that describe the spectral spatial characteristics of the signal are selected as DSP parameters, and such parameters reflect various statistics of the spectral distribution characteristics. For example, spectral domain feature class parameters can include the power spectrum standard deviation, and the power spectrum standard deviation can be determined based on the power spectrum data at multiple moments.
[0078] Of course, the above are just a few examples of DSP parameters, and there are no restrictions on these DSP parameters.
[0079] Step S15: When a vibration alarm is triggered in the target optical fiber unit, obtain the target alarm data corresponding to the target optical fiber unit. For the sake of convenience in distinction, the alarm data of the target optical fiber unit is referred to as the target alarm data.
[0080] For example, the target alarm data may include but is not limited to target environmental data, target alarm time, target alarm location, and vibration intensity. Of course, the above are just a few examples, and there are no restrictions on this target alarm data. The target environmental data can represent the surrounding environmental information of the target optical fiber unit, such as meteorological information (such as wind speed, precipitation, etc.), surrounding activity information (such as vehicle passing, train passing, construction vibration, animal activity, etc.), and there are no restrictions on the content of this target environmental data. The target alarm time can represent the time when the target optical fiber unit triggers a vibration alarm, that is, a vibration alarm is triggered at the target alarm time. The target alarm location can represent the vibration location sensed when the target optical fiber unit triggers a vibration alarm, which can be the location of the target optical fiber unit itself (such as longitude and latitude coordinates, etc.), that is, there is a large vibration at the target alarm location. The vibration intensity can be the vibration intensity value sensed by the target optical fiber unit and can reflect the vibration energy.
[0081] After obtaining the target alarm data, timing statistical parameters (i.e., timing statistical features) can be obtained based on the target alarm data. The timing statistical parameters include at least one of an immediacy parameter (i.e., an immediacy feature), a correlation parameter (i.e., a correlation feature), and a historicity parameter (i.e., a historicity feature). Subsequently, taking the immediacy parameter, the correlation parameter, and the historicity parameter as examples, these parameters all belong to the timing statistical parameters.
[0082] Step S16: Obtain an immediacy parameter based on the target alarm data. The immediacy parameter can represent multi-dimensional parameters of the target alarm data. That is to say, the immediacy parameter can represent parameters in multiple dimensions.
[0083] For example, the immediacy parameter can also be called an immediacy feature. By performing multi-dimensional feature analysis on the target alarm data, a feature vector for false alarm determination is constructed, and this feature vector is used as the immediacy parameter, and the immediacy parameter is used to evaluate whether the target alarm data has the characteristics of a false alarm.
[0084] Exemplarily, the real-time parameters may include at least one of a signal dimension matching degree, an environmental correlation dimension matching degree, and a spatio-temporal consistency dimension matching degree. The signal dimension matching degree may also be referred to as a signal feature matching degree. The target alarm data (current signal) can be compared with the sample signal features (i.e., known intrusion signal features) to calculate the matching degree, and this matching degree serves as the signal dimension matching degree. The greater the signal dimension matching degree, the higher the probability of false alarms. The environmental correlation dimension matching degree may also be referred to as an environmental correlation feature. By analyzing the correlation degree between the current environmental factors (such as weather conditions, animal activities, mechanical vibrations, etc.) and the current signal, this correlation degree serves as the environmental correlation dimension matching degree. If the environmental correlation dimension matching degree indicates a high correlation between the current signal and the environmental interference features, the probability of false alarms is higher. The spatio-temporal consistency dimension matching degree may also be referred to as a spatio-temporal consistency feature. The spatio-temporal consistency feature is used to evaluate whether the target alarm time and the target alarm location conform to the normal intrusion pattern. For example, the credibility of an alarm in a sparsely populated area at night may be higher, while the credibility of an alarm in a densely populated area during the day may be lower.
[0085] In a possible implementation manner, the signal dimension matching degree can be obtained based on signal pattern recognition technology. For example, an intrusion signal feature library can be pre-constructed. The intrusion signal feature library can store multiple sample signal features, and each sample signal feature is obtained by extracting features from the alarm data in a non-intrusion scenario. For example, for non-intrusion scenario 1 (such as a rainy day scenario), the alarm data corresponding to the optical fiber unit can be obtained, such as environmental data, alarm time, alarm location, vibration intensity, etc., and sample signal feature 1 is obtained by extracting features from the alarm data and stored in the intrusion signal feature library. For non-intrusion scenario 2 (such as a construction vibration scenario), the alarm data corresponding to the optical fiber unit can be obtained, and sample signal feature 2 is obtained by extracting features from the alarm data and stored in the intrusion signal feature library. And so on, multiple sample signal features of non-intrusion scenarios are stored in the intrusion signal feature library.
[0086] In step S16, after obtaining the target alarm data, the current signal features can be obtained by extracting features from the target alarm data. Then, the similarity between the current signal features and each sample signal feature is calculated. Based on the similarity between the current signal features and each sample signal feature, the maximum similarity can be used as the first similarity, and then the signal dimension matching degree is determined based on the first similarity.
[0087] For example, when extracting the current signal features from the target alarm data (extracting the sample signal features from the alarm data in a non-intrusion scenario), the current signal features can be at least one of the time-domain waveform features, the frequency-domain energy distribution features, and the time-frequency features, that is, the time-domain waveform features, the frequency-domain energy distribution features, and the time-frequency features are extracted as the current signal features, and there is no limitation on this.
[0088] For example, when calculating the similarity between the current signal features and the sample signal features, the Euclidean distance or the cosine similarity can be calculated. When calculating the Euclidean distance, the smaller the Euclidean distance, the greater the similarity. When calculating the cosine similarity, the greater the cosine similarity, the greater the similarity.
[0089] For example, the signal dimension matching degree can be determined by the following formula (1), and the signal dimension matching degree is used to characterize the matching degree between the current signal features and the sample signal features. Of course, formula (1) is only an example.
[0090] Formula (1) In formula (1), F 1 represents the signal dimension matching degree, S current represents the current signal features, S tcmplate represents the sample signal features, dist(⋅) represents the distance calculation function, such as calculating the Euclidean distance between the current signal features and the sample signal features. This Euclidean distance can be used as the first similarity. Obviously, if the Euclidean distance is smaller (that is, the similarity is greater, and the target alarm data is more similar to the alarm data in the non-intrusion scenario), then F 1 the greater it is, the greater the probability of false alarm. max_dist represents the maximum Euclidean distance, which can be an empirical value. For example, the Euclidean distance between the current signal features and the sample signal features will not exceed max_ dist That's it.
[0091] In a possible implementation, the extraction of the environmental correlation dimension matching degree focuses on capturing the influence of environmental factors on the signal. For example, an environmental information feature library can be pre-constructed. The environmental information feature library can store multiple sample environmental features, and each sample environmental feature is obtained by extracting features from environmental data in a non-intrusion scenario. For example, for non-intrusion scenario 1 (such as a rainy day scenario), the environmental data corresponding to the optical fiber unit can be obtained, such as meteorological information (such as wind speed, precipitation, etc.), surrounding activity information (such as vehicle passing, train passing, construction vibration, animal activity, etc.). The sample environmental feature 1 is obtained by extracting features from this environmental data, and the sample environmental feature 1 is stored in the environmental information feature library. For non-intrusion scenario 2 (such as a construction vibration scenario), the environmental data corresponding to the optical fiber unit can be obtained, and the sample environmental feature 2 is obtained by extracting features from this environmental data, and the sample environmental feature 2 is stored in the environmental information feature library. And so on, multiple sample environmental features of non-intrusion scenarios are stored in the environmental information feature library.
[0092] In step S16, after obtaining the target alarm data, the target alarm data includes the target environmental data (such as meteorological information, surrounding activity information) corresponding to the target optical fiber unit. The current environmental feature is obtained by extracting features from the target environmental data. Then, the similarity between the current environmental feature and each sample environmental feature is calculated. Based on the similarity between the current environmental feature and each sample environmental feature, the maximum similarity can be used as the second similarity, and then the environmental correlation dimension matching degree is determined based on the second similarity.
[0093] For example, when the current environmental feature is obtained by extracting features from the target environmental data, the current environmental feature is at least one of a time-domain waveform feature, a frequency-domain energy distribution feature, and a time-frequency feature. When calculating the similarity between the current environmental feature and the sample environmental feature, the Euclidean distance or cosine similarity can be calculated.
[0094] For example, the environmental correlation dimension matching degree can be determined by the following formula (2). Of course, formula (2) is just an example, and the calculation method of this environmental correlation dimension matching degree is not limited.
[0095] Formula (2) In formula (2), F 2 represents the environmental correlation dimension matching degree, S signal represents the current environmental feature, S env represents the sample environmental feature, corr(⋅) represents the correlation coefficient calculation function, such as calculating the cosine similarity between the current environmental feature and the sample environmental feature, and this cosine similarity can be used as the second similarity.
[0096] Obviously, if the cosine similarity is greater (i.e., the second similarity is greater, and the target environment data is more similar to the environment data in the non-intrusion scenario), it means that F 2 the greater it is, the greater the probability of false alarm.
[0097] In a possible implementation manner, the extraction of the spatio-temporal consistency dimension matching degree comprehensively considers two dimensions of time and space. In the time dimension, a false alarm probability model for different time periods is established based on historical data. This false alarm probability model includes the false alarm probabilities at multiple times in the time dimension, such as the false alarm probability corresponding to time period 1, the false alarm probability corresponding to time period 2, and so on. Regarding how to obtain the false alarm probability corresponding to each time period, all vibration alarms in this time period can be selected from the historical data, and the number of false alarms among these vibration alarms is counted. Then, based on the number of false alarms and the total number of vibration alarms, the false alarm probability of this time period is determined.
[0098] In the space dimension, a false alarm probability model for different positions is established based on historical data. This false alarm probability model includes the false alarm probabilities at multiple positions in the space dimension, such as the false alarm probability corresponding to position 1, the false alarm probability corresponding to position 2, and so on. Regarding how to obtain the false alarm probability corresponding to each position, all vibration alarms at this position can be selected from the historical data, and the number of false alarms among these vibration alarms is counted. Then, based on the number of false alarms and the total number of vibration alarms, the false alarm probability of this position is determined.
[0099] In step S16, after obtaining the target alarm data, the target alarm data may include the target alarm time and the target alarm position. By querying the false alarm probability model in the time dimension through the time period to which the target alarm time belongs, the first false alarm probability corresponding to the target alarm time is obtained. By querying the false alarm probability model in the space dimension through the target alarm position, the second false alarm probability corresponding to the target alarm position is obtained. Then, a weighted operation is performed on the first false alarm probability and the second false alarm probability to obtain the spatio-temporal consistency dimension matching degree.
[0100] For example, the spatio-temporal consistency dimension matching degree can be determined by using the following formula (3). Of course, formula (3) is just an example, and the calculation method of the spatio-temporal consistency dimension matching degree is not limited at this time.
[0101] Formula (3) In formula (3), F 3 represents the spatio-temporal consistency dimension matching degree, P(t) represents the target alarm time t of the first false alarm probability, which can also be called the time probability score, L(x,y) represents the target alarm position(x,y) The second false alarm probability, which can also be referred to as the position sensitivity score, w 1 and w 2 are weight coefficients.
[0102] Obviously, if the first false alarm probability is larger (i.e., there are more false alarms in the historical data for the target alarm time), it means F 3 is larger, and the probability of false alarm is greater. If the second false alarm probability is larger (i.e., there are more false alarms in the historical data for the target alarm position), it means F 3 is larger, and the probability of false alarm is greater.
[0103] Through the above three features, the timeliness feature F = F 1 , F 2 , F 3 can be constructed. The timeliness feature F provides a reliable feature basis for subsequent false alarm determination. During the feature extraction process, attention needs to be paid to the quality of signal preprocessing, the real-time nature of feature calculation, and the adjustment of model parameters to ensure the effectiveness and accuracy of the features.
[0104] Step S17: Obtain the correlation parameter based on the target alarm data. The correlation parameter can represent the correlation parameter between the target alarm data and the alarms in adjacent areas, and is used to evaluate the correlation degree between the target optical fiber unit and the surrounding optical fiber units, providing an important spatial dimension feature for false alarm determination.
[0105] For example, the correlation parameter can also be referred to as the correlation feature. By extracting the correlation parameter, alarm events with spatial correlation can be effectively identified, the discrimination ability for real intrusion behaviors can be improved, important spatial dimension information can be provided for the intrusion detection system, and the false alarm determination ability can be effectively enhanced. The extraction of the correlation parameter is a feature extraction method based on spatial correlation analysis. By evaluating the correlation degree between the target optical fiber unit and the surrounding monitoring area (i.e., analyzing the alarm data of the target optical fiber unit and the alarm data of the surrounding monitoring area to determine whether there is spatial correlation), an important spatial dimension feature is provided for false alarm determination.
[0106] During the extraction process of the correlation parameter, the following factors can be considered: The selection of the adjacent area (surrounding monitoring area) should consider the actual monitoring range and geographical environment characteristics. The parameters of the attenuation model need to be optimized according to the actual application scenario. The normalization processing of the signal strength is meaningful for improving the comparability of the features.
[0107] Based on the above factors, in this embodiment, in order to analyze the spatial correlation between the target optical fiber unit and the surrounding monitoring area, it is characterized by the following parameters: vibration intensity ( Ai ), and distance attenuation coefficient ( Di ). Among them, the vibration intensity ( Ai ) reflects the alarm signal intensity of the surrounding monitoring area, and a higher signal intensity usually indicates that there may be a real intrusion behavior. The distance attenuation coefficient ( Di ) takes into account the influence of spatial distance on signal propagation, and usually an exponential attenuation model or a linear attenuation model is used to describe the distance attenuation coefficient ( Di ).
[0108] In a possible implementation manner, a plurality of associated optical fiber units corresponding to the target optical fiber unit can be determined, and the distance between each associated optical fiber unit and the target optical fiber unit is less than the distance threshold. In this way, the associated optical fiber unit is the optical fiber unit in the surrounding monitoring area of the target optical fiber unit. In addition, each associated optical fiber unit triggers a vibration alarm. In this way, the associated optical fiber unit is also the optical fiber unit that triggers the vibration alarm.
[0109] On this basis, the target alarm data of the target optical fiber unit can be obtained, and the target alarm data includes the vibration intensity of the target optical fiber unit. The alarm data of each associated optical fiber unit can be obtained, and the alarm data includes the vibration intensity of the associated optical fiber unit. Then, based on the vibration intensity of the target optical fiber unit, the vibration intensity of each associated optical fiber unit, the distance attenuation coefficient corresponding to each associated optical fiber unit, and the total number of associated optical fiber units, a correlation parameter can be determined, and the correlation parameter can be a correlation score.
[0110] For example, the correlation parameter can be calculated by using the weighted average method. For example, the correlation parameter is determined by using the following formula (4). Of course, formula (4) is only an example, and there is no limitation on this calculation method.
[0111] Formula (4) In formula (4), RA represents the correlation parameter (correlation score), N represents the total number of associated optical fiber units, Ai represents the i th vibration intensity of the associated optical fiber unit, Di represents the i th distance attenuation coefficient corresponding to the associated optical fiber unit, X represents the vibration intensity of the target optical fiber unit. The correlation parameter RA reflects the overall correlation degree between the target optical fiber unit and the surrounding area. The correlation parameter RAThe higher it is, the stronger the spatial correlation between the target optical fiber unit and the surrounding area, and the higher the credibility of the alarm accordingly.
[0112] Exemplarily, for each associated optical fiber unit, the distance attenuation coefficient corresponding to the associated optical fiber unit can be determined based on the distance between the associated optical fiber unit and the target optical fiber unit. For example, given the longitude and latitude coordinates of the associated optical fiber unit and the longitude and latitude coordinates of the target optical fiber unit, the distance between the two can then be obtained.
[0113] For example, the distance attenuation coefficient corresponding to the associated optical fiber unit can be determined based on the linear attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit. For example, the following formula can be used to determine the distance attenuation coefficient corresponding to the i th associated optical fiber unit Di : . For example, di can represent the distance between the associated optical fiber unit and the target optical fiber unit, d max can represent the configured maximum influence distance.
[0114] For example, the distance attenuation coefficient corresponding to the associated optical fiber unit can be determined based on the exponential attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit. For example, the following formula can be used to determine the distance attenuation coefficient corresponding to the i th associated optical fiber unit Di : . For example, di represents the distance between the associated optical fiber unit and the target optical fiber unit, α can represent the attenuation coefficient, which is adjusted according to the actual scenario.
[0115] Step S18, obtaining historical parameters based on the target alarm data. The historical parameters can represent the correlation parameters between the target alarm data and the historical alarm data, that is, the historical parameters are related to the historical alarm data.
[0116] For example, the historical parameters can also be called historical features, and the historical parameters are extracted based on the feature extraction method of analyzing historical alarm data. By analyzing the matching degree between the target alarm data and the historical alarm data, features are extracted from three dimensions: time, space, and environment, providing a basis for false alarm determination.
[0117] Exemplarily, the historical parameters may include at least one of a time pattern matching degree, a space pattern matching degree, and an environment pattern matching degree. The time pattern matching degree is used to analyze whether the time point when the current alarm occurs is consistent with the high-incidence time period of historical false alarms, and to analyze the correlation between the time characteristics of the current alarm and the time distribution law of historical false alarms. The space pattern matching degree is used to analyze whether the location where the current alarm occurs coincides with the multiple-occurrence areas of historical false alarms, and to analyze the spatial distribution relationship between the location of the current alarm and historical false alarms. The environment pattern matching degree is used to analyze whether the current environmental conditions (such as weather, season) are similar to the environmental conditions when historical false alarms occur, and to analyze the environmental similarity between the current environmental conditions and when historical false alarms occur.
[0118] In a possible implementation manner, the target alarm data may include a target alarm time. The first statistical feature of the target alarm time and the second statistical feature of the historical false alarm time are determined based on the target alarm data and the historical alarm data. The historical false alarm time is the alarm time indicating the existence of vibration alarm false alarms in the historical alarm data. The time pattern matching degree is determined based on the first statistical feature and the second statistical feature.
[0119] For example, the time pattern matching degree can be determined using the following formula (5). Of course, formula (5) is only an example, and the calculation method of this time pattern matching degree is not limited in this embodiment.
[0120] Formula (5) In formula (5), P T represents the time pattern matching degree, and the time pattern matching degree reflects the coincidence degree between the time point when the current alarm occurs and the high-incidence period of historical false alarms. T i represents the i th time window of historical false alarms, that is, the historical false alarm time indicating the existence of vibration alarm false alarms in the historical alarm data. N represents the total number of the target alarm time and the historical false alarm time. When i = 1, I represents the second statistical feature of the first historical false alarm time, and so on. When i = (N - 1), I represents the second statistical feature of the (N - 1)th historical false alarm time. When i = N, I represents the first statistical feature of the target alarm time.
[0121] For example, within a statistical period starting from the target alarm time and moving forward, based on the historical alarm data and the target alarm data of this statistical period, determine the statistical characteristics of this statistical period (such as the number of alarms, the number of false alarms, the proportion of false alarms, etc.), and use this statistical characteristic as the first statistical characteristic of the target alarm time.
[0122] For example, multiple historical false alarm times can be determined based on the historical alarm data. For example, the historical alarm data can include multiple alarm times. For each alarm time, if there is a vibration alarm false alarm at this alarm time, then this alarm time can be used as a historical false alarm time. If there is no vibration alarm false alarm at this alarm time, then this alarm time is not used as a historical false alarm time.
[0123] For each historical false alarm time, within a statistical period (such as one day) starting from the historical false alarm time and moving forward, based on the historical alarm data of this statistical period, the statistical characteristics of this statistical period can be determined, and use this statistical characteristic as the second statistical characteristic of this historical false alarm time.
[0124] On this basis, the first statistical characteristic of the target alarm time and the second statistical characteristics of each historical false alarm time can be substituted into formula (5) to obtain the time pattern matching degree. P T 。
[0125] In a possible implementation manner, the target alarm data can include the target alarm location. Based on the target alarm data and the historical alarm data, determine the target alarm location and multiple historical false alarm locations. Each historical false alarm location is the alarm location indicating the existence of a vibration alarm false alarm in the historical alarm data. Determine the spatial pattern matching degree based on the spatial overlap degree between the target alarm location and each historical false alarm location.
[0126] For example, the following formula (6) can be used to determine the spatial pattern matching degree. Of course, formula (6) is just an example, and the calculation method of this spatial pattern matching degree is not limited in this embodiment.
[0127] Formula (6) In formula (6), P S represents the spatial pattern matching degree. L represents the target alarm location, and the target alarm location can be determined based on the target alarm data. R j represents the j th historical false alarm location. MIndicates the total number of historical false alarm positions. Multiple historical false alarm positions can be determined based on historical alarm data. For example, historical alarm data can include multiple alarm positions. For each alarm position, if there is a false vibration alarm at this alarm position, this alarm position can be used as a historical false alarm position; if there is no false vibration alarm at this alarm position, this alarm position is not used as a historical false alarm position.
[0128] w j Indicates the j weight corresponding to the nth historical false alarm position. The weights corresponding to different historical false alarm positions can be different, and the weights corresponding to different historical false alarm positions can also be the same.
[0129] overlap(⋅) represents a spatial overlap degree calculation function, that is, calculates the spatial overlap degree between the target alarm position L and the j nth historical false alarm position R j , and there is no limitation on the calculation method of this spatial overlap degree.
[0130] In a possible implementation manner, the target alarm data includes target environment data. Based on the target alarm data and historical alarm data, the current environmental characteristics and historical false alarm environmental characteristics corresponding to the target environment data are determined. The historical false alarm environmental characteristics are the environmental characteristics indicating the existence of false vibration alarms in the historical alarm data. The environmental mode matching degree is determined based on the current environmental characteristics and the historical false alarm environmental characteristics.
[0131] For example, the environmental mode matching degree can be determined by the following formula (7). Of course, formula (7) is only an example, and there is no limitation on the calculation method of this environmental mode matching degree in this embodiment.
[0132] Formula (7) In formula (7), P E represents the environmental mode matching degree. σ is a scale parameter, which can be configured according to experience and is not limited here. In addition, E current represents the current environmental characteristics corresponding to the target environmental data. The current environmental characteristics can be obtained by feature extraction of the target environmental data in the target alarm data. The current environmental characteristics are at least one of time domain waveform characteristics, frequency domain energy distribution characteristics, and time-frequency characteristics. In addition, E histIndicates the historical false alarm environment characteristics, which can be determined based on historical alarm data. For example, the historical alarm data can include multiple historical vibration alarms. For each historical vibration alarm, if there is a false alarm in the historical vibration alarm, the environmental data corresponding to the historical vibration alarm is subjected to feature extraction to obtain the false alarm environment characteristics. When multiple false alarm environment characteristics are obtained, any one of the false alarm environment characteristics can be used as the historical false alarm environment characteristics E hist , or operations can be performed on multiple false alarm environment characteristics (such as weighted operations, average value operations, etc.) to obtain the historical false alarm environment characteristics E hist .
[0133] Through the above three characteristics, historical characteristics can be constructed. By extracting historical characteristics, the regular information in historical alarm data can be effectively utilized, and the accuracy and reliability of false alarm determination can be improved. During the feature extraction process, attention needs to be paid to the update and maintenance of historical alarm data, the real-time nature of feature calculation, and the adjustment of model parameters to ensure the effectiveness and accuracy of the features and the continuous improvement of system performance
[0134] So far, the feature extraction process is completed, and a Mel spectrogram, a waterfall plot, DSP parameters, timeliness parameters, correlation parameters, and historical parameters can be obtained. Among them, the timeliness parameters can include signal dimension matching degree, environmental correlation dimension matching degree, and spatio-temporal consistency dimension matching degree. The historical parameters can include time pattern matching degree, space pattern matching degree, and environmental pattern matching degree
[0135] In a possible implementation manner, as shown in Figure 2 , after obtaining the DSP parameters, the DSP parameters can be converted into a color grid image, and the color grid image can also be called a color card diagram. For example, the DSP parameters are converted into a color grid image by using the parameter color card method. The parameter color card method is a data visualization method for converting multi-dimensional DSP parameters into a color grid image, which realizes the unified expression of heterogeneous data and can convert complex multi-dimensional DSP parameters into intuitive color grid images. For example, as shown in Figure 4 , which is a schematic diagram for converting DSP parameters into a color grid image, and this process can include
[0136] Step 401: Convert the DSP parameters into a parameter matrix, and the parameter matrix includes multiple parameter values
[0137] Exemplarily, the construction of the parameter matrix is a basic step in parameter color carding, which may include processes such as time frame processing, parameter extraction, and matrix organization. Through the construction of the parameter matrix, one-dimensional signal data (DSP parameters) can be converted into a two-dimensional parameter matrix, providing a structured data basis for subsequent visualization. For example, when converting DSP parameters into a parameter matrix, the following steps can be adopted: Step S21, time frame processing. The purpose of time frame processing is to segment continuous signal data according to the time dimension to capture the characteristic changes of the signal in different time periods. The frame division strategy of time frame processing is to select appropriate frame lengths and frame shifts according to the sampling rate and characteristic change frequency of the signal. For example, the entire signal is divided into a fixed number of frames to ensure the uniformity of time resolution. In addition, by providing a flexible parameter setting interface, dynamic adjustment of the frame length and frame shift is supported to adapt to different types of signal characteristics. To maintain the continuous expression of signal characteristics, a certain overlap between frames can be selected.
[0138] During the time frame processing, the total number of frames N (i.e., the frame length) can be determined. The total number of frames N indicates that the DSP parameters of N frames form a parameter matrix, and the total number of frames N can be configured according to experience.
[0139] During the time frame processing, the total number of sampling points of the original signal (i.e., phase data and power spectrum data) can be determined N total , that is, sampling N total phase data and N total power spectrum data.
[0140] Based on the total number of frames N and the total number of sampling points N total , the number of points per frame can be determined L frame , that is, each frame includes L frame phase data and L frame power spectrum data. Based on L frame phase data and L frame power spectrum data, the DSP parameters corresponding to one frame can be determined, and the DSP parameters can include m parameter values. For example, the number of points per frame L frame can be determined using the following formula: Lframe = N total / N 。
[0141] In summary, for the original signal data, it can be segmented according to the calculated number of points L frame to segment the original signal data, forming N frames, and each frame includes L frame phase data and L frame power spectrum data. Refer to Figure 5A as shown, which is a schematic diagram of time frame processing. The original signal length of the original signal data is N total , the calculated frame length is L frame , and segment the original signal data according to L frame to form N frames.
[0142] Step S22: Parameter extraction. The purpose of parameter extraction is to extract characteristic parameters (DSP parameters) from the signal data of each frame, construct a parameter sequence, and reflect the characteristic changes of the signal on the time axis.
[0143] For example, based on the signal data of frame 1 ( L frame phase data and L frame power spectrum data), the DSP parameters of frame 1 can be obtained, and the DSP parameters include m parameter values. For example, obtain the input signal data of the target optical fiber unit, and the input signal data includes phase data and power spectrum data. Then, signal preprocessing can be performed on the input signal data, such as filtering the input signal data for preprocessing, so as to improve the signal quality and eliminate noise interference. Then, time-energy dimension parameter extraction and space dimension parameter extraction can be performed on the preprocessed signal data ( L frame phase data and L frame power spectrum data) to obtain DSP parameters. The DSP parameters can include time-energy dimension parameters (such as P1...Pn) and space dimension parameters (such as Pn+1...Pm), that is, the DSP parameters include m parameter values, and m is a positive integer.
[0144] To ensure the comparability between different parameter values, normalization processing can also be performed on the m parameter values in the DSP parameters, such as mapping the m parameter values to a unified numerical interval (such as between 0 and 1).
[0145] In summary, based on the signal data of Frame 1 ( L frame phase data and L frame power spectrum data), m parameter values can be calculated. The m parameter values can include the root mean square (RMS), zero crossing rate (ZCR), peak-to-peak value, spectral entropy, etc. These m parameter values form the DSP parameters of Frame 1. Obviously, the DSP parameters can reflect the amplitude, frequency, and energy distribution characteristics of the signal, and there is no limitation on these DSP parameters.
[0146] For example, based on the signal data of Frame 2 (such as L frame phase data and L frame power spectrum data), the DSP parameters of Frame 2 can be obtained,..., and so on. Based on the signal data of Frame N (such as L frame phase data and L frame power spectrum data), the DSP parameters of Frame N can be obtained.
[0147] When calculating the DSP parameters of each frame, a unified parameter calculation process can be adopted to ensure the consistency of the DSP parameter calculation method and improve the reliability and repeatability of the DSP parameter calculation.
[0148] Refer to Figure 5B shown in the figure, which is a schematic diagram of parameter extraction. For the signal data of each frame, each characteristic parameter is calculated in sequence to form the parameter set of that frame. The parameter sets of all frames are arranged in order to construct a complete parameter sequence. For example, parameter extraction based on the signal data of Frame 1 obtains Parameter Set 1, and Parameter Set 1 includes the DSP parameters of Frame 1 (m parameter values). Parameter extraction based on the signal data of Frame 2 obtains Parameter Set 2, and Parameter Set 2 includes the DSP parameters of Frame 2. And so on, parameter extraction based on the signal data of Frame N obtains Parameter Set N, and Parameter Set N includes the DSP parameters of Frame N. On this basis, the DSP parameters of Parameter Set 1, the DSP parameters of Parameter Set 2,..., the DSP parameters of Parameter Set N can be combined to obtain a parameter sequence. Obviously, the parameter sequence can include N * m parameter values.
[0149] Step S23, matrix organization. The purpose of matrix organization is to organize the extracted parameter sequence into a two-dimensional matrix according to time and parameter dimensions, providing a data basis for subsequent visualization.
[0150] For example, for each of the consecutive N frames, the DSP parameters of that frame can be obtained, and the DSP parameters of that frame include m parameter values, and the N*m parameter values form a parameter sequence. Based on this parameter sequence, the m parameter values of each frame can be used as a row of a parameter matrix to obtain a parameter matrix. In this way, the parameter matrix can be an N-row m-column matrix. Or, based on this parameter sequence, the m parameter values of each frame can be used as a column of a parameter matrix to obtain a parameter matrix. In this way, the parameter matrix can be an N-column m-row matrix.
[0151] In summary, a parameter matrix can be constructed, which can clearly reflect the change relationship of parameters over time and realize the structured expression of DSP parameters. In addition, it can also support dynamically adjusting the structure and size of the matrix according to different numbers of parameters and number of frames. For example, the total number of frames can be dynamically adjusted. N .
[0152] See Figure 5C As shown, it is a schematic diagram of matrix organization. The DSP parameters of frame 1 (i.e., m parameter values, such as parameter 1, parameter 2,..., parameter m) are used as the first row (or first column) of the parameter matrix, and the DSP parameters of frame 2 (such as parameter 1, parameter 2,..., parameter m) are used as the second row (or second column) of the parameter matrix, and so on. The DSP parameters of frame N (such as parameter 1, parameter 2,..., parameter m) are used as the Nth row (or Nth column) of the parameter matrix, and then the parameter matrix is obtained.
[0153] Step 402, generate a grid image, which can include multiple grids.
[0154] Exemplarily, the purpose of generating the grid image is to map the parameter matrix to the pixel grid of the grid image (abbreviated as grid), so that the two-dimensional structure of the DSP parameters can be reflected in the image. By mapping the parameter values of the DSP parameters to the pixel grid of the grid image, the correspondence between the parameter values and the spatial positions is realized, forming an intuitive visual expression. The grid mapping is the step of converting the parameter matrix into an image.
[0155] Exemplarily, when generating the grid image, through resolution adjustment and grid filling, the parameter matrix is converted into a grayscale image with appropriate resolution and clarity to realize the visual expression of parameter features. For example, the resolution adjustment can include: dynamic adaptation, that is, according to the size of the parameter matrix and the desired image clarity, select an appropriate image size. Grid uniformity, that is, ensure that the grid size is an integer, or achieve uniform division through methods such as filling and interpolation. Boundary processing, that is, when the grid size cannot divide the image size evenly, adopt an appropriate edge filling strategy so that the grid size can divide the image size evenly.
[0156] Exemplarily, when generating a grid image, the grid image may include multiple grids (such as pixel grids). For each grid, the height dimension of the grid can be determined based on the height of the color grid image and the number of horizontal elements in the parameter matrix, and the width dimension of the grid can be determined based on the width of the color grid image and the number of vertical elements in the parameter matrix. For example, if the color grid image is the final output image, the height and width of the color grid image can be pre-configured to represent the desired height and width of the output color grid image.
[0157] For example, if the parameter matrix is an N-column and m-row matrix, that is, there are N elements vertically and m elements horizontally, the following formula is used to determine the height dimension of the grid: h = H / m , and the following formula is used to determine the width dimension of the grid: w =W / N. In the above formula, H represents the height (number of pixels) of the color grid image, that is, the height of the desired target image, W represents the width height (number of pixels) of the color grid image, that is, the width of the desired target image. h represents the height dimension of the grid, and w represents the width dimension of the grid.
[0158] Considering that the grid size is an integer, if H / m is an integer, then H / m is used as the height dimension of the grid. If H / m is not an integer, H / m can be rounded down to be used as the height dimension of the grid, or an appropriate edge padding strategy can be adopted to make H / m an integer. In addition, if W / N is an integer, then W / N is used as the width dimension of the grid. If W / N is not an integer, W / N can be rounded down to be used as the width dimension of the grid, or an appropriate edge padding strategy can be adopted to make W / N an integer.
[0159] Step 403: For each parameter value in the parameter matrix, determine the grid corresponding to the parameter value in the grid image, normalize the parameter value to a specified numerical range, and fill the normalized parameter value into the grid; where multiple parameter values in the parameter matrix correspond one-to-one with multiple grids in the grid image.
[0160] Exemplarily, when the parameter matrix is an N-column and m-row matrix, the height dimension of the grid is h = H / m , and the width dimension of the grid is w =W / N. Therefore, there are N grids horizontally in the grid image, and there are mA grid is used such that the N*m parameter values of the parameter matrix correspond one-to-one with the N*m grids of the grid image, that is, each parameter value corresponds to a single grid of the grid image.
[0161] For example, referring to Figure 5D As shown, it is a schematic diagram of grid division. The size of the grid image can be H*W. First, grid (1,1) can be divided. The width dimension of grid (1,1) can be w_grid (abbreviated as w), and the height dimension of grid (1,1) can be h_grid (abbreviated as h). Then, grid (1,2) and grid (2,1) can be divided, and so on. The division order of different grids can refer to Figure 5D As shown.
[0162] For example, after completing the grid division, the grid image can refer to Figure 5E As shown, the size of the grid image can be H*W. The width W corresponds to N grids, and the height H corresponds to m grids. In this way, the N*m parameter values of the parameter matrix correspond one-to-one with the N*m grids of the grid image. For example, grid (1,1) corresponds to the parameter value in the first row and first column of the parameter matrix, grid (1,2) corresponds to the parameter value in the first row and second column of the parameter matrix, grid (2,1) corresponds to the parameter value in the second row and first column of the parameter matrix, and so on.
[0163] Exemplarily, for each parameter value in the parameter matrix, the parameter value can be normalized to a specified numerical interval. The specified numerical interval can be [0, 255], that is, the numerical interval of the gray value, or it can be other numerical intervals, which is not restricted here. If the specified numerical interval is [0, 255], the following formula (8) can be used to normalize the parameter value to the specified numerical interval. Of course, formula (8) is just an example.
[0164] Formula (8) In formula (8), G ij represents the normalized parameter value, P ij represents the parameter value, 255 represents the maximum value of the specified numerical interval. When using other numerical intervals, 255 should also be replaced with the maximum value of the other numerical intervals accordingly. P min represents the minimum parameter value in the parameter matrix, P max represents the maximum parameter value in the parameter matrix. Through formula (8), the parameter value can be mapped to the gray range of [0, 255].
[0165] Exemplarily, for each parameter value in the parameter matrix, determine the grid corresponding to the parameter value in the grid image, and fill the normalized parameter value into the grid, that is, fill the normalized parameter value into the corresponding grid area. For example, when mapping the grid area, the following formula (9) can be used.
[0166] Formula (9) In formula (9), x start and y start represent the starting coordinates of the grid, x end and y end represent the ending coordinates of the grid, i represents the i th parameter value horizontally in the parameter matrix, j represents the j th parameter value vertically in the parameter matrix, S grid represents the width dimension w_grid or the height dimension h_grid of the grid.
[0167] Exemplarily, after filling the normalized parameter value corresponding to each parameter value in the parameter matrix into the grid image, a grayscale image can be obtained, that is, the grayscale image includes these normalized parameter values.
[0168] In the above process, adaptive grid division can be achieved, that is, according to the size of the parameter matrix, the grid size of the grid image is dynamically calculated to ensure that each parameter value corresponds to a specific pixel area (i.e., grid). Resolution configuration can be achieved, that is, it supports adjusting the size and resolution of the image according to needs to affect the fineness of the final image. The establishment of the mapping relationship can be achieved, mapping the elements in the parameter matrix to specific positions on the image to achieve an accurate correspondence between the parameter value and the pixel position.
[0169] Step 404: Perform a visualization transformation on the grayscale image to obtain a color grid image.
[0170] Exemplarily, a configured smoothing kernel can be used to perform a smoothing operation on the grayscale image to obtain a smoothed grayscale image. For example, the grayscale image can be smoothed according to requirements to improve the visual effect. The smoothing process is an optional step and can also not be performed. For example, the following formula can be used for the smoothing operation: I smooth = G ∗ K , I smooth can be the smoothed grayscale image, G can be the original grayscale image,K It can be a configured smoothing kernel, and ∗ can represent a convolution operation.
[0171] The smoothed grayscale image (or the original grayscale image) can be visually transformed to obtain a color grid image, such as converting the grayscale image to an RGB-type color image. There is no limitation on this conversion process. For example, the visual transformation is a process of converting a grayscale image into a color image, aiming to enhance the visual effect for easy human eye recognition and subsequent feature extraction. See Figure 5F As shown, it is a schematic diagram of a color grid image (DSP parameter color card) of a scene of climbing a ladder. See Figure 5G As shown, it is a schematic diagram of a color grid image of a scene where a vehicle passes by. See Figure 5H As shown, it is a schematic diagram of a color grid image of a rainstorm scene.
[0172] So far, the DSP parameter conversion process is completed, and a color grid image (color card image) can be obtained.
[0173] In a possible implementation manner, see Figure 2 As shown, after obtaining the Mel spectrogram, waterfall plot, and color grid image, feature fusion can also be performed based on the Mel spectrogram, waterfall plot, and color grid image, and then anomaly detection can be carried out. The following explains the anomaly detection process.
[0174] See Figure 6A As shown, it is a schematic diagram of the fusion of multi-source heterogeneous data or multimodal data. Multi-source heterogeneous data refers to a set of data with different forms, sources, or structures, including structured data (such as DSP parameters, alarm data) and unstructured data (such as Mel spectrograms, waterfall plots, etc.), and these data have differences in type, format, or dimension. Multimodal data is a set of data in different forms that describe the same object. Based on the fusion of multi-source heterogeneous data or multimodal data, feature fusion can be performed on the Mel spectrogram, waterfall plot, and color grid image to obtain the fused data, and then anomaly detection can be carried out based on the fused data. This anomaly detection process can include the following steps: Step S31: Obtain input data, such as the Mel spectrogram, waterfall plot, and color grid image.
[0175] Step S32: Perform feature preprocessing based on the input data, such as extracting RGB features based on the Mel spectrogram, performing grayscale transformation based on the waterfall plot, and performing parameter mapping based on the color grid image. There is no limitation on this feature preprocessing process. The feature preprocessing process is optional, and the following takes not performing it as an example.
[0176] Step S33: Perform feature fusion on the Mel spectrogram, waterfall plot, and color grid image. Here, the feature fusion can be channel-level fusion. Adopting a channel-level fusion strategy, map data of different modalities to the feature space uniformly. For example, perform splicing on the Mel spectrogram, waterfall plot, and color grid image in the channel dimension to obtain the spliced image, that is, the spliced image can include images of multiple channels.
[0177] For example, the spliced image can include acoustic spectrum features, time-frequency waterfall features, and parameter mapping features. The acoustic spectrum features are assigned 3 information channels, such as the 3 channels of the Mel spectrogram. The time-frequency waterfall features are assigned 1 information channel, such as the 1 channel of the waterfall plot. The parameter mapping features are assigned 1 information channel, such as the 1 channel of the color grid image. In summary, the spliced image can include 3 channels of the Mel spectrogram, 1 channel of the waterfall plot, and 1 channel of the color grid image. In this way, the spliced image is an image with 5 channels, and the spliced image includes the Mel spectrogram, waterfall plot, and color grid image.
[0178] Step S34: Input the spliced image into the anomaly detection model. The anomaly detection model performs model processing based on the spliced image to obtain the reconstructed image corresponding to the spliced image. Determine the initial anomaly score based on the difference between the reconstructed image and the spliced image, and output the initial anomaly score. In addition, the anomaly detection model can also output an interpretability analysis, and the content of this interpretability analysis is not restricted.
[0179] Exemplarily, the input data of the anomaly detection model is the spliced image (Mel spectrogram + waterfall plot + color grid image), and the output data of the anomaly detection model is the reconstructed image (reconstructed image of the Mel spectrogram + reconstructed image of the waterfall plot + reconstructed image of the color grid image). The processing process of this anomaly detection model is not restricted as long as it can process the spliced image to obtain the reconstructed image.
[0180] For example, the spliced image can be feature-mapped by the anomaly detection model to obtain the mapped features, and then the reconstructed image is generated based on the mapped features. When feature-mapping the spliced image, the following formula can be used: F = φ(X 1 , X 2 , X 3 ), where X 1 represents the acoustic spectrum features (such as the 3 channels of the Mel spectrogram), X 2 represents the time-frequency waterfall features (such as the 1 channel of the waterfall plot), and X 3 represents the parameter mapping features (such as the 1 channel of the color grid image). φ represents the configured feature mapping function.
[0181] For example, when performing feature mapping on the spliced image, the weight can also be adjusted adaptively according to the importance of features by matching the number of channels. The weight can be expressed as: W = {w 1 , w 2 , w 3}, where w 1 can represent the weight of the acoustic spectrum features, such as the three weights corresponding to the three channels of the Mel spectrogram, and w 2 can represent the weight of the time-frequency waterfall features, such as the one weight corresponding to the one channel of the waterfall diagram, and w 3 can represent the weight of the parameter mapping features, such as the one weight corresponding to the one channel of the color grid image.
[0182] Exemplarily, the network structure of the anomaly detection model can be referred to Figure 6B as shown. The anomaly detection model is a transformer network based on multi-task vision, such as a fusion model structure based on vision transformers. Of course, Figure 6B this is only an example of the network structure of the anomaly detection model, and there is no limitation on this network structure, as long as the anomaly detection model can process the spliced image to obtain the reconstructed image.
[0183] For example, the anomaly detection model may include a Patch Embedding network. The input feature of the Patch Embedding network is the spliced image. The Patch Embedding network is used to divide the spliced image into multiple non-overlapping small patches of a fixed size, and map each small patch into an embedding vector space of a specific dimension through a convolution operation, such as converting these small patches into 1D vectors (embedding, encoded image patches). There is no limitation on this processing process.
[0184] For example, the anomaly detection model may include a Position Encoding network. The input feature of the Position Encoding network is the output feature of the Patch Embedding network. The Position Encoding network is used to introduce position encoding at the input end of the transformer architecture and inject the position encoding into the input feature, so that the self-attention layer can pay attention to the position information when extracting feature information. As the only position information in the transformer architecture, the position encoding is superimposed on the input feature before entering the attention layer (or before entering the entire transformer architecture), and its dimension is consistent with the dimension of the input feature.
[0185] For example, the anomaly detection model may include Self Attention Layers (self-attention network). The input features of the Self Attention Layers are the output features of the Position Encoding network. The Self Attention Layers can perform self-attention processing based on the input features. For example, the following formula is used for self-attention processing: , where Q represents the query matrix, K represents the key matrix, V represents the value matrix, and d represents the feature dimension. There is no limitation on this self-attention processing process.
[0186] For example, the anomaly detection model may include a Feed Forward network. The input features of the Feed Forward network are the output features of the Self Attention Layers network. The Feed Forward network is also known as Forward propagation, which is a direct calculation method from the input layer to the output layer. The weight matrix is initialized to all 0, and the activation function is used for forward propagation until the output layer is calculated.
[0187] For example, the anomaly detection model may include a reconstruction decoder. The input features of the reconstruction decoder are the output features of the Feed Forward network. The reconstruction decoder is used to perform a reconstruction operation based on the input features to obtain the reconstructed image corresponding to the spliced image. The reconstructed image is used as the output feature of the anomaly detection model.
[0188] Exemplarily, after obtaining the reconstructed image, the initial anomaly score can be determined based on the difference between the reconstructed image and the spliced image. For example, when the number of channels of the reconstructed image is the same as that of the spliced image, and the spliced image includes a mel spectrogram, a waterfall plot, and a color grid image, the reconstructed image includes the reconstructed image of the mel spectrogram, the reconstructed image of the waterfall plot, and the reconstructed image of the color grid image.
[0189] On this basis, the difference between the reconstructed image and the spliced image can be calculated. For example, the MSE (Mean Square Error) between the reconstructed image and the spliced image can be calculated, and the initial anomaly score is determined based on the MSE. Of course, MSE is only an example, and there is no limitation on this. As long as the initial anomaly score is related to the difference between the images. When the difference between the reconstructed image and the spliced image is larger, the initial anomaly score is larger; when the difference between the reconstructed image and the spliced image is smaller, the initial anomaly score is smaller.
[0190] Exemplarily, in order to train the anomaly detection model, a reconstruction loss value, a knowledge distillation loss value, and a classification loss value are introduced in this embodiment. See Figure 6CAs shown, an optimization module is introduced after the anomaly detection model, and the optimization module is used to calculate the reconstruction loss value, the knowledge distillation loss value, and the classification loss value.
[0191] On this basis, in order to train the anomaly detection model, the following method can be adopted: Obtain the configured initial detection model, and refer to Figure 6B for the network structure of the initial detection model.
[0192] Obtain the sample data and the true labels of the sample data. The sample data can include sample Mel spectrograms, sample waterfall plots, and sample color grid images. The acquisition method of the sample Mel spectrogram refers to the acquisition method of the Mel spectrogram, the acquisition method of the sample waterfall plot refers to the acquisition method of the waterfall plot, and the acquisition method of the sample color grid image refers to the acquisition method of the color grid image. The true label of the sample data indicates that the vibration alarm is a false alarm (such as 0), or the true label indicates that the vibration alarm is a valid alarm (such as 1).
[0193] Perform channel dimension splicing on the sample Mel spectrogram, the sample waterfall plot, and the sample color grid image to obtain the spliced sample image, that is, the spliced image can include images of multiple channels.
[0194] After obtaining the spliced sample image, the spliced sample image can be input into the initial detection model to obtain the first sample reconstruction image and the predicted label. The predicted label can indicate that the vibration alarm is a false alarm (such as 0), or the true label indicates that the vibration alarm is a valid alarm (such as 1).
[0195] After obtaining the spliced sample image, the spliced sample image can also be input into the classroom detection model to obtain the second sample reconstruction image. For example, the classroom detection model and the student detection model can be constructed by means of knowledge distillation. The student detection model is the initial detection model. The network structure of the classroom detection model is the same as that of the student detection model. The classroom detection model is a larger detection model with higher detection accuracy, and the student detection model is a smaller detection model with lower detection accuracy. The training process of the initial detection model can be assisted by the classroom detection model to improve the detection accuracy of the initial detection model.
[0196] After obtaining the first sample reconstructed image, the second sample reconstructed image, and the predicted label, the reconstruction loss value can be determined based on the difference between the first sample reconstructed image and the image after sample splicing. That is, the greater the difference between the first sample reconstructed image and the image after sample splicing, the greater the reconstruction loss value. The optimization objective of the initial detection model is to make the reconstruction loss value smaller and smaller. The difference can be MSE or other types of differences. The knowledge distillation loss value can be determined based on the difference between the first sample reconstructed image and the second sample reconstructed image. That is, the greater the difference between the first sample reconstructed image and the second sample reconstructed image, the greater the knowledge distillation loss value. The optimization objective of the initial detection model is to make the knowledge distillation loss value smaller and smaller. The classification loss value can be determined based on the difference between the predicted label and the true label of the sample data. That is, the greater the difference between the predicted label and the true label, the greater the classification loss value. The optimization objective of the initial detection model is to make the classification loss value smaller and smaller.
[0197] Then, based on the reconstruction loss value, the knowledge distillation loss value, and the classification loss value, the target loss value is determined. For example, the target loss value is determined using the following formula: . In the above formula, L represents the target loss value, L ae represents the reconstruction loss value, α represents the weight coefficient corresponding to the reconstruction loss value, which can also be called the balance factor, L dist represents the knowledge distillation loss value, β represents the weight coefficient corresponding to the knowledge distillation loss value, L cls represents the classification loss value, γ represents the weight coefficient corresponding to the classification loss value.
[0198] After obtaining the target loss value, the parameters of the initial detection model can be adjusted based on the target loss value to obtain the adjusted model. During the parameter adjustment process, methods such as the gradient descent method can be used. The adjustment objective is to make the target loss value smaller and smaller. There are no restrictions on this parameter adjustment process.
[0199] Then, it is determined whether the adjusted model has converged. For example, if the target loss value is less than the threshold, the adjusted model has converged. If the target loss value is not less than the threshold, the adjusted model has not converged. Another example is that if the number of iterations reaches the iteration threshold, the adjusted model has converged. If the number of iterations does not reach the iteration threshold, the adjusted model has not converged. Another example is that if the iteration duration reaches the duration threshold, the adjusted model has converged. If the iteration duration does not reach the duration threshold, the adjusted model has not converged.
[0200] If the adjusted model has converged, the adjusted model can be determined as the anomaly detection model, and the model training process is completed to obtain a trained anomaly detection model. If the adjusted model has not converged, the adjusted model can be determined as the initial detection model, and the operation of inputting the sample spliced image to the initial detection model is returned, and then the above steps are repeated until the adjusted model has converged.
[0201] Step S35: Determine whether the vibration alarm is a false alarm or a valid alarm based on the initial abnormality score.
[0202] For example, if the initial anomaly score is not greater than a threshold, the vibration alarm is determined to be a false alarm, that is, the vibration alarm is an erroneous alarm result. Alternatively, if the initial anomaly score is greater than a threshold, the vibration alarm can be determined to be a valid alarm, that is, the vibration alarm is a correct alarm result.
[0203] For example, before the multimodal feature fusion (i.e., step S33), feature data alignment may also be involved, by establishing a unified benchmark in the time dimension while maintaining the unique expression of each feature in other dimensions, thereby achieving effective data alignment. Figure 6D The figure shows a schematic diagram of feature alignment. For example, the Mel spectrum graph in the frequency dimension, the waterfall graph in the spatial dimension, and the DSP parameter color card (i.e., the color grid image) in the parameter dimension can be aligned on the time axis. When aligning the time axis, a unified time reference can be established on the time dimension, and then the time axis alignment of the Mel spectrum graph, waterfall graph, and DSP parameter color card can be achieved.
[0204] Regarding the composition of feature dimensions, each feature image (Mel spectrum graph, waterfall graph, DSP parameter color card) contains two dimensional information, such as a unified time dimension (horizontal direction) and an independent feature dimension (vertical direction). On the unified time dimension, a unified time sampling benchmark is established to ensure that all features are fully aligned on the time axis and support continuous synchronization of real-time data streams. On the independent feature dimension, the Mel spectrum graph uses the frequency dimension to characterize the spectral distribution of the acoustic signal, the waterfall graph uses the spatial dimension to characterize the distribution of each spatial unit of the device, and the DSP parameter color card uses the parameter dimension to characterize the state characteristics of signal processing.
[0205] The alignment implementation strategy involves time dimension synchronization and multi-dimensional feature mapping. In the process of time dimension synchronization, the sampling frequency and time base can be unified, a time index correspondence mechanism can be established, and the temporal consistency of feature extraction can be ensured. In the process of multi-dimensional feature mapping, the independence of features in each dimension can be maintained, a standardized process for feature extraction can be established, and the physical meaning of the original data can be maintained.
[0206] In one possible implementation, see Figure 2As shown, after obtaining the timing statistical parameters, multi-level false alarm determination can also be performed based on the timing statistical parameters, and then anomaly detection can be carried out. The anomaly detection process is described below. During the multi-level false alarm determination process, the alarm data is accurately evaluated, false alarms are identified and filtered to ensure the reliability and effectiveness of the system. A multi-level false alarm determination logic is adopted to comprehensively analyze the alarm data from three dimensions: immediacy, relevance, and historicity, calculate the false alarm confidence level, and provide a basis for subsequent alarm processing. Refer to Figure 7 As shown, it is a schematic diagram of the false alarm determination process.
[0207] Step 701: When a vibration alarm is triggered in the target optical fiber unit, obtain the target alarm data of the target optical fiber unit. For example, the target optical fiber unit can be any optical fiber unit of the vibration optical fiber.
[0208] Step 702: Determine the immediacy parameter, relevance parameter, and historicity parameter based on the target alarm data.
[0209] Step 703: Determine the comprehensive false alarm score based on the immediacy score corresponding to the immediacy parameter, the relevance score corresponding to the relevance parameter, and the historicity score corresponding to the historicity parameter.
[0210] Exemplarily, if the immediacy parameter includes the signal dimension matching degree, the environmental correlation dimension matching degree, and the spatio-temporal consistency dimension matching degree, the immediacy score can be obtained by performing a weighted operation on the signal dimension matching degree, the environmental correlation dimension matching degree, and the spatio-temporal consistency dimension matching degree. For example, the immediacy score is calculated using the following formula: 。 SA represents the immediacy score, which is used to measure the immediate false alarm possibility of the current alarm, F 1 represents the signal dimension matching degree, w 1 represents the weight coefficient of the signal dimension matching degree, F 2 represents the environmental correlation dimension matching degree, w 2 represents the weight coefficient of the environmental correlation dimension matching degree, F 3 represents the spatio-temporal consistency dimension matching degree, w 3 represents the weight coefficient of the spatio-temporal consistency dimension matching degree, w 1 、 w 2 、 w 3 reflect the importance of each factor, satisfying w 1 + w2 + w 3 = 1。
[0211] The relevance parameter can be referred to in formula (4), and the relevance parameter RA can be used as the relevance score.
[0212] Exemplarily, if the historical parameters include a time pattern matching degree, a space pattern matching degree, and an environment pattern matching degree, then a weighted operation can be performed on the time pattern matching degree, the space pattern matching degree, and the environment pattern matching degree to obtain a historical score. For example, the following formula can be used to calculate the historical score: . HM represents the historical score and is used to represent the matching degree between the current alarm and the historical false alarm pattern. P T represents the time pattern matching degree, α represents the weight coefficient of the time pattern matching degree, P S represents the space pattern matching degree, β represents the weight coefficient of the space pattern matching degree, P E represents the environment pattern matching degree, γ represents the weight coefficient of the environment pattern matching degree, and satisfies α + β + γ = 1。
[0213] Exemplarily, after obtaining the immediacy score, the relevance score, and the historical score, a weighted operation can be performed on the immediacy score, the relevance score, and the historical score to obtain a comprehensive false alarm score. For example, the following formula can be used to calculate the comprehensive false alarm score: . FS represents the comprehensive false alarm score and comprehensively reflects the false alarm possibility of the current alarm, k 1 represents the dynamic weight coefficient of the immediacy score, k 2 represents the dynamic weight coefficient of the relevance score, k 3 represents the dynamic weight coefficient of the historical score, and the dynamic weight coefficient is adjusted according to the actual application scenario and requirements, and satisfies k 1 + k 2 + k 3 = 1。
[0214] Step 704: Determine the false alarm confidence level corresponding to the vibration alarm based on the comprehensive false alarm score.
[0215] Exemplarily, the false alarm confidence level may be directly proportional to the comprehensive false alarm score. There is no limitation on the way to determine the false alarm confidence level, as long as the false alarm confidence level is directly proportional to the comprehensive false alarm score. For example, in order to convert the comprehensive false alarm score into a probability value that can be directly used for decision-making, a logical function (Sigmoid function) is used to calculate the false alarm confidence level. For example, the false alarm confidence level is determined by the following formula: . C represents the false alarm confidence level, λ represents the configured adjustment coefficient, which is used to control the growth rate of the function, FS represents the comprehensive false alarm score, C The value range of is [0, 1], C The closer it is to 1, the greater the possibility of a false alarm.
[0216] Step 705: Determine whether the false alarm confidence level is not less than a threshold value (which can be configured according to experience).
[0217] If so, that is, the false alarm confidence level is not less than the threshold value, then step 706 can be executed.
[0218] If not, that is, the false alarm confidence level is less than the threshold value, then step 707 can be executed.
[0219] Step 706: Determine the vibration alarm as a false alarm, that is, the vibration alarm is an incorrect alarm result. In this case, the vibration alarm can be suppressed to avoid the transmission of false alarm information.
[0220] Step 707: Determine the vibration alarm as a valid alarm, that is, the vibration alarm is a correct alarm result. In this case, the corresponding alarm response can be triggered, such as sending a vibration alarm to the staff.
[0221] In a possible implementation manner, after obtaining the false alarm confidence level and the initial anomaly score, the false alarm confidence level and the initial anomaly score can also be combined, and a progressive suppression strategy can be adopted for anomaly detection (in Figure 2 , taking the progressive suppressor adopting the progressive suppression strategy for anomaly detection as an example), and the anomaly detection process is described below. The progressive suppression strategy means that the progressive suppressor dynamically adjusts the suppression coefficient according to the false alarm confidence level to achieve hierarchical suppression, improve the system reliability, and can dynamically adjust the suppression intensity of the alarm signal according to the high or low false alarm confidence level to achieve smooth and progressive suppression of false alarms. By setting the suppression level, calculating the suppression coefficient, applying the dynamic adjustment factor, etc., the alarm signal is refined to ensure that while reducing the false alarm rate, it does not affect the timely detection and response to real intrusion behaviors.
[0222] See Figure 8A As shown in, which is a schematic diagram of the progressive suppression process, this process may include: Step 801: Obtain the false alarm confidence level and the initial anomaly score.
[0223] Step 802: Determine the first suppression coefficient based on the false alarm confidence level.
[0224] Exemplarily, the first suppression coefficient is directly proportional to the false alarm confidence level. There is no limitation on the method for determining the first suppression coefficient as long as it is directly proportional to the false alarm confidence level. For example, based on the false alarm confidence level, a piecewise function can be used to calculate the first suppression coefficient. For example, the first suppression coefficient can be determined using the following formula (10). In formula (10), a piecewise function with four segments is used as an example to calculate the first suppression coefficient. Other piecewise functions (such as those with 3, 5, 6 segments, etc.) can also be used to calculate the first suppression coefficient.
[0225] Formula (10) x represents the false alarm confidence level, x the value range of S ( x ) represents the first suppression coefficient, T 1, T 2, T 3 represent the segmentation thresholds, and satisfy 0 < T 1 < T 2 < T 3 < 1, k 1, k 2, k 3 represent the slopes of each piecewise function, S 1 represents the suppression coefficient at the end of the first segment and serves as the starting point for the next segment, and S 1 = k 1 × ( T 2 − T 1), S 2 represents the suppression coefficient at the end of the second segment and serves as the starting point for the next segment, and S 2 = S 1 + k 2 × ( T 3 − T 2).
[0226] Step 803: Determine the suppression level based on the first suppression coefficient.
[0227] Exemplarily, according to the magnitude of the first suppression coefficient S ( x ), the suppression level is divided into 4 levels, or it can be divided into 2, 3, 5, 6 levels, etc. There is no limitation on this. Taking the division into 4 levels as an example, these 4 levels are called the normal suppression level, the mild suppression level, the moderate suppression level, and the high suppression level.
[0228] For example, if the first suppression coefficient S ( x ) is greater than or equal to 0 and less than the first value (e.g., 0 ≤ S ( x ) < 0.20), then the suppression level is determined to be the normal suppression level. Under the normal suppression level, it is in the normal monitoring state and does not suppress the alarm signal. That is to say, it does not suppress the initial anomaly score.
[0229] For example, if the first suppression coefficient S ( x ) is greater than or equal to the first value and less than the second value (e.g., 0.2 ≤ S(x) < 0.4), then the suppression level is determined to be the mild suppression level. Under the mild suppression level, a mild suppression measure is applied to the alarm signal with a relatively high false alarm probability, that is, the initial anomaly score is mildly suppressed.
[0230] For example, if the first suppression coefficient S ( x ) is greater than or equal to the second value and less than the third value (e.g., 0.4 ≤ S(x) < 0.7), then the suppression level is determined to be the moderate suppression level. Under the moderate suppression level, a moderate suppression measure is applied to the alarm signal with a relatively high false alarm confidence, that is, the initial anomaly score is moderately suppressed.
[0231] For example, if the first suppression coefficient S ( x ) is greater than or equal to the third value and less than or equal to the fourth value (the fourth value can be 1 or less than 1, such as 0.9, etc., e.g., 0.7 ≤ S(x) ≤ 0.9), then the suppression level is determined to be the high suppression level. Under the high suppression level, a strong suppression is performed on the alarm signal determined to be a high-probability false alarm to avoid the influence of false alarm information, that is, the initial anomaly score is strongly suppressed.
[0232] Step 804: Determine a second suppression coefficient based on the first suppression coefficient, the configured time adjustment factor, the configured space adjustment factor, and the configured environment adjustment factor.
[0233] Exemplarily, to improve the flexibility of the system, the progressive suppressor introduces a dynamic adjustment factor and modifies the first suppression coefficient according to the dynamic adjustment factor to obtain the second suppression coefficient. For example, the second suppression coefficient can be determined using the following formula (11). Of course, formula (11) is just an example.
[0234] Formula (11) In formula (11), S adjusted represents the adjusted suppression coefficient, that is, the second suppression coefficient, S( x ) represents the first suppression coefficient. F t represents a time adjustment factor. For example, different times have different time adjustment factors. For instance, the time adjustment factor for daytime is 1, and the time adjustment factor for nighttime is 2. Thus, if the target alarm time is during daytime, the time adjustment factor 1 is adopted. F s represents a space adjustment factor. For example, different regions have different space adjustment factors. For instance, the space adjustment factor for region 1 is 1, the space adjustment factor for region 2 is 2, and the space adjustment factor for region 3 is 3, and so on. Thus, if the target alarm location is in region 1, the space adjustment factor 1 is adopted. F e represents an environment adjustment factor. For example, different environments (such as weather, holidays, etc.) have different environment adjustment factors. For instance, the environment adjustment factor for environment 1 is 1, and the environment adjustment factor for environment 2 is 2, and so on. Thus, if the current vibration alarm corresponds to environment 1, the environment adjustment factor 1 is adopted. Regarding the values of each time adjustment factor, each space adjustment factor, and each environment adjustment factor, they can be pre-configured according to experience and are not limited in this embodiment.
[0235] Step 805: Determine a third suppression coefficient based on the second suppression coefficient and the configured attenuation coefficient.
[0236] Exemplarily, after obtaining the second suppression coefficient, the second suppression coefficient can be adjusted progressively. For example, a smoothing function (such as an exponential decay function) can be used to make the suppression effect transition smoothly and achieve a progressive curve adjustment. On this basis, the following formula (12) can be used to determine the third suppression coefficient: Formula (12) In formula (12), adjusted_confidence can represent the third suppression coefficient, base_confidence can represent the second suppression coefficient, α can represent the configured attenuation coefficient, t can represent a time interval. For example, the time interval can be the interval between the target alarm time and the configured initial time.
[0237] Step 806: Determine the target gain adjustment factor (night_gain) corresponding to the target alarm time.
[0238] For example, the night time interval and the day time interval can be pre-configured. The night time interval corresponds to a first factor value, and the day time interval corresponds to a second factor value. The first factor value is greater than the second factor value. For example, the first factor value is 1.2 and the second factor value is 1. Of course, in addition to the night time interval and the day time interval, more time intervals can be set, and each time interval corresponds to a factor value. On this basis, if the target alarm time is within the night time interval, the target gain adjustment factor is the first factor value; if the target alarm time is within the day time interval, the target gain adjustment factor is the second factor value.
[0239] By controlling the first factor value (such as 1.2) to be greater than the second factor value, the gain adjustment of the third suppression coefficient in the night time interval can be performed to improve the detection sensitivity in the night time interval.
[0240] Step 807: Determine the target suppression coefficient based on the third suppression coefficient and the target gain adjustment factor.
[0241] Exemplarily, if the product value between the third suppression coefficient and the target gain adjustment factor is less than a fixed value (which can be configured according to experience, and the fixed value can be less than 1, such as 0.9, etc.), then this product value is determined as the target suppression coefficient. If the product value between the third suppression coefficient and the target gain adjustment factor is not less than the fixed value, then the fixed value can be determined as the target suppression coefficient. In summary, the final target suppression coefficient can be calculated, and the maximum value of the target suppression coefficient is restricted not to exceed the fixed value.
[0242] Step 808: Adjust the initial anomaly score based on the target suppression coefficient and the configured dynamic influence factor to obtain the target anomaly score. For example, after obtaining the initial anomaly score, instead of directly taking the initial anomaly score as the target anomaly score, the target suppression coefficient is used to suppress the initial anomaly score, that is, to reduce the initial anomaly score, so as to consider the historical false alarm situation and suppress the current score. The greater the target suppression coefficient, the higher the degree of weakening of the initial anomaly score. In addition, the initial anomaly score can also be adjusted using the dynamic influence factor, taking into account the influence of the environment on the initial anomaly score.
[0243] Exemplarily, the initial anomaly score, the target suppression coefficient, and the dynamic influence factor can be fused to calculate the final alarm score (i.e., the target anomaly score). For example, the following formula (13) can be used to determine the target anomaly score. Of course, formula (13) is only an example and is not limited in this regard.
[0244] final_score = dl_score×(1−final_confidence)×factor Formula (13) In formula (13), final_score represents the target anomaly score, dl_scoreRepresents the initial anomaly score, which reflects the probability that the current signal is determined to be an intrusion by the anomaly detection model. final_confidence Represents the target suppression coefficient. factor Can represent a dynamic influence factor. (1−final_confidence) Indicates that considering the historical false alarm situation, the current score is suppressed. The larger the suppression coefficient, the higher the degree of weakening. factor Indicates that according to the analysis results, the score is dynamically adjusted to amplify possible intrusion signals and suppress possible natural interferences.
[0245] Regarding the dynamic influence factor factor , the type of the current signal can be determined according to the pattern recognition result (i.e., the detection result of the anomaly detection model). For example, the type of the current signal can be natural interference, intrusion threat, and others. Natural interference can be environmental noises such as wind blowing and rain hitting, intrusion threats can be intrusion behaviors such as climbing and destruction, and others can be signals that are not clearly classified. On this basis, for the signal type of natural interference, when calculating the dynamic influence factor factor , the calculation can be suppressed to reduce the impact on the total score. For the signal type of intrusion threat, when calculating the dynamic influence factor factor , the calculation can be amplified to enhance the impact on the total score. For the signal type of others, when calculating the dynamic influence factor factor , the dynamic influence factor factor can be kept unchanged. For example, the dynamic influence factor factor is kept as 1.
[0246] In summary, if the initial anomaly score is not greater than the threshold (i.e., the detection result of the anomaly detection model indicates that the type of the current signal is natural interference), the dynamic influence factor can be the value of the third factor, and the value of the third factor is used to reduce the impact on the initial anomaly score, such as the value of the third factor being less than 1. If the initial anomaly score is greater than the threshold (i.e., the detection result of the anomaly detection model indicates that the type of the current signal is intrusion threat), the dynamic influence factor can be the value of the fourth factor, and the value of the fourth factor is used to enhance the impact on the initial anomaly score, such as the value of the fourth factor being greater than 1. Obviously, the value of the third factor can be less than the value of the fourth factor.
[0247] Step 809: Determine whether the vibration alarm is a false alarm or a valid alarm based on the target anomaly score. For example, if the target anomaly score is not greater than the threshold, the vibration alarm can be determined as a false alarm, that is, the vibration alarm is an incorrect alarm result and does not trigger an alarm. If the target anomaly score is greater than the threshold, the vibration alarm can be determined as a valid alarm, that is, the vibration alarm is a correct alarm result and triggers an alarm. Regarding this threshold, it can be determined according to the system performance requirements and on-site environment debugging, and there is no limit to this.
[0248] Exemplarily, for the attenuation coefficient in step 805 α, attenuation coefficient α It is used to control the descending speed of the progressive curve and can be adjusted according to the characteristics of historical data. For the target gain adjustment factor (night_gain) in step 806, it can be appropriately adjusted according to the characteristics of the night environment to avoid excessive amplification or suppression. For the alarm threshold in step 809 ( Dt ), the false alarm rate and the miss alarm rate can be weighed to select an appropriate threshold.
[0249] Exemplarily, based on the above technical solution, multi-source information can be fused, and the initial anomaly score can be dynamically adjusted according to the real-time situation, so as to adapt to the complex and changeable environment and achieve dynamic adjustment. By introducing the target suppression coefficient and the dynamic influence factor, the false alarms caused by environmental noise and historical false alarms are reduced, and the false alarm rate is lowered. The anomaly detection model and the signal processing results can be comprehensively considered to give full play to their respective advantages, improve the reliability of the alarm decision-making, and enhance the accuracy of the alarm decision-making.
[0250] In a possible implementation manner, based on the initial anomaly score and the false alarm confidence, the target anomaly score can be determined by the result fusion decision maker. Refer to Figure 8B As shown, it is a structural schematic diagram of the result fusion decision maker, and the result fusion decision maker can include an input layer, a processing layer, and a fusion layer.
[0251] For the input layer, the input data can include the deep learning anomaly score (dl_score), the historical analysis result (history_result), and the time context (time_context). The deep learning anomaly score can be the initial anomaly score, which is the signal confidence score output by the anomaly detection model, ranging from 0 to 1, indicating the probability that the current signal is determined to be an intrusion. The historical analysis result can be the false alarm confidence. The time context can represent the current time information, which is used for day-night gain adjustment, etc., to help the system adapt to the characteristics of different time periods.
[0252] For the processing layer, it can involve historical analysis suppression calculation and dynamic influence factor calculation. During the historical analysis suppression calculation process, the first suppression coefficient can be determined based on the false alarm confidence, the second suppression coefficient can be determined based on the first suppression coefficient, the third suppression coefficient can be determined based on the second suppression coefficient and the attenuation coefficient, the target gain adjustment factor can be determined, and the target suppression coefficient can be determined based on the third suppression coefficient and the target gain adjustment factor.
[0253] During the dynamic influence factor calculation process, the dynamic influence factor can be calculated factor . For example, if the detection result of the anomaly detection model indicates that the type of the current signal is natural interference, the suppression calculation is performed, and the dynamic influence factor is the third factor value. The calculation method of the third factor value can be: factor = 1 - confidence*0.5 , confidenceThe first suppression coefficient, the second suppression coefficient, the third suppression coefficient, or the target suppression coefficient can be adopted. Of course, the above are only examples for determining the value of the third factor, and the value of the third factor is less than 1.
[0254] If the detection result of the anomaly detection model indicates that the type of the current signal is an intrusion threat, amplification calculation can be performed. The dynamic impact factor can be the value of the fourth factor, and the calculation method of the value of the fourth factor can be: factor = 1 + confidence*0.3 , confidence Adopt the first suppression coefficient, the second suppression coefficient, the third suppression coefficient, or the target suppression coefficient. The above are examples of the value of the fourth factor, and the value of the fourth factor is greater than 1.
[0255] If the detection result of the anomaly detection model indicates that the type of the current signal is other (neither intrusion threat nor natural interference), it can remain unchanged. For example, the dynamic impact factor can be 1, that is factor = 1 .
[0256] For the fusion layer, the target anomaly score can be obtained by fusing based on the target suppression coefficient, the dynamic impact factor, and the initial anomaly score. The target anomaly score is used to decide whether there is a false alarm.
[0257] As can be seen from the above technical solutions, a parameter color card method is proposed to convert multi-dimensional DSP parameters into a color grid image with a spatial structure, and through a mapping algorithm, an intuitive visual expression of signal features is realized. A heterogeneous data fusion method is proposed to fuse structured data and unstructured data through a unified visual expression, and an anomaly detection model is used to capture the correlation features of heterogeneous data to achieve more accurate event recognition.
[0258] Based on the above processing, higher accuracy and generalization are achieved with less data: through visual expression, the understanding and analysis of signal features are enhanced, which helps to quickly identify abnormal patterns. Compared with features such as spectrograms and waterfall diagrams, the DSP parameter color card has significant advantages in terms of training accuracy and generalization performance. This is because the parameter color card has undergone deep feature engineering processing and can more effectively extract and express the key features of vibration signals, and still achieve a high detection accuracy and better generalization when the training data is less.
[0259] Based on the above processing, a unified expression of heterogeneous data is realized: the parameter color card method presents complex multi-dimensional parameter data in the form of an image, solving the problem of difficult unified processing of different types of data.
[0260] Based on the above processing, the synergistic effect of the fused features is achieved: by fusing the DSP parameter color card with features such as spectrograms and waterfall plots, the overall performance of the model reaches the best, which indicates that there is a synergistic effect between different features, and the fused utilization can further enhance the adaptability and robustness of the model in complex scenarios.
[0261] As can be seen from the above technical solutions, it is possible to fuse historical data and comprehensively utilize long-term information. It is possible to implement multi-level false alarm determination, that is, introduce three-level false alarm determination mechanisms such as instant determination, relevance determination, and historical determination to comprehensively evaluate alarm signals. It is possible to implement a dynamic adjustment mechanism to enhance environmental adaptability, that is, comprehensively consider the impact of environmental factors (such as weather changes, seasonal factors, surrounding activities, etc.) on vibration signals, establish an association model between environmental factors and alarm features, and implement a dynamic adjustment mechanism for system parameters. It is possible to achieve progressive system optimization and autonomous learning ability, that is, have progressive optimization ability, and continuously adjust and optimize its own parameters according to real-time feedback and historical data to achieve autonomous learning.
[0262] Based on the above processing, it is possible to avoid common sense errors of the model from a global perspective: by deeply mining historical data within a long time range, it is possible to more comprehensively grasp the spatio-temporal evolution characteristics of signals, improve the recognition accuracy of abnormal events, and reduce false alarms caused by short-term abnormalities or noise. It can adaptively adjust to environmental changes: it can automatically adapt to environmental changes, maintain the stability of detection performance, and avoid false alarms or missed alarms caused by environmental factors. It can reduce maintenance costs: without frequent manual intervention, it reduces maintenance costs and can operate stably in complex and changeable actual environments for a long time.
[0263] As can be seen from the above technical solutions, it is possible to implement a model optimization method that fuses multiple loss functions, design a comprehensive loss function that fuses reconstruction loss, knowledge distillation loss, and classification loss, and achieve the collaborative improvement of the model under multiple tasks by simultaneously optimizing the reconstruction ability, knowledge transfer ability, and classification performance of the model. Based on the above processing, it is possible to reduce the forgetting level of the model: the knowledge distillation loss encourages the student model to learn the deep knowledge of the teacher model and maintain the memory of the learned knowledge while incrementally training. It can improve the accuracy of anomaly detection: the reconstruction loss and the classification loss are jointly learned to improve the accuracy and reliability of anomaly detection.
[0264] As can be seen from the above technical solutions, a multi-level false alarm determination mechanism can be introduced, combined with a progressive suppression strategy, to dynamically adjust the suppression coefficient. By combining signal processing with image processing, an intuitive visual expression of vibration signal features can be achieved, providing a basis for anomaly detection. Four types of complementary heterogeneous data are integrated: (1) phase data containing rich acoustic features and their corresponding Mel spectrograms, used to accurately characterize the characteristic patterns of various vibration events; (2) power spectral data reflecting the spatial energy distribution of signals and their corresponding waterfall plots, used to effectively distinguish intrusion behaviors from natural interferences; (3) DSP parameters providing multi-dimensional feature representations such as the time domain and frequency domain of signals and their color card visualizations, to achieve accurate classification of different types of vibration events and provide interpretable decision-making bases; (4) time series data of historical alarm statistical parameters containing long-term operation experience knowledge, providing reliable historical bases for model decision-making. By constructing a unified data expression framework, the deep fusion of these heterogeneous data is realized, which not only retains the unique advantages of each type of data but also gives full play to their complementarity. This multi-dimensional and multi-scale data fusion scheme not only significantly improves the generalization ability of the algorithm but also can achieve high detection rates and low false alarm rates, greatly reducing the amount of data required for model training.
[0265] Based on the same application concept as the above method, in an embodiment of the present application, an intrusion detection device based on a vibration optical fiber is proposed, which is applied to a management device of the vibration optical fiber. The vibration optical fiber includes a plurality of optical fiber units. Refer to Figure 9A As shown, it is a schematic structural diagram of the device. The device may include: An acquisition module 911, configured to obtain time series statistical parameters based on target alarm data of a target optical fiber unit when the target optical fiber unit triggers a vibration alarm. The target optical fiber unit is any one of the plurality of optical fiber units. The time series statistical parameters include at least one of an immediacy parameter, a correlation parameter, and a historicity parameter. Among them, the immediacy parameter represents multi-dimensional parameters of the target alarm data, the correlation parameter represents the correlation parameter between the target alarm data and alarms in adjacent regions, and the historicity parameter represents the correlation parameter between the target alarm data and historical alarm data; A determination module 912, configured to determine a false alarm confidence level corresponding to the vibration alarm based on the time series statistical parameters; A determination module 913, configured to determine whether the vibration alarm is a false alarm or a valid alarm based on the false alarm confidence level.
[0266] Exemplarily, the immediacy parameter includes at least one of a signal dimension matching degree, an environment correlation dimension matching degree, and a spatio-temporal consistency dimension matching degree; when the obtaining module 911 obtains the signal dimension matching degree, it specifically is used for: extracting features from the target alarm data to obtain the current signal features; determining a first similarity degree between the current signal features and the sample signal features, and determining the signal dimension matching degree based on the first similarity degree; wherein, the sample signal features are obtained by extracting features from the alarm data in a non-intrusion scenario. When the obtaining module 911 obtains the environment correlation dimension matching degree, it specifically is used for: if the target alarm data includes the target environment data corresponding to the target optical fiber unit, extracting features from the target environment data to obtain the current environment features; determining a second similarity degree between the current environment features and the sample environment features, and determining the environment correlation dimension matching degree based on the second similarity degree; wherein, the sample environment features are obtained by extracting features from the environment data in a non-intrusion scenario. When the obtaining module 911 obtains the spatio-temporal consistency dimension matching degree, it specifically is used for: if the target alarm data includes a target alarm time and a target alarm location, determining a first false alarm probability corresponding to the target alarm time, determining a second false alarm probability corresponding to the target alarm location, and performing a weighted operation on the first false alarm probability and the second false alarm probability to obtain the spatio-temporal consistency dimension matching degree; multiple times on the time dimension respectively correspond to false alarm probabilities, and multiple positions on the space dimension respectively correspond to false alarm probabilities.
[0267] Exemplarily, when the obtaining module 911 obtains the relevance parameter, it specifically is used for: determining a plurality of associated optical fiber units corresponding to the target optical fiber unit, the distance between each associated optical fiber unit and the target optical fiber unit is less than a distance threshold, and each associated optical fiber unit triggers a vibration alarm; if the target alarm data includes the vibration intensity of the target optical fiber unit, then based on the vibration intensity of the target optical fiber unit, the vibration intensity of each associated optical fiber unit, the distance attenuation coefficient corresponding to each associated optical fiber unit, and the total number of associated optical fiber units, determining the relevance parameter; Wherein, for each associated optical fiber unit, the distance attenuation coefficient is determined based on the linear attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit, or the distance attenuation coefficient is determined based on the exponential attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit.
[0268] Exemplarily, the historical parameter includes at least one of a time pattern matching degree, a space pattern matching degree, and an environment pattern matching degree; when the obtaining module 911 obtains the time pattern matching degree, it specifically is configured to: if the target alarm data includes a target alarm time, determine a first statistical feature of the target alarm time and a second statistical feature of a historical false alarm time based on the target alarm data and the historical alarm data, and determine the time pattern matching degree based on the first statistical feature and the second statistical feature; wherein, the historical false alarm time is an alarm time indicating a vibration alarm false alarm in the historical alarm data. When the obtaining module 911 obtains the space pattern matching degree, it specifically is configured to: if the target alarm data includes a target alarm location, determine the target alarm location and a plurality of historical false alarm locations based on the target alarm data and the historical alarm data, where each historical false alarm location is an alarm location indicating a vibration alarm false alarm in the historical alarm data; determine the space pattern matching degree based on the spatial overlap degree between the target alarm location and each historical false alarm location. When the obtaining module 911 obtains the environment pattern matching degree, it specifically is configured to: if the target alarm data includes target environment data, determine a current environment feature corresponding to the target environment data and a historical false alarm environment feature based on the target alarm data and the historical alarm data, where the historical false alarm environment feature is an environment feature indicating a vibration alarm false alarm in the historical alarm data; determine the environment pattern matching degree based on the current environment feature and the historical false alarm environment feature.
[0269] Exemplarily, when the determining module 912 determines the false alarm confidence level corresponding to the vibration alarm based on the time series statistical parameter, it specifically is configured to: determine a comprehensive false alarm score based on the time series statistical parameter; wherein, if the time series statistical parameter includes an immediacy parameter, a relevance parameter, and a historical parameter, perform a weighted operation on the immediacy score, the relevance score, and the historical score to obtain the comprehensive false alarm score; wherein, if the immediacy parameter includes a signal dimension matching degree, an environment correlation dimension matching degree, and a spatio-temporal consistency dimension matching degree, perform a weighted operation on the signal dimension matching degree, the environment correlation dimension matching degree, and the spatio-temporal consistency dimension matching degree to obtain the immediacy score; determine the relevance score based on the relevance parameter; if the historical parameter includes a time pattern matching degree, a space pattern matching degree, and an environment pattern matching degree, perform a weighted operation on the time pattern matching degree, the space pattern matching degree, and the environment pattern matching degree to obtain the historical score; determine the false alarm confidence level based on the comprehensive false alarm score; wherein, the false alarm confidence level is proportional to the comprehensive false alarm score.
[0270] Exemplarily, when determining the false alarm confidence based on the comprehensive false alarm score, the determining module 912 is specifically configured to: determine the false alarm confidence by using the following formula: ; where C represents the false alarm confidence, λ represents a configured adjustment coefficient, FS represents the comprehensive false alarm score, C The value range of is [0, 1], C The closer it is to 1, the greater the possibility of false alarm.
[0271] When determining whether the vibration alarm is a false alarm or a valid alarm based on the false alarm confidence, the determining module 913 is specifically configured to: if the false alarm confidence is not less than the threshold, determine that the vibration alarm is a false alarm; if the false alarm confidence is less than the threshold, determine that the vibration alarm is a valid alarm.
[0272] Exemplarily, when the target optical fiber unit triggers a vibration alarm, the obtaining module 911 is further configured to obtain the phase data and power spectrum data corresponding to the target optical fiber unit; determine a Mel spectrogram based on the phase data, and determine a waterfall plot based on the power spectrum data; obtain DSP parameters based on the phase data and the power spectrum data, and convert the DSP parameters into a color grid image; The intrusion detection device based on vibrating optical fiber further includes: a processing module, configured to splice the Mel spectrogram, the waterfall plot, and the color grid image in the channel dimension to obtain a spliced image; input the spliced image into an anomaly detection model to obtain an initial anomaly score; the determining module 913 is further configured to determine whether the vibration alarm is a false alarm or a valid alarm based on the initial anomaly score.
[0273] Exemplarily, when converting the DSP parameters into a color grid image, the obtaining module 911 is specifically configured to: convert the DSP parameters into a parameter matrix, where the parameter matrix includes a plurality of parameter values; generate a grid image, where the grid image includes a plurality of grids; the height dimension of the grid is determined based on the height of the color grid image and the number of horizontal elements of the parameter matrix, and the width dimension of the grid is determined based on the width of the color grid image and the number of vertical elements of the parameter matrix; for each parameter value in the parameter matrix, determine the grid corresponding to the parameter value in the grid image, normalize the parameter value to a specified numerical interval, and fill the normalized parameter value into the grid; the plurality of parameter values in the parameter matrix correspond to the plurality of grids in the grid image one by one; perform a visualization conversion on the grayscale image to obtain the color grid image; where, after filling all the normalized parameter values into the grid image, the grayscale image is obtained.
[0274] Exemplarily, when the obtaining module 911 converts the DSP parameters into a parameter matrix, it specifically is used for: for each of the continuous N frames, obtaining the DSP parameters of this frame, where the DSP parameters of this frame are obtained based on the phase data and power spectrum data of this frame, and the DSP parameters of this frame include m parameter values; taking the m parameter values of each frame as a row of the parameter matrix to obtain the parameter matrix; wherein, the parameter matrix is a matrix with N rows and m columns; or, taking the m parameter values of each frame as a column of the parameter matrix to obtain the parameter matrix; wherein, the parameter matrix is a matrix with N columns and m rows; N is a positive integer, and m is a positive integer.
[0275] Exemplarily, when the obtaining module 911 normalizes the parameter value to a specified numerical range, it specifically is used for: if the specified numerical range is [0, 255], then the following formula is used to normalize the parameter value to the specified numerical range: ; wherein, G ij represents the normalized parameter value, P ij represents this parameter value, P min represents the minimum parameter value in the parameter matrix, P max represents the maximum parameter value in the parameter matrix; When the obtaining module 911 performs a visualization conversion on the grayscale image to obtain the color grid image, it specifically is used for: performing a smoothing operation on the grayscale image by using a configured smoothing kernel to obtain a smoothed grayscale image, and performing a visualization conversion on the smoothed grayscale image to obtain the color grid image.
[0276] Exemplarily, when the processing module inputs the spliced image into the anomaly detection model to obtain an initial anomaly score, it specifically is used for: inputting the spliced image into the anomaly detection model to obtain a reconstructed image corresponding to the spliced image, and determining the initial anomaly score based on the difference between the reconstructed image and the spliced image; when the determination module 913 determines whether the vibration alarm is a false alarm or a valid alarm based on the initial anomaly score, it specifically is used for: if the initial anomaly score is not greater than the threshold, determining that the vibration alarm is a false alarm; if the initial anomaly score is greater than the threshold, determining that the vibration alarm is a valid alarm.
[0277] Exemplarily, the processing module is further configured to train the anomaly detection model based on the configured initial detection model. When the processing module trains the anomaly detection model, it is specifically configured to: obtain a sample Mel spectrogram, a sample waterfall plot, and a sample color grid image, splice them in the channel dimension to obtain a spliced sample image; input the spliced sample image into the initial detection model to obtain a first reconstructed sample image and a predicted label, and input the spliced sample image into the trained classroom detection model corresponding to the initial detection model to obtain a second reconstructed sample image; determine a reconstruction loss value based on the difference between the first reconstructed sample image and the spliced sample image, determine a knowledge distillation loss value based on the difference between the first reconstructed sample image and the second reconstructed sample image, and determine a classification loss value based on the difference between the predicted label and the true label of the spliced sample image; determine a target loss value based on the reconstruction loss value, the knowledge distillation loss value, and the classification loss value, and adjust the parameters of the initial detection model based on the target loss value to obtain an adjusted model; if the adjusted model has converged, determine the adjusted model as the anomaly detection model; if the adjusted model has not converged, determine the adjusted model as the initial detection model, and return to execute inputting the spliced sample image into the initial detection model.
[0278] Exemplarily, the determining module 912 is further configured to determine a target suppression coefficient based on the false alarm confidence, and adjust the initial anomaly score based on the target suppression coefficient and the configured dynamic influence factor to obtain a target anomaly score; the determining module 913 is further configured to, when determining whether the vibration alarm is a false alarm or a valid alarm, if the target anomaly score is not greater than the threshold, determine the vibration alarm as a false alarm; if the target anomaly score is greater than the threshold, determine the vibration alarm as a valid alarm.
[0279] Exemplarily, when the determining module 912 determines the target suppression coefficient based on the false alarm confidence, it is specifically configured to: determine a first suppression coefficient based on the false alarm confidence, and the first suppression coefficient is proportional to the false alarm confidence; determine a second suppression coefficient based on the first suppression coefficient, a time adjustment factor, a space adjustment factor, and an environment adjustment factor; determine a third suppression coefficient based on the second suppression coefficient and the configured attenuation coefficient; determine a target gain adjustment factor corresponding to the target alarm time of the vibration alarm, and determine the target suppression coefficient based on the third suppression coefficient and the target gain adjustment factor.
[0280] Exemplarily, when the determining module 912 determines the target suppression coefficient based on the third suppression coefficient and the target gain adjustment factor, it specifically is used for: if the product value between the third suppression coefficient and the target gain adjustment factor is less than a fixed value, determining the product value as the target suppression coefficient; if the product value is not less than the fixed value, determining the fixed value as the target suppression coefficient; wherein, if the target alarm time is within a configured night time interval, the target gain adjustment factor is a first factor value, and if the target alarm time is within a configured day time interval, the target gain adjustment factor is a second factor value, and the first factor value is greater than the second factor value.
[0281] Exemplarily, when the determining module 912 adjusts the initial anomaly score based on the target suppression coefficient and a configured dynamic influence factor to obtain a target anomaly score, it specifically is used for: determining the target anomaly score by using the following formula: final_score = dl_score×(1−final_confidence)×factor ; wherein, final_score represents the target anomaly score, dl_score represents the initial anomaly score, final_confidence represents the target suppression coefficient, factor represents the dynamic influence factor; if the initial anomaly score is not greater than a threshold value, the dynamic influence factor is a third factor value, and if the initial anomaly score is greater than the threshold value, the dynamic influence factor is a fourth factor value; wherein, the third factor value is less than the fourth factor value.
[0282] Based on the same application concept as the above method, an electronic device is proposed in an embodiment of the present application. As shown in Figure 9B , it includes: a processor 921 and a machine-readable storage medium 922. The machine-readable storage medium 922 stores machine-executable instructions that can be executed by the processor 921; the processor 921 is used to execute the machine-executable instructions to implement the intrusion detection method based on vibrating optical fiber disclosed in the above examples of the present application.
[0283] Based on the same application concept as the above method, an embodiment of the present application further provides a machine-readable storage medium. A number of computer instructions are stored on the machine-readable storage medium. When the computer instructions are executed by a processor, the intrusion detection method based on vibrating optical fiber disclosed in the above examples of the present application can be implemented.
[0284] Among them, the above machine-readable storage medium can be any electronic, magnetic, optical or other physical storage device that can contain or store information such as executable instructions, data, etc. For example, the machine-readable storage medium can be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drives (such as hard disk drives), solid-state drives, any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or a combination thereof.
[0285] Based on the same application concept as the above method, an embodiment of the present application further provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, it implements the intrusion detection method based on vibration optical fiber disclosed in the above examples of the present application.
[0286] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes. The above are only the embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A vibrating optical fiber-based intrusion detection method, characterized in that: A management device for a vibrating optical fiber, wherein the vibrating optical fiber comprises a plurality of optical fiber units, and the method comprises: When a target optical fiber unit triggers a vibration alarm, a time series statistical parameter is obtained based on the target alarm data of the target optical fiber unit, the target optical fiber unit is any optical fiber unit, and the time series statistical parameter includes at least one of an immediacy parameter, a correlation parameter, and a history parameter; wherein the immediacy parameter represents a multi-dimensional parameter of the target alarm data, the correlation parameter represents an association parameter between the target alarm data and an alarm in an adjacent area, and the history parameter represents an association parameter between the target alarm data and the history alarm data; Determine the false alarm confidence corresponding to the vibration alarm based on the time series statistical parameters; The vibration alarm is determined to be a false alarm or a valid alarm based on the false alarm confidence.
2. The method according to claim 1, characterized in that The immediacy parameter includes at least one of a signal dimension matching degree, an environment correlation dimension matching degree, and a spatiotemporal consistency dimension matching degree; The process of obtaining the signal dimension matching degree includes: extracting features from the target alarm data to obtain current signal features; determining a first similarity between the current signal features and sample signal features, and determining the signal dimension matching degree based on the first similarity; wherein the sample signal features are obtained by extracting features from alarm data in a non-intrusion scenario; The process of obtaining the matching degree of the environment correlation dimension includes: if the target alarm data includes the target environment data corresponding to the target optical fiber unit, extracting the features of the target environment data to obtain the current environment features; determining the second similarity between the current environment features and the sample environment features, and determining the matching degree of the environment correlation dimension based on the second similarity; wherein the sample environment features are obtained by extracting the features of the environment data in a non-intrusive scenario; Among them, the process of obtaining the matching degree of the spatiotemporal consistency dimension includes: if the target alarm data includes the target alarm time and the target alarm position, then determining the first false alarm probability corresponding to the target alarm time, determining the second false alarm probability corresponding to the target alarm position, and performing weighted operations on the first false alarm probability and the second false alarm probability to obtain the matching degree of the spatiotemporal consistency dimension; wherein, multiple times on the time dimension correspond to false alarm probabilities respectively, and multiple positions on the space dimension correspond to false alarm probabilities respectively.
3. The method according to claim 1, characterized in that The process of obtaining the correlation parameters includes: Determine a plurality of associated optical fiber units corresponding to the target optical fiber unit, wherein the distance between each associated optical fiber unit and the target optical fiber unit is less than a distance threshold, and each associated optical fiber unit triggers a vibration alarm; If the target alarm data includes the vibration intensity of the target optical fiber unit, determining the correlation parameter based on the vibration intensity of the target optical fiber unit, the vibration intensity of each associated optical fiber unit, the distance attenuation coefficient corresponding to each associated optical fiber unit, and the total number of associated optical fiber units; Wherein, for each associated optical fiber unit, the distance attenuation coefficient is determined based on a linear attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit, or the distance attenuation coefficient is determined based on an exponential attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit.
4. The method according to claim 1, characterized in that The historical parameter includes at least one of a temporal pattern matching degree, a spatial pattern matching degree, and an environmental pattern matching degree; The process of obtaining the time pattern matching degree includes: if the target alarm data includes a target alarm time, determining a first statistical feature of the target alarm time and a second statistical feature of a historical false alarm time based on the target alarm data and the historical alarm data, and determining the time pattern matching degree based on the first statistical feature and the second statistical feature; wherein the historical false alarm time is an alarm time indicating the existence of a vibration alarm false alarm in the historical alarm data; The process of acquiring the spatial pattern matching degree includes: if the target alarm data includes a target alarm position, determining the target alarm position and a plurality of historical false alarm positions based on the target alarm data and the historical alarm data, wherein each historical false alarm position is an alarm position where a vibration alarm false alarm exists as indicated in the historical alarm data; determining the spatial pattern matching degree based on the spatial overlap between the target alarm position and each historical false alarm position; Among them, the process of obtaining the environmental pattern matching degree includes: if the target alarm data includes target environmental data, then determining the current environmental characteristics and historical false alarm environmental characteristics corresponding to the target environmental data based on the target alarm data and the historical alarm data, wherein the historical false alarm environmental characteristics are environmental characteristics indicating the existence of vibration alarm false alarms in the historical alarm data; and determining the environmental pattern matching degree based on the current environmental characteristics and the historical false alarm environmental characteristics.
5. The method according to claim 1, characterized in that The determining the false alarm confidence corresponding to the vibration alarm based on the time series statistical parameter includes: Determine a comprehensive false alarm score based on the time series statistical parameters; wherein, if the time series statistical parameters include an immediacy parameter, a relevance parameter and a historicity parameter, perform a weighted operation on the immediacy score, the relevance score and the historicity score to obtain a comprehensive false alarm score; wherein, if the immediacy parameter includes a signal dimension matching degree, an environmental correlation dimension matching degree and a spatiotemporal consistency dimension matching degree, perform a weighted operation on the signal dimension matching degree, the environmental correlation dimension matching degree and the spatiotemporal consistency dimension matching degree to obtain an immediacy score; determine a relevance score based on the relevance parameter; if the historicity parameter includes a time pattern matching degree, a space pattern matching degree and an environment pattern matching degree, perform a weighted operation on the time pattern matching degree, the space pattern matching degree and the environment pattern matching degree to obtain a historicity score; determining the false alarm confidence based on the combined false alarm score; The false alarm confidence is proportional to the comprehensive false alarm score.
6. The method according to any one of claims 1 to 5, characterized in that: When the target optical fiber unit triggers a vibration alarm, the method further includes: Acquire phase data and power spectrum data corresponding to the target optical fiber unit; determine a Mel spectrum diagram based on the phase data, and determine a waterfall diagram based on the power spectrum data; acquire DSP parameters based on the phase data and the power spectrum data, and convert the DSP parameters into a color grid image; The mel spectrum graph, the waterfall graph and the color grid image are spliced in channel dimension to obtain a spliced image; the spliced image is input into an anomaly detection model to obtain an initial anomaly score; The vibration alarm is determined to be a false alarm or a valid alarm based on the initial abnormality score.
7. The method according to claim 6, characterized in that The converting the DSP parameters into a color grid image comprises: Converting the DSP parameters into a parameter matrix, wherein the parameter matrix includes a plurality of parameter values; Generate a grid image, wherein the grid image includes a plurality of grids; wherein the height of the grid is determined based on the height of the color grid image and the number of horizontal elements of the parameter matrix, and the width of the grid is determined based on the width of the color grid image and the number of vertical elements of the parameter matrix; For each parameter value in the parameter matrix, determine the grid corresponding to the parameter value in the grid image, normalize the parameter value to a specified numerical range, and fill the normalized parameter value into the grid; wherein the multiple parameter values in the parameter matrix correspond one-to-one to the multiple grids in the grid image; The grayscale image is visually converted to obtain the color grid image; wherein, after all normalized parameter values are filled into the grid image, the grayscale image is obtained.
8. The method according to claim 6, characterized in that Inputting the spliced image to an anomaly detection model to obtain an initial anomaly score includes: inputting the spliced image to an anomaly detection model to obtain a reconstructed image corresponding to the spliced image, and determining an initial anomaly score based on a difference between the reconstructed image and the spliced image; The determining, based on the initial abnormality score, that the vibration alarm is a false alarm or a valid alarm comprises: if the initial abnormality score is not greater than a threshold, determining the vibration alarm as a false alarm; if the initial abnormality score is greater than a threshold, determining the vibration alarm as a valid alarm.
9. The method according to claim 8, characterized in that Based on the configured initial detection model, the training process of the anomaly detection model includes: Obtain a sample Mel spectrum graph, a sample waterfall graph, and a sample color grid image, and perform channel dimension splicing on the sample Mel spectrum graph, the sample waterfall graph, and the sample color grid image to obtain a sample spliced image; input the sample spliced image to the initial detection model to obtain a first sample reconstructed image and a predicted label, and input the sample spliced image to a trained classroom detection model corresponding to the initial detection model to obtain a second sample reconstructed image; Determine a reconstruction loss value based on a difference between the first sample reconstructed image and the sample spliced image, determine a knowledge distillation loss value based on a difference between the first sample reconstructed image and the second sample reconstructed image, and determine a classification loss value based on a difference between the predicted label and the true label of the sample spliced image; Determining a target loss value based on the reconstruction loss value, the knowledge distillation loss value, and the classification loss value, and adjusting parameters of the initial detection model based on the target loss value to obtain an adjusted model; If the adjusted model has converged, determining the adjusted model as the anomaly detection model; If the adjusted model does not converge, the adjusted model is determined as the initial detection model, and the operation of inputting the sample spliced image to the initial detection model is returned to be executed.
10. The method according to claim 6, characterized in that The method further includes: determining the vibration alarm as a false alarm or a valid alarm based on the false alarm confidence and the initial abnormality score; The process of determining whether the vibration alarm is a false alarm or a valid alarm includes: Determining a target suppression coefficient based on the false alarm confidence, and adjusting the initial anomaly score based on the target suppression coefficient and a configured dynamic impact factor to obtain a target anomaly score; If the target abnormality score is not greater than the threshold, the vibration alarm is determined to be a false alarm; If the target abnormality score is greater than a threshold, the vibration alarm is determined to be a valid alarm.
11. The method according to claim 10, characterized in that The determining of the target suppression coefficient based on the false alarm confidence comprises: Determine a first suppression coefficient based on the false alarm confidence, the first suppression coefficient being proportional to the false alarm confidence; determine a second suppression coefficient based on the first suppression coefficient, a configured time adjustment factor, a configured space adjustment factor, and a configured environment adjustment factor; determining a third suppression coefficient based on the second suppression coefficient and a configured attenuation coefficient; A target gain adjustment factor corresponding to a target alarm time of the vibration alarm is determined, and a target suppression coefficient is determined based on the third suppression coefficient and the target gain adjustment factor.
12. An intrusion detection device based on vibrating optical fiber, characterized in that: A management device for a vibrating optical fiber, wherein the vibrating optical fiber comprises a plurality of optical fiber units, and the device comprises: An acquisition module, configured to acquire a time series statistical parameter based on target alarm data of a target optical fiber unit when a vibration alarm is triggered by a target optical fiber unit, wherein the target optical fiber unit is any optical fiber unit among the multiple optical fiber units, and the time series statistical parameter includes at least one of an immediacy parameter, a correlation parameter, and a history parameter; wherein the immediacy parameter represents a multi-dimensional parameter of the target alarm data, the correlation parameter represents an association parameter between the target alarm data and an alarm of an adjacent area, and the history parameter represents an association parameter between the target alarm data and history alarm data; A determination module, used to determine the false alarm confidence corresponding to the vibration alarm based on the time series statistical parameters; The determination module is used to determine whether the vibration alarm is a false alarm or a valid alarm based on the false alarm confidence level.
13. An electronic device, characterized in that: include: a processor and a machine-readable storage medium storing machine-executable instructions executable by the processor; The processor is used to execute machine executable instructions to implement the method described in any one of claims 1-11.
Citation Information
Patent Citations
Multi-dimensional feature intrusion detection method based on distributed optical fibers
CN115798131A
Optical fiber vibration abnormity identification method, apparatus and device, and computer program product
CN117648632A
Monitoring and early warning method and system of distributed optical fiber sonic sensor
CN119197740A
OTDR alarm data processing method and device, equipment and storage medium
CN119449572A
Heart rate monitoring method, device and apparatus
US20250025060A1
Cited By
Passive optical fiber multi-parameter digital twin drive abnormal root cause positioning method and system
CN121188579A
Alarm false alarm filtering method and system based on historical data
CN121353700A