Smart park monitoring method and system based on end-to-end cooperation
By constructing a collection of collaborative paths in the smart park monitoring system and injecting perturbations, extracting perturbations feedback, combining behavior generation path inversion and trust recovery judgment, the existing system's misjudgment problem of forged collaborative paths is solved, and the accurate identification and reconstruction of trusted paths is achieved, and the security and accuracy of the system are improved.
Patent Information
- Application Number
- CN202510742143.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-05
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-06-05
AI Technical Summary
The existing smart park monitoring system relies on the coordinated consistency judgment of multi-terminal data, and lacks verification of the authenticity of the coordinated path, which leads to attackers bypassing security judgments by forging data and forming misjudgments.
By constructing an initial collaborative path set, injecting perturbations and extracting perturbations feedback, generating elastic response trajectories, combining behavior generation path inversion and trust recovery determination, identifying pseudo-consistent collaborative behavior and reconstructing trusted paths.
It realizes accurate identification of forged collaborative paths and structural reconstruction of trusted paths, breaks through the assumption of "coordination is truth", and improves the security and accuracy of the monitoring system.
Smart Images

Figure CN120378459A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of end - to - end collaborative intelligent park monitoring and management. More specifically, the present invention relates to an intelligent park monitoring method and system based on end - to - end collaboration. Background Art
[0002] In the existing management system of intelligent parks, the identity confirmation of personnel behavior and event linkage usually rely on a collaborative verification mechanism of multi - terminal information. Generally speaking, this mechanism makes a fusion judgment based on data provided by multiple heterogeneous perception sources such as access card swiping, face recognition, WiFi trajectory, video images, etc.
[0003] To improve the automation level and response efficiency, system design usually tends to take the consistency of multi - terminal data as a prerequisite for triggering trust judgment and action execution. That is, when multiple data sources show collaborative matching in terms of time and semantics, the system considers the behavior legal and automatically passes the verification or completes the instruction operation. This type of collaborative verification mechanism in the prior art has been widely deployed in multiple intelligent park platforms and is used as the core criterion to replace manual intervention.
[0004] However, the above - mentioned technical routes are generally based on the default that the data sources of each terminal are independently credible, lacking the authenticity verification of the generation path of the collaborative relationship itself. With the development of technologies such as sensor simulation, image replacement, and communication timing manipulation, attackers can construct a set of forged data that is synchronized in time and matched in content, causing the system to misjudge it as a real behavior, and then bypassing the due anomaly recognition mechanism.
[0005] Since the system trust logic is essentially based on the assumption that "collaborative consistency equals authenticity", the higher the degree of collaboration, the greater the probability of system misjudgment, thus forming a structural paradox: the system relies on multi - terminal collaboration to improve security, while high - degree collaboration itself is exploited by attackers as a means to avoid security judgment. Summary of the Invention
[0006] In order to overcome the above - mentioned defects of the prior art, embodiments of the present invention provide an intelligent park monitoring method and system based on end - to - end collaboration. By injecting multi - type perturbations into the collaborative path and dynamically extracting its response elastic characteristics, combined with behavior generation path inversion and trust recoverability determination, the identification of pseudo - consistent collaborative behavior and the structural reconstruction of the trusted path are realized, thus solving the core problem that the existing system misidentifies the forged collaborative path as a real behavior, resulting in monitoring misjudgment.
[0007] To achieve the above object, the present invention provides the following technical solution: An intelligent park monitoring method based on end - to - end collaboration, comprising:
[0008] Obtain the collaborative behavior structure of multi-source synchronous perception data in the smart park. By constructing an initial set of collaborative paths and establishing an end-to-end collaborative behavior chain, extract candidate trusted paths in the park that meet the terminal response synchronization and type cross characteristics;
[0009] Execute perturbation injection on the terminals in the preliminary trusted collaborative chain and extract the perturbation feedback results to generate an elastic response trajectory with quantifiable characteristics;
[0010] Identify the elastic response abnormal chain that can be used for reverse derivation to generate paths by constructing elastic indicators and comparing with abnormal conditions;
[0011] Identify unnatural behavior paths that do not meet the device response conditions by constructing a behavior generation trajectory graph and calculating the transfer logic factor in the path, and output a pseudo-consistent collaborative behavior chain;
[0012] Execute light perturbation verification and recovery feature reconstruction on the paths weakened by behavior trust, identify the trust recoverable paths that meet multiple perturbation response constraint conditions, and output the final trusted collaborative path graph and the risk label of the pseudo-consistent chain for subsequent intervention decisions of the system.
[0013] In a preferred embodiment, obtain the perception behavior data set in the smart park monitoring. The perception behavior data set includes the card swiping event sequence, face recognition record sequence, and movement trajectory sequence of the smart park. Through the perception behavior data set, perform timestamp alignment operation and output a collaborative candidate data window; perform cross-modal fusion operation on each group of synchronous perception data in the collaborative candidate data window, and output an initial set of collaborative paths through behavior matching degree calculation;
[0014] For each path in the initial set of collaborative paths, extract its collaborative terminal combination group; the collaborative terminal combination group includes card swiping devices, face recognition terminals, and trajectory perception nodes.
[0015] In a preferred embodiment, perform structural connectivity analysis on the path structure of the collaborative terminal combination group, obtain an end-to-end collaborative behavior chain, construct a consistent collaborative path graph, extract the corresponding terminal response time series for each path chain in the consistent collaborative path graph, perform response time series continuity detection, and output a group of behavior synchronization chains;
[0016] If there is a terminal response time interval fluctuation less than the preset interval fluctuation threshold in the group of behavior synchronization chains, and the terminal type cross ratio is not lower than the lower limit of the preset cross ratio threshold, then mark the corresponding chain in the group of behavior synchronization chains as a preliminary trusted collaborative chain.
[0017] In a preferred embodiment, inject perturbation requests to each terminal in the preliminary trusted collaborative chain; the perturbation requests include path offset perturbation, identity confidence perturbation, and trigger timing perturbation;
[0018] By injecting the terminal behavior sequence after perturbation, extracting the set of perturbation response behavior trajectories, and constructing an end-to-end perturbation feedback flow; for each terminal trajectory in the perturbation feedback flow, perform dynamic recovery period analysis and output a set of perturbation recovery paths;
[0019] For each path in the set of perturbation recovery paths, extract the recovery response time, behavior deviation amplitude, and path adjustment frequency, and construct a perturbation elasticity index vector group.
[0020] In a preferred embodiment, if the recovery response time of any path in the perturbation elasticity index vector group exceeds the preset upper limit of the recovery period, and the combined value of the deviation amplitude and adjustment frequency exceeds the target elasticity distribution interval, then mark this path as an elastic response abnormal chain;
[0021] The terminals and path structures marked in the elastic response abnormal chain correspond to the established path structures in the collaborative behavior chain, and the path structures are used as the basis for back-deriving the behavior generation path.
[0022] In a preferred embodiment, for the set of terminals in the elastic response abnormal chain, extract its trigger time flow and behavior state transition flow, and construct a time-behavior generation trajectory diagram; for each behavior transition path in the time-behavior generation trajectory diagram, extract its transition logic factor and the original behavior start data; the original data includes personnel identity authentication input, device trigger events, and task scheduling records;
[0023] If the transition logic factor of any behavior transition path does not meet the preset original device trigger condition, then determine that this path is an unnatural behavior path.
[0024] In a preferred embodiment, summarize all unnatural behavior paths to form an abnormal behavior chain group, and the abnormal behavior chain group corresponds to the sub-path set marked as the elastic response abnormal chain; for each behavior path in the abnormal behavior chain group, perform behavior reconstruction verification, and generate a behavior generation credibility factor through the joint determination of trajectory closure, behavior causal continuity, and identity operation consistency;
[0025] If the behavior generation credibility factor is lower than the preset trust score baseline, and its corresponding elastic recovery index meets the conditions of the elastic response abnormal chain, then mark this path as a pseudo-consistent collaborative behavior chain.
[0026] In a preferred embodiment, for the terminal path structure in the pseudo-consistent collaborative behavior chain, perform behavior granularity backtracking, and establish a behavior trust mapping between the path and the task behavior result; if the behavior trigger in the behavior trust mapping fails to find the support of a behavior chain with a response time within the preset time limit in the non-pseudo-consistent chain, then mark this path with a trust weakening weight;
[0027] Re-inject light perturbation behavior into all paths marked with weight weakening, and reconstruct the perturbation trust evolution graph according to their perturbation recovery period and behavior stable trajectory.
[0028] In a preferred embodiment, if the recovery curve in the perturbation trust evolution graph has a change amplitude of the recovery time within the specified perturbation window lower than the preset time fluctuation threshold, the residual mean value of the continuous behavior offset value is lower than the residual determination lower limit, and the number of interruptions of the path continuation segment does not exceed the preset path continuous interruption threshold, it is regarded as a trust recoverable path;
[0029] The trust recoverable path refers to a chain group in the constructed collaborative path that still meets the trust determination conditions after perturbation elasticity analysis and behavior generation path inversion verification, and this chain group constitutes the final credible collaborative path graph;
[0030] For all chain groups that do not meet the determination conditions of the trust recoverable path, output a pseudo-consistent chain risk label, which is used for subsequent system behavior correction and alarm processes.
[0031] An end-to-end collaborative intelligent park monitoring system includes a collaborative extraction module, a perturbation construction module, an anomaly recognition module, a path inversion module, and a trust reconstruction module;
[0032] The collaborative extraction module is used to obtain the collaborative behavior structure of multi-source synchronous perception data in the intelligent park, establish an initial collaborative path set and an end-to-end collaborative behavior chain, and extract candidate credible paths in the park that meet the terminal response synchronization and type cross characteristics;
[0033] The perturbation construction module is used to inject perturbations into the terminals in the initially credible collaborative chain and extract the perturbation feedback results, generating an elastic response trajectory with quantifiable characteristics;
[0034] The anomaly recognition module is used to identify elastic response anomaly chains that can be used to reverse-derive generation paths by constructing elastic metrics and comparing with anomaly conditions;
[0035] The path inversion module identifies unnatural behavior paths that do not meet the device response conditions by constructing a behavior generation trajectory graph and calculating the transfer logic factor in the path, and outputs a pseudo-consistent collaborative behavior chain;
[0036] The trust reconstruction module is used to perform light perturbation verification and recovery feature reconstruction on paths with weakened behavior trust, identify trust recoverable paths that meet multiple perturbation response constraint conditions, and output the final credible collaborative path graph and pseudo-consistent chain risk label for subsequent system intervention decisions.
[0037] The technical effects and advantages of the present invention:
[0038] 1. This solution verifies the authenticity of the collaborative path substantially by injecting perturbations into the collaborative path and extracting the elastic response behavior of the terminal, breaking through the assumption of "true if collaborative and consistent".
[0039] 2. By constructing a vector group of perturbation elastic indicators, comprehensively analyzing behavior deviation, recovery duration, and path adjustment frequency, accurately identifying pseudo - collaborative paths that do not have the ability to recover structurally.
[0040] 3. Based on the behavior transfer logic factor and the time - state trajectory diagram, identify behavior paths that do not conform to the device response law, and realize the structural judgment of non - natural paths.
[0041] 4. Adopt a light - perturbation back - test and perturbation recovery scoring mechanism to verify the trust - weakening path with low intervention, construct the final credible collaborative path map and mark the risk of pseudo - chains. Description of the Drawings
[0042] Figure 1 It is the flow chart of the method step framework of the present invention.
[0043] Figure 2 It is the schematic diagram of the system module structure of the present invention.
[0044] Figure 3 It is the flow chart of collaborative behavior structure extraction and preliminary credible path screening of the present invention.
[0045] Figure 4 It is the flow chart of terminal perturbation injection and elastic index extraction of the present invention.
[0046] Figure 5 It is the flow chart of abnormal chain behavior path inversion and pseudo - consistent chain identification of the present invention.
[0047] Figure 6 It is the flow chart of trust weakening and perturbation back - test re - verification of the present invention.
[0048] Figure 7 It is the flow chart of outputting the credible path map and risk labels of the present invention. Detailed Embodiments
[0049] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0050] Referring to the attached Figure 1-7 description, a smart campus monitoring method based on end - to - end collaboration according to an embodiment of the present invention includes:
[0051] Obtain the collaborative behavior structure of multi-source synchronous perception data in the intelligent park. By constructing an initial set of collaborative paths and establishing an end-to-end collaborative behavior chain, extract candidate trusted paths in the park that meet the terminal response synchronization and type cross characteristics;
[0052] Perform perturbation injection on the terminals in the preliminary trusted collaborative chain and extract the perturbation feedback results to generate an elastic response trajectory with quantifiable characteristics;
[0053] Through the construction of elastic metrics and comparison with abnormal conditions, identify the elastic response abnormal chain that can be used for reverse derivation to generate paths;
[0054] By constructing a behavior generation trajectory graph and calculating the transfer logic factors in the paths, identify non-natural behavior paths that do not meet the device response conditions, and output a pseudo-consistent collaborative behavior chain;
[0055] Perform light perturbation verification and recovery feature reconstruction on the paths whose behavior trust has been weakened, identify the trust recoverable paths that meet multiple perturbation response constraint conditions, and output the final trusted collaborative path graph and the risk label of the pseudo-consistent chain for subsequent intervention decisions of the system.
[0056] It should be noted that in the formula structure involved in this solution, dimensionless terms can be used as proportional or structural adjustment factors. When combined with quantities with units, they only play a role in numerical scaling and do not introduce new physical dimensions. Therefore, they will not change or confuse the overall unit system of the expression; such combinations of "dimensionless terms and terms with units" can be understood as the composite structure expression forms commonly used in mathematical and physical modeling, conform to the principle of dimensional consistency, and have a clear physical interpretation basis;
[0057] Secondly, in the formula structure of this solution, if there are multiple variable terms with different physical units, including but not limited to time-type, mass-type, or energy-type variables, their joint appearance is to express the collaborative modeling relationship of multiple physical mechanisms. Each variable can be composed into a unified structure through function mapping, ratio combination, or normalization adjustment, with clear units and clear meanings. The overall expression conforms to the principle of dimensional consistency and the common norms of engineering modeling;
[0058] In this solution, if constants, weights, adjustment factors, threshold parameters, proportional coefficients, etc. are designed, they all belong to adjustable control parameters for different application environments. Their values depend on the target device configuration, data input characteristics, and performance optimization goals, and converge within a reasonable range through model verification, performance constraints, or engineering calibration during the implementation stage; although these parameters do not have a preset unique value, they have clear adjustment logics and calculation paths, belonging to the deterministic setting process in engineering implementation. The purpose of such setting is to ensure that the solution has both general adaptability and reproducibility and operability, without affecting its technical clarity and implementability;
[0059] Obtain a perception behavior data set in the intelligent park monitoring. The perception behavior data set includes the card - swiping event sequence, face recognition record sequence, and movement trajectory sequence of the intelligent park. Through the perception behavior data set, perform timestamp alignment operations and output a collaborative candidate data window; perform cross - modal fusion operations on each group of synchronized perception data in the collaborative candidate data window, and output an initial collaborative path set through behavior matching degree calculation; the calculation logic of the cross - modal fusion operation is as follows: map the identity identification value in the card - swiping data to a discrete coding value, perform normalization processing on the image feature vector in the face recognition result, extract the position coordinate sequence and timestamp sequence in the trajectory data to form a spatio - temporal behavior vector, and then align the three types of data by time slices and splice them into a joint behavior feature vector group; then calculate the label matching score between the identity code and the image feature, the displacement direction consistency score between the image feature and the trajectory behavior, and the temporal synchronization score between the card - swiping time and the trajectory time; finally, perform weighted average on the above three scores according to preset weights as the behavior matching degree value of this time slice; if there are multiple behavior matching degree values exceeding the set threshold in consecutive time slices, mark the associated card - swiping data, face image data, and trajectory data in this time period as a group of initial collaborative paths;
[0060] For each path in the initial collaborative path set, extract its collaborative terminal combination group; the collaborative terminal combination group includes card - swiping devices, face recognition terminals, and trajectory perception nodes;
[0061] In a further solution, perform three - element fusion of card - swiping identity coding, face image features, and trajectory vectors on each group of synchronized perception data in the collaborative candidate data window, construct a joint behavior feature structure, calculate the behavior matching degree as the basis for forming the initial collaborative path, and based on this, construct a cross - modal behavior matching degree joint model:
[0062]
[0063] Among them, the identity label alignment degree
[0064]
[0065] Among them, the displacement direction consistency
[0066]
[0067] The time synchronization intensity
[0068]
[0069] Among them, M tis the behavior matching degree value, which indicates whether the data group meets the condition of forming a collaborative path with cross-modal consistency at time slice t; I t is the identity tag coding sequence of the card swiping event, and the identity tag coding sequence of the card swiping event occurs in time slice t; F t is the depth feature tensor of the face image, and the depth feature tensor of the face image is generated by the image acquisition terminal at time slice t; T t represents the sequence of trajectory position vectors within the corresponding time slice, and the sequence of trajectory position vectors is collected from the trajectory perception terminal; is the identity matching function, and in practical applications, the identity matching function is used to evaluate the semantic mapping degree between the card swiping identity and the face image; δ i (I t ) is the status indication function of the i-th bit in the identity coding; is the i-th sub-feature region in the image tensor; is the identity semantic feature reference subspace; is the behavior direction consistency function; is the motion direction vector of the j-th region in the image frame; is the motion direction vector of the j-th time period in the trajectory segment; is the time synchronization function; is the occurrence time of the k-th event in the card swiping event sequence; is the sampling time of the k-th point in the trajectory sequence; ΔT max is the maximum allowed time deviation window; is the logical indication function for judging whether the card swiping time is within the corresponding time range of the trajectory path; respectively represent the element-level coupling and function output-level fusion operators; log represents compressing the final behavior matching value to a comparable range; n represents the total number of identity feature bits participating in the alignment calculation in I t ; m represents the total number of corresponding frame pairs between a group of images and trajectories used to construct the direction vector; q represents the total number of pairs of card swiping events and trajectory sampling points participating in the time synchronization calculation within a time window; in addition, rank in the above formula represents the semantic matching ranking position in the predefined to measure its matching priority with the identity coding; the symbol in the formula represents in the mapping projection operation to construct the image semantic representation relationship matching the card swiping identity coding; ∠ represents and the included angle between them, and the symbol ∠ in the above formula is used to measure their behavior direction consistency.
[0070] Perform structural connectivity analysis on the path structure of the collaborative terminal combination group, obtain the end-to-end collaborative behavior chain, construct a consistent collaborative path graph, extract the corresponding terminal response time series for each path chain in the consistent collaborative path graph, perform response time series continuity detection, and output a group of behavior synchronization chains;
[0071] If there is a terminal response time interval fluctuation in the behavior synchronization chain group that is less than the preset interval fluctuation threshold, and the terminal type cross-ratio is not lower than the lower limit of the preset cross-ratio threshold, then mark the corresponding chain in the behavior synchronization chain group as a preliminary credible collaborative chain.
[0072] Inject a perturbation request into each terminal in the preliminary credible collaborative chain; the perturbation request includes path offset perturbation, identity confidence perturbation, and trigger timing perturbation;
[0073] Extract the set of perturbation response behavior trajectories through the terminal behavior sequence after injecting the perturbation, and construct an end-to-end perturbation feedback flow; for each terminal trajectory in the perturbation feedback flow, perform dynamic recovery period analysis and output a set of perturbation recovery paths;
[0074] For each path in the perturbation recovery path set, extract the recovery response time, behavior offset amplitude, and path adjustment frequency, and construct a perturbation elasticity index vector group.
[0075] If the recovery response time of any path in the perturbation elasticity index vector group exceeds the upper limit of the preset recovery period, and the combined value of the offset amplitude and adjustment frequency exceeds the target elasticity distribution interval, then mark this path as an elastic response abnormal chain;
[0076] The terminals and path structures marked in the elastic response abnormal chain correspond to the path structures established in the collaborative behavior chain, and the path structure is used as the basis for reverse derivation of the behavior generation path;
[0077] In a further solution, inject perturbations into the terminals of the preliminary credible collaborative chain, construct a perturbation elasticity index and determine whether it is an abnormal chain by analyzing behavior offset, trajectory recovery dynamics, and path state change frequency, and based on this, construct a perturbation elasticity structure identification and abnormal chain judgment model:
[0078]
[0079] The first derivative of the recovery time curve is described as:
[0080]
[0081] The spatial curvature function Π i (t):
[0082]
[0083] State transition difference of the l-th segment of the path
[0084]
[0085] where ε i is the perturbation elasticity outlier of path i, and the perturbation elasticity outlier is used to determine whether it is an elastic response anomaly chain; Υ i (t) is the time difference function of the recovery process before and after perturbation; is the time function for path i to reach the stable behavior state; is the time function for path i to receive the perturbation input; is the perturbation behavior offset vector of path i at time t; θ i (t) is the angle between the direction vectors before and after perturbation; represents the time derivative and second-order partial derivative operations; L is the number of path segments; l represents the l-th behavior state segment into which path i is divided, and is used to represent the index number of each state transition after segmentation during the perturbation recovery process of the path; sup represents extracting the maximum second-order change rate within the recovery interval; represents the state number of the current moment of the l-th state segment of the path, and is used to identify the real-time behavior state of this segment during the perturbation recovery process; represents the state number of the l-th state segment of the path in the previous time frame, and is used to compare with the current state to determine whether a state transition has occurred.
[0086] For the terminal set in the elastic response anomaly chain, extract its trigger time stream and behavior state transition stream, and construct a time-behavior generation trajectory graph; for each behavior transfer path in the time-behavior generation trajectory graph, extract its transfer logic factor and the original behavior start data; the original data includes personnel identity authentication input, device trigger events, and task scheduling records; where the transfer logic factor refers to whether the state transition between each behavior node and its previous node in the behavior transfer path conforms to the device trigger logic and behavior causal law, and its calculation logic is: perform a joint match on the time interval, device activation state, and personnel identity continuity between two adjacent behavior nodes. If the time is within the device response window, the identity remains the same, and the behavior type satisfies the predefined state transition rules, then output that the transfer logic factor of this segment is valid; otherwise, this factor is marked as violating the trigger logic and is used to determine whether the behavior path is natural;
[0087] If the transfer logic factor of any behavior transfer path does not meet the preset original device trigger conditions (the original device trigger conditions include but are not limited to the preset conditions: there is a device response record but the person has not swiped the card), then determine that this path is an unnatural behavior path.
[0088] Summarize all non-natural behavior paths to form an abnormal behavior chain group, and the abnormal behavior chain group corresponds to a set of sub-paths marked as the elastic response abnormal chain; for each behavior path in the abnormal behavior chain group, perform behavior reconstruction verification, and generate a behavior generation credibility factor through the joint determination of trajectory closure, behavior causal continuity, and identity operation consistency;
[0089] If the behavior generation credibility factor is lower than the preset trust score baseline, and its corresponding elastic recovery index meets the elastic response abnormal chain condition, then mark this path as a pseudo-consistent collaborative behavior chain.
[0090] For the terminal path structure in the pseudo-consistent collaborative behavior chain, perform behavior granularity backtracking, and establish a behavior trust mapping between the path and the task behavior result; if the behavior trigger in the behavior trust mapping fails to find a behavior chain support with a response time within the preset time limit in the non-pseudo-consistent chain, then apply a trust weakening weight mark to this path;
[0091] Re-inject light perturbation behaviors into all paths marked with weight weakening, and reconstruct the perturbation trust evolution graph according to their perturbation recovery period and behavior stable trajectory.
[0092] If the change amplitude of the recovery time within the specified perturbation window in the recovery curve of the perturbation trust evolution graph is lower than the preset time fluctuation threshold, the residual mean value of the continuous behavior offset value is lower than the residual determination lower limit, and the number of interruptions in the path continuation segment does not exceed the preset path continuous interruption threshold, then it is regarded as a trust recoverable path;
[0093] The trust recoverable path refers to a set of chains in the constructed collaborative path that still meet the trust determination conditions after perturbation elastic analysis and behavior generation path inversion verification, and this set of chains constitutes the final credible collaborative path graph;
[0094] For all sets of chains that do not meet the trust recoverable path determination conditions, output a pseudo-consistent chain risk label, which is used for subsequent system behavior correction and alarm processes;
[0095] As a further solution, it should be noted that for the paths marked with trust weakening, inject light perturbations and observe the entire process of their perturbation recovery, construct an overall score through recovery time fluctuation, behavior error dynamics, and path connectivity, judge whether it can be restored to a credible path, and based on this, construct a comprehensive determination model for the recovery strength of the trust recoverable path, so as to output the final credible path;
[0096]
[0097] where is the perturbation recovery strength score of path j; H j(t) is the disturbance recovery time curve function, and the disturbance recovery time curve function represents the response stability of the path at time t; is the second-order time fluctuation during the recovery process; Ξ j (t) is the dynamic change rate of the behavior error of path j at time t; is the behavior state vector that should theoretically appear; is the actually observed behavior state vector; ρ j (t) is the structural connectivity function of the path segment; is the number of interruptions of path j within the observation window; λ is the connectivity attenuation coefficient, and the connectivity attenuation coefficient is used to adjust the impact of interruptions on scoring; τ0, τ1 are the start and end boundaries of the recovery observation time window.
[0098] A smart campus monitoring system based on end-to-end collaboration, including a collaborative extraction module, a disturbance construction module, an anomaly recognition module, a path inversion module, and a trust reconstruction module;
[0099] The collaborative extraction module is used to obtain the collaborative behavior structure of multi-source synchronous perception data in the smart campus, build an initial collaborative path set and establish an end-to-end collaborative behavior chain, and extract candidate trustworthy paths in the campus that meet the terminal response synchronization and type cross characteristics;
[0100] The disturbance construction module is used to perform disturbance injection on the terminals in the preliminary trustworthy collaborative chain and extract the disturbance feedback results, generating an elastic response trajectory with quantifiable characteristics;
[0101] The anomaly recognition module is used to identify an elastic response anomaly chain that can be used for reverse derivation to generate a path by constructing an elastic index and comparing it with the anomaly conditions;
[0102] The path inversion module identifies unnatural behavior paths that do not meet the device response conditions by constructing a behavior generation trajectory map and calculating the transfer logic factor in the path, and outputs a pseudo-consistent collaborative behavior chain;
[0103] The trust reconstruction module is used to perform light disturbance verification and recovery feature reconstruction on paths with weakened behavior trust, identify trust recoverable paths that meet multiple disturbance response constraint conditions, and output the final trustworthy collaborative path map and the risk label of the pseudo-consistent chain for subsequent intervention decisions of the system.
[0104] It should be noted as a whole, including but not limited to: in the existing smart campus scenarios, identity authentication and behavior determination generally rely on multi-terminal collaboration mechanisms. For example, swiping card behavior, face recognition, WiFi trajectories, etc. are aligned on the time axis and jointly participate in the judgment of the legality of the behavior; when these terminal data are coordinated in time and the content matches, the system will automatically recognize this behavior chain as trustworthy, thus triggering actions such as access control release, task authorization, or anomaly exemption;
[0105] However, the existing technology defaults that all terminal data sources are naturally trustworthy and lacks the ability to model the authenticity of this "synergy relationship itself"; attackers can construct a set of forged information with consistent time and matching data to simulate the "legitimate behavior" pattern, thus deceiving the system to form false trust and achieving the purpose of bypassing monitoring; this logic relying on "surface consistency" is more likely to be misbelieved by the system when the attack intensity is higher and the forgery behavior is more coordinated, constituting a serious structural paradox;
[0106] Therefore, the present invention is not an optimization of the accuracy of a single terminal, but a full-link solution to the core ontological problem of "whether the collaborative path is real";
[0107] This solution includes a collaborative behavior chain construction stage:
[0108] Obtain the synchronous behavior data collected by multiple sensing terminals in the smart park, including the card-swipe event sequence, face recognition results, and trajectory path sequence; construct the joint behavior features within each time slice through timestamp alignment, spatial position synchronization, and identity semantic fusion; then calculate the cross-modal behavior matching degree based on these features, form the "initial collaborative path set" with high matching degree paragraphs, and further screen out the "candidate trusted paths" that meet the requirements of terminal response synchronization and device type intersection;
[0109] The design intention of this stage is: not taking the single-terminal data as the basis for behavior, but using the structural strength of the collaborative chain and the consistency between modalities as the evaluation unit to provide a chain-level data basis for subsequent perturbation judgment;
[0110] This solution includes a perturbation response behavior construction stage:
[0111] For the initially trusted paths, the system injects interference requests into the corresponding terminals; the interference methods include not only trajectory perturbation (such as path deviation), but also identity confidence interference (simulating misidentification) and trigger timing perturbation (controlling the response time difference); by recording the behavior feedback trajectories of the terminals under interference, extract the response time, behavior deviation trajectories, and state adjustment frequencies during the recovery process of each path to construct a "perturbation elasticity index vector group";
[0112] Attackers can synchronously construct consistent paths, but cannot truly reproduce the path recovery elasticity under interference conditions; by constructing a perturbation-recovery mapping relationship, it can be inferred which path behaviors are only superficially collaborative and lack real behavior inertia, thus identifying the "elastic response abnormal chain";
[0113] This solution includes a reverse behavior generation path derivation stage:
[0114] For the identified abnormal chain path, reverse extract the process of its behavior generation, and construct a "time-state trajectory graph" to analyze whether each node conforms to the natural generation logic; this judgment is carried out by calculating the transfer logic factor between behavior nodes, such as whether the response time difference between adjacent behaviors falls within the device response window, whether the identity is continuous, whether the behavior trigger is reasonable, etc.;
[0115] This part differentiates the behavior chain truly executed by the user naturally from the pseudo-path spliced by the attacker through the "generation path inversion" method, strengthening the internal verification of the authenticity of the collaborative path structure;
[0116] This solution includes the behavior trust attenuation and re-verification stage:
[0117] If a certain behavior path is identified as a "pseudo-consistent chain", the system will not immediately eliminate it, but perform a "trust weakening process" on it; that is: map the path behavior to the actual task execution record. If no behavior chain that can support its trigger can be found in the non-pseudo-consistent chain, the trust degree of this path will decrease; thereafter, the system re-injects low-intensity perturbations into it and collects its recovery trajectory for further establishing the perturbation recovery intensity score;
[0118] This shows that this solution does not rely on a rigid strategy of "judging and killing in one step", but has the ability of multi-round dynamic feedback verification, improving the misjudgment recovery rate and system elasticity;
[0119] This solution includes the trust path reconstruction and pseudo-chain marking stage:
[0120] Execute multiple restorative constraint judgments on the recovery score results, including joint judgments of indicators such as the fluctuation range of the perturbation recovery time, the change trend of the behavior offset residual, and the number of path interruptions; when the path maintains a stable recovery mode within all constraint conditions, it is determined as a "trust recoverable path" and re-included in the trusted path map; otherwise, output a "pseudo-consistent chain risk label" for subsequent monitoring systems to issue alarms or interventions;
[0121] This stage constitutes the closing mechanism of the system security judgment, ensuring that only the paths that have truly experienced interference tests and recovered stably are confirmed as trusted, thus realizing the paradigm shift from "surface-level collaborative judgment" to "process trusted verification".
[0122] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A smart campus monitoring method based on end-to-end collaboration, characterized in that Including: Obtain the collaborative behavior structure of multi-source synchronous perception data in the smart park. By constructing an initial collaborative path set and establishing an end-to-end collaborative behavior chain, extract candidate trusted paths in the park that meet the terminal response synchronization and type cross characteristics; Execute perturbation injection on the terminals in the preliminary trusted collaborative chain and extract the perturbation feedback results to generate an elastic response trajectory with quantifiable characteristics; Through the construction of elastic metrics and comparison with abnormal conditions, identify the elastic response abnormal chain that can be used for reverse derivation to generate paths; By constructing a behavior generation trajectory graph and calculating the transfer logic factor in the path, identify the unnatural behavior paths that do not meet the device response conditions, and output the pseudo-consistent collaborative behavior chain; Execute light perturbation verification and recovery feature reconstruction on the paths weakened by behavior trust, identify the trust recoverable paths that meet multiple perturbation response constraint conditions, and output the final trusted collaborative path graph and the risk label of the pseudo-consistent chain for subsequent intervention decisions of the system.
2. The method for monitoring a smart park based on end-to-end collaboration according to claim 1, characterized in that: In the monitoring of the smart park, obtain the perception behavior data set. The perception behavior data set includes the card swiping event sequence, the face recognition record sequence and the movement trajectory sequence of the smart park. Through the perception behavior data set, perform timestamp alignment operation and output the collaborative candidate data window; perform cross-modal fusion operation on each group of synchronous perception data in the collaborative candidate data window, and output the initial collaborative path set through behavior matching degree calculation; For each path in the initial collaborative path set, extract its collaborative terminal combination group; the collaborative terminal combination group includes card swiping devices, face recognition terminals and trajectory perception nodes.
3. The method for monitoring a smart park based on end-to-end collaboration according to claim 2, characterized in that: Perform structural connectivity analysis on the path structure of the collaborative terminal combination group to obtain the end-to-end collaborative behavior chain, construct a consistent collaborative path graph, extract the corresponding terminal response time series for each path chain in the consistent collaborative path graph, perform response time series continuity detection, and output the behavior synchronization chain group; If there is a terminal response time interval fluctuation in the behavior synchronization chain group that is less than the preset interval fluctuation threshold, and the terminal type cross ratio is not lower than the lower limit of the preset cross ratio threshold, then mark the corresponding chain in the behavior synchronization chain group as the preliminary trusted collaborative chain.
4. The method for monitoring a smart park based on end-to-end collaboration according to claim 3, characterized in that: Inject a perturbation request to each terminal in the preliminary trusted collaborative chain; the perturbation request includes path offset perturbation, identity confidence perturbation and trigger timing perturbation; Through the terminal behavior sequence after injecting the perturbation, extract the perturbation response behavior trajectory set and construct an end-to-end perturbation feedback flow; for each terminal trajectory in the perturbation feedback flow, perform dynamic recovery period analysis and output the perturbation recovery path set; For each path in the perturbation recovery path set, extract the recovery response time, behavior offset amplitude and path adjustment frequency, and construct a perturbation elastic index vector group.
5. The method for monitoring a smart park based on end-to-end collaboration according to claim 4, characterized in that: If the recovery response time of any path in the disturbed elastic index vector group exceeds the upper limit of the preset recovery period, and the combined value of the deviation amplitude and the adjustment frequency exceeds the target elastic distribution interval, then mark this path as an abnormal elastic response chain; The terminals marked in the abnormal elastic response chain and the path structure correspond to the established path structure in the collaborative behavior chain, and the path structure is used as the basis for back-deriving the behavior generation path.
6. A smart campus monitoring method based on end-to-end collaboration according to claim 5, characterized in that: For the terminal set in the abnormal elastic response chain, extract its trigger time stream and behavior state transition stream, and construct a time behavior generation trajectory graph; for each behavior transfer path in the time behavior generation trajectory graph, extract its transfer logic factor and the original behavior start data; the original data includes personnel identity authentication input, device trigger events, and task scheduling records; If the transfer logic factor of any behavior transfer path does not meet the preset original device trigger condition, then determine that this path is an unnatural behavior path.
7. A smart campus monitoring method based on end-to-end collaboration according to claim 6, characterized in that: Summarize all unnatural behavior paths to form an abnormal behavior chain group, and the abnormal behavior chain group is correspondingly marked as a sub-path set of the abnormal elastic response chain; for each behavior path in the abnormal behavior chain group, perform behavior reconstruction verification, and generate a behavior generation credibility factor through the joint determination of the trajectory closure degree, behavior causal continuity, and identity operation consistency; If the behavior generation credibility factor is lower than the preset trust score baseline, and its corresponding elastic recovery index meets the abnormal elastic response chain condition, then mark this path as a pseudo-consistent collaborative behavior chain.
8. A smart campus monitoring method based on end-to-end collaboration according to claim 7, characterized in that: For the terminal path structure in the pseudo-consistent collaborative behavior chain, perform behavior granularity backtracking, and establish a behavior trust mapping between the path and the task behavior result; if the behavior trigger in the behavior trust mapping fails to find a behavior chain support with a response time within the preset time limit in the non-pseudo-consistent chain, then apply a trust weakening weight mark to this path; Re-inject light disturbance behaviors into all paths marked with weight weakening, and reconstruct a disturbance trust evolution graph according to their disturbance recovery periods and behavior stability trajectories.
9. A smart campus monitoring method based on end-to-end collaboration according to claim 8, characterized in that: If the change amplitude of the recovery time within the specified disturbance window of the recovery curve in the disturbance trust evolution graph is lower than the preset time fluctuation threshold, the residual mean value of the continuous behavior offset value is lower than the residual determination lower limit, and the number of interruptions in the path continuation segment does not exceed the preset path continuous interruption threshold, then it is regarded as a trust recoverable path; The trust recoverable path refers to a chain group that still meets the trust determination conditions after disturbance elastic analysis and behavior generation path inversion verification in the established collaborative path, and this chain group constitutes the final credible collaborative path graph; For all chain groups that do not meet the trust recoverable path determination conditions, output a pseudo-consistent chain risk label, and the pseudo-consistent chain risk label is used for subsequent system behavior correction and alarm processes.
10. A smart campus monitoring system based on end-to-end collaboration, including a method for smart campus monitoring based on end-to-end collaboration as claimed in claim 9, comprising a collaborative extraction module, a perturbation construction module, an anomaly identification module, a path inversion module, and a trust reconstruction module, characterized in that: The collaborative extraction module is used to obtain the collaborative behavior structure of multi-source synchronous perception data in the smart campus, extract candidate trustworthy paths in the campus that meet the terminal response synchronization and type cross characteristics by constructing an initial collaborative path set and establishing an end-to-end collaborative behavior chain; The perturbation construction module is used to perform perturbation injection on the terminals in the initially trustworthy collaborative chain and extract the perturbation feedback results to generate an elastic response trajectory with quantifiable characteristics; The anomaly identification module is used to identify an elastic response anomaly chain that can be used for reverse derivation to generate a path by comparing the construction of elastic metrics with anomaly conditions; The path inversion module identifies unnatural behavior paths that do not meet the device response conditions by constructing a behavior generation trajectory graph and calculating the transfer logic factor in the path, and outputs a pseudo-consistent collaborative behavior chain; The trust reconstruction module is used to perform light perturbation verification and recovery feature reconstruction on paths with weakened behavior trust, identify trust recoverable paths that meet multiple perturbation response constraint conditions, and output the final trustworthy collaborative path graph and the risk label of the pseudo-consistent chain for subsequent intervention decisions of the system.
Citation Information
Patent Citations
Big data intelligent cooperative processing method and system and cloud platform
CN113360714A
Artificial intelligence risk level supervision system
CN120069567A
Network defense capability verification method and system based on intrusion attack simulation
CN120090868A
Cited By
Smart park comprehensive data management method and system
CN120951313A