Intelligent civil air defense space safety assessment method and system based on environment detection

By constructing a disturbance event library and a security knowledge graph, combined with a multi-dimensional security scoring matrix, the problem of lack of comprehensive evaluation in the civil defense space safety assessment is solved, and a real-time and comprehensive evaluation of the civil defense space safety status is achieved, as well as the accuracy and efficiency of emergency response are improved.

CN120471443BActive Publication Date: 2025-10-10TANGSHAN KAIYE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510575507.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-10-10
Estimated Expiration
2045-05-06

AI Technical Summary

Technical Problem

Existing technologies lack comprehensive security assessment methods in the security assessment of civil defense spaces and are unable to comprehensively and real-time reflect the security status of civil defense spaces.

Method used

Build a disturbance event library to simulate safety disturbances, establish a safety knowledge graph based on environmental detection, conduct multi-dimensional safety scoring, including structural conductivity risk assessment, equipment collaborative stability assessment, human response matching assessment and isolation mechanism triggering efficiency assessment, and output safety level assessment results.

Benefits of technology

It has achieved real-time and comprehensive assessment of the security status of civil air defense space, and improved the accuracy and efficiency of emergency response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120471443B_ABST
    Figure CN120471443B_ABST
Patent Text Reader

Abstract

The application discloses a smart civil air defense space safety evaluation method and system based on environment detection, relates to the technical field of data processing, and comprises the following steps: constructing a disturbance event library, selecting a disturbance event to perform safety disturbance simulation, guiding the smart civil air defense space to enter an emergency state; establishing a safety knowledge graph of the smart civil air defense space under normal conditions; configuring a stage life cycle of the smart civil air defense space, performing node response data collection of the smart civil air defense space in the stage life cycle, updating a graph state of the safety knowledge graph according to the response data collection result; performing multi-dimensional graph safety scoring on the time-series updated safety knowledge graph, establishing a multi-dimensional graph safety scoring matrix; and outputting a safety level evaluation result by using the multi-dimensional graph safety scoring matrix. The application solves the technical problem that there is a lack of comprehensive safety evaluation means in the safety evaluation of the civil air defense space in the prior art, and achieves the technical effect of real-time evaluation of the safety state of the smart civil air defense space.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to an intelligent civil air defense space safety assessment method and system based on environmental detection. Background Art

[0002] Currently, safety assessments of civil air defense spaces primarily rely on traditional structural analysis and static environmental monitoring, typically using sensors to collect basic data such as temperature, humidity, and gas concentration. However, these assessments lack comprehensive consideration of multidimensional factors such as equipment coordination, human behavior, and environmental changes, making it impossible to fully and real-timely reflect the safety status of civil air defense spaces. Summary of the Invention

[0003] This application provides an intelligent civil defense space safety assessment method and system based on environmental detection, which is used to solve the technical problem of the lack of comprehensive safety assessment means in the existing technology in civil defense space safety assessment.

[0004] In view of the above problems, this application provides an intelligent civil defense space safety assessment method and system based on environmental detection.

[0005] The first aspect of the present application provides a smart civil air defense space safety assessment method based on environmental detection, the method comprising:

[0006] Construct a disturbance event library, select disturbance events in the disturbance event library to perform safety disturbance simulation, and guide the smart civil air defense space into an emergency state; establish a safety knowledge graph for the smart civil air defense space under normal conditions, and the safety knowledge graph includes spatial structure nodes, functional equipment nodes, sensor nodes, personnel behavior nodes, and functional status nodes; configure the stage life cycle of the smart civil air defense space, and execute node response data collection of the smart civil air defense space within the stage life cycle to update the graph state of the safety knowledge graph in response to the data collection results; perform multi-dimensional graph security scoring on the time-series updated safety knowledge graph, and establish a multi-dimensional graph safety scoring matrix, and the evaluation dimensions of the multi-dimensional graph safety scoring include structural conductivity risk assessment, equipment collaborative stability assessment, human response matching assessment, and isolation mechanism triggering efficiency assessment; use the multi-dimensional graph safety scoring matrix to output the safety level assessment result.

[0007] The second aspect of the present application provides an intelligent civil air defense space safety assessment system based on environmental detection, the system comprising:

[0008] A security disturbance simulation module is used to construct a disturbance event library, select disturbance events in the disturbance event library to perform security disturbance simulation, and guide the smart civil air defense space into an emergency state; a security knowledge graph establishment module is used to establish a security knowledge graph of the smart civil air defense space under a normal environment, and the security knowledge graph includes spatial structure nodes, functional equipment nodes, sensor nodes, personnel behavior nodes, and functional status nodes; a data acquisition module is used to configure the stage life cycle of the smart civil air defense space, and execute node response data acquisition of the smart civil air defense space within the stage life cycle to update the graph state of the security knowledge graph in response to the data acquisition results; a security scoring module is used to perform multi-dimensional graph security scoring on the time-series updated security knowledge graph, and establish a multi-dimensional graph safety scoring matrix. The evaluation dimensions of the multi-dimensional graph safety scoring include structural conductivity risk assessment, equipment collaborative stability assessment, human response matching assessment, and isolation mechanism triggering efficiency assessment; a security level assessment result acquisition module is used to output the security level assessment result using the multi-dimensional graph safety scoring matrix.

[0009] One or more technical solutions provided in this application have at least the following technical effects or advantages:

[0010] This application constructs a disturbance event library, selects disturbance events in the disturbance event library to perform safety disturbance simulation, and guides the smart civil defense space into an emergency state; establishes a safety knowledge graph of the smart civil defense space under a normal environment, and the safety knowledge graph includes spatial structure nodes, functional equipment nodes, sensor nodes, personnel behavior nodes, and functional status nodes; configures the stage life cycle of the smart civil defense space, and executes node response data collection of the smart civil defense space within the stage life cycle to update the graph state of the safety knowledge graph in response to the data collection results; performs a multi-dimensional graph security score on the time-series updated safety knowledge graph, and establishes a multi-dimensional graph safety score matrix, and the evaluation dimensions of the multi-dimensional graph safety score include structural conductivity risk assessment, equipment collaborative stability assessment, human response matching assessment, and isolation mechanism triggering efficiency assessment; and uses the multi-dimensional graph safety score matrix to output the safety level assessment result. The present invention solves the technical problem of the lack of comprehensive security assessment means in the existing technology in the security assessment of civil defense space. By constructing a disturbance event library to simulate security disturbances, establishing a security knowledge graph based on environmental detection, and an evaluation method of a multi-dimensional security scoring matrix, the technical effect of real-time assessment of the security status of the smart civil defense space is achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed to be used in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort on the basis of these drawings.

[0012] Figure 1 A flowchart of a safety evaluation method for a smart civil air defense space based on environmental detection is provided for the embodiments of the present application.

[0013] Figure 2 A structural diagram of a safety evaluation system for a smart civil air defense space based on environmental detection is provided for the embodiments of the present application.

[0014] Legend: safety disturbance simulation module 11, safety knowledge graph establishment module 12, data acquisition module 13, safety score module 14, safety grade evaluation result acquisition module 15. DETAILED DESCRIPTION

[0015] The present application provides a safety evaluation method and system for a smart civil air defense space based on environmental detection, which solves the technical problem of lack of comprehensive safety evaluation means in the prior art in the safety evaluation of a civil air defense space. The technical effect of real-time evaluation of the safety state of a smart civil air defense space is achieved by constructing a disturbance event library for safety disturbance simulation, establishing a safety knowledge graph based on environmental detection, and a multi-dimensional safety score matrix evaluation method.

[0016] The technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings of the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without any creative effort fall within the scope of protection of the present application.

[0017] It should be noted that any variation of the terms "comprise" and "have" is intended to cover non-exclusive inclusion, for example, a process, method, system, product or server comprising a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or modules that are not clearly listed or inherent to these processes, methods, products or devices.

[0018] Embodiment one, as shown in the present application provides a safety evaluation method for a smart civil air defense space based on environmental detection, which comprises: Figure 1

[0019] ​Step S100: Build a disturbance event library, select disturbance events in the disturbance event library to perform safety disturbance simulation, and guide the smart civil air defense space into an emergency state.

[0020] In the embodiment of the present application, a data collection method is first used to construct a disturbance event library. Specifically, all possible disturbance event types, such as fire, power outage, equipment failure, etc., are collected from a historical database, and their information (including type, possible impact, frequency of occurrence, etc.) is stored in the database to form a disturbance event library.

[0021] Next, a disturbance event is selected based on real-time monitoring data collected by pre-defined sensors (such as temperature, humidity, and gas concentration). For example, if an environmental sensor detects abnormal temperature or smoke, a fire event is selected as the disturbance event. Simulation technology is then used to perform a safety disturbance simulation, simulating the potential impact of the selected event on the civil air defense space.

[0022] To avoid bias caused by relying solely on manual pre-sets for disturbance events, a cross-validation process was introduced. During the simulation, key data such as recorded disturbance trigger points, environmental parameter change trends, and response delays were compared with actual perception data. Simultaneously, historical spatial drills or emergency response records were used as references to calculate residuals of the simulation results, identify deviations, and correct them.

[0023] For example, during a field test conducted in a specific location, the estimated smoke density rise and firefighting equipment response time during the simulation were compared with the actual collected data. The deviation was found to be within 2.8 seconds, and the response paths of key equipment within the space matched over 92%. This demonstrates that the disturbance simulation not only has realistic accuracy but also has the ability to reasonably trace and deduce historical behavior.

[0024] Finally, based on the simulation results, safety measures in the civil air defense space are adjusted to guide the space into an emergency state. For example, in a fire simulation, the fire extinguishing system is automatically activated and evacuation orders are issued to personnel. This ensures timely response to disturbances and ensures the safety of the civil air defense space.

[0025] Step S200: Establish a security knowledge graph of the smart civil air defense space under normal conditions, wherein the security knowledge graph includes space structure nodes, functional equipment nodes, sensor nodes, personnel behavior nodes, and functional status nodes.

[0026] In this embodiment of the application, to establish a security knowledge graph for smart civil air defense spaces under normal conditions, we first establish spatial structure nodes. Using 3D modeling technology and spatial data acquisition (such as laser scanning and sensor data), we record the physical structure of the civil air defense space in detail. Each spatial area (such as a room, corridor, door, or window) is defined as a node, which contains the basic attributes of the area, such as size and shape.

[0027] Next, functional device nodes are established through the equipment monitoring system. Each key device (such as air conditioning systems, lighting equipment, and fire protection facilities) records its operating status, fault information, and operational history through the monitoring system. Each function and status of the device is converted into a node. Sensor nodes are then established. By deploying various sensors (such as smoke sensors, temperature and humidity sensors, and gas sensors) within the space, environmental changes are monitored in real time. The data collected by these sensors (such as temperature, humidity, and smoke concentration) is converted into sensor nodes.

[0028] Next, monitoring equipment and behavior recognition algorithms are used to establish human behavior nodes. These nodes track the location and behavior of individuals within a space in real time, recording information such as their movement trajectory, dwell time, and whether they interact with devices. Each human behavior node represents the behavior patterns of a specific individual. Based on these behaviors, it is determined whether the individual is following the prescribed path and whether any violations or abnormal behavior are occurring, thereby improving spatial safety.

[0029] Finally, all collected data (spatial structure, equipment, sensors, human behavior, etc.) is aggregated into a functional status node. This node integrates real-time data from spatial structure nodes, functional equipment nodes, sensor nodes, and human behavior nodes to form a comprehensive security assessment model. By dynamically updating the functional status nodes, the overall security status of the civil air defense space is assessed in real time, and emergency response measures are automatically adjusted when safety hazards arise. Through these steps, the security knowledge graph of the smart civil air defense space is established and continuously updated.

[0030] Step S300: Configure the stage life cycle of the smart civil air defense space, and execute the node response data collection of the smart civil air defense space within the stage life cycle to update the graph status of the security knowledge graph in response to the data collection results.

[0031] In an embodiment of the present application, the stage life cycle is first configured, that is, different life cycle stages are divided according to the actual operation requirements of the civil air defense space, such as the normal operation stage, the equipment maintenance stage, the emergency response stage, etc. In the normal operation stage, the environmental parameters and equipment status of the space are mainly monitored to ensure that all equipment is working normally. In the equipment maintenance stage, the focus is on the maintenance and repair of the equipment to ensure that the equipment operates in the best condition. When an emergency occurs, the space enters the emergency response stage, and all monitoring focuses shift to real-time response to the incident. At each stage, the focus and strategy of monitoring are adjusted according to environmental conditions and safety requirements.

[0032] Next, the node response data collection process begins. This phase relies on various sensors and devices deployed within the space to collect real-time data. These sensors, including temperature and humidity sensors, gas sensors, smoke detectors, and occupant location sensors, are specifically designed to monitor environmental changes and human activity within the space. Sensor data is transmitted to the data processing unit via wireless communication or a wired network. During this process, the state changes of each sensor and device are recorded and converted into data points, forming different nodes (such as spatial structure nodes, functional device nodes, sensor nodes, and human behavior nodes).

[0033] Once the data is collected, it enters the update phase of the security knowledge graph. Based on the results of data collection, the status of each node (such as temperature, humidity, equipment operating status, etc.) will be updated accordingly according to the stage it is in. For example, in the normal operation stage, temperature changes or increased smoke concentrations may trigger status updates to fire equipment nodes; while in the emergency response stage, equipment nodes may need to be quickly updated based on the working status of the equipment to ensure that the emergency response system can reflect the safety status of the space in real time. At each stage, the update of the graph can reflect changes in the current environment and equipment status, help to conduct accurate safety assessments, and provide real-time feedback on the overall safety of the space. Through this process, the update of the graph status of the security knowledge graph is completed.

[0034] Step S400: Perform a multi-dimensional graph security score on the time-series updated security knowledge graph and establish a multi-dimensional graph security score matrix. The evaluation dimensions of the multi-dimensional graph safety score include structural conductivity risk assessment, equipment collaborative stability assessment, human response matching assessment, and isolation mechanism triggering efficiency assessment.

[0035] In an embodiment of the present application, when performing a multi-dimensional graph security score on a time-series updated security knowledge graph, the evaluation dimensions include structural conductivity risk assessment, equipment collaborative stability assessment, human response matching assessment, and isolation mechanism triggering efficiency assessment.

[0036] When performing a multidimensional atlas safety score, the structural conductivity risk assessment analyzes the risk transmission capacity of the spatial structure in the face of emergencies (such as earthquakes or explosions), assessing the stability and protection capabilities of the structural components. The equipment coordination stability assessment evaluates whether the various devices can work together in an emergency to ensure the safety of the space, specifically the ability of the devices to coordinate and respond together. The human response matching assessment analyzes personnel behavior data to assess whether personnel take appropriate emergency measures in accordance with safety regulations. The isolation mechanism triggering efficiency assessment evaluates whether the isolation mechanisms within the space (such as fire doors and gas isolation devices) can be activated promptly and effectively to prevent the spread of the accident during an emergency. Through analysis of these assessment dimensions, the structural conductivity risk assessment score, the equipment coordination stability assessment score, the human response matching assessment score, and the isolation mechanism triggering efficiency assessment score are obtained. These scores form the multidimensional atlas safety score matrix. This matrix integrates the scoring results of each assessment dimension to reflect the overall safety status of the smart civil air defense space.

[0037] Furthermore, in the method provided in the embodiment of the application, the multi-dimensional graph security scoring of the time-series updated security knowledge graph further includes:

[0038] The security knowledge graph under normal conditions is used as the steady-state baseline graph; with the steady-state baseline graph as the comparison benchmark, the disturbance source node identification of the time-series updated security knowledge graph is performed, and the impact propagation tracking is performed, and the impact propagation path length and diffusion speed are calculated; the impact propagation path length and diffusion speed are used to identify and lock key vulnerable nodes and high-risk connected links; and the structural conductivity risk assessment is completed based on the identification and locking results, the impact propagation path length and diffusion speed.

[0039] In the present embodiment, data collection and monitoring technologies (such as IoT sensors and environmental monitoring systems) are first used to collect real-time data on temperature, humidity, gas concentration, device status, and human behavior within the space. This data is integrated to form a safety knowledge graph under normal conditions, i.e., a steady-state baseline graph reflecting the normal operating status of each node (such as equipment, sensors, and areas) within the space.

[0040] On the basis of the steady-state baseline graph, the disturbance source nodes are identified through the time-series updated security knowledge graph. Specifically, when the status of certain nodes in the monitored space (such as equipment, sensors, etc.) is abnormal, these nodes will be marked as disturbance source nodes. For example, assuming that the value of a temperature sensor suddenly changes from the normal 20°C to 35°C, the temperature sensor will be identified as a disturbance source node and marked as the source of the possible abnormal event. Using the data comparison method, by comparing the time-series updated security knowledge graph with the steady-state baseline graph, the nodes that have changed compared to the baseline state are identified. The identification of disturbance source nodes uses a difference detection algorithm, for example, calculating the amplitude of the node value change, and judging whether it exceeds the normal fluctuation range based on a pre-set threshold.

[0041] Once the disturbance source node is identified, impact propagation tracking is performed to simulate how the impact of the disturbance source node propagates through the spatial structure. Through this propagation simulation, the impact propagation path length and diffusion speed are calculated. The impact propagation path length refers to the shortest path for the disturbance to propagate from the source node to the target node, while the diffusion speed is the speed at which the impact propagates. By using the shortest path algorithm (such as the Dijkstra algorithm), the shortest propagation path from the disturbance source to other nodes is calculated. Assuming that device A is the disturbance source, device B is directly connected to device A, device C is connected to device B, device D is connected to device C, and device E is connected to device D, then the propagation path length from device A to device E is 1+2+3+4=10 meters.

[0042] Diffusion speed is the speed of the impact of propagation, indicating the propagation time from the source node to other nodes. Assuming the propagation speed from device A to device B is 2 m / s, the propagation speed from device B to device C is 1.5 m / s, the propagation speed from device C to device D is 1 m / s, and the propagation speed from device D to device E is 0.8 m / s. The propagation time from device A to device E can be calculated using the following steps: 1 m ÷ 2 m / s = 0.5 seconds, 2 m ÷ 1.5 m / s = 1.33 seconds, 3 m ÷ 1.5 m / s = 3 seconds, and 4 m ÷ 0.8 m / s = 5 seconds. The total diffusion time is 0.5 + 1.33 + 3 + 5 = 9.83 seconds.

[0043] The calculated impact propagation path length and diffusion rate are then used to identify key vulnerable nodes and high-risk connectivity links. These nodes and links are critical to system stability during the impact propagation process. High-risk connectivity links are those that connect multiple key nodes. A failure in a high-risk connectivity link could potentially cause the failure of multiple devices or nodes. By analyzing the connection paths and nodes, combined with node dependencies and impact strength, high-risk connectivity links are identified. For example, if device A is connected to multiple key devices via a power supply line, the propagation path length and diffusion rate would identify this power supply line as a high-risk connectivity link. Key vulnerable nodes are those most susceptible to failures or disturbances during the impact propagation process. These nodes typically have close dependencies with multiple other nodes. By analyzing the propagation path, we can identify nodes whose failure could cause serious problems for the entire system. For example, a failure in device A could directly affect the operation of devices B and C, making device A a vulnerable node.

[0044] Finally, based on the identification and locking results, the length of the affected propagation path, and the diffusion rate, the structural conductivity risk assessment is completed. The purpose of this assessment is to simulate how disturbance events propagate through spatial structures and evaluate the safety of the entire system. Structural conductivity analysis is performed using methods such as finite element analysis (FEA) and Monte Carlo simulation to simulate the impact of disturbance sources on equipment and structures in space. Through these simulations, the response capability, stability, and load-bearing capacity of each device and structure in the face of different disturbances are calculated. For example, assuming that the fire source is located at device A, finite element analysis is used to simulate how the fire source is transmitted through device A to nodes such as device B and device C, and the stability of each node under the influence of high temperature is calculated.

[0045] Through this assessment, it is possible to identify which nodes and paths are structurally the most vulnerable, and which equipment and connection link failures will cause a chain reaction in the entire system, thereby affecting the overall security of the system. Finally, all of this risk data will be normalized, and different risk factors (such as those affecting the length of the propagation path, the speed of diffusion, the vulnerability of the nodes, etc.) will be converted into a unified scoring standard. The normalization process is usually carried out through the minimum-maximum normalization method, scaling each assessment value between 0 and 1, with 0 representing the lowest risk and 1 representing the highest risk. For example, if the conduction risk of device A is 80% and that of device B is 60%, after normalization, the score of device A is 0.8 and the score of device B is 0.6. Finally, the scores of all devices and structures are aggregated and averaged to obtain an overall safety score, which is used to evaluate the safety status of the space.

[0046] Furthermore, in the method provided in the embodiment of the application, the identification and locking of key vulnerable nodes and high-risk connectivity links by influencing the propagation path length and diffusion speed also includes:

[0047] After constructing the first round of high-risk connectivity links, a high-risk node set is established; using the high-risk node set as a new disturbance source, repeated propagation simulations are performed to establish second-order propagation intensity; the second-order propagation intensity is superimposed on the first-order propagation intensity of the first round of high-risk connectivity links to establish a cascading risk network; and the cascading risk network is used to update key vulnerable nodes.

[0048] In an embodiment of the present application, the first round of high-risk connectivity links is constructed. High-risk connectivity links refer to paths connecting multiple key nodes. If these paths fail, they may cause wider impacts. At this stage, the connection relationship between all nodes in the space is identified through network connectivity analysis. Each node represents an important entity (such as a device, sensor or area), and the connectivity link represents the physical or logical connection between them. By analyzing the connection relationship of these nodes, the functional importance of the nodes, the fault history and the criticality of the connection, the vulnerability of each path is evaluated. For example, assuming there are 100 device nodes and 50 sensor nodes in the space, by performing dependency analysis on these nodes, the 30 most critical paths are identified. The vulnerability of each path is evaluated based on fault history data, node importance and the number of connected devices. For example, if a power supply line is connected to multiple key devices at the same time, once a failure occurs, these devices will not be able to operate normally, and the impact will be wide-ranging. Therefore, this line is marked as a high-risk connectivity link.

[0049] Next, a high-risk node set is established based on these high-risk connectivity links. The nodes connected to each high-risk connectivity link, especially those that play a key role on the path, will be considered high-risk nodes. These nodes are usually greatly affected when a disturbance occurs, so they are prioritized for identification and used as disturbance sources for subsequent simulations. To identify these nodes, fault tree analysis (FTA) or risk matrix analysis methods are used to construct a high-risk node set based on the failure probability, importance, and dependency of each node with other nodes. For example, if a key sensor node fails, it may cause the entire monitoring system to fail, and in turn affect other important equipment. Such a node is considered a high-risk node.

[0050] After establishing a set of high-risk nodes, these high-risk nodes are used as new disturbance sources to perform repeated propagation simulations. This process uses a propagation model to simulate the impact propagation after the failure of high-risk nodes. The simulation starts from these nodes and how the disturbance propagates through each node and path. For example, suppose that device A fails, it will affect devices B and C. This propagation is simulated by a propagation algorithm (such as a graph propagation method based on an adjacency matrix) to calculate the impact strength from device A to device B and device C. The calculation of impact strength is usually based on the connection weights between nodes, the severity of the fault, and the response capability of each node. For example, suppose the failure of device A causes a power outage to device B. The impact strength of this fault can be set to 0.8, while the power outage impact strength of device C can be set to 0.6.

[0051] The method for calculating impact strength is based on the connection weights between nodes, which reflect the dependencies and mutual influence between nodes. For example, in a power system, the connection weight between devices A and B can be calculated based on the importance of the devices, the degree of connectivity with other devices, and the failure rate of the devices. The higher the connection weight, the greater the impact strength. This results in the second-order propagation strength, which is the impact strength from the high-risk node to other nodes.

[0052] Once the second-order propagation strength is calculated, it is superimposed with the first-order propagation strength of the high-risk connected links in the first round. In the first round of propagation, the direct impact of the disturbance from the source node to the target node, i.e., the first-order propagation strength, is calculated. By superimposing the second-order propagation strength with the first-order propagation strength, the overall impact of the propagation can be more comprehensively assessed. For example, if the propagation strength from device A to device B is 1.0 (full impact) and the second-order propagation strength is 0.6, then their total propagation strength will be 1.6. In this way, it is possible to identify which nodes and paths play a key role in multiple rounds of propagation, and thus identify high-risk paths that may cause system crashes.

[0053] Next, a cascading risk network is constructed by combining the risk data from first-order and second-order propagation intensities. This network shows how perturbations gradually spread across the network, identifying nodes and paths that may lead to wider-scale impacts during the propagation process. The network reveals which nodes are frequently affected during multiple rounds of propagation. These nodes are often the most vulnerable parts of the system, and their failures can quickly lead to larger-scale security issues.

[0054] Finally, the cascading risk network is used to update key vulnerable nodes. In the cascading risk network, by calculating and analyzing the node propagation strength, the most vulnerable nodes are dynamically updated. These nodes are frequently affected during multiple rounds of propagation or those whose failure would cause the rest of the system to crash. For example, if the propagation strength of device B accumulates to 2.0 over multiple rounds of propagation and it is connected to key nodes such as device C and device D, then device B is identified as a key vulnerable node.

[0055] Furthermore, in the method provided in the embodiment of the application, the multi-dimensional graph security scoring of the time-series updated security knowledge graph further includes:

[0056] Configure the key equipment collaborative chain according to the selected disturbance event; calculate the collaborative success rate of the link node based on the time-series updated security knowledge graph and the key equipment collaborative chain, and generate the collaborative success rate calculation result; obtain the collaborative response time node of the link node, perform trigger time stability analysis according to the collaborative response time node, and establish the trigger time stability analysis result; identify the collaborative interruption point, and complete the equipment collaborative stability evaluation according to the collaborative interruption point, the collaborative success rate calculation result, and the trigger time stability analysis result.

[0057] In an embodiment of the present application, a collaborative chain of key devices is first configured according to a selected disturbance event. Disturbance events can be caused by equipment failures, environmental changes, etc., which may affect the coordinated response between devices. The collaborative chain of key devices is composed of multiple devices, which need to work together to ensure the stability of the system when a disturbance event occurs. For example, in the event of a power failure, device A, device B, and device C may form a collaborative chain, which need to work together to restore power supply or solve other problems. Based on the dependencies and functional requirements between devices, the device collaborative chain will be configured according to specific disturbance events to ensure that these devices can respond effectively and maintain stable operation of the system.

[0058] Next, the collaborative success rate of the link nodes is calculated based on the time- updated security knowledge graph and the key device collaboration chain. The time- updated security knowledge graph reflects the status of devices, sensors, and other nodes based on real-time data, evaluating the performance of each node. The collaborative success rate represents the probability of a device successfully completing a task in collaboration with other devices in the chain. For example, the collaborative success rate of device A and device B is 0.9, meaning that device A and device B can successfully complete tasks 90% of the time. This calculation relies on historical operational data, failure rates, response capabilities, and other factors for each device. If device A and device B have successfully completed 90 tasks out of 100 collaborations in the past, their collaborative success rate is 0.9. The collaborative success rate of each device is updated based on real-time data and provides a basis for subsequent stability assessments.

[0059] Next, the collaborative response time node of the link nodes is obtained. The collaborative response time is the time required for a device to start and execute a task after receiving a collaboration task. If device A needs 5 seconds to start the fire extinguishing device after receiving a fire alarm, the response time node of this device is 5 seconds. The response time of a device is a key factor affecting the stability of the collaboration chain, and if the response time of a device is unstable, it may affect the effectiveness of the entire collaboration chain. For example, the response time of device B may exceed 10 seconds in some cases, which will affect the stability of the collaboration chain. Therefore, the response time of each device is analyzed to identify devices that may affect collaboration efficiency.

[0060] Next, trigger timeliness stability analysis is performed based on the obtained collaborative response time node. This analysis assesses whether devices can respond and complete tasks in a timely manner, especially when facing disturbances. For example, the response time of device A is always within 5 seconds, while the response time of device B fluctuates greatly and may take more than 10 seconds. In this case, the response time of device B is unstable and may become a factor affecting the stability of the collaboration chain. Therefore, trigger timeliness stability analysis helps identify potential delay issues in devices.

[0061] After completing the trigger timeliness stability analysis, collaborative breakpoints are identified. Collaborative breakpoints are key nodes in the collaboration chain that cannot complete tasks on time due to device failures, response delays, and other reasons, causing the entire collaboration chain to fail. For example, device A may cause devices B and C to be unable to continue collaboration due to a failure, and these devices become collaborative breakpoints. By analyzing the collaborative success rate, response time stability, and failure mode of each node, these breakpoints are identified. Device A may be a collaborative breakpoint because its failure will cause the entire collaboration chain to be interrupted.

[0062] Finally, based on the collaboration interruption points, collaboration success rate calculation results, and trigger time stability analysis results, the device collaboration stability assessment is completed. This assessment comprehensively considers the collaboration success rate, response time stability, and collaboration interruption points of each node to evaluate the stability of the device collaboration chain. For example, device A has a collaboration success rate of 0.9, a stable response time, and no interruptions, so device A is highly stable. However, device B has a collaboration success rate of 0.6, large response time fluctuations, and collaboration interruptions, so device B is less stable. Based on these evaluation results, a comprehensive stability score for the device collaboration chain is calculated, reflecting the stability performance of the devices during the collaboration process.

[0063] Finally, all evaluation results are normalized. Normalization converts all scores to a uniform scale, typically between 0 and 1, where 0 represents the lowest stability and 1 represents the highest. For example, if device A has a stability score of 0.85 and device B has a stability score of 0.6, after normalization, device A might receive a score of 0.9 and device B a score of 0.7. Through normalization, the scores of all devices and collaborative chains are aggregated and averaged to create a unified, comprehensive stability score.

[0064] Furthermore, in the method provided in the embodiment of the application, the multi-dimensional graph security scoring of the time-series updated security knowledge graph further includes:

[0065] The time-series updated security knowledge graph is used to extract personnel motion data under motion detection and industrial control response, and establish the evolution trajectory of personnel behavior nodes; based on the evolution trajectory of the personnel behavior nodes, matching scores are performed on the number of offset steps and the motion missing rate to establish a first matching score result; the personnel's heart rate collection data is obtained, and the psychological load fitness score is performed based on the heart rate collection data and the evolution trajectory of the personnel behavior nodes to establish a second matching score result. The evaluation features of the psychological load fitness score include heart rate features, motion pause features, and repetitive operation features; the first matching score result and the second matching score result are used to complete the human response matching assessment.

[0066] In an embodiment of the present application, personnel behavior data is extracted through a time-series updated security knowledge graph, and personnel behavior is evaluated based on this data. First, personnel behavior data is monitored in real time through sensors (such as video surveillance, position sensors, motion capture equipment, etc.) and converted into a personnel behavior node evolution trajectory. This trajectory records the personnel's actions at each step from the occurrence of the fire to the response process, such as walking from room A to the fire extinguisher and activating the fire extinguisher. These trajectories are compared with the preset shortest path to calculate the number of offset steps. The offset step number is used to measure whether the personnel are following the shortest path for emergency response. Assuming the preset path is 10 meters and the personnel actually walked 15 meters, the offset step number is 5 meters. If the personnel chooses a longer path or takes a detour, the offset step number will increase, thereby affecting the score. The offset step number is quantified according to preset rules. The larger the offset step number, the lower the score, indicating that the timeliness of the personnel response is poor. For example, a personnel with a 5-meter offset will be scored as 0.3 for the offset step number, while a personnel with a 10-meter offset will be scored as 0.1 for the offset step number. Next, the missing action rate is calculated to assess whether personnel omitted key steps during the emergency response process. For example, during a firefighting operation, personnel should complete the steps of removing the fire extinguisher's safety pin, pressing the fire sprinkler, and ensuring that the fire is completely extinguished. If a worker misses a step, the missing action rate is calculated based on the number of steps missed. Assume that the firefighting process consists of five steps, and the worker misses two. The missing action rate is 2 / 5 = 0.4. According to the preset rule, a higher missing action rate indicates a lower score, indicating incomplete operation, which may affect the firefighting effect. A missing action rate of 0.4 results in a score of 0.5. The above steps yield the first matching score, which is a comprehensive evaluation of the two metrics: the number of offset steps and the missing action rate. Assuming the number of offset steps is scored as 0.3 (large offset) and the missing action rate is scored as 0.5 (partial missing action), these two scores are combined using a weighted average method. The number of offset steps and the missing action rate are weighted equally. The first matching score is obtained through calculation.

[0067] Next, the psychological load adaptability score is calculated by collecting the heart rate data of the personnel combined with the behavior trajectory of the personnel. The psychological load adaptability score reflects the psychological stress of the personnel in the emergency response process. The psychological load adaptability score is evaluated by the heart rate feature, the action pause feature and the repeated operation feature. The heart rate feature is collected by a wearable device (such as a smart bracelet, a heart rate belt, etc.) in real time. If the heart rate of the personnel increases from the normal 70 times / minute to 120 times / minute, it indicates that the fluctuation of the heart rate is large and the psychological load is high. Assuming that the change range of the heart rate is 50%, according to the preset rule, such a change range may correspond to a score of 0.8. The action pause feature measures whether the personnel has a long pause in the fire extinguishing process. Assuming that the personnel pauses for more than 5 seconds in the fire extinguishing operation, it may be caused by tension or excessive stress. According to the length of the pause time, the score is increased if the pause is more than 5 seconds, and the score is assumed to be 0.7. The repeated operation feature evaluates whether the personnel repeats the same operation due to unskilled or psychological stress. If the personnel repeatedly checks the fire extinguisher or repeats the same operation in the fire extinguishing process, the psychological load score is increased according to the number of repetitions. Assuming that the number of repeated operations is large, the score is 0.6. The psychological load adaptability score is calculated by weighting the scores of the three features. For example, assuming that the weight of the heart rate feature is 0.5, the weight of the action pause feature is 0.3, and the weight of the repeated operation feature is 0.2, the psychological load adaptability score is calculated by weighting, and the score is taken as the second matching score result.

[0068] Finally, the human response matching evaluation is completed by combining the first matching score result and the second matching score result. In this step, the logical chain between the key operation, the device response and the environmental change is identified from the personnel behavior node evolution trajectory. This logical chain reveals how the personnel behavior triggers the response of the device and the change of the environmental state. For example, in a fire scene, the fire extinguishing operation of the personnel may trigger the start of the fire extinguishing device, and then change the environmental conditions of the fire area. According to these relationships, a behavior-driven risk map is established to identify the potential paths of the risks induced by the human operation. Through this risk map, the potential paths of the risks induced by the human operation are identified, which may be the safety hazards caused by the personnel operation errors or untimely. Further, the additional score result is constructed by using these potential risk paths, which reflects the risks caused by the human operation to the overall safety. Finally, the additional score result is combined with the first matching score result (such as the offset step number and the action missing rate) and the second matching score result (such as the psychological load adaptability score) obtained before, and the final result of the human response matching evaluation is obtained through comprehensive evaluation.

[0069] Further, in the method provided by the application embodiment, the human response matching evaluation is completed by using the first matching score result and the second matching score result, and further comprises:

[0070] Identify the logical chain of key operations-equipment responses-environmental changes in the evolution trajectory of personnel behavior nodes; establish a behavior-driven risk map based on the logical chain to identify potential paths of risks induced by human operations; use the potential paths of risks induced by human operations to construct additional scoring results, and complete the human response matching assessment based on the additional scoring results, the first matching scoring results, and the second matching scoring results.

[0071] In an embodiment of the present application, the evolution trajectory of the personnel behavior node is first used to identify the logical chain between key operations, equipment responses and environmental changes. This process uses data association and analysis technology to record each action step of the personnel (for example, walking from room A to the fire extinguisher position and starting the fire extinguisher) through time series monitoring and sensors (such as position sensors, video surveillance, motion capture equipment, etc.). Then, by analyzing the relationship between the personnel operation and the equipment response (such as the activation of the fire extinguishing equipment) and environmental changes (such as temperature drop, smoke concentration reduction), the causal chain is identified. For example, the personnel operation triggers the response of the equipment, which in turn changes the temperature and smoke concentration in the fire area. Such an operation-response-environmental change chain is used as a logical chain. This chain describes how personnel behavior affects the response of the equipment and how the response of the equipment changes the environmental conditions. For example, the fire extinguishing operation of the staff may trigger the activation of the fire extinguishing equipment, which in turn changes the temperature and smoke concentration in the fire area. By analyzing these causal relationships, the potential path of human operation-induced risks is identified and incorporated into the behavior-driven risk map. The behavior-driven risk map uses personnel's operating behavior, equipment's response, and environmental changes as nodes of the map. The connections between nodes represent the causal relationship between operation and response, and between response and environmental changes.

[0072] Based on the behavior-driven risk map, risk paths induced by human actions are identified. For example, if a worker fails to follow the designated path to the fire extinguisher, resulting in a delayed equipment response, this risk path is identified and an additional score is calculated. The additional score reflects the additional risk posed by the human behavior to system safety and is initially assigned a score of 1. Based on the identified risk paths, the additional score is calculated by quantifying their impact. For example, suppose a deviation from the fire extinguisher's path delays the activation of the fire extinguisher by 10 seconds. The score is set to decrease by 0.05 points for each second of delay. For a 10-second equipment response delay, the additional score = 10 × (-0.05) = -0.5. Therefore, the additional score due to the equipment response delay is 0.5, representing the additional risk introduced by the operational delay. Furthermore, the score is adjusted based on the risk paths of equipment response delay and environmental changes. For example, if a delayed equipment response delay delays the extinguisher's discharge, the temperature in the fire area rises and the smoke density increases. Assume that each second of delay results in a 0.2°C increase in the fire area temperature and a 0.1 unit increase in smoke density. The environmental risk score is set to decrease by 0.03 points for each second of delay. After a 10-second delay, the risk score drops by 0.3 points. Therefore, the final additional score = 1 - 0.5 - 0.3 = 0.2.

[0073] Finally, the additional scoring results are combined with the first matching scoring results (number of offset steps and missing motion rate) and the second matching scoring results (mental workload adaptability score) to perform a human response fit assessment. Assuming the first matching score is 0.4 (indicating high number of offset steps and missing motion rate), the second matching score is 0.7 (indicating high mental workload), and the additional scoring result is 0.2 (indicating additional risk caused by human interaction), these scores are combined using a weighted average or other merging method. For example, assuming the weight of the first matching score is 0.3, the weight of the second matching score is 0.3, and the weight of the additional scoring result is 0.4, the final human response fit assessment score = (0.4 × 0.3) + (0.7 × 0.3) + (0.2 × 0.4) = 0.41. This process completes the human response fit assessment and obtains the corresponding human response fit score.

[0074] Furthermore, in the method provided in the embodiment of the application, the multi-dimensional graph security scoring of the time-series updated security knowledge graph further includes:

[0075] An isolation mechanism triggering efficiency scoring function is established. The evaluation characteristics of the isolation mechanism triggering efficiency scoring function include effectiveness assessment characteristics, isolation closed-loop completion characteristics, strategy triggering responsiveness characteristics, and delay characteristics. The characteristic weight coefficients of the isolation mechanism triggering efficiency scoring function are dynamically adjusted through the airtightness characteristics and connectivity characteristics of the space. The isolation mechanism triggering efficiency scoring function is used to complete the isolation mechanism triggering efficiency evaluation.

[0076] In this embodiment, an isolation mechanism trigger efficiency scoring function is first established: S = w1·E + w2·C + w3·R + w4·D. Here, S represents the isolation mechanism trigger efficiency score, E represents the effectiveness assessment feature, C represents the isolation closed-loop completion feature, R represents the policy trigger responsiveness feature, and D represents the latency feature. w1, w2, w3, and w4 represent corresponding weight coefficients, which sum to 1.

[0077] The effectiveness assessment feature is used to evaluate whether the isolation mechanism has effectively completed its intended tasks, such as whether the fire door is closed in time and whether the gas isolation device is activated normally. The status of the space is monitored in real time through environmental sensors (such as smoke sensors, temperature sensors, etc.) to determine whether the isolation device is activated according to the intended function. Sensor data collection and algorithm matching are used to determine whether the equipment has met the predetermined standards. For example, in a fire scenario, when the fire alarm system sends a signal, whether the fire door is closed smoothly. If the equipment is successfully activated, a higher score, such as 0.9, is given; if it fails to start on time, a lower score, such as 0.3, is given.

[0078] The isolation closed-loop completion feature assesses whether all necessary steps have been completed for the isolation operation. For example, in a fire emergency, after the fire door is closed, is the air conditioning system turned off and the exhaust system stopped? Whether the closed loop is completed is determined by real-time monitoring of equipment status and feedback information (such as equipment switch status, airflow sensor data, etc.). The startup and shutdown of the equipment are recorded. If all links are completed, a higher score is given; if a link is not completed, the missing part is calculated, and a score is given based on the missing link and preset rules. For example, if the fire door is closed but the air conditioning is not stopped, the score may be 0.6.

[0079] The Policy Trigger Responsiveness feature assesses how quickly the isolation mechanism responds to external triggers. For example, when a fire alarm is triggered, can fire doors and fire extinguishing equipment activate within the specified time? Time series analysis techniques and event triggering are used to calculate the delay between signal reception and device activation. The shorter the response time, the higher the score. For example, if the device activates within 3 seconds of receiving the fire alarm, it is given a higher score (e.g., 0.8); if the response delay exceeds 5 seconds, the score drops to 0.4.

[0080] The latency characteristic assesses the response delay of the isolation mechanism, specifically the time difference between the trigger signal and the execution of the isolation action. The time interval from signal to execution is calculated using equipment monitoring and time recording techniques. Assuming a 10-second delay in detecting the activation of a fire extinguisher, the latency score is calculated based on a pre-defined rule (e.g., a 0.05-point decrease for every 1-second delay). For example, a 10-second delay would result in a 0.5-point decrease in the score, resulting in a score of 0.5.

[0081] The weight coefficients of each feature in the isolation mechanism triggering efficiency scoring function are dynamically adjusted based on the airtightness and connectivity characteristics of the space. Airtightness reflects the degree of sealing of the space, affecting the effectiveness and integrity of isolation devices (such as fire doors and gas isolation devices); connectivity reflects the ability to communicate between devices within the space, affecting the speed and timeliness of device responses. Based on the actual measurement results of these characteristics, technical experts dynamically adjust the weight of each feature.

[0082] For example, in environments with high airtightness, greater emphasis is placed on effectiveness assessment features and isolation closed-loop completion features, as these are crucial to isolation effectiveness in well-sealed environments. In contrast, in environments with poor connectivity, information transmission may be delayed. Based on this, technical experts will increase the weight of policy trigger responsiveness features to ensure that isolation mechanisms can still be activated promptly even in environments with large response delays.

[0083] Finally, the isolation mechanism triggering efficiency scoring function is used to complete the isolation mechanism triggering efficiency evaluation and obtain a corresponding score.

[0084] Step S500: Outputting a security level assessment result using the multi-dimensional graph security scoring matrix.

[0085] In the embodiments of this application, to obtain the security level assessment results, a comprehensive score is calculated based on the score values ​​of each dimension. In this process, the scores of each dimension are weighted using a weighted average method to generate a comprehensive overall security score. In this process, each dimension in the multidimensional atlas security score matrix has the same weight.

[0086] Next, based on the calculated total safety score, the system outputs a safety rating according to a preset rating range. For example, if the total safety score is greater than or equal to 0.9, the safety rating is rated "high"; if the total score is between 0.7 and 0.9, the safety rating is rated "medium"; and if the score is less than 0.7, the safety rating is rated "low".

[0087] Furthermore, in the method provided in the embodiment of the application, the outputting of the security level assessment result using the multi-dimensional graph security scoring matrix further includes:

[0088] The time-series updated security knowledge graph is used to perform statistics on the response frequency, anomaly rate, and stability of nodes and edges in the graph, and calculate the trust level. The trust level is used to identify the dependent components and high-risk components in the smart civil air defense space, and the dependent components and high-risk components are used to compensate for the security level assessment results.

[0089] In an embodiment of the present application, a time-series updated security knowledge graph is first used to perform statistics on the response frequency, anomaly rate, and stability of nodes and edges within the graph. To obtain the response frequency, the number of responses of each device or sensor over a period of time is recorded. For example, a fire extinguisher may have responded to 10 emergency requests in the past month, so the response frequency is 10 times. To obtain the anomaly rate, the frequency of anomalies at each node or edge is calculated. For example, if a gas detection sensor has failed 3 times in the past week and has monitored a total of 1,000 data points, then its anomaly rate is 3 / 1,000 = 0.003. Stability measures the reliability of a node or edge under different environmental conditions and is usually expressed by the failure rate of the node. For example, a device that has not failed in the past 6 months indicates high stability, while a device that fails once a month indicates poor stability. In order to quantify stability, the system calculates the number of times a device fails in a specific time period and compares it with the total operating time to obtain a stability index.

[0090] The trustworthiness of each node and edge is calculated based on the response frequency, anomaly rate, and stability data obtained. The weights corresponding to response frequency, 1 minus the anomaly rate, and stability are pre-set. The trustworthiness is calculated by weighting these factors.

[0091] Based on the trust calculation results, preset thresholds are used to identify reliable and high-risk components. Reliable components are highly trusted and can reliably perform tasks in emergency situations, such as fire protection systems or gas isolation devices that can respond quickly. High-risk components, on the other hand, are less trusted and may cause failures or compromise safety, such as frequently malfunctioning sensors or unstable equipment. This method categorizes the various components in the smart civil air defense space and identifies which are critical and reliable, and which may pose safety risks.

[0092] After obtaining reliable and high-risk components, the security rating is compensated based on these components. Specifically, if reliable components account for a large proportion, exceeding 80%, it indicates that the smart civil air defense space has high reliability and security, and the security rating will be improved, for example, raising the security level to "high". On the other hand, if high-risk components account for a large proportion, the security rating will be lowered, for example, to "medium" or "low".

[0093] Furthermore, in the method provided in the embodiment of the application, the outputting of the security level assessment result using the multi-dimensional graph security scoring matrix further includes:

[0094] Obtaining the important factors of the selected disturbance event in the disturbance event library; after using the important factors to compensate the multidimensional atlas safety scoring matrix, obtaining the coverage of all selected disturbance events on the disturbance event library; and outputting the safety level assessment result using the compensation result and the coverage.

[0095] In the embodiment of the present application, firstly, an important factor of the selected disturbance event in the disturbance event library is obtained, and the important factor is a preset coefficient.

[0096] Next, the extracted important factors are applied to the multidimensional atlas safety score matrix, and each evaluation dimension in the matrix is ​​weighted and adjusted according to the important factors of each disturbance event.

[0097] The coverage of the disturbance event library for all selected disturbance events is then calculated. Coverage reflects the extent of the impact of the selected disturbance event on the safety assessment and is achieved by calculating the ratio of the sum of the importance factors of the selected disturbance event to the sum of the importance factors of all disturbance events in the disturbance event library. For example, if fire, power outage, and equipment failure events are selected, and the sum of the importance factors of these events is 1.9, while the sum of the importance factors of all disturbance events in the disturbance event library is 3.0, then the calculated coverage is 1.9 / 3.0 = 0.6333, indicating that the impact of these three disturbance events on the safety assessment covers 63.33% of all disturbance events in the disturbance event library.

[0098] Finally, the final safety rating is calculated by combining the compensated matrix score and coverage. The compensated matrix score reflects the specific impact of the disturbance event on each safety assessment dimension, while the coverage indicates the scope of the disturbance event's impact on the overall safety assessment library. These two are combined through weighted averaging to output a comprehensive safety score. For example, assuming a compensated matrix score of 0.85 and a coverage of 0.6333, the final safety score is 0.85 × 0.6333 = 0.5373. Based on the preset scoring criteria, the safety level is rated "medium," indicating that under the influence of the current disturbance event, overall safety is relatively stable but still presents certain risks.

[0099] In the embodiments of the present application, in summary, the embodiments of the present application have at least the following technical effects:

[0100] This application constructs a disturbance event library, selects disturbance events in the disturbance event library to perform safety disturbance simulation, and guides the smart civil defense space into an emergency state; establishes a safety knowledge graph of the smart civil defense space under a normal environment, and the safety knowledge graph includes spatial structure nodes, functional equipment nodes, sensor nodes, personnel behavior nodes, and functional status nodes; configures the stage life cycle of the smart civil defense space, and executes node response data collection of the smart civil defense space within the stage life cycle to update the graph state of the safety knowledge graph in response to the data collection results; performs a multi-dimensional graph security score on the time-series updated safety knowledge graph, and establishes a multi-dimensional graph safety score matrix, and the evaluation dimensions of the multi-dimensional graph safety score include structural conductivity risk assessment, equipment collaborative stability assessment, human response matching assessment, and isolation mechanism triggering efficiency assessment; and uses the multi-dimensional graph safety score matrix to output the safety level assessment result. The present invention solves the technical problem of the lack of comprehensive security assessment means in the existing technology in the security assessment of civil defense space. By constructing a disturbance event library to simulate security disturbances, establishing a security knowledge graph based on environmental detection, and an evaluation method of a multi-dimensional security scoring matrix, the technical effect of real-time assessment of the security status of the smart civil defense space is achieved.

[0101] Example 2, based on the same inventive concept as the intelligent civil air defense space safety assessment method based on environmental detection in the previous embodiment, Figure 2 As shown, this application provides an intelligent civil air defense space safety assessment system based on environmental detection. The system and method embodiments in the embodiments of this application are based on the same inventive concept. The system includes:

[0102] The security disturbance simulation module 11 is used to construct a disturbance event library, select disturbance events in the disturbance event library to perform security disturbance simulation, and guide the smart civil defense space into an emergency state; the security knowledge graph establishment module 12 is used to establish a security knowledge graph of the smart civil defense space under a normal environment, and the security knowledge graph includes spatial structure nodes, functional equipment nodes, sensor nodes, personnel behavior nodes, and functional status nodes; the data acquisition module 13 is used to configure the stage life cycle of the smart civil defense space, and execute node response data collection of the smart civil defense space within the stage life cycle to update the graph state of the security knowledge graph in response to the data collection results; the security scoring module 14 is used to perform multi-dimensional graph security scoring on the time-series updated security knowledge graph, and establish a multi-dimensional graph safety scoring matrix. The evaluation dimensions of the multi-dimensional graph safety scoring include structural conductivity risk assessment, equipment collaborative stability assessment, human response matching assessment, and isolation mechanism triggering efficiency assessment; the security level assessment result acquisition module 15 is used to output the security level assessment result using the multi-dimensional graph safety scoring matrix.

[0103] Furthermore, the system is also used to implement the following functions:

[0104] The security knowledge graph in a normal environment is taken as a steady-state baseline graph; the steady-state baseline graph is taken as a comparison benchmark to perform disturbance source node identification of the security knowledge graph updated in time sequence, and influence propagation tracking is performed to calculate influence propagation path length and diffusion speed; the influence propagation path length and diffusion speed are used to identify and lock key vulnerable nodes and high-risk connected links; and structure conduction risk assessment is completed according to the identification and locking result, the influence propagation path length and the diffusion speed.

[0105] Further, the system is also used to implement the following functions:

[0106] After the first round of high-risk connected links is constructed, a high-risk node set is established; the high-risk node set is taken as a new disturbance source to perform repeated propagation simulation to establish second-order propagation intensity; the second-order propagation intensity is superimposed with the first-order propagation intensity of the first round of high-risk connected links to establish a cascading risk network; and the key vulnerable nodes are updated by using the cascading risk network.

[0107] Further, the system is also used to implement the following functions:

[0108] According to the selected disturbance event, a key device cooperation chain is configured; based on the security knowledge graph updated in time sequence and the key device cooperation chain, a cooperation success rate of a link node is calculated to generate a cooperation success rate calculation result; a cooperation response time node of the link node is acquired, trigger time effectiveness stability analysis is performed according to the cooperation response time node to establish a trigger time effectiveness stability analysis result; a cooperation breakpoint is identified, and device cooperation stability evaluation is completed according to the cooperation breakpoint, the cooperation success rate calculation result and the trigger time effectiveness stability analysis result.

[0109] Further, the system is also used to implement the following functions:

[0110] Personnel action data under action detection and industrial control response are extracted by using the security knowledge graph updated in time sequence to establish an evolution track of a personnel behavior node; a matching score of a deviation step number and an action missing rate is established based on the evolution track of the personnel behavior node to establish a first matching score result; heart rate collection data of the personnel are acquired, and a psychological load adaptability score is performed according to the heart rate collection data and the evolution track of the personnel behavior node to establish a second matching score result, wherein the evaluation features of the psychological load adaptability score include heart rate features, action pause features and repeated operation features; and human factor response matching evaluation is completed by using the first matching score result and the second matching score result.

[0111] Further, the system is also used to implement the following functions:

[0112] Identify the logical chain of key operation-equipment response-environment change in the personnel behavior node evolution trajectory; establish a behavior-driven risk map according to the logical chain to identify the potential path of human operation induced risk; use the potential path of human operation induced risk to build an additional scoring result, and complete the human response matching evaluation according to the additional scoring result, the first matching scoring result and the second matching scoring result.

[0113] Further, the system is also used to realize the following functions:

[0114] An isolation mechanism triggering efficiency scoring function is established, the evaluation features of the isolation mechanism triggering efficiency scoring function include effectiveness evaluation features, isolation closed loop completion degree features, strategy triggering responsiveness features and delay features, and the feature weight coefficients of the isolation mechanism triggering efficiency scoring function are dynamically adjusted through the space airtightness features and communication features; the isolation mechanism triggering efficiency evaluation is completed by using the isolation mechanism triggering efficiency scoring function.

[0115] Further, the system is also used to realize the following functions:

[0116] The response frequency, abnormal rate and stability data statistics of nodes and edges in the graph are performed by using the time sequence updated security knowledge graph, the trust degree is calculated, the reliable components and high-risk components in the intelligent civil air defense space are identified by using the trust degree, and the security level evaluation result is compensated by using the reliable components and high-risk components.

[0117] Further, the system is also used to realize the following functions:

[0118] The important factors of the selected disturbance events in the disturbance event library are obtained; after the multi-dimensional graph security scoring matrix is compensated by using the important factors, the coverage of all selected disturbance events on the disturbance event library is obtained; and the security level evaluation result is output by using the compensation result and the coverage.

[0119] It should be noted that the above sequence of the embodiments of the present application is only for description, and does not represent the advantages and disadvantages of the embodiments. The above describes a specific embodiment of the present application. The processes depicted in the drawings do not necessarily require the specific order and continuous order shown to achieve the desired results. In some embodiments, multi-task processing and parallel processing are also possible or may be advantageous.

[0120] The above only describes the preferred embodiments of the present application, and does not limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

[0121] This specification and drawings are merely illustrative of the present application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Obviously, those skilled in the art may make various modifications and variations to this application without departing from the scope of this application. Thus, this application is intended to include such modifications and variations as fall within the scope of this application and its equivalents.

Claims

1. The intelligent civil air defense space safety assessment method based on environmental detection is characterized by: The method comprises: Build a disturbance event library, select disturbance events from the library to perform safety disturbance simulation, and guide the smart civil air defense space into an emergency state; Establish a security knowledge graph for smart civil air defense space under normal conditions, which includes space structure nodes, functional equipment nodes, sensor nodes, personnel behavior nodes, and functional status nodes; Configuring a stage life cycle of the smart civil air defense space, executing node response data collection of the smart civil air defense space within the stage life cycle, and updating the graph state of the security knowledge graph in response to the data collection results; Perform a multi-dimensional graph safety score on the time-series updated safety knowledge graph and establish a multi-dimensional graph safety score matrix. The evaluation dimensions of the multi-dimensional graph safety score include structural conductivity risk assessment, equipment collaborative stability assessment, human response matching assessment, and isolation mechanism triggering efficiency assessment; Outputting a safety rating result using the multi-dimensional graph safety scoring matrix; The multi-dimensional graph security scoring for the time-series updated security knowledge graph includes: Use the security knowledge graph under normal conditions as the steady-state baseline graph; Using the steady-state baseline graph as a comparison benchmark, identify the disturbance source nodes of the time-series updated security knowledge graph, and perform impact propagation tracking to calculate the impact propagation path length and diffusion speed; Identify and lock key vulnerable nodes and high-risk connectivity links by influencing the propagation path length and diffusion speed; Complete structural conductivity risk assessment based on identification and locking results, impact propagation path length and diffusion speed; The identification and locking of key vulnerable nodes and high-risk connectivity links by influencing the propagation path length and diffusion speed includes: After building the first round of high-risk connectivity links, establish a high-risk node set; Using the high-risk node set as a new disturbance source, performing repeated propagation simulations to establish second-order propagation strength; Superimposing the second-order propagation intensity with the first-order propagation intensity of the high-risk connected links in the first round to establish a cascading risk network; Updating key vulnerable nodes using the cascading risk network; The multi-dimensional graph security scoring for the time-series updated security knowledge graph further includes: Configure the key equipment collaborative chain according to the selected disturbance event; Calculate the collaboration success rate of link nodes based on the time-series updated security knowledge graph and key equipment collaboration chain, and generate the collaboration success rate calculation results; Acquire the coordinated response time node of the link node, perform trigger time stability analysis based on the coordinated response time node, and establish a trigger time stability analysis result; Identify the collaborative interruption point, and complete the equipment collaborative stability assessment based on the collaborative interruption point, the collaborative success rate calculation result, and the trigger time stability analysis result.

2. The intelligent civil air defense space safety assessment method based on environmental detection according to claim 1 is characterized in that: The multi-dimensional graph security scoring for the time-series updated security knowledge graph further includes: Utilize the time-series updated security knowledge graph to extract personnel action data under action detection and industrial control response, and establish the evolution trajectory of personnel behavior nodes; Perform matching scores based on the number of offset steps and the action missing rate based on the evolution trajectory of the personnel behavior node, and establish a first matching score result; Acquiring heart rate data collected by the personnel, performing a mental load fitness score based on the heart rate data and the evolution trajectory of the personnel's behavior nodes, and establishing a second matching score result, wherein evaluation features of the mental load fitness score include heart rate features, action pause features, and repetitive operation features; The first matching score result and the second matching score result are used to complete the human response matching assessment.

3. The intelligent civil air defense space safety assessment method based on environmental detection as claimed in claim 2 is characterized in that: The method of completing the human factor response matching assessment using the first matching score result and the second matching score result includes: Identify the logical chain of key operations-equipment responses-environmental changes in the evolution trajectory of personnel behavior nodes; Establish a behavior-driven risk map based on the logical chain to identify potential paths of risks induced by human operations; An additional scoring result is constructed using the potential path of risk induced by human operation, and a human response matching assessment is completed based on the additional scoring result, the first matching scoring result, and the second matching scoring result.

4. The intelligent civil air defense space safety assessment method based on environmental detection according to claim 1 is characterized in that: The multi-dimensional graph security scoring for the time-series updated security knowledge graph further includes: Establish an isolation mechanism triggering efficiency scoring function. The evaluation features of the isolation mechanism triggering efficiency scoring function include effectiveness assessment features, isolation closed-loop completion features, strategy triggering responsiveness features, and delay features. The weight coefficients of each feature of the isolation mechanism triggering efficiency scoring function are dynamically adjusted based on the airtightness and connectivity features of the space. The isolation mechanism triggering efficiency evaluation is completed by utilizing the isolation mechanism triggering efficiency scoring function.

5. The intelligent civil air defense space safety assessment method based on environmental detection according to claim 1 is characterized in that: Outputting the security level assessment result using the multi-dimensional graph security scoring matrix includes: Use the time-series updated security knowledge graph to collect statistics on the response frequency, anomaly rate, and stability of nodes and edges within the graph, and calculate the trust level; The trust level is used to identify the reliable components and high-risk components in the smart civil air defense space, and the reliable components and high-risk components are used to compensate the security level assessment results.

6. The intelligent civil air defense space safety assessment method based on environmental detection according to claim 1 is characterized in that: The method of outputting a security level assessment result using the multi-dimensional graph security scoring matrix further includes: Obtain the important factors of the selected disturbance event in the disturbance event database; After compensating the multi-dimensional atlas safety score matrix using the important factors, the coverage of the disturbance event library by all selected disturbance events is obtained; The compensation results and coverage are used to output the safety level assessment results.

7. The intelligent civil air defense space safety assessment system based on environmental detection is characterized by: The system is used to execute the intelligent civil air defense space safety assessment method based on environmental detection according to any one of claims 1 to 6, and the system includes: A safety disturbance simulation module is used to build a disturbance event library, select disturbance events in the disturbance event library to perform safety disturbance simulation, and guide the smart civil air defense space into an emergency state; A security knowledge graph establishment module is used to establish a security knowledge graph for smart civil air defense space under normal conditions. The security knowledge graph includes space structure nodes, functional equipment nodes, sensor nodes, personnel behavior nodes, and functional status nodes. A data collection module is used to configure the stage life cycle of the smart civil air defense space, execute node response data collection of the smart civil air defense space within the stage life cycle, and update the graph state of the security knowledge graph in response to the data collection results; A safety scoring module is used to perform multi-dimensional graph safety scoring on the time-series updated safety knowledge graph and establish a multi-dimensional graph safety scoring matrix. The evaluation dimensions of the multi-dimensional graph safety scoring include structural conductivity risk assessment, equipment collaborative stability assessment, human response matching assessment, and isolation mechanism triggering efficiency assessment; The security level assessment result acquisition module is used to output the security level assessment result using the multi-dimensional atlas security scoring matrix.

Citation Information

Patent Citations

  • Civil air defense door deformation detection system and method based on machine vision

    CN114881936A

  • Power load monitoring and control method based on digital twinning

    CN118657045A