A digital management system and method for public security data based on artificial intelligence

By collecting data from multiple dimensions and using artificial intelligence analysis, combined with various monitoring methods and personnel feedback, monitoring blind spots are identified and corrected, solving the problems of decision-making blind spots and judgment errors in traditional public security management, and achieving more accurate and timely public security management.

CN120107050BActive Publication Date: 2025-10-31NANCHANG KERTE SOFTWARE TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510588464.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-08
Publication Date
2025-10-31
Estimated Expiration
2045-05-08

AI Technical Summary

Technical Problem

Traditional security management methods rely on a single data source and human experience, leading to blind spots in decision-making and affecting the efficiency and accuracy of security management. This can lead to judgment errors, especially when dealing with complex events. Furthermore, single-sensor threshold alarm mechanisms may overlook important information, affecting timeliness and public safety.

Method used

By employing multi-dimensional data collection and artificial intelligence analysis, and utilizing various monitoring methods such as video surveillance, sound sensors, and pedestrian flow monitoring, combined with feedback from relevant personnel, anomalies are identified and monitoring blind spots are corrected. Trigger mechanisms are set up to improve the accuracy and timeliness of decision-making.

Benefits of technology

It enables more accurate and timely identification and handling of public security incidents, reduces misjudgments, and improves the effectiveness of decision-making and the efficiency of resource utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120107050B_ABST
    Figure CN120107050B_ABST
Patent Text Reader

Abstract

This invention discloses an artificial intelligence-based digital management system and method for public security data, relating to the field of public security management technology. The management method includes the following steps: conducting multi-dimensional data collection on any public security event; identifying anomalies in the actual occurrence of any public security event based on processing feedback results; arbitrarily selecting public security events with normal evaluation results and identifying monitoring blind spots in each dimension; correcting the regional scope of each monitoring blind spot based on the differences in evaluation results between different public security events, and analyzing the feature values ​​of each dimension; setting triggering mechanisms for existing evaluation conflicts based on the differences in feature values ​​of each dimension; conducting multi-dimensional data collection on the target area in real time to obtain the feature values ​​of each dimension at the current moment; analyzing the triggering situation between the feature values ​​of each dimension and the evaluation conflict mechanism to determine whether a public security event exists at the current moment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of public security management technology, specifically to a digital management system and method for public security data based on artificial intelligence. Background Technology

[0002] With the acceleration of urbanization and the increasing complexity of social security, public security management faces more and more challenges. Traditional public security management methods often rely on human experience and a single data source, leading to blind spots in the decision-making process and affecting the efficiency and accuracy of public security management. Especially when dealing with complex public security incidents, one-dimensional decision-making may lead to judgment errors, which in turn affect the response and handling of incidents.

[0003] In the digital management system for public security data, the diversity and complexity of data make it impossible for single-dimensional data analysis to fully reflect the public security situation. Traditional systems rely on single sensor threshold alarm mechanisms, but if they rely solely on this data source, they may overlook other important information. For example, when the video analysis module detects abnormal behavior, but the sensors in the corresponding area do not respond, the system often falls into a decision-making deadlock. This decision-making blind spot not only affects the timeliness of public security management, but may also pose a threat to public safety. Summary of the Invention

[0004] The purpose of this invention is to provide a digital management system and method for public security data based on artificial intelligence, so as to solve the problems raised in the prior art.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a digital management method for public security data based on artificial intelligence, the management method comprising the following steps:

[0006] Step S100: Preset several monitoring methods to monitor security incidents occurring in the target area, and collect multi-dimensional data on any security incident; based on the handling feedback results of relevant personnel, identify anomalies in the actual occurrence of any security incident;

[0007] Step S200: Randomly select a public security event with a normal evaluation result, and identify the monitoring blind spots in each dimension; based on the differences in evaluation results between different public security events, correct the area range of each monitoring blind spot;

[0008] Step S300: Based on the area range of monitoring blind spots in different dimensions in any security incident, analyze the feature values ​​of each dimension; based on the differences in feature values ​​of each dimension, set a trigger mechanism for existing assessment conflicts;

[0009] Step S400: Conduct multi-dimensional data collection on the target area in real time to obtain the feature values ​​of each dimension at the current moment; analyze the triggering situation between the feature values ​​of each dimension and the assessment conflict mechanism to determine whether a security incident exists at the current moment.

[0010] Furthermore, step S100 includes the following steps:

[0011] Step S101: Set the monitoring data obtained by any monitoring method as the dimensional data of the corresponding dimension, and preset the corresponding anomaly identification rules for each dimension. Whenever at least one dimension of dimensional data is found to be abnormal after being identified by the anomaly identification rules, the dimension with abnormal dimensional data is set as the abnormal dimension. Different monitoring methods include video surveillance, sound sensor monitoring, people flow monitoring, and alarm alarms. The corresponding anomaly identification rules set for different monitoring methods are as follows: video surveillance and image recognition technology are used to capture user behavior characteristics and compare them with the behavior characteristics in the preset behavior database to determine whether there is an anomaly; sound sensors can monitor the intensity and frequency changes of abnormal sounds to determine whether there is an anomaly; people flow monitoring can determine whether there is an anomaly by the magnitude of changes in people flow.

[0012] Step S102: Obtain the monitoring range of each monitoring method in the target area and set it as the corresponding dimension region; extract the dimension region of any abnormal dimension and set it as the feature region. If there is a common area between the dimension region of other dimensions and the feature region of the abnormal dimension, set the dimension region of the other dimensions as the feature region; collect and summarize the dimension data of any dimension in each feature region to generate a security event.

[0013] Step S103: Whenever a security incident is generated, relevant personnel are dispatched to handle it, and the feedback results of the handling by the relevant personnel are collected. If there is an anomaly in the handling feedback results, the corresponding security incident is set as an abnormal security incident. An anomaly in the handling feedback results indicates that the security incident has not actually occurred. Therefore, an abnormal security incident represents a situation that has not occurred, while the regular security incidents in the subsequent steps represent security incidents that have actually occurred.

[0014] It is inaccurate to directly determine whether a security incident has actually occurred based solely on a single monitoring method. For example, if video surveillance identifies a user's movement as a fighting action, or if someone accidentally triggers an alarm device, relevant personnel need to handle the situation and provide feedback before it can be determined whether an incident has actually occurred. Therefore, the above steps illustrate that the anomaly identification of a single monitoring method is inaccurate, which leads to the need for a comprehensive evaluation method based on multiple monitoring sources.

[0015] Furthermore, step S200 includes the following steps:

[0016] Step S201: Define a security incident in which no abnormality is found in the processing feedback as a regular security incident. Select any regular security incident and set each dimension of each feature area monitored in the selected regular security record as the target dimension. Divide the target dimensions according to whether they are abnormal dimensions to obtain a normal dimension set and an abnormal dimension set.

[0017] Step S202: Randomly select an abnormal dimension from the abnormal dimension set to obtain the feature region corresponding to the selected abnormal dimension. Merge the feature regions of all abnormal dimensions to obtain a comprehensive abnormal region. Randomly select a normal dimension from the normal dimension set to obtain the common region between the selected normal dimension and the comprehensive abnormal region. Set the common region as a desired blind zone of the selected normal dimension and obtain the regional range of the desired blind zone in the target region.

[0018] Step S203: Set the selected normal dimension as the i-th dimension among all dimensions. Then, obtain the dimension region of the i-th dimension from the other regular security events. When the i-th dimension is a normal dimension, extract the common region between the dimension region of the i-th dimension and the comprehensive abnormal region of the regular security event. If there is an inclusion relationship between the common region of the i-th dimension and the expected blind zone, set the expected blind zone as the common region with a larger area. Otherwise, set the common region as another expected blind zone of the i-th dimension, and use the set expected blind zones as the monitoring blind zones of the i-th dimension.

[0019] Step S204: Randomly select an abnormal security event. If the i-th dimension of the selected abnormal security event is an abnormal dimension, then extract all normal dimensions that have a common area with the i-th dimension from the selected abnormal security event. If the monitoring blind zone of the i-th dimension includes the common area with the normal dimensions, set the included common area as the initial area, and then obtain each monitoring blind zone of the included normal dimensions. Here, the j-th monitoring blind zone in the i-th dimension is set as A1(i,j), and the k-th monitoring blind zone in the included normal dimensions is set as A2. k If the monitoring blind zone A2 k There is a common area A between the initial area and the common area A. pub1 Then, the public area A will be removed from the initial area. pub1 The removal process yields a corrected region.

[0020] Step S205: Compare the correction area with the monitoring blind zone A1(i,j). If there is a common area A between the two areas... pub2 Then, the public area A will be extracted from the monitoring blind zone A1(i,j).pub2 After removal, the corrected j-th monitoring blind zone A1 in the i-th dimension is obtained. ’ (i,j), and perform range correction for each monitoring blind zone of the i-th dimension;

[0021] Firstly, by identifying no abnormal data in the selected dimensions while abnormal data is detected in other dimensions, and assuming a security incident actually occurs, we can initially determine the monitoring blind spots of the selected dimensions. If, within the monitoring blind spots, abnormal data is detected in the corresponding other dimensions even though no security incident has occurred, but no abnormal data is detected in the selected dimensions, it indicates that the public area does not actually belong to the monitoring blind spots. The monitoring blind spots can then be corrected to obtain more accurate monitoring blind spots.

[0022] Furthermore, step S300 includes the following steps:

[0023] Step S301: Arbitrarily select the i-th dimension and obtain each monitoring blind zone after correction of the i-th dimension, wherein the area of ​​the j-th monitoring blind zone is set to S. (i,j) According to the formula:

[0024] ;

[0025] Where j is a positive integer and j∈(1,m), m is the number of monitoring blind spots contained in the i-th dimension, and S(i) is the monitoring range area of ​​the monitoring method corresponding to the i-th dimension in the target area; the proportion a of the first feature of the i-th dimension is calculated. i The first feature percentage represents the area percentage of the monitoring blind zone in any dimension, which is the probability of a judgment error. This is because anomalies occurring in the monitoring blind zone are likely to be missed.

[0026] Step S302: Divide all security incidents into a first event set and a second event set according to whether the i-th dimension is an anomalous dimension. In the first event set, the i-th dimension of each security incident is an anomalous dimension. Count the number of regular security incidents in each event set, and set the number of regular security incidents in the first event set as p1. i The number of regular security incidents in the second event set is p2 i According to the formula:

[0027] ;

[0028] Among them, n2 i Let N be the number of security incidents in the second event set, and N be the total number of all security incidents; calculate the proportion b of the second feature in the i-th dimension. iThe second feature percentage represents the accuracy of any dimension in the historical identification process. The higher the accuracy, the more effective the monitoring method corresponding to the dimension.

[0029] Step S303: Obtain the number of security events in the first event set as n1 i The anomaly frequency of the i-th dimension is calculated to be η = n1. i / N; According to the formula:

[0030] ;

[0031] The confidence score Z of the i-th dimension is calculated. i The confidence levels for each dimension are based on historical accuracy and the probability of accuracy in the assessment, which helps to make the obtained confidence levels more accurate and is beneficial for the subsequent development of anomaly detection mechanisms.

[0032] Step S304: Randomly select a security incident, and arbitrarily select the i-th dimension from the selected security incidents. If the i-th dimension is an abnormal dimension, obtain the preset anomaly identification rule for the i-th dimension, obtain the normal value range of the i-th dimension, extract the actual value of the i-th dimension in the selected security incidents, and obtain the anomaly offset magnitude F under the i-th dimension. i Let the confidence level of the i-th dimension be Z. i The feature value of the i-th dimension is calculated to be T. i =Z i ×(1+F i If the i-th dimension is a normal dimension, then the feature value T of the i-th dimension is obtained. i =Z i The eigenvalue reflects the degree of anomalies in the monitoring data under the corresponding dimension. Based on the confidence level, the larger the anomaly offset, the greater the probability that the anomaly actually occurs.

[0033] Step S305: Extract feature values ​​from each dimension of the selected security incident, and extract the minimum feature value T from all abnormal dimensions. min Extract the largest eigenvalue T from all normal dimensions max If a security incident is selected as a routine security incident, then the number of dimensions v in which the feature value is greater than or equal to the minimum feature value is counted. If a security incident is selected as an abnormal security incident, then the number of dimensions w in which the feature value is less than or equal to the maximum feature value is counted.

[0034] Step S306: Obtain the number of dimensions v with feature values ​​greater than or equal to the minimum feature value or the number of dimensions w with feature values ​​less than or equal to the maximum feature value in each security incident. Calculate the expected number of abnormal dimensions v by averaging the number of dimensions with feature values ​​greater than or equal to the minimum feature value.ax The expected number of normal dimensions w is obtained by averaging the number of dimensions whose eigenvalues ​​are less than or equal to the largest eigenvalue. ax The expected triggering mechanism for judging and evaluating conflict results is Max(v). ax ,w ax ), where Max() is the function to take the maximum value; the significance of the expected triggering mechanism is to divide the anomaly judgment method into two types. One is that if the number of abnormal dimensions exceeds the expected triggering mechanism at the same time, it indicates that a security incident has occurred. The other is that if the number of normal dimensions exceeds the expected triggering mechanism at the same time, it indicates that no security incident has occurred. However, whether to judge based on the number of abnormal dimensions or the number of normal dimensions needs to be dynamically adjusted based on the judgment situation of historical security incidents. The purpose of dividing into two judgment methods is to make the judgment result more accurate.

[0035] Furthermore, step S400 includes the following steps:

[0036] Step S401: Obtain monitoring data for each monitoring method in the target area at the current time, obtain dimensional data of arbitrary dimensions, and extract the abnormal dimensions existing at the current time; set the i-th dimension at the current time as the abnormal dimension, then the abnormal offset magnitude of the i-th dimension is (F i ) now And confidence value Z i The feature value of the i-th dimension is calculated as (T) i ) now =(F i ) now ×Z i ;

[0037] Step S402: Obtain the feature values ​​of each dimension at the current time. If the expected triggering mechanism for judging the conflict result at the current time is Max(v ax ,w ax )=v ax Then, obtain the minimum eigenvalue of each anomaly dimension, and count the number of dimensions whose eigenvalues ​​are greater than or equal to the minimum eigenvalue as v. now If v now ≥v ax If a security incident is detected at the current moment, it is determined that a security incident exists; if the desired trigger mechanism is Max(v) ax ,w ax )=w ax Then, obtain the maximum eigenvalue of each normal dimension, and count the number of dimensions whose eigenvalues ​​are less than or equal to the maximum eigenvalue as w. now If w now ≤v ax If so, it is determined that a public security incident exists at the current moment.

[0038] To better implement the above methods, a digital management system for public security data is also proposed. The management system includes a historical public security analysis module, a dimensional anomaly analysis module, a confidence conflict analysis module, and a real-time public security analysis module.

[0039] The historical security analysis module is used to monitor security incidents occurring in the target area using several preset monitoring methods, and to collect multi-dimensional data on any security incident; based on the feedback results of relevant personnel, it identifies anomalies in the actual occurrence of any security incident.

[0040] The dimensional anomaly analysis module is used to select any public security event with a normal evaluation result and identify monitoring blind spots in each dimension; based on the differences in evaluation results between different public security events, the area range of each monitoring blind spot is corrected;

[0041] The confidence conflict analysis module is used to analyze the feature values ​​of each dimension based on the area range of monitoring blind spots in any security incident; and to set trigger mechanisms for existing assessment conflicts based on the differences in feature values ​​of each dimension.

[0042] The real-time security analysis module is used to collect multi-dimensional data of the target area in real time, obtain the feature values ​​of each dimension at the current moment, analyze the triggering of each feature value and the assessment conflict mechanism, and determine whether a security incident exists at the current moment.

[0043] Furthermore, the historical security analysis module includes a historical data acquisition unit and a difference assessment and identification unit;

[0044] The historical data acquisition unit is used to monitor security incidents occurring in the target area using several preset monitoring methods, and to collect multi-dimensional data on any security incident; the difference assessment and identification unit is used to identify anomalies in the actual occurrence of any security incident based on the feedback results from relevant personnel.

[0045] Furthermore, the dimensional anomaly analysis module includes a dimensional blind zone identification unit and a blind zone range correction unit;

[0046] The dimensional blind spot identification unit is used to arbitrarily select public security events with normal evaluation results and identify the monitoring blind spots in each dimension; the blind spot range correction unit is used to correct the area range of each monitoring blind spot based on the differences in evaluation results between different public security events.

[0047] Furthermore, the confidence conflict analysis module includes a dimensional confidence assessment unit and an assessment conflict determination unit;

[0048] The dimensional confidence assessment unit is used to analyze the feature values ​​of each dimension based on the area range of the monitoring blind spots of different dimensions in any security incident; the assessment conflict determination unit is used to set a trigger mechanism for assessment conflicts based on the differences in feature values ​​of each dimension.

[0049] Furthermore, the real-time security analysis module includes a real-time data acquisition unit and an anomaly detection and identification unit;

[0050] The real-time data acquisition unit is used to collect multi-dimensional data of the target area in real time and obtain the feature values ​​of each dimension at the current moment; the anomaly judgment and identification unit is used to analyze the triggering situation between the feature values ​​of each dimension and the assessment conflict mechanism to determine whether there is a security incident at the current moment.

[0051] Compared with the prior art, the beneficial effects of the present invention are:

[0052] 1. This invention comprehensively analyzes data from various dimensions to reflect the occurrence of anomalies in the target area, enabling more accurate and effective analysis of whether a security incident has occurred. While ensuring the timeliness of security management, it can also eliminate some erroneous judgments and avoid waste of resources.

[0053] 2. This invention analyzes the monitoring blind spots in various dimensions, which can accurately obtain the actual effective monitoring area in each dimension. It provides an accurate understanding of the monitoring situation in the monitoring blind spots of each dimension, helps relevant personnel to make an effective judgment on abnormal data, and improves the effectiveness of decision-making.

[0054] 3. This invention evaluates the effectiveness and accuracy of different monitoring methods by analyzing the corresponding feature values ​​set in different dimensions, and then judges the actual occurrence of security incidents based on the quantitative relationship between abnormal and normal data. When there are differences in the judgment of abnormal situations by different monitoring methods, it can make accurate and rapid decisions and improve the timeliness of security management. Attached Figure Description

[0055] Figure 1 A schematic diagram illustrating the steps of a digital management method for public security data based on artificial intelligence;

[0056] Figure 2 This is a schematic diagram of the structure of a digital management system for public security data based on artificial intelligence. Detailed Implementation

[0057] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0058] Example: Figures 1 to 2 As shown, this invention provides a digital management method for public security data based on artificial intelligence. The management method includes the following steps:

[0059] Step S100: Preset several monitoring methods to monitor security incidents occurring in the target area, and collect multi-dimensional data on any security incident; based on the handling feedback results of relevant personnel, identify anomalies in the actual occurrence of any security incident;

[0060] Step S100 includes the following steps:

[0061] Step S101: Set the monitoring data obtained by any monitoring method as the dimension data of the corresponding dimension, and preset the corresponding anomaly identification rules for each dimension. Whenever there is an anomaly in the dimension data of at least one dimension after being identified by the anomaly identification rules, the dimension with the anomaly dimension data is set as the anomaly dimension.

[0062] Step S102: Obtain the monitoring range of each monitoring method in the target area and set it as the corresponding dimension region; extract the dimension region of any abnormal dimension and set it as the feature region. If there is a common area between the dimension region of other dimensions and the feature region of the abnormal dimension, set the dimension region of the other dimensions as the feature region; collect and summarize the dimension data of any dimension in each feature region to generate a security event.

[0063] Step S103: Whenever a security incident is generated, relevant personnel are dispatched to handle it, and the handling feedback results of the relevant personnel are collected. If there is an anomaly in the handling feedback results, the corresponding security incident is set as an abnormal security incident.

[0064] Step S200: Randomly select a public security event with a normal evaluation result, and identify the monitoring blind spots in each dimension; based on the differences in evaluation results between different public security events, correct the area range of each monitoring blind spot;

[0065] Step S200 includes the following steps:

[0066] Step S201: Define a security incident in which no abnormality is found in the processing feedback as a regular security incident. Select any regular security incident and set each dimension of each feature area monitored in the selected regular security record as the target dimension. Divide the target dimensions according to whether they are abnormal dimensions to obtain a normal dimension set and an abnormal dimension set.

[0067] Step S202: Randomly select an abnormal dimension from the abnormal dimension set to obtain the feature region corresponding to the selected abnormal dimension. Merge the feature regions of all abnormal dimensions to obtain a comprehensive abnormal region. Randomly select a normal dimension from the normal dimension set to obtain the common region between the selected normal dimension and the comprehensive abnormal region. Set the common region as a desired blind zone of the selected normal dimension and obtain the regional range of the desired blind zone in the target region.

[0068] Step S203: Set the selected normal dimension as the i-th dimension among all dimensions. Then, obtain the dimension region of the i-th dimension from the other regular security events. When the i-th dimension is a normal dimension, extract the common region between the dimension region of the i-th dimension and the comprehensive abnormal region of the regular security event. If there is an inclusion relationship between the common region of the i-th dimension and the expected blind zone, set the expected blind zone as the common region with a larger area. Otherwise, set the common region as another expected blind zone of the i-th dimension, and use the set expected blind zones as the monitoring blind zones of the i-th dimension.

[0069] Step S204: Randomly select an abnormal security event. If the i-th dimension of the selected abnormal security event is an abnormal dimension, then extract all normal dimensions that have a common area with the i-th dimension from the selected abnormal security event. If the monitoring blind zone of the i-th dimension includes the common area with the normal dimensions, set the included common area as the initial area, and then obtain each monitoring blind zone of the included normal dimensions. Here, the j-th monitoring blind zone in the i-th dimension is set as A1(i,j), and the k-th monitoring blind zone in the included normal dimensions is set as A2. k If the monitoring blind zone A2 k There is a common area A between the initial area and the common area A. pub1 Then, the public area A will be removed from the initial area. pub1 The removal process yields a corrected region.

[0070] Step S205: Compare the correction area with the monitoring blind zone A1(i,j). If there is a common area A between the two areas... pub2 Then, the public area A will be extracted from the monitoring blind zone A1(i,j). pub2After removal, the corrected j-th monitoring blind zone A1 in the i-th dimension is obtained. ’ (i,j), and perform range correction for each monitoring blind zone of the i-th dimension.

[0071] Step S300: Based on the area range of monitoring blind spots in different dimensions in any security incident, analyze the feature values ​​of each dimension; based on the differences in feature values ​​of each dimension, set a trigger mechanism for existing assessment conflicts;

[0072] Step S300 includes the following steps:

[0073] Step S301: Arbitrarily select the i-th dimension and obtain each monitoring blind zone after correction of the i-th dimension, wherein the area of ​​the j-th monitoring blind zone is set to S. (i,j) According to the formula:

[0074] ;

[0075] Where j is a positive integer and j∈(1,m), m is the number of monitoring blind spots contained in the i-th dimension, and S(i) is the monitoring range area of ​​the monitoring method corresponding to the i-th dimension in the target area; the proportion a of the first feature of the i-th dimension is calculated. i ;

[0076] Example 1: Assume that after correction, the i-th dimension has two monitoring blind spots, and the area of ​​each blind spot is 5m². 2 and 3m 2 The total area of ​​the target region is set to 50m. 2 Calculate the proportion a of the first feature in the i-th dimension. i =(5+3) / 50=16%;

[0077] Step S302: Divide all security incidents into a first event set and a second event set according to whether the i-th dimension is an anomalous dimension. In the first event set, the i-th dimension of each security incident is an anomalous dimension. Count the number of regular security incidents in each event set, and set the number of regular security incidents in the first event set as p1. i The number of regular security incidents in the second event set is p2 i According to the formula:

[0078] ;

[0079] Among them, n2 i Let N be the number of security incidents in the second event set, and N be the total number of all security incidents; calculate the proportion b of the second feature in the i-th dimension. i ;

[0080] Example 2: Given that the i-th dimension is an anomaly, the number of regular security incidents is 10, and given that the i-th dimension is a normal dimension, the number of regular security incidents is 20. Simultaneously, the number of security incidents in the i-th dimension that are normal is set to 50, and the total number of all security incidents is 100. This yields the proportion b of the second feature. i =(10+50-20) / 100=40%;

[0081] Step S303: Obtain the number of security events in the first event set as n1 i The anomaly frequency of the i-th dimension is calculated to be η = n1. i / N; According to the formula:

[0082] ;

[0083] The confidence score Z of the i-th dimension is calculated. i ;

[0084] Example 3: Given that the i-th dimension is an anomaly dimension, the number of security incidents is 50, and the total number of security incidents is 100. The anomaly frequency of the i-th dimension is 50%. Based on Examples 1 and 2, the proportion of the first feature is 16%, and the proportion of the second feature is 40%. The confidence level Z of the i-th dimension is then calculated. i =50%×16%+50%×40%=28%;

[0085] Step S304: Randomly select a security incident, and arbitrarily select the i-th dimension from the selected security incidents. If the i-th dimension is an abnormal dimension, obtain the preset anomaly identification rule for the i-th dimension, obtain the normal value range of the i-th dimension, extract the actual value of the i-th dimension in the selected security incidents, and obtain the anomaly offset magnitude F under the i-th dimension. i Let the confidence level of the i-th dimension be Z. i The feature value of the i-th dimension is calculated to be T. i =Z i ×(1+F i If the i-th dimension is a normal dimension, then the feature value T of the i-th dimension is obtained. i =Z i ;

[0086] Step S305: Extract feature values ​​from each dimension of the selected security incident, and extract the minimum feature value T from all abnormal dimensions. min Extract the largest eigenvalue T from all normal dimensions maxIf a security incident is selected as a routine security incident, then the number of dimensions v in which the feature value is greater than or equal to the minimum feature value is counted. If a security incident is selected as an abnormal security incident, then the number of dimensions w in which the feature value is less than or equal to the maximum feature value is counted.

[0087] Step S306: Obtain the number of dimensions v with feature values ​​greater than or equal to the minimum feature value or the number of dimensions w with feature values ​​less than or equal to the maximum feature value in each security incident. Calculate the expected number of abnormal dimensions v by averaging the number of dimensions with feature values ​​greater than or equal to the minimum feature value. ax The expected number of normal dimensions w is obtained by averaging the number of dimensions whose eigenvalues ​​are less than or equal to the largest eigenvalue. ax The expected triggering mechanism for judging and evaluating conflict results is Max(v). ax ,w ax ), where Max() is the function to find the maximum value.

[0088] Step S400: Conduct multi-dimensional data collection on the target area in real time to obtain the feature values ​​of each dimension at the current moment; analyze the triggering situation between the feature values ​​of each dimension and the assessment conflict mechanism to determine whether a security incident exists at the current moment;

[0089] Step S400 includes the following steps:

[0090] Step S401: Obtain monitoring data for each monitoring method in the target area at the current time, obtain dimensional data of arbitrary dimensions, and extract the abnormal dimensions existing at the current time; set the i-th dimension at the current time as the abnormal dimension, then the abnormal offset magnitude of the i-th dimension is (F i ) now And confidence value Z i The feature value of the i-th dimension is calculated as (T) i ) now =(F i ) now ×Z i ;

[0091] Step S402: Obtain the feature values ​​of each dimension at the current time. If the expected triggering mechanism for judging the conflict result at the current time is Max(v ax ,w ax )=v ax Then, obtain the minimum eigenvalue of each anomaly dimension, and count the number of dimensions whose eigenvalues ​​are greater than or equal to the minimum eigenvalue as v. now If v now ≥v ax If a security incident is detected at the current moment, it is determined that a security incident exists; if the desired trigger mechanism is Max(v) ax ,wax )=w ax Then, obtain the maximum eigenvalue of each normal dimension, and count the number of dimensions whose eigenvalues ​​are less than or equal to the maximum eigenvalue as w. now If w now ≤v ax If so, it is determined that a public security incident exists at the current moment.

[0092] A digital management system for public security data, comprising a historical public security analysis module, a dimensional anomaly analysis module, a confidence conflict analysis module, and a real-time public security analysis module;

[0093] The historical security analysis module is used to monitor security incidents occurring in the target area using several preset monitoring methods, and to collect multi-dimensional data on any security incident; based on the feedback results of relevant personnel, it identifies anomalies in the actual occurrence of any security incident.

[0094] The dimensional anomaly analysis module is used to select any public security event with a normal evaluation result and identify monitoring blind spots in each dimension; based on the differences in evaluation results between different public security events, the area range of each monitoring blind spot is corrected;

[0095] The confidence conflict analysis module is used to analyze the feature values ​​of each dimension based on the area range of monitoring blind spots in any security incident; and to set trigger mechanisms for existing assessment conflicts based on the differences in feature values ​​of each dimension.

[0096] The real-time security analysis module is used to collect multi-dimensional data of the target area in real time, obtain the feature values ​​of each dimension at the current moment, analyze the triggering of each feature value and the assessment conflict mechanism, and determine whether a security incident exists at the current moment.

[0097] The historical security analysis module includes a historical data collection unit and a difference assessment and identification unit.

[0098] The historical data acquisition unit is used to monitor security incidents occurring in the target area using several preset monitoring methods, and to collect multi-dimensional data on any security incident; the difference assessment and identification unit is used to identify anomalies in the actual occurrence of any security incident based on the feedback results from relevant personnel.

[0099] The dimensional anomaly analysis module includes a dimensional blind zone identification unit and a blind zone range correction unit.

[0100] The dimensional blind spot identification unit is used to arbitrarily select public security events with normal evaluation results and identify the monitoring blind spots in each dimension; the blind spot range correction unit is used to correct the area range of each monitoring blind spot based on the differences in evaluation results between different public security events.

[0101] The confidence conflict analysis module includes a dimensional confidence assessment unit and an assessment conflict determination unit.

[0102] The dimensional confidence assessment unit is used to analyze the feature values ​​of each dimension based on the area range of the monitoring blind spots of different dimensions in any security incident; the assessment conflict determination unit is used to set a trigger mechanism for assessment conflicts based on the differences in feature values ​​of each dimension.

[0103] The real-time security analysis module includes a real-time data acquisition unit and an anomaly detection and identification unit.

[0104] The real-time data acquisition unit is used to collect multi-dimensional data of the target area in real time and obtain the feature values ​​of each dimension at the current moment; the anomaly judgment and identification unit is used to analyze the triggering situation between the feature values ​​of each dimension and the assessment conflict mechanism to determine whether there is a security incident at the current moment.

[0105] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.

Claims

1. A method for digital management of public security data based on artificial intelligence, characterized in that: The management method includes the following steps: Step S100: Preset several monitoring methods to monitor security incidents occurring in the target area, and collect multi-dimensional data on any security incident; based on the handling feedback results of relevant personnel, identify anomalies in the actual occurrence of any security incident; Step S200: Randomly select a public security event with a normal evaluation result, and identify the monitoring blind spots in each dimension; based on the differences in evaluation results between different public security events, correct the area range of each monitoring blind spot; Step S300: Based on the area range of monitoring blind spots in different dimensions in any security incident, analyze the feature values ​​of each dimension; based on the differences in feature values ​​of each dimension, set a trigger mechanism for existing assessment conflicts; Step S400: Conduct multi-dimensional data collection on the target area in real time to obtain the feature values ​​of each dimension at the current moment; analyze the triggering situation between the feature values ​​of each dimension and the assessment conflict mechanism to determine whether a security incident exists at the current moment; Step S100 includes the following steps: Step S101: Set the monitoring data obtained by any monitoring method as the dimension data of the corresponding dimension, and preset the corresponding anomaly identification rules for each dimension. Whenever there is an anomaly in the dimension data of at least one dimension after being identified by the anomaly identification rules, the dimension with the anomaly dimension data is set as the anomaly dimension. Step S102: Obtain the monitoring range of each monitoring method in the target area and set it as the corresponding dimension region; extract the dimension region of any abnormal dimension and set it as the feature region. If there is a common area between the dimension region of other dimensions and the feature region of the abnormal dimension, set the dimension region of the other dimensions as the feature region; collect and summarize the dimension data of any dimension in each feature region to generate a security event. Step S103: Whenever a security incident is generated, relevant personnel are dispatched to handle it, and the feedback results of the handling by the relevant personnel are collected. If there is an anomaly in the handling feedback results, the corresponding security incident is set as an abnormal security incident. Step S200 includes the following steps: Step S201: Define a security incident in which no abnormality is found in the processing feedback as a regular security incident. Select any regular security incident and set each dimension of each feature area monitored in the selected regular security record as the target dimension. Divide the target dimensions according to whether they are abnormal dimensions to obtain a normal dimension set and an abnormal dimension set. Step S202: Randomly select an abnormal dimension from the abnormal dimension set to obtain the feature region corresponding to the selected abnormal dimension. Merge the feature regions of all abnormal dimensions to obtain a comprehensive abnormal region. Randomly select a normal dimension from the normal dimension set to obtain the common region between the selected normal dimension and the comprehensive abnormal region. Set the common region as a desired blind zone of the selected normal dimension and obtain the regional range of the desired blind zone in the target region. Step S203: Set the selected normal dimension as the i-th dimension among all dimensions. Then, obtain the dimension region of the i-th dimension from the other regular security events. When the i-th dimension is a normal dimension, extract the common area between the dimension region of the i-th dimension and the comprehensive abnormal area of ​​the regular security event. If there is an inclusion relationship between the common area of ​​the i-th dimension and the expected blind area, set the expected blind area as the common area with a larger range. Otherwise, set the common area as another expected blind area of ​​the i-th dimension, and use the set expected blind areas as the monitoring blind areas of the i-th dimension. Step S204: Randomly select an abnormal security event. If the i-th dimension of the selected abnormal security event is an abnormal dimension, then extract all normal dimensions that have a common area with the i-th dimension from the selected abnormal security event. If the monitoring blind zone of the i-th dimension includes the common area with the normal dimensions, set the included common area as the initial area, and then obtain each monitoring blind zone of the included normal dimensions. Here, the j-th monitoring blind zone in the i-th dimension is set as A1(i,j), and the k-th monitoring blind zone in the included normal dimensions is set as A2. k If the monitoring blind zone A2 k There is a common area A between the initial area and the common area A. pub1 Then, the public area A will be removed from the initial area. pub1 The removal process yields a corrected region. Step S205: Compare the correction area with the monitoring blind zone A1(i,j). If there is a common area A between the two areas... pub2 Then, the public area A will be extracted from the monitoring blind zone A1(i,j). pub2 After removal, the corrected j-th monitoring blind zone A1 in the i-th dimension is obtained. ’ (i,j), and perform range correction for each monitoring blind zone of the i-th dimension.

2. The method for digital management of public security data based on artificial intelligence according to claim 1, characterized in that: Step S300 includes the following steps: Step S301: Arbitrarily select the i-th dimension and obtain each monitoring blind zone after correction of the i-th dimension, wherein the area of ​​the j-th monitoring blind zone is set to S. (i,j) According to the formula: Where j is a positive integer and j∈(1,m), m is the number of monitoring blind spots contained in the i-th dimension, and S(i) is the monitoring range area of ​​the monitoring method corresponding to the i-th dimension in the target area; the proportion a of the first feature of the i-th dimension is calculated. i ; Step S302: Divide all security incidents into a first event set and a second event set according to whether the i-th dimension is an anomalous dimension. In the first event set, the i-th dimension of each security incident is an anomalous dimension. Count the number of regular security incidents in each event set, and set the number of regular security incidents in the first event set as p1. i The number of regular security incidents in the second event set is p2 i According to the formula: Where, n2 i Let N be the number of security incidents in the second event set, and N be the total number of all security incidents; calculate the proportion b of the second feature in the i-th dimension. i ; Step S303: Obtain the number of security events in the first event set as n1 i The anomaly frequency of the i-th dimension is calculated to be η = n1. i / N; According to the formula: Z i =(1-η)×(1-a i )+η×b i ; The confidence score Z of the i-th dimension is calculated. i ; Step S304: Randomly select a security incident, and arbitrarily select the i-th dimension from the selected security incidents. If the i-th dimension is an abnormal dimension, obtain the preset anomaly identification rule for the i-th dimension, obtain the normal value range of the i-th dimension, extract the actual value of the i-th dimension in the selected security incidents, and obtain the anomaly offset magnitude F under the i-th dimension. i Let the confidence level of the i-th dimension be Z. i The feature value of the i-th dimension is calculated to be T. i =Z i ×(1+F i If the i-th dimension is a normal dimension, then the feature value T of the i-th dimension is obtained. i =Z i ; Step S305: Extract feature values ​​from each dimension of the selected security incident, and extract the minimum feature value T from all abnormal dimensions. min Extract the largest eigenvalue T from all normal dimensions max If a security incident is selected as a routine security incident, then the number of dimensions v in which the feature value is greater than or equal to the minimum feature value is counted. If a security incident is selected as an abnormal security incident, then the number of dimensions w in which the feature value is less than or equal to the maximum feature value is counted. Step S306: Obtain the number of dimensions v with feature values ​​greater than or equal to the minimum feature value or the number of dimensions w with feature values ​​less than or equal to the maximum feature value in each security incident. Calculate the expected number of abnormal dimensions v by averaging the number of dimensions with feature values ​​greater than or equal to the minimum feature value. ax The expected number of normal dimensions w is obtained by averaging the number of dimensions whose eigenvalues ​​are less than or equal to the largest eigenvalue. ax The expected triggering mechanism for judging and evaluating conflict results is Max(v). ax ,w ax ), where Max() is the function to find the maximum value.

3. The method for digital management of public security data based on artificial intelligence according to claim 2, characterized in that: Step S400 includes the following steps: Step S401: Obtain monitoring data for each monitoring method in the target area at the current time, obtain dimensional data of arbitrary dimensions, and extract the abnormal dimensions existing at the current time; set the i-th dimension at the current time as the abnormal dimension, then the abnormal offset magnitude of the i-th dimension is (F i ) now And confidence value Z i The feature value of the i-th dimension is calculated as (T) i ) now =(F i ) now ×Z i ; Step S402: Obtain the feature values ​​of each dimension at the current time. If the expected triggering mechanism for judging the conflict result at the current time is Max(v ax ,w ax ) = v ax Then, obtain the minimum eigenvalue of each anomaly dimension, and count the number of dimensions whose eigenvalues ​​are greater than or equal to the minimum eigenvalue as v. now If v now ≥v ax If a security incident is detected at the current moment, it is determined that a security incident exists; if the desired trigger mechanism is Max(v) ax ,w ax ) = w ax Then, obtain the maximum eigenvalue of each normal dimension, and count the number of dimensions whose eigenvalues ​​are less than or equal to the maximum eigenvalue as w. now If w now ≤v ax If so, it is determined that a public security incident exists at the current moment.

4. A public security data digital management system, used to execute the public security data digital management method based on artificial intelligence as described in any one of claims 1-3, characterized in that: The management system includes a historical security analysis module, a dimensional anomaly analysis module, a confidence conflict analysis module, and a real-time security analysis module. The historical security analysis module is used to monitor security incidents occurring in the target area using several preset monitoring methods, and to collect multi-dimensional data on any security incident; based on the feedback results from relevant personnel, it identifies anomalies in the actual occurrence of any security incident. The dimensional anomaly analysis module is used to arbitrarily select public security events with normal evaluation results, identify monitoring blind spots in each dimension, and correct the regional range of each monitoring blind spot based on the differences in evaluation results between different public security events. The confidence conflict analysis module is used to analyze the feature values ​​of each dimension based on the area range of the monitoring blind spots in different dimensions in any security incident; and to set a trigger mechanism for existing assessment conflicts based on the differences in feature values ​​of each dimension. The real-time security analysis module is used to collect multi-dimensional data of the target area in real time, obtain the feature values ​​of each dimension at the current moment, analyze the triggering situation between the feature values ​​of each dimension and the assessment conflict mechanism, and determine whether there is a security incident at the current moment.

5. A public security data digital management system according to claim 4, characterized in that: The historical security analysis module includes a historical data acquisition unit and a difference assessment and identification unit; The historical data acquisition unit is used to monitor security incidents occurring in the target area using several preset monitoring methods, and to collect multi-dimensional data on any security incident; the difference assessment and identification unit is used to identify anomalies in the actual occurrence of any security incident based on the processing feedback results of relevant personnel.

6. A public security data digital management system according to claim 4, characterized in that: The dimensional anomaly analysis module includes a dimensional blind zone identification unit and a blind zone range correction unit; The dimension blind spot identification unit is used to arbitrarily select public security events with normal evaluation results and identify the monitoring blind spots existing in each dimension; the blind spot range correction unit is used to correct the area range of each monitoring blind spot based on the differences in evaluation results between different public security events.

7. A public security data digital management system according to claim 4, characterized in that: The confidence conflict analysis module includes a dimensional confidence assessment unit and an assessment conflict determination unit; The dimensional confidence assessment unit is used to analyze the feature values ​​of each dimension based on the area range of the monitoring blind spots of different dimensions in any security incident; the assessment conflict determination unit is used to set a trigger mechanism for existing assessment conflicts based on the differences in feature values ​​of each dimension.

8. A public security data digital management system according to claim 4, characterized in that: The real-time security analysis module includes a real-time data acquisition unit and an anomaly detection and identification unit; The real-time data acquisition unit is used to perform multi-dimensional data acquisition on the target area in real time to obtain the feature values ​​of each dimension at the current moment. The anomaly detection and identification unit is used to analyze the triggering of feature values ​​in various dimensions and the evaluation conflict mechanism to determine whether a security incident exists at the current moment.

Citation Information

Patent Citations

  • Video data analysis system and method based on intelligent security and protection technology

    CN117523451A

  • Regional monitoring point distribution method and system

    CN118172892A