Intelligent security data analysis and decision method and system based on artificial intelligence
By collecting multiple heterogeneous data streams and performing spatiotemporal feature fusion and adaptive clustering, combined with an anomaly propagation network model, the problems of single data analysis and static device partitioning in intelligent security are solved. This enables in-depth characterization of complex scenarios and accurate risk prediction, provides collaborative response strategies, and improves the intelligence and reliability of security decision-making.
Patent Information
- Application Number
- CN202510334908.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2045-03-20
AI Technical Summary
Existing intelligent security technologies suffer from problems such as relying on single data analysis, static device classification, and lack of correlation analysis of abnormal device signals when facing complex and ever-changing real-world scenarios, resulting in incomplete and untimely security decision-making.
Multiple heterogeneous data streams are collected, spatiotemporal feature vectors are generated through a spatiotemporal feature fusion model, dynamic device clustering is performed using an adaptive clustering algorithm, and the correlation of device abnormal signals is analyzed through an anomaly propagation network model to generate cluster-level risk prediction and collaborative response instructions.
It enables in-depth characterization of security scenarios and accurate risk prediction, adapts to changes in scenarios in real time, provides collaborative response strategies, and improves the intelligence and reliability of security decision-making.
Smart Images

Figure CN120216929B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of artificial intelligence, in particular to an intelligent security data analysis and decision-making method and system based on artificial intelligence. BACKGROUND
[0002] With the development of society and the progress of technology, the field of intelligent security has attracted widespread attention. Under the demand of ensuring the safety of various places, the intelligent level of security systems is continuously improved. However, the current intelligent security technology still has many limitations when facing complex and variable actual scenes.
[0003] In traditional security data analysis methods, often only focus on the processing of a single type of data. For example, most systems only rely on video monitoring data, ignoring other important information sources such as infrared sensor signals, audio waveforms, and device status logs. This single data analysis method cannot comprehensively and accurately reflect the actual security situation of the target area, and is likely to miss many potential security threats.
[0004] For the processing of multi-source data, previous technologies even try to integrate different types of data, but only perform simple splicing or shallow correlation analysis, making it difficult to mine the deep internal relationship between data. These methods do not fully consider the spatio-temporal characteristics of data and environmental context information, and cannot effectively extract features that accurately depict security scenes, resulting in low accuracy and reliability of the analysis results.
[0005] In terms of device management and cluster division, traditional technologies mostly use static division methods. Fixed device grouping rules are pre-set, without considering the actual running state and correlation changes of devices at different times and in different environments. When the security situation of the target area changes dynamically, this static division method cannot adapt in time, resulting in low efficiency of subsequent data analysis and difficulty in quickly and accurately discovering abnormal situations.
[0006] In terms of anomaly analysis and risk prediction, existing security systems usually perform independent anomaly detection on a single device, lacking in-depth analysis of the correlation of abnormal signals between devices. It is difficult to grasp the security risks from the overall level, and it is impossible to predict possible chain reactions or complex security incidents in advance, resulting in insufficient comprehensive and timely decision-making when facing complex security threats, and difficulty in taking effective coordinated measures. SUMMARY
[0007] In view of the above-mentioned problems, in combination with the first aspect of the present application, the embodiments of the present application provide an intelligent security data analysis and decision-making method based on artificial intelligence, which comprises:
[0008] Collecting a plurality of heterogeneous data streams uploaded by a plurality of security monitoring devices in a target area in real time, wherein the heterogeneous data streams include video frame sequences, infrared sensing signals, audio waveforms, and device state logs;
[0009] Extracting multi-modal features of the heterogeneous data streams through a spatio-temporal feature fusion model to generate a spatio-temporal feature vector corresponding to each security monitoring device, wherein the spatio-temporal feature vector includes device deployment coordinates, monitoring timestamps, environmental context correlation degrees, and abnormal signal intensities;
[0010] Based on the spatio-temporal feature vector, performing dynamic cluster division on the plurality of security monitoring devices using an adaptive clustering algorithm to generate a plurality of device clusters, wherein the similarity of security monitoring devices in the same device cluster on the spatio-temporal feature vector is greater than the similarity of devices across clusters;
[0011] For each device cluster, analyzing the abnormal signal correlation of security monitoring devices in the device cluster through an abnormal propagation network model to generate a cluster-level risk prediction result and a device cooperative response instruction;
[0012] According to the cluster-level risk prediction result, dynamically adjusting the node weights of the abnormal propagation network model and updating the cluster centers of the adaptive clustering algorithm to optimize subsequent cluster division.
[0013] In another aspect, the embodiment of the present application also provides an intelligent security data analysis and decision system based on artificial intelligence, which includes a processor and a machine readable storage medium, the machine readable storage medium is connected with the processor, the machine readable storage medium is used for storing programs, instructions or codes, and the processor is used for executing the programs, instructions or codes in the machine readable storage medium to realize the above-mentioned method.
[0014] Based on the above aspects, the embodiment of the present application collects a plurality of heterogeneous data streams in the target area, including video frame sequences, infrared sensing signals, audio waveforms, and device state logs, which breaks through the limitation of traditional security data analysis relying on only a single type of data. Multi-modal feature extraction is performed through a spatio-temporal feature fusion model to generate a spatio-temporal feature vector containing device deployment coordinates, monitoring timestamps, environmental context correlation degrees, and abnormal signal intensities, which can comprehensively and meticulously depict the complex scene information monitored by security monitoring devices. This way of fusing multi-source heterogeneous data and extracting deep features greatly improves the perception accuracy of the security situation of the target area and can discover potential security risks that are difficult to detect by traditional methods.
[0015] The adaptive clustering algorithm is used to dynamically divide multiple security monitoring devices into clusters based on the spatiotemporal feature vectors. The devices within the same device cluster have high similarity in spatiotemporal feature vectors and are distinctly distinguished from devices across clusters. Compared with traditional fixed clustering methods, this dynamic cluster division can adapt to changes in security conditions in the target area in real time and automatically adjust the device cluster structure. For example, the relevance between devices may change at different time periods or under different environmental conditions. The adaptive clustering algorithm can quickly respond to these changes to ensure that the cluster division always matches the actual security scenario, thereby improving the relevance and efficiency of subsequent data analysis.
[0016] For each device cluster, the abnormal signal relevance of the security monitoring devices is analyzed in depth through the abnormal propagation network model, which not only accurately generates cluster-level risk prediction results but also provides device cooperative response instructions. This network model-based analysis method fully considers the complex interaction relationships between devices, can predict potential security risks in advance, and develop a cooperative response strategy. Compared with traditional simple anomaly detection methods, this method can more deeply mine the logical relationships behind abnormal signals to achieve more intelligent and comprehensive security decisions.
[0017] According to the cluster-level risk prediction results, the node weights of the abnormal propagation network model are dynamically adjusted, and the clustering centers of the adaptive clustering algorithm are updated, forming an intelligent iterative optimization mechanism. This self-optimization capability enables the system to continuously learn and adapt to new security conditions. Over time, the model and algorithm can more accurately predict risks and divide device clusters, thereby continuously improving the performance and reliability of the entire intelligent security data analysis and decision-making system. BRIEF DESCRIPTION OF DRAWINGS
[0018] Figure 1 is the execution flow diagram of the intelligent security data analysis and decision-making method based on artificial intelligence provided by the embodiment of the application.
[0019] Figure 2 is the hardware architecture diagram of the intelligent security data analysis and decision-making system based on artificial intelligence provided by the embodiment of the application. DETAILED DESCRIPTION
[0020] The application will be specifically described below with reference to the drawings of the specification, Figure 1 is the flow diagram of the intelligent security data analysis and decision-making method based on artificial intelligence provided by an embodiment of the application. The intelligent security data analysis and decision-making method based on artificial intelligence will be described in detail below.
[0021] Step S110, collect the heterogeneous data stream uploaded by the plurality of security monitoring devices in the target region in real time, wherein the heterogeneous data stream comprises a video frame sequence, an infrared sensing signal, an audio waveform and a device state log.
[0022] In this embodiment, an industrial park is considered as the target region, and various security monitoring devices are distributed in the industrial park. In various corners of the industrial park, such as the entrance of the park, around the production workshop, near the warehouse and beside the roads in the park, a plurality of cameras are installed, which continuously collect video frame sequences. The video frame sequence contains the activity of the personnel in the park, the driving track of the vehicle and the overall picture of the region. For example, the camera at the entrance of a production workshop in the park can continuously capture the appearance features of the employees entering the workshop, the items they carry and the time of entry, and a series of video frames will be generated every second, which form a video frame sequence.
[0023] Meanwhile, in some key areas, such as around the warehouse storing flammable goods, infrared sensing devices are installed. These infrared sensing devices continuously upload infrared sensing signals. When an object with abnormal temperature approaches the warehouse, for example, a vehicle with a high engine temperature approaches the warehouse after driving, the infrared sensing device can detect the existence of the heat source and send out the infrared sensing signal, which contains various information about the heat source, such as the approximate position of the heat source and the intensity of the heat.
[0024] Audio monitoring devices are also installed in the park and distributed in different areas. These audio monitoring devices record the sound in the park in real time to form an audio waveform. For example, in the office area of the park, the audio monitoring device can capture the conversation between employees, the sound of the printer working, etc.; in the public area of the park, it may capture the sound of vehicles driving, the sound of broadcast announcements, etc.
[0025] In addition, each security monitoring device itself will also generate a device state log. Taking a camera as an example, the device state log will record the working status of the camera, such as whether it is running normally, whether the lens is blocked, whether the storage device is full, etc.; for the infrared sensing device, the device state log will contain information such as the temperature calibration of the device and whether the signal transmission is normal; the device state log of the audio monitoring device will record information such as whether the volume detection range of the device is normal and whether there is a microphone failure. All these different types of video frame sequences, infrared sensing signals, audio waveforms and device state logs uploaded by the security monitoring devices in real time constitute the heterogeneous data stream, which is collected for subsequent processing.
[0026] In step S120, the multi-modal feature extraction is performed on the heterogeneous data stream by the spatio-temporal feature fusion model to generate a spatio-temporal feature vector corresponding to each security monitoring device, wherein the spatio-temporal feature vector includes device deployment coordinates, monitoring time stamp, environmental context correlation degree, and abnormal signal strength.
[0027] Still taking the industrial park as an example, for the collected video frame sequence, the embodiment performs optical flow analysis. For example, in the video frame sequence collected by the camera at the entrance of the park, when a car enters the park, the trajectory of the moving target car and the consistency parameter of the driving direction of the car can be accurately extracted by optical flow analysis. If the car drives straight into the park along the specified lane, the motion direction consistency parameter is relatively high; if the car abnormally turns or sways, the parameter will reflect this abnormal situation.
[0028] For the infrared sensing signal, frequency domain transformation is performed. It is assumed that an infrared sensing device near the warehouse detects a heat source approaching the warehouse. After frequency domain transformation, the heat source distribution density can be extracted, such as whether it is concentrated in a small area or relatively dispersed. If it is a malfunctioning electrical device that is heating up, the heat source distribution may be relatively concentrated; if it is because of the hot weather that causes the ambient air temperature to rise universally, the heat source distribution may be relatively dispersed. At the same time, the temperature gradient change rate can also be extracted. If an object suddenly approaches the warehouse and has a relatively high temperature, the temperature gradient change rate will be relatively large.
[0029] In terms of audio waveform, voiceprint feature decomposition is performed. For example, in the audio waveform collected by the audio monitoring device in the office area, if an abnormal high-decibel sharp sound suddenly appears, through voiceprint feature decomposition, the abnormal sound source positioning coordinates can be extracted to determine whether the sound comes from a specific office or a corridor, etc., and the sound pressure level mutation frequency, i.e., the frequency of the sudden increase in the intensity of the sound, can be obtained.
[0030] The device state log is subjected to time sequence analysis. Taking a camera as an example, if the device state log of the camera shows that the storage device is full frequently in a certain time period, through time sequence analysis, it can be extracted that the device running stability index is relatively low, and the fault warning interval can be calculated, such as how often the storage-related problems occur.
[0031] Then the motion target trajectory, heat source distribution density, abnormal sound source positioning coordinates and equipment operation stability index are input into the encoder layer of the spatio-temporal feature fusion model to generate a primary feature representation. Assuming that a camera near a production workshop in the park, the motion target trajectory captured by the camera shows normal personnel flow, the heat source distribution density detected by the nearby infrared sensing equipment is also normal, the audio monitoring equipment does not detect abnormal sound sources, and the device operation stability index of the camera itself is good. These features are input into the encoder layer, which generates a primary feature representation reflecting the overall state of this area.
[0032] Then, through the attention mechanism layer of the spatio-temporal feature fusion model, the contribution weights of different modal features in the primary feature representation are calculated, and different modal features are dynamically weighted and fused according to the contribution weights. For example, when judging whether a region has a security risk, since this region is a production workshop, the stability of the equipment operation may be more important, so the contribution weight of the equipment operation stability index modal feature will be relatively high. If it is in a public area of the park, the flow of personnel and vehicles may be more important, so the contribution weight of the motion target trajectory modal feature will be increased.
[0033] Finally, the weighted and fused features are spliced with the motion direction consistency parameter, temperature gradient change rate, sound pressure level mutation frequency and fault warning interval to generate a spatio-temporal feature vector. For a security monitoring device in the park, its spatio-temporal feature vector includes its device deployment coordinates (such as specific latitude and longitude coordinates in the park), monitoring timestamp (monitoring data collection time accurate to seconds), environmental context correlation degree (such as environmental information related correlation degree of the region, such as production area, office area or warehouse area), and abnormal signal strength (whether there is an anomaly and the degree of anomaly judged by various modal features).
[0034] Step S130, based on the spatio-temporal feature vector, an adaptive clustering algorithm is used to dynamically cluster the plurality of security monitoring devices to generate a plurality of device clusters, wherein the similarity of the security monitoring devices in the same device cluster on the spatio-temporal feature vector is greater than the similarity of the devices across clusters.
[0035] In the security monitoring system of the industrial park, the embodiment begins to divide the device clusters using the adaptive clustering algorithm. First, initialize the cluster centers of the adaptive clustering algorithm, select the feature vectors corresponding to the top K security monitoring devices with the highest abnormal signal strength in the spatio-temporal feature vector as the cluster centers, and assume K = 3. For example, select the spatio-temporal feature vectors of an infrared sensor located near the dangerous chemical warehouse in the park (because it may often detect some small temperature fluctuations, and the abnormal signal strength is relatively high), a camera at the entrance of the park (because personnel and vehicles frequently enter and exit, and occasionally there will be abnormal personnel behavior or vehicle violations, and the abnormal signal strength is also high), and an audio monitoring device in the office area (which may produce a high abnormal signal strength due to personnel quarrels and the like) as the initial cluster centers.
[0036] Then, the cosine similarity of the spatio-temporal feature vector of each security monitoring device with all cluster centers is calculated. For example, a camera located inside a production workshop, whose spatio-temporal feature vector contains device deployment coordinates inside the workshop, monitoring timestamp during normal working hours, environmental context correlation degree as production environment, and low abnormal signal strength (because everything in the workshop is normal). Calculate the cosine similarity of the spatio-temporal feature vector of this camera with the above three cluster centers. According to the set similarity threshold, if the similarity of this camera with the cluster center of the infrared sensor near the warehouse is lower than the threshold, the similarity with the cluster center of the camera at the entrance of the park is also lower than the threshold, but the similarity with the cluster center of the audio monitoring device in the office area is higher than the threshold, then this camera is assigned to the temporary cluster with the audio monitoring device in the office area as the cluster center.
[0037] For each temporary cluster, the mean and variance of the spatio-temporal feature vectors of the security monitoring devices inside the temporary cluster are calculated. Assume that in the temporary cluster with the audio monitoring device in the office area as the cluster center, there are multiple cameras and audio monitoring devices. If the variance of this temporary cluster is greater than the set variance threshold, it may mean that the devices inside this cluster are similar to some extent, but there are also large differences. For example, some devices in this cluster are near the conference room in the office area, and some are near the corridor in the office area, and the environmental context correlation degree is quite different, so the temporary cluster is split into two sub-clusters, and a new cluster center is added. For example, the devices near the conference room are divided into a sub-cluster, and the devices near the corridor are divided into another sub-cluster, and new cluster centers are determined respectively.
[0038] According to the re-computed similarity between all security monitoring devices and the updated cluster centers, the assignment and split operations are iteratively performed. For example, a newly installed camera in the park has not been assigned to a suitable cluster before, after updating the cluster centers, re-compute its similarity with each cluster center, it can be assigned to a suitable cluster. This process is repeated until the intra-cluster variance of all clusters is below the set variance threshold.
[0039] Finally, adjacent clusters with a similarity greater than the set merging threshold are merged, and isolated clusters with a number of devices below the minimum size threshold are deleted, generating a final stable multiple device clusters. For example, two adjacent office area device clusters have a high spatio-temporal feature vector similarity, so they are merged into one device cluster; if there is a cluster with only one device, and the number of devices is below the minimum size threshold, the isolated cluster is deleted, and finally a stable device cluster is formed, which can better reflect the distribution and correlation of security monitoring devices in the industrial park.
[0040] Step S140, for each device cluster, analyze the abnormal signal correlation of the security monitoring devices in the device cluster through the anomaly propagation network model, and generate a cluster-level risk prediction result and a device cooperative response instruction.
[0041] Taking the previously divided device clusters in the industrial park as an example, analyze one of the device clusters containing cameras around the production workshop, infrared sensing devices and audio monitoring devices. First, build an anomaly propagation graph with this device cluster as a node. In this device cluster, if a camera detects that a person enters the production workshop at a non-working time, and the infrared sensing device in the workshop detects that the temperature of a certain device suddenly rises, the time synchronization of these two abnormal signals is high, and since the camera and the infrared sensing device are close in space, their spatial proximity is also high, so the weight of the edge connecting the two devices in the anomaly propagation graph will be higher.
[0042] Input the spatio-temporal feature vector of this device cluster into the graph convolution layer of the anomaly propagation network model to extract the potential risk features of the cluster nodes. Assuming that the spatio-temporal feature vector of this device cluster shows that the recent maintenance record of the devices in the workshop is poor, the environmental temperature is high, and the personnel flow has abnormally increased in a certain time period, these features input into the graph convolution layer can extract potential risk features about the possible risks of this device cluster, such as increased device failure risk, increased safety violation risk, etc.
[0043] The time recursive layer of the anomaly propagation network model is analyzed to predict the evolution pattern of potential risk features at consecutive time steps, and the risk outbreak probability of the cluster node in the future time window is predicted. For example, in the past few hours, the temperature of the equipment in the workshop has been rising, and the frequency of personnel entering the workshop in violation of regulations has also been increasing. According to the changes in these potential risk features at consecutive time steps, it is predicted that the risk outbreak probability of this equipment cluster in the next hour is 30%.
[0044] If this risk outbreak probability exceeds the preset probability, assuming that the preset probability is 20%, the device cooperative response instruction generation process is triggered. According to the deployment coordinates and monitoring capabilities of the security monitoring devices in the device cluster, the master device and the auxiliary device roles are assigned. For example, in this production workshop device cluster, since the camera located in the center of the workshop can cover a larger area and its data transmission stability is better, this camera is assigned as the master device, and the other cameras and infrared sensing devices, audio monitoring devices around the workshop are assigned as auxiliary devices.
[0045] Based on the real-time data feedback of the master device, the working mode and data acquisition frequency of the auxiliary device are dynamically adjusted. If the master device finds that there is abnormal smoke in a certain area of the workshop, it can notify the nearby infrared sensing device to increase the data acquisition frequency in order to more accurately monitor the temperature change; at the same time, it can notify the surrounding cameras to adjust the shooting angle and focus on the area where there may be risks.
[0046] A cross-device cooperative warning signal transmission path is generated to ensure low-latency synchronization of warning information among devices in the cluster. For example, a direct communication link is established between the master camera and each auxiliary device, so that when the master device detects an abnormal situation, it can quickly send a warning signal to all auxiliary devices, enabling the entire device cluster to respond quickly.
[0047] Step S150, according to the cluster-level risk prediction result, dynamically adjusting the node weight of the anomaly propagation network model, and updating the clustering center of the adaptive clustering algorithm to optimize the subsequent cluster division.
[0048] Continuing with the example of the security monitoring system in the industrial park, after predicting the risk of the production workshop device cluster, the execution effect data of the device cooperative response instruction is collected. Assuming that the device cooperative response instruction requires the cameras and infrared sensing devices in the workshop to cooperate in monitoring when an anomaly is detected, the execution effect data includes risk suppression response time, device cooperation success rate, and false alarm rate. If it is found that the risk suppression response time from the occurrence of an anomaly to the start of device cooperative response is long, the device cooperation success rate is low, and there is a certain false alarm rate, for example, the device mistakenly judges normal device startup heat as abnormally high temperature.
[0049] The prediction error gradient of the anomaly propagation network model is calculated according to the execution effect data, and the weight parameters of the graph convolution layer and the time recursion layer are updated through the back propagation algorithm. For example, due to the high false positive rate, the weight setting of the graph convolution layer for the normal state features of the equipment may be unreasonable, and the weight parameters related to the normal operation features of the equipment in the graph convolution layer are adjusted through the back propagation algorithm; due to the long risk suppression response time, the time step setting of the time recursion layer when predicting the risk evolution may be inaccurate, and the weight parameters of the time recursion layer are adjusted.
[0050] The updated anomaly propagation network model is re-applied to the historical spatio-temporal feature vectors to generate corrected cluster-level risk prediction results. The spatio-temporal feature vectors before the production plant equipment cluster are re-input into the updated anomaly propagation network model to obtain new risk prediction results, for example, the previously predicted risk outbreak probability is 30%, which may be corrected to 25%.
[0051] The difference between the cluster-level risk prediction results before and after correction is compared, and the equipment cluster with the largest prediction deviation is identified as the clustering center optimization target. If it is found that the prediction deviation of the production plant equipment cluster is the largest, the equipment cluster is taken as the target of clustering center optimization.
[0052] For this clustering center optimization target, the spatio-temporal feature vector mean of the clustering center optimization target and the feature vector of the adjacent cluster are interpolated to generate a new clustering center and replace the original center. Assuming that the spatio-temporal feature vector mean of the production plant equipment cluster contains information such as average deployment coordinates of the equipment, average monitoring timestamp, average environmental context correlation degree, and average abnormal signal strength, it is interpolated with the feature vector of the adjacent warehouse equipment cluster to obtain a new clustering center, which replaces the original clustering center of the production plant equipment cluster.
[0053] A new round of equipment cluster division process is triggered until the prediction deviation of all clusters is below the convergence threshold. For example, all security monitoring equipment in the industrial park is re-clustered according to the new clustering center, and this process is repeated until the prediction deviation of each equipment cluster is small enough, below the convergence threshold, thereby optimizing the equipment cluster division and risk prediction capability of the entire security monitoring system.
[0054] Based on the above steps, the embodiments of the present application collect multiple heterogeneous data streams in the target area, covering video frame sequences, infrared sensor signals, audio waveforms, and device status logs. This breaks through the limitations of traditional security data analysis, which relies on only a single type of data. Through a spatio-temporal feature fusion model, multi-modal feature extraction is performed to generate spatio-temporal feature vectors containing device deployment coordinates, monitoring timestamps, environmental context correlation, and abnormal signal intensity. This can comprehensively and meticulously depict the complex scene information monitored by security monitoring devices. This method of fusing multiple heterogeneous data and extracting deep features greatly improves the perception accuracy of the security situation in the target area, enabling the discovery of potential security risks that traditional methods cannot detect.
[0055] A self-adaptive clustering algorithm is used to dynamically divide multiple security monitoring devices into clusters based on spatio-temporal feature vectors. Devices within the same device cluster have high similarity in spatio-temporal feature vectors and are distinctly different from devices across clusters. Compared to traditional fixed clustering methods, this dynamic cluster division can adapt to changes in security situations in the target area in real time and automatically adjust the device cluster structure. For example, the relevance between devices may change at different time periods or under different environmental conditions. The self-adaptive clustering algorithm can quickly respond to these changes, ensuring that the cluster division always matches the actual security scene, thereby improving the relevance and efficiency of subsequent data analysis.
[0056] For each device cluster, an abnormal propagation network model is used to analyze the abnormal signal correlation of security monitoring devices. This not only accurately generates cluster-level risk prediction results but also provides device cooperative response instructions. This network model-based analysis method fully considers the complex interaction relationships between devices, enabling the prediction of potential security risks in advance and the development of cooperative response strategies. Compared to traditional simple anomaly detection methods, this method can more deeply mine the logical relationships behind abnormal signals, enabling more intelligent and comprehensive security decisions.
[0057] According to the cluster-level risk prediction results, the node weights of the abnormal propagation network model are dynamically adjusted, and the clustering centers of the self-adaptive clustering algorithm are updated, forming an intelligent iterative optimization mechanism. This self-optimization capability enables the system to continuously learn and adapt to new security situations. Over time, the model and algorithm can more accurately perform risk prediction and device cluster division, thereby continuously improving the performance and reliability of the entire intelligent security data analysis and decision-making system.
[0058] In one possible implementation, step S120 includes:
[0059] Step S121 performs optical flow analysis on the video frame sequence to extract motion target trajectories and motion direction consistency parameters.
[0060] For example, on the main road of the park, the camera continuously shoots the passing vehicles and pedestrians. The optical flow analysis technology can accurately track each moving target in the picture, so as to extract the moving target trajectory. Taking a forklift driving in the park as an example, through optical flow analysis, the complete driving trajectory of the forklift from a warehouse to a production workshop along a specific channel can be accurately depicted. At the same time, the motion direction consistency parameter can also be obtained. If the forklift always drives straight along the specified lane during driving without sudden turning or irregular deviation, the motion direction consistency parameter will be high, which indicates that the driving state of the forklift is normal; on the contrary, if the forklift makes multiple irregular turns or swings between lanes, the parameter will be low, which may indicate that the forklift driver operates improperly or the forklift itself has hidden trouble.
[0061] Step S122, frequency domain transformation is performed on the infrared sensing signal to extract the heat source distribution density and the temperature gradient change rate.
[0062] Then, the infrared sensing signal emitted by the infrared sensing device installed in the key area (such as around the warehouse storing flammable and explosive goods) in the park is subjected to frequency domain transformation. When a truck that has just completed a transportation task is parked near the warehouse, the infrared sensing signal can detect the heat source generated by the long-time work of the engine of the truck. Through frequency domain transformation, the heat source distribution density can be accurately extracted. If the engine cooling is normal, the heat will be relatively uniformly distributed around the engine, and the heat source distribution density will present a relatively regular pattern; if the engine cooling has a fault, it may cause local overheating, so the heat source distribution density will present a concentrated state in the overheated area. At the same time, the temperature gradient change rate can also be accurately obtained. When the truck just stops, the engine temperature is high, and with the passage of time, the heat is gradually dissipated, and the temperature gradually decreases. The temperature change speed in this process is represented by the temperature gradient change rate. If the temperature drop speed is too slow, it may indicate that the vehicle has potential safety risks, such as engine cooling system failure.
[0063] Step S123, acoustic feature decomposition is performed on the audio waveform to extract abnormal sound source positioning coordinates and sound pressure level mutation frequency.
[0064] Then, the audio waveforms collected by the audio monitoring devices in each area of the park (such as office area, production workshop, public area, etc.) are decomposed into voiceprint features. In the office area, the normal conversations of employees, the working sound of printers, and the running sound of air conditioners, etc. constitute a complex audio environment. When an abnormal sound suddenly appears, for example, a sharp sound of equipment collision occurs in a certain office, through voiceprint feature decomposition, the coordinates of the abnormal sound source can be accurately located to determine which office or which specific location the sound comes from. Moreover, the sound pressure level mutation frequency can also be extracted. If this equipment collision sound is one-time, the sound pressure level mutation frequency is a short peak; if it is an abnormal high-frequency noise continuously emitted by the equipment, the sound pressure level mutation frequency will remain at a high value for a period of time, which may mean that the equipment has a serious fault and needs timely maintenance.
[0065] Step S124, time series analysis of the device status log is performed to extract the device running stability index and the fault warning interval.
[0066] In addition, the device status log generated by each security monitoring device itself is time series analyzed. Taking the cameras in each corner of the park as an example, the device status log records various running state information of the cameras. Through time series analysis, the device running stability index can be extracted. If the camera frequently appears image blur, data transmission interruption and other problems within a period of time, the device running stability index will be low, indicating that the camera may have hardware failure or unstable network connection. At the same time, the fault warning interval can also be determined. For example, if the camera prompts a storage capacity shortage every few days, this time interval is the fault warning interval, which can help the operation and maintenance personnel to plan the device maintenance and data cleaning work in advance to ensure the normal operation of the camera.
[0067] Step S125, the moving target trajectory, the heat source distribution density, the abnormal sound source positioning coordinates and the device running stability index are input into the encoder layer of the spatio-temporal feature fusion model to generate a primary feature representation.
[0068] For example, near the production workshop of the park, the moving target trajectory of personnel and equipment monitored by the camera, the heat source distribution density detected by the infrared sensing device in the workshop, the abnormal sound source positioning coordinates analyzed by the surrounding audio monitoring device, and the device running stability index of the camera itself are collectively input into the encoder layer. Assuming that the activities of personnel and equipment in the production workshop are in a normal state, the heat source distribution is normal, no abnormal sound source is detected, and the camera runs stably, then the encoder layer will generate a primary feature representation that can reflect the overall stable state of this production workshop area. This primary feature representation integrates the basic feature information of each aspect.
[0069] Step S126, the contribution weights of different modal features in the primary feature representation are calculated through the attention mechanism layer of the spatio-temporal feature fusion model, and different modal features are dynamically weighted and fused according to the contribution weights.
[0070] After that, in the environment of the industrial park, the security monitoring focus of different areas is different. For the production workshop area, the stability of equipment operation and the motion trajectory of personnel and equipment may be more important. Therefore, in the calculation of the attention mechanism layer, the contribution weights of the equipment operation stability index and the motion target trajectory of the two modal features will be relatively high. For the office area, the abnormal sound source positioning coordinates and the sound pressure level mutation frequency of the sound source may be more concerned, because the office area needs to maintain a quiet working environment, so the contribution weights of the two modal features will be increased accordingly in the calculation of the office area. According to different contribution weights, each modal feature is dynamically weighted and fused, so that the fused features can better reflect the security monitoring focus and actual needs of different areas.
[0071] Step S127, the weighted and fused features are spliced with the motion direction consistency parameter, the temperature gradient change rate, the sound pressure level mutation frequency and the fault warning interval to generate the spatio-temporal feature vector.
[0072] Continuing to take a specific security monitoring device in the park as an example, this security monitoring device may be a camera located at the entrance of the warehouse. The weighted and fused features include comprehensive information about the activities of personnel and vehicles in the warehouse entrance area, the surrounding heat source situation, the sound environment and the running state of the device itself, etc. after weighted processing. The motion direction consistency parameter reflects whether the vehicle drives according to the specified route when entering the warehouse; the temperature gradient change rate reflects the change of the ambient temperature of the warehouse, for example, whether the ambient temperature of the warehouse is abnormally high in hot weather; the sound pressure level mutation frequency indicates whether there is a sudden high-decibel sound near the warehouse, which may be a sound emitted by equipment failure or abnormal operation; the fault warning interval shows the fault warning situation of the camera itself. Splicing these information together generates the spatio-temporal feature vector corresponding to the camera located at the entrance of the warehouse, which comprehensively contains the deployment coordinates of the device, the monitoring timestamp, the environmental context correlation degree and the abnormal signal strength, etc. providing a rich data basis for subsequent security monitoring analysis.
[0073] In one possible implementation, step S130 includes:
[0074] Step S131, initializing the cluster centers of the adaptive clustering algorithm as the feature vectors corresponding to the first K security monitoring devices with the highest abnormal signal strength in the spatio-temporal feature vector, K being a preset initial cluster number.
[0075] In this embodiment, K is the preset initial cluster number, assuming K = 3. Among the numerous security monitoring devices in the industrial park, the top 3 feature vectors corresponding to the security monitoring devices with the highest abnormal signal strength in the spatio-temporal feature vector can be found as the initial cluster centers. For example, an infrared sensor located near the dangerous chemical warehouse in the park, due to the special nature of dangerous chemicals, small temperature changes in this area can be considered as abnormal signals, so the abnormal signal strength of this device is high; a camera at the entrance of the park, due to the frequent entry and exit of personnel and vehicles, occasional situations such as personnel not following the specified procedures or vehicles violating the parking rules, etc., make its abnormal signal strength also high; there is also a sensor in the production workshop for monitoring the running state of the key equipment, once the equipment appears abnormal fluctuation, it will produce higher abnormal signal strength. The spatio-temporal feature vectors of these three devices are determined as the initial cluster centers.
[0076] Step S132, calculate the cosine similarity of the spatio-temporal feature vector of each security monitoring device with all cluster centers, and distribute the device to a temporary cluster according to the similarity threshold.
[0077] For example, a camera in the office area corridor in the park, its spatio-temporal feature vector contains device deployment coordinates in the office corridor, monitoring timestamp is normal working hours, environmental context correlation degree is office environment, and abnormal signal strength is low (because the office area is usually stable). Therefore, the cosine similarity of the spatio-temporal feature vector of this camera with the above three cluster centers (infrared sensor near the dangerous chemical warehouse, camera at the entrance of the park, sensor in the production workshop) can be calculated respectively. If the set similarity threshold is 0.6, and the cosine similarity of this camera with the cluster center of the infrared sensor near the dangerous chemical warehouse is 0.3, the cosine similarity with the cluster center of the camera at the entrance of the park is 0.5, and the cosine similarity with the cluster center of the sensor in the production workshop is 0.7, since the cosine similarity with the cluster center of the sensor in the production workshop is higher than the threshold, then this camera will be distributed to the temporary cluster with the sensor in the production workshop as the cluster center.
[0078] Step S133, for each temporary cluster, the mean and variance of the spatio-temporal feature vectors of the security monitoring devices inside the temporary cluster are calculated, if the variance is greater than the set variance threshold, the temporary cluster is split into two sub-clusters, and a new cluster center is added.
[0079] For example, a temporary cluster with a production workshop sensor as the cluster center may include multiple cameras, sensors, and other devices in the workshop. The average spatiotemporal feature vector of these devices is calculated, including average device deployment coordinates, average monitoring timestamp, average environmental context correlation, and average abnormal signal strength. The variance is also calculated. If the variance is greater than the set variance threshold, it means that the devices in this temporary cluster are similar to some extent, but there are also significant differences. For example, some devices are close to large production equipment, and some devices are close to the workshop passage, resulting in a large difference in environmental context correlation, which may result in a large variance. In this case, the temporary cluster is split into two sub-clusters, and a new cluster center is added. For example, devices close to large production equipment are divided into a sub-cluster, and the spatiotemporal feature vector of one of the devices is used as the new cluster center. Devices close to the workshop passage are divided into another sub-cluster, and a new cluster center is determined.
[0080] Step S134, according to the split sub-clusters, recalculate the similarity between all security monitoring devices and the updated cluster center, and iteratively perform the assignment and split operation until the internal variance of all clusters is less than the set variance threshold.
[0081] For example, a new sensor installed in the corner of the workshop in the park was previously assigned to a temporary cluster with a production workshop sensor as the cluster center. However, after the temporary cluster is split, it needs to recalculate its similarity with the new cluster center. If the similarity between this sensor and the new cluster center of the sub-cluster close to large production equipment is higher, it will be reassigned to this sub-cluster. This process is repeated until the internal variance of all clusters is less than the set variance threshold, ensuring that the devices in each cluster have high similarity.
[0082] Step S135, merge adjacent clusters with a spatiotemporal feature vector similarity greater than the set merging threshold, and delete isolated clusters with a device quantity less than the minimum scale threshold, to generate a final stable multiple device clusters.
[0083] Suppose there are two sub-clusters in the workshop, one is a device cluster close to large production equipment, and the other is a device cluster close to small auxiliary equipment, and their spatio-temporal feature vector similarity is 0.8 after calculation, and the set merging threshold is 0.75. Since their similarity is higher than the merging threshold, the two clusters are merged into one device cluster. If there is a cluster containing only one device, and the number of this device is lower than the minimum scale threshold, for example, this device may be a temporary installation for testing a sensor in a certain area, since it does not have enough representativeness or monitoring significance, the isolated cluster is deleted. Through such operation, finally a plurality of stable device clusters are generated, which can better reflect the distribution and correlation of the security monitoring devices in the industrial park in the spatio-temporal characteristics, and provide a reasonable device grouping basis for subsequent security analysis and management.
[0084] In a possible implementation, step S140 comprises:
[0085] Step S141, an anomaly propagation graph with device clusters as nodes is constructed, and the weight of the edge in the anomaly propagation graph is determined by the time synchronization and spatial proximity of the abnormal signals between devices.
[0086] In this embodiment, for example, in a device cluster containing security monitoring devices in a production workshop and its surrounding area, there are multiple cameras, infrared sensing devices, and audio monitoring devices, etc. If a camera in the production workshop detects that a worker enters the workshop at a non-working time, and at the same time an infrared sensing device in the workshop detects that the temperature of a certain device suddenly rises, the time of the two abnormal signals is almost synchronous, and since the camera and the infrared sensing device are close in space, the weight of the edge connecting the nodes corresponding to the two devices in the anomaly propagation graph will be higher. If an audio monitoring device in the workshop detects an abnormal sound, but the sound is not synchronized in time with the previous two abnormal signals, and the audio monitoring device is far away from the previous two devices in space, then the weight of the edge connecting the nodes corresponding to it and the previous two devices will be lower. This anomaly propagation graph determines the weight of the edge through the time synchronization and spatial proximity of the abnormal signals between devices, thereby reflecting the correlation of abnormal signals between devices in the device cluster.
[0087] Step S142, input the spatio-temporal feature vector of each device cluster into the graph convolution layer of the anomaly propagation network model to extract the potential risk features of the cluster nodes.
[0088] For the equipment cluster of the above production workshop, the space-time feature vector thereof contains deployment coordinates of the equipment (e.g., specific positions of respective equipment in the workshop), monitoring time stamps (time information of data collection by the equipment), environmental context correlation degree (related information of the production environment in the workshop, etc.), and abnormal signal strength (comprehensive strength of various abnormal signals detected previously), and the like. After inputting these space-time feature vectors into the graph convolution layer, the graph convolution layer processes these information. Assuming that the equipment in the workshop has poor recent maintenance records, which can be reflected from the space-time feature vector, and that the personnel flow in the workshop has an abnormal increase in a specific time period, and that the operating temperature of part of the equipment in the workshop approaches a critical value, and the like, these information can extract potential risk features about possible risks of the equipment cluster under the processing of the graph convolution layer, such as increased risk of equipment failure, increased risk of violation operation, and increased risk of safety accident, and the like.
[0089] In step S143, the time recursion layer of the abnormal propagation network model is used to analyze the evolution mode of the potential risk features in consecutive time steps, and the risk outbreak probability of the cluster nodes in a future time window is predicted.
[0090] If the risk outbreak probability exceeds a preset probability, a device cooperative response instruction generation process is triggered, and the device cooperative response instruction generation process specifically includes:
[0091] According to the deployment coordinates and monitoring capabilities of the security monitoring equipment in the equipment cluster, the roles of the master device and the auxiliary device are allocated.
[0092] Based on real-time data feedback of the master device, the working mode and data collection frequency of the auxiliary device are dynamically adjusted.
[0093] A cooperative early warning signal transmission path across devices is generated to ensure low-delay synchronization of early warning information among devices in the cluster.
[0094] In the example of the production workshop, from the past few hours, the temperature of the equipment in the workshop continues to rise, the frequency of personnel entering the workshop in violation of rules also increases, and the unstable operation state of some equipment in the workshop continues to deteriorate. The time recursion layer analyzes the changes of these potential risk features in consecutive time steps. Assuming that the future time window is set to be the next one hour, the risk outbreak probability of the equipment cluster in this future time window is calculated to be 30% through analysis.
[0095] If the risk outbreak probability exceeds the preset probability, which is assumed to be 20%, the device cooperative response instruction generation process is triggered. First, according to the deployment coordinates and monitoring capabilities of the security monitoring devices in the device cluster, the roles of the master device and the auxiliary device are assigned. In the device cluster of the production workshop, since a high-definition camera located in the center of the workshop can cover a larger area and its data transmission stability is better, this camera is assigned as the master device. While the other cameras around the workshop, although the coverage is small, can supplement the monitoring dead angle, the infrared sensing device is used to accurately detect the temperature change of the device, and the audio monitoring device is used to monitor abnormal sound, these devices are assigned as auxiliary devices.
[0096] Based on the real-time data feedback of the master device, the working mode and data acquisition frequency of the auxiliary device are dynamically adjusted. For example, the master device finds that there is abnormal smoke in a certain area of the workshop, it can send instructions to the nearby infrared sensing device to increase the data acquisition frequency, in order to more accurately monitor the temperature change, because the smoke may be accompanied by abnormal temperature rise, more timely and accurate data is needed. At the same time, the master device will notify the surrounding cameras to adjust the shooting angle and focus on the area where the risk may exist, such as the area where the smoke appears or the area where the personnel gather, to obtain more detailed image information.
[0097] A cross-device cooperative warning signal transmission path is generated to ensure low-latency synchronization of warning information between devices in the cluster. Direct communication links are established between the master camera and each auxiliary device, using a high-speed and stable communication protocol. When the master device detects an abnormal situation, it can quickly send a warning signal to all auxiliary devices. For example, when the master camera finds a fire hazard in the workshop, it can send a warning signal to all infrared sensing devices, other cameras and audio monitoring devices in the workshop in a very short time, so that the entire device cluster can quickly respond, such as starting the fire extinguishing device or evacuating personnel, etc.
[0098] The step S150 comprises:
[0099] Step S151, collect the execution effect data of the device cooperative response instruction, the execution effect data includes risk suppression response time, device cooperation success rate and false positive rate.
[0100] In this process, the node weights of the anomaly propagation network model also need to be dynamically adjusted, and the cluster centers of the adaptive clustering algorithm need to be updated to optimize subsequent cluster division. First, the execution effect data of the device cooperative response instruction is collected, including risk suppression response time, device cooperation success rate, false positive rate, etc. In the example of a production plant device cluster, if it is found that the risk suppression response time from the occurrence of an anomaly (such as a fire hazard) to the start of device cooperative response (such as starting the fire extinguishing device or evacuating personnel) is relatively long, the device cooperation success rate is low, for example, some devices do not adjust the working mode or data collection frequency in a timely manner according to the instruction, and there is a certain false positive rate, for example, the device mistakenly judges normal device startup heat as abnormally high temperature.
[0101] Step S152, calculate the prediction error gradient of the anomaly propagation network model according to the execution effect data, and update the weight parameters of the graph convolution layer and the time recursion layer through the back propagation algorithm.
[0102] Due to the high false positive rate, the weight setting of the graph convolution layer for the normal state features of the device may be unreasonable. By adjusting the weight parameters related to the normal operation features of the device in the graph convolution layer through the back propagation algorithm, the model can be more accurate in judging the normal state and the abnormal state of the device. Due to the long risk suppression response time, the time step setting of the time recursion layer in predicting risk evolution may be inaccurate, so the weight parameters of the time recursion layer are adjusted to more accurately predict the speed and time node of risk evolution.
[0103] Step S153, reapply the updated anomaly propagation network model to the historical spatiotemporal feature vector to generate a corrected cluster-level risk prediction result.
[0104] In this embodiment, the spatiotemporal feature vector before the production plant device cluster is input into the updated anomaly propagation network model to obtain a new risk prediction result. For example, the previously predicted risk outbreak probability is 30%, which may be changed to 25% after correction.
[0105] Step S154, compare the differences between the cluster-level risk prediction results before and after correction, and identify the device cluster with the largest prediction deviation as the clustering center optimization target.
[0106] If it is found that the prediction deviation of the production plant device cluster is the largest, the device cluster is taken as the target of clustering center optimization.
[0107] Step S155, for the clustering center optimization target, interpolate the spatiotemporal feature vector mean of the clustering center optimization target and the feature vector of the adjacent cluster to generate a new clustering center and replace the original center.
[0108] Assuming that the spatio-temporal feature vector mean of the production workshop equipment cluster contains information such as average deployment coordinates, average monitoring timestamp, average environmental context correlation, and average abnormal signal strength, interpolate it with the feature vector of the adjacent warehouse equipment cluster to obtain a new cluster center. This new cluster center integrates some features of the production workshop and warehouse equipment cluster, and replaces the original cluster center of the production workshop equipment cluster with this new cluster center.
[0109] Step S156, trigger a new round of equipment cluster division process until the prediction deviation of all clusters is below the convergence threshold.
[0110] For example, re-cluster all security monitoring devices in the industrial park according to the new cluster center, and perform similar evaluation and adjustment for other equipment clusters. This process is repeated until the prediction deviation of each equipment cluster is small enough, below the convergence threshold, thereby optimizing the equipment cluster division and risk prediction capability of the entire security monitoring system, making the security monitoring of the industrial park more accurate and efficient, and being able to discover and respond to various potential security risks in time.
[0111] In one possible implementation, the method further comprises:
[0112] Step S210, introduce an adversarial training mechanism in the spatio-temporal feature fusion model, synthesize simulated heterogeneous data streams containing random noise through a generative adversarial network, and input the simulated data streams and real data streams into the spatio-temporal feature fusion model.
[0113] In this embodiment, the spatio-temporal feature fusion model plays a crucial role in the security monitoring system of the industrial park. To enhance its performance, an adversarial training mechanism is introduced. First, synthetic heterogeneous data streams containing random noise are generated through a generative adversarial network (GAN). In the industrial park, the synthesis of synthetic heterogeneous data streams needs to consider the actual security monitoring situation. For example, for the simulation of video frame sequences, the GAN generates corresponding video frame sequences according to the common scenes, personnel and vehicle activity patterns in each area of the park (such as production workshops, warehouses, office areas, etc.), while adding random noise to simulate the interference factors in the real environment, such as camera pictures may be affected by light changes, slight shaking, etc. For the simulation of infrared sensing signals, the heat source distribution and temperature changes of different devices during normal operation and possible abnormal situations are generated, and random noise is added, such as simulating the influence of temperature fluctuations around the warehouse due to weather changes or other external factors on infrared sensing signals. The simulation of audio waveforms is constructed according to common sound sources in the park (personnel communication sound, equipment operation sound, etc.), while considering random noise to simulate environmental noise interference. The simulation of device status logs is generated according to various state parameters during normal operation of the device and possible failure modes, and random noise is added to simulate possible inaccuracies or interference in log recording.
[0114] During a certain period of time, the security monitoring system of the park has collected real video frame sequences of production workshop cameras, real infrared sensing signals of infrared sensing devices around the warehouse, real audio waveforms of audio monitoring devices in the office area, and real device status logs of various security monitoring devices, while mixing the synthesized simulated corresponding data streams with them. Such mixed input can enable the spatio-temporal feature fusion model to learn and optimize in the presence of both real data and simulated data.
[0115] Step S220, calculate the feature extraction error of the spatio-temporal feature fusion model for the simulated data stream, and use the feature extraction error as the attention mechanism layer parameter of the adversarial loss function to optimize the model.
[0116] Taking a sequence of video frames as an example, the motion target trajectory and motion direction consistency parameters are extracted from the simulated video frame sequence through optical flow analysis, and compared with the pre-set accurate value (set according to the simulation of the actual situation) to calculate the error of this part. For the infrared sensing signal, the error is obtained by comparing the heat source distribution density and temperature gradient change rate extracted by frequency domain transformation with the standard value set during simulation. For the abnormal sound source positioning coordinates and sound pressure level mutation frequency obtained by decomposing the audio waveform and voiceprint features, and the device operation stability indicators and fault warning intervals obtained by analyzing the device status log, similar comparison with the standard value is performed to calculate the error. The errors of these modal features from the simulated data stream are integrated, and the integrated feature extraction error is used as the attention mechanism layer parameter of the adversarial loss function optimization model.
[0117] Step S230, when the spatio-temporal feature fusion model's feature extraction error of the simulated data stream is lower than the pre-set proportion of the real data stream error, it is determined that the spatio-temporal feature fusion model reaches the anti-noise training target.
[0118] Suppose the pre-set proportion is 80%, if the model's feature extraction error of the simulated data stream is 70% of the real data stream error, then it can be considered that the model has reached the anti-noise training target. This means that the model can better extract accurate features when processing data containing noise, thereby improving the reliability and accuracy in actual industrial park security monitoring.
[0119] In one possible implementation, the method further comprises:
[0120] Step S310, assigning a dynamic risk level label to each device cluster, which is generated by matching the cluster-level risk prediction result and the historical risk event library.
[0121] In the security monitoring of an industrial park, assigning a dynamic risk level label to each device cluster is an important step. This dynamic risk level label is generated by matching the cluster-level risk prediction result and the historical risk event library. For example, for a device cluster containing security monitoring devices around a production workshop, the cluster-level risk prediction result is obtained through the previous abnormal propagation network model analysis. If the prediction result shows that the device failure risk in the workshop is high and the personnel violation operation risk is moderate, and combined with the severity, frequency, etc. of the device failure, personnel violation, etc. events in the historical risk event library of the production workshop, a corresponding risk level label such as high risk level is matched for this device cluster. For a device cluster containing security monitoring devices in the office area, if the risk prediction result shows that there is no obvious abnormal situation in the office area, and combined with the fact that there are few serious security events in the historical risk event library of the office area, a low risk level label is matched for it.
[0122] Step S320, when the risk level labels of multiple device clusters are detected to be upgraded at the same time, a cross-cluster risk linkage analysis process is started, which includes:
[0123] Step S330, extracting the spatio-temporal feature vectors of the risk clusters and the edge weight data in the abnormal propagation graph.
[0124] Step S340, identifying the potential association paths between the risk clusters by a community discovery algorithm and calculating the risk transmission intensity on the potential association paths.
[0125] Step S350, if the risk transmission intensity exceeds the linkage threshold, merging the clusters on the potential association paths into a focus cluster and generating a global collaborative response strategy.
[0126] The global collaborative response strategy includes:
[0127] Election of a leading device node within the focus cluster to uniformly schedule the monitoring resources of all security monitoring devices.
[0128] Establishing a redundant data backup channel across clusters to enable seamless migration of critical data in the event of device failure.
[0129] Adjusting the cluster center position of the focus cluster to cover the spatio-temporal feature distribution range of all associated clusters.
[0130] When the risk level labels of multiple device clusters are detected to be upgraded at the same time, a cross-cluster risk linkage analysis process is started. Suppose in an industrial park, the risk level labels of a device cluster containing production workshop devices and a device cluster containing warehouse devices are upgraded from low risk to medium risk at the same time. First, the spatio-temporal feature vectors of the risk clusters (the production workshop device cluster and the warehouse device cluster) and the edge weight data in the anomaly propagation graph are extracted. The spatio-temporal feature vector of the production workshop device cluster contains the deployment coordinates of the devices in the workshop, the monitoring timestamps, the environmental context correlation degree of the workshop (such as the busy degree of the production process, the storage situation of dangerous goods, etc.), and the abnormal signal strength (such as the abnormal rise in device temperature, the strength corresponding to the situation that personnel violate the rules to enter a certain area, etc.), and the spatio-temporal feature vector of the warehouse device cluster contains the deployment coordinates of the devices in the warehouse, the monitoring timestamps, the environmental context correlation degree of the warehouse (such as the type of goods storage, the requirements for fire and moisture prevention, etc.), and the abnormal signal strength (such as the abnormal temperature and humidity of the warehouse, the strength corresponding to the security hidden danger of goods storage). At the same time, the edge weight data in the anomaly propagation graph is extracted, for example, in the production workshop device cluster, the edge weight between the sensor monitoring the device temperature and the camera monitoring the personnel activity, which reflects the correlation degree of the abnormal signals of the two (such as whether the personnel's reaction or operation is in compliance when the device temperature is abnormal), and in the warehouse device cluster, the edge weight between the sensor monitoring the warehouse humidity and the camera monitoring the goods handling, etc.
[0131] Then, the community discovery algorithm is used to identify the potential association path between the risk clusters and calculate the risk transmission strength on the potential association path. In the industrial park, the production workshop and the warehouse may have connections such as material transportation and device sharing, and the community discovery algorithm will identify such potential association paths. For example, the products produced in the production workshop need to be transported to the warehouse for storage, so the security monitoring devices on the transportation channel connecting the production workshop and the warehouse constitute a potential association path. When calculating the risk transmission strength on this path, the risk factors of the production workshop (such as device failure that may cause product quality problems, and then affect the warehouse storage) and the risk factors of the warehouse (such as warehouse humidity problems that may affect product quality, and trace back to the production link of the production workshop) and the abnormal signal correlation between the security monitoring devices on the path (such as the abnormal situation of the transportation vehicle monitored by the camera on the transportation channel and the association of the production workshop and the warehouse) are considered.
[0132] If the risk transmission intensity exceeds the linkage threshold, the clusters on the potential correlation path are merged into a focus cluster, and a global coordinated response strategy is generated. Assuming that the linkage threshold is 0.6, if the risk transmission intensity on the potential correlation path between the production workshop and the warehouse is calculated to be 0.7, the production workshop equipment cluster and the warehouse equipment cluster are merged into a focus cluster. For this focus cluster, a global coordinated response strategy is generated. A dominant device node is elected within the focus cluster, for example, a camera located at a transportation hub position between the production workshop and the warehouse is selected as the dominant device node, because this camera can monitor the shipment of the production workshop and the incoming of the warehouse at the same time, and has a good global view. This dominant device node uniformly schedules the monitoring resources of all security monitoring devices, such as adjusting the shooting angle and frequency of the cameras in the production workshop to better monitor the production link that may affect product quality, and adjusting the sensor monitoring parameters in the warehouse to ensure the safety of goods storage. A redundant data backup channel is established across clusters, for example, a high-speed data channel is established between the storage server in the production workshop and the storage server in the warehouse. When a device in the production workshop fails and data is lost, key data can be seamlessly migrated from the backup data in the warehouse, and vice versa. The position of the cluster center of the focus cluster is adjusted to cover the spatiotemporal feature distribution range of all associated clusters. For example, the position of the cluster center is adjusted from the original inside of the production workshop or the warehouse to a certain balance point between the production workshop and the warehouse, which can better reflect the spatiotemporal feature distribution of all devices in the merged focus cluster, thereby optimizing subsequent security monitoring and risk analysis.
[0133] In a possible implementation, the method further includes:
[0134] A hierarchical topology structure of the device cluster is constructed, and the hierarchical topology structure includes a physical layer, a feature layer, and a decision layer.
[0135] The physical layer records the deployment coordinates and hardware connection relationships of the devices of the cluster.
[0136] The feature layer stores the spatiotemporal feature vectors and historical risk prediction results of the cluster.
[0137] The decision layer maintains device coordinated response instructions and dynamic adjustment records.
[0138] Through the inter-layer mapping relationship between the topology structures, the following functions are achieved:
[0139] When the physical layer detects that a device node is invalid, a standby device with the closest spatiotemporal features is selected from the feature layer to join the cluster.
[0140] When the execution effect of the instructions of the decision layer does not meet the expectation, a spatiotemporal vector re-extraction process of the feature layer is triggered.
[0141] When the risk prediction result of the feature layer changes, the response instruction generation logic of the decision layer is updated synchronously.
[0142] In this embodiment, the physical layer mainly records the device deployment coordinates and hardware connection relationships of the cluster. In the industrial park, there are numerous security monitoring devices distributed in each region. For example, in the production workshop, cameras are installed in various corners of the workshop, entrances, and near key devices. Each camera has its precise deployment coordinates, such as a position 3 meters above the ground in the southeast corner of the workshop. These cameras are connected to other devices through wired or wireless networks, forming specific hardware connection relationships, such as several cameras connected to the same switch, and then to the security monitoring center of the park. For infrared sensor devices, they may be deployed around electrical equipment in the workshop or flammable material storage areas, also with clear deployment coordinates, and have hardware connections with related monitoring devices or servers for data transmission. Audio monitoring devices are distributed in office areas, public areas, etc., with their deployment coordinates accurately recorded, and hardware connection relationships ensuring that the collected audio waveform data can be smoothly transmitted to the processing center.
[0143] The feature layer stores the spatio-temporal feature vectors and historical risk prediction results of the cluster. Taking a cluster containing production workshop devices as an example, its spatio-temporal feature vectors include device deployment coordinates (already recorded in detail in the physical layer), monitoring time stamps (such as the time mark corresponding to the data collected by a certain camera at a specific time), environmental context correlation degree (for a production workshop, this involves the correlation between production process busy degree, device running state, personnel activity regularity, etc. and security monitoring), and abnormal signal strength (such as the signal strength corresponding to the sudden temperature rise of a device in the workshop, personnel violation into restricted areas, etc.). At the same time, the feature layer also stores historical risk prediction results, which are obtained through previous risk analysis processes. For example, in the past period of time, according to the running data of devices in the production workshop, personnel activity, etc., it is predicted that the device failure risk is at a medium level, and the personnel violation operation risk is low, etc. These historical data provide an important reference for subsequent security decisions.
[0144] The decision layer maintains device collaborative response instructions and dynamic adjustment records. When an abnormal situation occurs in the production workshop, the decision layer will generate device collaborative response instructions. For example, if a camera in the workshop detects that a device is smoking, the decision layer will generate instructions according to pre-set rules, requiring nearby infrared sensor devices to increase monitoring frequency, other cameras to adjust shooting angles and focus on the smoking device, and the broadcasting system in the workshop to issue an alarm. The decision layer also records the dynamic adjustment of these instructions, such as the initial setting of the infrared sensor device monitoring frequency increase amplitude is not enough, and further adjustment of the increase amplitude according to subsequent conditions, etc. adjustment records.
[0145] Various functions are achieved through the inter-layer mapping relationship between topologies. When the physical layer detects that a device node fails, the spare device with the closest spatiotemporal features is selected from the feature layer to join the cluster. Assuming that a camera in a corner of a production workshop suddenly fails (the physical layer detects that the device fails), in the feature layer, the system will find the spare camera with the closest spatiotemporal features to the failed camera. This spare camera may be close to the failed camera in deployment coordinates, its monitored area partially overlaps, and the data collected when it is working normally is similar to the failed camera in terms of environmental context correlation, abnormal signal strength, etc. After finding this spare camera, it is added to the device cluster to ensure that there is no loophole in the security monitoring of the production workshop.
[0146] When the execution effect of the instruction of the decision layer does not meet the expectation, the spatiotemporal vector re-extraction process of the feature layer is triggered. For example, the decision layer issues an instruction requiring the camera and infrared sensing device in the workshop to cooperatively monitor a suspected faulty device, but the actual execution effect is not good, and it cannot accurately determine whether the device is really faulty. At this time, the feature layer re-extracts the spatiotemporal feature vector of the related device. The video frame sequence of the camera is re-analyzed by optical flow to obtain more accurate motion target trajectory and motion direction consistency parameters, and the infrared sensing signal is re-transformed in the frequency domain to obtain more accurate heat source distribution density and temperature gradient change rate, etc., to provide a more reliable data basis for subsequent risk analysis.
[0147] When the risk prediction result of the feature layer changes, the response instruction generation logic of the decision layer is updated synchronously. For example, the feature layer adjusts the fault risk prediction of a device in the production workshop from low risk to high risk according to newly collected data and analysis results. After receiving this change, the decision layer updates its response instruction generation logic synchronously. Originally, for the low risk condition, it may only require regular inspection of the device state, but now for the high risk condition, the decision layer generates more stringent instructions, such as immediately stopping the device from running, dispatching technical personnel for comprehensive inspection, etc.
[0148] In one possible implementation, the method further includes:
[0149] An explainability analysis module is integrated in the abnormal propagation network model to visualize the basis of risk prediction decisions.
[0150] The explainability analysis module performs the following operations:
[0151] The high-dimensional feature activation map of the cluster node in the graph convolution layer is extracted, and a human-understandable semantic label is generated through dimension reduction mapping.
[0152] The focus of the time recursion layer at different time steps is recorded to form a visual timeline of the risk evolution path.
[0153] The contribution percentage of each influencing factor in the collaborative response instruction generation process of the labeling device.
[0154] When the artificial audit module proposes a correction opinion on the automatically generated response instruction, the labeling rules of the explainability analysis module are adjusted in reverse according to the correction opinion.
[0155] In the security monitoring system of the industrial park, the integration of the explainability analysis module in the abnormal propagation network model helps to improve the transparency and manageability of risk prediction.
[0156] The operation performed by the explainability analysis module is first to extract the high-dimensional feature activation map of the cluster node in the graph convolution layer, and then to generate human-understandable semantic labels through dimension reduction mapping. In the abnormal propagation network model corresponding to the device cluster containing the production workshop devices, the graph convolution layer processes the spatiotemporal feature vector and other data of the cluster node. For the device nodes in the production workshop, the high-dimensional feature activation map of the device contains various complex feature information of the device, such as the activation state of the device operating parameters, the association features with other devices, etc. after the graph convolution layer operation. Through dimension reduction mapping technology, these high-dimensional and difficult-to-understand feature information is converted into human-understandable semantic labels. For example, the semantic label generated after dimension reduction mapping of the high-dimensional feature activation map of a certain device node may be "device operating temperature close to critical value and associated device active frequently", which enables security personnel to intuitively understand the state characteristics of the device.
[0157] The recording time recursion layer focuses on different time steps, forming a visual time axis of the risk evolution path. In the security monitoring of the production workshop, the time recursion layer focuses on different factors at different time steps when analyzing the risk evolution of the device cluster. For example, at the initial time step, it may focus on the startup state of the device, the arrival of personnel, etc.; as time goes on, when the device has been running for a period of time, it may focus on factors such as temperature change, operating efficiency, etc. The explainability analysis module records the focus of attention at different time steps, forming a visual time axis. Security personnel can clearly see from the time axis how the risk evolves over time, such as the development process from the normal startup of the device to the gradual increase in temperature, and then to the risk state that may affect the production process.
[0158] The contribution percentage of each influencing factor in the generation of the device collaborative response instruction is marked. When an abnormal situation occurs in the production workshop, the decision layer generates a device collaborative response instruction, and multiple influencing factors participate in the generation. The explainability analysis module marks the contribution percentage of these influencing factors. For example, when a device in the workshop smokes and triggers a device collaborative response instruction, the factor of abnormal temperature rise of the device may account for 50% of the contribution, because it is the main reason for the smoke; the layout and running state of the surrounding devices may account for 20% of the contribution, because they may affect the spread of smoke and the safety of other devices; the operation of personnel may account for 10% of the contribution, and 20% may be other environmental factors. Such marking helps security personnel understand the basis for the generation of the device collaborative response instruction.
[0159] When the artificial audit module proposes a correction opinion on the automatically generated response instruction, the marking rules of the explainability analysis module are adjusted in reverse according to the correction opinion. Suppose the artificial audit module believes that in the previous case of device smoking, the contribution of the factor of abnormal temperature rise of the device should be higher, such as increased to 70%. The explainability analysis module will adjust its marking rules in reverse according to this correction opinion. In the analysis of subsequent similar situations, the contribution of each influencing factor will be more accurately marked, and the basis for the generation of the device collaborative response instruction will be more reasonable and transparent.
[0160] In one possible implementation, the method further includes:
[0161] An evolution mechanism of the device cluster is established, and the evolution mechanism includes:
[0162] Periodically collecting new monitoring data patterns of devices in the cluster to identify unmonitored event types.
[0163] When the occurrence frequency of the unmonitored event type exceeds a set learning threshold, an incremental learning process of the spatio-temporal feature fusion model is triggered.
[0164] In the incremental learning process, most layers of the original parameters of the abnormal propagation network model are frozen, and only the last layer of the fully connected network and the attention mechanism weight are fine-tuned.
[0165] The abnormal propagation network model updated by the incremental learning reextracts the spatio-temporal feature vector, and triggers dynamic reorganization of the device cluster.
[0166] The performance change of the model after each incremental learning is recorded, and when the performance improvement amplitude is lower than a degradation threshold, the abnormal propagation network model is rolled back to the last stable version.
[0167] In the security monitoring scene of an industrial park, the evolution mechanism of the device cluster helps the system to continuously adapt to new security needs and changes.
[0168] Periodically collect new monitoring data patterns of devices in the cluster, identify unmonitored event types. In a device cluster in a production workshop, security monitoring devices will periodically collect data. For example, as the production process upgrades, new devices are introduced into the workshop, which may generate some new monitoring data patterns. The camera may capture the appearance characteristics of the new device in a unique running state, the infrared sensing device may detect the different heat source distribution pattern of the new device, the audio monitoring device may collect the new sound frequency emitted by the new device when it is running, etc. Through the analysis of these new monitoring data patterns, unmonitored event types are identified. For example, the new device produces a low-frequency vibration sound in a certain running state, which has not been included in the scope of security monitoring, and is identified as an unmonitored event type.
[0169] When the occurrence frequency of unmonitored event types exceeds the set learning threshold, trigger the incremental learning process of the spatio-temporal feature fusion model. Assuming that the set learning threshold is 3 times a day, if the low-frequency vibration sound produced by this new device is detected 5 times a day, it exceeds the set threshold. At this time, the incremental learning process of the spatio-temporal feature fusion model is triggered. In this incremental learning process, most of the original parameters of the abnormal propagation network model are frozen, and only the last layer of fully connected network and attention mechanism weight are fine-tuned. This is done to learn and adapt to new event types based on existing model knowledge. For example, in the security monitoring of the production workshop, the layers related to the parameters of the normal running characteristics of the device, the common personnel activity pattern, etc. that have been learned before are frozen, while the last layer of fully connected network related to the new event type (which may involve the classification and judgment of new sound frequency characteristics, etc.) and the attention mechanism weight (adjusting the attention degree to the characteristics of new event types) are fine-tuned.
[0170] The updated abnormal propagation network model extracts spatio-temporal feature vectors again, and triggers the dynamic reorganization of the device cluster. After incremental learning, the updated abnormal propagation network model is used to extract spatio-temporal feature vectors of devices in the production workshop device cluster. For example, re-analyze the video frame sequence of the camera, the infrared sensing signal, the audio waveform, and the device state log, etc. to obtain spatio-temporal feature vectors containing new event type information. Then, according to these new spatio-temporal feature vectors, trigger the dynamic reorganization of the device cluster. Other devices with higher association with the new device may be recombined together to form a new device cluster structure, so as to better monitor and manage the new security situation.
[0171] The model performance change after each incremental learning is recorded, and when the performance improvement amplitude is lower than the degradation threshold, the abnormal propagation network model is rolled back to the last stable version. After each incremental learning, the system records the model performance change in detail, such as by comparing the accuracy of the new model in predicting risks in the production workshop, the identification accuracy of new event types, and other indicators to measure the performance improvement amplitude. Assuming that the degradation threshold is 10%, if the model performance improvement amplitude after incremental learning is only 5%, which is lower than the degradation threshold, it means that the incremental learning may not have achieved the expected effect, or even may have a negative impact on the model performance. At this time, the system rolls back to the last stable version of the abnormal propagation network model to ensure the stability and reliability of the security monitoring system.
[0172] Figure 2 The hardware structure of the intelligent security data analysis and decision system 100 based on artificial intelligence provided by the embodiment of the present application for implementing the above-mentioned intelligent security data analysis and decision method based on artificial intelligence is shown, as shown in Figure 2 The intelligent security data analysis and decision system 100 based on artificial intelligence can include a processor 110, a machine-readable storage medium 120, a bus 130, and a communication unit 140.
[0173] The machine-readable storage medium 120 can store data and / or instructions. In some embodiments, the machine-readable storage medium 120 can store data obtained from an external terminal. In some embodiments, the machine-readable storage medium 120 can store data and / or instructions used by the intelligent security data analysis and decision system 100 based on artificial intelligence to perform or use to complete the exemplary methods described in the present application.
[0174] In the specific implementation process, one or more processors 110 execute computer executable instructions stored in the machine-readable storage medium 120, so that the processor 110 can perform the intelligent security data analysis and decision method based on artificial intelligence of the above method embodiment. The processor 110, the machine-readable storage medium 120 and the communication unit 140 are connected through the bus 130, and the processor 110 can be used to control the transceiving action of the communication unit 140.
[0175] The specific implementation process of the processor 110 can refer to the above-mentioned various method embodiments executed by the intelligent security data analysis and decision system 100 based on artificial intelligence, which has similar implementation principles and technical effects, and will not be described here.
[0176] In addition, the embodiment of the present application also provides a readable storage medium, wherein computer executable instructions are pre-stored in the readable storage medium, and when the processor executes the computer executable instructions, the above-mentioned intelligent security data analysis and decision method based on artificial intelligence is realized.
[0177] It should be noted that the foregoing description of embodiments of the application has been presented for the purposes of illustration and description. It is not intended to be exhaustive or to limit the application to the precise form described, and many modifications, variations, and alternatives are possible.
Claims
1. An intelligent security data analysis and decision-making method based on artificial intelligence, characterized in that: The method comprises: Collect heterogeneous data streams uploaded in real time by multiple security monitoring devices in the target area, including video frame sequences, infrared sensor signals, audio waveforms, and device status logs; Perform multimodal feature extraction on the heterogeneous data stream using a spatiotemporal feature fusion model to generate a spatiotemporal feature vector corresponding to each security monitoring device, wherein the spatiotemporal feature vector includes device deployment coordinates, monitoring timestamp, environmental context relevance, and abnormal signal strength; Based on the spatiotemporal feature vectors, dynamically clustering the plurality of security monitoring devices using an adaptive clustering algorithm to generate a plurality of device clusters, wherein the similarity of the spatiotemporal feature vectors of the security monitoring devices within the same device cluster is greater than the similarity of the devices across clusters; For each device cluster, the abnormal signal correlation of the security monitoring devices in the device cluster is analyzed through the abnormal propagation network model, and cluster-level risk prediction results and device coordinated response instructions are generated; According to the cluster-level risk prediction results, dynamically adjust the node weights of the anomaly propagation network model and update the cluster centers of the adaptive clustering algorithm to optimize subsequent cluster divisions; The analysis of the abnormal signal correlation of the security monitoring devices in the device cluster through the abnormal propagation network model to generate cluster-level risk prediction results and device coordinated response instructions includes: Construct an anomaly propagation graph with device clusters as nodes. The weights of the edges in the anomaly propagation graph are determined by the temporal synchronization and spatial proximity of anomaly signals between devices. Input the spatiotemporal feature vector of each device cluster into the graph convolution layer of the anomaly propagation network model to extract the potential risk features of the cluster nodes; Analyzing the evolution pattern of potential risk characteristics at consecutive time steps through the time recursive layer of the anomaly propagation network model, and predicting the probability of risk outbreak of cluster nodes in the future time window; If the risk outbreak probability exceeds the preset probability, the device collaborative response instruction generation process is triggered, and the device collaborative response instruction generation process specifically includes: Assign the roles of master and auxiliary devices based on the deployment coordinates and monitoring capabilities of security monitoring devices within the device cluster; Dynamically adjust the working mode and data collection frequency of auxiliary equipment based on real-time data feedback from the main control equipment; Generate cross-device collaborative warning signal transmission paths to ensure low-latency synchronization of warning information between devices in the cluster; The dynamically adjusting the node weights of the abnormal propagation network model and updating the cluster centers of the adaptive clustering algorithm to optimize subsequent cluster divisions include: Collecting execution effect data of the device collaborative response instruction, the execution effect data including risk suppression response time, device collaboration success rate, and false alarm rate; Calculating the prediction error gradient of the abnormal propagation network model according to the execution effect data, and updating the weight parameters of the graph convolution layer and the time recursive layer through the back propagation algorithm; Reapply the updated anomaly propagation network model to the historical spatiotemporal feature vectors to generate revised cluster-level risk prediction results; Compare the differences in cluster-level risk prediction results before and after correction, and identify the device cluster with the largest prediction deviation as the cluster center optimization target; For the cluster center optimization target, interpolate the spatiotemporal feature vector mean of the cluster center optimization target with the feature vectors of adjacent clusters to generate a new cluster center and replace the original center; A new round of device clustering is triggered until the prediction deviations of all clusters are below the convergence threshold.
2. The intelligent security data analysis and decision-making method based on artificial intelligence according to claim 1 is characterized in that: The multimodal feature extraction is performed on the heterogeneous data stream by using the spatiotemporal feature fusion model to generate a spatiotemporal feature vector corresponding to each security monitoring device, including: Performing optical flow analysis on the video frame sequence to extract the trajectory of the moving object and the consistency parameters of the moving direction; Performing frequency domain transformation on the infrared sensor signal to extract the heat source distribution density and temperature gradient change rate; Performing voiceprint feature decomposition on the audio waveform to extract the abnormal sound source location coordinates and sound pressure level mutation frequency; Performing time series analysis on the device status log to extract device operation stability indicators and fault warning intervals; Inputting the moving target trajectory, heat source distribution density, abnormal sound source positioning coordinates and equipment operation stability index into the encoder layer of the spatiotemporal feature fusion model to generate a primary feature representation; Calculating the contribution weights of different modal features in the primary feature representation through the attention mechanism layer of the spatiotemporal feature fusion model, and dynamically weighted fusion of the different modal features according to the contribution weights; The weighted fusion features are spliced with the motion direction consistency parameter, the temperature gradient change rate, the sound pressure level mutation frequency and the fault warning interval to generate the spatiotemporal feature vector.
3. The intelligent security data analysis and decision-making method based on artificial intelligence according to claim 2 is characterized in that: The method of dynamically clustering the plurality of security monitoring devices based on the spatiotemporal feature vector using an adaptive clustering algorithm to generate a plurality of device clusters includes: Initialize the cluster centers of the adaptive clustering algorithm to the feature vectors corresponding to the first K security monitoring devices with the highest abnormal signal strength in the spatiotemporal feature vector, where K is the preset number of initial clusters; Calculate the cosine similarity between the spatiotemporal feature vector of each security monitoring device and all cluster centers, and assign the device to a temporary cluster based on the similarity threshold; For each temporary cluster, the mean and variance of the spatiotemporal feature vectors of the security monitoring devices within the temporary cluster are calculated. If the variance is greater than a set variance threshold, the temporary cluster is split into two subclusters and a new cluster center is added. Recalculating the similarity between all security monitoring devices and the updated cluster center based on the split subclusters, and iteratively performing the assignment and splitting operations until the internal variance of all clusters is lower than the set variance threshold; Adjacent clusters whose spatiotemporal feature vector similarity is greater than the set merging threshold are merged, and isolated clusters whose device number is lower than the minimum size threshold are deleted to generate multiple stable device clusters.
4. The intelligent security data analysis and decision-making method based on artificial intelligence according to claim 1 is characterized in that: The method further comprises: An adversarial training mechanism is introduced into the spatiotemporal feature fusion model, a simulated heterogeneous data stream containing random noise is synthesized by generating an adversarial network, and the simulated data stream is mixed with the real data stream and input into the spatiotemporal feature fusion model; Calculating the feature extraction error of the spatiotemporal feature fusion model on the simulated data stream, and using the feature extraction error as the attention mechanism layer parameter of the adversarial loss function optimization model; When the feature extraction error of the spatiotemporal feature fusion model for the simulated data stream is lower than a preset proportion of the real data stream error, it is determined that the spatiotemporal feature fusion model has achieved the anti-noise training goal.
5. The intelligent security data analysis and decision-making method based on artificial intelligence according to claim 4 is characterized in that: The method further comprises: Assign a dynamic risk level label to each device cluster. The dynamic risk level label is generated by matching the cluster-level risk prediction results and the historical risk event library. When it is detected that the risk level labels of multiple device clusters are upgraded simultaneously, the cross-cluster risk linkage analysis process is initiated. The process includes: Extract the spatiotemporal feature vectors of risk clusters and edge weight data in the anomaly propagation graph; Identify potential association paths between risk clusters through community discovery algorithms and calculate the risk transmission intensity along the potential association paths; If the risk transmission intensity exceeds the linkage threshold, the clusters on the potential correlation path are merged into a focus cluster, and a global coordinated response strategy is generated; The global coordinated response strategy includes: Elect the leading device node within the monitoring cluster to centrally dispatch monitoring resources of all security monitoring devices; Establish redundant data backup channels across clusters to enable seamless migration of critical data in the event of device failures; The cluster center position of the focus cluster is adjusted to cover the spatiotemporal feature distribution range of all associated clusters.
6. The intelligent security data analysis and decision-making method based on artificial intelligence according to claim 5 is characterized in that: The method further comprises: Constructing a hierarchical topology structure of the device cluster, wherein the hierarchical topology structure includes a physical layer, a feature layer, and a decision layer; The physical layer records the device deployment coordinates and hardware connection relationships of the cluster; The feature layer stores the spatiotemporal feature vectors and historical risk prediction results of the cluster; The decision-making layer maintains equipment collaborative response instructions and dynamic adjustment records; The following functions are achieved through the inter-layer mapping relationship between topological structures: When the physical layer detects a device node failure, it selects a backup device with the closest temporal and spatial characteristics from the feature layer to join the cluster; When the execution effect of the decision-making layer's instructions does not meet expectations, the spatiotemporal vector re-extraction process of the feature layer is triggered; When the risk prediction results of the feature layer change, the response instruction generation logic of the decision layer is updated synchronously.
7. The intelligent security data analysis and decision-making method based on artificial intelligence according to claim 6 is characterized in that: The method further comprises: Integrate an interpretability analysis module into the anomaly propagation network model to visualize the basis for risk prediction decisions; The interpretability analysis module performs the following operations: Extract high-dimensional feature activation maps of cluster nodes in the graph convolution layer and generate human-understandable semantic labels through dimensionality reduction mapping; Record the focus of the time recursive layer at different time steps to form a visual timeline of the risk evolution path; The contribution percentage of each influencing factor in the process of generating collaborative response instructions of the marking equipment; When the manual review module proposes correction opinions on the automatically generated response instructions, the labeling rules of the explainability analysis module are reversely adjusted according to the correction opinions.
8. The intelligent security data analysis and decision-making method based on artificial intelligence according to claim 7 is characterized in that: The method further comprises: Establishing an evolution mechanism for a device cluster, the evolution mechanism comprising: Periodically collect new monitoring data patterns from devices within the cluster to identify previously unmonitored event types; When the occurrence frequency of the unmonitored event type exceeds a set learning threshold, the incremental learning process of the spatiotemporal feature fusion model is triggered; In the incremental learning process, most layers of the original parameters of the anomaly propagation network model are frozen, and only the last layer of the fully connected network and the attention mechanism weights are fine-tuned; Re-extracting spatiotemporal feature vectors from the anomaly propagation network model updated through the incremental learning, and triggering dynamic reorganization of the device cluster; Record the model performance changes after each incremental learning. When the performance improvement is lower than the degradation threshold, roll back to the previous stable version of the anomaly propagation network model.
9. An intelligent security data analysis and decision-making system based on artificial intelligence, characterized in that: The artificial intelligence-based intelligent security data analysis and decision-making system includes a processor and a memory, the memory is connected to the processor, the memory is used to store programs, instructions or codes, and the processor is used to execute the programs, instructions or codes in the memory to implement the artificial intelligence-based intelligent security data analysis and decision-making method described in any one of claims 1 to 8 above.
Citation Information
Patent Citations
Large-scale data mining method based on multi-tuple data optimization
CN119089404A
Data exception traceability tracking and positioning method, system and device and storage medium
CN119416131A