Monitoring and early warning system and method based on intelligent door lock
By constructing a dynamic event graph network and a quantum superimposed weighting method, the intelligent door lock monitoring and early warning system can identify abnormal cooperative relationships between devices and generate multi-level early warning signals, solving the problem of insufficient identification of complex behavior patterns in the prior art, and improving the recognition accuracy and response speed.
Patent Information
- Application Number
- CN202510682862.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-08-12
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing smart door lock monitoring and early warning system cannot effectively identify abnormal behaviors in complex device collaboration modes, and lacks dynamic adjustments to the spatial and temporal correlation between devices, resulting in misjudgment and delayed responses.
Build a dynamic event graph network, collect intelligent device data through the Internet of Things gateway to generate event nodes and associated edges, combine quantum superposition weights and dynamic adjustment methods, identify abnormal cooperative relationships, and generate multi-level early warning signals.
It improves the recognition accuracy and response speed of complex behavior patterns, enhances the intelligence and real-time nature of security guarantees, and can accurately warn of potential safety hazards.
Smart Images

Figure CN120472640A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of intelligent security technology, and in particular to a monitoring and early warning system and method based on an intelligent door lock. Background Art
[0002] With the rapid development of the Internet of Things (IoT) and smart devices, smart door locks are becoming a mainstream trend. Smart door locks, when linked to smart devices, leverage wireless communication technology and sensors to enable remote control and monitoring, significantly improving security. Smart door locks not only enable remote unlocking but also record operation logs. In conjunction with other smart devices, such as cameras and sensors, they enhance real-time and precise security. In recent years, monitoring and early warning technologies based on smart door locks have become a research focus. Intelligent algorithms analyze device operation data to identify abnormal behavior and potential security threats.
[0003] However, existing technologies are often limited to monitoring systems based on single devices or simple rules. They lack in-depth analysis of device collaboration patterns and are unable to effectively identify complex abnormal behaviors. For example, device behavior prediction in existing technologies relies on traditional rule engines or static models, which cannot dynamically respond to complex collaborative relationships between devices or accurately provide early warnings based on historical user behavior patterns and real-time data. Furthermore, most existing methods ignore the spatiotemporal correlations between devices and the dynamic adjustment of behavioral changes, resulting in a high risk of misjudgment and delayed response for smart door lock systems when handling complex scenarios. Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides a monitoring and early warning method based on smart door locks to solve the problem of insufficient abnormal behavior detection and early warning capabilities of smart devices in the prior art.
[0006] In order to solve the above technical problems, the present invention provides the following technical solutions: In a first aspect, the present invention provides a monitoring and early warning method based on a smart door lock, which includes initializing a dynamic event graph network, generating event nodes and event-related edges based on real-time operation data of the smart door lock and smart devices, and establishing an event graph structure; Analyze the association patterns between event nodes based on the event graph structure, identify abnormal collaboration relationships and form a list of abnormal collaboration relationships; Combine the abnormal collaboration relationship list with the user's geographic location, time information, and behavior pattern to perform spatiotemporal correlation analysis on the current operation behavior and output a correlation score list; Match the user's historical behavior data in different scenarios with the associated score list to generate multi-level early warning signals; Link smart devices to perform alert operations based on multi-level warning signals; The dynamic event graph network is updated in real time based on the feedback data of the alert operation, and the weight configuration of event nodes and event-related edges is optimized.
[0007] As a preferred solution of the monitoring and early warning method based on the smart door lock of the present invention, wherein: the initialization of the dynamic event graph network, generating event nodes and event-related edges according to the real-time operation data of the smart door lock and the smart device, and establishing the event graph structure, the specific steps are as follows: Based on the IoT gateway, the smart device ID, event type, timestamp and status value in the smart device are collected through the wireless communication protocol as the basic attributes of the smart device; Define the basic attributes of smart devices as event nodes; The weighted association analysis method is used to extract time intervals, spatial associations, and interaction weights from the basic attributes of smart devices and define them as event association edges. Collect smart device operation data through the IoT gateway and store it in a time series database to dynamically update event nodes and event-related edges; Extract event node sets and event-related edge sets based on historical data in a time series database; For the event node set and the event associated edge set, weighted edge weights are used to quantify the association strength and establish an event graph structure.
[0008] As a preferred solution of the monitoring and early warning method based on the smart door lock of the present invention, wherein: the correlation pattern between event nodes is analyzed based on the event graph structure, abnormal collaboration relationships are identified and a list of abnormal collaboration relationships is formed. The specific steps are as follows: Defining the event graph structure , the expression is: ; in, Represents a set of event nodes in an event graph structure, Represents the set of associated edges in the event graph structure; Define each event node The initial quantum state is ;in, The index variable representing the event node; Defining incident edges The quantum superposition weight is ;in, An index variable representing the adjacent event node; The quantum initial state is calculated based on the basic attributes of each event node in the event graph. The expression is: ; in, Represents an event node The initial quantum state of represents the normalization factor, Represents an event node The total number of associated nodes, Represents an event node and the number of the adjacent event node, Represents an event node The average distance to the adjacent event nodes, Indicates the distance between the event node and the adjacent event node number, represents the deviation value of the adjacent node, Represents an event node The standard deviation of Represents an event node The basis vectors of the numbers of the adjacent event nodes in the quantum state space; Also follow the calculation event node The expression of the quantum initial state is used to further calculate the adjacent event nodes The quantum initial state ; Event-based nodes and adjacent event nodes The quantum initial state and , the quantum state difference metric is calculated by the Euclidean distance of the state ; Utilize the historical interaction records between event nodes and dynamically calculate the associated edges based on the time dependency relationship The quantum superposition weight of is expressed as: ; in, Represents an event node The quantum superposition weight between adjacent event nodes, Represents an event node The temporal and spatial distance between adjacent event nodes; Calculate the quantum superposition weight of the associated edge based on the time-dependent quantum random walk model The transfer probability dynamically adjusts the quantum superposition weight of the associated edge, and the expression is: ; ; in, Indicates time Lower associated edge The weight transfer probability, Indicates time The normalization factor under represents the time-integrated variable, represents an exponential decay function, represents the weight adjustment function based on the association strength value, Represents an event node The strength of the association with the adjacent event node, Indicates the time integral variable during the integration process Small increments of The adjusted quantum superposition weight is stored in the associated edge attribute to describe the dynamic characteristics of the associated edge; In the description process of dynamic characteristics, the high-correlation paths in the event graph are identified according to the weighted transfer probability to form a high-correlation path set; Adopt subgraph edge extraction method to extract related edges from high-related path sets ; Calculate each associated edge by weighted transfer probability difference The asymmetry of the relationship is considered as the initial basis for judging abnormal collaborative relationships; Based on the preliminary judgment basis of abnormal cooperative relationship, the asymmetric abnormal measurement is constructed by using quantum interference effect, and the expression is: ; in, Represents an event node The asymmetric anomaly metric between the adjacent event nodes, represents the number of potential collaboration paths between nodes in the event graph, Indicates the intermediate event node number in the collaboration path, represents the frequency factor of the sine function, Represents an event node Dynamic association weights between the intermediate event node numbers in the collaboration path, Indicates the dynamic association weight between the intermediate event node number and the adjacent event node in the collaboration path, represents the asymmetric magnification factor, represents the exponential adjustment function, Represents associated edges The asymmetry of the bidirectional weight transfer probability; Based on asymmetric anomaly metrics ,The abnormal collaboration relationship matrix is constructed through the threshold filtering method; Use graph clustering algorithms to analyze the abnormal collaboration relationship matrix and identify abnormal collaboration relationship clusters ; The weighted average method is used to identify abnormal collaborative relationship clusters. All associated edges Asymmetric anomaly measure of Find the mean and get the average asymmetric anomaly metric ; Abnormal collaboration cluster The time and space differences of all associated edges in the metric are weighted averaged and the spatiotemporal consistency value is output. ; Setting the threshold for spatiotemporal consistency metrics ; when When , it is determined to be an abnormal collaborative relationship cluster The time-space anomaly condition is satisfied, otherwise it is judged as not satisfying the time-space anomaly condition; All abnormal collaboration relationship clusters that meet the spatiotemporal abnormal conditions Organize into a list of abnormal collaborations, sort by severity and output a list of abnormal collaboration relationships , the expression is: .
[0009] As a preferred solution of the monitoring and early warning method based on smart door locks described in the present invention, the abnormal collaborative relationship list is combined with the user's geographical location, time information and behavior pattern, and the current operation behavior is analyzed in time and space to output a correlation score list. The specific steps are as follows: Record users’ geographic location and time information in real time through the logging function of IoT gateways and smart devices; Use frequency statistics to extract user interaction records between devices from the operation logs of smart devices and construct behavioral patterns; Based on the abnormal collaboration relationship list ,Using the user’s real-time geographic location and time information, the initial association weight is generated through an exponential decay function; Conduct time series analysis on behavior patterns to extract behavior feature vectors and abnormal collaborative behavior feature vectors; Calculate the behavioral similarity between the behavioral feature vector and the abnormal collaborative behavior feature vector; The initial association weight and behavioral similarity are integrated to calculate the association score through the weighted linear combination method; Normalize the abnormal collaboration relationships in the correlation score and append the normalized correlation score to the abnormal collaboration list , forming a list of associated scores.
[0010] As a preferred solution of the monitoring and early warning method based on the smart door lock of the present invention, the user's historical behavior data in different scenarios is matched with the associated score list to generate a multi-level early warning signal. The specific steps are as follows: Collect behavioral data from IoT gateways and smart devices in real time and integrate them into historical behavioral data through timestamps; Divide historical behavior data into scenarios and use the rule engine to extract the time, geographic, and device characteristics of each scenario; Combine time features, geographic features, and device features into a scene feature vector, and generate a scene feature library through cluster analysis; Use cosine similarity to calculate the similarity between each record in the association score list and the scene in the scene feature library, and match the corresponding historical scene for each record; Set up multi-level warning rules based on correlation scores, asymmetric anomaly metrics, and spatiotemporal consistency; Based on the historical scenarios matched by records and multi-level warning rules, a multi-level warning signal is generated including warning level, abnormal equipment, time and location.
[0011] As a preferred solution of the monitoring and early warning method based on the smart door lock of the present invention, wherein: the smart device is linked to perform the alert operation according to the multi-level early warning signal, the specific steps are as follows: Extract warning level, abnormal equipment, time and location from multi-level warning signals; Match corresponding alert response measures from multi-level alert rules based on the alert level, and execute alert operations through IoT gateway linkage devices; While executing alert operations, the system dynamically adjusts the alarm notification content based on abnormal equipment, time and location, and sends real-time alarm notifications to users; Update smart device status based on real-time alarm notifications and provide user control permissions through the app.
[0012] As a preferred solution of the monitoring and early warning method based on the smart door lock of the present invention, wherein: the dynamic event graph network is updated in real time based on the feedback data of the alert operation, and the weight configuration of the event nodes and event-related edges is optimized. The specific steps are as follows: Receive real-time feedback data on alert operations from the IoT gateway and standardize it into an event graph data format; Match the standardized feedback data with the event nodes and associated edges in the event graph structure, mark abnormal event nodes and associated edges, and record their update status; Adjust the basic attributes of the event node according to the update status, and dynamically update the quantum superposition weight of the event node based on the trigger frequency of the alert event and the response timeliness of the smart device; According to the interaction frequency between event nodes and the impact of feedback, the quantum superposition weights of the associated edges in the event graph structure are adjusted.
[0013] In a second aspect, the present invention provides a monitoring and early warning system based on a smart door lock, comprising an event graph module, an anomaly recognition module, a spatiotemporal association module, a history matching module, an early warning linkage module, and a weight optimization module; The event graph module is used to initialize a dynamic event graph network, generate event nodes and event-related edges based on the real-time operation data of smart door locks and smart devices, and establish an event graph structure; The anomaly identification module is used to analyze the association pattern between event nodes based on the event graph structure, identify abnormal collaboration relationships and form an abnormal collaboration relationship list; The spatiotemporal correlation module is used to combine the abnormal collaboration relationship list with the user's geographical location, time information and behavior pattern, perform spatiotemporal correlation analysis on the current operation behavior, and output a correlation score list; The history matching module is used to match the user's historical behavior data in different scenarios with the associated score list to generate a multi-level warning signal; The warning linkage module is used to link smart devices to perform warning operations according to multi-level warning signals; The weight optimization module is used to update the dynamic event graph network in real time based on the feedback data of the alert operation, and optimize the weight configuration of event nodes and event-related edges.
[0014] In a third aspect, the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program is executed by the processor, any step of the monitoring and early warning method based on the smart door lock as described in the first aspect of the present invention is implemented.
[0015] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, it implements any step of the monitoring and early warning method based on smart door locks as described in the first aspect of the present invention.
[0016] The beneficial effects of the present invention are as follows: by constructing a dynamic event graph network and combining it with a quantum computing model, the present invention can accurately identify abnormal collaborative relationships between smart door locks and smart devices, and generate multi-level warning signals based on spatiotemporal correlation analysis. In traditional technologies, smart door locks have limited ability to recognize complex behavioral patterns and are prone to false positives or missed reports. However, the present invention greatly improves recognition accuracy and response speed through a comprehensive analysis of the collaborative patterns between devices, user historical behaviors, and real-time locations. In particular, the use of quantum superposition weights and dynamic adjustment methods can optimize the structure of the event graph in real time, thereby effectively responding to dynamically changing environments, accurately identifying potential safety hazards, and accurately warning of abnormal behaviors. This not only improves adaptability to complex collaborative patterns, but also enables the execution of immediate safety precautions through the linkage control of smart devices, enhancing the intelligence and real-time nature of security protection, and greatly improving response efficiency and protection capabilities in emergency situations. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0018] Figure 1 This is a flow chart of the monitoring and early warning method based on the smart door lock in Example 1.
[0019] Figure 2 This is a module diagram of the monitoring and early warning system based on the smart door lock in Example 1. DETAILED DESCRIPTION
[0020] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0021] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0022] Secondly, the term "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in various places throughout this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive of other embodiments.
[0023] Example 1, with reference to Figure 1 and Figure 2 , which is the first embodiment of the present invention, provides a monitoring and early warning method based on a smart door lock, comprising the following steps: S1. Initialize the dynamic event graph network, generate event nodes and event-related edges based on the real-time operation data of smart door locks and smart devices, and establish an event graph structure.
[0024] Furthermore, based on the IoT gateway, the smart device ID, event type, timestamp, and status value in the smart device are collected through wireless communication protocols (such as Zigbee, Z-Wave, and Wi-Fi) as the basic attributes of the smart device; It should be noted that the smart device ID is a commonly used device identification method in the existing technology, generally provided by the device manufacturer, and is used to uniquely identify each smart device (such as the serial number of a smart door lock); event type is a common record item in existing smart devices, such as unlocking, turning on the device, and alarm triggering. These types are usually defined by the device firmware and provided through operation logs or status reports; timestamp is a core component of device data records, which is used to mark the specific time point when the event occurs. Almost all smart devices have this attribute; status value is a description of the current operating status of the smart device, such as the "unlocked / locked" status of a door lock and the "on / off" status of a light.
[0025] Define the basic attributes of smart devices as event nodes; Preferably, defining the basic attributes of smart devices as event nodes helps to structure and model the operational behaviors of smart devices, providing a clear node basis for the subsequent construction of event graphs, and thus supporting association analysis and dynamic updates.
[0026] The weighted association analysis method is used to extract time intervals, spatial associations, and interaction weights from the basic attributes of smart devices and define them as event association edges. Specifically, the basic attribute set of smart devices is obtained, including the identifier, operation type, occurrence time, and operating status of each smart device, to construct a time series data table of device operation records. For time intervals, each pair of event records is selected from the time series data table. By comparing their occurrence times, the time difference between the two events is calculated and stored as a temporary attribute to support subsequent association strength calculations. For spatial associations, the physical proximity between the two devices is determined using the device's installation location information (such as room division) or dynamic location information (such as location coordinates). Spatial association attributes are generated to describe the positional relationship between the devices. Next, based on the device's interaction history, the interaction frequency between each pair of devices is counted. At the same time, the overall interaction strength between the two devices is evaluated by combining the time interval and spatial association information. This strength is quantified as an interaction weight and used as the primary association attribute of the edge. Finally, the three attributes of time interval, spatial association, and interaction weight are integrated to define a complete description of the event association edge.
[0027] Collect smart device operation data through the IoT gateway and store it in a time series database to dynamically update event nodes and event-related edges; It should be noted that dynamic updating of event nodes and event-related edges can ensure that the event graph reflects the latest operating status and interaction relationships of smart devices in real time, improving timeliness and accuracy. At the same time, by dynamically adjusting node attributes and edge weights to adapt to changes in the environment and device behavior, it can avoid the interference of outdated data on analysis results, effectively optimize resource utilization, reduce computing costs, and provide support for anomaly detection and device linkage in IoT scenarios.
[0028] Extract event node sets and event-related edge sets based on historical data in a time series database; Specifically, based on the historical data in the time series database, the device operation records stored in the time series database are first queried according to the predefined node attribute format (device ID, event type, timestamp, status value), and each operation record is directly mapped to an event node; then, the time interval between adjacent nodes is calculated through the timestamp field, and the spatial association is calculated in combination with the spatial location information of the device. At the same time, the interaction weight is extracted according to the historical interaction frequency, and this information is integrated to generate event association edges; finally, all extracted event node sets and association edge sets are stored as the basic input of the graph structure, providing complete data support for the subsequent dynamic update and construction of the event graph.
[0029] For the event node set and the event associated edge set, weighted edge weights are used to quantify the association strength and establish an event graph structure.
[0030] S2. Analyze the association patterns between event nodes based on the event graph structure, identify abnormal collaboration relationships and form a list of abnormal collaboration relationships.
[0031] Going further, define the event graph structure , the expression is: ; in, Represents a set of event nodes in an event graph structure, Represents the set of associated edges in the event graph structure; It should be noted that the event graph structure By mapping the operation records of smart devices or smart door locks into a set of event nodes and the association relationships between nodes into a set of association edges, the interaction pattern between devices is effectively described, laying a data foundation for subsequent quantum state-based node characteristic analysis, association edge weight calculation, and abnormal collaborative relationship identification. The event nodes represent each operation event, and the association edges describe the association strength and interaction frequency between nodes through edge weights. This formal definition can not only accurately model the complex dynamic interactions between devices, but also reflect the time-varying association characteristics through the adjustment of the dynamic weights of the association edges, thereby providing necessary support for the subsequent time-dependent quantum random walk model to dynamically calculate the transfer probability of the association edge weight, and ultimately ensure that the identification of abnormal collaborative relationships is based on an accurate and complete data structure.
[0032] Define each event node The initial quantum state is ;in, The index variable representing the event node; It should be noted that defining the quantum initial state of each event node effectively quantifies the attributes of the event node and its correlation characteristics with adjacent nodes. This quantum state accurately describes the local characteristics of the node, providing a basis for subsequent dynamic weight adjustment based on the time-dependent random walk model. In the process of calculating the quantum initial state, key attributes such as the distance deviation, average distance, and standard deviation between the event node and adjacent nodes are embedded in the quantum state expression. This quantized description can fully reflect the local correlation characteristics of the node. Based on the quantum initial state, the dynamic weight of the associated edge can be more accurately calculated and adjusted, so that the characteristics of the edge can reflect the dynamic changes between nodes in real time. In this way, when subsequently identifying abnormal collaborative relationships, the complex correlation patterns between nodes can be more accurately captured, improving the recognition accuracy and spatiotemporal adaptability of the overall solution.
[0033] Defining incident edges The quantum superposition weight is ;in, An index variable representing the adjacent event node; It should be noted that by quantifying the strength of associations between event nodes, the collaborative relationships between nodes can be dynamically reflected. In subsequent steps, the quantum superposition weights of the associated edges serve as the basis for calculating the probability of transitions between the associated edge weights, enabling the associated edges to be adaptively adjusted based on historical interactions between nodes and spatiotemporal changes. The introduction of these quantum superposition weights not only imbues the associated edges with dynamic characteristics but also provides a precise basis for identifying highly correlated paths. Ultimately, by analyzing the asymmetry of the associated edges, anomalous collaborative relationships can be accurately identified, effectively improving the accuracy and reliability of the solution in anomaly detection.
[0034] The quantum initial state is calculated based on the basic attributes of each event node in the event graph. The expression is: ; in, Represents an event node The initial quantum state of represents the normalization factor, Represents an event node The total number of associated nodes, Represents an event node and the number of the adjacent event node, Represents an event node The average distance to the adjacent event nodes, Indicates the distance between the event node and the adjacent event node number, represents the deviation value of the adjacent node, Represents an event node The standard deviation of Represents an event node The basis vectors of the numbers of the adjacent event nodes in the quantum state space; It should be noted that the initial quantum state Describes the initial association characteristics of the event node, including the distance between the event node and the adjacent event node numbers , which is used for subsequent calculation of associated edges The quantum superposition weight of Provides basic data.
[0035] Also follow the calculation event node The expression of the quantum initial state is used to further calculate the adjacent event nodes The quantum initial state ; Event-based nodes and adjacent event nodes The quantum initial state and , the quantum state difference metric is calculated by the Euclidean distance of the state ; Utilize the historical interaction records between event nodes and dynamically calculate the associated edges based on the time dependency relationship The quantum superposition weight of is expressed as: ; in, Represents an event node The quantum superposition weight between adjacent event nodes, Represents an event node The temporal and spatial distance between adjacent event nodes; It should be noted that the time and space distance here Can be regarded as an event node The degree of correlation with the adjacent event node at a certain moment. The distance information of adjacent nodes is already included in The calculation of can be regarded as a measure of the degree of dynamic correlation based on the static distance information implicit in the initial quantum state and the characteristics of space-time evolution. It further reflects the dynamic differences between the two nodes during the evolution of the quantum state, so that the weight of the associated edge not only takes into account the static correlation of the nodes, but also can reflect the changing characteristics of the quantum state between the nodes in real time.
[0036] Specifically, in the quantum initial state In the calculation of It provides basic information for describing the initial association of nodes at static moments. In the dynamic evolution process, This correlation is further extended in the time dimension, so that the degree of correlation can reflect the temporal and spatial changes between nodes. At the same time, the quantum state difference measurement With the introduction of , combined with the time-varying interaction characteristics between nodes, the calculation of the associated edge weight can dynamically correct and supplement the initial associated information. Therefore, in the process of calculating the quantum superposition weight of the associated edge, the initial associated information (given by The weight of the associated edge can accurately describe the dynamic association characteristics between nodes that change over time and space.
[0037] Calculate the quantum superposition weight of the associated edge based on the time-dependent quantum random walk model The transfer probability dynamically adjusts the quantum superposition weight of the associated edge, and the expression is: ; ; in, Indicates time Lower associated edge The weight transfer probability, Indicates time The normalization factor under represents the time-integrated variable, represents an exponential decay function, represents the weight adjustment function based on the association strength value, Represents an event node The strength of the association with the adjacent event node, Indicates the time integral variable during the integration process Small increments of Preferably, the dynamic evolution mechanism of the time-dependent quantum random walk model can not only capture the time-varying correlation between event nodes, but also combine historical interaction records and real-time state changes to achieve an accurate description of the dynamic characteristics of the correlation edges.
[0038] Furthermore, in the existing technology, fixed weights or simple time weighting are mostly used to describe the node association relationship, which cannot dynamically reflect the real-time interaction characteristics between nodes, resulting in insufficient recognition accuracy when processing complex dynamic event graphs. However, this method introduces the quantum random walk model, utilizes its natural time evolution ability and quantum superposition state characteristics, and realizes adaptive modeling of the dynamic characteristics of the association edge, ensuring that the node association changes can be accurately reflected at different time points, thereby improving the recognition accuracy of highly correlated paths and the judgment effect of abnormal collaborative relationships.
[0039] The adjusted quantum superposition weight is stored in the associated edge attribute to describe the dynamic characteristics of the associated edge; Specifically, the dynamic characteristics of the associated edges are represented by changes in quantum superposition weights. As the interaction data between event nodes is continuously updated and time passes, the quantum superposition weights of the associated edges are dynamically adjusted to reflect the real-time state of the strength of the association between the nodes. The dynamic updates of the quantum superposition weights not only describe the current characteristics of the associated edges but can also be used to further calculate the probability of weight transitions at different points in time, thus providing a basis for identifying highly correlated paths.
[0040] In the description process of dynamic characteristics, the high-correlation paths in the event graph are identified according to the weighted transfer probability to form a high-correlation path set; Specifically, during the dynamic characterization process, the weighted transition probability of each associated edge is combined to identify highly correlated paths in the event graph. First, all possible paths between nodes are traversed and the cumulative weight of each path is calculated. The cumulative weight is the product of the weights of all associated edges in the path. The cumulative results for different paths are then summed to obtain the total correlation strength between the nodes.
[0041] Furthermore, after calculating the cumulative weights, the total correlation strength between nodes is sorted by size. A predefined weight threshold is set to filter out paths with a total correlation strength exceeding this threshold. These filtered paths are considered highly correlated, indicating their importance in the event graph. Finally, all highly correlated paths are aggregated to form a highly correlated path set, which provides a basis for subsequent analysis of abnormal collaborative relationships. This method dynamically calculates path correlation using weighted transition probabilities, ensuring the real-time and accurate identification of highly correlated paths.
[0042] Adopt subgraph edge extraction method to extract related edges from high-related path sets ; Specifically, each path in the highly correlated path set is parsed. Each path consists of a series of sequentially connected event nodes. Next, each pair of adjacent event nodes is identified from the path, and the associated edges between these nodes are extracted. Subsequently, the associated edges extracted from all paths are deduplicated, ensuring that only one copy of each associated edge is retained, thereby constructing a subgraph edge set. Finally, the extracted subgraph edge set is used for subsequent asymmetry calculations and identification of unusual collaborative relationships. This process significantly reduces the redundancy of associated edges by precisely screening the key associated edges in highly correlated paths, focusing on truly important edges and improving the accuracy and efficiency of unusual collaborative relationship identification. It also avoids the additional computational overhead of a global search across the entire event graph, making the overall solution more targeted and computationally performant.
[0043] Calculate each associated edge by weighted transfer probability difference The asymmetry of the relationship is considered as the initial basis for judging abnormal collaborative relationships; It should be noted that calculating the difference in weighted transfer probabilities of associated edges effectively measures whether there is significant asymmetry in the collaboration between two event nodes. This asymmetry is often a key characteristic of abnormal collaboration. Therefore, using this as a preliminary basis for judgment can quickly screen out potentially abnormal associated edges, reducing the burden of subsequent complex calculations and improving the efficiency of the overall solution. Furthermore, through this preliminary screening, resources can be concentrated on further analyzing the selected high-risk associated edges, improving the accuracy and response speed of anomaly detection, thereby playing a key role in promoting the identification of overall abnormal collaboration relationships and making the final output of the abnormal collaboration list more accurate and reliable.
[0044] Based on the preliminary judgment basis of abnormal cooperative relationship, the asymmetric abnormal measurement is constructed by using quantum interference effect, and the expression is: ; in, Represents an event node The asymmetric anomaly metric between the adjacent event nodes, represents the number of potential collaboration paths between nodes in the event graph, Indicates the intermediate event node number in the collaboration path, represents the frequency factor of the sine function, Represents an event node Dynamic association weights between the intermediate event node numbers in the collaboration path, Indicates the dynamic association weight between the intermediate event node number and the adjacent event node in the collaboration path, represents the asymmetric magnification factor, represents the exponential adjustment function, Represents associated edges The asymmetry of the bidirectional weight transfer probability; It should be noted that potential collaboration paths refer to paths where interactions or collaborations may occur in the event graph structure, and these paths of interactions or collaborations are formed by connecting a series of event nodes. Specifically, potential collaboration paths refer to potential collaboration or dependency paths formed between a set of event nodes through the connection of associated edges. Although they do not necessarily exhibit actual collaborative behavior at the beginning, they exist in the structure of the event graph and may become active due to specific abnormal behaviors or conditions. Furthermore, in the section “Analyzing the association pattern between event nodes based on the event graph structure”, it is mentioned that the difference measurement of quantum states (such as quantum state difference measurement) can be used to analyze the association pattern between event nodes. ) and weighted edge analysis to identify unusual collaborative relationships, which may be manifested through potential collaborative paths. When two event nodes have a high correlation (weight) and are connected by other nodes or edges, they may form a potential collaborative path, which becomes the subject of further analysis.
[0045] It should also be noted that collaborative paths refer to confirmed paths of collaboration or interaction within an event graph, reflecting the actual cooperation or dependency between nodes. The nodes and edges within these collaborative paths demonstrate the actual interdependence and collaboration, often driven by historical data, behavioral patterns, or other temporal and spatial characteristics. Furthermore, the section "Based on Quantum Superposition Weights in Event Graphs" mentions that by analyzing historical interaction records between event nodes and combining quantum computing methods to calculate the weight transfer probability of each associated edge, it is possible to identify collaborative paths that exhibit anomalous collaborative behavior. The weight changes in these collaborative paths can then be used as a basis for determining whether the node collaboration is anomalous. Graph clustering and other algorithms can be used to extract actual collaborative paths from potential collaborative paths.
[0046] The preferred approach, based on the initial basis for determining abnormal collaborative relationships, is to construct an asymmetric anomaly metric by introducing the quantum interference effect, enabling more accurate identification of abnormal interaction patterns between nodes. Traditional methods rely solely on correlation strength or transition probability, which can easily overlook the underlying complex connections between nodes. However, the quantum interference effect can capture the implicit nonlinear relationships between multiple nodes by superimposing the influence of different paths, further amplifying anomaly signals and effectively detecting even weakly correlated anomalies.
[0047] Specifically, when constructing an asymmetric anomaly metric, the weight differences of bidirectional interactions between associated edges are considered, combined with the multipath interference effect between nodes to calculate a final asymmetric metric value, thereby quantifying the degree of anomaly. This asymmetric metric serves as an important indicator for subsequent screening of anomalous collaborative relationship clusters. It can significantly improve the accuracy and comprehensiveness of identification, avoid missing key anomaly patterns, and provide a more accurate data foundation for spatiotemporal consistency analysis, helping the overall solution achieve greater robustness and adaptability in complex scenarios.
[0048] Based on asymmetric anomaly metrics ,The abnormal collaboration relationship matrix is constructed through the threshold filtering method; Specifically, based on the asymmetric anomaly metric, a threshold is first set to determine whether the association between two nodes is abnormal. Subsequently, all associations between nodes are traversed, and the association metric values of each pair of nodes are compared. If the association metric exceeds the set threshold, the association is considered a potential abnormal collaboration and retained. Otherwise, it is filtered out. Ultimately, a relationship matrix containing only potential abnormal collaborations is constructed, providing a basis for subsequent anomaly analysis.
[0049] Use graph clustering algorithms to analyze the abnormal collaboration relationship matrix and identify abnormal collaboration relationship clusters ; Specifically, a graph clustering algorithm is used to analyze the abnormal collaboration relationship matrix. First, the abnormal collaboration relationship matrix is preprocessed to remove isolated points and noise in the matrix to ensure the quality of the input data. Then, the processed matrix is decomposed into eigenvalues, and the main eigenvectors are extracted to form a feature space. Each abnormal collaboration relationship is mapped to the feature space. Then, a clustering algorithm is applied in the feature space to divide the clusters by calculating the similarity between data points, and the optimal number of clusters is selected to ensure the accuracy of the clustering effect. Finally, multiple abnormal collaboration relationship clusters are identified based on the clustering results. Each cluster contains highly correlated abnormal collaboration relationships, thereby completing the identification of the abnormal collaboration relationship cluster U.
[0050] The weighted average method is used to identify abnormal collaborative relationship clusters. All associated edges Asymmetric anomaly measure of Find the mean and get the average asymmetric anomaly metric ; Specifically, when processing all associated edges in an abnormal collaborative relationship cluster, all associated edges in the cluster and their corresponding asymmetric anomaly metrics are first extracted, and then these asymmetric anomaly metrics are weighted, where the weights can be set according to the time or space characteristics between the associated edges to reflect the importance of the edges. The weighted anomaly metrics are accumulated and summed, and then divided by the sum of all weights to obtain the average asymmetric anomaly metric value of the cluster. This value can comprehensively measure the overall abnormality level in the cluster and serve as an important indicator for subsequent judgment.
[0051] Abnormal collaboration cluster The time and space differences of all associated edges in the metric are weighted averaged and the spatiotemporal consistency value is output. ; It should be noted that time difference refers to the difference between the timestamps of two event nodes, which can be measured by calculating the difference in timestamps. For example, a large difference in the timestamps of two operation events indicates that they occurred a long time apart, which may reflect inconsistent behavior or different user behavior patterns.
[0052] Spatial difference: This refers to the physical distance between two event nodes, or the difference in the devices or regions where they occur. For example, two event nodes may occur in different rooms, which involves spatial difference. Spatial difference can be represented by the geographic location of the device ID or calculated based on the device's coordinate system.
[0053] Setting the threshold for spatiotemporal consistency metrics ; It should be noted that setting a threshold for spatiotemporal consistency metrics can be based on historical data statistics. This involves collecting spatiotemporal consistency metrics for a large number of normal collaboration clusters, calculating their average and standard deviation, and then selecting an appropriate deviation range as the threshold. Specifically, the spatiotemporal consistency metrics are first calculated for each normal collaboration cluster to obtain a set of sample data. The average and standard deviation of this sample data are then calculated. The average represents the central level of normal collaboration, and the standard deviation reflects the degree of fluctuation within the normal range. Finally, the threshold is set to the average plus a certain multiple of the standard deviation. This multiple can be determined based on the tolerance of the actual application scenario. For example, 1.5 times the standard deviation can be used to identify abnormal collaboration clusters with moderate deviations, or 2 times the standard deviation can be used to identify abnormal collaboration clusters with significant deviations. This allows the set threshold to filter out normal collaborations while effectively identifying potential abnormal collaborations.
[0054] when When , it is determined to be an abnormal collaborative relationship cluster The time-space anomaly condition is satisfied, otherwise it is judged as not satisfying the time-space anomaly condition; It should be noted that spatiotemporal anomalies specifically refer to the fact that the temporal and spatial distribution characteristics of event nodes in the abnormal collaborative relationship cluster deviate significantly from the normal collaborative pattern, that is, the occurrence time intervals of these event nodes are short or the location distribution is concentrated, forming an abnormal spatiotemporal aggregation phenomenon.
[0055] Furthermore, in order to judge spatiotemporal anomalies, we first need to calculate the time difference and spatial distance between all event nodes in each abnormal collaborative relationship cluster, and perform weighted average of these time and spatial differences to obtain a comprehensive spatiotemporal consistency measurement value, which reflects the degree of spatiotemporal aggregation of events within the cluster; then, the calculated spatiotemporal consistency measurement value is compared with the preset threshold. When it is less than the threshold, it means that the spatiotemporal distribution of the abnormal collaborative relationship cluster is significantly abnormal, and it is therefore judged as a spatiotemporal anomaly; otherwise, it is deemed that the spatiotemporal anomaly conditions are not met.
[0056] All abnormal collaboration relationship clusters that meet the spatiotemporal abnormal conditions Organize into a list of abnormal collaborations, sort by severity and output a list of abnormal collaboration relationships , the expression is: .
[0057] It should be noted that the list of abnormal collaboration relationships, L, is directly derived from the abnormal collaboration relationships identified in the previous step. Its construction process is based on the event graph. By analyzing the correlation patterns between event nodes, collaboration relationships with asymmetric abnormal characteristics are identified and further screened based on spatiotemporal consistency. Specifically, quantum states and dynamic weights are first used to calculate the anomaly metric of the associated edges, identifying potential abnormal collaboration relationships. These potential abnormal collaboration relationships are then grouped using a graph clustering algorithm to form clusters of abnormal collaboration relationships. Next, the average anomaly metric and spatiotemporal consistency are calculated for each cluster. A threshold for the spatiotemporal consistency metric is set to screen clusters that meet the spatiotemporal anomaly criteria. Finally, these screening results are organized into a list, L, and sorted by severity. This list, closely linked to the abnormal collaboration relationships in the previous step, further screens and organizes the initial identification results. This step not only effectively improves the accuracy of abnormal collaboration relationship identification but also allows for the classification and quantification of complex correlation patterns, providing more precise decision-making for subsequent security policies and significantly improving the reliability and practicality of the overall solution.
[0058] S3. Combine the abnormal collaboration relationship list with the user's geographic location, time information, and behavior pattern, perform spatiotemporal correlation analysis on the current operation behavior, and output a correlation score list.
[0059] Furthermore, the user's geographic location and time information can be recorded in real time through the logging function of IoT gateways and smart devices; Specifically, a communication connection is established between the IoT gateway and the smart device. The gateway regularly polls the status data of each smart device and uses the built-in sensors of the device (such as GPS module or Wi-Fi positioning module) to obtain the real-time geographic location. At the same time, the smart device records the specific time of the operation through the embedded timestamp function every time the status changes or interaction events occur. The gateway integrates the collected geographic location data with the timestamp information, associates it with the user identity through the device identifier, and generates a log record containing geographic location, time information and user operation information.
[0060] Use frequency statistics to extract user interaction records between devices from the operation logs of smart devices and construct behavioral patterns; Specifically, by collecting the original data in the operation logs of smart devices, including information such as operation time, operation type and device identification, all log records are grouped by device identification, and the operation frequency, time period distribution and operation type proportion of each device are counted; further combined with the time dimension, the operation frequency of each device is analyzed in time series, and the usage peaks and troughs within a specific time period are extracted; then the analysis results are combined with user behavior characteristics, and the device operation modes are clustered to extract the interaction patterns between users and each device, and finally a behavior pattern that includes device usage frequency, operation habits and time period characteristics is constructed, laying the foundation for subsequent behavior analysis and anomaly detection.
[0061] Frequency statistics are a preferred method for extracting user interaction records from smart device operation logs, accurately capturing the behavioral patterns of users in their daily lives. By constructing behavioral patterns, it is possible to identify users' frequently used devices, usage preferences, and operation frequency, providing a basis for automated device control and personalized recommendations, thereby enhancing the user experience.
[0062] Based on the abnormal collaboration relationship list ,Using the user’s real-time geographic location and time information, the initial association weight is generated through an exponential decay function; Specifically, extract the list of abnormal collaboration relationships The device node information corresponding to each abnormal collaborative relationship is collected and associated with the user's current real-time geographic location and time information; then, the spatiotemporal distance parameters of each collaborative relationship are calculated by analyzing the physical distance and interaction time interval between the user and each device node; then, the spatiotemporal distance parameters are input into a preset exponential decay function model, and the association weight is dynamically decayed according to the increasing time interval or the expansion of the geographical distance to generate the initial association weight of each abnormal collaborative relationship; finally, the generated initial association weight is re-annotated into the abnormal collaborative relationship list L to provide basic data support for subsequent behavioral pattern analysis and comprehensive scoring.
[0063] Conduct time series analysis on behavior patterns to extract behavior feature vectors and abnormal collaborative behavior feature vectors; Calculate the behavioral similarity between the behavioral feature vector and the abnormal collaborative behavior feature vector; Specifically, cosine similarity is used as the similarity measurement indicator. The user's behavioral feature vector and the abnormal collaborative behavior feature vector are normalized into unit vectors to eliminate the difference in feature dimensions. Then, the dot product between the two vectors is calculated to measure their directional consistency. Next, the dot product result is normalized and mapped to the range of [0,1] to enhance the interpretability of the similarity score. Finally, according to the set similarity threshold, the similarity score is judged to reflect the degree of consistency between the user behavior and the abnormal collaborative behavior, thereby achieving accurate analysis and judgment.
[0064] Optimally, by extracting behavioral feature vectors and abnormal collaborative behavior feature vectors and calculating their behavioral similarity, we can accurately identify the similarity between user behavior and potential abnormal behavior. This process effectively reveals abnormal user behavior or abnormal device operation patterns, allowing for early risk assessment and alerting, improving the security and stability of monitoring and early warning.
[0065] The initial association weight and behavioral similarity are integrated to calculate the association score through the weighted linear combination method; Normalize the abnormal collaboration relationships in the correlation score and append the normalized correlation score to the abnormal collaboration list , forming a list of associated scores.
[0066] It should be noted that by normalizing the abnormal collaborative relationships in the association score, data of different scoring dimensions and magnitudes can be converted into a unified scale, thereby eliminating the impact of differences in scoring ranges and ensuring that the scores between different abnormal collaborative relationships are comparable; the scoring results after normalization can more intuitively reflect the severity of each abnormal collaborative relationship, making the score ranking more accurate; then the normalized association score is appended to the abnormal collaboration list L, which can further improve the list information, associate each abnormal collaborative relationship with its corresponding score one-to-one, and form an intuitive and unified association score list, which provides a scientific basis for subsequent risk assessment, priority sorting and automated processing, thereby improving the reliability and efficiency of the overall solution in anomaly detection and decision support.
[0067] S4. Match the user's historical behavior data in different scenarios with the associated score list to generate multi-level warning signals.
[0068] Furthermore, behavioral data from IoT gateways and smart devices are collected in real time and integrated into historical behavioral data through timestamps; Specifically, the IoT gateway connects various smart devices in real time and continuously collects device operational information, including behavioral data such as device startup and shutdown, status changes, and data transmission. Each time a device performs an operation, a precise timestamp is recorded for each action. The device's status, operation type, location, and other relevant information are also synchronized. All collected behavioral data is then consolidated using timestamps, ensuring that each record accurately reflects the device's behavior at a specific point in time. This consolidated data forms a time series, comprising comprehensive historical behavioral data, providing the foundational data for subsequent analysis and prediction.
[0069] Divide historical behavior data into scenarios and use the rule engine to extract the time, geographic, and device characteristics of each scenario; It should be noted that a rules engine is an automated decision-making system that analyzes and processes input data based on pre-defined rules (such as time, location, and device status). The rules engine can help extract key characteristics from the data, such as time, location, and device characteristics.
[0070] Combine time features, geographic features, and device features into a scene feature vector, and generate a scene feature library through cluster analysis; Use cosine similarity to calculate the similarity between each record in the association score list and the scene in the scene feature library, and match the corresponding historical scene for each record; It should be noted that cosine similarity is a mathematical method that measures the similarity between two vectors. It evaluates their similarity by calculating the cosine of the angle between the two vectors. Specifically, cosine similarity is used to calculate the similarity between historical behavior records and a scene feature library, thereby helping to match the most relevant historical scenes.
[0071] Set up multi-level warning rules based on correlation scores, asymmetric anomaly metrics, and spatiotemporal consistency; Specifically, a relevance score is calculated for each record to assess its similarity to historical scenarios. A higher score indicates more conventional behavior, while a lower similarity indicates a possible anomaly. Next, an asymmetric anomaly metric is calculated to further identify records whose behavior deviates from conventional patterns. This asymmetric metric accurately reflects the degree of asymmetry, leading to more sensitive anomaly detection. Finally, spatiotemporal consistency analysis is combined to ensure temporal and spatial consistency, further eliminating anomalies that are inconsistent in time and space, ensuring more accurate warnings. By combining these three elements and setting different thresholds, different warning levels can be defined: a high-level warning is triggered when the relevance score is low, the anomaly metric is high, and spatiotemporal consistency is poor; conversely, a lower-level warning is triggered, ensuring a response appropriate to the severity of the anomaly.
[0072] For example, three alert levels are set: low, medium, and high. If a behavior record's correlation score is less than 0.3, its asymmetric anomaly metric exceeds 0.7, and its temporal and spatial consistency is poor (e.g., the time or location range deviates significantly from normal behavior), a "high" alert is triggered, indicating that the behavior is highly likely anomalous or malicious and requires immediate response. If the correlation score is between 0.3 and 0.6, the anomaly metric is between 0.4 and 0.7, and there is a slight deviation in temporal and spatial consistency, a "medium" alert is triggered, indicating that the behavior may be due to device failure or user error, and a moderate response is appropriate. If the correlation score is greater than 0.6, the anomaly metric is low, and temporal and spatial consistency is good, a "low" alert is triggered, indicating that the behavior is a normal operating pattern and does not require extensive intervention. This set of alert rules effectively distinguishes different levels of anomalies, ensuring that responses are tailored to the severity of the anomaly.
[0073] Ideally, setting up multi-level warning rules based on correlation scores, asymmetric anomaly metrics, and spatiotemporal consistency can help adjust response strategies in a timely manner according to the severity of anomalies. This not only improves the sensitivity of anomaly detection, but also reduces false positives and missed negatives, ensuring that monitoring and warnings can operate accurately in various scenarios.
[0074] Based on the historical scenarios matched by records and multi-level warning rules, a multi-level warning signal is generated including warning level, abnormal equipment, time and location.
[0075] It should be noted that the historical scenario corresponding to the current record is determined based on the similarity between the historical behavior record and the scenario feature library. Next, according to the preset multi-level warning rules, based on factors such as correlation score, anomaly measurement, and spatiotemporal consistency, the behavior of each historical scenario is detected for anomalies and classified into different warning levels according to the degree of anomaly. Specifically, if the record has a high degree of similarity with the historical scenario and there is obvious abnormal behavior, a high-level warning will be triggered, otherwise a low-level warning will be triggered. Finally, the warning signal is combined with the time and location information of the abnormal device to generate a complete multi-level warning signal, including the specific warning level, the affected abnormal device, and the time and location of the occurrence. In this process, the division of warning levels is based on the analysis results of multiple dimensions to ensure that the warning signal can accurately reflect the abnormal status of the equipment and the possible risks it may bring.
[0076] Ideally, by generating multi-level warning signals, different levels of response can be provided based on the historical scenarios matched by the records and different warning rules. This approach can help users take appropriate measures in a timely manner, effectively preventing potential security threats or equipment failures, and improving the safety and reliability of smart door locks.
[0077] S5. Link smart devices to perform warning operations based on multi-level warning signals.
[0078] Furthermore, the warning level, abnormal equipment, time and location are extracted from the multi-level warning signals; Match corresponding alert response measures from multi-level alert rules based on the alert level, and execute alert operations through IoT gateway linkage devices; Specifically, the system first matches the alert response measures corresponding to the current event level. Appropriate response strategies are selected based on the different alert levels. For example, when the alert level is high, security measures such as whole-house monitoring and locking doors and windows are activated. When the alert level is medium, local devices such as alarms or flashing lights are activated. Subsequently, through the IoT gateway, relevant smart devices are linked to execute alert operations. Specifically, commands are sent to each device, such as unlocking or locking commands for smart door locks, starting recording commands for cameras, and flashing commands for smart lights, to ensure that the devices can automatically respond and link to ensure safety.
[0079] For example, if an unauthorized unlocking of a smart door lock occurs at night, the event is identified as a high-risk alarm based on the pre-set multi-level warning rules. In this case, the corresponding emergency response measures are automatically executed, activating security devices such as whole-house video surveillance, audible and visual alarms, and door and window locking devices. Through the IoT gateway, a command is sent to the smart door lock, instantly locking it, activating the alarm, starting the camera to record, and sending a real-time alert notification to the user's mobile app. This series of automated measures ensures that high-risk incidents are handled swiftly while ensuring safety.
[0080] Preferably, by selecting appropriate alert response measures based on the warning level, the response method can be automatically adjusted according to the degree of threat to avoid overreaction or underreaction.
[0081] While executing alert operations, the system dynamically adjusts the alarm notification content based on abnormal equipment, time and location, and sends real-time alarm notifications to users; It should be noted that when executing alert operations, the urgency and relevance of the alert are first analyzed based on the abnormal device detected (such as abnormal status of door and window sensors, cameras, or smart locks) and the time and location (such as late at night, holidays, or unusual behavior within a specific geographic area). Specifically, the alert notification content is adjusted based on the time and location information.
[0082] For example, at night, notifications can be reduced in volume or simplified to minimize interruptions. Alternatively, in specific areas, more pronounced alerts can be triggered based on actual conditions. Furthermore, based on the specific circumstances of the abnormal device, notifications can be supplemented with detailed information about the faulty or intruding device. These adjusted alert notifications are promptly pushed to users via the IoT gateway, ensuring rapid communication of current security risks and appropriate countermeasures.
[0083] Update smart device status based on real-time alarm notifications and provide user control permissions through the app.
[0084] Preferably, the device status is updated based on real-time alarm notifications, and the user is provided with the function of controlling permissions through the APP, so that the user can obtain real-time information about the device at the first time and make adjustments according to actual needs.
[0085] S6. Update the dynamic event graph network in real time based on the feedback data of the alert operation, and optimize the weight configuration of event nodes and event-related edges.
[0086] Furthermore, feedback data of alert operations is received from the IoT gateway in real time and standardized into an event graph data format; Specifically, the system communicates with IoT devices through interfaces to acquire raw data transmitted by the devices, including detailed information such as device status changes, operation timestamps, and triggered alarm types. Next, the system parses the received raw data to extract key event information, such as device ID, alert type, operation timestamp, and device-related environmental data (e.g., temperature, humidity, and location). Predefined data conversion rules are then used to convert the raw data into a structured event graph. Each event node represents an independent alert event or device status change, and edges represent relationships between events, such as interactions between devices or the order of state changes. During this process, events are sorted using timestamps to ensure accurate representation of temporal dependencies between events. Related event nodes are linked using device IDs, enabling the event graph to accurately reflect the interaction patterns and behavioral patterns between devices. Finally, the standardized event data is converted into a compliant event graph format, providing effective data support for subsequent anomaly analysis and risk warning.
[0087] Match the standardized feedback data with the event nodes and associated edges in the event graph structure, mark abnormal event nodes and associated edges, and record their update status; Specifically, based on key parameters in the feedback data (such as timestamp, device ID, and feedback status), the corresponding event nodes and associated edges are identified. By comparing real-time feedback with historical event characteristics, event nodes and their associated edges that exhibit abnormal behavior are marked, and the updated status of these events and associated edges is recorded to provide data support for subsequent processing.
[0088] Adjust the basic attributes of the event node according to the update status, and dynamically update the quantum superposition weight of the event node based on the trigger frequency of the alert event and the response timeliness of the smart device; Specifically, based on the update status, the basic attributes of the event node are first adjusted. By analyzing real-time feedback and historical data, the basic information of the event node, such as device type, working status, and interaction records, is corrected to ensure the accuracy of the node attributes. Subsequently, the quantum superposition weight of the event node is dynamically updated based on the triggering frequency of the alert event and the timeliness of the smart device response. Furthermore, when an event node frequently triggers alerts or responses, the weight of the node will increase, reflecting its importance in the event graph; conversely, if the device response is delayed or the triggering frequency is low, the node weight will decrease. This dynamic adjustment mechanism ensures that the quantum superposition weight can reflect the activity and influence of the device in the current situation in real time, thereby optimizing the accuracy and responsiveness of the entire event graph structure.
[0089] It should be noted that the trigger frequency of alert events is determined by monitoring and analyzing historical and real-time data. First, the behavioral data of each smart device, including the alert events it triggers, is recorded in real time. For each event node, the number of times the node triggers an alert event within a certain time window is calculated. The frequency of these trigger events is collected through the IoT gateway. Whenever the device status changes or an anomaly is detected, an alert event is triggered and the trigger frequency is updated. By accumulating and statistically analyzing these trigger event data, we can determine how frequently devices trigger alert events, providing a basis for subsequent adjustments to the quantum superposition weight.
[0090] It should also be noted that the response timeliness of smart devices is calculated by recording the time it takes for a device to respond from the time an alert event is triggered. Each time an alert event is triggered, the device's response time is monitored in real time, and the time difference from the alert event triggering to the device's completion of the response is calculated. This response timeliness data reflects the device's responsiveness and efficiency. The response timeliness calculation not only considers the device's own performance but also external environmental factors such as network latency and device load. This timeliness data is continuously updated to assess the device's real-time responsiveness and incorporate it into the dynamically adjusted weighting calculation.
[0091] Optimally, by analyzing the update status of event nodes, the basic attributes of event nodes (such as time and device status) are further adjusted to ensure that the attributes of nodes in the event graph reflect changes in the current environment in real time. Furthermore, based on the frequent triggering of alert events and the timeliness of smart device responses, the quantum superposition weights of event nodes are dynamically adjusted. This adjustment process enhances flexibility and adaptability, allowing the IoT environment to optimize alert responses based on actual conditions, thereby enhancing security.
[0092] According to the interaction frequency between event nodes and the impact of feedback, the quantum superposition weights of the associated edges in the event graph structure are adjusted.
[0093] Specifically, the interaction frequency of each associated edge is first calculated. This frequency reflects the frequency of interactions between event nodes within a specific time period. Next, the interaction strength between event nodes is analyzed by combining the impact of feedback following each interaction. By quantifying the impact of feedback, interactions with greater influence are assigned higher weights. Finally, based on a comprehensive analysis of interaction frequency and feedback impact, the quantum superposition weights of associated edges are dynamically adjusted to ensure that the weights of associated edges in the event graph accurately reflect the actual interaction strength between event nodes, thereby optimizing the event graph structure and improving its accuracy in predicting future events and its early warning capabilities.
[0094] Optimally, by analyzing the frequency of interactions and the impact of feedback between event nodes, the weights of the associated edges in the event graph can be further adjusted. Dynamically adjusting weights reflects the changing correlations between different events, allowing the event graph to more accurately depict the actual patterns of event occurrence and correlation. This optimization process can effectively identify and predict potential risks, enhancing early warning capabilities and responsiveness, especially in complex IoT environments.
[0095] This embodiment also provides a monitoring and early warning system based on smart door locks, including: an event graph module, an anomaly recognition module, a spatiotemporal association module, a history matching module, an early warning linkage module and a weight optimization module; the event graph module is used to initialize the dynamic event graph network, generate event nodes and event association edges according to the real-time operation data of the smart door lock and the smart device, and establish an event graph structure; the anomaly recognition module is used to analyze the association pattern between event nodes based on the event graph structure, identify abnormal collaboration relationships and form an abnormal collaboration relationship list; the spatiotemporal association module is used to combine the abnormal collaboration relationship list with the user's geographic location, time information and behavior pattern, perform spatiotemporal association analysis on the current operation behavior, and output a correlation score list; the history matching module is used to match the user's historical behavior data in different scenarios with the correlation score list to generate a multi-level early warning signal; the early warning linkage module is used to link the smart device to perform an alert operation according to the multi-level early warning signal; the weight optimization module is used to update the dynamic event graph network in real time according to the feedback data of the alert operation, and optimize the weight configuration of the event nodes and event association edges.
[0096] This embodiment also provides a computer device, which is suitable for the monitoring and early warning method based on smart door locks, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute computer-executable instructions to implement the monitoring and early warning method based on smart door locks proposed in the above embodiment.
[0097] The computer device may be a terminal, comprising a processor, memory, a communication interface, a display, and an input device connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores an operating system and computer programs. The internal memory provides an environment for the operating system and computer programs stored in the non-volatile storage media. The communication interface of the computer device is used to communicate with external terminals via wired or wireless communication. Wireless communication may be achieved via Wi-Fi, a carrier network, NFC (near-field communication), or other technologies. The display of the computer device may be a liquid crystal display or an electronic ink display. The input device may be a touchscreen overlay on the display, buttons, a trackball, or a touchpad on the computer device housing, or an external keyboard, touchpad, or mouse.
[0098] This embodiment also provides a storage medium having a computer program stored thereon, which, when executed by a processor, implements the monitoring and early warning method based on the smart door lock proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0099] In summary, by constructing a dynamic event graph network and combining it with a quantum computing model, the present invention can accurately identify abnormal collaborative relationships between smart door locks and smart devices, and generate multi-level warning signals based on spatiotemporal correlation analysis. In traditional technologies, smart door locks have limited ability to recognize complex behavioral patterns and are prone to false positives or missed reports. However, the present invention greatly improves recognition accuracy and response speed through a comprehensive analysis of the collaborative patterns between devices, user historical behaviors, and real-time locations. In particular, the use of quantum superposition weights and dynamic adjustment methods can optimize the structure of the event graph in real time, thereby effectively responding to dynamically changing environments, accurately identifying potential safety hazards, and accurately warning of abnormal behaviors. This not only improves adaptability to complex collaborative patterns, but also enables the execution of immediate safety precautions through the linkage control of smart devices, enhancing the intelligence and real-time nature of security protection, and greatly improving response efficiency and protection capabilities in emergency situations.
[0100] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. A monitoring and early warning method based on smart door locks, characterized by: include, Initialize the dynamic event graph network, generate event nodes and event-related edges based on the real-time operation data of smart door locks and smart devices, and establish the event graph structure; Analyze the association patterns between event nodes based on the event graph structure, identify abnormal collaboration relationships and form a list of abnormal collaboration relationships; Combine the abnormal collaboration relationship list with the user's geographic location, time information, and behavior pattern to perform spatiotemporal correlation analysis on the current operation behavior and output a correlation score list; Match the user's historical behavior data in different scenarios with the associated score list to generate multi-level early warning signals; Link smart devices to perform alert operations based on multi-level warning signals; The dynamic event graph network is updated in real time based on the feedback data of the alert operation, and the weight configuration of event nodes and event-related edges is optimized.
2. The monitoring and early warning method based on the smart door lock according to claim 1, characterized in that: The initialization of the dynamic event graph network generates event nodes and event-related edges based on the real-time operation data of the smart door lock and the smart device, and establishes the event graph structure. The specific steps are as follows: Based on the IoT gateway, the smart device ID, event type, timestamp and status value in the smart device are collected through the wireless communication protocol as the basic attributes of the smart device; Define the basic attributes of smart devices as event nodes; The weighted association analysis method is used to extract time intervals, spatial associations, and interaction weights from the basic attributes of smart devices and define them as event association edges. Collect smart device operation data through the IoT gateway and store it in a time series database to dynamically update event nodes and event-related edges; Extract event node sets and event-related edge sets based on historical data in a time series database; For the event node set and the event associated edge set, weighted edge weights are used to quantify the association strength and establish an event graph structure.
3. The monitoring and early warning method based on the smart door lock according to claim 2, characterized in that: The specific steps of analyzing the association patterns between event nodes based on the event graph structure, identifying abnormal collaboration relationships and forming an abnormal collaboration relationship list are as follows: Defining the event graph structure , the expression is: ; in, Represents a set of event nodes in an event graph structure, Represents the set of associated edges in the event graph structure; Define each event node The initial quantum state is ;in, The index variable representing the event node; Defining incident edges The quantum superposition weight is ;in, An index variable representing the adjacent event node; The quantum initial state is calculated based on the basic attributes of each event node in the event graph. The expression is: ; in, Represents an event node The initial quantum state of represents the normalization factor, Represents an event node The total number of associated nodes, Represents an event node and the number of the adjacent event node, Represents an event node The average distance to the adjacent event nodes, Indicates the distance between the event node and the adjacent event node number, represents the deviation value of the adjacent node, Represents an event node The standard deviation of Represents an event node The basis vectors of the numbers of the adjacent event nodes in the quantum state space; Also follow the calculation event node The expression of the quantum initial state is used to further calculate the adjacent event nodes The quantum initial state ; Event-based nodes and adjacent event nodes The quantum initial state and , the quantum state difference metric is calculated by the Euclidean distance of the state ; Utilize the historical interaction records between event nodes and dynamically calculate the associated edges based on the time dependency relationship The quantum superposition weight of is expressed as: ; in, Represents an event node The quantum superposition weight between adjacent event nodes, Represents an event node The temporal and spatial distance between adjacent event nodes; Calculate the quantum superposition weight of the associated edge based on the time-dependent quantum random walk model The transfer probability dynamically adjusts the quantum superposition weight of the associated edge, and the expression is: ; ; in, Indicates time Lower associated edge The weight transfer probability, Indicates time The normalization factor under represents the time-integrated variable, represents an exponential decay function, represents the weight adjustment function based on the association strength value, Represents an event node The strength of the association with the adjacent event node, Indicates the time integral variable during the integration process Small increments of The adjusted quantum superposition weight is stored in the associated edge attribute to describe the dynamic characteristics of the associated edge; In the description process of dynamic characteristics, the high-correlation paths in the event graph are identified according to the weighted transfer probability to form a high-correlation path set; Adopt subgraph edge extraction method to extract related edges from high-related path sets ; Calculate each associated edge by weighted transfer probability difference The asymmetry of the relationship is considered as the initial basis for judging abnormal collaborative relationships; Based on the preliminary judgment basis of abnormal cooperative relationship, the asymmetric abnormal measurement is constructed by using quantum interference effect, and the expression is: ; in, Represents an event node The asymmetric anomaly metric between the adjacent event nodes, represents the number of potential collaboration paths between nodes in the event graph, Indicates the intermediate event node number in the collaboration path, represents the frequency factor of the sine function, Represents an event node Dynamic association weights between the intermediate event node numbers in the collaboration path, Indicates the dynamic association weight between the intermediate event node number and the adjacent event node in the collaboration path, represents the asymmetric magnification factor, represents the exponential adjustment function, Represents associated edges The asymmetry of the bidirectional weight transfer probability; Based on asymmetric anomaly metrics ,The abnormal collaboration relationship matrix is constructed through the threshold filtering method; Use graph clustering algorithms to analyze the abnormal collaboration relationship matrix and identify abnormal collaboration relationship clusters ; The weighted average method is used to identify abnormal collaborative relationship clusters. All associated edges Asymmetric anomaly measure of Find the mean and get the average asymmetric anomaly metric ; Abnormal collaboration cluster The time and space differences of all associated edges in the metric are weighted averaged and the spatiotemporal consistency value is output. ; Setting the threshold for spatiotemporal consistency metrics ; when When , it is determined to be an abnormal collaborative relationship cluster The time-space anomaly condition is satisfied, otherwise it is judged as not satisfying the time-space anomaly condition; All abnormal collaboration relationship clusters that meet the spatiotemporal abnormal conditions Organize into a list of abnormal collaborations, sort by severity and output a list of abnormal collaboration relationships , the expression is: 。 4. The monitoring and early warning method based on the smart door lock according to claim 3, characterized in that: The abnormal collaboration relationship list is combined with the user's geographical location, time information and behavior pattern to perform spatiotemporal correlation analysis on the current operation behavior and output a correlation score list. The specific steps are as follows: Record users’ geographic location and time information in real time through the logging function of IoT gateways and smart devices; Use frequency statistics to extract user interaction records with each device from the operation logs of smart devices and construct behavioral patterns; Based on the abnormal collaboration relationship list ,Using the user’s real-time geographic location and time information, the initial association weight is generated through an exponential decay function; Conduct time series analysis on behavior patterns to extract behavior feature vectors and abnormal collaborative behavior feature vectors; Calculate the behavioral similarity between the behavioral feature vector and the abnormal collaborative behavior feature vector; The initial association weight and behavioral similarity are integrated to calculate the association score through the weighted linear combination method; Normalize the abnormal collaboration relationships in the correlation score and append the normalized correlation score to the abnormal collaboration list , forming a list of associated scores.
5. The monitoring and early warning method based on the smart door lock according to claim 4, characterized in that: The user's historical behavior data in different scenarios is matched with the associated score list to generate a multi-level warning signal. The specific steps are as follows: Collect behavioral data from IoT gateways and smart devices in real time and integrate them into historical behavioral data through timestamps; Divide historical behavior data into scenarios and use the rule engine to extract the time, geographic, and device characteristics of each scenario; Combine time features, geographic features, and device features into a scene feature vector, and generate a scene feature library through cluster analysis; Use cosine similarity to calculate the similarity between each record in the association score list and the scene in the scene feature library, and match the corresponding historical scene for each record; Set up multi-level warning rules based on correlation scores, asymmetric anomaly metrics, and spatiotemporal consistency; Based on the historical scenarios matched by records and multi-level warning rules, a multi-level warning signal is generated including warning level, abnormal equipment, time and location.
6. The monitoring and early warning method based on the smart door lock according to claim 5, characterized in that: The specific steps of linking intelligent devices to perform warning operations based on multi-level warning signals are as follows: Extract warning level, abnormal equipment, time and location from multi-level warning signals; Match corresponding alert response measures from multi-level alert rules based on the alert level, and execute alert operations through IoT gateway linkage devices; While executing alert operations, the system dynamically adjusts the alarm notification content based on abnormal equipment, time and location, and sends real-time alarm notifications to users; Update smart device status based on real-time alarm notifications and provide user control permissions through the app.
7. The monitoring and early warning method based on the smart door lock according to claim 6, characterized in that: The dynamic event graph network is updated in real time based on the feedback data of the alert operation, and the weight configuration of event nodes and event-related edges is optimized. The specific steps are as follows: Receive real-time feedback data on alert operations from the IoT gateway and standardize it into an event graph data format; Match the standardized feedback data with the event nodes and associated edges in the event graph structure, mark abnormal event nodes and associated edges, and record their update status; Adjust the basic attributes of the event node according to the update status, and dynamically update the quantum superposition weight of the event node based on the trigger frequency of the alert event and the response timeliness of the smart device; According to the interaction frequency between event nodes and the impact of feedback, the quantum superposition weights of the associated edges in the event graph structure are adjusted.
8. A monitoring and early warning system based on a smart door lock, based on the monitoring and early warning method based on a smart door lock according to any one of claims 1 to 7, characterized in that: Including event graph module, anomaly identification module, spatiotemporal correlation module, history matching module, early warning linkage module and weight optimization module; The event graph module is used to initialize a dynamic event graph network, generate event nodes and event-related edges based on the real-time operation data of smart door locks and smart devices, and establish an event graph structure; The anomaly identification module is used to analyze the association pattern between event nodes based on the event graph structure, identify abnormal collaboration relationships and form an abnormal collaboration relationship list; The spatiotemporal correlation module is used to combine the abnormal collaboration relationship list with the user's geographical location, time information and behavior pattern, perform spatiotemporal correlation analysis on the current operation behavior, and output a correlation score list; The history matching module is used to match the user's historical behavior data in different scenarios with the associated score list to generate a multi-level warning signal; The warning linkage module is used to link smart devices to perform warning operations according to multi-level warning signals; The weight optimization module is used to update the dynamic event graph network in real time based on the feedback data of the alert operation, and optimize the weight configuration of event nodes and event-related edges.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the monitoring and early warning method based on the smart door lock are implemented as described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the monitoring and early warning method based on the smart door lock according to any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Intelligent machine room multi-dimensional dynamic monitoring management method and system based on digital twinning
CN120746066A