An intrusion detection method, device and equipment based on vibrating optical fiber

By obtaining the immediacy, correlation and historical parameters of the vibrating fiber, the problem of high false alarm rate of vibrating fiber is solved, and higher accuracy and stable intrusion detection are achieved.

CN120048051BActive Publication Date: 2025-08-05HANGZHOU KUANGXIN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510511439.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-08-05
Estimated Expiration
2045-04-22

AI Technical Summary

Technical Problem

Intrusion detection methods based on vibrating fibers are prone to high false alarm rates under environmental interference.

Method used

By obtaining the immediate parameters, correlation parameters and historical parameters of the target fiber unit, the false alarm confidence is determined, and the vibration alarm is determined as an error report alarm or an effective alarm based on the false alarm confidence.

Benefits of technology

The false alarm rate is reduced and the accuracy, stability and environmental adaptability of vibrating fiber intrusion detection are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120048051B_ABST
    Figure CN120048051B_ABST
Patent Text Reader

Abstract

The present application provides an intrusion detection method, device and equipment based on vibration optical fiber. The method includes: when a target optical fiber unit triggers a vibration alarm, obtaining timing statistical parameters based on the target alarm data of the target optical fiber unit, where the target optical fiber unit is any optical fiber unit, and the timing statistical parameters include at least one of an immediacy parameter, a correlation parameter and a historic parameter; wherein, the immediacy parameter represents multi-dimensional parameters of the target alarm data, the correlation parameter represents the correlation parameter between the target alarm data and adjacent area alarms, and the historic parameter represents the correlation parameter between the target alarm data and historical alarm data; determining a false alarm confidence level corresponding to the vibration alarm based on the timing statistical parameters; and determining whether the vibration alarm is a false alarm or a valid alarm based on the false alarm confidence level. Through the technical solution of the present application, the false alarm rate can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of vibration optical fiber sensing, and in particular, to an intrusion detection method, device and equipment based on vibration optical fiber. Background Art

[0002] Ordinary optical fiber realizes optical signal transmission through total internal reflection of light, while vibration optical fiber realizes optical signal transmission through minute vibrations inside the optical fiber. Vibration optical fiber (such as distributed vibration optical fiber) is an intelligent sensing technology that uses the optical fiber as both a sensor and a transmission channel at the same time. Vibration optical fiber works based on the principle of optical time domain reflectometry, and realizes full-course vibration monitoring by analyzing the scattering characteristics of optical signals. Vibration optical fiber can be used to measure signals such as temperature, pressure, acceleration, vibration, etc., and has the characteristics of high sensitivity, strong anti-interference ability, high reliability, etc. Vibration optical fiber has been widely used in various fields.

[0003] With its advantages such as distributed sensing and high-precision positioning, vibration optical fiber shows great application potential in the security field. For example, vibration optical fiber can be deployed on the perimeter wall of the park scene. If someone passes through the vibration optical fiber into the park, the vibration optical fiber can sense the vibration caused by the person, and then issue a vibration alarm, and the vibration alarm is used to inform that someone has passed through the vibration optical fiber into the park.

[0004] However, when issuing a vibration alarm based on the vibration sensed by the vibration optical fiber, it is easily affected by environmental interference. Environments such as rain and passing trains will cause the vibration optical fiber to sense vibration and then issue a false vibration alarm, that is, there is a problem of alarm error, resulting in a high false alarm rate. Summary of the Invention

[0005] This application provides an intrusion detection method based on vibration optical fiber, which is applied to the management device of vibration optical fiber. The vibration optical fiber includes a plurality of optical fiber units. The method includes:

[0006] When a target optical fiber unit triggers a vibration alarm, obtain timing statistical parameters based on the target alarm data of the target optical fiber unit. The target optical fiber unit is any optical fiber unit, and the timing statistical parameters include at least one of an immediacy parameter, a correlation parameter, and a historicity parameter; wherein, the immediacy parameter represents multi-dimensional parameters of the target alarm data, the correlation parameter represents the correlation parameter between the target alarm data and the alarms in adjacent areas, and the historicity parameter represents the correlation parameter between the target alarm data and the historical alarm data;

[0007] Determine the false alarm confidence level corresponding to the vibration alarm based on the timing statistical parameters;

[0008] Determine whether the vibration alarm is a false alarm or a valid alarm based on the false alarm confidence level.

[0009] The present application provides an intrusion detection device based on a vibrating optical fiber, which is applied to a management device of the vibrating optical fiber. The vibrating optical fiber includes a plurality of optical fiber units. The device includes:

[0010] An acquisition module, configured to obtain a timing statistical parameter based on target alarm data of a target optical fiber unit when the target optical fiber unit triggers a vibration alarm. The target optical fiber unit is any one of the plurality of optical fiber units. The timing statistical parameter includes at least one of an immediacy parameter, a correlation parameter, and a historicity parameter. Among them, the immediacy parameter represents a multi-dimensional parameter of the target alarm data, the correlation parameter represents a correlation parameter between the target alarm data and an alarm in an adjacent area, and the historicity parameter represents a correlation parameter between the target alarm data and historical alarm data.

[0011] A determination module, configured to determine a false alarm confidence level corresponding to the vibration alarm based on the timing statistical parameter.

[0012] A decision module, configured to determine whether the vibration alarm is a false alarm or a valid alarm based on the false alarm confidence level.

[0013] The present application provides an electronic device, including: a processor and a machine-readable storage medium. The machine-readable storage medium stores machine-executable instructions that can be executed by the processor. The processor is configured to execute the machine-executable instructions to implement the above-mentioned intrusion detection method based on a vibrating optical fiber.

[0014] The present application provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, it implements the above-mentioned intrusion detection method based on a vibrating optical fiber.

[0015] The present application provides a machine-readable storage medium, which stores machine-executable instructions that can be executed by a processor. Among them, the processor is configured to execute the machine-executable instructions to implement the above-mentioned intrusion detection method based on a vibrating optical fiber in the example.

[0016] As can be seen from the above technical solutions, in the embodiments of the present application, when a target optical fiber unit triggers a vibration alarm, instead of directly issuing the vibration alarm, the false alarm confidence level is determined based on the immediacy parameter, the correlation parameter, and the historicity parameter of the target optical fiber unit, and the vibration alarm is determined as a false alarm or a valid alarm based on the false alarm confidence level. If the vibration alarm is determined as a false alarm, the vibration alarm is not issued, thereby avoiding issuing a false vibration alarm and reducing the false alarm rate. If the vibration alarm is determined as a valid alarm, the vibration alarm is issued, thereby informing that someone has passed by the vibrating optical fiber, and implementing intrusion detection based on the vibrating optical fiber. It can improve the accuracy, stability, and environmental adaptability of vibrating optical fiber intrusion detection, increase the detection rate, and reduce the false alarm rate. Brief Description of the Drawings

[0017] Figure 1A is a flowchart of an intrusion detection method based on vibration optical fiber in an embodiment of the present application;

[0018] Figure 1B is a flowchart of an intrusion detection method based on vibration optical fiber in an embodiment of the present application;

[0019] Figure 1C is a flowchart of an intrusion detection method based on vibration optical fiber in an embodiment of the present application;

[0020] Figure 2 is a schematic structural diagram of a vibration optical fiber intrusion detection system in an embodiment of the present application;

[0021] Figure 3 is a schematic structural diagram of a feature extraction process in an embodiment of the present application;

[0022] Figure 4 is a schematic diagram of converting DSP parameters into a color grid image in an embodiment of the present application;

[0023] Figure 5A is a schematic diagram of time frame processing in an embodiment of the present application;

[0024] Figure 5B is a schematic diagram of parameter extraction in an embodiment of the present application;

[0025] Figure 5C is a schematic diagram of matrix organization in an embodiment of the present application;

[0026] Figure 5D is a schematic diagram of grid division in an embodiment of the present application;

[0027] Figure 5E is a schematic diagram of a grid image in an embodiment of the present application;

[0028] Figure 5F is a schematic diagram of a color grid image of a ladder climbing scenario in an embodiment of the present application;

[0029] Figure 5G is a schematic diagram of a color grid image of a vehicle passing scenario in an embodiment of the present application;

[0030] Figure 5H is a schematic diagram of a color grid image of a heavy rain scenario in an embodiment of the present application;

[0031] Figure 6A is a schematic diagram of multi-source heterogeneous data or multi-modal data fusion in an embodiment of the present application;

[0032] Figure 6B It is a schematic diagram of the network structure of an anomaly detection model in an embodiment of the present application;

[0033] Figure 6C It is a schematic diagram of the network structure of an anomaly detection model in an embodiment of the present application;

[0034] Figure 6D It is a schematic diagram of feature alignment in an embodiment of the present application;

[0035] Figure 7 It is a schematic diagram of the false alarm determination process in an embodiment of the present application;

[0036] Figure 8A It is a schematic diagram of the progressive suppression process in an embodiment of the present application;

[0037] Figure 8B It is a schematic diagram of the structure of the result fusion decision maker in an embodiment of the present application;

[0038] Figure 9A It is a structural diagram of an intrusion detection device based on vibrating optical fiber in an embodiment of the present application;

[0039] Figure 9B It is a hardware structural diagram of an electronic device in an embodiment of the present application. Specific embodiments

[0040] In an embodiment of the present application, an intrusion detection method based on vibrating optical fiber is proposed, which is applied to a management device of vibrating optical fiber. The vibrating optical fiber (such as a distributed vibrating optical fiber) may include multiple fiber units. Refer to Figure 1A As shown, it is a schematic flowchart of the intrusion detection method based on vibrating optical fiber. The method may include:

[0041] Step 111: When a vibration alarm is triggered in a target fiber unit, obtain time-series statistical parameters based on the target alarm data of the target fiber unit. The target fiber unit may be any fiber unit, and the time-series statistical parameters include at least one of an immediacy parameter, a correlation parameter, and a historical parameter. Among them, the immediacy parameter represents multi-dimensional parameters of the target alarm data, the correlation parameter represents the correlation parameter between the target alarm data and the alarms in adjacent areas, and the historical parameter represents the correlation parameter between the target alarm data and historical alarm data.

[0042] Step 112: Determine the false alarm confidence level corresponding to the vibration alarm based on the time-series statistical parameters.

[0043] Step 113: Determine whether the vibration alarm is a false alarm or a valid alarm based on the false alarm confidence level.

[0044] For example, if the false alarm confidence level is not less than a threshold value (which can be configured according to experience), the vibration alarm can be determined as a false alarm, that is, the vibration alarm is an incorrect alarm result and does not need to trigger the vibration alarm. Or, if the false alarm confidence level is less than the threshold value, the vibration alarm can be determined as a valid alarm, that is, the vibration alarm is a correct alarm result and needs to trigger the vibration alarm.

[0045] As can be seen from the above technical solution, in the embodiment of the present application, when a vibration alarm is triggered by a target optical fiber unit, instead of directly sending out the vibration alarm, the false alarm confidence level is determined based on the instantaneous parameters, correlation parameters, and historical parameters of the target optical fiber unit, and the vibration alarm is determined as a false alarm or a valid alarm based on the false alarm confidence level. If the vibration alarm is determined as a false alarm, the vibration alarm is not sent out, thereby avoiding sending out incorrect vibration alarms and reducing the false alarm rate. If the vibration alarm is determined as a valid alarm, the vibration alarm is sent out, thereby informing that someone has passed by the vibrating optical fiber, realizing intrusion detection based on the vibrating optical fiber. It can improve the accuracy, stability, and environmental adaptability of vibrating optical fiber intrusion detection, increase the detection rate, and reduce the false alarm rate.

[0046] In the embodiment of the present application, an intrusion detection method based on a vibrating optical fiber is proposed, which is applied to a management device of the vibrating optical fiber. The vibrating optical fiber (such as a distributed vibrating optical fiber) can include multiple optical fiber units. Refer to Figure 1B As shown, it is a flow schematic diagram of an intrusion detection method based on a vibrating optical fiber. The method can include:

[0047] Step 121, when a vibration alarm is triggered by a target optical fiber unit, obtain the phase data and power spectrum data corresponding to the target optical fiber unit. The target optical fiber unit can be any optical fiber unit.

[0048] Step 122, determine a Mel spectrogram based on the phase data, determine a waterfall plot based on the power spectrum data, obtain DSP parameters based on the phase data and power spectrum data, and convert the DSP parameters into a color grid image.

[0049] Step 123, splice the Mel spectrogram, the waterfall plot, and the color grid image in the channel dimension to obtain a spliced image; input the spliced image into an anomaly detection model to obtain an initial anomaly score.

[0050] Step 124, determine the vibration alarm as a false alarm or a valid alarm based on the initial anomaly score.

[0051] For example, if the initial anomaly score is not greater than a threshold value (which can be configured based on experience), the vibration alarm can be determined as a false alarm, that is, the vibration alarm is an incorrect alarm result and does not need to trigger the vibration alarm. Or, if the initial anomaly score is greater than the threshold value, the vibration alarm can be determined as a valid alarm, that is, the vibration alarm is a correct alarm result and needs to trigger the vibration alarm.

[0052] As can be seen from the above technical solutions, in the embodiments of the present application, when a vibration alarm is triggered by a target optical fiber unit, instead of directly issuing a vibration alarm, the Mel spectrogram, the waterfall plot, and the color grid image are spliced in the channel dimension to obtain a spliced image, and the spliced image is input into an anomaly detection model to obtain an initial anomaly score. Then, based on the initial anomaly score, the vibration alarm is determined as a false alarm or a valid alarm. If the vibration alarm is determined as a false alarm, the vibration alarm is not issued, thus avoiding issuing incorrect vibration alarms and reducing the false alarm rate. If the vibration alarm is determined as a valid alarm, the vibration alarm is issued, thus informing that someone has passed by the vibrating optical fiber, realizing intrusion detection based on the vibrating optical fiber. It can improve the accuracy, stability, and environmental adaptability of vibrating optical fiber intrusion detection, improve the detection rate, and reduce the false alarm rate.

[0053] In the embodiments of the present application, an intrusion detection method based on a vibrating optical fiber is proposed, which is applied to a management device of the vibrating optical fiber. The vibrating optical fiber (such as a distributed vibrating optical fiber) can include multiple optical fiber units. Refer to Figure 1C As shown, it is a schematic flowchart of an intrusion detection method based on a vibrating optical fiber. The method can include:

[0054] Step 131: When a vibration alarm is triggered by a target optical fiber unit, obtain timing statistical parameters based on the target alarm data of the target optical fiber unit. The target optical fiber unit can be any optical fiber unit, and the timing statistical parameters include at least one of an immediacy parameter, a correlation parameter, and a historical parameter. Among them, the immediacy parameter represents multi-dimensional parameters of the target alarm data, the correlation parameter represents the correlation parameter between the target alarm data and the alarms in adjacent areas, and the historical parameter represents the correlation parameter between the target alarm data and historical alarm data.

[0055] Step 132: Determine the false alarm confidence level corresponding to the vibration alarm based on the timing statistical parameters.

[0056] Step 133: Obtain the phase data and power spectrum data corresponding to the target optical fiber unit, determine the Mel spectrogram based on the phase data, determine the waterfall plot based on the power spectrum data, obtain DSP parameters based on the phase data and the power spectrum data, and convert the DSP parameters into a color grid image.

[0057] Step 134: Concatenate the Mel spectrogram, waterfall plot, and color grid image along the channel dimension to obtain a concatenated image; input the concatenated image into the anomaly detection model to obtain an initial anomaly score.

[0058] Step 135: Determine a target anomaly score based on the false alarm confidence and the initial anomaly score, and determine whether the vibration alarm is a false alarm or a valid alarm based on the target anomaly score.

[0059] For example, if the target anomaly score is not greater than a threshold (which can be configured according to experience), the vibration alarm can be determined as a false alarm, that is, the vibration alarm is an incorrect alarm result and does not need to trigger the vibration alarm. Or, if the target anomaly score is greater than the threshold, the vibration alarm can be determined as a valid alarm, that is, the vibration alarm is a correct alarm result and needs to trigger the vibration alarm.

[0060] As can be seen from the above technical solutions, in the embodiments of the present application, when a vibration alarm is triggered by a target optical fiber unit, instead of directly issuing the vibration alarm, the false alarm confidence is determined based on the instantaneous parameters, correlation parameters, and historical parameters of the target optical fiber unit, and an initial anomaly score is obtained based on the Mel spectrogram, waterfall plot, and color grid image. The target anomaly score is determined based on the false alarm confidence and the initial anomaly score, and then the vibration alarm is determined as a false alarm or a valid alarm based on the target anomaly score. If the vibration alarm is determined as a false alarm, the vibration alarm is not issued, thus avoiding issuing incorrect vibration alarms and reducing the false alarm rate. If the vibration alarm is determined as a valid alarm, the vibration alarm is issued, thus informing that someone has passed by the vibrating optical fiber, realizing intrusion detection based on the vibrating optical fiber. It can improve the accuracy, stability, and environmental adaptability of vibrating optical fiber intrusion detection, can improve the detection rate, and reduce the false alarm rate.

[0061] Exemplarily, the instantaneous parameters may include at least one of the signal dimension matching degree, the environmental correlation dimension matching degree, and the spatio-temporal consistency dimension matching degree. Among them, the process of obtaining the signal dimension matching degree may include, but is not limited to: extracting features from the target alarm data to obtain the current signal features; determining the first similarity between the current signal features and the sample signal features, and determining the signal dimension matching degree based on the first similarity; where the sample signal features are obtained by extracting features from the alarm data in a non-intrusion scenario.

[0062] The process of obtaining the matching degree of the environmental correlation dimension may include, but is not limited to: if the target alarm data includes the target environmental data corresponding to the target optical fiber unit, feature extraction is performed on the target environmental data to obtain the current environmental features; determining the second similarity between the current environmental features and the sample environmental features, and determining the matching degree of the environmental correlation dimension based on the second similarity; the sample environmental features are obtained by performing feature extraction on the environmental data in a non-intrusion scenario. The process of obtaining the matching degree of the spatio-temporal consistency dimension may include, but is not limited to: if the target alarm data includes the target alarm time and the target alarm location, determining the first false alarm probability corresponding to the target alarm time, determining the second false alarm probability corresponding to the target alarm location, and performing a weighted operation on the first false alarm probability and the second false alarm probability to obtain the matching degree of the spatio-temporal consistency dimension; multiple times in the time dimension respectively correspond to false alarm probabilities, and multiple locations in the space dimension respectively correspond to false alarm probabilities.

[0063] Exemplarily, the process of obtaining the correlation parameter may include, but is not limited to: determining multiple associated optical fiber units corresponding to the target optical fiber unit, the distance between each associated optical fiber unit and the target optical fiber unit is less than the distance threshold, and each associated optical fiber unit triggers a vibration alarm; if the target alarm data includes the vibration intensity of the target optical fiber unit, based on the vibration intensity of the target optical fiber unit, the vibration intensity of each associated optical fiber unit, the distance attenuation coefficient corresponding to each associated optical fiber unit, and the total number of associated optical fiber units, determining the correlation parameter. Among them, for each associated optical fiber unit, the distance attenuation coefficient may be determined based on the linear attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit, or the distance attenuation coefficient may be determined based on the exponential attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit.

[0064] Exemplarily, the historical parameter may include at least one of the time pattern matching degree, the space pattern matching degree, and the environmental pattern matching degree. Among them, the process of obtaining the time pattern matching degree may include, but is not limited to: if the target alarm data includes the target alarm time, determining the first statistical feature of the target alarm time and the second statistical feature of the historical false alarm time based on the target alarm data and the historical alarm data, and determining the time pattern matching degree based on the first statistical feature and the second statistical feature; where the historical false alarm time is the alarm time indicating the existence of vibration alarm false alarms in the historical alarm data.

[0065] The process of obtaining the spatial pattern matching degree may include, but is not limited to: If the target alarm data includes the target alarm location, determining the target alarm location and multiple historical false alarm locations based on the target alarm data and historical alarm data, where each historical false alarm location is an alarm location indicating a false alarm of vibration alarm in the historical alarm data; determining the spatial pattern matching degree based on the spatial overlap degree between the target alarm location and each historical false alarm location. The process of obtaining the environmental pattern matching degree may include, but is not limited to: If the target alarm data includes the target environmental data, determining the current environmental characteristics and historical false alarm environmental characteristics corresponding to the target environmental data based on the target alarm data and historical alarm data, where the historical false alarm environmental characteristics are the environmental characteristics indicating a false alarm of vibration alarm in the historical alarm data; determining the environmental pattern matching degree based on the current environmental characteristics and historical false alarm environmental characteristics.

[0066] Exemplarily, determining the false alarm confidence level corresponding to the vibration alarm based on the time series statistical parameters may include, but is not limited to: determining a comprehensive false alarm score based on the time series statistical parameters; where, if the time series statistical parameters include an immediacy parameter, a relevance parameter, and a historicity parameter, performing a weighted operation on the immediacy score, the relevance score, and the historicity score to obtain the comprehensive false alarm score; where, if the immediacy parameter includes a signal dimension matching degree, an environmental relevance dimension matching degree, and a spatio-temporal consistency dimension matching degree, performing a weighted operation on the signal dimension matching degree, the environmental relevance dimension matching degree, and the spatio-temporal consistency dimension matching degree to obtain the immediacy score; determining the relevance score based on the relevance parameter; if the historicity parameter includes a time pattern matching degree, a spatial pattern matching degree, and an environmental pattern matching degree, performing a weighted operation on the time pattern matching degree, the spatial pattern matching degree, and the environmental pattern matching degree to obtain the historicity score. Then, determining the false alarm confidence level based on the comprehensive false alarm score; where the false alarm confidence level and the comprehensive false alarm score may be directly proportional.

[0067] Exemplarily, the false alarm confidence level may be determined using the following formula: ; where C may represent the false alarm confidence level, λ may represent the configured adjustment coefficient, FS may represent the comprehensive false alarm score, C The value range of C is [0, 1], and the closer it is to 1, the greater the possibility of a false alarm.

[0068] Exemplarily, the DSP parameters may include, but are not limited to, time-energy dimension parameters and / or spatial dimension parameters. The time-energy dimension parameters are used to characterize the features of the signal in the time domain and the energy domain, and the spatial dimension parameters are used to characterize the features of the signal in the spatial domain. For example, the time-energy dimension parameters may include, but are not limited to, at least one of energy feature type parameters, time domain feature type parameters, frequency domain feature type parameters, and morphological feature type parameters; the energy feature type parameters are used to reflect the signal energy level, the time domain feature type parameters are used to reflect the statistics of the signal time domain features, the frequency domain feature type parameters are used to reflect the frequency domain distribution features of the signal, and the morphological feature type parameters are used to reflect the indicators of the signal waveform features. For example, the spatial dimension parameters may include, but are not limited to, at least one of statistical feature type parameters, morphological feature type parameters, and spectral domain feature type parameters; the statistical feature type parameters are used to reflect the statistics of the signal spatial distribution features, the morphological feature type parameters are used to reflect the signal spatial morphological features, and the spectral domain feature type parameters are used to reflect the signal spectral spatial features.

[0069] Exemplarily, converting the DSP parameters into a color grid image may include, but is not limited to: converting the DSP parameters into a parameter matrix, which may include multiple parameter values. Generating a grid image, which may include multiple grids; wherein, the height dimension of the grid may be determined based on the height of the color grid image and the number of horizontal elements of the parameter matrix, and the width dimension of the grid may be determined based on the width of the color grid image and the number of vertical elements of the parameter matrix. For each parameter value in the parameter matrix, determining the grid in the grid image corresponding to the parameter value, normalizing the parameter value to a specified numerical range, and filling the normalized parameter value into the grid; wherein, the multiple parameter values in the parameter matrix correspond to the multiple grids in the grid image one by one. Performing a visualization conversion on the grayscale image to obtain a color grid image; wherein, after filling all the normalized parameter values into the grid image, a grayscale image can be obtained.

[0070] Exemplarily, converting the DSP parameters into a parameter matrix may include, but is not limited to: for each of the continuous N frames, obtaining the DSP parameters of the frame, the DSP parameters of the frame are obtained based on the phase data and power spectrum data of the frame, and the DSP parameters of the frame include m parameter values; taking the m parameter values of each frame as a row of the parameter matrix to obtain the parameter matrix; wherein, the parameter matrix is a matrix with N rows and m columns; or, taking the m parameter values of each frame as a column of the parameter matrix to obtain the parameter matrix; wherein, the parameter matrix is a matrix with N columns and m rows; wherein, N is a positive integer, and m is a positive integer.

[0071] Exemplarily, normalizing the parameter value to a specified numerical range may include, but is not limited to: if the specified numerical range is [0, 255], the following formula may be used to normalize the parameter value to the specified numerical range: ;in, G ij represents the normalized parameter value, P ij Indicates the parameter value. P min represents the minimum parameter value in the parameter matrix, P max Represents the maximum parameter value in the parameter matrix.

[0072] Exemplarily, visually converting a grayscale image to obtain a color grid image may include but is not limited to: using a configured smoothing kernel to smooth the grayscale image to obtain a smoothed grayscale image, and visually converting the smoothed grayscale image to obtain a color grid image.

[0073] Exemplarily, inputting the spliced image into an anomaly detection model to obtain an initial anomaly score may include, but is not limited to: inputting the spliced image into the anomaly detection model to obtain a reconstructed image corresponding to the spliced image, and determining the initial anomaly score based on the difference between the reconstructed image and the spliced image.

[0074] Exemplarily, based on the configured initial detection model, the training process of the anomaly detection model includes, but is not limited to: obtaining a sample mel-spectrogram, a sample waterfall diagram, and a sample color grid image, splicing the sample mel-spectrogram, the sample waterfall diagram, and the sample color grid image in the channel dimension to obtain a sample spliced image; inputting the sample spliced image into the initial detection model to obtain a first sample reconstructed image and a predicted label, and inputting the sample spliced image into the trained classroom detection model corresponding to the initial detection model to obtain a second sample reconstructed image. A reconstruction loss value is determined based on the difference between the first sample reconstructed image and the sample spliced image, a knowledge distillation loss value is determined based on the difference between the first sample reconstructed image and the second sample reconstructed image, and a classification loss value is determined based on the difference between the predicted label and the true label of the sample spliced image. A target loss value is determined based on the reconstruction loss value, the knowledge distillation loss value, and the classification loss value, and the parameters of the initial detection model are adjusted based on the target loss value to obtain an adjusted model. If the adjusted model has converged, the adjusted model is determined as the anomaly detection model; if the adjusted model has not converged, the adjusted model is determined as the initial detection model, and the operation of inputting the sample spliced image into the initial detection model is returned.

[0075] Exemplarily, determining a target anomaly score based on the false alarm confidence and the initial anomaly score may include, but is not limited to: determining a target suppression coefficient based on the false alarm confidence, and adjusting the initial anomaly score based on the target suppression coefficient and a configured dynamic impact factor to obtain the target anomaly score.

[0076] Exemplarily, determining the target suppression coefficient based on the false alarm confidence may include, but is not limited to: determining a first suppression coefficient based on the false alarm confidence, where the first suppression coefficient is proportional to the false alarm confidence; determining a second suppression coefficient based on the first suppression coefficient, the configured time adjustment factor, the configured space adjustment factor, and the configured environment adjustment factor; determining a third suppression coefficient based on the second suppression coefficient and the configured attenuation coefficient; determining a target gain adjustment factor corresponding to the target alarm time of the vibration alarm, and determining the target suppression coefficient based on the third suppression coefficient and the target gain adjustment factor.

[0077] The first suppression coefficient can be determined using the following formula: ; where x can represent the false alarm confidence, T 1, T 2, T 3 represent piecewise thresholds, and satisfy 0 < T 1 < T 2 < T 3 < 1, k 1, k 2, k 3 can represent the slope, S 1 = k 1 × ( T 2 − T 1), S 2 = S 1 + k 2 × ( T 3 − T 2).

[0078] The third suppression coefficient can be determined using the following formula: ; where adjusted_confidence can represent the third suppression coefficient, base_confidence can represent the second suppression coefficient, α can represent the attenuation coefficient, t can represent the time interval.

[0079] Exemplarily, determining the target suppression coefficient based on the third suppression coefficient and the target gain adjustment factor may include, but is not limited to: if the product value between the third suppression coefficient and the target gain adjustment factor is less than a fixed value, then determining the product value as the target suppression coefficient; if the product value is not less than the fixed value, then determining the fixed value as the target suppression coefficient; where, if the target alarm time is within the configured night time interval, the target gain adjustment factor is the first factor value, and if the target alarm time is within the configured day time interval, the target gain adjustment factor is the second factor value, and the first factor value is greater than the second factor value.

[0080] Exemplarily, adjusting the initial anomaly score based on the target suppression coefficient and the configured dynamic influence factor to obtain the target anomaly score may include, but is not limited to: The target anomaly score can be determined using the following formula: final_ score = dl_score×(1−final_confidence)×factor . Wherein, final_score can represent the target anomaly score, dl_score can represent the initial anomaly score, final_confidence can represent the target suppression coefficient, factor can represent the dynamic influence factor. For example, if the initial anomaly score is not greater than the threshold, the dynamic influence factor can be the third factor value; if the initial anomaly score is greater than the threshold, the dynamic influence factor can be the fourth factor value; wherein, the third factor value is less than the fourth factor value.

[0081] The above technical solutions of the embodiments of the present application will be described below in combination with specific application scenarios.

[0082] Vibrating optical fibers (such as distributed vibrating optical fibers) show great application potential in the security field due to their advantages such as distributed sensing and high-precision positioning. For example, vibrating optical fibers can be deployed on the perimeter walls of a park scenario. If a person passes through the vibrating optical fiber into the park, the vibrating optical fiber can sense the vibration caused by the person and then issue a vibration alarm, and the vibration alarm is used to inform that a person has passed through the vibrating optical fiber into the park. However, when issuing a vibration alarm based on the vibration sensed by the vibrating optical fiber, it is easily affected by environmental interference. Environments such as rain and passing trains will cause the vibrating optical fiber to sense vibration and then issue a false vibration alarm, that is, there is a problem of alarm error, resulting in a high false alarm rate.

[0083] In view of the above findings, the embodiments of the present application propose a vibrating optical fiber intrusion detection system and method based on multi-source heterogeneous data fusion, which can integrate four types of complementary heterogeneous data, namely phase data and its Mel spectrogram, power spectrum data and its waterfall diagram, multi-dimensional DSP (Digital Signal Processing) parameters and its color card diagram (color grid image), and alarm data. By constructing a unified data expression method, the deep fusion of structured data and unstructured data is achieved, giving full play to the characteristics of various data sources, significantly improving the reliability and environmental adaptability of the system. Greatly reducing the amount of data required for model training and significantly improving the generalization ability of the system. It can improve the accuracy, stability and environmental adaptability of vibrating optical fiber intrusion detection.

[0084] In the embodiments of the present application, a vibrating optical fiber intrusion detection system based on multi-source heterogeneous data fusion is proposed. Refer to Figure 2 As shown, it is a schematic structural diagram of the vibrating optical fiber intrusion detection system. The vibrating optical fiber intrusion detection system can include a data input layer, a signal processing layer, a feature generation layer and a fusion detection layer.

[0085] At the data input layer, a vibrating optical fiber (which can be a distributed vibrating optical fiber, such as a distributed fiber vibration sensing system) can collect alarm data, phase data, and power spectrum data, and send the alarm data, phase data, and power spectrum data to the management device of the vibrating optical fiber. The management device obtains the alarm data, phase data, and power spectrum data and performs subsequent processing based on the alarm data, phase data, and power spectrum data.

[0086] At the signal processing layer, data processing can be performed based on the alarm data, phase signal processing can be performed based on the phase data, power spectrum processing can be performed based on the power spectrum data, and DSP parameter extraction can be performed based on the phase data and power spectrum data. At the feature generation layer, statistical feature extraction can be performed based on the alarm data, and time-series statistical parameters can be generated. High-pass filtering and short-time Fourier transform can be performed based on the phase data, and a Mel spectrogram can be generated. Power spectrum normalization can be performed based on the power spectrum data, and a waterfall plot can be generated. Normalization and grid mapping transformation can be performed on the DSP parameters, and a color card map can be generated.

[0087] At the fusion detection layer, feature fusion can be performed on the Mel spectrogram, waterfall plot, and color card map to obtain a fused image. Anomaly detection can be performed based on the fused image, and the model result can be output. Multilevel false alarm determination can be performed based on the time-series statistical parameters, and the model result can be adjusted based on a progressive suppressor and a dynamic adjustment factor, and the final result (the result of whether the vibration alarm is a false alarm or a valid alarm) can be output.

[0088] Based on the data input layer, signal processing layer, feature generation layer, and fusion detection layer, through the gradual transfer of the data stream, intrusion detection and alarm output are finally achieved. This hierarchical architecture can ensure the modularity and scalability of the vibrating optical fiber intrusion detection system, and at the same time improve the detection accuracy and reliability.

[0089] Exemplarily, statistical feature extraction can be performed based on the alarm data to obtain time-series statistical parameters. A Mel spectrogram can be generated based on the phase data, a waterfall plot can be generated based on the power spectrum data, and feature extraction can be performed based on the phase data and power spectrum data to obtain DSP parameters. For example, as shown in Figure 3 As shown, it is a schematic structural diagram of the feature extraction process. In the feature extraction process, a multi-dimensional feature extraction function can be implemented to extract rich multi-dimensional features from the alarm data and real-time vibration signals (such as phase data and power spectrum data), providing a data basis for subsequent event recognition and decision-making.

[0090] The input data of the feature extraction process may include alarm data, phase data, and power spectrum data. Based on the alarm data, statistical feature extraction can be performed to obtain time series statistical parameters, which may include at least one of an immediacy parameter, a correlation parameter, and a historic parameter, and the immediacy parameter, the correlation parameter, and the historic parameter are output. Based on the phase data, a Mel spectrogram can be generated and the Mel spectrogram is output. Based on the power spectrum data, a waterfall plot can be generated and the waterfall plot is output. Based on the phase data and the power spectrum data, spatial dimension feature extraction and time energy dimension feature extraction can be performed to obtain DSP parameters, and the DSP parameters are output. The processing process of feature extraction is described below in conjunction with the following steps.

[0091] Step S11: When a vibration alarm is triggered in a target optical fiber unit, obtain the phase data and power spectrum data corresponding to the target optical fiber unit. The target optical fiber unit may be any optical fiber unit of the vibration optical fiber.

[0092] For example, when a certain optical fiber unit of the vibration optical fiber triggers a vibration alarm, use this optical fiber unit as the target optical fiber unit and perform an intrusion detection method for the target optical fiber unit. Or, when multiple optical fiber units of the vibration optical fiber trigger vibration alarms, use each optical fiber unit that triggers the vibration alarm as the target optical fiber unit, and perform an intrusion detection method for each target optical fiber unit respectively. For the convenience of description, in this embodiment, the processing process of one target optical fiber unit is taken as an example to perform an intrusion detection method for the target optical fiber unit.

[0093] When a vibration alarm is triggered in the target optical fiber unit, obtain the phase data corresponding to the target optical fiber unit. The phase data is used to describe the vibration situation. For example, the phase data may include a phase angle, a vibration amplitude, and a frequency, etc. The phase angle represents the offset situation of the vibration waveform, the vibration amplitude represents the intensity of the vibration, which can be represented by displacement, velocity, or acceleration, and the frequency represents the periodic change rate of the vibration, with the unit of hertz (Hz).

[0094] When a vibration alarm is triggered in the target optical fiber unit, obtain the power spectrum data (abbreviated as power spectrum) corresponding to the target optical fiber unit. The power spectrum is the abbreviation of power spectral density, which is defined as the signal power within a unit frequency band. The power spectrum represents the variation of the signal power with frequency, that is, the distribution of the signal power in the frequency domain.

[0095] Step S12: Generate a Mel spectrogram based on the phase data. The Mel spectrogram may be a frequency domain feature, that is, obtain more detailed three-dimensional features of time, frequency, and energy based on the phase data at the alarm moment, and the three-dimensional features can be characterized by the Mel spectrogram. The generation method of this Mel spectrogram is not limited.

[0096] Of course, in addition to the Mel spectrogram, other types of spectrograms can also be generated based on the phase data, that is, a spectrogram is generated based on the phase data. In this embodiment, the Mel spectrogram is taken as an example of the spectrogram.

[0097] Step S13: Determine a waterfall plot based on the power spectrum data. The waterfall plot can be a spatio-temporal feature, that is, the joint features of time, space, and energy are obtained based on the power spectrum data (spatial power spectrum) at the alarm moment, and the joint features can be characterized by the waterfall plot. The generation method of this waterfall plot is not limited.

[0098] Step S14: Obtain DSP parameters based on the phase data and the power spectrum data.

[0099] Exemplarily, the DSP parameters are multi-dimensional and scalable signal features. Any type of parameter can be used as the DSP parameter. For example, DSP parameters are constructed based on feature significance, computational efficiency, and complementarity. By carefully selecting and combining various DSP parameters, a comprehensive characterization of the distributed fiber optic vibration signal is achieved.

[0100] Exemplarily, in order to ensure that the generated color card diagram can effectively and comprehensively reflect the characteristics of the distributed fiber optic vibration signal, the selection of DSP parameters can follow the following principles: the principle of feature significance, select DSP parameters that can effectively reflect signal characteristics, have good discrimination ability, and are stable. The principle of computational efficiency: preferentially select DSP parameters with low computational complexity, less resource occupancy, and easy implementation. The principle of complementarity: ensure that the DSP parameters can describe signal characteristics from different dimensions and form a complementary synergistic effect.

[0101] For example, the DSP parameters can include but are not limited to: time-energy dimension parameters and / or space dimension parameters. The type of DSP parameters is not limited. Among them, the time-energy dimension parameters are used to characterize the characteristics of the signal in the time domain and the energy domain, and the space dimension parameters are used to characterize the characteristics of the signal in the space domain.

[0102] For example, the time-energy dimension parameters can include but are not limited to at least one of the following:

[0103] Energy feature type parameters. Energy feature type parameters are used to reflect the signal energy level, that is, parameters that reflect the signal energy level are selected as DSP parameters. This type of parameters includes various energy ratio indicators. For example, the energy feature type parameters can include the root mean square value (RMS) and the absolute peak value (Absolute Peak), etc. The root mean square value can be determined based on the phase data at multiple moments, and the absolute peak value can be determined based on the phase data and the power spectrum data. The determination process of this type of energy feature parameters is not limited in this embodiment.

[0104] Time-domain feature class parameters are statistics used to reflect the time-domain characteristics of a signal. That is, various statistics that reflect the time-domain characteristics of the signal are selected as DSP parameters, and these parameters can characterize the frequency of signal changes. For example, time-domain feature class parameters can include the zero crossing rate, etc. The zero crossing rate can be determined based on phase data at multiple moments, and there is no restriction on this determination process.

[0105] Frequency-domain feature class parameters are used to reflect the frequency-domain distribution characteristics of a signal. That is, parameters that reflect the frequency-domain distribution characteristics of the signal are selected as DSP parameters, and these parameters can characterize the signal complexity. For example, frequency-domain feature class parameters can include spectral entropy, band energy ratio, etc. The spectral entropy can be determined based on phase data at multiple moments, and the band energy ratio can be determined based on phase data at multiple moments. There is no restriction on the determination process of these frequency-domain feature class parameters.

[0106] Morphological feature class parameters are indicators used to reflect the waveform characteristics of a signal. That is, various indicators that describe the waveform characteristics of the signal are selected as DSP parameters, and these parameters can reflect the pulse characteristics of the signal. For example, morphological feature class parameters can include impulse indicator, shape indicator, main impact strength, etc. The impulse indicator, shape indicator, and main impact strength can all be determined based on phase data at multiple moments, and there is no restriction on this.

[0107] For example, the spatial dimension parameters can include, but are not limited to, at least one of the following:

[0108] Statistical feature class parameters are statistics used to reflect the spatial distribution characteristics of a signal. That is, various statistics that describe the spatial distribution characteristics of the signal are selected as DSP parameters, and these parameters reflect the spatial aggregation degree of the signal. For example, statistical feature class parameters can include kurtosis, frame mean, etc. The kurtosis and frame mean can be determined based on power spectrum data at multiple moments, and there is no restriction on this.

[0109] Morphological feature class parameters are used to reflect the spatial morphological characteristics of a signal. That is, parameters that describe the spatial morphological characteristics of the signal are selected as DSP parameters, and these parameters reflect various indicators of the spatial continuity of the signal. For example, morphological feature class parameters can include the maximum connected area, and the maximum connected area can be determined based on power spectrum data at multiple moments.

[0110] Spectral domain feature class parameters are used to reflect the spectral space characteristics of a signal. That is, parameters describing the spectral space characteristics of the signal are selected as DSP parameters, and these parameters reflect various statistics of the spectral distribution characteristics. For example, spectral domain feature class parameters can include the power spectral standard deviation (PSD Standard Deviation), which can be determined based on power spectral data at multiple moments.

[0111] Of course, the above are just a few examples of DSP parameters, and there are no restrictions on these DSP parameters.

[0112] Step S15: When a vibration alarm is triggered in the target optical fiber unit, obtain the target alarm data corresponding to the target optical fiber unit. For the convenience of distinction, the alarm data of the target optical fiber unit is called target alarm data.

[0113] For example, the target alarm data can include but is not limited to target environment data, target alarm time, target alarm location, and vibration intensity. Of course, the above are just a few examples, and there are no restrictions on the target alarm data. The target environment data can represent the surrounding environment information of the target optical fiber unit, such as meteorological information (such as wind speed, precipitation, etc.), surrounding activity information (such as vehicle passing, train passing, construction vibration, animal activity, etc.), and there are no restrictions on the content of the target environment data. The target alarm time can represent the time when the target optical fiber unit triggers a vibration alarm, that is, a vibration alarm is triggered at the target alarm time. The target alarm location can represent the vibration location sensed when the target optical fiber unit triggers a vibration alarm, which can be the location of the target optical fiber unit itself (such as longitude and latitude coordinates, etc.), that is, there is a large vibration at the target alarm location. The vibration intensity can be the vibration intensity value sensed by the target optical fiber unit, which can reflect the vibration energy.

[0114] After obtaining the target alarm data, timing statistical parameters (i.e., timing statistical features) can be obtained based on the target alarm data. The timing statistical parameters include at least one of an immediacy parameter (i.e., immediacy feature), a correlation parameter (i.e., correlation feature), and a historicity parameter (i.e., historicity feature). Subsequently, taking the immediacy parameter, the correlation parameter, and the historicity parameter as examples, these parameters all belong to the timing statistical parameters.

[0115] Step S16: Obtain an immediacy parameter based on the target alarm data. The immediacy parameter can represent multi-dimensional parameters of the target alarm data. That is to say, the immediacy parameter can represent parameters in multiple dimensions.

[0116] For example, the immediacy parameter can also be called an immediacy feature. By performing multi-dimensional feature analysis on the target alarm data, a feature vector for false alarm determination is constructed, and this feature vector is used as the immediacy parameter, and the immediacy parameter is used to evaluate whether the target alarm data has the characteristics of a false alarm.

[0117] Exemplarily, the real-time parameters may include at least one of a signal dimension matching degree, an environmental correlation dimension matching degree, and a spatio-temporal consistency dimension matching degree. The signal dimension matching degree may also be referred to as a signal feature matching degree. The target alarm data (current signal) can be compared with the sample signal features (i.e., known intrusion signal features) to calculate the matching degree, and this matching degree is used as the signal dimension matching degree. The greater the signal dimension matching degree, the higher the probability of false alarms. The environmental correlation dimension matching degree may also be referred to as an environmental correlation feature. By analyzing the correlation degree between the current environmental factors (such as weather conditions, animal activities, mechanical vibrations, etc.) and the current signal, this correlation degree is used as the environmental correlation dimension matching degree. If the environmental correlation dimension matching degree indicates a high correlation between the current signal and the environmental interference features, the probability of false alarms is higher. The spatio-temporal consistency dimension matching degree may also be referred to as a spatio-temporal consistency feature. The spatio-temporal consistency feature is used to evaluate whether the target alarm time and the target alarm location conform to the normal intrusion pattern. For example, the credibility of an alarm in an area with few people at night may be higher, while the credibility of an alarm in an area with a large number of people during the day may be lower.

[0118] In a possible implementation manner, the signal dimension matching degree can be obtained based on signal pattern recognition technology. For example, an intrusion signal feature library can be pre-constructed. The intrusion signal feature library can store multiple sample signal features, and each sample signal feature is obtained by extracting features from the alarm data in a non-intrusion scenario. For example, for non-intrusion scenario 1 (such as a rainy day scenario), the alarm data corresponding to the optical fiber unit can be obtained, such as environmental data, alarm time, alarm location, and vibration intensity, etc. The sample signal feature 1 is obtained by extracting features from this alarm data and stored in the intrusion signal feature library. For non-intrusion scenario 2 (such as a construction vibration scenario), the alarm data corresponding to the optical fiber unit can be obtained, and the sample signal feature 2 is obtained by extracting features from this alarm data and stored in the intrusion signal feature library. And so on, multiple sample signal features of non-intrusion scenarios are stored in the intrusion signal feature library.

[0119] In step S16, after obtaining the target alarm data, the features of the target alarm data can be extracted to obtain the current signal features. Then, the similarity between the current signal features and each sample signal feature is calculated. Based on the similarity between the current signal features and each sample signal feature, the maximum similarity can be used as the first similarity, and then the signal dimension matching degree is determined based on the first similarity.

[0120] For example, when extracting the current signal features from the target alarm data (extracting the sample signal features from the alarm data in a non-intrusion scenario), the current signal features can be at least one of the time-domain waveform features, frequency-domain energy distribution features, and time-frequency features, that is, the time-domain waveform features, frequency-domain energy distribution features, and time-frequency features are extracted as the current signal features, and there is no restriction on this.

[0121] For example, when calculating the similarity between the current signal features and the sample signal features, the Euclidean distance or cosine similarity can be calculated. When calculating the Euclidean distance, if the Euclidean distance is smaller, it means the similarity is greater. When calculating the cosine similarity, the greater the cosine similarity, the greater the similarity.

[0122] For example, the signal dimension matching degree can be determined by the following formula (1). The signal dimension matching degree is used to characterize the matching degree between the current signal features and the sample signal features. Of course, formula (1) is just an example.

[0123] Formula (1)

[0124] In formula (1), F 1 represents the signal dimension matching degree, S current represents the current signal features, S tcmplate represents the sample signal features, dist(⋅) represents the distance calculation function, such as calculating the Euclidean distance between the current signal features and the sample signal features. This Euclidean distance can be used as the first similarity. Obviously, if the Euclidean distance is smaller (that is, the similarity is greater, and the target alarm data is more similar to the alarm data in the non-intrusion scenario), then F 1 the greater it is, the greater the probability of false alarm. max_dist represents the maximum Euclidean distance, which can be an empirical value. For example, the Euclidean distance between the current signal features and the sample signal features will not exceed max_ dist That's it.

[0125] In a possible implementation, the extraction of the environmental correlation dimension matching degree focuses on capturing the impact of environmental factors on the signal. For example, an environmental information feature library can be pre-constructed, which can store multiple sample environmental features, and each sample environmental feature is obtained by extracting features from environmental data in a non-intrusion scenario. For example, for non-intrusion scenario 1 (such as a rainy day scenario), the environmental data corresponding to the fiber optic unit can be obtained, such as meteorological information (such as wind speed, precipitation, etc.), surrounding activity information (such as vehicle passing, train passing, construction vibration, animal activity, etc.), and sample environmental feature 1 is obtained by extracting features from this environmental data and stored in the environmental information feature library. For non-intrusion scenario 2 (such as a construction vibration scenario), the environmental data corresponding to the fiber optic unit can be obtained, sample environmental feature 2 is obtained by extracting features from this environmental data and stored in the environmental information feature library. And so on, sample environmental features of multiple non-intrusion scenarios are stored in the environmental information feature library.

[0126] In step S16, after obtaining the target alarm data, the target alarm data includes the target environmental data (such as meteorological information, surrounding activity information) corresponding to the target fiber optic unit, and the current environmental feature is obtained by extracting features from the target environmental data. Then, the similarity between the current environmental feature and each sample environmental feature is calculated, and based on the similarity between the current environmental feature and each sample environmental feature, the maximum similarity can be used as the second similarity, and then the environmental correlation dimension matching degree is determined based on the second similarity.

[0127] For example, when the current environmental feature is obtained by extracting features from the target environmental data, the current environmental feature is at least one of a time-domain waveform feature, a frequency-domain energy distribution feature, and a time-frequency feature. When calculating the similarity between the current environmental feature and the sample environmental feature, the Euclidean distance or cosine similarity can be calculated.

[0128] For example, the following formula (2) can be used to determine the environmental correlation dimension matching degree. Of course, formula (2) is just an example, and the calculation method of this environmental correlation dimension matching degree is not limited.

[0129] Formula (2)

[0130] In formula (2), F 2 represents the environmental correlation dimension matching degree, S signal represents the current environmental feature, S env represents the sample environmental feature, corr(⋅)Denote the correlation coefficient calculation function, such as calculating the cosine similarity between the current environmental characteristics and the sample environmental characteristics, and this cosine similarity can be used as the second similarity.

[0131] Obviously, if the cosine similarity is larger (that is, the second similarity is larger, and the target environmental data is more similar to the environmental data in the non-intrusion scenario), it means F 2 the larger it is, the greater the possibility of false alarm.

[0132] In a possible implementation, the extraction of the spatio-temporal consistency dimension matching degree comprehensively considers two dimensions of time and space. In the time dimension, a false alarm probability model for different time periods is established based on historical data. This false alarm probability model includes the false alarm probabilities at multiple times in the time dimension, such as the false alarm probability corresponding to time period 1, the false alarm probability corresponding to time period 2, …, and so on. Regarding how to obtain the false alarm probability corresponding to each time period, all vibration alarms in this time period can be selected from historical data, and the number of false alarms in these vibration alarms is counted, and then the false alarm probability of this time period is determined based on the number of false alarms and the total number of vibration alarms.

[0133] In the space dimension, a false alarm probability model for different positions is established based on historical data. This false alarm probability model includes the false alarm probabilities at multiple positions in the space dimension, such as the false alarm probability corresponding to position 1, the false alarm probability corresponding to position 2, …, and so on. Regarding how to obtain the false alarm probability corresponding to each position, all vibration alarms at this position can be selected from historical data, and the number of false alarms in these vibration alarms is counted, and then the false alarm probability of this position is determined based on the number of false alarms and the total number of vibration alarms.

[0134] In step S16, after obtaining the target alarm data, the target alarm data may include the target alarm time and the target alarm position. By querying the false alarm probability model in the time dimension through the time period to which the target alarm time belongs, the first false alarm probability corresponding to the target alarm time is obtained. By querying the false alarm probability model in the space dimension through the target alarm position, the second false alarm probability corresponding to the target alarm position is obtained. Then, a weighted operation is performed on the first false alarm probability and the second false alarm probability to obtain the spatio-temporal consistency dimension matching degree.

[0135] For example, the spatio-temporal consistency dimension matching degree can be determined by the following formula (3). Of course, formula (3) is only an example, and the calculation method of the spatio-temporal consistency dimension matching degree at this time is not limited.

[0136] Formula (3)

[0137] In formula (3), F 3 denotes the spatio-temporal consistency dimension matching degree, P(t)Indicates the target alarm time t The first false alarm probability, which can also be called the time probability score L(x,y) Indicates the target alarm location (x,y) The second false alarm probability, which can also be called the location sensitivity score w 1 and w 2 are weight coefficients

[0138] Obviously, if the first false alarm probability is larger (that is, there are more false alarms for the target alarm time in historical data), it means F 3 is larger and the false alarm possibility is greater. If the second false alarm probability is larger (that is, there are more false alarms for the target alarm location in historical data), it means F 3 is larger and the false alarm possibility is greater

[0139] Based on the above three features, the immediacy feature F = F 1 , F 2 , F 3 can be constructed. The immediacy feature F provides a reliable feature basis for subsequent false alarm determination. During the feature extraction process, attention should be paid to the quality of signal preprocessing, the real-time nature of feature calculation, and the adjustment of model parameters to ensure the effectiveness and accuracy of the features

[0140] Step S17: Obtain the correlation parameter based on the target alarm data. The correlation parameter can represent the correlation parameter between the target alarm data and the alarms in adjacent areas. The correlation parameter is used to evaluate the correlation degree between the target optical fiber unit and the surrounding optical fiber units, providing an important spatial dimension feature for false alarm determination

[0141] For example, the correlation parameter can also be called the correlation feature. By extracting the correlation parameter, alarm events with spatial correlation can be effectively identified, the discrimination ability for real intrusion behaviors can be improved, important spatial dimension information can be provided for the intrusion detection system, and the false alarm determination ability can be effectively enhanced. The extraction of the correlation parameter is a feature extraction method based on spatial correlation analysis. By evaluating the correlation degree between the target optical fiber unit and the surrounding monitoring areas (that is, analyzing the alarm data of the target optical fiber unit and the alarm data of the surrounding monitoring areas to determine whether there is spatial correlation), an important spatial dimension feature is provided for false alarm determination

[0142] In the process of extracting the correlation parameters, the following factors can be considered: The selection of adjacent areas (peripheral monitoring areas) should consider the actual monitoring range and geographical environment characteristics. The parameters of the attenuation model need to be optimized according to the actual application scenario. The normalization of signal strength is meaningful for improving the comparability of features.

[0143] Based on the above factors, in this embodiment, in order to analyze the spatial correlation between the target optical fiber unit and the peripheral monitoring area, it is characterized by the following parameters: vibration intensity ( Ai ), and distance attenuation coefficient ( Di ). Among them, vibration intensity ( Ai ) reflects the alarm signal intensity of the peripheral monitoring area. A higher signal intensity usually indicates that there may be a real intrusion behavior. The distance attenuation coefficient ( Di ) considers the influence of spatial distance on signal propagation, and usually uses an exponential attenuation model or a linear attenuation model to describe the distance attenuation coefficient ( Di ).

[0144] In a possible implementation manner, multiple associated optical fiber units corresponding to the target optical fiber unit can be determined. The distance between each associated optical fiber unit and the target optical fiber unit is less than the distance threshold. In this way, the associated optical fiber units are the optical fiber units in the peripheral monitoring area of the target optical fiber unit. In addition, each associated optical fiber unit triggers a vibration alarm. In this way, the associated optical fiber units are also the optical fiber units that trigger the vibration alarm.

[0145] On this basis, the target alarm data of the target optical fiber unit can be obtained, and the target alarm data includes the vibration intensity of the target optical fiber unit. The alarm data of each associated optical fiber unit can be obtained, and the alarm data includes the vibration intensity of the associated optical fiber unit. Then, based on the vibration intensity of the target optical fiber unit, the vibration intensity of each associated optical fiber unit, the distance attenuation coefficient corresponding to each associated optical fiber unit, and the total number of associated optical fiber units, the correlation parameter can be determined, and the correlation parameter can be a correlation score.

[0146] For example, the correlation parameter can be calculated by using the weighted average method. For example, the correlation parameter is determined by the following formula (4). Of course, formula (4) is just an example, and there is no limitation on this calculation method.

[0147] Formula (4)

[0148] In formula (4), RA represents the correlation parameter (correlation score), N represents the total number of associated optical fiber units, Ai represents the i th vibration intensity of the associated optical fiber unit, DiIndicates the distance attenuation coefficient corresponding to the i th associated optical fiber unit, X indicating the vibration intensity of the target optical fiber unit. The correlation parameter RA reflects the overall correlation degree between the target optical fiber unit and the surrounding area. The higher the correlation parameter RA , the stronger the spatial correlation between the target optical fiber unit and the surrounding area, and the higher the credibility of the alarm.

[0149] Exemplarily, for each associated optical fiber unit, the distance attenuation coefficient corresponding to the associated optical fiber unit can be determined based on the distance between the associated optical fiber unit and the target optical fiber unit. For example, given the longitude and latitude coordinates of the associated optical fiber unit and the longitude and latitude coordinates of the target optical fiber unit, the distance between the two can be obtained.

[0150] For example, the distance attenuation coefficient corresponding to the associated optical fiber unit can be determined based on the linear attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit. For example, the following formula can be used to determine the distance attenuation coefficient corresponding to the i th associated optical fiber unit Di : . For example, di can represent the distance between the associated optical fiber unit and the target optical fiber unit, d max can represent the configured maximum influence distance.

[0151] For example, the distance attenuation coefficient corresponding to the associated optical fiber unit can be determined based on the exponential attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit. For example, the following formula can be used to determine the distance attenuation coefficient corresponding to the i th associated optical fiber unit Di : . For example, di represents the distance between the associated optical fiber unit and the target optical fiber unit, α can represent the attenuation coefficient, which is adjusted according to the actual scenario.

[0152] Step S18, obtaining historical parameters based on the target alarm data. The historical parameters can represent the correlation parameters between the target alarm data and the historical alarm data, that is, the historical parameters are related to the historical alarm data.

[0153] For example, the historical parameters can also be called historical features, and the historical parameters are extracted by a feature extraction method based on historical alarm data analysis. By analyzing the matching degree between the target alarm data and the historical alarm data, features are extracted from three dimensions of time, space, and environment to provide a basis for false alarm determination.

[0154] Exemplarily, the historical parameters may include at least one of a time pattern matching degree, a space pattern matching degree, and an environment pattern matching degree. The time pattern matching degree is used to analyze whether the time point when the current alarm occurs is consistent with the high-occurrence time period of historical false alarms, and to analyze the correlation between the time characteristics of the current alarm and the time distribution law of historical false alarms. The space pattern matching degree is used to analyze whether the location where the current alarm occurs coincides with the high-occurrence areas of historical false alarms, and to analyze the spatial distribution relationship between the location of the current alarm and historical false alarms. The environment pattern matching degree is used to analyze whether the current environmental conditions (such as weather, season) are similar to the environmental conditions when historical false alarms occurred, and to analyze the environmental similarity between the current environmental conditions and when historical false alarms occurred.

[0155] In a possible implementation manner, the target alarm data may include a target alarm time. The first statistical feature of the target alarm time and the second statistical feature of the historical false alarm time are determined based on the target alarm data and the historical alarm data. The historical false alarm time is the alarm time indicating the existence of vibration alarm false alarms in the historical alarm data. The time pattern matching degree is determined based on the first statistical feature and the second statistical feature.

[0156] For example, the time pattern matching degree can be determined using the following formula (5). Of course, formula (5) is only an example, and the calculation method of this time pattern matching degree is not limited in this embodiment.

[0157] Formula (5)

[0158] In formula (5), P T represents the time pattern matching degree, and the time pattern matching degree reflects the coincidence degree between the time point when the current alarm occurs and the high-occurrence period of historical false alarms. T i represents the i th time window of historical false alarms, that is, the historical false alarm time indicating the existence of vibration alarm false alarms in the historical alarm data. N represents the total number of the target alarm time and the historical false alarm time. When i = 1, I represents the second statistical feature of the first historical false alarm time, and so on. When i = (N - 1), I represents the second statistical feature of the (N - 1)th historical false alarm time. When i = N, I represents the first statistical feature of the target alarm time.

[0159] For example, within a statistical period starting from the target alarm time and moving forward, based on the historical alarm data and the target alarm data of this statistical period, determine the statistical characteristics of this statistical period (such as the number of alarms, the number of false alarms, the proportion of false alarms, etc.), and use this statistical characteristic as the first statistical characteristic of the target alarm time.

[0160] For example, multiple historical false alarm times can be determined based on the historical alarm data. For example, the historical alarm data can include multiple alarm times. For each alarm time, if there is a vibration alarm false alarm at this alarm time, then this alarm time can be used as a historical false alarm time; if there is no vibration alarm false alarm at this alarm time, then this alarm time is not used as a historical false alarm time.

[0161] For each historical false alarm time, within a statistical period starting from the historical false alarm time and moving forward (such as one day), based on the historical alarm data of this statistical period, the statistical characteristics of this statistical period can be determined, and this statistical characteristic is used as the second statistical characteristic of this historical false alarm time.

[0162] On this basis, the first statistical characteristic of the target alarm time and the second statistical characteristics of each historical false alarm time can be substituted into formula (5) to obtain the time pattern matching degree. P T .

[0163] In a possible implementation, the target alarm data can include the target alarm location. Based on the target alarm data and the historical alarm data, determine the target alarm location and multiple historical false alarm locations. Each historical false alarm location is the alarm location indicating a vibration alarm false alarm in the historical alarm data. Determine the spatial pattern matching degree based on the spatial overlap degree between the target alarm location and each historical false alarm location.

[0164] For example, the following formula (6) can be used to determine the spatial pattern matching degree. Of course, formula (6) is just an example, and the calculation method of this spatial pattern matching degree is not limited in this embodiment.

[0165] Formula (6)

[0166] In formula (6), P S represents the spatial pattern matching degree. L represents the target alarm location, and the target alarm location can be determined based on the target alarm data. R j represents the j th historical false alarm location, MIndicates the total number of historical false alarm positions, and multiple historical false alarm positions can be determined based on historical alarm data. For example, historical alarm data can include multiple alarm positions. For each alarm position, if there is a false alarm of vibration alarm at this alarm position, this alarm position can be used as a historical false alarm position; if there is no false alarm of vibration alarm at this alarm position, this alarm position will not be used as a historical false alarm position.

[0167] w j Indicates the weight corresponding to the j th historical false alarm position. The weights corresponding to different historical false alarm positions can be different, and the weights corresponding to different historical false alarm positions can also be the same.

[0168] overlap(⋅) represents a spatial overlap degree calculation function, that is, calculating the spatial overlap degree between the target alarm position L and the j th historical false alarm position R j There is no limitation on the calculation method of this spatial overlap degree.

[0169] In a possible implementation manner, the target alarm data includes target environmental data. Based on the target alarm data and historical alarm data, the current environmental characteristics and historical false alarm environmental characteristics corresponding to the target environmental data are determined. The historical false alarm environmental characteristics are the environmental characteristics indicating the existence of false alarms of vibration alarms in the historical alarm data. The environmental mode matching degree is determined based on the current environmental characteristics and the historical false alarm environmental characteristics.

[0170] For example, the environmental mode matching degree can be determined using the following formula (7). Of course, formula (7) is just an example, and there is no limitation on the calculation method of this environmental mode matching degree in this embodiment.

[0171] Formula (7)

[0172] In formula (7), P E represents the environmental mode matching degree. σ is a scale parameter, which can be configured according to experience and there is no limitation on this scale parameter for now. In addition, E current represents the current environmental characteristics corresponding to the target environmental data. The current environmental characteristics can be obtained by extracting the characteristics of the target environmental data in the target alarm data. The current environmental characteristics are at least one of time-domain waveform characteristics, frequency-domain energy distribution characteristics, and time-frequency characteristics. In addition, E histRepresents the historical false alarm environment characteristics, which can be determined based on historical alarm data. For example, the historical alarm data can include multiple historical vibration alarms. For each historical vibration alarm, if there is a false alarm in the vibration alarm, the environmental data corresponding to the historical vibration alarm is subjected to feature extraction to obtain the false alarm environment characteristics. When multiple false alarm environment characteristics are obtained, any one of the false alarm environment characteristics can be used as the historical false alarm environment characteristics E hist , or operations can be performed on multiple false alarm environment characteristics (such as weighted operations, average value operations, etc.) to obtain the historical false alarm environment characteristics E hist .

[0173] Historical features can be constructed through the above three features. By extracting historical features, the regular information in historical alarm data can be effectively utilized, improving the accuracy and reliability of false alarm determination. During the feature extraction process, attention needs to be paid to the update and maintenance of historical alarm data, the real-time nature of feature calculation, and the adjustment of model parameters to ensure the effectiveness and accuracy of the features and the continuous improvement of system performance

[0174] So far, the feature extraction process is completed, and a Mel spectrogram, a waterfall plot, DSP parameters, timeliness parameters, correlation parameters, and historical parameters can be obtained. Among them, the timeliness parameters can include signal dimension matching degree, environmental correlation dimension matching degree, and spatio-temporal consistency dimension matching degree. The historical parameters can include time pattern matching degree, space pattern matching degree, and environmental pattern matching degree

[0175] In one possible implementation, as shown in Figure 2 , after obtaining the DSP parameters, the DSP parameters can be converted into a color grid image, which can also be called a color card diagram. For example, the DSP parameters are converted into a color grid image using the parameter color carding method. The parameter color carding method is a data visualization method that converts multi-dimensional DSP parameters into a color grid image, achieving unified expression of heterogeneous data and being able to convert complex multi-dimensional DSP parameters into intuitive color grid images. For example, as shown in Figure 4 , is a schematic diagram of converting DSP parameters into a color grid image, and this process can include

[0176] Step 401: Convert the DSP parameters into a parameter matrix, and the parameter matrix includes multiple parameter values

[0177] Exemplarily, the construction of the parameter matrix is a basic step in parameter color carding, which may include processes such as time frame processing, parameter extraction, and matrix organization. Through the construction of the parameter matrix, one-dimensional signal data (DSP parameters) can be converted into a two-dimensional parameter matrix, providing a structured data basis for subsequent visualization. For example, when converting DSP parameters into a parameter matrix, the following steps can be adopted:

[0178] Step S21, time frame processing. The purpose of time frame processing is to segment continuous signal data according to the time dimension to capture the characteristic changes of the signal in different time periods. The frame division strategy of time frame processing is to select appropriate frame lengths and frame shifts according to the sampling rate and characteristic change frequency of the signal. For example, the entire signal is divided into a fixed number of frames to ensure the uniformity of time resolution. In addition, by providing a flexible parameter setting interface, dynamic adjustment of the frame length and frame shift is supported to adapt to different types of signal characteristics. To maintain the continuous expression of signal characteristics, a certain overlap between frames can be selected.

[0179] During the time frame processing, the total number of frames N (i.e., the frame length) can be determined. The total number of frames N indicates that the DSP parameters of N frames need to form a parameter matrix, and the total number of frames N can be configured according to experience.

[0180] During the time frame processing, the total number of sampling points of the original signal (i.e., phase data and power spectrum data) can be determined N total , that is, sampling N total phase data and N total power spectrum data.

[0181] Based on the total number of frames N and the total number of sampling points N total , the number of points per frame L frame can be determined, that is, each frame includes L frame phase data and L frame power spectrum data. Based on L frame phase data and L frame power spectrum data, the DSP parameters corresponding to one frame can be determined, and the DSP parameters can include m parameter values. For example, the number of points per frame L frame can be determined by the following formula:L frame = N total / N 。

[0182] In summary, for the original signal data, it can be segmented according to the calculated number of points L frame to segment the original signal data, forming N frames, and each frame includes L frame phase data and L frame power spectrum data. As shown in Figure 5A the original signal length of the original signal data is N total , the calculated frame length is L frame , and the original signal data is segmented according to L frame to form N frames.

[0183] Step S22: Parameter extraction. The purpose of parameter extraction is to extract characteristic parameters (DSP parameters) from the signal data of each frame, construct a parameter sequence, and reflect the characteristic changes of the signal on the time axis.

[0184] For example, based on the signal data of Frame 1 ( L frame phase data and L frame power spectrum data), the DSP parameters of Frame 1 can be obtained, and the DSP parameters include m parameter values. For example, the input signal data of the target fiber unit is obtained, and the input signal data includes phase data and power spectrum data. Then, signal preprocessing can be performed on the input signal data, such as filtering the input signal data for preprocessing, so as to improve the signal quality and eliminate noise interference. Then, time-energy dimension parameter extraction and space dimension parameter extraction can be performed on the preprocessed signal data ( L frame phase data and L frame power spectrum data) to obtain DSP parameters. The DSP parameters can include time-energy dimension parameters (such as P1...Pn) and space dimension parameters (such as Pn+1...Pm), that is, the DSP parameters include m parameter values, and m is a positive integer.

[0185] To ensure the comparability between different parameter values, normalization processing can also be performed on the m parameter values in the DSP parameters, such as mapping the m parameter values to a unified numerical interval (such as between 0 and 1).

[0186] In summary, based on the signal data of Frame 1 ( L frame phase data and L frame power spectrum data), m parameter values can be calculated. The m parameter values can include the root mean square value (RMS), zero crossing rate (ZCR), peak-to-peak value, spectral entropy, etc. These m parameter values form the DSP parameters of Frame 1. Obviously, the DSP parameters can reflect the amplitude, frequency, and energy distribution characteristics of the signal, and there is no limitation on these DSP parameters.

[0187] For example, based on the signal data of Frame 2 (such as L frame phase data and L frame power spectrum data), the DSP parameters of Frame 2 can be obtained,... And so on, based on the signal data of Frame N (such as L frame phase data and L frame power spectrum data), the DSP parameters of Frame N can be obtained.

[0188] When calculating the DSP parameters of each frame, a unified parameter calculation process can be adopted to ensure the consistency of the DSP parameter calculation method and improve the reliability and repeatability of the DSP parameter calculation.

[0189] Refer to Figure 5B shown in the figure. For the signal data of each frame, calculate each characteristic parameter in turn to form the parameter set of this frame. Arrange the parameter sets of all frames in order to construct a complete parameter sequence. For example, extracting parameters based on the signal data of Frame 1 obtains Parameter Set 1, and Parameter Set 1 includes the DSP parameters of Frame 1 (m parameter values). Extracting parameters based on the signal data of Frame 2 obtains Parameter Set 2, and Parameter Set 2 includes the DSP parameters of Frame 2. And so on, extracting parameters based on the signal data of Frame N obtains Parameter Set N, and Parameter Set N includes the DSP parameters of Frame N. On this basis, the DSP parameters of Parameter Set 1, the DSP parameters of Parameter Set 2,..., the DSP parameters of Parameter Set N can be combined to obtain a parameter sequence. Obviously, the parameter sequence can include N * m parameter values.

[0190] Step S23: Matrix organization. The purpose of matrix organization is to organize the extracted parameter sequence into a two-dimensional matrix according to time and parameter dimensions, providing a data basis for subsequent visualization.

[0191] For example, for each of the consecutive N frames, the DSP parameters of that frame can be obtained, and the DSP parameters of that frame include m parameter values, and the N*m parameter values form a parameter sequence. Based on this parameter sequence, the m parameter values of each frame can be used as a row of a parameter matrix to obtain a parameter matrix. In this way, the parameter matrix can be an N-row and m-column matrix. Alternatively, based on this parameter sequence, the m parameter values of each frame can be used as a column of a parameter matrix to obtain a parameter matrix. In this way, the parameter matrix can be an N-column and m-row matrix.

[0192] In summary, a parameter matrix can be constructed, which can clearly reflect the variation relationship of parameters over time and achieve a structured expression of DSP parameters. In addition, it can also support dynamically adjusting the structure and size of the matrix according to different numbers of parameters and frames. For example, the total number of frames can be dynamically adjusted. N .

[0193] See Figure 5C As shown, it is a schematic diagram of matrix organization. The DSP parameters of frame 1 (i.e., m parameter values, such as parameter 1, parameter 2,..., parameter m) are used as the first row (or first column) of the parameter matrix, the DSP parameters of frame 2 (such as parameter 1, parameter 2,..., parameter m) are used as the second row (or second column) of the parameter matrix, and so on. The DSP parameters of frame N (such as parameter 1, parameter 2,..., parameter m) are used as the Nth row (or Nth column) of the parameter matrix, and then the parameter matrix is obtained.

[0194] Step 402: Generate a grid image, which can include multiple grids.

[0195] Exemplarily, the purpose of generating a grid image is to map the parameter matrix to the pixel grid of the grid image (abbreviated as grid), so that the two-dimensional structure of DSP parameters can be reflected in the image. By mapping the parameter values of DSP parameters to the pixel grid of the grid image, the correspondence between parameter values and spatial positions is realized, forming an intuitive visual expression. The grid mapping is the step of converting the parameter matrix into an image.

[0196] Exemplarily, when generating a grid image, through resolution adjustment and grid filling, the parameter matrix is converted into a grayscale image with appropriate resolution and clarity, realizing the visual expression of parameter features. For example, the resolution adjustment can include: dynamic adaptation, that is, according to the size of the parameter matrix and the desired image clarity, select an appropriate image size. Grid uniformity, that is, ensure that the grid size is an integer, or achieve uniform division through methods such as filling and interpolation. Boundary processing, that is, when the grid size cannot divide the image size evenly, adopt an appropriate edge filling strategy so that the grid size can divide the image size evenly.

[0197] Exemplarily, when generating a grid image, the grid image may include multiple grids (such as pixel grids). For each grid, the height dimension of the grid may be determined based on the height of the color grid image and the number of horizontal elements of the parameter matrix, and the width dimension of the grid may be determined based on the width of the color grid image and the number of vertical elements of the parameter matrix. For example, if the color grid image is the final output image, the height and width of the color grid image may be pre-configured, indicating that a color grid image with such height and width is expected to be output.

[0198] For example, if the parameter matrix is a matrix with N columns and m rows, that is, there are N elements vertically and m elements horizontally, the following formula is used to determine the height dimension of the grid: h = H / m , and the following formula is used to determine the width dimension of the grid: w =W / N. In the above formula, H represents the height (number of pixels) of the color grid image, that is, the height of the expected target image, W represents the width height (number of pixels) of the color grid image, that is, the width of the expected target image. h represents the height dimension of the grid, and w represents the width dimension of the grid.

[0199] Considering that the grid size is an integer, if H / m is an integer, then H / m is used as the height dimension of the grid. If H / m is not an integer, H / m can be rounded down to be used as the height dimension of the grid, or an appropriate edge filling strategy can be adopted to make H / m an integer. In addition, if W / N is an integer, then W / N is used as the width dimension of the grid. If W / N is not an integer, W / N can be rounded down to be used as the width dimension of the grid, or an appropriate edge filling strategy can be adopted to make W / N an integer.

[0200] Step 403: For each parameter value in the parameter matrix, determine the grid in the grid image corresponding to the parameter value, normalize the parameter value to a specified numerical interval, and fill the normalized parameter value into the grid; where multiple parameter values in the parameter matrix correspond to multiple grids in the grid image one by one.

[0201] Exemplarily, when the parameter matrix is a matrix with N columns and m rows, the height dimension of the grid is h = H / m , and the width dimension of the grid is w =W / N. Therefore, there are N grids horizontally in the grid image, and there are ma grid, so that the N*m parameter values of the parameter matrix correspond one-to-one with the N*m grids of the grid image, that is, each parameter value corresponds to a grid of the grid image individually.

[0202] For example, refer to Figure 5D As shown, it is a schematic diagram of grid division. The size of the grid image can be H*W. First, grid (1,1) can be divided. The width size of grid (1,1) can be w_grid (abbreviated as w), and the height size of grid (1,1) can be h_grid (abbreviated as h). Then, grid (1,2) and grid (2,1) can be divided, and so on. The division order of different grids can refer to Figure 5D As shown.

[0203] For example, after completing the grid division, the grid image can refer to Figure 5E As shown, the size of the grid image can be H*W. The width W corresponds to N grids, and the height H corresponds to m grids. In this way, the N*m parameter values of the parameter matrix correspond one-to-one with the N*m grids of the grid image. For example, grid (1,1) corresponds to the parameter value in the first row and first column of the parameter matrix, grid (1,2) corresponds to the parameter value in the first row and second column of the parameter matrix, grid (2,1) corresponds to the parameter value in the second row and first column of the parameter matrix, and so on.

[0204] Exemplarily, for each parameter value in the parameter matrix, the parameter value can be normalized to a specified numerical interval. The specified numerical interval can be [0, 255], that is, the numerical interval of the gray value, or it can be other numerical intervals, and there is no restriction on this. If the specified numerical interval is [0, 255], the following formula (8) can be used to normalize the parameter value to the specified numerical interval. Of course, formula (8) is just an example.

[0205] Formula (8)

[0206] In formula (8), G ij represents the normalized parameter value, P ij represents the parameter value, 255 represents the maximum value of the specified numerical interval. When using other numerical intervals, 255 is also correspondingly replaced by the maximum value of other numerical intervals. P min represents the minimum parameter value in the parameter matrix, P max represents the maximum parameter value in the parameter matrix. Through formula (8), the parameter value can be mapped to the gray range of [0, 255].

[0207] Exemplarily, for each parameter value in the parameter matrix, determine the grid corresponding to the parameter value in the grid image, and fill the normalized parameter value into the grid, that is, fill the normalized parameter value into the corresponding grid area. For example, when mapping the grid area, the following formula (9) can be used.

[0208] Formula (9)

[0209] In formula (9), x start and y start represent the starting coordinates of the grid, x end and y end represent the ending coordinates of the grid, i represents the i th parameter value in the horizontal direction of the parameter matrix, j represents the j th parameter value in the vertical direction of the parameter matrix, S grid represents the width dimension w_grid or the height dimension h_grid of the grid.

[0210] Exemplarily, after filling the normalized parameter value corresponding to each parameter value in the parameter matrix into the grid image, a grayscale image can be obtained, that is, the grayscale image includes these normalized parameter values.

[0211] In the above process, adaptive grid division can be achieved, that is, according to the size of the parameter matrix, the grid size of the grid image is dynamically calculated to ensure that each parameter value corresponds to a specific pixel area (i.e., grid). Resolution configuration can be achieved, that is, it supports adjusting the size and resolution of the image according to needs to affect the fineness of the final image. The establishment of the mapping relationship can be achieved, mapping the elements in the parameter matrix to specific positions on the image to achieve an accurate correspondence between the parameter value and the pixel position.

[0212] Step 404: Perform a visualization transformation on the grayscale image to obtain a color grid image.

[0213] Exemplarily, a configured smoothing kernel can be used to perform a smoothing operation on the grayscale image to obtain a smoothed grayscale image. For example, the grayscale image can be smoothed according to requirements to improve the visual effect. The smoothing process is an optional step and can also not be performed. For example, the following formula can be used for the smoothing operation: I smooth = G ∗ K , I smooth can be the smoothed grayscale image, GIt can be the original grayscale image, K It can be the configured smoothing kernel, and * can represent the convolution operation.

[0214] The smoothed grayscale image (or the original grayscale image) can be visually transformed to obtain a color grid image. For example, the grayscale image can be converted into a color image of the RGB type, and there is no limitation on this conversion process. For example, the visual transformation is the process of converting a grayscale image into a color image, aiming to enhance the visual effect, facilitate human eye recognition, and subsequent feature extraction. See Figure 5F As shown, it is a schematic diagram of the color grid image (DSP parameter color card) of the ladder climbing scenario. See Figure 5G As shown, it is a schematic diagram of the color grid image of the vehicle passing scenario. See Figure 5H As shown, it is a schematic diagram of the color grid image of the heavy rain scenario.

[0215] So far, the DSP parameter conversion process is completed, and a color grid image (color card image) can be obtained.

[0216] In a possible implementation manner, see Figure 2 As shown, after obtaining the Mel spectrogram, waterfall plot, and color grid image, feature fusion can also be performed based on the Mel spectrogram, waterfall plot, and color grid image, and then anomaly detection can be carried out. The following is an explanation of the anomaly detection process.

[0217] See Figure 6A As shown, it is a schematic diagram of the fusion of multi-source heterogeneous data or multi-modal data. Multi-source heterogeneous data refers to a data set with different forms, sources, or structures, including structured data (such as DSP parameters, alarm data) and unstructured data (such as Mel spectrograms, waterfall plots, etc.), and there are differences in the type, format, or dimension of these data. Multimodal data is a data set that describes the same object in different forms. Based on the fusion of multi-source heterogeneous data or multi-modal data, feature fusion can be performed on the Mel spectrogram, waterfall plot, and color grid image to obtain the fused data, and then anomaly detection can be carried out based on the fused data. The anomaly detection process can include the following steps:

[0218] Step S31: Obtain input data, such as the Mel spectrogram, waterfall plot, and color grid image.

[0219] Step S32: Perform feature preprocessing based on the input data. For example, extract RGB features based on the Mel spectrogram, perform grayscale transformation based on the waterfall plot, and perform parameter mapping based on the color grid image. There is no limitation on this feature preprocessing process. The feature preprocessing process is optional, and the following takes not performing it as an example.

[0220] Step S33: Perform feature fusion on the Mel spectrogram, waterfall plot, and color grid image. Here, the feature fusion can be channel-level fusion. Adopting a channel-level fusion strategy, map data of different modalities into the feature space. For example, perform splicing in the channel dimension on the Mel spectrogram, waterfall plot, and color grid image to obtain a spliced image, that is, the spliced image can include images of multiple channels.

[0221] For example, the spliced image can include acoustic spectral features, time-frequency waterfall features, and parameter mapping features. The acoustic spectral features are assigned 3 information channels, such as the 3 channels of the Mel spectrogram. The time-frequency waterfall features are assigned 1 information channel, such as the 1 channel of the waterfall plot. The parameter mapping features are assigned 1 information channel, such as the 1 channel of the color grid image. To sum up, the spliced image can include 3 channels of the Mel spectrogram, 1 channel of the waterfall plot, and 1 channel of the color grid image. In this way, the spliced image is an image with 5 channels, and the spliced image includes the Mel spectrogram, waterfall plot, and color grid image.

[0222] Step S34: Input the spliced image into the anomaly detection model. The anomaly detection model performs model processing based on the spliced image to obtain a reconstructed image corresponding to the spliced image. Determine an initial anomaly score based on the difference between the reconstructed image and the spliced image, and output the initial anomaly score. In addition, the anomaly detection model can also output an interpretability analysis, and the content of this interpretability analysis is not restricted.

[0223] Exemplarily, the input data of the anomaly detection model is the spliced image (Mel spectrogram + waterfall plot + color grid image), and the output data of the anomaly detection model is the reconstructed image (reconstructed image of the Mel spectrogram + reconstructed image of the waterfall plot + reconstructed image of the color grid image). The processing process of this anomaly detection model is not restricted, as long as it can process the spliced image to obtain a reconstructed image.

[0224] For example, the anomaly detection model can perform feature mapping on the spliced image to obtain mapped features, and then generate a reconstructed image based on the mapped features. When performing feature mapping on the spliced image, the following formula can be used: F = φ(X1, X2, X3), where X1 represents the acoustic spectral features (such as the 3 channels of the Mel spectrogram), X2 represents the time-frequency waterfall features (such as the 1 channel of the waterfall plot), X3 represents the parameter mapping features (such as the 1 channel of the color grid image). φ represents the configured feature mapping function.

[0225] For example, when performing feature mapping on the spliced image, the weights can also be adjusted according to the number of channels to adaptively regulate the importance of features. The weights can be expressed as: W = {w1, w2, w3}, where w1 can represent the weight of the acoustic spectrum features, such as the three weights corresponding to the three channels of the Mel spectrogram; w2 can represent the weight of the time-frequency waterfall features, such as the one weight corresponding to the one channel of the waterfall diagram; w3 can represent the weight of the parameter mapping features, such as the one weight corresponding to the one channel of the color grid image.

[0226] Exemplarily, the network structure of the anomaly detection model can be referred to Figure 6B as shown. The anomaly detection model is a transformer network based on multi-task vision, such as a fusion model structure based on vision transformers. Of course, Figure 6B this is only an example of the network structure of the anomaly detection model, and there is no limitation on this network structure, as long as the anomaly detection model can process the spliced image to obtain the reconstructed image.

[0227] For example, the anomaly detection model can include a Patch Embedding network. The input feature of the Patch Embedding network is the spliced image. The Patch Embedding network is used to divide the spliced image into multiple non-overlapping small patches of a fixed size and map each small patch into an embedding vector space of a specific dimension through convolution operations, such as converting these small patches into 1D vectors (embedding, encoded image patches). There is no limitation on this processing process.

[0228] For example, the anomaly detection model can include a Position Encoding network. The input feature of the Position Encoding network is the output feature of the Patch Embedding network. The Position Encoding network is used to introduce position encoding at the input end of the transformer architecture and inject the position encoding into the input feature, so that the self-attention layer can pay attention to the position information when extracting feature information. As the only position information in the transformer architecture, the position encoding is superimposed on the input feature before entering the attention layer (or before entering the entire transformer architecture), and its dimension is consistent with the dimension of the input feature.

[0229] For example, the anomaly detection model may include Self Attention Layers (self-attention network). The input features of the Self Attention Layers are the output features of the Position Encoding network. The Self Attention Layers can perform self-attention processing based on the input features. For example, the following formula can be used for self-attention processing: , where Q represents the query matrix, K represents the key matrix, V represents the value matrix, and d represents the feature dimension. There is no limitation on this self-attention processing process.

[0230] For example, the anomaly detection model may include a Feed Forward network. The input features of the Feed Forward network are the output features of the Self Attention Layers network. The Feed Forward network is also known as Forward propagation, which is a direct calculation method from the input layer to the output layer. The weight matrix is initialized to all 0s, and the activation function is used to propagate forward until the output layer is calculated.

[0231] For example, the anomaly detection model may include a reconstruction decoder. The input features of the reconstruction decoder are the output features of the Feed Forward network. The reconstruction decoder is used to perform a reconstruction operation based on the input features to obtain a reconstructed image corresponding to the concatenated image. The reconstructed image is used as the output feature of the anomaly detection model.

[0232] Exemplarily, after obtaining the reconstructed image, an initial anomaly score can be determined based on the difference between the reconstructed image and the concatenated image. For example, when the number of channels of the reconstructed image is the same as that of the concatenated image, and the concatenated image includes a mel spectrogram, a waterfall plot, and a color grid image, the reconstructed image includes the reconstructed image of the mel spectrogram, the reconstructed image of the waterfall plot, and the reconstructed image of the color grid image.

[0233] Based on this, the difference between the reconstructed image and the concatenated image can be calculated. For example, the MSE (Mean Square Error) between the reconstructed image and the concatenated image can be calculated, and the initial anomaly score can be determined based on the MSE. Of course, MSE is only an example, and there is no limitation on this. As long as the initial anomaly score is related to the difference between the images. When the difference between the reconstructed image and the concatenated image is larger, the initial anomaly score is larger. When the difference between the reconstructed image and the concatenated image is smaller, the initial anomaly score is smaller.

[0234] Exemplarily, in order to train the anomaly detection model, a reconstruction loss value, a knowledge distillation loss value, and a classification loss value are introduced in this embodiment. See Figure 6CAs shown, an optimization module is introduced behind the anomaly detection model, and the optimization module is used to calculate the reconstruction loss value, the knowledge distillation loss value, and the classification loss value.

[0235] On this basis, in order to train the anomaly detection model, the following method can be adopted:

[0236] Obtain the configured initial detection model, and the network structure of the initial detection model is shown in Figure 6B as shown.

[0237] Obtain the sample data and the true label of the sample data. The sample data can include sample Mel spectrograms, sample waterfall diagrams, and sample color grid images. The acquisition method of the sample Mel spectrogram refers to the acquisition method of the Mel spectrogram, the acquisition method of the sample waterfall diagram refers to the acquisition method of the waterfall diagram, and the acquisition method of the sample color grid image refers to the acquisition method of the color grid image. The true label of the sample data indicates that the vibration alarm is a false alarm (such as 0), or the true label indicates that the vibration alarm is a valid alarm (such as 1).

[0238] Perform channel dimension splicing on the sample Mel spectrogram, the sample waterfall diagram, and the sample color grid image to obtain the sample spliced image, that is, the spliced image can include images of multiple channels.

[0239] After obtaining the sample spliced image, the sample spliced image can be input into the initial detection model to obtain the first sample reconstructed image and the predicted label. The predicted label can indicate that the vibration alarm is a false alarm (such as 0), or the true label indicates that the vibration alarm is a valid alarm (such as 1).

[0240] After obtaining the sample spliced image, the sample spliced image can also be input into the classroom detection model to obtain the second sample reconstructed image. For example, the classroom detection model and the student detection model can be constructed by means of knowledge distillation. The student detection model is the initial detection model. The network structure of the classroom detection model is the same as that of the student detection model. The classroom detection model is a larger detection model with higher detection accuracy, and the student detection model is a smaller detection model with lower detection accuracy. The training process of the initial detection model can be assisted by the classroom detection model to improve the detection accuracy of the initial detection model.

[0241] After obtaining the first sample reconstructed image, the second sample reconstructed image, and the predicted label, the reconstruction loss value can be determined based on the difference between the first sample reconstructed image and the sample concatenated image. That is, the greater the difference between the first sample reconstructed image and the sample concatenated image, the greater the reconstruction loss value. The optimization objective of the initial detection model is to make the reconstruction loss value smaller and smaller. The difference can be MSE or other types of differences. The knowledge distillation loss value can be determined based on the difference between the first sample reconstructed image and the second sample reconstructed image. That is, the greater the difference between the first sample reconstructed image and the second sample reconstructed image, the greater the knowledge distillation loss value. The optimization objective of the initial detection model is to make the knowledge distillation loss value smaller and smaller. The classification loss value can be determined based on the difference between the predicted label and the true label of the sample data. That is, the greater the difference between the predicted label and the true label, the greater the classification loss value. The optimization objective of the initial detection model is to make the classification loss value smaller and smaller.

[0242] Then, based on the reconstruction loss value, the knowledge distillation loss value, and the classification loss value, the target loss value is determined. For example, the target loss value is determined using the following formula: . In the above formula, L represents the target loss value, L ae represents the reconstruction loss value, α represents the weight coefficient corresponding to the reconstruction loss value, which can also be called the balance factor, L dist represents the knowledge distillation loss value, β represents the weight coefficient corresponding to the knowledge distillation loss value, L cls represents the classification loss value, γ represents the weight coefficient corresponding to the classification loss value.

[0243] After obtaining the target loss value, the parameters of the initial detection model can be adjusted based on the target loss value to obtain the adjusted model. In the process of parameter adjustment, methods such as the gradient descent method can be used. The adjustment objective is to make the target loss value smaller and smaller. There are no restrictions on this parameter adjustment process.

[0244] Then, it is judged whether the adjusted model has converged. For example, if the target loss value is less than the threshold, the adjusted model has converged. If the target loss value is not less than the threshold, the adjusted model has not converged. Another example is that if the number of iterations reaches the iteration threshold, the adjusted model has converged. If the number of iterations does not reach the iteration threshold, the adjusted model has not converged. Another example is that if the iteration duration reaches the duration threshold, the adjusted model has converged. If the iteration duration does not reach the duration threshold, the adjusted model has not converged.

[0245] If the adjusted model has converged, it can be determined as the anomaly detection model, completing the model training process and obtaining a trained anomaly detection model. If the adjusted model has not converged, it can be determined as the initial detection model, and the process of inputting the concatenated sample image to the initial detection model is repeated until the adjusted model has converged.

[0246] Step S35: Determine whether the vibration alarm is a false alarm or a valid alarm based on the initial abnormality score.

[0247] For example, if the initial anomaly score is not greater than a threshold, the vibration alarm is determined to be a false alarm, meaning it is an erroneous alarm result. Alternatively, if the initial anomaly score is greater than a threshold, the vibration alarm can be determined to be a valid alarm, meaning it is a correct alarm result.

[0248] For example, before multimodal feature fusion (i.e., step S33), feature data alignment may also be involved. By establishing a unified benchmark in the time dimension while maintaining the unique expression of each feature in other dimensions, effective data alignment is achieved. Figure 6D The figure below shows a schematic diagram of feature alignment. For example, the frequency-dimensional Mel-spectrogram, spatial-dimensional waterfall plot, and parameter-dimensional DSP parameter color chart (i.e., color grid image) can be aligned along the time axis. This alignment establishes a unified time reference along the time dimension, enabling the time alignment of the Mel-spectrogram, waterfall plot, and DSP parameter color chart.

[0249] Regarding the composition of feature dimensions, each feature image (Mel-spectrogram, waterfall plot, DSP parameter color card) contains two dimensions of information: a unified time dimension (horizontally) and an independent feature dimension (vertically). Within the unified time dimension, a unified time sampling benchmark is established to ensure that all features are fully aligned on the time axis, supporting continuous synchronization of real-time data streams. Within the independent feature dimensions, the Mel-spectrogram uses the frequency dimension to represent the spectral distribution of the acoustic signal, the waterfall plot uses the spatial dimension to represent the distribution of each spatial unit of the device, and the DSP parameter color card uses the parameter dimension to represent the state characteristics of signal processing.

[0250] Alignment implementation strategies involve time dimension synchronization and multidimensional feature mapping. Time dimension synchronization unifies the sampling frequency and time base, establishes a time index mapping mechanism, and ensures temporal consistency in feature extraction. Multidimensional feature mapping maintains the independence of features in each dimension, establishes a standardized feature extraction process, and preserves the physical meaning of the original data.

[0251] In one possible implementation, see Figure 2As shown, after obtaining the timing statistical parameters, multi-level false alarm determination can also be performed based on the timing statistical parameters, and then anomaly detection can be carried out. The following describes the anomaly detection process. In the multi-level false alarm determination process, the alarm data is accurately evaluated, false alarms are identified and filtered to ensure the reliability and effectiveness of the system. A multi-level false alarm determination logic is adopted to comprehensively analyze the alarm data from three dimensions: immediacy, relevance, and historicity, calculate the false alarm confidence level, and provide a basis for subsequent alarm processing. Refer to Figure 7 As shown, it is a schematic diagram of the false alarm determination process.

[0252] Step 701: When a vibration alarm is triggered by a target optical fiber unit, obtain the target alarm data of the target optical fiber unit. For example, the target optical fiber unit can be any optical fiber unit of the vibration optical fiber.

[0253] Step 702: Determine the immediacy parameter, relevance parameter, and historicity parameter based on the target alarm data.

[0254] Step 703: Determine the comprehensive false alarm score based on the immediacy score corresponding to the immediacy parameter, the relevance score corresponding to the relevance parameter, and the historicity score corresponding to the historicity parameter.

[0255] Exemplarily, if the immediacy parameter includes signal dimension matching degree, environmental correlation dimension matching degree, and spatio-temporal consistency dimension matching degree, then a weighted operation can be performed on the signal dimension matching degree, environmental correlation dimension matching degree, and spatio-temporal consistency dimension matching degree to obtain the immediacy score. For example, the following formula is used to calculate the immediacy score: . SA represents the immediacy score, which is used to measure the immediate false alarm possibility of the current alarm, F 1 represents the signal dimension matching degree, w 1 represents the weight coefficient of the signal dimension matching degree, F 2 represents the environmental correlation dimension matching degree, w 2 represents the weight coefficient of the environmental correlation dimension matching degree, F 3 represents the spatio-temporal consistency dimension matching degree, w 3 represents the weight coefficient of the spatio-temporal consistency dimension matching degree, w 1 、 w 2 、 w 3 reflect the importance of each factor, satisfying w 1 + w2 + w 3 = 1.

[0256] The relevance parameter can be referred to in formula (4), and the relevance parameter RA can be used as the relevance score.

[0257] Exemplarily, if the historical parameters include the time pattern matching degree, the space pattern matching degree, and the environment pattern matching degree, then the weighted operation can be performed on the time pattern matching degree, the space pattern matching degree, and the environment pattern matching degree to obtain the historical score. For example, the historical score can be calculated using the following formula: . HM represents the historical score and is used to represent the matching degree between the current alarm and the historical false alarm pattern. P T represents the time pattern matching degree, α represents the weight coefficient of the time pattern matching degree, P S represents the space pattern matching degree, β represents the weight coefficient of the space pattern matching degree, P E represents the environment pattern matching degree, γ represents the weight coefficient of the environment pattern matching degree, satisfying α + β + γ = 1.

[0258] Exemplarily, after obtaining the immediacy score, the relevance score, and the historical score, the weighted operation can be performed on the immediacy score, the relevance score, and the historical score to obtain the comprehensive false alarm score. For example, the comprehensive false alarm score can be calculated using the following formula: . FS represents the comprehensive false alarm score, comprehensively reflecting the false alarm possibility of the current alarm, k 1 represents the dynamic weight coefficient of the immediacy score, k 2 represents the dynamic weight coefficient of the relevance score, k 3 represents the dynamic weight coefficient of the historical score, and the dynamic weight coefficient is adjusted according to the actual application scenario and requirements, and satisfies k 1 + k 2 + k 3 = 1.

[0259] Step 704, determine the false alarm confidence level corresponding to the vibration alarm based on the comprehensive false alarm score.

[0260] Exemplarily, the false alarm confidence level may be proportional to the comprehensive false alarm score, and there is no limitation on the method for determining the false alarm confidence level, as long as the false alarm confidence level is proportional to the comprehensive false alarm score. For example, in order to convert the comprehensive false alarm score into a probability value that can be directly used for decision-making, a logical function (Sigmoid function) is used to calculate the false alarm confidence level. For example, the false alarm confidence level is determined using the following formula: . C represents the false alarm confidence level, λ represents the configured adjustment coefficient, which is used to control the growth rate of the function, FS represents the comprehensive false alarm score, C The value range of is [0, 1], C The closer it is to 1, the greater the possibility of a false alarm.

[0261] Step 705: Determine whether the false alarm confidence level is not less than a threshold value (which can be configured according to experience).

[0262] If so, that is, the false alarm confidence level is not less than the threshold value, then step 706 can be executed.

[0263] If not, that is, the false alarm confidence level is less than the threshold value, then step 707 can be executed.

[0264] Step 706: Determine the vibration alarm as a false alarm, that is, the vibration alarm is an incorrect alarm result. In this case, the vibration alarm can be suppressed to avoid the transmission of false alarm information.

[0265] Step 707: Determine the vibration alarm as a valid alarm, that is, the vibration alarm is a correct alarm result. In this case, the corresponding alarm response can be triggered, such as sending a vibration alarm to the staff.

[0266] In a possible implementation manner, after obtaining the false alarm confidence level and the initial anomaly score, the false alarm confidence level and the initial anomaly score can also be combined, and a progressive suppression strategy can be used for anomaly detection (in Figure 2 , taking the progressive suppressor using the progressive suppression strategy for anomaly detection as an example). The following describes the anomaly detection process. The progressive suppression strategy means that the progressive suppressor dynamically adjusts the suppression coefficient according to the false alarm confidence level to achieve hierarchical suppression, improve the system reliability, and can dynamically adjust the suppression intensity of the alarm signal according to the high or low false alarm confidence level to achieve smooth and progressive suppression of false alarms. By setting the suppression level, calculating the suppression coefficient, applying the dynamic adjustment factor, etc., the alarm signal is refined to ensure that while reducing the false alarm rate, it does not affect the timely detection and response to real intrusion behaviors.

[0267] Referring to Figure 8A shown, it is a schematic diagram of the progressive suppression process, and this process may include:

[0268] Step 801, obtain the false alarm confidence level and the initial anomaly score.

[0269] Step 802, determine the first suppression coefficient based on the false alarm confidence level.

[0270] Exemplarily, the first suppression coefficient is proportional to the false alarm confidence level. There is no limitation on the method for determining the first suppression coefficient as long as the first suppression coefficient is proportional to the false alarm confidence level. For example, based on the false alarm confidence level, a piecewise function can be used to calculate the first suppression coefficient. For example, the first suppression coefficient can be determined using the following formula (10). In formula (10), a piecewise function with four segments is used as an example to calculate the first suppression coefficient. Other piecewise functions (such as those with 3, 5, 6 segments, etc.) can also be used to calculate the first suppression coefficient.

[0271] Formula (10)

[0272] x represents the false alarm confidence level, x The value range of is [0, 1], S ( x ) represents the first suppression coefficient, T 1, T 2, T 3 represent the segmentation thresholds, and satisfy 0 < T 1 < T 2 < T 3 < 1, k 1, k 2, k 3 represent the slopes of the respective piecewise functions, S 1 represents the suppression coefficient at the end of the first segment and serves as the starting point for the next segment, and S 1 = k 1×( T 2 − T 1), S 2 represents the suppression coefficient at the end of the second segment and serves as the starting point for the next segment, and S 2 = S 1 + k 2×( T 3 − T 2).

[0273] Step 803, determine the suppression level based on the first suppression coefficient.

[0274] Exemplarily, according to the first suppression coefficient S ( x)Based on the size of [], the suppression level is divided into 4 levels, or the suppression level is divided into levels such as 2, 3, 5, and 6. There is no limitation on this. Taking the division into 4 levels as an example, these 4 levels are called normal suppression level, mild suppression level, moderate suppression level, and high suppression level.

[0275] For example, if the first suppression coefficient S ( x ) is greater than or equal to 0 and less than the first value (such as 0 ≤ S ( x ) < 0.20), then the suppression level is determined to be the normal suppression level. Under the normal suppression level, it is in the normal monitoring state and does not suppress the alarm signal. That is to say, it does not suppress the initial abnormal score.

[0276] For example, if the first suppression coefficient S ( x ) is greater than or equal to the first value and less than the second value (such as 0.2 ≤ S(x) < 0.4), then the suppression level is determined to be the mild suppression level. Under the mild suppression level, a slight suppression measure is applied to the alarm signal with a relatively high false alarm probability. That is, the initial abnormal score is slightly suppressed.

[0277] For example, if the first suppression coefficient S ( x ) is greater than or equal to the second value and less than the third value (such as 0.4 ≤ S(x) < 0.7), then the suppression level is determined to be the moderate suppression level. Under the moderate suppression level, a moderate suppression measure is applied to the alarm signal with a relatively high false alarm confidence level. That is, the initial abnormal score is moderately suppressed.

[0278] For example, if the first suppression coefficient S ( x ) is greater than or equal to the third value and less than or equal to the fourth value (the fourth value can be 1 or less than 1, such as 0.9, etc., such as 0.7 ≤ S(x) ≤ 0.9), then the suppression level is determined to be the high suppression level. Under the high suppression level, a strong suppression is performed on the alarm signal determined to be a high - probability false alarm to avoid the influence of false alarm information. That is, the initial abnormal score is strongly suppressed.

[0279] Step 804: Determine the second suppression coefficient based on the first suppression coefficient, the configured time adjustment factor, the configured space adjustment factor, and the configured environment adjustment factor.

[0280] Exemplarily, to improve the flexibility of the system, the progressive suppressor introduces a dynamic adjustment factor and modifies the first suppression coefficient according to the dynamic adjustment factor to obtain the second suppression coefficient. For example, the second suppression coefficient can be determined by the following formula (11). Of course, formula (11) is just an example.

[0281] Formula (11)

[0282] In Formula (11), S adjusted represents the adjusted suppression coefficient, i.e., the second suppression coefficient, S ( x ) represents the first suppression coefficient. F t represents the time adjustment factor. For example, different times have different time adjustment factors. For instance, the daytime has a time adjustment factor of 1, and the nighttime has a time adjustment factor of 2. Thus, if the target alarm time is during the daytime, the time adjustment factor 1 is adopted. F s represents the space adjustment factor. For example, different regions have different space adjustment factors. For instance, Region 1 has a space adjustment factor of 1, Region 2 has a space adjustment factor of 2, Region 3 has a space adjustment factor of 3, and so on. Thus, if the target alarm location is in Region 1, the space adjustment factor 1 is adopted. F e represents the environment adjustment factor. For example, different environments (such as weather, holidays, etc.) have different environment adjustment factors. For instance, Environment 1 has an environment adjustment factor of 1, Environment 2 has an environment adjustment factor of 2, and so on. Thus, if the current vibration alarm corresponds to Environment 1, the environment adjustment factor 1 is adopted. Regarding the values of each time adjustment factor, each space adjustment factor, and each environment adjustment factor, they can be pre-configured according to experience and are not limited in this embodiment.

[0283] Step 805: Determine the third suppression coefficient based on the second suppression coefficient and the configured attenuation coefficient.

[0284] Exemplarily, after obtaining the second suppression coefficient, the second suppression coefficient can be adjusted progressively. For example, a smoothing function (such as an exponential decay function) is used to make the suppression effect transition smoothly and achieve a progressive curve adjustment. On this basis, the following Formula (12) can be used to determine the third suppression coefficient:

[0285] Formula (12)

[0286] In Formula (12), adjusted_confidence can represent the third suppression coefficient, base_confidence can represent the second suppression coefficient, α can represent the configured attenuation coefficient, t can represent the time interval. For example, the time interval can be the interval between the target alarm time and the configured initial time.

[0287] Step 806: Determine the target gain adjustment factor (night_gain) corresponding to the target alarm time.

[0288] For example, the night time interval and the day time interval can be pre-configured. The night time interval corresponds to a first factor value, and the day time interval corresponds to a second factor value. The first factor value is greater than the second factor value. For example, the first factor value is 1.2 and the second factor value is 1. Of course, in addition to the night time interval and the day time interval, more time intervals can be set, and each time interval corresponds to a factor value. On this basis, if the target alarm time is within the night time interval, the target gain adjustment factor is the first factor value, and if the target alarm time is within the day time interval, the target gain adjustment factor is the second factor value.

[0289] By controlling the first factor value (such as 1.2) to be greater than the second factor value, the gain adjustment of the third suppression coefficient in the night time interval can be performed to improve the detection sensitivity in the night time interval.

[0290] Step 807: Determine the target suppression coefficient based on the third suppression coefficient and the target gain adjustment factor.

[0291] Exemplarily, if the product value between the third suppression coefficient and the target gain adjustment factor is less than a fixed value (which can be configured according to experience, and the fixed value can be less than 1, such as 0.9, etc.), then this product value is determined as the target suppression coefficient. If the product value between the third suppression coefficient and the target gain adjustment factor is not less than the fixed value, then the fixed value can be determined as the target suppression coefficient. In summary, the final target suppression coefficient can be calculated, and the maximum value of the target suppression coefficient is limited not to exceed the fixed value.

[0292] Step 808: Adjust the initial anomaly score based on the target suppression coefficient and the configured dynamic influence factor to obtain the target anomaly score. For example, after obtaining the initial anomaly score, instead of directly using the initial anomaly score as the target anomaly score, the target suppression coefficient is used to suppress the initial anomaly score, that is, reduce the initial anomaly score, so as to consider the historical false alarm situation and suppress the current score. The greater the target suppression coefficient, the higher the degree of weakening of the initial anomaly score. In addition, the initial anomaly score can also be adjusted using the dynamic influence factor, considering the influence of the environment on the initial anomaly score.

[0293] Exemplarily, the initial anomaly score, the target suppression coefficient, and the dynamic influence factor can be fused to calculate the final alarm score (i.e., the target anomaly score). For example, the following formula (13) can be used to determine the target anomaly score. Of course, formula (13) is only an example and is not limited thereto.

[0294] final_score = dl_score×(1−final_confidence)×factor Formula (13)

[0295] In formula (13),final_score Represents the target anomaly score, dl_score Represents the initial anomaly score, reflecting the probability that the current signal is determined to be an intrusion by the anomaly detection model. final_confidence Represents the target suppression coefficient, factor which can represent a dynamic influence factor. (1−final_confidence) Indicates that considering the historical false alarm situation, the current score is suppressed. The larger the suppression coefficient, the higher the degree of weakening. factor Indicates that the score is dynamically adjusted according to the analysis result, amplifying possible intrusion signals and suppressing possible natural interference.

[0296] Regarding the dynamic influence factor factor , the type of the current signal can be determined according to the pattern recognition result (i.e., the detection result of the anomaly detection model). For example, the type of the current signal can be natural interference, intrusion threat, and others. Natural interference can be environmental noises such as wind blowing and rain hitting, intrusion threats can be intrusion behaviors such as climbing and destruction, and others can be signals that are not clearly classified. Based on this, for the signal type of natural interference, when calculating the dynamic influence factor factor , the calculation can be suppressed to reduce the impact on the total score. For the signal type of intrusion threat, when calculating the dynamic influence factor factor , the calculation can be amplified to enhance the impact on the total score. For the signal type of others, when calculating the dynamic influence factor factor , the dynamic influence factor factor can be kept unchanged. For example, the dynamic influence factor factor is kept as 1.

[0297] In summary, if the initial anomaly score is not greater than the threshold (i.e., the detection result of the anomaly detection model indicates that the type of the current signal is natural interference), the dynamic influence factor can be the value of the third factor, and the value of the third factor is used to reduce the impact on the initial anomaly score, such as the value of the third factor is less than 1. If the initial anomaly score is greater than the threshold (i.e., the detection result of the anomaly detection model indicates that the type of the current signal is an intrusion threat), the dynamic influence factor can be the value of the fourth factor, and the value of the fourth factor is used to enhance the impact on the initial anomaly score, such as the value of the fourth factor is greater than 1. Obviously, the value of the third factor can be less than the value of the fourth factor.

[0298] Step 809: Determine whether the vibration alarm is a false alarm or a valid alarm based on the target anomaly score. For example, if the target anomaly score is not greater than the threshold, the vibration alarm can be determined as a false alarm, that is, the vibration alarm is an incorrect alarm result and does not trigger an alarm. If the target anomaly score is greater than the threshold, the vibration alarm can be determined as a valid alarm, that is, the vibration alarm is a correct alarm result and triggers an alarm. Regarding this threshold, it can be determined according to the system performance requirements and on-site environment debugging, and there is no limit to this.

[0299] Exemplarily, for the attenuation coefficient in step 805 α , the attenuation coefficient α is used to control the descending speed of the progressive curve and can be adjusted according to the characteristics of historical data. For the target gain adjustment factor (night_gain) in step 806, it can be appropriately adjusted according to the characteristics of the night environment to avoid excessive amplification or suppression. For the alarm threshold in step 809 ( Dt ), the false negative rate and false positive rate can be weighed to select an appropriate threshold.

[0300] Exemplarily, based on the above technical solution, multi-source information can be fused, and the initial anomaly score can be dynamically adjusted according to real-time conditions, so as to adapt to the complex and changeable environment and achieve dynamic adjustment. By introducing the target suppression coefficient and the dynamic influence factor, the false alarms caused by environmental noise and historical false alarms are reduced, and the false positive rate is lowered. The advantages of the anomaly detection model and the signal processing result can be combined to improve the reliability of the alarm decision-making and enhance the accuracy of the alarm decision-making.

[0301] In a possible implementation manner, based on the initial anomaly score and the false alarm confidence, the target anomaly score can be determined by the result fusion decision maker. Refer to Figure 8B shown in the structural schematic diagram of the result fusion decision maker. The result fusion decision maker can include an input layer, a processing layer, and a fusion layer.

[0302] For the input layer, the input data can include the deep learning anomaly score (dl_score), the historical analysis result (history_result), and the time context (time_context). The deep learning anomaly score can be the initial anomaly score, which is the signal confidence score output by the anomaly detection model and ranges from 0 to 1, indicating the probability that the current signal is determined to be an intrusion. The historical analysis result can be the false alarm confidence. The time context can represent the current time information and is used for day-night gain adjustment, etc., to help the system adapt to the characteristics of different time periods.

[0303] For the processing layer, it can involve historical analysis suppression calculation and dynamic influence factor calculation. In the historical analysis suppression calculation process, the first suppression coefficient can be determined based on the false alarm confidence, the second suppression coefficient can be determined based on the first suppression coefficient, the third suppression coefficient can be determined based on the second suppression coefficient and the attenuation coefficient, the target gain adjustment factor can be determined, and the target suppression coefficient can be determined based on the third suppression coefficient and the target gain adjustment factor.

[0304] In the dynamic influence factor calculation process, the dynamic influence factor can be calculated factorFor example, if the detection result of the anomaly detection model indicates that the type of the current signal is natural interference, then the calculation is suppressed, and the dynamic influence factor is the value of the third factor. The calculation method of the value of the third factor can be as follows: factor = 1 - confidence*0.5 , confidence The first suppression coefficient, the second suppression coefficient, the third suppression coefficient or the target suppression coefficient can be adopted. Of course, the above are only examples for determining the value of the third factor, and the value of the third factor is less than 1.

[0305] If the detection result of the anomaly detection model indicates that the type of the current signal is an intrusion threat, then the calculation can be amplified, and the dynamic influence factor can be the value of the fourth factor. And the calculation method of the value of the fourth factor can be as follows: factor = 1 + confidence*0.3 , confidence The first suppression coefficient, the second suppression coefficient, the third suppression coefficient or the target suppression coefficient is adopted. The above are examples of the value of the fourth factor, and the value of the fourth factor is greater than 1.

[0306] If the detection result of the anomaly detection model indicates that the type of the current signal is other (neither intrusion threat nor natural interference), then it can remain unchanged. For example, the dynamic influence factor can be 1, that is factor = 1 .

[0307] For the fusion layer, based on the target suppression coefficient, the dynamic influence factor and the initial anomaly score, fusion can be performed to obtain the target anomaly score, and the target anomaly score is used to decide whether there is a false alarm.

[0308] As can be seen from the above technical solutions, a parameter color card method is proposed, which converts multi-dimensional DSP parameters into a color grid image with a spatial structure, and through a mapping algorithm, an intuitive visual expression of signal features is realized. A heterogeneous data fusion method is proposed, which fuses structured data and unstructured data through a unified visual expression, and uses an anomaly detection model to capture the associated features of heterogeneous data, realizing more accurate event recognition.

[0309] Based on the above processing, higher accuracy and generalization are achieved with less data: through visual expression, the understanding and analysis of signal features are enhanced, which helps to quickly identify abnormal patterns. Compared with features such as spectrograms and waterfall diagrams, the DSP parameter color card has significant advantages in terms of training accuracy and generalization performance. This is because the parameter color card has undergone deep feature engineering processing, can more effectively extract and express the key features of vibration signals, and can still achieve a high detection accuracy and better generalization with less training data.

[0310] Based on the above processing, a unified expression of heterogeneous data is realized: the parameter color card method presents complex multi-dimensional parameter data in the form of an image, solving the problem that different types of data are difficult to process uniformly.

[0311] Based on the above processing, the synergistic effect of the fused features is achieved: by fusing the DSP parameter color card with features such as spectrograms and waterfall plots, the overall performance of the model reaches the best, which indicates that there is a synergistic effect between different features, and the fused utilization can further enhance the adaptability and robustness of the model in complex scenarios.

[0312] As can be seen from the above technical solutions, it is possible to fuse historical data and comprehensively utilize long-term information. It is possible to implement multi-level false alarm determination, that is, introduce three-level false alarm determination mechanisms such as immediacy determination, relevance determination, and historicity determination to comprehensively evaluate alarm signals. It is possible to implement a dynamic adjustment mechanism to enhance environmental adaptability, that is, comprehensively consider the influence of environmental factors (such as weather changes, seasonal factors, surrounding activities, etc.) on vibration signals, establish an association model between environmental factors and alarm features, and implement a dynamic adjustment mechanism for system parameters. It is possible to achieve progressive system optimization and self-learning ability, that is, have progressive optimization ability, continuously adjust and optimize its own parameters according to real-time feedback and historical data, and achieve self-learning.

[0313] Based on the above processing, it is possible to avoid the common sense errors of the model from a global perspective: by deeply mining historical data within a long time range, it is possible to more comprehensively grasp the spatio-temporal evolution characteristics of signals, improve the recognition accuracy of abnormal events, and reduce false alarms caused by short-term anomalies or noises. It can adaptively adjust to environmental changes: it can automatically adapt to environmental changes, maintain the stability of detection performance, and avoid false alarms or missed alarms caused by environmental factors. It can reduce maintenance costs: without frequent manual intervention, it reduces maintenance costs and can operate stably in complex and changeable actual environments for a long time.

[0314] As can be seen from the above technical solutions, it is possible to implement a model optimization method that fuses multiple loss functions, design a comprehensive loss function that fuses reconstruction loss, knowledge distillation loss, and classification loss, and achieve the collaborative improvement of the model under multiple tasks by simultaneously optimizing the reconstruction ability, knowledge transfer ability, and classification performance of the model. Based on the above processing, it is possible to reduce the forgetting level of the model: the knowledge distillation loss encourages the student model to learn the deep knowledge of the teacher model and maintain the memory of the learned knowledge during incremental training. It can improve the accuracy of anomaly detection: the reconstruction loss and the classification loss are jointly learned to improve the accuracy and reliability of anomaly detection.

[0315] As can be seen from the above technical solutions, a multi-level false alarm determination mechanism can be introduced, combined with a progressive suppression strategy, to dynamically adjust the suppression coefficient. By combining signal processing and image processing, an intuitive visual expression of the vibration signal characteristics can be achieved, providing a basis for anomaly detection. Four types of complementary heterogeneous data are integrated: (1) phase data containing rich acoustic features and their corresponding Mel spectrograms, used to accurately characterize the characteristic patterns of various vibration events; (2) power spectral data reflecting the spatial energy distribution of the signal and their corresponding waterfall plots, used to effectively distinguish intrusion behaviors from natural disturbances; (3) DSP parameters providing multi-dimensional feature representations such as the time domain and frequency domain of the signal and their color card visualizations, to achieve accurate classification of different types of vibration events and provide an interpretable decision-making basis; (4) time series data of historical alarm statistical parameters containing long-term operation experience knowledge, providing a reliable historical basis for model decision-making. By constructing a unified data expression framework, the deep fusion of these heterogeneous data is achieved, which not only retains the unique advantages of each type of data but also fully exploits their complementarity. This multi-dimensional and multi-scale data fusion scheme not only significantly improves the generalization ability of the algorithm but also enables a high detection rate and a low false alarm rate, and greatly reduces the amount of data required for model training.

[0316] Based on the same application concept as the above method, in an embodiment of the present application, an intrusion detection device based on a vibrating optical fiber is proposed, which is applied to a management device of the vibrating optical fiber. The vibrating optical fiber includes a plurality of optical fiber units. Refer to Figure 9A As shown, it is a schematic structural diagram of the device. The device may include:

[0317] An acquisition module 911, configured to obtain time series statistical parameters based on target alarm data of a target optical fiber unit when a vibration alarm is triggered by the target optical fiber unit. The target optical fiber unit is any one of the plurality of optical fiber units, and the time series statistical parameters include at least one of an immediacy parameter, a correlation parameter, and a historicity parameter; wherein, the immediacy parameter represents multi-dimensional parameters of the target alarm data, the correlation parameter represents a correlation parameter between the target alarm data and alarms in adjacent regions, and the historicity parameter represents a correlation parameter between the target alarm data and historical alarm data;

[0318] A determination module 912, configured to determine a false alarm confidence level corresponding to the vibration alarm based on the time series statistical parameters;

[0319] A determination module 913, configured to determine whether the vibration alarm is a false alarm or a valid alarm based on the false alarm confidence level.

[0320] Exemplarily, the immediacy parameter includes at least one of a signal dimension matching degree, an environment correlation dimension matching degree, and a spatio-temporal consistency dimension matching degree; when obtaining the signal dimension matching degree, the obtaining module 911 is specifically configured to: extract features from the target alarm data to obtain current signal features; determine a first similarity between the current signal features and sample signal features, and determine the signal dimension matching degree based on the first similarity; wherein, the sample signal features are obtained by extracting features from alarm data in a non-intrusion scenario. When obtaining the environment correlation dimension matching degree, the obtaining module 911 is specifically configured to: if the target alarm data includes target environment data corresponding to the target optical fiber unit, extract features from the target environment data to obtain current environment features; determine a second similarity between the current environment features and sample environment features, and determine the environment correlation dimension matching degree based on the second similarity; wherein, the sample environment features are obtained by extracting features from environment data in a non-intrusion scenario. When obtaining the spatio-temporal consistency dimension matching degree, the obtaining module 911 is specifically configured to: if the target alarm data includes a target alarm time and a target alarm location, determine a first false alarm probability corresponding to the target alarm time, determine a second false alarm probability corresponding to the target alarm location, and perform a weighted operation on the first false alarm probability and the second false alarm probability to obtain the spatio-temporal consistency dimension matching degree; multiple times in the time dimension respectively correspond to false alarm probabilities, and multiple positions in the space dimension respectively correspond to false alarm probabilities.

[0321] Exemplarily, when obtaining the correlation parameter, the obtaining module 911 is specifically configured to: determine a plurality of associated optical fiber units corresponding to the target optical fiber unit, the distance between each associated optical fiber unit and the target optical fiber unit is less than a distance threshold, and each associated optical fiber unit triggers a vibration alarm; if the target alarm data includes the vibration intensity of the target optical fiber unit, determine the correlation parameter based on the vibration intensity of the target optical fiber unit, the vibration intensity of each associated optical fiber unit, the distance attenuation coefficient corresponding to each associated optical fiber unit, and the total number of associated optical fiber units;

[0322] Wherein, for each associated optical fiber unit, the distance attenuation coefficient is determined based on the linear attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit, or the distance attenuation coefficient is determined based on the exponential attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit.

[0323] Exemplarily, the historical parameter includes at least one of a time pattern matching degree, a space pattern matching degree, and an environment pattern matching degree; when the obtaining module 911 obtains the time pattern matching degree, it is specifically configured to: if the target alarm data includes a target alarm time, determine a first statistical feature of the target alarm time and a second statistical feature of a historical false alarm time based on the target alarm data and the historical alarm data, and determine the time pattern matching degree based on the first statistical feature and the second statistical feature; wherein, the historical false alarm time is the alarm time indicating the existence of vibration alarm false alarms in the historical alarm data. When the obtaining module 911 obtains the space pattern matching degree, it is specifically configured to: if the target alarm data includes a target alarm location, determine the target alarm location and a plurality of historical false alarm locations based on the target alarm data and the historical alarm data, where each historical false alarm location is the alarm location indicating the existence of vibration alarm false alarms in the historical alarm data; determine the space pattern matching degree based on the spatial overlap degree between the target alarm location and each historical false alarm location. When the obtaining module 911 obtains the environment pattern matching degree, it is specifically configured to: if the target alarm data includes target environment data, determine a current environment feature corresponding to the target environment data and a historical false alarm environment feature based on the target alarm data and the historical alarm data, where the historical false alarm environment feature is the environment feature indicating the existence of vibration alarm false alarms in the historical alarm data; determine the environment pattern matching degree based on the current environment feature and the historical false alarm environment feature.

[0324] Exemplarily, when the determining module 912 determines the false alarm confidence level corresponding to the vibration alarm based on the time series statistical parameter, it is specifically configured to: determine a comprehensive false alarm score based on the time series statistical parameter; wherein, if the time series statistical parameter includes an immediacy parameter, a relevance parameter, and a historical parameter, perform a weighted operation on the immediacy score, the relevance score, and the historical score to obtain the comprehensive false alarm score; wherein, if the immediacy parameter includes a signal dimension matching degree, an environment relevance dimension matching degree, and a spatio-temporal consistency dimension matching degree, perform a weighted operation on the signal dimension matching degree, the environment relevance dimension matching degree, and the spatio-temporal consistency dimension matching degree to obtain the immediacy score; determine the relevance score based on the relevance parameter; if the historical parameter includes a time pattern matching degree, a space pattern matching degree, and an environment pattern matching degree, perform a weighted operation on the time pattern matching degree, the space pattern matching degree, and the environment pattern matching degree to obtain the historical score; determine the false alarm confidence level based on the comprehensive false alarm score; wherein, the false alarm confidence level is proportional to the comprehensive false alarm score.

[0325] Exemplarily, when determining the false alarm confidence based on the comprehensive false alarm score, the determining module 912 is specifically configured to: determine the false alarm confidence by using the following formula: ; where C represents the false alarm confidence, λ represents a configured adjustment coefficient, FS represents the comprehensive false alarm score, C The value range of is [0, 1], C The closer it is to 1, the greater the possibility of a false alarm.

[0326] When determining whether the vibration alarm is a false alarm or a valid alarm based on the false alarm confidence, the determining module 913 is specifically configured to: if the false alarm confidence is not less than the threshold, determine that the vibration alarm is a false alarm; if the false alarm confidence is less than the threshold, determine that the vibration alarm is a valid alarm.

[0327] Exemplarily, when the target optical fiber unit triggers a vibration alarm, the obtaining module 911 is further configured to obtain the phase data and power spectrum data corresponding to the target optical fiber unit; determine a Mel spectrogram based on the phase data, and determine a waterfall plot based on the power spectrum data; obtain DSP parameters based on the phase data and the power spectrum data, and convert the DSP parameters into a color grid image;

[0328] The intrusion detection device based on vibrating optical fiber further includes: a processing module, configured to splice the Mel spectrogram, the waterfall plot, and the color grid image in the channel dimension to obtain a spliced image; input the spliced image into an anomaly detection model to obtain an initial anomaly score; the determining module 913 is further configured to determine whether the vibration alarm is a false alarm or a valid alarm based on the initial anomaly score.

[0329] Exemplarily, when the obtaining module 911 converts the DSP parameters into a color grid image, it is specifically configured to: convert the DSP parameters into a parameter matrix, where the parameter matrix includes multiple parameter values; generate a grid image, where the grid image includes multiple grids; the height dimension of the grid is determined based on the height of the color grid image and the number of horizontal elements of the parameter matrix, and the width dimension of the grid is determined based on the width of the color grid image and the number of vertical elements of the parameter matrix; for each parameter value in the parameter matrix, determine the grid corresponding to the parameter value in the grid image, normalize the parameter value to a specified numerical interval, and fill the normalized parameter value into the grid; multiple parameter values in the parameter matrix correspond to multiple grids in the grid image one by one; perform a visualization conversion on the grayscale image to obtain the color grid image; where, after filling all the normalized parameter values into the grid image, the grayscale image is obtained.

[0330] Exemplarily, when converting the DSP parameters into a parameter matrix, the obtaining module 911 is specifically configured to: for each of the continuous N frames, obtain the DSP parameters of this frame, where the DSP parameters of this frame are obtained based on the phase data and power spectrum data of this frame, and the DSP parameters of this frame include m parameter values; use the m parameter values of each frame as a row of the parameter matrix to obtain the parameter matrix; where the parameter matrix is a matrix with N rows and m columns; or, use the m parameter values of each frame as a column of the parameter matrix to obtain the parameter matrix; where the parameter matrix is a matrix with N columns and m rows; N is a positive integer, and m is a positive integer.

[0331] Exemplarily, when normalizing the parameter value to a specified numerical range, the obtaining module 911 is specifically configured to: if the specified numerical range is [0, 255], then use the following formula to normalize the parameter value to the specified numerical range: ; where G ij represents the normalized parameter value, P ij represents this parameter value, P min represents the minimum parameter value in the parameter matrix, P max represents the maximum parameter value in the parameter matrix;

[0332] When the obtaining module 911 performs visual conversion on the grayscale image to obtain the color grid image, it is specifically configured to: perform a smoothing operation on the grayscale image using a configured smoothing kernel to obtain a smoothed grayscale image, and perform a visual conversion on the smoothed grayscale image to obtain the color grid image.

[0333] Exemplarily, when the processing module inputs the spliced image into the anomaly detection model to obtain an initial anomaly score, it is specifically configured to: input the spliced image into the anomaly detection model to obtain a reconstructed image corresponding to the spliced image, and determine the initial anomaly score based on the difference between the reconstructed image and the spliced image; when the determination module 913 determines whether the vibration alarm is a false alarm or a valid alarm based on the initial anomaly score, it is specifically configured to: if the initial anomaly score is not greater than the threshold, determine the vibration alarm as a false alarm; if the initial anomaly score is greater than the threshold, determine the vibration alarm as a valid alarm.

[0334] Exemplarily, the processing module is further configured to train the anomaly detection model based on the configured initial detection model. When the processing module trains the anomaly detection model, it is specifically configured to: obtain sample Mel spectrograms, sample waterfall plots, and sample color grid images, splice the sample Mel spectrograms, the sample waterfall plots, and the sample color grid images in the channel dimension to obtain a spliced sample image; input the spliced sample image into the initial detection model to obtain a first reconstructed sample image and a predicted label, and input the spliced sample image into the trained classroom detection model corresponding to the initial detection model to obtain a second reconstructed sample image; determine a reconstruction loss value based on the difference between the first reconstructed sample image and the spliced sample image, determine a knowledge distillation loss value based on the difference between the first reconstructed sample image and the second reconstructed sample image, and determine a classification loss value based on the difference between the predicted label and the true label of the spliced sample image; determine a target loss value based on the reconstruction loss value, the knowledge distillation loss value, and the classification loss value, and adjust the parameters of the initial detection model based on the target loss value to obtain an adjusted model; if the adjusted model has converged, determine the adjusted model as the anomaly detection model; if the adjusted model has not converged, determine the adjusted model as the initial detection model, and return to execute inputting the spliced sample image into the initial detection model.

[0335] Exemplarily, the determining module 912 is further configured to determine a target suppression coefficient based on the false alarm confidence, and adjust the initial anomaly score based on the target suppression coefficient and the configured dynamic influence factor to obtain a target anomaly score; the determining module 913 is further configured to, in the process of determining whether the vibration alarm is a false alarm or a valid alarm, if the target anomaly score is not greater than the threshold, determine the vibration alarm as a false alarm; if the target anomaly score is greater than the threshold, determine the vibration alarm as a valid alarm.

[0336] Exemplarily, when the determining module 912 determines the target suppression coefficient based on the false alarm confidence, it is specifically configured to: determine a first suppression coefficient based on the false alarm confidence, and the first suppression coefficient is proportional to the false alarm confidence; determine a second suppression coefficient based on the first suppression coefficient, a time adjustment factor, a space adjustment factor, and an environment adjustment factor; determine a third suppression coefficient based on the second suppression coefficient and the configured attenuation coefficient; determine a target gain adjustment factor corresponding to the target alarm time of the vibration alarm, and determine the target suppression coefficient based on the third suppression coefficient and the target gain adjustment factor.

[0337] Exemplarily, when determining the target suppression coefficient based on the third suppression coefficient and the target gain adjustment factor, the determining module 912 is specifically configured to: if the product value between the third suppression coefficient and the target gain adjustment factor is less than a fixed value, determine the product value as the target suppression coefficient; if the product value is not less than the fixed value, determine the fixed value as the target suppression coefficient; wherein, if the target alarm time is within the configured night time interval, the target gain adjustment factor is a first factor value, and if the target alarm time is within the configured day time interval, the target gain adjustment factor is a second factor value, and the first factor value is greater than the second factor value.

[0338] Exemplarily, when adjusting the initial anomaly score to obtain a target anomaly score based on the target suppression coefficient and the configured dynamic influence factor, the determining module 912 is specifically configured to: determine the target anomaly score using the following formula: final_score = dl_score×(1−final_confidence)×factor ; wherein, final_score represents the target anomaly score, dl_score represents the initial anomaly score, final_confidence represents the target suppression coefficient, factor represents the dynamic influence factor; if the initial anomaly score is not greater than a threshold value, the dynamic influence factor is a third factor value, and if the initial anomaly score is greater than the threshold value, the dynamic influence factor is a fourth factor value; wherein, the third factor value is less than the fourth factor value.

[0339] Based on the same application concept as the above method, an electronic device is proposed in an embodiment of the present application. As shown in Figure 9B it includes: a processor 921 and a machine-readable storage medium 922. The machine-readable storage medium 922 stores machine-executable instructions that can be executed by the processor 921; the processor 921 is configured to execute the machine-executable instructions to implement the intrusion detection method based on vibration optical fiber disclosed in the above examples of the present application.

[0340] Based on the same application concept as the above method, an embodiment of the present application further provides a machine-readable storage medium. A number of computer instructions are stored on the machine-readable storage medium. When the computer instructions are executed by a processor, the intrusion detection method based on vibration optical fiber disclosed in the above examples of the present application can be implemented.

[0341] Among them, the above machine-readable storage medium can be any electronic, magnetic, optical or other physical storage device that can contain or store information, such as executable instructions, data, and so on. For example, the machine-readable storage medium can be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drives (such as hard disk drives), solid-state drives, any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or a combination thereof.

[0342] Based on the same application concept as the above method, an embodiment of the present application further provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, it implements the intrusion detection method based on vibrating optical fiber disclosed in the above examples of the present application.

[0343] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes. The above are only the embodiments of the present application and do not limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A vibrating optical fiber-based intrusion detection method, characterized in that: A management device for a vibrating optical fiber, wherein the vibrating optical fiber includes a plurality of optical fiber units, and the method includes: When a target optical fiber unit triggers a vibration alarm, a time series statistical parameter is obtained based on target alarm data of the target optical fiber unit, where the target optical fiber unit is any optical fiber unit, and the time series statistical parameter includes at least one of an immediacy parameter, a correlation parameter, and a history parameter; wherein the immediacy parameter represents a multi-dimensional parameter of the target alarm data, the correlation parameter represents a correlation parameter between the target alarm data and alarms in adjacent areas, and the history parameter represents a correlation parameter between the target alarm data and historical alarm data; and a false alarm confidence level corresponding to the vibration alarm is determined based on the time series statistical parameter; Obtaining phase data and power spectrum data corresponding to the target optical fiber unit, determining a mel spectrum graph based on the phase data, and determining a waterfall graph based on the power spectrum data; obtaining DSP parameters based on the phase data and the power spectrum data, and converting the DSP parameters into a color grid image; performing channel-dimensional splicing on the mel spectrum graph, the waterfall graph, and the color grid image to obtain a spliced image; and inputting the spliced image into an anomaly detection model to obtain an initial anomaly score; The vibration alarm is determined to be a false alarm or a valid alarm based on the false alarm confidence and the initial anomaly score; wherein, a target suppression coefficient is determined based on the false alarm confidence, and the initial anomaly score is adjusted based on the target suppression coefficient and a configured dynamic impact factor to obtain a target anomaly score; if the target anomaly score is not greater than a threshold, the vibration alarm is determined to be a false alarm; if the target anomaly score is greater than the threshold, the vibration alarm is determined to be a valid alarm.

2. The method according to claim 1, characterized in that The immediacy parameter includes at least one of a signal dimension matching degree, an environment correlation dimension matching degree, and a spatiotemporal consistency dimension matching degree; The process of obtaining the signal dimension matching degree includes: extracting features from the target alarm data to obtain current signal features; determining a first similarity between the current signal features and sample signal features, and determining the signal dimension matching degree based on the first similarity; wherein the sample signal features are obtained by extracting features from alarm data in a non-intrusion scenario; The process of obtaining the environmental correlation dimension matching degree includes: if the target alarm data includes target environmental data corresponding to the target optical fiber unit, extracting features from the target environmental data to obtain current environmental features; determining a second similarity between the current environmental features and sample environmental features, and determining the environmental correlation dimension matching degree based on the second similarity; wherein the sample environmental features are obtained by extracting features from environmental data in a non-invasive scenario; Among them, the process of obtaining the matching degree of the spatiotemporal consistency dimension includes: if the target alarm data includes the target alarm time and the target alarm position, then determining the first false alarm probability corresponding to the target alarm time, determining the second false alarm probability corresponding to the target alarm position, and performing a weighted operation on the first false alarm probability and the second false alarm probability to obtain the matching degree of the spatiotemporal consistency dimension; wherein, multiple times on the time dimension correspond to false alarm probabilities respectively, and multiple positions on the space dimension correspond to false alarm probabilities respectively.

3. The method according to claim 1, characterized in that The process of obtaining the correlation parameters includes: Determine multiple associated optical fiber units corresponding to the target optical fiber unit, wherein a distance between each associated optical fiber unit and the target optical fiber unit is less than a distance threshold, and each associated optical fiber unit triggers a vibration alarm; If the target alarm data includes the vibration intensity of the target optical fiber unit, determining the correlation parameter based on the vibration intensity of the target optical fiber unit, the vibration intensity of each associated optical fiber unit, the distance attenuation coefficient corresponding to each associated optical fiber unit, and the total number of associated optical fiber units; For each associated optical fiber unit, the distance attenuation coefficient is determined based on a linear attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit, or the distance attenuation coefficient is determined based on an exponential attenuation value of the distance between the associated optical fiber unit and the target optical fiber unit.

4. The method according to claim 1, wherein The historical parameter includes at least one of a temporal pattern matching degree, a spatial pattern matching degree, and an environmental pattern matching degree; The process of obtaining the time pattern matching degree includes: if the target alarm data includes a target alarm time, determining a first statistical feature of the target alarm time and a second statistical feature of a historical false alarm time based on the target alarm data and the historical alarm data, and determining the time pattern matching degree based on the first statistical feature and the second statistical feature; wherein the historical false alarm time is an alarm time at which a vibration alarm false alarm exists as indicated in the historical alarm data; The process of obtaining the spatial pattern matching degree includes: if the target alarm data includes a target alarm position, determining the target alarm position and multiple historical false alarm positions based on the target alarm data and the historical alarm data, wherein each historical false alarm position is an alarm position where a vibration alarm false alarm exists as indicated in the historical alarm data; and determining the spatial pattern matching degree based on the spatial overlap between the target alarm position and each historical false alarm position; Among them, the process of obtaining the environmental pattern matching degree includes: if the target alarm data includes target environmental data, then determining the current environmental characteristics and historical false alarm environmental characteristics corresponding to the target environmental data based on the target alarm data and the historical alarm data, wherein the historical false alarm environmental characteristics are environmental characteristics indicating the presence of vibration alarm false alarms in the historical alarm data; and determining the environmental pattern matching degree based on the current environmental characteristics and the historical false alarm environmental characteristics.

5. The method according to claim 1, wherein The determining, based on the time series statistical parameter, a false alarm confidence level corresponding to the vibration alarm, includes: Determining a comprehensive false alarm score based on the time series statistical parameters; wherein, if the time series statistical parameters include an immediacy parameter, a relevance parameter, and a history parameter, performing a weighted operation on the immediacy score, the relevance score, and the history score to obtain a comprehensive false alarm score; wherein, if the immediacy parameter includes a signal dimension matching degree, an environmental correlation dimension matching degree, and a spatiotemporal consistency dimension matching degree, performing a weighted operation on the signal dimension matching degree, the environmental correlation dimension matching degree, and the spatiotemporal consistency dimension matching degree to obtain an immediacy score; determining a relevance score based on the relevance parameter; if the history parameter includes a time pattern matching degree, a space pattern matching degree, and an environment pattern matching degree, performing a weighted operation on the time pattern matching degree, the space pattern matching degree, and the environment pattern matching degree to obtain a history score; determining the false alarm confidence level based on the combined false alarm score; The false alarm confidence is proportional to the comprehensive false alarm score.

6. The method according to claim 1, characterized in that The converting of the DSP parameters into a color grid image comprises: Converting the DSP parameters into a parameter matrix, wherein the parameter matrix includes a plurality of parameter values; Generate a grid image, the grid image comprising a plurality of grids; wherein the height of the grid is determined based on the height of the color grid image and the number of horizontal elements of the parameter matrix, and the width of the grid is determined based on the width of the color grid image and the number of vertical elements of the parameter matrix; For each parameter value in the parameter matrix, determine the grid corresponding to the parameter value in the grid image, normalize the parameter value to a specified numerical range, and fill the normalized parameter value into the grid; wherein the plurality of parameter values in the parameter matrix correspond one-to-one to the plurality of grids in the grid image; The grayscale image is visually converted to obtain the color grid image; wherein, the grayscale image is obtained after filling all normalized parameter values into the grid image.

7. The method according to claim 1, characterized in that Inputting the spliced image to an anomaly detection model to obtain an initial anomaly score includes: inputting the spliced image to an anomaly detection model to obtain a reconstructed image corresponding to the spliced image, and determining the initial anomaly score based on a difference between the reconstructed image and the spliced image.

8. The method according to claim 7, characterized in that Based on the configured initial detection model, the training process of the anomaly detection model includes: Obtain a sample mel-spectrogram, a sample waterfall diagram, and a sample color grid image, and perform channel-dimensional splicing on the sample mel-spectrogram, the sample waterfall diagram, and the sample color grid image to obtain a sample spliced image; input the sample spliced image to the initial detection model to obtain a first sample reconstructed image and a predicted label, and input the sample spliced image to a trained classroom detection model corresponding to the initial detection model to obtain a second sample reconstructed image; Determine a reconstruction loss value based on a difference between the first sample reconstructed image and the sample spliced image, determine a knowledge distillation loss value based on a difference between the first sample reconstructed image and the second sample reconstructed image, and determine a classification loss value based on a difference between the predicted label and the true label of the sample spliced image; determining a target loss value based on the reconstruction loss value, the knowledge distillation loss value, and the classification loss value, and adjusting parameters of the initial detection model based on the target loss value to obtain an adjusted model; If the adjusted model has converged, determining the adjusted model as the anomaly detection model; If the adjusted model does not converge, the adjusted model is determined as the initial detection model, and the process returns to executing the operation of inputting the sample spliced image into the initial detection model.

9. The method according to claim 1, characterized in that Determining a target suppression coefficient based on the false alarm confidence level includes: Determining a first suppression coefficient based on the false alarm confidence, the first suppression coefficient being proportional to the false alarm confidence; and determining a second suppression coefficient based on the first suppression coefficient, a configured time adjustment factor, a configured space adjustment factor, and a configured environment adjustment factor; determining a third suppression coefficient based on the second suppression coefficient and a configured attenuation coefficient; A target gain adjustment factor corresponding to a target alarm time of the vibration alarm is determined, and a target suppression coefficient is determined based on the third suppression coefficient and the target gain adjustment factor.

10. An intrusion detection device based on vibrating optical fiber, characterized in that: A management device for a vibrating optical fiber, wherein the vibrating optical fiber includes a plurality of optical fiber units, the device comprising: an acquisition module, configured to acquire, when a target optical fiber unit triggers a vibration alarm, a time series statistical parameter based on target alarm data of the target optical fiber unit, wherein the target optical fiber unit is any optical fiber unit among the multiple optical fiber units, and the time series statistical parameter includes at least one of an immediacy parameter, a correlation parameter, and a history parameter; wherein the immediacy parameter represents a multi-dimensional parameter of the target alarm data, the correlation parameter represents a correlation parameter between the target alarm data and an alarm in an adjacent area, and the history parameter represents a correlation parameter between the target alarm data and historical alarm data; A determination module, configured to determine a false alarm confidence level corresponding to the vibration alarm based on the time series statistical parameters; The acquisition module is further configured to acquire phase data and power spectrum data corresponding to the target optical fiber unit; determine a Mel spectrum graph based on the phase data, and determine a waterfall graph based on the power spectrum data; acquire DSP parameters based on the phase data and the power spectrum data, and convert the DSP parameters into a color grid image; a processing module, configured to perform channel-dimensional splicing on the mel-spectrogram, the waterfall plot, and the color grid image to obtain a spliced image; and input the spliced image into an anomaly detection model to obtain an initial anomaly score; A determination module is configured to determine whether the vibration alarm is a false alarm or a valid alarm based on the false alarm confidence level and the initial anomaly score; wherein the determination module is specifically configured to determine a target suppression coefficient based on the false alarm confidence level, and adjust the initial anomaly score based on the target suppression coefficient and a configured dynamic impact factor to obtain a target anomaly score; if the target anomaly score is not greater than a threshold, the vibration alarm is determined to be a false alarm; if the target anomaly score is greater than the threshold, the vibration alarm is determined to be a valid alarm.

11. An electronic device, characterized in that: include: a processor and a machine-readable storage medium storing machine-executable instructions capable of being executed by the processor; The processor is configured to execute machine-executable instructions to implement the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Multi-dimensional feature intrusion detection method based on distributed optical fibers

    CN115798131A

  • Optical fiber vibration abnormity identification method, apparatus and device, and computer program product

    CN117648632A