Public safety multi-source risk factor correlation identification and analysis method based on a knowledge graph
By integrating and analyzing public safety risk factor data using a knowledge graph-based approach, a multi-level interconnected network is constructed. This addresses the shortcomings of existing technologies in data integration and dynamic transmission mechanisms, achieving comprehensiveness and accuracy in risk identification and early warning, and providing a scientific basis for risk prevention and control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HANGZHOU ZHUIXING VIDEO TECH CO LTD
- Filing Date
- 2025-07-04
- Publication Date
- 2026-04-28
AI Technical Summary
Existing public safety risk analysis methods are unable to effectively integrate and process structured and unstructured multi-source heterogeneous data, lack characterization of the dynamic transmission mechanism between risk elements, and fail to fully capture the characteristics and correlation information of risk elements, thus affecting the comprehensiveness and accuracy of risk analysis.
Using a knowledge graph-based approach, structured and unstructured public safety risk factor data are integrated to construct an initial risk factor association network. Through feature analysis and community discovery techniques, closely related relationships are identified, a multi-level risk factor association network is constructed, and transmission path analysis is performed to generate risk warning information.
It improves the comprehensiveness and accuracy of risk identification, enhances the ability to identify potential security risks and the precision of early warning, realizes the dynamic propagation simulation and prediction of risks, and provides government departments with scientific risk prevention and control measures.
Smart Images

Figure CN120744859B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to risk identification technology, and more particularly to a knowledge graph-based method for identifying and analyzing the association of multiple sources of public safety risk factors. Background Technology
[0002] Public safety is a crucial foundation for national security and social stability. With socio-economic development, the risk factors facing public safety are becoming increasingly complex and volatile. Public safety risk elements encompass multiple areas, including natural disasters, accidents, public health emergencies, and social security, and these risk elements exhibit complex interrelationships and influences. Traditional public safety risk analysis methods primarily rely on data analysis within a single domain, lacking comprehensive analysis of the correlations between multi-source risk elements. In recent years, the development of knowledge graph technology has provided new technical means for the integration and correlation analysis of multi-source heterogeneous data, offering new research approaches for public safety risk analysis.
[0003] Existing public safety risk analysis methods struggle to effectively integrate and process structured and unstructured multi-source heterogeneous data, resulting in an inability to fully capture the characteristics and correlations of various risk factors, thus affecting the comprehensiveness and accuracy of risk analysis.
[0004] Traditional risk analysis methods often employ static correlation analysis frameworks, which lack characterization of the dynamic transmission mechanisms between risk elements. They cannot accurately reflect the evolution and diffusion patterns of public safety risks, thus limiting the ability to identify and warn of potential risks in their early stages.
[0005] Existing technologies lack effective community discovery and multi-level network representation methods in the construction of risk factor association networks, making it difficult to reveal the implicit association patterns and complex hierarchical structures among risk factors, thus failing to provide accurate support and guidance for risk management and decision-making. Summary of the Invention
[0006] This invention provides a knowledge graph-based method for identifying and analyzing the associations of multiple sources of public safety risk factors, which can solve the problems in the prior art.
[0007] A first aspect of this invention provides a method for identifying and analyzing the association of multiple sources of public safety risk factors based on knowledge graphs, comprising:
[0008] Acquire multi-source public safety risk element data, which includes structured and unstructured public safety risk element data; process the unstructured public safety risk element data to extract public safety risk element information; integrate the structured public safety risk element data and the processed unstructured public safety risk element data to construct an initial public safety risk element association network;
[0009] Feature analysis is performed on the public safety risk element nodes in the initial public safety risk element association network to obtain the feature vectors of the public safety risk element nodes; a similarity matrix is calculated based on the feature vectors.
[0010] Community discovery is performed on the similarity matrix to identify subgroups of public safety risk elements with close relationships; a multi-level public safety risk element association network is constructed based on the subgroups of public safety risk elements.
[0011] A transmission path analysis is performed on the multi-level public safety risk element association network to calculate the transmission weights between public safety risk element nodes. Based on the transmission weights and the analysis results of the multi-level public safety risk element association network, public safety risk early warning information is generated.
[0012] Integrating the structured public safety risk element data and the processed unstructured public safety risk element data to construct an initial public safety risk element association network includes:
[0013] The unstructured public safety risk element data is processed to extract the security management unit entity, public safety attributes, and public safety relationship information from the unstructured public safety risk element data, and the security management unit entity, public safety attributes, and public safety relationship information are transformed into a data structure that matches the structured public safety risk element data according to preset mapping rules;
[0014] The structured public safety risk element data and the transformed unstructured public safety risk element data are integrated according to a preset public safety system to construct an initial public safety risk element association network.
[0015] Feature analysis is performed on the public safety risk element nodes in the initial public safety risk element association network to obtain feature vectors for the public safety risk element nodes; the similarity matrix between public safety risk element nodes is calculated based on the feature vectors, including:
[0016] Feature analysis is performed on the public safety risk element nodes in the initial public safety risk element association network. The static attribute feature vector of the security management unit, the public safety time series feature vector, and the security network topology feature vector of the public safety risk element nodes are extracted. The static attribute feature vector of the security management unit, the public safety time series feature vector, and the security network topology feature vector are combined to construct the multi-dimensional feature vector of the public safety risk element nodes.
[0017] Based on the multi-dimensional feature vectors, a sliding window adaptive clustering method is used to calculate the basic similarity value between the public safety risk element nodes. The sliding window adaptive clustering includes constructing a feature window of a preset size, dynamically grouping the features of the public safety risk element nodes within the feature window, and calculating the similarity between the public safety risk element nodes based on the dynamic grouping; calculating the temporal similarity value between the public safety risk element nodes using the sliding window adaptive clustering method based on the public safety temporal feature vectors; and calculating the topological similarity value between the public safety risk element nodes using the sliding window adaptive clustering method based on the security network topology feature vectors.
[0018] The initial public safety risk element association network is optimized and reconstructed using the basic similarity value, the temporal similarity value, and the topological similarity value to obtain a similarity matrix between public safety risk element nodes.
[0019] Based on the public safety temporal feature vector, the sliding window adaptive clustering is used to calculate the temporal similarity value between the public safety risk element nodes; based on the security network topology feature vector, the sliding window adaptive clustering is used to calculate the topological similarity value between the public safety risk element nodes, including:
[0020] A sliding window with a preset size is constructed, which is used to extract the feature vectors of public safety risk element nodes in segments;
[0021] Based on the sliding window, the temporal feature vectors of the public safety risk element nodes are segmented to extract local temporal features of public safety, and adaptive clustering is used to calculate the temporal similarity value between the public safety risk element nodes; based on the sliding window, the topological feature vectors of the public safety risk element nodes are segmented to extract local topological features of the security network, and adaptive clustering is used to calculate the topological similarity value between the public safety risk element nodes.
[0022] Community discovery is performed on the similarity matrix to identify subgroups of public safety risk elements with close relationships; a multi-level public safety risk element association network is constructed based on these subgroups, including:
[0023] For each security management node in the similarity matrix, the community affiliation strength based on the edge weights between neighboring security management nodes is calculated. The community label of the security management node is iteratively calculated and continuously updated according to the community affiliation strength until the distribution of the community label tends to stabilize and converge, resulting in a community partitioning result containing multiple initial security management communities.
[0024] For each security management community in the community partitioning results, its cohesion is calculated. The cohesion is quantified based on the edge weight relationship between security management nodes within the community. Security management communities with a cohesion greater than a preset cohesion threshold are marked as stable communities. Security management communities with a cohesion less than the preset cohesion threshold are recursively decomposed into multiple security management sub-communities with higher cohesion. The association strength of the security management sub-communities is calculated based on the distribution characteristics of the internal nodes of the security management sub-communities and the connection relationship between the sub-communities.
[0025] Based on the stable community, the security management sub-community, and the association strength, the inter-layer edge weights are dynamically updated and optimized to obtain a multi-level public safety risk element association network with a complete hierarchical structure.
[0026] A transmission path analysis is performed on the multi-level public safety risk element association network to calculate the transmission weights between public safety risk element nodes. Based on the transmission weights and the analysis results of the multi-level public safety risk element association network, public safety risk early warning information is generated, including:
[0027] Obtain the transmission path between public safety risk element node pairs in the multi-level public safety risk element association network, obtain historical transmission data of the public safety risk element nodes at different times based on the transmission path, obtain the transmission feature vector, and calculate the temporal dependency relationship between the public safety risk element node pairs based on the transmission feature vector.
[0028] Based on the temporal dependency, a temporal decay factor is calculated by combining the time difference between the current time and historical time. The temporal dependency is multiplied by the temporal decay factor to obtain the initial transmission weight between the public safety risk element node pairs. The initial transmission weight is adjusted according to the connection relationship of the public safety risk element nodes in the transmission path to obtain the dynamic transmission weight.
[0029] The dynamic transmission weight is combined with the risk level of the public safety risk element node along the transmission path to obtain the public safety risk transmission intensity. The public safety risk transmission intensity is accumulated to obtain the public safety risk early warning index. When the public safety risk early warning index exceeds the preset early warning threshold, public safety risk early warning information is generated.
[0030] The public safety risk transmission intensity is obtained by combining the dynamic transmission weight with the risk level of the public safety risk element nodes along the transmission path. The public safety risk transmission intensity is accumulated to obtain public safety risk early warning indicators, including:
[0031] Based on the dynamic transmission weights and risk levels of public safety risk element nodes, the PageRank algorithm is used to calculate the centrality score of the public safety risk element nodes. The centrality score is combined with the dynamic transmission weights to obtain the carrying capacity of the public safety risk element nodes. Based on the PageRank algorithm, the structural importance of the public safety risk element nodes is calculated. The structural importance is combined with the carrying capacity to obtain the failure threshold of the public safety risk element nodes.
[0032] The dynamic transmission weight is combined with the risk level of the public safety risk element node along the transmission path to obtain the public safety risk transmission intensity; based on the public safety risk transmission intensity, it is determined whether the public safety risk element node has reached the failure threshold, and the public safety risk element node that has reached the failure threshold is marked as a trigger node;
[0033] The PageRank algorithm is used to calculate the degree of influence of the triggering node on adjacent public safety risk element nodes on the transmission path. Based on the degree of influence, the propagation impact is determined, and the propagation impact is accumulated to obtain the cumulative effect of public safety risk. Based on the cumulative effect of public safety risk and the intensity of public safety risk transmission, a public safety risk early warning index is calculated.
[0034] A second aspect of the present invention provides an electronic device, comprising:
[0035] processor;
[0036] Memory used to store processor-executable instructions;
[0037] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.
[0038] A third aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.
[0039] The beneficial effects of this application are as follows:
[0040] This invention integrates structured and unstructured public safety risk factor data to construct a multi-level public safety risk factor association network, which can comprehensively capture the complex relationships between risk factors from different sources, thereby improving the comprehensiveness and accuracy of risk identification.
[0041] This invention employs feature analysis and community discovery techniques to effectively identify risk element subgroups with close relationships, revealing the implicit relationships and clustering characteristics among risk elements, thereby enhancing the ability to identify potential security risks and the accuracy of early warnings.
[0042] This invention uses transmission path analysis to calculate the transmission weights between risk element nodes, enabling dynamic simulation and prediction of risk propagation. This makes public safety risk early warning more forward-looking and operable, and provides a scientific basis for government departments to formulate risk prevention and control measures. Attached Figure Description
[0043] Figure 1 This is a flowchart illustrating the knowledge graph-based method for identifying and analyzing the association of multiple sources of public safety risk factors according to an embodiment of the present invention.
[0044] Figure 2 This is a schematic diagram comparing the performance of feature vector similarity calculation in embodiments of the present invention;
[0045] Figure 3 This is a bar chart comparing the performance of the multi-level public safety risk element association network in an embodiment of the present invention.
[0046] Figure 4 This is a flowchart illustrating the risk warning information generation process based on a multi-level public safety risk element association network, as described in an embodiment of the present invention.
[0047] Figure 5 This is a bar chart comparing the performance of the public safety risk transmission model in embodiments of the present invention. Detailed Implementation
[0048] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0049] The technical solution of the present invention will be described in detail below with reference to specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.
[0050] Figure 1 This is a flowchart illustrating the knowledge graph-based method for identifying and analyzing the association of multiple sources of public safety risk factors, as described in this embodiment of the invention. Figure 1 As shown, the method includes:
[0051] Acquire multi-source public safety risk element data, which includes structured and unstructured public safety risk element data; process the unstructured public safety risk element data to extract public safety risk element information; integrate the structured public safety risk element data and the processed unstructured public safety risk element data to construct an initial public safety risk element association network;
[0052] Feature analysis is performed on the public safety risk element nodes in the initial public safety risk element association network to obtain the feature vectors of the public safety risk element nodes; a similarity matrix is calculated based on the feature vectors.
[0053] Community discovery is performed on the similarity matrix to identify subgroups of public safety risk elements with close relationships; a multi-level public safety risk element association network is constructed based on the subgroups of public safety risk elements.
[0054] A transmission path analysis is performed on the multi-level public safety risk element association network to calculate the transmission weights between public safety risk element nodes. Based on the transmission weights and the analysis results of the multi-level public safety risk element association network, public safety risk early warning information is generated.
[0055] In one optional implementation, integrating the structured public safety risk element data and the processed unstructured public safety risk element data to construct an initial public safety risk element association network includes:
[0056] The unstructured public safety risk element data is processed to extract the security management unit entity, public safety attributes, and public safety relationship information from the unstructured public safety risk element data, and the security management unit entity, public safety attributes, and public safety relationship information are transformed into a data structure that matches the structured public safety risk element data according to preset mapping rules;
[0057] The structured public safety risk element data and the transformed unstructured public safety risk element data are integrated according to a preset public safety system to construct an initial public safety risk element association network.
[0058] Acquire both structured and unstructured public safety risk element data. Structured data comes from government statistical databases, structured records in enterprise safety management systems, etc. This data is typically stored in tables, databases, etc., with clearly defined fields and formats. For example, a chemical company's safety inspection record database includes fields such as inspection time, inspectors, inspection items, risk level, and corrective measures. Unstructured data comes from textual materials such as safety accident reports, news reports, expert opinions, and meeting minutes. This data lacks a predefined data model or organizational method.
[0059] Named entity recognition (NAME) technology is used to identify safety management unit entities from unstructured text. For example, from the text "A production workshop experienced a leak due to equipment aging," the system can identify "A production workshop" as a safety management unit entity. The system maintains an entity type dictionary, including unit types such as enterprise, department, workshop, and work group. By matching words in the text with entity types in the dictionary, and combining this with contextual analysis, the system determines the safety management unit entity within the text.
[0060] By employing keyword extraction and semantic analysis techniques, the system extracts public safety attribute information from unstructured text. For example, from the text "The equipment is operating at excessively high temperatures, and the pressure has exceeded the safety threshold, posing an explosion risk," the system extracts safety attributes such as "excessive temperature," "excessive pressure," and "explosion risk." The system pre-establishes a safety attribute classification system, including categories such as equipment status, environmental factors, personnel operation, and management measures, with a specific attribute vocabulary for each category. By matching words in the text with the attribute vocabulary and combining this with semantic understanding, the system can identify the public safety attributes described in the text.
[0061] This system utilizes dependency parsing and relation extraction techniques to extract public safety relationship information from unstructured text. For example, from the text "Safety valve failure leads to pressure not being released, which in turn causes container rupture," the system extracts the causal relationship chain of "safety valve failure -- pressure not being released -- container rupture." The system predefines a series of relationship types, such as causal relationships, inclusion relationships, and temporal relationships, and identifies the relationship types between entities by analyzing relational words (such as "leads to," "causes," "includes," etc.) and their context.
[0062] After extracting information on security management unit entities, public safety attributes, and public safety relationships, the system transforms this information into a data structure that matches the structured public safety risk element data, based on preset mapping rules. The mapping rules define how entities, attributes, and relationships in unstructured data are mapped to the fields and formats of structured data.
[0063] Specifically, for safety management unit entities, the system maps them to fields such as "Unit ID", "Unit Name", and "Unit Type" in structured data. For example, "Production Workshop A" extracted from the text is mapped to a structured record with Unit ID "WS001", Unit Name "Production Workshop A", and Unit Type "Production Unit".
[0064] For public safety attributes, the system maps them to fields such as "attribute category," "attribute value," and "risk level" in structured data. For example, "temperature too high" extracted from text is mapped to a structured record with the attribute category "equipment status," the attribute value "temperature too high," and the risk level "high."
[0065] For public safety relationship information, the system maps it to fields such as "relationship type", "source entity", "target entity", and "relationship description" in structured data. For example, the text extracted "safety valve failure caused pressure to be unable to be released" is mapped to a structured record with the relationship type "causal relationship", the source entity "safety valve failure", the target entity "pressure cannot be released", and the relationship description "caused".
[0066] After completing the structuring transformation of unstructured data, the system integrates the structured public safety risk element data and the transformed unstructured public safety risk element data according to the preset public safety system to construct an initial public safety risk element association network.
[0067] The pre-defined public safety system is a multi-layered classification framework, including the safety management unit layer, the safety risk element layer, and the safety relationship layer. The safety management unit layer includes safety management responsibility units at all levels; the safety risk element layer includes categories such as equipment and facility risks, environmental risks, personnel risks, and management risks; and the safety relationship layer defines the relationships between units and between risk elements.
[0068] Based on a pre-defined public safety framework, the system constructs a network structure from the integrated data. In this network, nodes represent safety management units and safety risk elements, and edges represent the relationships between them. For example, "Production Workshop A" is a node, and there is a "risk exists" relationship edge between it and the risk element node representing "excessive temperature"; the "excessive temperature" node and the "explosion risk" node have a "cause" relationship edge.
[0069] In this way, the system successfully integrates structured and unstructured public safety risk factor data into an initial public safety risk factor association network. This network intuitively displays the security management units, security risk factors, and the complex relationships between them, providing a foundation for subsequent risk assessment and early warning.
[0070] In one optional implementation, feature analysis is performed on the public safety risk element nodes in the initial public safety risk element association network to obtain feature vectors for the public safety risk element nodes; calculating the similarity matrix between public safety risk element nodes based on the feature vectors includes:
[0071] Feature analysis is performed on the public safety risk element nodes in the initial public safety risk element association network. The static attribute feature vector of the security management unit, the public safety time series feature vector, and the security network topology feature vector of the public safety risk element nodes are extracted. The static attribute feature vector of the security management unit, the public safety time series feature vector, and the security network topology feature vector are combined to construct the multi-dimensional feature vector of the public safety risk element nodes.
[0072] Based on the multi-dimensional feature vectors, a sliding window adaptive clustering method is used to calculate the basic similarity value between the public safety risk element nodes. The sliding window adaptive clustering includes constructing a feature window of a preset size, dynamically grouping the features of the public safety risk element nodes within the feature window, and calculating the similarity between the public safety risk element nodes based on the dynamic grouping; calculating the temporal similarity value between the public safety risk element nodes using the sliding window adaptive clustering method based on the public safety temporal feature vectors; and calculating the topological similarity value between the public safety risk element nodes using the sliding window adaptive clustering method based on the security network topology feature vectors.
[0073] The initial public safety risk element association network is optimized and reconstructed using the basic similarity value, the temporal similarity value, and the topological similarity value to obtain a similarity matrix between public safety risk element nodes.
[0074] In the feature analysis phase, for each risk element node in the initial public safety risk element association network, three types of feature vectors are extracted: static attribute feature vector of safety management unit, time-series feature vector of public safety, and topology feature vector of safety network.
[0075] The extraction of static attribute feature vectors of safety management units is achieved by processing the basic attribute data of public safety management units. These feature vectors include feature dimensions such as unit type, safety level, jurisdiction, and personnel size. For example, for a city's fire management department, its static attribute feature vector can be represented as [3,4,2,5], which respectively represent that the unit is a fire type (3), a safety level of A (4), a jurisdiction of the city level (2), and a personnel size of 500 people (5).
[0076] The extraction of public safety time-series feature vectors is based on historical safety event data, quantifying the trend of risk changes over time. The time-series feature vector includes dimensions such as event frequency, fluctuations in event severity, and seasonal characteristics. Specifically, by dividing the safety event data of the past 24 months into monthly segments, the number and severity of events each month are counted, forming a time-series feature vector of length 48. For example, the first 12 values of the traffic safety time-series feature vector for a certain region are [5,7,3,4,8,10,12,9,6,4,3,5], representing the number of events over 12 months, with subsequent values representing the quantified severity of the events.
[0077] The extraction of topological feature vectors in a secure network is achieved by analyzing the structural characteristics of nodes within the interconnected network. This primarily includes network features such as degree centrality, betweenness centrality, proximity centrality, and eigenvector centrality. Specifically, for a node v in the network, the degree centrality is calculated by determining the number of connections it has with all other nodes; the betweenness centrality is calculated by the ratio of the number of shortest paths through node v to the total number of shortest paths in the network; the proximity centrality is calculated by taking the reciprocal of the average distance from node v to all other nodes; and the eigenvector centrality is obtained by iteratively calculating the eigenvalues of the adjacency matrix. For a node in a public health management department, its topological feature vector is [23, 0.15, 0.42, 0.38], representing that the node is connected to 23 other nodes, has a betweenness centrality of 0.15, a proximity centrality of 0.42, and an eigenvector centrality of 0.38.
[0078] The three types of feature vectors mentioned above are combined in a concatenated manner to construct a multi-dimensional feature vector. For a node with m-dimensional static attribute features, n-dimensional temporal features, and p-dimensional topological features, the length of its multi-dimensional feature vector is m+n+p. In practical applications, different weights can be assigned to different types of features to enhance the influence of key features. For example, for the node in the example above, its multi-dimensional feature vector is [3,4,2,5,5,7,3,4,8,10,12,9,6,4,3,5...23,0.15,0.42,0.38].
[0079] In the similarity calculation stage, a sliding window adaptive clustering method is used to calculate the similarity between nodes. Sliding window adaptive clustering first constructs a feature window of a preset size, which is set according to the feature vector dimension and data characteristics, typically 20%-30% of the feature vector dimension. Within the feature window, the features of public safety risk element nodes are dynamically grouped, and the similarity between nodes is calculated based on these dynamic groupings.
[0080] In the specific implementation, for the multi-dimensional feature vectors Va and Vb of two nodes a and b, let the feature window size be w. Starting from the first dimension of the feature vectors, w dimensions are selected each time to form a window, and the feature similarity between the two nodes is calculated within the window. The feature similarity within the window is calculated using the cosine similarity method, that is, the dot product of the two feature vectors within the window is divided by the product of their respective norms. The weighted average of the calculation results for all windows is taken as the basic similarity value between nodes a and b.
[0081] For example, given the multi-dimensional feature vectors Va=[3,4,2,5,7,9,4,2] and Vb=[2,5,3,4,8,7,3,3] of nodes a and b, and assuming a window size w=3, the features within the first window are Va1=[3,4,2] and Vb1=[2,5,3], with a calculated similarity of 0.85. The features within the second window are Va2=[4,2,5] and Vb2=[5,3,4], with a calculated similarity of 0.92, and so on. The final weighted average yields a basic similarity value of 0.88.
[0082] The temporal similarity value is calculated using the same sliding window adaptive clustering method, but only the public safety temporal feature vector portion is used. For the temporal feature vectors Vat and Vbt of nodes a and b, the time window size is set to wt (usually 3-6 months). The similarity of node activity patterns is calculated within each time window, and the results of each time window are combined to obtain the temporal similarity value.
[0083] The calculation of topological similarity values also employs the sliding window adaptive clustering method, but only uses the topological feature vector portion of the secure network. For the topological feature vectors Vag and Vbg of nodes a and b, the similarity of the nodes' positions in the network structure is calculated within the feature window, focusing on the similarity of the nodes' connection patterns and centrality features.
[0084] The basic similarity value, temporal similarity value, and topological similarity value are weighted and fused to optimize and reconstruct the initial public safety risk element association network, resulting in a similarity matrix between public safety risk element nodes. In practical applications, the weights of basic similarity, temporal similarity, and topological similarity can be set to 0.3, 0.4, and 0.3, respectively, and the specific weights can be adjusted according to the application scenario and data characteristics.
[0085] For a network containing N nodes, the similarity matrix S is an N×N matrix, where the element S[i][j] represents the comprehensive similarity value between node i and node j. For example, in a public safety risk association network of a certain city, containing 50 nodes, in the similarity matrix S calculated by the above method, the similarity value S
[12]
[25] =0.78 between the fire department and the emergency management department, indicating that the two departments have a high similarity in risk characteristics; while the similarity value S
[12]
[38] =0.32 between the fire department and the education department, indicating that the two departments have a low similarity in risk characteristics.
[0086] The construction of the similarity matrix provides a foundation for subsequent community discovery and multi-level network construction, effectively identifying closely related subgroups of public safety risk elements and supporting public safety risk early warning. This method allows for in-depth exploration of potential connections between different security management units and risk elements, improving the accuracy and timeliness of risk early warning.
[0087] Figure 2 This diagram illustrates the performance comparison of feature vector similarity calculation in embodiments of the present invention. It shows the performance trends of three different feature similarity calculation methods as the number of nodes changes. The present invention is a novel network feature extraction algorithm, while the static feature similarity method is a traditional method based on static network features for similarity calculation. The traditional network feature method is the most fundamental network feature extraction method. The performance curves show that the present invention maintains the best performance across the entire range of node numbers, with an initial similarity of 0.88, and shows a steady upward trend as the number of nodes increases, reaching a similarity of 0.99 when the number of nodes reaches 100. The static feature similarity method performs second best, with an initial similarity of 0.72, slowly increasing with the number of nodes, eventually reaching 0.82 when the number of nodes reaches 100. The traditional network feature method performs the worst, with an initial similarity of only 0.50. Although it also increases with the number of nodes, the increase is small, reaching only 0.61 when the number of nodes reaches 100. It is worth noting that the performance gap among the three methods remained relatively stable as the number of nodes increased, with our proposed solution consistently maintaining a significant lead. This fully demonstrates the stability and reliability of our solution when handling feature extraction from networks of different sizes. Experimental results show that our proposed solution has a clear performance advantage in network feature similarity calculation, especially when dealing with large-scale node networks.
[0088] In one optional implementation, based on the public safety temporal feature vector, the sliding window adaptive clustering is used to calculate the temporal similarity value between the public safety risk element nodes; based on the security network topology feature vector, the sliding window adaptive clustering is used to calculate the topological similarity value between the public safety risk element nodes, including:
[0089] A sliding window with a preset size is constructed, which is used to extract the feature vectors of public safety risk element nodes in segments;
[0090] Based on the sliding window, the temporal feature vectors of the public safety risk element nodes are segmented to extract local temporal features of public safety, and adaptive clustering is used to calculate the temporal similarity value between the public safety risk element nodes; based on the sliding window, the topological feature vectors of the public safety risk element nodes are segmented to extract local topological features of the security network, and adaptive clustering is used to calculate the topological similarity value between the public safety risk element nodes.
[0091] A sliding window of preset size is constructed to extract feature vectors of public safety risk element nodes in segments. The size of the sliding window can be set according to the actual application scenario. In this embodiment, the sliding window size is set to 24 hours, and the window sliding step size is set to 1 hour. The sliding window moves on the time axis, extracting local features within the window for calculation each time, effectively handling the dynamic change characteristics of time series data.
[0092] For calculating the temporal similarity value, the system extracts the temporal feature vectors of public safety risk element nodes in segments based on a sliding window. Assume a city area has two public safety risk element nodes, A and B. The temporal feature vector of node A is [12,15,18,25,30,28,22,18,15,20,25,28], and the temporal feature vector of node B is [10,14,17,23,29,27,20,17,14,19,24,27], representing the safety risk index of these two nodes over a consecutive 12-hour period. The sliding window size is set to 6. When the window slides across the temporal feature vectors, the first 6 time points [12,15,18,25,30,28] of node A and the first 6 time points [10,14,17,23,29,27] of node B are extracted as local features.
[0093] Adaptive clustering was used to calculate the temporal similarity between these two local features. First, the Euclidean distance between the two local features was calculated, resulting in 3.74. Then, the distance was converted to a similarity using a Gaussian kernel function, calculated as exp(-distance). 2 / 2σ 2 ), where σ is an adaptive parameter that is dynamically adjusted according to the current data distribution, with its initial value set as the average of the standard deviations of local features. In this example, σ is calculated to be 5.2, therefore the temporal similarity between nodes A and B in the current window is 0.87, indicating that the change trends of these two nodes are highly similar during this time period.
[0094] The window slides back one step, extracting [15,18,25,30,28,22] from node A and [14,17,23,29,27,20] from node B, and recalculates the similarity value to 0.89. By continuously sliding, the similarity values within all time windows are calculated, ultimately yielding the temporal similarity value sequence for nodes A and B: [0.87,0.89,0.92,0.90,0.88,0.91,0.85]. The average of these values, 0.89, is taken as the overall temporal similarity value for nodes A and B.
[0095] For calculating the topological similarity value, the system extracts the topological feature vectors of public safety risk element nodes in segments based on a sliding window. Assume that the topological feature vector of node A is [5,8,12,15,18,20,16,12,10,14,16,18], and the topological feature vector of node B is [6,9,13,16,19,21,17,13,11,15,17,19], representing the connectivity metrics of these two nodes with other safety risk nodes over a consecutive 12-hour period. The sliding window size is also set to 6. First, the first 6 topological features of node A [5,8,12,15,18,20] and the first 6 topological features of node B [6,9,13,16,19,21] are extracted as local topological features.
[0096] Adaptive clustering was used to calculate the similarity between these two local topological features. First, the Euclidean distance was calculated to be 2.45, and then converted into a similarity value using a Gaussian kernel function. Based on the current topological data distribution, the adaptive parameter σ was adjusted to 4.8, and the calculated topological similarity between nodes A and B in the current window was 0.93, indicating that these two nodes have high similarity in network topology.
[0097] The window continues to slide, extracting subsequent local topological features and calculating similarity values, resulting in a topological similarity value sequence [0.93, 0.94, 0.92, 0.91, 0.93, 0.95, 0.92]. The average of these values, 0.93, is taken as the overall topological similarity value between nodes A and B.
[0098] To improve the accuracy of adaptive clustering, the system dynamically adjusts the clustering parameters during the calculation process. When the change in the feature distribution between two adjacent sliding windows exceeds a preset threshold (set to 15% in this embodiment), the clustering parameter σ is automatically recalculated. For example, when sliding from the third window to the fourth window, if the temporal feature distribution change rate of node A is 17%, exceeding the threshold, the system adjusts σ from 5.2 to 4.8 to better adapt to the current data distribution characteristics.
[0099] In practical applications, temporal similarity and topological similarity values can be considered together. For example, a weighted average of 0.4 × 0.89 + 0.6 × 0.93 = 0.914 can be used as the comprehensive similarity value between nodes A and B, where the weights can be adjusted according to the specific application scenario. This comprehensive similarity value can be used for subsequent risk propagation path prediction, security event correlation analysis, and risk control strategy formulation.
[0100] This implementation utilizes sliding window adaptive clustering technology to effectively capture the similarity of public safety risk element nodes in both temporal and topological dimensions, providing strong support for constructing accurate public safety risk evolution models. This method is highly adaptable, computationally efficient, and capable of handling security risk networks of varying sizes, demonstrating significant application value.
[0101] In one optional implementation, community discovery is performed on the similarity matrix to identify subgroups of public safety risk elements with close relationships; constructing a multi-level public safety risk element association network based on the subgroups of public safety risk elements includes:
[0102] For each security management node in the similarity matrix, the community affiliation strength based on the edge weights between neighboring security management nodes is calculated. The community label of the security management node is iteratively calculated and continuously updated according to the community affiliation strength until the distribution of the community label tends to stabilize and converge, resulting in a community partitioning result containing multiple initial security management communities.
[0103] For each security management community in the community partitioning results, its cohesion is calculated. The cohesion is quantified based on the edge weight relationship between security management nodes within the community. Security management communities with a cohesion greater than a preset cohesion threshold are marked as stable communities. Security management communities with a cohesion less than the preset cohesion threshold are recursively decomposed into multiple security management sub-communities with higher cohesion. The association strength of the security management sub-communities is calculated based on the distribution characteristics of the internal nodes of the security management sub-communities and the connection relationship between the sub-communities.
[0104] Based on the stable community, the security management sub-community, and the association strength, the inter-layer edge weights are dynamically updated and optimized to obtain a multi-level public safety risk element association network with a complete hierarchical structure.
[0105] When calculating the community affiliation strength for each security management node in the similarity matrix, a community label propagation method based on edge weights is adopted. For node i in the network, let its set of neighboring nodes be N(i), and the edge weight between node i and its neighboring node j be w(i,j), which is the corresponding element value in the similarity matrix. The community affiliation strength of node i is calculated by summing the weight values of the community labels of each neighboring node j of node i, and the weight value is equal to the edge weight w(i,j) between node i and node j. For example, in a city emergency management network, node A is adjacent to nodes B, C, and D, with edge weights of 0.8, 0.6, and 0.3, respectively. Neighboring nodes B and C belong to community 1, and node D belongs to community 2. Then, the affiliation strength of node A to community 1 is 0.8 + 0.6 = 1.4, and the affiliation strength to community 2 is 0.3.
[0106] During the iterative calculation of community labels, the processing order for each node is randomly selected. Based on the node's affiliation strength to each community, the node is assigned to the community with the highest affiliation strength. When a node has equal affiliation strength to multiple communities, one of the communities is randomly selected as the node's label. The iterative process continues until more than 95% of the nodes in the network maintain their community labels unchanged for five consecutive iterations, indicating that the community label distribution tends to stabilize.
[0107] In practical applications, taking a city's public safety risk association network as an example, it contains 100 safety management nodes, each initially assigned a unique community label. After iterative calculations, the network eventually converges into 8 initial safety management communities, each corresponding to different types of safety management functional areas. For example, community 1 includes nodes related to fire protection and safety supervision, while community 2 includes nodes related to public security and transportation.
[0108] When calculating the cohesion of each security management community in the community partitioning results, a community cohesion calculation method based on edge weights is adopted. The cohesion of community C is calculated as follows: the sum of the edge weights between all pairs of nodes within the community divided by the product of the maximum number of edges within the community and the maximum edge weight. In specific implementation, for a community containing n nodes, the maximum number of edges is n×(n-1) / 2, and the maximum edge weight is 1.0. For example, if a community contains 5 nodes and the sum of its internal edge weights is 8.2, then its cohesion is 8.2÷(5×4 / 2×1.0)=0.82.
[0109] A preset cohesion threshold of 0.7 is set, and security management communities with a cohesion greater than 0.7 are marked as stable communities. For communities with a cohesion less than 0.7, a recursive decomposition process is used. The decomposition process employs a hierarchical clustering method, starting with the edge with the smallest weight within the community to divide it into two sub-communities. Then, the cohesion of each sub-community is recursively calculated until the cohesion of all sub-communities is greater than the preset threshold or the size of the sub-communities is reduced to an indivisible level (e.g., containing only 3 nodes).
[0110] Taking community 3 in a city's public safety network as an example, this community contains 15 nodes with a cohesion of 0.65, which is less than the preset threshold of 0.7. Through recursive decomposition, community 3 is divided into two sub-communities, 3a and 3b, containing 8 and 7 nodes respectively, with cohesions of 0.75 and 0.72 respectively, both greater than the preset threshold. Therefore, the decomposition process ends.
[0111] For the security management sub-communities obtained from the decomposition, it is necessary to calculate the association strength between the sub-communities. The association strength is calculated based on the weights of the connecting edges between the sub-communities: the sum of the weights of all connecting edges between two sub-communities divided by the product of the number of nodes in the two sub-communities. For example, if there are 12 connecting edges between sub-communities 3a and 3b, and the sum of the edge weights is 5.4, then the association strength is 5.4 ÷ (8 × 7) = 0.096.
[0112] When constructing a multi-level network of public safety risk elements, stable communities are used as nodes in the upper-level network, sub-communities obtained from decomposition are used as nodes in the middle-level network, and the original security management nodes constitute the lower-level network. The weights of the inter-layer edges are set based on the membership and association strength between communities and sub-communities, and between sub-communities and the original nodes.
[0113] The dynamic updating and optimization of inter-layer edge weights adopts an adaptive weight adjustment mechanism. For community node A in the upper layer network and sub-community node B in the middle layer network, if sub-community B is obtained by decomposing community A, the inter-layer edge weight from A to B is initially set to the cohesion value of B. For sub-community node B in the middle layer network and original node C in the lower layer network, if node C belongs to sub-community B, the inter-layer edge weight from B to C is initially set to the centrality value of node C in sub-community B, which is calculated based on the connection edge weights between node C and other nodes in sub-community B.
[0114] As the risk network dynamically evolves, the edge weights between layers need to be updated periodically. The update cycle can be set to every 7 days or every 30 days, depending on the real-time requirements of the application scenario. During the update process, based on the changes in the relationships between the underlying nodes, the cohesion of the sub-communities and the strength of the associations between communities are recalculated, and then the edge weights of each level are updated from bottom to top.
[0115] For example, the hierarchical structure of a city's public safety risk network includes: four stable communities at the top (corresponding to four major security management areas), twelve sub-communities in the middle (corresponding to subdivided security management functional groups), and 100 original security management nodes at the bottom. After a month of data updates, the relationships between nodes in the bottom-level network changed, causing the cohesion of a certain sub-community to drop from 0.75 to 0.68, below the preset threshold, requiring further decomposition; at the same time, the cohesion of two sub-communities that originally had a correlation strength of 0.1 increased to 0.25, indicating that their connection has strengthened, and this change needs to be reflected in the upper-level network.
[0116] By dynamically updating and optimizing the edge weights between layers, a multi-level public safety risk element association network with a complete hierarchical structure is finally constructed. This network can clearly reflect the relationships between different levels of safety management units, providing a foundation for subsequent risk transmission analysis.
[0117] Figure 3 This is a bar chart comparing the performance of multi-level public safety risk element association networks according to embodiments of the present invention. The chart illustrates the performance comparison of three different community analysis methods. The single-level community segmentation method is a traditional algorithm based on a single level for community identification; the hierarchical community segmentation method is an algorithm considering hierarchical relationships within groups; and the present invention is a novel comprehensive community analysis method. Looking at the three key performance indicators, the present invention performs best in community detection accuracy, reaching 83.2%, significantly better than the hierarchical community segmentation method's 67.8% and the single-level community segmentation method's 52.5%. In terms of cohesion identification efficiency, the present invention also maintains a leading advantage, reaching 82.5%, while the hierarchical method achieves 59.7% and the single-level method only 46.3%. In terms of hierarchical association performance, the present invention still performs best, reaching 76.7%, compared to the hierarchical method's 53.2%, while the single-level method is relatively weaker at only 31.9%. The data comparison clearly shows that this technical solution significantly outperforms traditional methods in all three evaluation dimensions, particularly demonstrating a clear advantage in handling hierarchical relationships within communities. This indicates that the solution has strong practical value and application prospects in the field of community structure analysis. This data fully demonstrates the importance and effectiveness of novel comprehensive analysis methods in community structure research.
[0118] In one optional implementation, a transmission path analysis is performed on the multi-level public safety risk element association network to calculate the transmission weights between public safety risk element nodes. Based on the transmission weights and the analysis results of the multi-level public safety risk element association network, public safety risk early warning information is generated, including:
[0119] Obtain the transmission path between public safety risk element node pairs in the multi-level public safety risk element association network, obtain historical transmission data of the public safety risk element nodes at different times based on the transmission path, obtain the transmission feature vector, and calculate the temporal dependency relationship between the public safety risk element node pairs based on the transmission feature vector.
[0120] Based on the temporal dependency, a temporal decay factor is calculated by combining the time difference between the current time and historical time. The temporal dependency is multiplied by the temporal decay factor to obtain the initial transmission weight between the public safety risk element node pairs. The initial transmission weight is adjusted according to the connection relationship of the public safety risk element nodes in the transmission path to obtain the dynamic transmission weight.
[0121] The dynamic transmission weight is combined with the risk level of the public safety risk element node along the transmission path to obtain the public safety risk transmission intensity. The public safety risk transmission intensity is accumulated to obtain the public safety risk early warning index. When the public safety risk early warning index exceeds the preset early warning threshold, public safety risk early warning information is generated.
[0122] like Figure 4 As shown, the method includes:
[0123] Obtain the transmission paths between nodes of public safety risk elements in the network. For example, in a network containing multiple levels of risk elements such as natural disasters, social security, and public health, it can be determined that there is a transmission path between earthquake (A) and secondary disaster fire (B), and there is also a transmission path between fire (B) and casualties (C), thus forming a transmission link of A--B--C.
[0124] Based on the established transmission paths, the system collects historical transmission data of these risk factor nodes at different times. For example, it collects historical data on fires caused by earthquakes over the past five years, including indicators such as earthquake intensity, fire probability, and fire size. Specifically, it can be found that the probability of a fire caused by an earthquake of magnitude 6 is 0.3; the probability of a fire caused by an earthquake of magnitude 7 is 0.5; and the probability of a fire caused by an earthquake of magnitude 8 is 0.7. Based on this historical data, a transmission feature vector is formed, such as the transmission feature vector between earthquakes and fires, which can be represented as [magnitude 6, 0.3; magnitude 7, 0.5; magnitude 8, 0.7].
[0125] Based on the transmission feature vector, the temporal dependencies between risk factor node pairs are calculated. By analyzing the time delay and probability relationship between earthquakes and fires in historical data, the strength of their temporal dependencies is determined. For example, the analysis found that the dependency strength for a fire occurring within 24 hours of an earthquake is 0.6, the dependency strength within 24-48 hours is 0.2, and the dependency strength decreases to 0.1 within 48-72 hours.
[0126] Based on the calculated temporal dependency and the time difference between the current moment and historical moments, the temporal decay factor is calculated. Assuming a magnitude 6 earthquake has occurred and 12 hours have passed since then, the temporal decay factor can be calculated as 0.8 according to the time decay model. Multiplying the temporal dependency (0.6) by the temporal decay factor (0.8) yields an initial transmission weight of 0.48 between the earthquake and the fire.
[0127] Based on the connectivity of risk element nodes in the transmission path, the initial transmission weights are adjusted to obtain dynamic transmission weights. Considering the existence of multiple transmission paths between earthquakes and fires, such as earthquake-building damage-fire, earthquake-power system damage-fire, etc., the weights of these paths are comprehensively evaluated. Assuming that the adjustment coefficient after comprehensive evaluation is 1.2, the dynamic transmission weight is 0.48 × 1.2 = 0.576.
[0128] The dynamic transmission weights are combined with the risk levels of risk element nodes along the transmission path to obtain the public safety risk transmission intensity. Assuming the current risk level assessment of a magnitude 6 earthquake is 0.7 (out of 1), the earthquake-fire risk transmission intensity is 0.576 × 0.7 = 0.4032.
[0129] The intensity of public safety risk transmission is accumulated to obtain a public safety risk early warning index. In the transmission link A-B-C, if the risk transmission intensity from fire to casualties is 0.5, then the cumulative risk early warning index from earthquake to casualties can be calculated as 0.4032 × 0.5 = 0.2016. The system's preset early warning threshold is 0.2. When the calculated risk early warning index of 0.2016 exceeds the early warning threshold, the system generates a public safety risk early warning message: "Following a magnitude 6 earthquake in the current area, the risk of fire causing casualties is high. Relevant departments are requested to prepare for emergency response."
[0130] In practical applications, the system can be extended to more complex, multi-level risk networks. For example, different types of public safety risk elements, such as environmental pollution and traffic accidents, can be incorporated into the network to analyze the transmission relationships between them. The system can identify non-obvious risk transmission paths, such as the transmission chain of environmental pollution – public health events – social stability issues – economic impact.
[0131] By adjusting the parameters of the time-series decay model, the system can adapt to the time decay characteristics of different types of risks. For example, the risk transmission of earthquake-induced tsunamis has a rapid decay characteristic, and the time-series decay factor can be set to an exponential decay model; while environmental pollution-induced public health problems have a long-term cumulative effect, and the time-series decay factor can be set to a slow linear decay model.
[0132] The risk level assessment of risk element nodes will be dynamically updated. For example, when an increase in continuous rainfall is detected in a certain area, the risk level of flooding in that area will increase accordingly, which will affect the calculation results of all risk transmission paths related to flooding.
[0133] The public safety risk early warning method in this embodiment analyzes the transmission relationship between multi-level risk elements, which can promptly identify potential risk chains, generate early warning information in advance, and provide a scientific basis for emergency decision-making by relevant departments.
[0134] In one optional implementation, the public safety risk transmission intensity is obtained by combining the dynamic transmission weight with the risk level of the public safety risk element node along the transmission path. The public safety risk transmission intensity is then accumulated to obtain a public safety risk early warning indicator, including:
[0135] Based on the dynamic transmission weights and risk levels of public safety risk element nodes, the PageRank algorithm is used to calculate the centrality score of the public safety risk element nodes. The centrality score is combined with the dynamic transmission weights to obtain the carrying capacity of the public safety risk element nodes. Based on the PageRank algorithm, the structural importance of the public safety risk element nodes is calculated. The structural importance is combined with the carrying capacity to obtain the failure threshold of the public safety risk element nodes.
[0136] The dynamic transmission weight is combined with the risk level of the public safety risk element node along the transmission path to obtain the public safety risk transmission intensity; based on the public safety risk transmission intensity, it is determined whether the public safety risk element node has reached the failure threshold, and the public safety risk element node that has reached the failure threshold is marked as a trigger node;
[0137] The PageRank algorithm is used to calculate the degree of influence of the triggering node on adjacent public safety risk element nodes on the transmission path. Based on the degree of influence, the propagation impact is determined, and the propagation impact is accumulated to obtain the cumulative effect of public safety risk. Based on the cumulative effect of public safety risk and the intensity of public safety risk transmission, a public safety risk early warning index is calculated.
[0138] Based on the established network of public safety risk element nodes and transmission paths, the centrality score, carrying capacity and failure threshold of the nodes are calculated. Then, it is determined whether the node has reached the failure threshold and the triggering node is marked. Finally, the cumulative effect of public safety risks and early warning indicators are calculated.
[0139] A network of public safety risk element nodes can include multiple different types of risk element nodes, such as natural disaster nodes, accident and disaster nodes, public health nodes, and social security nodes. Specific transmission paths exist between these nodes, along which risks can be transmitted from one node to another.
[0140] The PageRank algorithm is used to calculate the centrality score of nodes representing public safety risk factors. For example, for a network containing 10 nodes representing public safety risk factors, the centrality score of each node can be calculated iteratively. Assume node A has a centrality score of 0.15, node B has a centrality score of 0.12, node C has a centrality score of 0.09, and so on. These centrality scores reflect the importance and influence of each node in the network.
[0141] The carrying capacity of a node is calculated by combining its centrality score with its dynamic transmission weight. Assuming node A has a dynamic transmission weight of 0.8, its carrying capacity can be calculated as 0.15 × 0.8 = 0.12; node B has a dynamic transmission weight of 0.7, so its carrying capacity is 0.12 × 0.7 = 0.084; and node C has a dynamic transmission weight of 0.6, so its carrying capacity is 0.09 × 0.6 = 0.054. Carrying capacity represents the maximum risk intensity a node can withstand.
[0142] The PageRank algorithm is used to calculate the structural importance of nodes representing public safety risk factors. Structural importance reflects the criticality of a node within the network structure. Assuming node A has a structural importance of 0.25, node B has a structural importance of 0.2, and node C has a structural importance of 0.18, combining structural importance with carrying capacity yields the node's failure threshold. For example, the failure threshold for node A can be calculated as 0.25 + 0.12 = 0.37; for node B, 0.2 + 0.084 = 0.284; and for node C, 0.18 + 0.054 = 0.234. The failure threshold represents the critical point at which a node transitions from a normal state to a risky state.
[0143] When risks are transmitted along the transmission path, the dynamic transmission weight is combined with the risk level of the public safety risk element nodes to calculate the public safety risk transmission intensity. Assuming the risk level of node A is 0.5, the risk level of node B is 0.4, and the risk level of node C is 0.3, then the risk transmission intensity from node A to node B can be calculated as 0.8 × 0.5 = 0.4; the risk transmission intensity from node B to node C can be calculated as 0.7 × 0.4 = 0.28.
[0144] Based on the calculated public safety risk transmission intensity, it is determined whether each node has reached the failure threshold. For example, if the risk transmission intensity received by node B is 0.4, which is greater than its failure threshold of 0.284, then node B is marked as a trigger node; if the risk transmission intensity received by node C is 0.28, which is greater than its failure threshold of 0.234, then node C is also marked as a trigger node.
[0145] For a marked trigger node, the PageRank algorithm is used to calculate its influence on neighboring nodes along the propagation path. For example, trigger node B has an influence of 0.35 on its neighboring node D and 0.3 on its neighboring node E. Based on these influence levels, the propagation impact can be determined. Assuming the risk level of node D is 0.25, the propagation impact of B on D can be calculated as 0.35 × 0.25 = 0.0875; assuming the risk level of node E is 0.2, the propagation impact of B on E can be calculated as 0.3 × 0.2 = 0.06.
[0146] The cumulative effect of all propagation impacts is obtained by accumulating them. For example, if there are multiple triggering nodes (B and C) in the system, and the total propagation impact of B is 0.15 and the total propagation impact of C is 0.12, then the cumulative effect of public safety risk is 0.15 + 0.12 = 0.27.
[0147] Based on the cumulative effect and transmission intensity of public safety risks, a public safety risk early warning index is calculated. For example, the early warning index can be obtained by adding the average value of the cumulative effect and transmission intensity of public safety risks. Assuming the average value of the transmission intensity is 0.34, the public safety risk early warning index would be 0.27 + 0.34 = 0.61. This index can be used to guide public safety management departments in taking corresponding prevention and response measures.
[0148] Through the above steps, dynamic monitoring and early warning of public safety risks can be achieved, providing a scientific basis for public safety management decisions. This method considers key characteristics such as the centrality, carrying capacity, and failure threshold of risk element nodes, and can accurately reflect the transmission process and cumulative effect of public safety risks, thus helping to improve the efficiency and accuracy of public safety risk management.
[0149] Figure 5 This is a bar chart comparing the performance of public safety risk transmission models in embodiments of the present invention. The chart illustrates the performance comparison of three different risk assessment models: the basic PageRank model, a fundamental risk assessment algorithm based on webpage importance calculation; the dynamic transmission weight model, a risk transmission assessment method considering the dynamic relationships between network nodes; and the multi-level risk accumulation model, a comprehensive risk assessment model combining the characteristics of multi-level network structures. Specifically, in terms of early warning accuracy, the multi-level risk accumulation model performs best at 89.5%, followed by the dynamic transmission weight model at 78.2%, and the basic PageRank model at 65.8%. Regarding risk transmission recognition rate, all three models show high recognition capabilities, with the multi-level model reaching 91.2%, the dynamic transmission model at 83.7%, and the basic model at 72.3%. In terms of computational efficiency, the basic PageRank model performs best at 93.5%, followed closely by the dynamic transmission weight model at 87.1%, with the multi-level model slightly lower at 84.3%. Overall, the multi-level risk accumulation model performed best in the two core indicators of early warning accuracy and risk transmission identification rate, but it was slightly inferior to the other two models in terms of computational efficiency. This reflects a certain trade-off between model performance and computational complexity.
[0150] A second aspect of the present invention provides an electronic device, comprising:
[0151] processor;
[0152] Memory used to store processor-executable instructions;
[0153] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.
[0154] A third aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.
[0155] This invention can be a method, apparatus, system, and / or computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for performing various aspects of the invention.
[0156] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A knowledge graph-based method for identifying and analyzing the associations of multiple sources of public safety risk factors, characterized in that: include: Acquire public safety multi-source risk factor data, which includes structured public safety risk factor data and unstructured public safety risk factor data; The unstructured public safety risk element data is processed to extract public safety risk element information; The structured public safety risk element data and the processed unstructured public safety risk element data are integrated to construct an initial public safety risk element association network; Feature analysis is performed on the public safety risk element nodes in the initial public safety risk element association network to obtain the feature vectors of the public safety risk element nodes; based on The similarity matrix is calculated from the feature vectors, including: Feature analysis is performed on the public safety risk element nodes in the initial public safety risk element association network. The static attribute feature vector of the security management unit, the public safety time series feature vector, and the security network topology feature vector of the public safety risk element nodes are extracted. The static attribute feature vector of the security management unit, the public safety time series feature vector, and the security network topology feature vector are combined to construct the multi-dimensional feature vector of the public safety risk element nodes. Based on the multi-dimensional feature vectors, a sliding window adaptive clustering method is used to calculate the basic similarity value between the public safety risk element nodes. The sliding window adaptive clustering includes constructing a feature window of a preset size, dynamically grouping the features of the public safety risk element nodes within the feature window, and calculating the similarity between the public safety risk element nodes based on the dynamic grouping; calculating the temporal similarity value between the public safety risk element nodes using the sliding window adaptive clustering method based on the public safety temporal feature vectors; and calculating the topological similarity value between the public safety risk element nodes using the sliding window adaptive clustering method based on the security network topology feature vectors. The initial public safety risk element association network is optimized and reconstructed using the basic similarity value, the temporal similarity value, and the topological similarity value to obtain a similarity matrix between public safety risk element nodes; Community discovery is performed on the similarity matrix to identify subgroups of public safety risk elements with close relationships; a multi-level public safety risk element association network is constructed based on the subgroups of public safety risk elements. A transmission path analysis is performed on the multi-level public safety risk element association network to calculate the transmission weights between public safety risk element nodes. Based on the transmission weights and the analysis results of the multi-level public safety risk element association network, public safety risk early warning information is generated.
2. The method according to claim 1, characterized in that, Integrating the structured public safety risk element data and the processed unstructured public safety risk element data to construct an initial public safety risk element association network includes: The unstructured public safety risk element data is processed to extract the security management unit entity, public safety attributes, and public safety relationship information from the unstructured public safety risk element data, and the security management unit entity, public safety attributes, and public safety relationship information are transformed into a data structure that matches the structured public safety risk element data according to preset mapping rules; The structured public safety risk element data and the transformed unstructured public safety risk element data are integrated according to a preset public safety system to construct an initial public safety risk element association network.
3. The method according to claim 1, characterized in that, Based on the public safety temporal feature vector, the sliding window adaptive clustering is used to calculate the temporal similarity value between the public safety risk element nodes; based on the security network topology feature vector, the sliding window adaptive clustering is used to calculate the topological similarity value between the public safety risk element nodes, including: A sliding window with a preset size is constructed, which is used to extract the feature vectors of public safety risk element nodes in segments; Based on the sliding window, the temporal feature vectors of the public safety risk element nodes are segmented to extract local temporal features of public safety, and adaptive clustering is used to calculate the temporal similarity value between the public safety risk element nodes; based on the sliding window, the topological feature vectors of the public safety risk element nodes are segmented to extract local topological features of the security network, and adaptive clustering is used to calculate the topological similarity value between the public safety risk element nodes.
4. The method according to claim 1, characterized in that, Community discovery is performed on the similarity matrix to identify subgroups of public safety risk elements with close relationships; a multi-level public safety risk element association network is constructed based on these subgroups, including: For each security management node in the similarity matrix, the community affiliation strength based on the edge weights between neighboring security management nodes is calculated. The community label of the security management node is iteratively calculated and continuously updated according to the community affiliation strength until the distribution of the community label tends to stabilize and converge, resulting in a community partitioning result containing multiple initial security management communities. For each security management community in the community partitioning results, its cohesion is calculated. The cohesion is quantified based on the edge weight relationship between security management nodes within the community. Security management communities with a cohesion greater than a preset cohesion threshold are marked as stable communities. Security management communities with a cohesion less than the preset cohesion threshold are recursively decomposed into multiple security management sub-communities with higher cohesion. The association strength of the security management sub-communities is calculated based on the distribution characteristics of the internal nodes of the security management sub-communities and the connection relationship between the sub-communities. Based on the stable community, the security management sub-community, and the association strength, the inter-layer edge weights are dynamically updated and optimized to obtain a multi-level public safety risk element association network with a complete hierarchical structure.
5. The method according to claim 1, characterized in that, A transmission path analysis is performed on the multi-level public safety risk element association network to calculate the transmission weights between public safety risk element nodes. Based on the transmission weights and the analysis results of the multi-level public safety risk element association network, public safety risk early warning information is generated, including: Obtain the transmission path between public safety risk element node pairs in the multi-level public safety risk element association network, obtain historical transmission data of the public safety risk element nodes at different times based on the transmission path, obtain the transmission feature vector, and calculate the temporal dependency relationship between the public safety risk element node pairs based on the transmission feature vector. Based on the time-series dependency, a time-series decay factor is calculated by combining the time difference between the current moment and the historical moment. The time-series dependency is multiplied by the time-series decay factor to obtain the initial transmission weight between the public safety risk element node pairs. The initial transmission weight is adjusted based on the connection relationship of the public safety risk element nodes in the transmission path to obtain the dynamic transmission weight; The dynamic transmission weight is combined with the risk level of the public safety risk element node along the transmission path to obtain the public safety risk transmission intensity. The public safety risk transmission intensity is accumulated to obtain the public safety risk early warning index. When the public safety risk early warning index exceeds the preset early warning threshold, public safety risk early warning information is generated.
6. The method according to claim 5, characterized in that, The public safety risk transmission intensity is obtained by combining the dynamic transmission weight with the risk level of the public safety risk element nodes along the transmission path. The public safety risk transmission intensity is then accumulated to obtain public safety risk early warning indicators, including: Based on the dynamic transmission weights and risk levels of public safety risk element nodes, the PageRank algorithm is used to calculate the centrality score of the public safety risk element nodes. The centrality score is then combined with the dynamic transmission weights to obtain the carrying capacity of the public safety risk element nodes. The structural importance of the public safety risk element node is calculated based on the PageRank algorithm, and the failure threshold of the public safety risk element node is obtained by combining the structural importance with the carrying capacity. The public safety risk transmission intensity is obtained by combining the dynamic transmission weight with the risk level of the public safety risk element node along the transmission path. Based on the intensity of the transmission of public safety risks, it is determined whether the public safety risk element node has reached the failure threshold, and the public safety risk element node that has reached the failure threshold is marked as a trigger node; The PageRank algorithm is used to calculate the degree of influence of the triggering node on adjacent public safety risk element nodes on the transmission path. Based on the degree of influence, the propagation impact is determined, and the propagation impact is accumulated to obtain the cumulative effect of public safety risk. Based on the cumulative effect of public safety risk and the intensity of public safety risk transmission, a public safety risk early warning index is calculated.
7. An electronic device, characterized in that, include: processor; Memory used to store processor-executable instructions; The processor is configured to invoke instructions stored in the memory to execute the method according to any one of claims 1 to 6.
8. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, they implement the method described in any one of claims 1 to 6.
Citation Information
Patent Citations
Method and system for identifying risk communities
CN111738817A
Knowledge graph-based information processing method and device, equipment and storage medium
CN112699249A