Civil aviation safety situation research and judgment and risk prediction analysis

By building a security situation knowledge graph and a risk factor matching model, the shortcomings of digitalization and intelligence in airport security risk management are solved, and the automated risk management and real-time and dynamic risk prediction are realized, which improves the identification and management capabilities of airport security risks.

CN120258528AInactive Publication Date: 2025-07-04杨岳波
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510417817.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-07-04
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Airport security risk management has room for improvement in digitalization and intelligence, especially in the field of security risk prediction and security situation analysis. The lack of algorithm model support integrated with production operation environment systems has led to risk ratings that rely too much on subjective judgment and lack of information support, making it difficult to achieve real-time and dynamic risk control.

Method used

The security map construction module is used to build a security situation knowledge graph, integrate multi-source data through data acquisition technology, establish a risk factor matching model, and use model training to build a risk factor matching model, set risk fluctuation calculation components to realize automated management of unsafe events and dynamic adjustment of risk values.

Benefits of technology

It realizes fully automated management of airport security risks, improves the timeliness and accuracy of risk identification and analysis, breaks down the data barriers of departmental information systems, provides a comprehensive and accurate knowledge graph of security situations, and supports real-time risk prediction and dynamic management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120258528A_ABST
    Figure CN120258528A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of risk prediction, in particular to civil aviation security situation research and judgment and risk prediction analysis, which comprises a security map construction module, a security situation management module and a risk dynamic management module, the security map construction module adopts a data acquisition technology to acquire multi-source data, and constructs a security situation knowledge map; the security situation management module adopts a model training method to construct a risk factor matching model, and determines a management and control object in a security situation knowledge graph; setting a risk fluctuation calculation component, and calculating a change value of a risk value of a management and control object in the security situation knowledge graph; the risk dynamic management module is used for adjusting a corresponding risk value when an unsafe event occurs within a time threshold, so that the problem of information splitting between airport subsystems is solved, and the problems that the overall risk control of an airport is not dynamic enough and cannot be real-time are solved; and full-process automation capability is provided for airport risk data collection, risk prediction analysis and security situation research and judgment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of risk prediction, and more specifically, to the judgment of civil aviation safety situation and risk prediction analysis. Background Art

[0002] Due to the particularity of the civil aviation industry, safe operation has always been the most crucial. Take the safe operation of airports as an example. There are many airport operating units and the regional environment is complex. These characteristics increase the safety risk factors faced by airports and the probability of accidents. Incidents such as casualties on the airport apron and damage to aircraft will cause extremely serious losses to the airport; problems such as flight delays, lost luggage, and passenger congestion will also have an adverse impact on the normal operation of the airport.

[0003] To address these situations, the International Civil Aviation Organization has launched the Safety Management System (SMS for short). Its purpose is to use a systematic approach to conduct safety risk management of hazard sources and investigation and treatment of potential hazards throughout the civil aviation industry, effectively improving the safety level of the civil aviation industry and accumulating a large number of effective methods and rich experience.

[0004] However, from the overall situation, the level of airport safety risk management in terms of digitization and intelligence still needs to be improved. Especially in the two aspects of safety risk prediction and safety situation judgment, there is a lack of algorithm model support that can be directly integrated with the production operation environment system. There are mainly two reasons as follows: On the one hand, most of the current SMS management software is still mainly based on level-by-level reporting, and the information transmitted is mainly text-based. For problems such as violations, work deviations, and behavioral oversights that have not caused serious consequences, they are usually reported and processed in different systems (such as the "snap and report" system and the "safety whistleblower" system). These reported information has not been associated with the safety risks and safety situations in the SMS. On the other hand, the methods, measures, and accumulated experience adopted by the SMS mostly exist in the form of unstructured text and document knowledge. Most models are subjective experience models, or the data required by the models need to be obtained through subjective scoring, and it is difficult to directly convert them into algorithm models that can run on a computer. For example, some airports have constructed complex safety evaluation index systems, but these indicators lack data support from information systems in the actual production environment and often require manual subjective evaluation. Or the relevant data are scattered in different departments and systems, and it is very difficult to obtain and integrate them. The final result is that airport managers cannot comprehensively understand and monitor the risk situation, the control of the overall safety risk is not dynamic and real-time enough, the risk rating process relies too much on subjective judgment, and there is a lack of sufficient information support. In view of this, we propose the judgment of civil aviation safety situation and risk prediction analysis. Summary of the Invention

[0005] The object of the present invention is to solve the problem that there is room for improvement in the digitalization and intelligentization of airport safety risk management, especially in the fields of safety risk prediction and safety situation judgment, and there is a lack of algorithm model support for system integration with the production operation environment.

[0006] To achieve the above object, the present invention provides civil aviation safety situation judgment and risk prediction analysis, including a safety map construction module, a safety situation management module, and a risk dynamic management module; The safety map construction module uses data collection technology to collect multi-source data and construct a safety situation knowledge map; the safety situation management module uses a model training method to construct a risk factor matching model, analyzes the relationship between safety problem descriptions and risk factors, matches risk factors when a safety problem occurs, and determines the control objects in the safety situation knowledge map; a risk fluctuation calculation component is set to calculate the change value of the risk value of the control objects in the safety situation knowledge map; the risk dynamic management module is used to match the event classification and control objects corresponding to unsafe events, calculate the risk value, and set a time threshold, and adjust the risk value corresponding to the unsafe event when it occurs within the time threshold.

[0007] As a further improvement of this technical solution, the working principle of the data collection technology in the safety map construction module is as follows: send an HTTP request to the API endpoint storing multi-source data, inform the API of the multi-source data to be obtained, after receiving the request, the API extracts multi-source data from the corresponding data source according to the content of the request, and encapsulates the data in the response and returns it to the safety map construction module, where the multi-source data respectively includes: airport internal risk source files, airport system data, and standard files.

[0008] The beneficial effect of adopting the above further solution is that the data collection technology in the present invention realizes breaking the data barriers between the information systems of each operation department in the airport, integrating safety-related data scattered in different systems, providing a rich data basis for constructing a comprehensive and accurate safety situation knowledge map, and making the risk analysis and prediction of the safety situation knowledge map more reliable.

[0009] On the basis of the above technical solution, the present invention can also be improved as follows.

[0010] As a further improvement of this technical solution, the safety situation knowledge map constructed in the safety map construction module is composed of control objects, risk factors, event classifications, safety problem descriptions, event descriptions, and the relationships between them. The detailed working steps are as follows: S1. Extract control objects from the airport internal risk source files, enter them into the safety situation knowledge map, and create each control object as a node in the safety situation knowledge map; S2. Use the risk factor list mining algorithm to construct a risk factor list between risk factors and safety issues in the airport system data; create each risk factor node, connect the risk factor with the control object node therein, and add a "causative" relationship edge for each risk factor node and the corresponding control object node; and set the relationship edge weight according to the influence degree of the risk factor on the risk value of the control object; set classification rules to classify the risk factors according to human factors, facility and equipment factors, management factors, and environmental factors. S3. Set mapping rules to map each event category in the various standard documents one by one according to the mapping rules, and classify the event categories into the merged underlying event category set. Create an event classification node, establish the relationship between the event classification node and the control object node, and add a "corresponding" relationship edge for each event classification node and the corresponding control object node in the knowledge graph.

[0011] The beneficial effect of adopting the above further solution is that in the present invention, the safety situation knowledge graph links the airport unsafe events and safety issues through the control object by establishing the control object and taking the control object as the core, realizes the union of data of multiple systems in the knowledge graph, and predicts the possibility of unsafe events through the discovery of safety issues, and perceives the situation of airport operation safety and air defense safety.

[0012] On the basis of the above technical solution, the present invention can also be improved as follows.

[0013] As a further improvement of this technical solution, the working principle of the risk factor list mining algorithm in S2 is as follows: S2.1. Combine each influencing factor and safety issue into a safety issue transaction set, and calculate the support degree of each item set in the safety issue transaction set in turn: ; where is the item set in the safety issue transaction set; S2.2. Set the minimum support degree threshold, and construct the item sets with the support degree > the minimum support degree threshold as frequent item sets; S2.3. Traverse all non-empty subsets of the frequent item sets, use each non-empty subset as the antecedent of the risk factor list, and the part of the frequent item set excluding this subset as the consequent to generate the risk factor list; S2.4. Calculate the confidence degree of each risk factor list: ; where is the risk factor list; S2.5. Set the minimum confidence degree threshold, When the minimum confidence threshold is reached, it is determined that there is an association between the combination of risk factors in the risk factor list and the safety issue, that is, the corresponding risk factors have a significant impact on the safety issue, and it is constructed as a risk factor list.

[0014] As a further improvement of this technical solution, the working steps of S3 for event category fusion are as follows: S3.1. Sense different unsafe event classification standard sets in the standard file as , where represents the th standard; each standard includes an event category set of , where represents the th event category in standard , is the number of event categories in standard ; Let be the fused set of underlying event categories, , represents the th underlying event category after fusion, is the number of underlying event categories; S3.2. Define a mapping rule function , that accepts an event category as input and outputs its corresponding category in the fused set of underlying event categories according to pre-established rules, that is: ; ; S3.3. The mapping rule is formulated based on the characteristics of the event category. Sense that the event category has a feature set , where represents the th feature of the event category , is the number of features of the event category ; S3.4. For each event category in each standard , map it to the fused set of underlying event categories through the mapping rule function , that is: .

[0015] As a further improvement of this technical solution, the model training method in the security situation management module (200) uses data collection technology to regularly obtain security issue data with labeled security issue descriptions and corresponding risk factors from external systems for training a risk factor matching model. The specific working principle is as follows: Step 1: Use a word segmentation tool to split the security issue description and risk factor text into individual words, and map each word after word segmentation into a low-dimensional vector representation, that is, word embedding. Step 2: Perform deep feature extraction on the security issue description and risk factor text through a multi-layer self-attention mechanism and a feed-forward neural network to capture the semantic information and context relationships in the text, generate a text representation vector containing semantic information, and calculate the semantic similarity between the two to determine the matching degree. Step 3: Use the labeled security issue data as the training set. For each pair of security issue descriptions and risk factors, predict the similarity score, use a loss function to measure the difference between the predicted score and the true label, calculate the gradient of the loss function with respect to the model parameters through the backpropagation algorithm, and then use an optimization algorithm to update the model parameters to minimize the loss function, learn the internal relationship between the security issue description and the risk factor, and train a risk factor model.

[0016] As a further improvement of this technical solution, the security situation management module calculates the change value of the risk value of the control object in the security situation knowledge graph: The perceived current risk value is , the deduction standard for security issues is (determined according to the security issue type and severity), the security issue status is ( indicates that a problem is discovered, indicates that the problem has been rectified), then the change value of the risk value is calculated by the following formula: ; The updated risk value is: .

[0017] The beneficial effect of adopting the above further solution is to achieve full automation, save labor and time costs, avoid errors that may be caused by manual identification, and improve the timeliness and accuracy of risk identification and analysis.

[0018] On the basis of the above technical solution, the present invention can also be improved as follows.

[0019] As a further improvement of the present technical solution, the security situation management module is further configured to establish a security situation table with the risk values. The security situation table is divided into a detailed risk value fluctuation table and a general security situation table; and the security situation table provides a query interface externally.

[0020] The beneficial effect of adopting the above further solution is that the query interface provided externally by the security situation table in the present invention enables the staff to query the risk values and the details of risk changes of the control objects according to time, and provides statistical data on security issues, including the number of occurrences of various types of security issues and unsafe events, the number of issues that have been processed, and the number of unprocessed issues under each control object within a time range, assisting the management personnel to comprehensively perceive the security situation of airport operations.

[0021] Based on the above technical solution, the present invention can be further improved as follows.

[0022] As a further improvement of the present technical solution, the working principle of the risk dynamic management module for adjusting the risk value is as follows: Perceive the time difference of the occurrence of the same unsafe event. If the time difference > the time threshold, the risk value in the security situation table is restored by using an exponential decay function; if the same type of event occurs within the time threshold, points are deducted double on the basis of the unrecovered score.

[0023] As a further improvement of the present technical solution, the exponential decay function is: , where represents the time interval for each recovery, is the original score, represents the value of deducted points.

[0024] The beneficial effect of adopting the above further solution is that the application of the exponential decay function in the present invention makes the risk value recovery not a simple linear process, but a process that follows the actual risk reduction law more as time goes by, increasing the flexibility of risk management, being able to better adapt to the complex and changeable environment of the airport, and the risk recovery speed of different types of unsafe events can be set personalized by adjusting the parameters of the exponential decay function to meet the diverse security management needs of the airport.

[0025] Based on the above technical solution, the present invention can be further improved as follows. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 is the overall module schematic diagram of the present invention; Figure 2 is the working flow chart of the security map construction module of the present invention; Figure 3 is the working flow chart of the security situation management module of the present invention; Figure 4 This is the workflow diagram of the risk dynamic management module of the present invention; Figure 5 This is the entity-relationship schematic diagram of the knowledge graph in the present invention.

[0027] The meanings of each label in the figure are as follows: 100, security graph construction module; 200, security situation management module; 300, risk dynamic management module. Specific implementation manners

[0028] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.

[0029] In the first embodiment, in order to avoid the situation that there are many operating departments in the airport, each department has its own information system for data reception and processing, and these systems are often independent of each other. Although the data generated by each system is related, they cannot be interconnected. Also, since the risks within the airport often involve the data of multiple systems and departments, if multiple data cannot be shared, it will be difficult for traditional risk analysis and prediction models to integrate the security data of multiple systems from a more comprehensive perspective, and it will be even more impossible to establish the connections between various pieces of information, resulting in an incomplete and inaccurate perception of the airport's security situation. Refer to Figures 1 - 5 As shown: The security graph construction module 100 uses data acquisition technology to collect multi-source data for further construction of the security situation knowledge graph.

[0030] The working principle of the data collection technology in the security graph construction module 100 is as follows: Send an HTTP request to the API endpoint storing multi-source data, inform the API of the multi-source data to be obtained. After receiving the request, the API processes it according to the content of the request, extracts the multi-source data from the corresponding data sources (such as databases, file systems, etc.), and encapsulates the data in a specific format (such as JSON, XML, etc.) and returns it to the security graph construction module 100 in the response. The multi-source data respectively includes: the airport internal risk source files for control object construction (the airport internal risk source files include files such as airport internal risk source files, airport assessment index files, and Civil Aviation Administration's evaluation files on airport safety capabilities); the airport system data for risk factor list construction (risk factor models constructed by other past systems, and real safety problem data collected by each airport system); the standard files for event classification construction (multiple standard files such as the Civil Aviation Administration's unsafe event classification standard file and the airport group's unsafe event classification standard file). Thus, it realizes breaking the data barriers between the information systems of each operation department in the airport, integrating the safety-related data scattered in different systems, providing a rich data basis for constructing a comprehensive and accurate security situation knowledge graph, and making the risk analysis and prediction of the security situation knowledge graph more reliable.

[0031] To avoid that traditional security management methods often rely on manual experience and after-the-fact processing and are difficult to achieve real-time monitoring and accurate prediction of security risks, the security graph construction module 100 is also used to construct a security situation knowledge graph.

[0032] Specifically, the security situation knowledge graph constructed in the security graph construction module 100 consists of five types of entities: control objects, risk factors, event classifications, security problem descriptions, and event descriptions, and the relationships between them. The detailed working steps are as follows: S1. Extract control objects from the airport internal risk source files, enter them into the security situation knowledge graph, and create each control object as a node in the security situation knowledge graph; The specific working principle of extracting control objects is as follows: Adopt web crawler technology to construct a control object database, and compare each word in the control object database with the airport internal risk source files one by one: Starting from the first character of the airport internal risk source files, compare it with the words in the control object database in turn. For each word in the control object database, compare it character by character with the string of the same length starting from the current position in the risk source files. If all characters are the same, it is determined that a control object is extracted.

[0033] S2. Use the risk factor list mining algorithm to construct a risk factor list between risk factors and safety issues in airport system data (for example, "{personnel fatigue operation, runway slipperiness, aircraft operation error}", where "personnel fatigue operation" and "runway slipperiness" are risk factors, and "aircraft operation error" is a safety issue) to construct a risk factor list. The risk factor list refers to the influencing factors that cause the occurrence of accident types in the control object; Create each risk factor node, connect the risk factor to the control object node therein, and add a "causative factor" relationship edge for each risk factor node and the corresponding control object node; and set the relationship edge weight according to the influence degree of the risk factor on the risk value of the control object; Since the risk factor is the causative factor of the control object, when a certain safety issue is discovered, it is possible to know the control object with fluctuating risk values by querying the safety situation knowledge graph; Set classification rules to classify risk factors according to human factors, facility and equipment factors, management factors, and environmental factors. For example, "personnel fatigue operation" belongs to human factors based on the classification rules, and "runway slipperiness" belongs to environmental factors based on the classification rules.

[0034] S3. Set mapping rules to map each event category in each standard document one by one according to the mapping rules, and classify the event categories into the merged underlying event category set; Create an event classification node, establish the relationship between the event classification node and the control object node, and add a "corresponding" relationship edge for each event classification node and the corresponding control object node in the knowledge graph. Thus, in the safety situation knowledge graph, the control object links the safety issues and unsafe events recorded in different systems together. Further, by querying the safety situation knowledge graph, the safety events caused by potential safety hazards can be read out, or conversely, when an unsafe event occurs, it can be traced back to which links have problems, specifically realizing the prediction of the possibility of the occurrence of unsafe events.

[0035] The working principle of the risk factor list mining algorithm in S2 above is as follows: S2.1. Combine each influencing factor and safety issue into a safety issue transaction set, and calculate the support degree of each item set in the safety issue transaction set in turn (the support degree represents the frequency of an item set appearing in the safety issue transaction set, reflecting the appearance frequency of a certain item set in the safety issue transaction set): ; where is an item set in the safety issue transaction set (the item set is a set composed of risk factors and safety issues, such as "{personnel fatigue operation, runway slipperiness, aircraft operation error}" is an item set, and each element ("personnel fatigue operation", "runway slipperiness", "aircraft operation error") is called an item); S2.2. Set the minimum support threshold, and construct the frequent item sets for the item sets whose support > the minimum support threshold; S2.3. Traverse all non-empty subsets of the frequent item sets, use each non-empty subset as the antecedent of the risk factor list, and the part of the frequent item set excluding this subset as the consequent to generate the risk factor list; S2.4. Calculate the confidence of each risk factor list: ; where is the risk factor list; S2.5. Set the minimum confidence threshold, When the confidence is greater than or equal to the minimum confidence threshold, it is determined that there is an association relationship between the antecedent (risk factor combination) and the consequent (safety issue) in the risk factor list, that is, the corresponding risk factor has a significant impact on the safety issue, and construct it into the risk factor list.

[0036] The working steps of the above S3 for event category fusion are as follows: S3.1. Sense different unsafe event classification criteria sets in the standard file as , where represents the th criterion; each criterion includes an event category set as , where represents the th event category in the criterion , is the number of event categories in the criterion ; Let be the set of fused underlying event categories, , represents the th underlying event category after fusion, is the number of underlying event categories; S3.2. Define the mapping rule function , accepts the event category as input and outputs its corresponding category in the set of fused underlying event categories according to the pre-established rules , that is: ; S3.3. The mapping rule is formulated based on the characteristics of the event category. Sense that the event category has a feature set , where represents the th feature of the event category , For the event category the number of features

[0037] For example, for the event categories in the Civil Aviation Administration of China standards its feature set is ; The mapping rule set is ; S3.4. For each event category in each standard map it to the merged underlying event category set through the mapping rule function i.e., .

[0038] Example Refer to Figure 5 , Figure 5 which is a simple knowledge graph entity-relationship diagram. The diagram labels two control objects, FOD and aircraft damage. Risk factors such as construction personnel's non-compliant operations (human factors), inadequate equipment management (management factors), and pavement damage (environmental factors) are all causative factors for FOD and aircraft damage; event classifications such as not entering the airport movement area as required and finding foreign objects belong to FOD, and engine ingestion of foreign objects, animal strikes, and lightning strikes belong to aircraft damage

[0039] If an unsafe event of the type of finding foreign objects occurs at the airport, it can be queried from the graph to check for safety problems such as equipment management and pavement damage. If problems are found, they can be handled in a timely manner to avoid the recurrence of unsafe events caused by safety problems

[0040] Example 2. On the basis of Example 1, in order to avoid the problems of information fragmentation between airport subsystems and the lack of dynamics and real-time capabilities in overall airport risk control, therefore refer to Figure 1 , Figure 2 and Figure 3As shown in the figure, the difference between this embodiment and the first embodiment is that the security situation management module 200 constructs a risk factor matching model by using the model training method (for determining the risk factors in security problems and further for matching the corresponding control objects). The model training method uses data acquisition technology to regularly obtain security problem data with labeled security problem descriptions and corresponding risk factors from external systems (the security problem data includes data such as security hazards, security inspections, and illegal operations), trains the risk factor matching model, solves the problem of information fragmentation between airport subsystems, and the problem that the overall risk control of the airport is not dynamic enough and cannot be real-time, provides an automated ability for the whole process of airport risk data collection, risk prediction analysis, and security situation judgment, and comprehensively improves the airport's risk handling ability. The specific working principle is as follows.

[0041] Step 1: Use a word segmentation tool to split the security problem description and risk factor text into individual words, map each word after word segmentation to a low-dimensional vector representation, that is, word embedding. Let the size of the vocabulary be , and the word embedding dimension be (the purpose of word embedding is to convert discrete words into continuous low-dimensional vector representations so that the model can process them). Through the embedding matrix convert each word into a word vector .

[0042] Step 2: Use a multi-layer self-attention mechanism and a feed-forward neural network to perform deep feature extraction on the security problem description and risk factor text, capture the semantic information and context relationships in the text, generate a text representation vector containing semantic information, and calculate the semantic similarity between the two to judge the matching degree.

[0043] The self-attention mechanism can assign different attention weights to each word according to the semantic associations between words in the text. Specifically, each word in the input sequence is mapped into three different vectors: a query vector, a key vector, and a value vector. By calculating the dot product between the query vector and all key vectors and dividing by a scaling factor (usually the square root of the key vector dimension), the attention score is obtained. The calculation formula is as follows: The text vector sequence of the perceived security problem description is: , and the text vector sequence of the risk factor is: ; where and are the word vectors in the security problem description and risk factor text respectively.

[0044] Calculate the query, key, and value vectors: Security problem description text: ; Risk factor text: ; Where is a learnable weight matrix; Calculate the attention distribution: The attention distribution of the security issue description text is ; The attention distribution of the risk factor text is ; Calculate the self-attention score: The self-attention score of the security issue description text is ; The self-attention score of the risk factor text is .

[0045] Perform further non-linear transformation on the output of the self-attention mechanism through a feed-forward neural network, introduce non-linearity through an activation function, increase the expressive power of the model, and generate a text representation vector containing rich semantic information. The calculation formula is as follows: Perceive the self-attention score of the security issue description text , through the feed-forward neural network: ; Perceive the self-attention output of the risk factor text , through the feed-forward neural network: ; where is the learnable weight matrix and bias vector, is the activation function; Semantic similarity calculation and matching degree judgment: ; where is the security issue description text vector and the risk factor text 's similarity, represents the dot product of vectors, represents the norm of the vector; Set the threshold , if , then it is determined that the security issue description and the risk factor match; otherwise, it is determined that they do not match.

[0046] Step 3: Use the labeled security issue data as the training set. For each pair of security issue descriptions and risk factors, predict the similarity score, use the loss function to measure the difference between the predicted score and the true label, calculate the gradient of the loss function with respect to the model parameters through the backpropagation algorithm, and then use the optimization algorithm to update the model parameters to minimize the loss function, thereby learning the internal relationship between the security issue description and the risk factor, and training a risk factor model. The detailed working principle and calculation formula: Perceive that the true label is (0 means not matching, 1 means matching), the similarity score predicted by the model is converted to a probability through the sigmoid function, then the cross-entropy loss function is: ; During the optimization process, the optimization algorithm is used to update the model parameters : ; ; ; ; ; where is the gradient of the loss function with respect to the parameter , and are the first and second moment estimates of the gradient respectively, and are hyperparameters of the optimization algorithm, is the learning rate, is a constant, is the number of iterations, which improves the accuracy of the model. The accuracies of event classification and risk factor identification both reach 90%. The automated processing flow can save manpower, reduce human errors in identification, and at the same time, the automated flow reduces the risks of data omission and abuse, improving the data security of the entire system.

[0047] The security situation management module 200 constructs a risk factor matching model. When the subsequent input is the description of the security problem "Construction machinery and tools are randomly placed without fixation at the construction site", the risk factor matching model outputs the risk factor corresponding to "Construction workers operating in violation of regulations"; After constructing the risk factor matching model, the security situation management module 200 perceives the risk factors output by the risk factor matching model, retrieves the nodes associated with the risk factors in the security situation knowledge graph, finds the corresponding relationship edges, and determines the control objects corresponding to the risk factors.

[0048] Step 4: Set up a risk fluctuation calculation component (the risk fluctuation calculation component customizes the total score and deduction criteria according to the airport situation and different types of security problems, and calculates the change value of the risk value according to the status of various security problems (problem discovered or problem rectification completed)). Use the security problem status field in the security problem data as the input of the risk fluctuation calculation component. The risk fluctuation calculation component is used to calculate the change value of the risk value: Perceive the current risk value as , the deduction standard for the security problem is (determined according to the type and severity of the security problem), the security problem status is ( indicates that the problem is discovered, indicates that the problem rectification is completed), then the change value of the risk value is calculated as follows: ; The updated risk value is: 。

[0049] Detailed list of risk value fluctuations Step 5: Establish a security situation table, which is divided into a detailed list of risk value fluctuations and a general security situation table. (The general security situation table records the current scores of each control object, and the detailed list of risk value fluctuations records the numerical values of each score change and the sources of risk value changes). According to the control objects matched in Step 2 and the risk values calculated in Step 3, update the relevant information to the security situation table, add a new record to the detailed list of risk value fluctuations, including the numerical value of score change and the source of risk value change; find the corresponding control object record in the general security situation table and update its current score; Moreover, the security situation table provides an external query interface, through which managers can query the current overall security situation of the airport. The interface supports multiple query methods, such as querying by time range, by control object, by risk value range, etc. For example, managers can query the overall security situation of the airport in the past week, or query the current risk value and risk change details of the "aircraft damage" control object.

[0050] General security situation table Example: For example, the system obtains a safety hazard data from the outside. The hazard description is "construction machinery and tools at the construction site are randomly placed without fixation", and the hazard status is "under rectification". Through the risk factor matching model, it is obtained that this hazard belongs to the risk factor of

construction personnel's illegal operation

[0051] Embodiment 3, based on Embodiment 2, in order to avoid the problem of lack of dynamics and flexibility in the handling of unsafe events, if it is impossible to reasonably adjust the risk deduction according to factors such as the occurrence frequency and time interval of unsafe events, it is difficult to achieve precise dynamic management of airport security risks. Therefore, referring to Figure 4 As shown, the difference between this embodiment and Embodiment 1 is that: the risk dynamic management module 300 uses the model training method again to construct an event classification model, and predicts through the event classification model, and matches the event classification and control objects corresponding to the unsafe event description text through the security situation knowledge graph; uses the risk fluctuation calculation component to calculate the risk value of the unsafe event.

[0052] Set a time threshold. If the same unsafe event does not occur within the time threshold, the deduction points caused by the unsafe event will gradually recover over time; the recovery process is described by an exponential decay function. The exponential decay function , where represents the time interval for each recovery, is the original score, represents the deduction score value If the same type of event occurs within the time threshold, the deduction points will be doubled on the basis of the unrecovered score.

[0053] Example: For example, the system obtains an unsafe event data from the outside. The event text is "The aircraft encounters lightning strike during flight". Through the event classification model, it is obtained that this unsafe event belongs to [Lightning Strike / Electric Shock]. Querying the atlas shows that this classification belongs to the control object [Aircraft Damage].

[0054] Through the calculation of the risk fluctuation calculation component, it is found that the lightning strike / electric shock unsafe event needs to deduct m points. Finally, in the safety situation table, subtract m points from the existing score of aircraft damage, and record the m-point deduction with the source of the unsafe event in the detailed list. If no event of the same type occurs after 1 month, calculate the value of the recovered score according to the exponential decay function. In the safety situation table, add the corresponding score to the existing score of aircraft damage, and record the score addition with the source of no event of the same type in the detailed list.

[0055] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art of this industry should understand that the present invention is not limited by the above embodiments. The above embodiments and descriptions in the specification are only preferred examples of the present invention and are not used to limit the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.

Claims

1. Civil aviation safety situation assessment and risk prediction analysis, characterized in that It includes a security graph construction module (100), a security situation management module (200), and a risk dynamic management module (300); The security graph construction module (100) uses data collection technology to collect multi-source data and construct a security situation knowledge graph; the security situation management module (200) uses a model training method to construct a risk factor matching model, analyze the relationship between security problem descriptions and risk factors, match risk factors when security problems occur, and determine the control objects in the security situation knowledge graph; A risk fluctuation calculation component is set to calculate the change value of the risk value of the control objects in the security situation knowledge graph; the risk dynamic management module (300) is used to match the event classification and control objects corresponding to unsafe events, calculate the risk value, and set a time threshold to adjust the risk value corresponding to the unsafe events when they occur within the time threshold.

2. The civil aviation safety situation judgment and risk prediction analysis according to claim 1, characterized in that: The working principle of the data collection technology in the security graph construction module (100) is as follows: Send an HTTP request to the API endpoint storing multi-source data, inform the API of the multi-source data to be obtained. After receiving the request, the API extracts the multi-source data from the corresponding data sources according to the content of the request, and encapsulates the data in the response and returns it to the security graph construction module (100), where the multi-source data respectively includes: airport internal risk source files, airport system data, and standard files.

3. The civil aviation safety situation assessment and risk prediction analysis according to claim 2, characterized in that: The security situation knowledge graph constructed in the security graph construction module (100) consists of control objects, risk factors, event classifications, security problem descriptions, event descriptions, and the relationships between them. The detailed working steps are as follows: S1. Extract control objects from the airport internal risk source files and enter them into the security situation knowledge graph, and create each control object as a node in the security situation knowledge graph; S2. Use the risk factor list mining algorithm to construct a risk factor list between risk factors and security problems in the airport system data; create each risk factor node, connect the risk factor with the control object nodes among them, add a "causative" relationship edge for each risk factor node and the corresponding control object node; and set the relationship edge weight according to the influence degree of the risk factor on the risk value of the control object; set classification rules to classify the risk factors into human factors, facility and equipment factors, management factors, and environmental factors; S3. Set mapping rules to map each event category in the standard files one by one according to the mapping rules, and classify the event categories into the merged underlying event category set; Create an event classification node, establish the relationship between the event classification node and the control object node, and add a "corresponding" relationship edge for each event classification node and the corresponding control object node in the knowledge graph.

4. The civil aviation safety situation assessment and risk prediction analysis according to claim 3, characterized in that: The working principle of the risk factor list mining algorithm in S2 is as follows: S2.

1. Combine each influencing factor and safety issue into a safety issue transaction set, and calculate the support degree of each item set in the safety issue transaction set in turn: ; where is the item set in the safety issue transaction set; S2.

2. Set the minimum support threshold, and construct the item sets with support > the minimum support threshold as frequent item sets; S2.

3. Traverse all non-empty subsets of the frequent item set, use each non-empty subset as the antecedent of the risk factor list, and the part of the frequent item set excluding this subset as the consequent to generate the risk factor list; S2.

4. Calculate the confidence level of each risk factor list: ; where is the risk factor list; S2.

5. Set the minimum confidence threshold. When the minimum confidence threshold is reached, it is determined that there is an association between the combination of risk factors in the risk factor list and the safety issue, that is, the corresponding risk factors have a significant impact on the safety issue, and it is constructed as a risk factor list.

5. The civil aviation safety situation judgment and risk prediction analysis according to claim 4, characterized in that: The working steps of fusing the event categories in S3 are as follows: S3.

1. Perceive different insecure event classification criteria sets in the standard file as , where represents the -th criterion; each criterion includes an event category set as , where represents the -th event category in the criterion , and is the number of event categories in the criterion .​ Let be the set of fused underlying event categories, , denote the th fused underlying event category, and be the number of underlying event categories; S3.

2. Define the mapping rule function , Accept the event category as input, and output its corresponding category in the merged set of underlying event categories according to the pre-established rules, that is: ; ; S3.

3. The mapping rule is formulated based on the event category features to perceive the event category has a feature set , where represents the th feature of the event category is the number of features of the event category ; S3.

4. For each standard and for each event category in it, map it to the set of fused underlying event categories through the mapping rule function, i.e.: .

6. The civil aviation safety situation judgment and risk prediction analysis according to claim 5, characterized in that: The model training method in the security situation management module (200) uses data acquisition technology to periodically obtain security problem data with labeled security problem descriptions and corresponding risk factors from an external system for training the risk factor matching model. The specific working principle is as follows: Step 1: Use a word segmentation tool to segment the security issue description and risk factor text into individual words, and map each word after word segmentation into a low-dimensional vector representation, namely word embedding. Step 2: Perform deep feature extraction on the security issue description and risk factor text through a multi-layer self-attention mechanism and feedforward neural network to capture the semantic information and contextual relationship in the text, generate a text representation vector containing semantic information, and calculate the semantic similarity between the two to determine the degree of matching; Step 3: Use the labeled security issue data as the training set. For each pair of security issue descriptions and risk factors, predict the similarity score. Use the loss function to measure the difference between the predicted score and the true label. Calculate the gradient of the loss function with respect to the model parameters through the back propagation algorithm. Then use the optimization algorithm to update the model parameters to minimize the loss function. In this way, the intrinsic relationship between the security issue descriptions and the risk factors is learned, and the risk factor model is trained.

7. The civil aviation safety situation assessment and risk prediction analysis according to claim 6, characterized in that: The security situation management module (200) calculates the change value of the risk value of the control object in the security situation knowledge graph: The perceived current risk value is , and the deduction standard for safety issues is (determined according to the type and severity of safety issues), and the status of safety issues is ( indicates that a problem is discovered, indicates that the problem rectification is completed), then the change value of the risk value The calculation formula is: ; Updated risk value is as follows: .

8. The civil aviation safety situation judgment and risk prediction analysis according to claim 1, characterized in that: The security situation management module (200) is also used to establish a security situation table containing the risk value, the security situation table being divided into a risk value fluctuation detail table and a security situation summary table; and the security situation table provides an external query interface.

9. The civil aviation safety situation assessment and risk prediction analysis according to claim 8, characterized in that: The working principle of the risk dynamic management module (300) to adjust the risk value is as follows: The time difference between the occurrence of the same unsafe event is perceived. If the time difference is greater than the time threshold, the risk value in the security situation table is restored by using an exponential decay function; if the same type of event occurs within the time threshold, the points are doubled based on the unrestored score.

10. The civil aviation safety situation judgment and risk prediction analysis according to claim 9, characterized in that: The exponential decay function is as follows: , where represents the time interval for each recovery, is the original score, represents the deducted score value.