Abnormal intrusion monitoring method and related device
By deploying intrusion detection units of multiple information collection modules at the electronic fence of the camp, the intrusion risk prediction model is used to evaluate intrusion risks and generate dynamic disposal information, the limitations of manual patrols and traditional defense facilities are solved, and the safety and security efficiency of the camp are improved.
Patent Information
- Application Number
- CN202510651000.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2045-05-20
AI Technical Summary
In the prior art, the security alert in the camp relies on manual patrols and traditional walls and posts, making it difficult to monitor invasions in a comprehensive and timely manner, and defense facilities are easily breached, resulting in invasion monitoring and security difficulties.
The intrusion detection unit deployed at the electronic fence includes a variety of information collection modules. The multi-dimensional intrusion monitoring information is evaluated through the intrusion risk prediction model and dynamic intrusion disposal information is generated, including intrusion disposal scheduling, methods and early warning.
It improves the ability to perceive and detect and discriminate intrusion behavior, enhances the response efficiency of intrusion disposal, reduces the risk of intrusion, and improves the security of the camp.
Smart Images

Figure CN120472595A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing, and in particular to an abnormal intrusion monitoring method and related devices. Background Art
[0002] A military camp is a multi-functional, multi-unit assembly base. It typically includes various buildings and facilities, such as combat areas, weapon and equipment storage areas, dormitories, cafeterias, and medical facilities. Security measures, such as security checks, patrols, and entrance and exit inspections, are implemented to ensure camp safety.
[0003] In related technologies, security in military camps is typically maintained through manual patrols. However, human senses, reaction speed, and abilities are limited, making oversights and missed reports unavoidable. Furthermore, the buildings and facilities in military camps are relatively scattered, limiting the coverage area of manual patrols and ensuring comprehensive and timely detection of all intrusions. Furthermore, while defensive structures such as walls and sentry posts enhance military camp security, they cannot effectively prevent intrusions. Furthermore, the defense structures themselves are at risk of being breached or compromised, making intrusion detection and security even more difficult. Therefore, the limited defensive measures of manual patrols and traditional structural defenses such as walls and sentry posts in related technologies are difficult to adapt to increasingly complex intrusion methods.
[0004] Therefore, in order to improve the security of the camp, a new abnormal intrusion monitoring solution is urgently needed. Summary of the Invention
[0005] The present application provides an abnormal intrusion monitoring method and related devices for risk prediction of multi-dimensional intrusion monitoring information, realizing automated intrusion monitoring of the identified objects, improving the efficiency of abnormal intrusion monitoring, and enhancing the security of the camp.
[0006] In a first aspect, the present application provides a method for detecting abnormal intrusions, the method comprising:
[0007] In response to an early warning instruction for an object to be processed, multi-dimensional intrusion monitoring information of the object to be processed is obtained; the multi-dimensional intrusion monitoring information is monitored by an intrusion detection unit in the target camp; the intrusion detection unit is deployed at the electronic fence of the target camp; the intrusion detection unit includes multiple different types of information collection modules;
[0008] Through the intrusion risk prediction model, risk prediction is performed on multi-dimensional intrusion monitoring information to obtain risk prediction information of the object to be processed;
[0009] Dynamic intrusion handling information is generated based on risk prediction information; wherein, the dynamic intrusion handling information at least includes: intrusion handling scheduling information, intrusion handling method, intrusion warning information; the intrusion handling scheduling information is used to indicate the handling personnel and / or equipment that need to be scheduled.
[0010] In a second aspect, an embodiment of the present application provides an abnormal intrusion monitoring device, the device comprising:
[0011] an acquisition unit configured to acquire multi-dimensional intrusion monitoring information of the target object in response to an early warning instruction for the target object; the multi-dimensional intrusion monitoring information is acquired by monitoring an intrusion detection unit in the target camp; the intrusion detection unit is deployed at an electronic fence of the target camp; the intrusion detection unit includes a plurality of different types of information acquisition devices;
[0012] The risk prediction unit is configured to perform risk prediction on the multi-dimensional intrusion monitoring information through an intrusion risk prediction model to obtain risk prediction information of the object to be processed;
[0013] The generation unit is configured to generate dynamic intrusion handling information based on risk prediction information; wherein the dynamic intrusion handling information at least includes: intrusion handling scheduling information, intrusion handling method, and intrusion warning information; the intrusion handling scheduling information is used to indicate the handling personnel and / or equipment that need to be scheduled.
[0014] In a third aspect, an embodiment of the present application provides a computing device, the computing device comprising:
[0015] at least one processor, memory, and input-output unit;
[0016] The memory is used to store a computer program, and the processor is used to call the computer program stored in the memory to execute the abnormal intrusion monitoring method of the first aspect.
[0017] In a fourth aspect, a computer-readable storage medium is provided, which includes instructions. When the instructions are executed on a computer, the computer executes the abnormal intrusion monitoring method of the first aspect.
[0018] In the technical solution provided by the embodiments of the present application, first, in response to an early warning instruction for a target target, multi-dimensional intrusion monitoring information is obtained for the target target. This multi-dimensional intrusion monitoring information is obtained by intrusion detection units within the target camp. The intrusion detection units are deployed at the target camp's electronic fence and include multiple different types of information collection modules. By deploying intrusion detection units within the target camp and utilizing different types of information collection modules, more comprehensive multi-dimensional intrusion monitoring information can be obtained, improving the ability to detect intrusions. Furthermore, risk prediction is performed on the multi-dimensional intrusion monitoring information using an intrusion risk prediction model to obtain risk prediction information for the target target. This risk prediction of the multi-dimensional intrusion monitoring information using the intrusion risk prediction model enables a rapid and accurate assessment of the target target's intrusion risk level, providing more comprehensive risk prediction information and improving the accuracy of intrusion risk monitoring. Finally, dynamic intrusion response information is generated based on the risk prediction information. This dynamic intrusion response information includes at least intrusion response scheduling information, intrusion response methods, and intrusion early warning information. The intrusion response scheduling information indicates the required response personnel and / or equipment. This helps improve the efficiency of risk prediction response and enhances the security of the target camp. In particular, it helps avoid delays caused by the limitations of manual patrols and improves the efficiency of handling camp security issues.
[0019] In the technical solution of the present application, multi-dimensional intrusion monitoring information in the target camp is obtained more comprehensively, the perception ability of intrusion behavior is improved, and the multi-dimensional intrusion monitoring information is processed through the intrusion risk prediction model to improve the detection and discrimination ability of intrusion behavior, effectively enhance the response efficiency of intrusion disposal, reduce the risk of intrusion, and ensure the safety of the target camp. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0021] Figure 1 This is a flow chart of an abnormal intrusion monitoring method according to an embodiment of the present application;
[0022] Figure 2 This is a schematic diagram of the principle of an intrusion risk prediction model according to an embodiment of the present application;
[0023] Figure 3 This is a schematic diagram of the principle of a multi-dimensional review network according to an embodiment of the present application;
[0024] Figure 4 This is a schematic structural diagram of an abnormal intrusion monitoring device according to an embodiment of the present application;
[0025] Figure 5 It is a structural diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0026] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0027] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application pertains. The terms used herein in the specification of this application are for the purpose of describing specific embodiments only and are not intended to limit this application.
[0028] A military camp is a multi-functional base where multiple units gather. It typically includes various buildings and facilities, such as dormitories, canteens, medical facilities, and warehouses. It also has security measures such as guard posts, patrols, and entrance and exit checks to ensure security.
[0029] In related technologies, security in military camps is typically maintained through manual patrols. However, human senses, reaction speed, and abilities are limited, making oversights and missed reports unavoidable. Furthermore, the buildings and facilities in military camps are relatively scattered, limiting the coverage area of manual patrols and ensuring comprehensive and timely detection of all intrusions. Furthermore, while defensive structures such as walls and sentry posts enhance military camp security, they cannot effectively prevent intrusions. Furthermore, the defense structures themselves are at risk of being breached or compromised, making intrusion detection and security even more difficult. Therefore, the limited defensive measures of manual patrols and traditional structural defenses such as walls and sentry posts in related technologies are difficult to adapt to increasingly complex intrusion methods.
[0030] Therefore, in order to improve the security of the camp, a new abnormal intrusion monitoring solution is urgently needed.
[0031] To solve at least one of the above technical problems, an embodiment of the present application provides an abnormal intrusion monitoring method and related devices.
[0032] Specifically, in the abnormal intrusion monitoring solution, first, in response to an early warning instruction for a target target, multi-dimensional intrusion monitoring information is obtained for the target target. This multi-dimensional intrusion monitoring information is obtained by intrusion detection units within the target camp. The intrusion detection units are deployed at the target camp's electronic fence and include multiple different types of information collection modules. By deploying intrusion detection units within the target camp and utilizing different types of information collection modules, more comprehensive multi-dimensional intrusion monitoring information can be obtained, improving the ability to detect intrusion behavior. Furthermore, risk prediction is performed on the multi-dimensional intrusion monitoring information using an intrusion risk prediction model to obtain risk prediction information for the target target. This risk prediction of the multi-dimensional intrusion monitoring information using the intrusion risk prediction model enables a rapid and accurate assessment of the target target's intrusion risk level, providing more comprehensive risk prediction information and improving the accuracy of intrusion risk monitoring. Finally, dynamic intrusion response information is generated based on the risk prediction information. This dynamic intrusion response information includes at least intrusion response scheduling information, intrusion response methods, and intrusion early warning information. The intrusion response scheduling information indicates the required response personnel and / or equipment. This helps improve the efficiency of risk prediction response and enhances the security of the target camp. In particular, it helps avoid delays caused by the limitations of manual patrols and improves the efficiency of handling camp security issues.
[0033] In the abnormal intrusion monitoring solution, multi-dimensional intrusion monitoring information in the target camp is obtained more comprehensively, the perception ability of intrusion behavior is improved, and the multi-dimensional intrusion monitoring information is processed through the intrusion risk prediction model to improve the detection and discrimination ability of intrusion behavior, effectively enhance the response efficiency of intrusion disposal, reduce intrusion risks, and ensure the safety of the target camp.
[0034] The abnormal intrusion monitoring solution provided in the embodiments of the present application can be executed by an electronic device, which can be a server, a server cluster, or a cloud server. The electronic device can also be a terminal device such as a mobile phone, a computer, a tablet computer, a wearable device, or a dedicated device (such as a dedicated terminal device with an abnormal intrusion monitoring system). In an optional embodiment, the electronic device can be installed with a service program for executing the abnormal intrusion monitoring solution.
[0035] Figure 1 A schematic diagram of an abnormal intrusion monitoring method provided in an embodiment of the present application is shown as follows: Figure 1 As shown, the method includes the following steps:
[0036] 101. In response to an early warning instruction for an object to be processed, obtain multi-dimensional intrusion monitoring information of the object to be processed.
[0037] In this embodiment of the present application, the objects to be processed are candidate intruders detected entering the target camp. Here, candidate intruders can be individuals or groups of individuals. Specifically, the objects to be identified can be one person or a group of people. Alternatively, they can be devices, such as drones or vehicles.
[0038] For example, if the target camp is undergoing intrusion monitoring, then the early warning instruction for the object to be processed may refer to the situation where one or a group of suspicious persons or illegal items such as drones are found in a certain area within the target camp. In this case, the object to be processed is the candidate intrusion object that is detected entering the target camp. It can be a single suspicious person or drone, or a group of suspicious persons or drones. After a candidate intrusion object is detected, multi-dimensional intrusion monitoring information can be obtained through the intrusion monitoring equipment, such as the location, speed, direction of travel, volume, weight, sound, image and other multi-dimensional intrusion monitoring information of the candidate intrusion object, for further analysis and identification. Based on this multi-dimensional intrusion monitoring information, the risk assessment and prediction of the candidate intrusion object can be carried out, and then dynamic intrusion disposal information can be generated to assist security personnel in taking corresponding intrusion disposal measures.
[0039] In this embodiment of the present application, multi-dimensional intrusion monitoring information is obtained by an intrusion detection unit within the target camp. Specifically, the intrusion detection unit is deployed at the target camp's electronic fence. The intrusion detection unit includes multiple different types of information collection modules. The target camp's electronic fence is a security facility used to define and protect the boundaries of the target area, using electronic technology for monitoring and control.
[0040] In one possible example, the target camp's electric fence may consist of the following components: sonar sensors, photoelectric sensors, vibration sensors, and a video surveillance system. Based on this, in 101, the electric fence may be equipped with sonar sensors, installed on the fence or around the ground. These sensors use sound waves to detect and identify the movement of objects or people. When a person or object approaches or touches the fence, the sonar sensors capture the associated sound signals and trigger an alarm system. The electric fence may also use photoelectric sensors, installed on part or all of the fence. These sensors monitor activity around the fence by emitting infrared beams and detecting beam interruptions. When a person or object crosses the infrared beam, the photoelectric sensor detects the beam interruption and sounds an alarm. The electric fence may also be equipped with vibration sensors, installed on the fence structure. These sensors detect contact or tampering by external objects or people by sensing vibrations. If someone attempts to climb over, hit, or damage the fence, the vibration sensors capture the vibration signals and trigger an alarm. The electric fence may be integrated with a video surveillance system, with cameras installed to cover key areas around the fence. These cameras provide real-time monitoring of the fence's exterior and provide high-definition images or video footage. Monitoring personnel can observe the video in real time through the monitoring center and take further action as needed. The above is an example of an electronic fence in a target camp. By integrating multiple sensors and monitoring technologies, the electronic fence can monitor and detect intrusions around the fence in real time and provide multi-dimensional intrusion monitoring information to ensure the security of the target area.
[0041] Based on the above example, the warning instructions for the target object can be issued by the intrusion detection unit. The intrusion detection unit uses different types of information collection modules to monitor the boundaries or specific areas of the target camp. When suspicious intrusion behavior occurs, the intrusion detection unit can automatically trigger a warning instruction. These warning instructions may include but are not limited to the following situations:
[0042] Scenario 1: Triggering an alarm: The intrusion detection unit can trigger an alarm through sound, light flash, vibration, etc. to attract the attention of security personnel. This can promptly alert staff in the target camp that a suspicious intrusion is occurring.
[0043] Case 2: Sending notifications: The intrusion detection unit can send notifications to designated security personnel through the communication channel connected to the central management system. In this way, the security personnel can quickly receive the intrusion warning information and make appropriate responses and handling.
[0044] Case 3: Triggering surveillance video. The intrusion detection unit can be integrated with the video surveillance system. When suspicious intrusion behavior is detected, the system can automatically obtain the relevant surveillance video from the camera and send it to security personnel for real-time review and analysis.
[0045] Through these early warning instructions, the intrusion detection unit can promptly alarm and notify relevant personnel so that they can react and respond quickly to protect the safety of the target camp.
[0046] In another example, an intrusion detection unit can be composed of several different types of information collection modules: high-definition cameras, infrared sensors, sound sensors, and pressure sensors. Specifically, the intrusion detection unit can be equipped with high-definition cameras for real-time monitoring of the area surrounding the target camp. These cameras can capture visual information of intrusions, such as images of suspicious individuals or vehicles, thereby providing visual monitoring information of the target. The intrusion detection unit can also include infrared sensors to detect infrared radiation from the human body or other heat sources. When a person or animal enters the target area, the infrared sensor responds, providing thermal signal monitoring information of the target. The intrusion detection unit can also integrate sound sensors to detect changes in sound within the target area. For example, if someone knocks on a fence or makes an unusual sound, the sound sensor can capture these signals and trigger an alert, providing sound monitoring information of the target. The intrusion detection unit can also use pressure sensors, mounted on a fence or the ground, to monitor pressure changes within the target area. When a person or vehicle steps on or applies pressure, the pressure sensor can detect these changes, providing pressure monitoring information of the target.
[0047] These information collection modules can be connected to the intrusion detection unit via wireless communication or wired connection, and send the collected multi-dimensional intrusion monitoring information to the central management system for processing and analysis in real time, thereby providing comprehensive, multi-angle intrusion intelligence, helping to accurately judge the intrusion nature and risk level of the object to be processed.
[0048] In 102, risk prediction is performed on the multi-dimensional intrusion monitoring information through the intrusion risk prediction model to obtain risk prediction information of the object to be processed.
[0049] Specifically, an intrusion risk prediction model can be constructed based on historical data and machine learning algorithms. It comprehensively considers multiple factors, such as the type of intrusion, the time of intrusion, the intruder's behavioral patterns, and related intrusion monitoring information. By analyzing and modeling these factors, the model can assess and predict the risk of the target. The prediction result of the intrusion risk prediction model can be a numerical value or a risk level, indicating the degree of risk the target may face. For example, three different risk levels may be predicted: low, medium, and high, with higher scores indicating higher risk. The purpose of the intrusion risk prediction model is to help camp security personnel take appropriate measures based on the risk prediction information of the target. For example, for high-risk targets, nearby security personnel or security equipment can be immediately dispatched for response and emergency action. For low-risk targets, scheduled patrols or increased surveillance can be implemented.
[0050] For example, let's assume that the intrusion risk prediction model for a target camp uses image recognition technology to identify whether someone has crossed a fence within a specific area. The intrusion risk prediction model then includes at least the following structure: a feature extraction layer, a hidden risk prediction layer, and a prediction output layer. The hidden risk prediction layer consists of multiple stacked connected layers, each of which processes the output of the previous layer to extract higher-level feature representations for subsequent risk prediction.
[0051] In this intrusion risk prediction model, the feature extraction layer might process images captured by surveillance cameras to extract key features such as pedestrian outlines, posture, and gait. In the next step, the first hidden risk prediction layer might learn basic feature representations from these features, such as pedestrian presence, speed, and direction. Then, in subsequent hidden risk prediction layers, each connected layer might process features from the previous layer to further extract higher-level features, such as certain movement patterns and preferences of pedestrians in the visible area. In this way, the model can map the hidden risk prediction features of each layer to more abstract feature representations that are more relevant to specific intrusion situations.
[0052] When the input data passes through all the hidden layers and finally reaches the output layer, the model may integrate the information from all the hidden layers to form a model output that represents the risk level of the object being processed. This output may be a result of classifying the intrusion behavior or grading it by risk, such as unpredictable intrusion, low risk, medium risk, or high risk.
[0053] As an optional embodiment, it is assumed that the intrusion risk prediction model includes at least the following structures: a feature extraction layer, a hidden risk prediction layer, and a prediction output layer. Furthermore, the hidden risk prediction layer includes multiple hidden risk prediction layers connected in a stacked manner.
[0054] Based on the above structure, in 102, the risk prediction of the multi-dimensional intrusion monitoring information is performed through the intrusion risk prediction model to obtain the risk prediction information of the object to be processed, such as Figure 2 As shown, it can be implemented as follows:
[0055] 201 , extracting intrusion behavior features from the multi-dimensional intrusion monitoring information through a feature extraction layer of an intrusion risk prediction model.
[0056] Extract intrusion behavior features from multi-dimensional intrusion monitoring information, such as the location and time of intrusion, and these features will serve as input to the feature extraction layer.
[0057] 202 : Learning and extracting a first hidden risk feature from the intrusion behavior feature through each hidden risk prediction layer of the intrusion risk prediction model.
[0058] In the hidden risk prediction layer, the intrusion risk prediction model learns to extract risk features from the extracted features. These hidden risk features may be related to the type of intrusion behavior, the behavior pattern of the intruder, etc.
[0059] 203 , performing feature fusion processing based on the second hidden risk feature output by the previous hidden risk prediction layer and the first hidden risk feature through each hidden risk prediction layer of the intrusion risk prediction model to obtain a third hidden risk feature.
[0060] To improve the model's predictive accuracy, the hidden risk prediction layer can be stacked with multiple hidden layers, with each hidden layer continuing to learn useful feature representations from the previous layer. At each level of the hidden risk prediction layer, the model performs feature fusion based on the output features of the previous layer and the input features of the current layer. For example, the output features of the previous hidden layer can be concatenated with the input features of the current layer as the input features of the current layer, or some other feature fusion method can be used.
[0061] 204 , performing risk prediction processing on the hidden risk features outputted by each of the multiple hidden risk prediction layers through the prediction output layer of the intrusion risk prediction model to obtain the intrusion risk prediction probability of the object to be processed.
[0062] After feature extraction and feature fusion processing in multiple hidden risk prediction layers, the model will input the features into the prediction output layer for classification or regression prediction, such as determining the intrusion risk level faced by the object to be processed.
[0063] In practical applications, as an optional embodiment, the process of obtaining the predicted probability of intrusion risk is expressed as follows:
[0064] y=σ(w(L+1) ·h (L) +b (L+1) )
[0065] Where y represents the predicted probability of intrusion risk, σ(·) represents the expression of risk prediction processing, and h (L) represents the hidden risk feature output by the Lth hidden risk prediction layer, b (L+1) Expressed as a bias scalar, w (L+1) It is represented as the weight vector corresponding to the Lth hidden risk prediction layer.
[0066] As an optional embodiment, a training method for an intrusion risk prediction model can be implemented as follows: First, pseudo sample data matching the multidimensional intrusion monitoring information is generated. This pseudo sample data can be generated by simulating various types of intrusion behaviors, scenarios, and environments to increase the diversity of the model's training samples. Then, the multidimensional intrusion monitoring information and the matching pseudo sample data are input into the intrusion risk prediction model, and each hidden risk prediction layer within the intrusion risk prediction model is trained from the bottom up. This data may include information on multiple dimensions, such as the time, location, and behavior pattern of the intrusion. Next, the contrast divergence difference between each piece of multidimensional intrusion monitoring information and the matching pseudo sample data in each hidden risk prediction layer is obtained. Contrastive divergence is a metric that measures the difference between two data distributions and is used to measure the distance between the predicted result and the true result. Finally, the model parameters in each hidden risk prediction layer are adjusted based on the contrast divergence difference to complete the training of the intrusion risk prediction model. In this way, the model parameters in each hidden risk prediction layer are adjusted based on the contrast divergence difference using optimization methods such as gradient descent. Through continuous iteration and adjustment, the model parameters are optimized, enabling the model to more accurately predict the risk of the target object.
[0067] Through the above training steps, the generated pseudo-sample data can be used to train the intrusion risk prediction model. By optimizing the model parameters and using the contrastive divergence difference as a metric, the model's predictive ability is gradually improved, thereby increasing the accuracy of the risk prediction for the processed objects. This training method can increase the model's generalization ability and improve the model's predictive performance on unseen samples.
[0068] In 103, dynamic intrusion handling information is generated based on the risk prediction information.
[0069] In the embodiment of the present application, the dynamic intrusion handling information includes at least: intrusion handling scheduling information, intrusion handling methods, and intrusion warning information.
[0070] Intrusion response scheduling information is used to indicate the personnel and / or equipment that need to be dispatched. Specifically, the following intrusion response scheduling information can be generated. For example, personnel scheduling information can be generated. Specifically, based on risk prediction information, the most suitable security personnel can be selected to carry out the response task. If a high-risk intrusion is predicted in an area, this information can be used to instruct security personnel with response capabilities and located in a similar location to proceed to the area for response. For example, equipment scheduling information can be generated. Specifically, relevant monitoring equipment can be dispatched for response based on risk prediction information. If a high-risk intrusion is predicted in an area, nearby cameras may be dispatched for monitoring and automatically perform processing operations such as recording and image analysis. By generating intrusion response scheduling information, the response time and effectiveness of intrusion response can be optimized. Based on different intrusion risk predictions, response resources can be rationally allocated, and appropriate personnel and equipment can be dispatched for timely response, thereby reducing the losses and threats caused by the intrusion.
[0071] In addition to intrusion handling scheduling information, dynamic intrusion handling information also includes intrusion handling methods and intrusion warning information.
[0072] Regarding intrusion response methods, let's assume the risk prediction model predicts an intrusion risk in a certain area and has generated corresponding intrusion response scheduling information. Next, it's necessary to select an appropriate intrusion response method based on the actual situation. For example, intrusion response methods include, but are not limited to, the following: enhancing physical security measures, such as strengthening security access control at the area's perimeter and increasing security patrol density; strengthening technical security protections, such as enabling intrusion detection systems, strengthening network firewalls, updating security patches, and disabling sensitive accounts; and implementing public security response measures, such as dispatching police forces, developing public security patrol plans, and increasing patrol intensity. Depending on the actual situation of the target camp, different intrusion response methods can be adopted and corresponding response strategies established.
[0073] Intrusion warning information is primarily used to alert users and provide relevant intrusion predictions and response recommendations. For example, users can receive intrusion warning information via mobile phones, computers, and other terminals, allowing them to stay informed and take appropriate action based on the warning recommendations. Examples of intrusion warning information include, but are not limited to: intrusion risk predictions, such as predicting possible intrusions in a specific area within a certain period of time; alert information push, such as real-time delivery of intrusion warning information and response recommendations to key personnel; and relevant information, such as intrusion history, case studies of similar security incidents, and technical white papers, to better understand the intrusion situation and response methods. The timely distribution and appropriate use of intrusion warning information can prevent relevant security threats and enhance the effectiveness of intrusion response.
[0074] As an optional embodiment, before step 103 , a real-time positioning model may be used to perform trajectory positioning processing on the multi-dimensional intrusion monitoring information to obtain the real-time movement trajectory of the object to be processed.
[0075] Accordingly, in step 103, the real-time location of the target is first determined based on the real-time trajectory. Then, based on the intrusion behavior in the risk prediction information and the real-time location, an intrusion response dispatch route is generated for the target. Finally, the range of camp locations covered by the intrusion response dispatch route within the target camp is obtained, and intrusion alert information matching the range of camp locations is generated.
[0076] For example, assume that multiple intrusion monitoring devices, such as cameras and sensors, are deployed in a target camp to monitor intrusions. Simultaneously, the system uses a real-time positioning model to perform trajectory positioning on the multi-dimensional intrusion monitoring information to obtain the real-time movement trajectory of the target. Specifically, the real-time positioning model, combined with the location data in the intrusion monitoring information, can determine the real-time location of the target. This can be achieved through various positioning technologies, such as GPS. Furthermore, based on the intrusion behavior and the real-time location of the target, an intrusion response dispatch route can be generated. This route specifies the personnel and / or equipment to be dispatched, as well as the sequence and path of the response actions. Finally, by obtaining the camp location range covered by the intrusion response dispatch route within the target camp, intrusion alert information matching the camp location range can be generated. This alert information can include the type of intrusion, risk level, and specific location, and can be notified to relevant personnel through various means, such as mobile phone push notifications and text message notifications.
[0077] For example, suppose the real-time positioning model detects a potential intruder in a certain area of the target camp and, based on risk prediction information, determines that the intrusion is high-risk. It can then generate an intrusion response route, instructing the nearest security personnel to proceed to that area and ensure they follow the designated route. Simultaneously, an intrusion alert is generated, indicating the intrusion risk and specific location in that area, allowing personnel to take timely action.
[0078] By using real-time positioning models combined with risk prediction information, the location and movement trajectory of the object to be processed can be determined more accurately, and corresponding intrusion disposal scheduling routes and alarm information can be generated to improve the efficiency and accuracy of intrusion disposal.
[0079] In the embodiments of the present application, by deploying intrusion detection units and utilizing different types of information collection modules, more comprehensive multi-dimensional intrusion monitoring information can be obtained within the target camp, thereby improving the ability to detect intrusions. These intrusion detection units, deployed at the target camp's electronic fences, can promptly detect intrusions and, through the information collection modules, collect various types of monitoring information. Next, by using an intrusion risk prediction model to perform risk prediction on this multi-dimensional intrusion monitoring information, the intrusion risk level of the target target can be quickly and accurately assessed, providing more comprehensive risk prediction information. This risk prediction information can help decision-makers better understand intrusion risks and formulate appropriate response strategies based on the risk level. Based on this risk prediction information, dynamic intrusion response information can be generated. Intrusion response scheduling information indicates the personnel and / or equipment that need to be dispatched to promptly address intrusions. The intrusion response method will select appropriate security measures based on the specific situation, such as enhanced physical security and technical safety protection. Simultaneously, intrusion warning information will alert relevant personnel and provide information such as intrusion predictions and response recommendations. By more comprehensively acquiring multi-dimensional intrusion monitoring information and combining it with analysis from intrusion risk prediction models, we can improve our ability to detect and identify intrusions, increase the efficiency of intrusion response, reduce intrusion risks, and ensure the security of target camps. In particular, the technical means described in the embodiments of this application can overcome the delays inherent in traditional manual patrols and improve the efficiency of handling security issues.
[0080] In the above or following embodiments, the embodiments of the present application also provide a method for optimizing and correcting risk prediction information.
[0081] Specifically, after step 101, a multidimensional review network can be used to review the multidimensional intrusion monitoring information to obtain behavioral risk review information for the subject to be processed. The multidimensional review network includes behavioral review branches for processing different types of intrusion monitoring information. After step 102, a risk optimization model can be used to perform prediction and correction processing on the risk prediction information based on the behavioral risk review information to obtain optimized and corrected risk prediction information for the subject to be processed.
[0082] Based on the above embodiment, a multi-dimensional review network is used to review different types of behavior data in the multi-dimensional intrusion monitoring information to obtain the behavior risk review information of the object to be processed. Figure 3 As shown, it can be implemented as follows:
[0083] 301, pre-processing the multi-dimensional intrusion monitoring information to obtain intrusion monitoring information adapted to different behavior review branches;
[0084] 302 , using the video review branch model, the audio review branch model, and the behavior trajectory branch review model in the multi-dimensional review network, the corresponding intrusion monitoring information is respectively identified to obtain intrusion behavior prediction information including the review results of each branch.
[0085] The intrusion behavior prediction information is used to represent the probability prediction value of the object to be processed implementing various intrusion behaviors.
[0086] For example, suppose a target camp is equipped with multi-dimensional monitoring equipment, including video surveillance, audio monitoring, and behavioral trajectory monitoring. These monitoring devices record and detect various intrusion behaviors, such as illegal intrusion and unusual sounds. In the multi-dimensional verification network, the video verification branch analyzes the behavior of the target within the target camp by analyzing video surveillance. For example, the video analysis algorithm can detect behaviors such as the target wearing camouflage or carrying suspicious items, and generate corresponding intrusion behavior prediction information, indicating the probability that the target has committed illegal intrusion. In the audio verification branch, audio monitoring can analyze the sounds produced by the target. For example, the sound analysis algorithm can detect unusual noises or explosions produced by the target, and generate corresponding intrusion behavior prediction information, indicating the probability that the target has committed sabotage. In the behavioral trajectory branch, behavioral trajectory monitoring can analyze the target's movement trajectory and activity patterns within the target camp. For example, it can identify the target's activities in non-work areas and generate corresponding intrusion behavior prediction information, indicating the probability that the target has committed boundary violations.
[0087] By reviewing different types of intrusion monitoring information through a multi-dimensional review network, comprehensive intrusion behavior prediction information can be obtained. This intrusion behavior prediction information represents the predicted probability of various intrusion behaviors being carried out by the target, which helps to assess risks and formulate appropriate response measures. For example, if the intrusion behavior prediction information for the target indicates a high probability, an alarm will be issued, instructing security personnel to take appropriate action to address the intrusion.
[0088] By adopting a multi-dimensional review network and generating intrusion behavior prediction information, the intrusion risk of the target object can be assessed more comprehensively and accurately, and a more accurate assessment basis can be provided to effectively respond to intrusion incidents and improve the security of the target camp.
[0089] As an optional embodiment, in step 302, the corresponding intrusion monitoring information is identified by using the audio review branch model in the multi-dimensional review network to obtain intrusion behavior prediction information including the review results of each branch. This can be implemented as follows:
[0090] 3021, multiple local acoustic features are extracted from audio intrusion monitoring information through the multi-layer feature extraction layer of the audio review branch model.
[0091] For example, raw audio data (i.e., audio intrusion monitoring information) undergoes Mel-Frequency Cepstral Coefficient (MFCC) feature extraction to produce a sequence of audio features with distinct frequency and temporal characteristics. Mel-Frequency Cepstral Coefficients are a feature extraction method used in audio signal processing that converts frequency-domain features into Mel-frequency-scaled cepstral coefficients. This conversion better accommodates the characteristics of human hearing.
[0092] In an embodiment of the present application, a shared convolution layer is used to set shared weights between multiple feature extraction layers. In traditional network design, each feature extraction layer will have independent convolution kernel parameters, that is, the convolution kernels between different layers are trained independently. However, in an embodiment of the present application, a shared convolution layer is selected to set shared weights. Specifically, in this example, you can choose to set shared weights on the convolution layer of layer A, and use these shared weights for the convolution operations of layers B and C. This means that the convolution operations of layers B and C use the same convolution kernel parameters as layer A, that is, they share the same convolution kernel. For example, suppose that in the convolution layer of layer A, a 3x3 convolution kernel parameter [w1, w2, w3; w4, w5, w6; w7, w8, w9] is used, where wi represents the weight of the convolution kernel. Then, in the convolution operations of layers B and C, the same 3x3 convolution kernel parameters [w1, w2, w3; w4, w5, w6; w7, w8, w9] will also be used. This allows for shared convolutional layer weights, reducing the number of network parameters and improving model efficiency. It also allows for the joint learning and representation of features across different layers. By sharing weights, we can leverage the collectively learned features across all layers and better respond to input variations.
[0093] 3022, through the primary capsule layer (Primary Capsule) of the audio review branch model, multiple local acoustic features are downsampled using capsule units, and the multiple local acoustic features are regrouped to obtain multiple groups of local acoustic features.
[0094] The main capsule layer contains multiple capsule units, each of which can extract different local acoustic features and represent each feature as a correlation vector. The value on each vector represents the strength and location information of the feature corresponding to each capsule unit.
[0095] For example, by performing an average pooling operation on the MFCC sequence, a set of local acoustic features is extracted to represent a certain sound pattern in the audio.
[0096] 3023, through the digital capsule layer (Digit Capsule) of the audio review branch model, multiple groups of local acoustic features are transmitted to the classification output layer through dynamic routing capsules to enhance the learning ability of local acoustic features.
[0097] Specifically, the capsule unit calculates the corresponding capsule output based on the local acoustic features of the input using a dynamic routing algorithm, thereby enhancing the learning ability of local acoustic features while retaining spatial information.
[0098] 3024, through the classification output layer of the audio review branch model, the classification probability of multiple groups of local acoustic features after preliminary classification is predicted under various intrusion behaviors to obtain the intrusion behavior probability corresponding to the local acoustic features.
[0099] For example, the classification output layer can output probability prediction values for different intrusion behaviors (such as breaking doors and windows), indicating the likelihood of each intrusion behavior occurring. Using these predicted probabilities, the probability of the intrusion behavior corresponding to the local acoustic features can be obtained.
[0100] For example, suppose you want to use the primary capsule layer and the digital capsule layer to extract and classify audio signals. First, the audio signal is feature extracted using the MFCC method, generating a series of MFCC sequences. Each MFCC sequence is equivalent to an image and can be considered a small signal composed of multiple local acoustic features, each capturing different acoustic properties. Each MFCC sequence is then passed to the primary capsule layer for processing. In the primary capsule layer, each capsule unit receives input from multiple local acoustic features, learns the relationships between them using a dynamic routing mechanism, and generates a capsule output. By establishing connections between multiple capsule units, the capsule layer can aggregate local acoustic features to obtain more discriminative features. Specifically, the primary capsule layer first inputs each MFCC sequence into a convolutional layer, which is designed to capture different local acoustic features. Then, after pooling and nonlinear activation operations, each convolution kernel produces a small signal map. For example, assuming three 3x3 convolution kernels are used, each kernel produces a 7x7 map. At this point, a feature tensor consisting of three mappings is obtained. Next, this feature tensor is processed using the primary capsule layer. In the primary capsule layer, each capsule unit downsamples small signals with similar characteristics and recombines them to generate a set of capsule outputs. Unlike traditional convolution operations, capsule units learn not only the features of the input but also the relationships between them. This dynamic routing mechanism helps improve the model's adaptability and generalization. Finally, in the output of the primary capsule layer, each capsule unit corresponds to an acoustic pattern, such as the sound of a vehicle approaching or a window breaking. These patterns have more abstract and robust feature representations, better distinguishing different acoustic events. In summary, the primary capsule layer is a key layer that downsamples and encodes multiple local acoustic features, helping to extract more discriminative and abstract features. Through processing in the primary capsule layer, we can better understand the acoustic events in the audio signal and more accurately classify and predict them.
[0101] In the above example, the main capsule layer can be viewed as an adaptive feature extractor. By downsampling and reorganizing capsule units, the main capsule layer can capture higher-dimensional acoustic features and transform them into different correlation vectors for further classification. This dynamic routing mechanism allows the model to adaptively extract local acoustic features, rather than being limited to fixed, predefined feature extraction.
[0102] Let's further introduce the digital capsule layer. The digital capsule layer in the audio verification branch model, as used in the camp example above, can be applied to representation learning and encoding of sound patterns. Consider an audio verification branch model used to review speech signals and determine whether there are any abnormal sounds. First, the audio signal can be feature extracted using the MFCC method, generating a series of MFCC sequences. Each MFCC sequence can be considered a small signal segment composed of multiple local acoustic features, each reflecting a different attribute of the sound. These MFCC sequences are then passed to the digital capsule layer for feature learning and representation encoding. In the digital capsule layer, each capsule unit encodes each MFCC sequence and learns the relationships between them to form a representation of the sound pattern. The capsule units here can be considered low-level acoustic components extracted from the audio signal, each of which is assigned a set of weights. Through processing in the digital capsule layer, a set of capsule outputs representing audio sound patterns is obtained. Each capsule output represents a sound pattern, such as normal human voice, ambient noise, or high-decibel sound. These capsule outputs contain not only the characteristic information of the sound but also the relationships between the sounds. Finally, these capsule outputs can be used for abnormal sound detection and classification. The capsule output can be connected to the next layer, such as a fully connected layer or a classifier, to determine whether there are any abnormal sounds in the audio signal. In this step, the capsule output results represent the confidence level of different sound patterns and can be used to determine whether there are any abnormal sounds. By adding a digital capsule layer, the audio verification branch model can better understand the sound patterns in the audio signal and convert them into interpretable feature codes. This design can improve the performance and interpretability of the audio verification model, providing more accurate and reliable results for sound anomaly detection and classification tasks.
[0103] In another optional embodiment, for the intrusion monitoring task of the target camp, the video review branch model involved in 302 can be implemented as the following structure:
[0104] Input layer: The input of the video composite branch model is a video sequence data, such as video streams captured by multiple surveillance cameras.
[0105] Convolutional layer: Uses convolution operations to extract features from each video frame, extracting local spatial features and dynamic temporal features from the video. For example, since surveillance cameras typically capture video of the same area, pre-trained convolution kernels, such as VGG16 and Inception video composite branch models, can be used for feature extraction.
[0106] Temporal Convolution Layer: To better learn the temporal features of video sequences, a temporal convolution layer can be added before each ResNet residual block. The size of the temporal convolution layer can be set to (1,3), indicating that the convolution operation is performed only in the temporal dimension, preserving the temporal information of the input data.
[0107] Residual Block Layer: Residual blocks are used to deeply learn higher-order feature representations. Each residual block consists of multiple convolutional layers and batch normalization layers, with skip connections used to mitigate the vanishing gradient problem and accelerate training. Within each residual block, temporal convolutional layers and convolutional layers alternate to effectively learn temporal and spatial features.
[0108] Global Average Pooling Layer: This layer performs global average pooling on the feature data and compresses it into a fixed-size feature vector. This can reduce the number of parameters, avoid overfitting, and retain important feature information.
[0109] Spatial convolutional layers: Several spatial convolutional layers are added at the end of the network to increase the receptive field and extract spatial features. These spatial convolutional layers operate on feature maps, further improving the performance and accuracy of the video composite branch model.
[0110] Fully connected layer: Finally, it connects the global average pooling layer and the output layer to output classification probabilities. The fully connected layer uses the softmax function to map features to probabilities of normal or abnormal categories. If there are more intrusion behavior subdivisions, the number of categories in the output layer can be increased.
[0111] The above structure enables the implementation of a video verification branch model, combining the context of the target camp with the video stream captured by the surveillance camera for intrusion monitoring. This video composite branch model can detect abnormal behaviors in the video stream in real time, such as sneaking, crawling, and crossing boundaries, and promptly notify relevant personnel. This video composite branch model can play a vital role in ensuring the security of the target camp.
[0112] In another optional embodiment, for the intrusion monitoring task of the target camp, the behavior trajectory branch review model involved in 302 can be implemented as the following structure:
[0113] Input layer: The input of the behavior trajectory branch review model is a behavior trajectory sequence data, such as the behavior trajectory recorded by sensors in the target camp (such as video surveillance, infrared sensors, etc.).
[0114] Position Encoding Layer: To add position information to sequence data, a position encoding layer can be used. The position encoding layer adds position information to the behavior trajectory at each time step in the sequence, so that the behavior trajectory branch review model can learn the contextual relationship between behavior trajectories.
[0115] Stacked Transformer encoding layers: The encoding layer of the Transformer behavior trajectory branch-review model is used to learn the global information of the input sequence and generate a representation of the corresponding behavior trajectory. The Transformer behavior trajectory branch-review model uses a self-attention mechanism to learn global relationships in the sequence, effectively capturing the temporal dependencies and contextual relationships between behavior trajectories.
[0116] Classification Output Layer: Add a classification output layer at the end of the behavior trajectory branch review model. Use a Softmax layer to map the behavior trajectory representation to the probabilities of different categories. Specifically, the output layer can be set to multiple categories (such as normal behavior, abnormal behavior, etc.) based on task requirements to classify the behavior trajectory.
[0117] The above structure enables the implementation of a behavioral trajectory branching and verification model, which analyzes and classifies recorded behavioral trajectories based on the context of the target camp. For example, in an intrusion monitoring mission at a target camp, the behavioral trajectory branching and verification model can learn the characteristics of normal behavioral trajectories and identify different types of abnormal behavior trajectories, such as running, sneaking, and interacting. The behavioral trajectory branching and verification model outputs the probability of each behavioral trajectory belonging to a category, thereby providing accurate intrusion behavior prediction information. This behavioral trajectory branching and verification model enables real-time monitoring and analysis of behavior at the target camp, improving the accuracy and efficiency of intrusion detection and further ensuring the security of the target camp.
[0118] In another embodiment of the present application, an abnormal intrusion monitoring device is also provided. Figure 4 As shown, the device includes the following units:
[0119] an acquisition unit configured to acquire multi-dimensional intrusion monitoring information of the target object in response to an early warning instruction for the target object; the multi-dimensional intrusion monitoring information is acquired by monitoring an intrusion detection unit in the target camp; the intrusion detection unit is deployed at an electronic fence of the target camp; the intrusion detection unit includes a plurality of different types of information acquisition devices;
[0120] The risk prediction unit is configured to perform risk prediction on the multi-dimensional intrusion monitoring information through an intrusion risk prediction model to obtain risk prediction information of the object to be processed;
[0121] The generation unit is configured to generate dynamic intrusion handling information based on risk prediction information; wherein the dynamic intrusion handling information at least includes: intrusion handling scheduling information, intrusion handling method, and intrusion warning information; the intrusion handling scheduling information is used to indicate the handling personnel and / or equipment that need to be scheduled.
[0122] Further optionally, the device also includes a review unit, which is configured to: after the acquisition unit obtains the multidimensional intrusion monitoring information of the object to be processed, use a multidimensional review network to review the multidimensional intrusion monitoring information to obtain the behavioral risk review information of the object to be processed; wherein, the multidimensional review network includes a behavioral review branch for processing different types of intrusion monitoring information.
[0123] The review unit is also configured to: after the risk prediction unit performs risk prediction on the multi-dimensional intrusion monitoring information through the intrusion risk prediction model to obtain the risk prediction information of the object to be processed, based on the behavioral risk review information, use the risk optimization model to perform prediction correction processing on the risk prediction information to obtain the optimized and corrected risk prediction information of the object to be processed.
[0124] Further optionally, the review unit uses a multi-dimensional review network to review different types of behavior data in the multi-dimensional intrusion monitoring information to obtain behavior risk review information of the object to be processed, and is specifically configured as follows:
[0125] Preprocessing the multi-dimensional intrusion monitoring information to obtain intrusion monitoring information adapted to different behavior review branches;
[0126] Through the video review branch model, the audio review branch model, and the behavior trajectory branch review model in the multidimensional review network, the corresponding intrusion monitoring information is respectively identified to obtain intrusion behavior prediction information including the review results of each branch;
[0127] The intrusion behavior prediction information is used to represent the probability prediction value of the object to be processed implementing various intrusion behaviors.
[0128] Further optionally, the review unit identifies corresponding intrusion monitoring information through the video review branch model, the audio review branch model, and the behavior trajectory branch review model in the multidimensional review network to obtain intrusion behavior prediction information including the review results of each branch, and is specifically configured as follows:
[0129] Extracting multiple local acoustic features from audio intrusion monitoring information through a multi-layer feature extraction layer of an audio review branch model; using a shared convolution layer to set shared weights between the multi-layer feature extraction layers;
[0130] Through the main capsule layer of the audio review branch model, multiple local acoustic features are downsampled using capsule units and regrouped to obtain multiple groups of local acoustic features;
[0131] Through the digital capsule layer of the audio review branch model, multiple groups of local acoustic features are transmitted to the classification output layer through dynamic routing capsules to enhance the learning ability of local acoustic features;
[0132] Through the classification output layer of the audio review branch model, the classification probability of multiple groups of local acoustic features after preliminary classification is predicted under various intrusion behaviors to obtain the intrusion behavior probability corresponding to the local acoustic features.
[0133] Further optionally, the device further includes a real-time positioning unit configured to:
[0134] Before generating dynamic intrusion handling information based on the risk prediction information, the generating unit uses a real-time positioning model to perform trajectory positioning processing on the multi-dimensional intrusion monitoring information to obtain a real-time action trajectory of the object to be processed;
[0135] The generation unit is specifically configured to: determine the real-time location of the object to be processed based on the real-time action trajectory; generate an intrusion disposal scheduling route for the object to be processed based on the intrusion behavior in the risk prediction information and the real-time location; obtain the camp location range covered by the intrusion disposal scheduling route in the target camp, and generate intrusion alarm information matching the camp location range.
[0136] Further optionally, the intrusion risk prediction model comprises at least the following structures: a feature extraction layer, a hidden risk prediction layer, and a prediction output layer; the hidden risk prediction layer comprises a plurality of stacked hidden risk prediction layers. The risk prediction unit is specifically configured as follows:
[0137] Extracting intrusion behavior features from the multi-dimensional intrusion monitoring information through a feature extraction layer of an intrusion risk prediction model;
[0138] Through each hidden risk prediction layer of the intrusion risk prediction model, a first hidden risk feature is learned and extracted from the intrusion behavior feature; a feature fusion process is performed based on the second hidden risk feature output by the previous hidden risk prediction layer and the first hidden risk feature to obtain a third hidden risk feature;
[0139] The hidden risk features outputted by each of the multiple hidden risk prediction layers are subjected to risk prediction processing through the prediction output layer of the intrusion risk prediction model to obtain the intrusion risk prediction probability of the object to be processed.
[0140] Further optionally, the process of obtaining the predicted probability of intrusion risk is expressed as the following expression:
[0141] y=σ(w (L+1) ·h (L) +b (L+1) )
[0142] Where y represents the predicted probability of intrusion risk, σ(·) represents the expression of risk prediction processing, and h (L) represents the hidden risk feature output by the Lth hidden risk prediction layer, b (L+1) Expressed as a bias scalar, w (L+1) It is represented as the weight vector corresponding to the Lth hidden risk prediction layer.
[0143] Further optionally, the apparatus further includes a training unit configured to:
[0144] generating pseudo sample data matching the multi-dimensional intrusion monitoring information;
[0145] Inputting the multi-dimensional intrusion monitoring information and the matched pseudo sample data into the intrusion risk prediction model, and training each hidden risk prediction layer in the intrusion risk prediction model from bottom to top;
[0146] Obtain the contrast divergence difference between each multidimensional intrusion monitoring information and the matched pseudo sample data in each hidden risk prediction layer;
[0147] The model parameters in each hidden risk prediction layer are adjusted based on the contrast divergence difference to complete the training of the intrusion risk prediction model.
[0148] In the embodiment of the present application, through the abnormal intrusion monitoring device, multi-dimensional intrusion monitoring information in the target camp is obtained more comprehensively, the perception ability of intrusion behavior is improved, and the multi-dimensional intrusion monitoring information is processed through the intrusion risk prediction model to improve the detection and discrimination ability of intrusion behavior, effectively enhance the response efficiency of intrusion disposal, reduce the risk of intrusion, and ensure the safety of the target camp.
[0149] In another embodiment of the present application, an electronic device is provided, comprising: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;
[0150] Memory for storing computer programs;
[0151] The processor is used to implement the abnormal intrusion monitoring method described in the method embodiment when executing the program stored in the memory.
[0152] The communication bus 1140 mentioned in the electronic device can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus 1140 can be divided into an address bus, a data bus, a control bus, etc.
[0153] For ease of representation, Figure 5 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.
[0154] The communication interface 1120 is used for communication between the electronic device and other devices.
[0155] The memory 1130 may include a random access memory (RAM) or a non-volatile memory (non-volatile memory), such as at least one disk storage. Alternatively, the memory may be at least one storage device located away from the processor.
[0156] The above-mentioned processor 1110 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0157] Accordingly, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, which, when executed, can implement the steps that can be performed by the electronic device in the above method embodiment.
Claims
1. A method for monitoring abnormal intrusion, characterized in that: include: In response to an early warning instruction for an object to be processed, obtaining multi-dimensional intrusion monitoring information of the object to be processed; The multi-dimensional intrusion monitoring information is obtained by monitoring the intrusion detection unit in the target camp; The intrusion detection unit is deployed at the electronic fence of the target camp; the intrusion detection unit includes multiple different types of information collection modules; Performing risk prediction on the multi-dimensional intrusion monitoring information through an intrusion risk prediction model to obtain risk prediction information of the object to be processed; Dynamic intrusion handling information is generated based on the risk prediction information; wherein, the dynamic intrusion handling information at least includes: intrusion handling scheduling information, intrusion handling method, and intrusion warning information; the intrusion handling scheduling information is used to indicate the handling personnel and / or equipment that need to be scheduled.
2. The abnormal intrusion monitoring method according to claim 1, characterized in that: After obtaining the multi-dimensional intrusion monitoring information of the object to be processed, the method further includes: A multi-dimensional review network is used to review the multi-dimensional intrusion monitoring information to obtain behavioral risk review information of the object to be processed; wherein the multi-dimensional review network includes behavioral review branches for processing different types of intrusion monitoring information; After performing risk prediction on the multi-dimensional intrusion monitoring information using the intrusion risk prediction model to obtain risk prediction information of the object to be processed, the method further includes: Based on the behavioral risk review information, a risk optimization model is used to perform prediction correction processing on the risk prediction information to obtain optimized and corrected risk prediction information of the object to be processed.
3. The abnormal intrusion monitoring method according to claim 2, characterized in that: The multi-dimensional review network is used to review different types of behavior data in the multi-dimensional intrusion monitoring information to obtain behavior risk review information of the object to be processed, including: Preprocessing the multi-dimensional intrusion monitoring information to obtain intrusion monitoring information adapted to different behavior review branches; Through the video review branch model, the audio review branch model, and the behavior trajectory branch review model in the multidimensional review network, the corresponding intrusion monitoring information is respectively identified to obtain intrusion behavior prediction information including the review results of each branch; The intrusion behavior prediction information is used to represent the probability prediction value of the object to be processed implementing various intrusion behaviors.
4. The abnormal intrusion monitoring method according to claim 3, characterized in that: The video review branch model, the audio review branch model, and the behavior trajectory branch review model in the multi-dimensional review network are used to respectively identify corresponding intrusion monitoring information to obtain intrusion behavior prediction information including the review results of each branch, including: Extracting multiple local acoustic features from audio intrusion monitoring information through a multi-layer feature extraction layer of an audio review branch model; using a shared convolution layer to set shared weights between the multi-layer feature extraction layers; Through the main capsule layer of the audio review branch model, multiple local acoustic features are downsampled using capsule units and regrouped to obtain multiple groups of local acoustic features; Through the digital capsule layer of the audio review branch model, multiple groups of local acoustic features are transmitted to the classification output layer through dynamic routing capsules to enhance the learning ability of local acoustic features; Through the classification output layer of the audio review branch model, the classification probability of multiple groups of local acoustic features after preliminary classification is predicted under various intrusion behaviors to obtain the intrusion behavior probability corresponding to the local acoustic features.
5. The abnormal intrusion monitoring method according to claim 1, characterized in that: Before generating dynamic intrusion handling information based on the risk prediction information, the method further includes: Using a real-time positioning model, the multi-dimensional intrusion monitoring information is subjected to trajectory positioning processing to obtain the real-time movement trajectory of the object to be processed; Generating dynamic intrusion handling information based on the risk prediction information includes: Determining the real-time location of the object to be processed according to the real-time movement trajectory; generating an intrusion handling scheduling route for the object to be processed based on the intrusion behavior and the real-time location in the risk prediction information; The camp location range covered by the intrusion handling scheduling route in the target camp is obtained, and intrusion alarm information matching the camp location range is generated.
6. The abnormal intrusion monitoring method according to claim 1, characterized in that: The intrusion risk prediction model at least includes the following structures: a feature extraction layer, a hidden risk prediction layer, and a prediction output layer; the hidden risk prediction layer includes multiple hidden risk prediction layers connected in a stacked manner; The risk prediction of the multi-dimensional intrusion monitoring information is performed using an intrusion risk prediction model to obtain risk prediction information of the object to be processed, including: Extracting intrusion behavior features from the multi-dimensional intrusion monitoring information through a feature extraction layer of an intrusion risk prediction model; Through each hidden risk prediction layer of the intrusion risk prediction model, a first hidden risk feature is learned and extracted from the intrusion behavior feature; a feature fusion process is performed based on the second hidden risk feature output by the previous hidden risk prediction layer and the first hidden risk feature to obtain a third hidden risk feature; The hidden risk features outputted by each of the multiple hidden risk prediction layers are subjected to risk prediction processing through the prediction output layer of the intrusion risk prediction model to obtain the intrusion risk prediction probability of the object to be processed.
7. The abnormal intrusion monitoring method according to claim 6, characterized in that: The process of obtaining the predicted probability of intrusion risk is expressed as follows: y=σ(w (L+1) ·h (L) +b (L+1) ) Where y represents the predicted probability of intrusion risk, σ(·) represents the expression of risk prediction processing, and h (L) represents the hidden risk feature output by the Lth hidden risk prediction layer, b (L+1) Expressed as a bias scalar, w (L+1) It is represented as the weight vector corresponding to the Lth hidden risk prediction layer.
8. The abnormal intrusion monitoring method according to claim 1, characterized in that: The training method of the intrusion risk prediction model further includes: generating pseudo sample data matching the multi-dimensional intrusion monitoring information; Inputting the multi-dimensional intrusion monitoring information and the matched pseudo sample data into the intrusion risk prediction model, and training each hidden risk prediction layer in the intrusion risk prediction model from bottom to top; Obtain the contrast divergence difference between each multidimensional intrusion monitoring information and the matched pseudo sample data in each hidden risk prediction layer; The model parameters in each hidden risk prediction layer are adjusted based on the contrast divergence difference to complete the training of the intrusion risk prediction model.
9. An abnormal intrusion monitoring device, characterized in that: The device comprises: an acquisition unit configured to acquire multi-dimensional intrusion monitoring information of a target object in response to an early warning instruction for the target object; the multi-dimensional intrusion monitoring information is acquired by an intrusion detection unit within a target camp; the intrusion detection unit is deployed at an electronic fence of the target camp; the intrusion detection unit includes a plurality of different types of information acquisition devices; a risk prediction unit configured to perform risk prediction on the multi-dimensional intrusion monitoring information through an intrusion risk prediction model to obtain risk prediction information of the object to be processed; A generation unit is configured to generate dynamic intrusion handling information based on the risk prediction information; wherein the dynamic intrusion handling information includes at least: intrusion handling scheduling information, intrusion handling method, and intrusion warning information; the intrusion handling scheduling information is used to indicate the handling personnel and / or equipment that need to be scheduled.
10. A computing device, characterized in that The computing device comprises: at least one processor, memory, and input-output unit; The memory is used to store a computer program, and the processor is used to call the computer program stored in the memory to execute the abnormal intrusion monitoring method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Smart door / window Anti-intrusion apparatus and system and smart access control system
WO2014139415A1
System and method for sequence labeling using hierarchical capsule based neural network
WO2020261234A1
Systems, methods, kits, and apparatuses for generative artificial intelligence, graphical neural networks, transformer models, and converging technology stacks in value chain networks
WO2024226801A2