Context-aware driven multi-dimension anomaly detection and early warning method

By generating an initial feature set containing environmental parameter sequences and behavioral pattern maps, an adapted detection model is constructed and dynamic early warning commands are triggered. This solves the problems of lag, false alarms, and missed alarms in traditional anomaly detection methods in complex scenarios, and achieves efficient and accurate anomaly detection and early warning.

CN120748147BActive Publication Date: 2025-11-21山西益通电网保护自动化有限责任公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511261277.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-05
Publication Date
2025-11-21
Estimated Expiration
2045-09-05

AI Technical Summary

Technical Problem

Traditional anomaly detection methods rely on single-dimensional feature data, which makes it difficult to cope with the challenges brought about by dynamic changes in context in complex scenarios. This leads to delayed warnings, false alarms, or missed alarms. Furthermore, the models lack generalization ability when applied across different scenarios and cannot flexibly switch detection models based on real-time monitoring data.

Method used

Collect real-time contextual data of the target monitoring scene, generate an initial feature set including environmental parameter sequences and behavioral pattern maps, construct a first detection model and a second detection model adapted to the scene type, trigger dynamic early warning instructions based on real-time monitoring data, and adjust the trigger threshold of the abnormal response strategy and the priority of the risk handling process.

Benefits of technology

It enables comprehensive detection of environmental parameters and behavioral patterns, improves the accuracy and real-time performance of anomaly detection, dynamically adjusts response strategies to adapt to complex scenarios, avoids missed and false alarms, and improves the operating efficiency of the monitoring system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120748147B_ABST
    Figure CN120748147B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of anomaly detection and discloses a context-aware driven multi-dimensional anomaly detection early warning method. Real-time context data in a target monitoring scene is collected to generate an initial feature set containing an environmental parameter sequence and a behavior pattern atlas; a first detection model and a second detection model adapted to the scene type are respectively constructed according to the initial feature set, the first model contains a dynamic correlation function of environmental indexes and anomaly probabilities, and the second model contains a nonlinear mapping rule of behavior features and risk levels; based on real-time context deviation and a feature fluctuation coefficient, a dynamic early warning instruction is triggered to generate a target model, and the early warning instruction is pushed to an execution module to adjust a trigger threshold of an abnormal response strategy or a priority of a risk disposal process. The method combines multi-dimensional data, triggers a dynamic model, adjusts a response strategy, improves the adaptability and accuracy of anomaly detection, and is suitable for various monitoring scenes.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of anomaly detection, in particular to a context-aware multi-dimensional anomaly detection and early warning method. BACKGROUND

[0002] With the rapid development of Internet of Things and artificial intelligence technologies, various monitoring scenarios have increasingly high requirements for the real-time performance and accuracy of anomaly detection. In the fields of industrial production, intelligent security, and environmental monitoring, traditional anomaly detection methods mostly rely on single-dimensional feature data, such as determining anomalies only by fixed threshold values of environmental parameters or assessing risks only based on static features of behavior patterns. Such single-dimensional detection methods are difficult to cope with the challenges brought by dynamic changes in context in complex scenarios.

[0003] In industrial production scenarios, the operating state of equipment is not only affected by environmental parameters such as temperature and pressure, but also closely related to the operation process of operators and the collaborative behavior between equipment. Traditional methods only provide early warnings by setting fixed threshold values of environmental parameters. When the environmental parameters fluctuate slightly around the threshold values but the operation behavior has already shown abnormal trends, the traditional methods often fail to identify the situation in time, resulting in delayed early warnings. In the field of intelligent security, the behavior patterns of personnel flow have strong dynamics, and the normal behavior features in different time periods and different regions differ significantly. Traditional detection models based on static behavior feature libraries are difficult to adapt to such dynamic changes and are prone to false positives or false negatives, such as misjudging temporarily adjusted patrol routes as abnormal behavior or failing to respond in time to sudden group gathering behavior.

[0004] The field of environmental monitoring also faces similar problems. In natural environments, changes in parameters such as temperature, humidity, and pollutant concentration are closely related to context factors such as biological activities and weather conditions. Traditional methods only provide early warnings based on whether the pollutant concentration exceeds the standard, ignoring the influence of biological activities in different seasons and time periods on the diffusion of pollutants, resulting in a situation where, in some cases, the pollutant concentration does not exceed the standard but there is a potential risk when combined with abnormal biological activities, and an effective early warning cannot be issued. In addition, the response strategies of traditional anomaly detection models are mostly fixed patterns. Once an early warning is triggered, the execution module performs disposal according to the preset process, and it is difficult to adjust the response priority according to the real-time risk level. When multiple anomalies occur simultaneously, it is easy to cause unreasonable allocation of resources and affect disposal efficiency.

[0005] In the prior art, some improved detection methods attempt to combine multi-dimensional data, but do not fully consider the adaptability of scene types when constructing the model, resulting in insufficient generalization ability of the model when applied across scenes. At the same time, these methods lack dynamic perception of context deviation and feature fluctuation coefficient, and cannot flexibly switch detection models according to real-time monitoring data, limiting the adaptability and flexibility of anomaly detection. After the generation of early warning instructions, the response strategy adjustment of the execution module is mostly static adjustment, which cannot optimize the triggering threshold and disposition process priority in real time according to the dynamic early warning result, and it is difficult to meet the precise and efficient anomaly detection requirements in complex scenarios. SUMMARY

[0006] The purpose of the present application is to provide a context-aware multi-dimensional anomaly detection and early warning method to solve the problems raised in the background art.

[0007] To achieve the above purpose, the present application provides a context-aware multi-dimensional anomaly detection and early warning method, which comprises:

[0008] Collecting real-time context data in the target monitoring scene to generate an initial feature set, the initial feature set including an environmental parameter sequence and a behavior pattern graph;

[0009] According to the environmental parameter sequence in the initial feature set, a first detection model adapted to the scene type is constructed, the first detection model including a dynamic association function of environmental indicators and anomaly probability;

[0010] According to the behavior pattern graph in the initial feature set, a second detection model adapted to the scene type is constructed, the second detection model including a nonlinear mapping rule of behavior features and risk levels;

[0011] Based on the context deviation data and feature fluctuation coefficient data in the real-time monitoring process, triggering the target model in the first detection model or the second detection model, and generating a dynamic early warning instruction through the target model;

[0012] Pushing the dynamic early warning instruction to the execution module of the monitoring system to adjust the triggering threshold of the abnormal response strategy or the priority of the risk disposition process.

[0013] Preferably, collecting real-time context data in the target monitoring scene to generate an initial feature set comprises:

[0014] Synchronously collecting environmental state data of the target scene within the monitoring period through multi-source perception devices, the environmental state data including a physical parameter time sequence stream and a logical state encoding set;

[0015] According to the feature interval in the physical parameter time sequence flow, the target scene is divided into at least two sub-scene units, and each sub-scene unit is assigned a corresponding initial monitoring threshold range and risk assessment reference value;

[0016] The historical environment correction parameters and behavior characteristic compensation coefficients matched with each sub-scene unit are extracted from a preset feature library;

[0017] The historical environment correction parameters are subjected to spatio-temporal alignment processing to generate an optimized environment parameter sequence corresponding to each sub-scene unit;

[0018] The behavior characteristic compensation coefficients are subjected to trend smoothing processing to generate an optimized behavior mode atlas corresponding to each sub-scene unit;

[0019] The initial feature set is fused and generated according to the optimized environment parameter sequence and the optimized behavior mode atlas of each sub-scene unit.

[0020] Preferably, the first detection model and the second detection model are constructed, including:

[0021] The optimized environment parameter sequence is input into a preset rule inference engine, the rule weight is iteratively updated through multiple rounds of condition matching, an abnormal probability calculation function in the first detection model is generated, and the abnormal probability calculation function is a target model in the first detection model;

[0022] The optimized behavior mode atlas is input into a statistical feature extraction module, key behavior indicators are screened through a feature dimension reduction algorithm, a risk level division matrix in the second detection model is generated, and the risk level division matrix is a target model in the second detection model;

[0023] After the rule inference engine and the statistical feature extraction module are stable, core parameter vectors in the abnormal probability calculation function and the risk level division matrix are extracted, respectively;

[0024] The core parameter vectors are associated with real-time collected environment state data for relevance analysis to verify the applicability of the first detection model and the second detection model;

[0025] When the relevance analysis result is lower than a preset threshold, the matching conditions of the rule inference engine and the dimension reduction parameters of the statistical feature extraction module are readjusted until the core parameter vectors meet the applicability conditions.

[0026] Preferably, based on the context deviation degree data and the feature fluctuation coefficient data in the real-time monitoring process, a target model in the first detection model or the second detection model is triggered, a dynamic early warning instruction is generated through the target model, and the dynamic early warning instruction includes:

[0027] Real-time tracking of the context deviation change curve and the characteristic fluctuation coefficient amplitude;

[0028] When the context deviation change curve exceeds the first trigger threshold and the characteristic fluctuation coefficient amplitude is within the preset safe interval, triggering the anomaly probability calculation function in the first detection model;

[0029] According to the probability distribution rule in the anomaly probability calculation function, a dynamic threshold adjustment instruction for the anomaly response strategy is generated;

[0030] When the characteristic fluctuation coefficient amplitude exceeds the second trigger threshold and the context deviation change curve is within the preset stable interval, triggering the risk level division matrix in the second detection model;

[0031] According to the level judgment rule in the risk level division matrix, a dynamic priority adjustment instruction for the risk disposal process is generated;

[0032] If the context deviation change curve and the characteristic fluctuation coefficient amplitude exceed the trigger threshold at the same time, the dynamic threshold adjustment instruction generated by the first detection model is preferentially executed, and the adjustment instruction of the second detection model is delayed until the threshold update of the anomaly response strategy is completed.

[0033] Preferably, the execution module for pushing the dynamic early warning instruction to the monitoring system adjusts the trigger threshold of the anomaly response strategy or the priority of the risk disposal process, comprising:

[0034] According to the threshold compensation value in the dynamic threshold adjustment instruction, the judgment threshold of each early warning level in the anomaly response strategy is updated in stages;

[0035] After each threshold update, real-time anomaly probability data is collected and deviation analysis is performed with the predicted value of the anomaly probability calculation function;

[0036] If the deviation value continues to decrease, the current threshold adjustment direction is maintained until the target probability interval is reached;

[0037] If the deviation value shows an upward trend, the judgment threshold is adjusted in the opposite direction and the parameter optimization of the anomaly probability calculation function is retriggered;

[0038] According to the priority parameter in the dynamic priority adjustment instruction, the execution order of the risk disposal process in different scenarios is dynamically configured;

[0039] During the priority adjustment process, the risk disposal effect is monitored in real time through a state feedback mechanism, and the level weight in the risk level division matrix is dynamically updated according to the monitoring result.

[0040] Preferably, the method further comprises an effect calibration stage after the dynamic early warning instruction is executed, including the following operations:

[0041] Collecting final abnormality mitigation data and risk level retest results after the early warning treatment is completed;

[0042] Comparing the final abnormality mitigation data with the predicted mitigation range of the first detection model to generate an abnormality detection error signal;

[0043] Conducting consistency analysis on the risk level retest results and the expected level standard of the second detection model to generate a risk assessment error signal;

[0044] Adjusting the probability distribution rule in the first detection model according to the systematic bias component in the abnormality detection error signal;

[0045] Optimizing the level weight coefficient in the second detection model according to the random fluctuation component in the risk assessment error signal;

[0046] Synchronously updating the adjusted probability distribution rule and level weight coefficient to the historical feature library of the initial feature set.

[0047] Preferably, the process of adjusting the probability distribution rule and the level weight coefficient includes:

[0048] Identifying the static bias component in the abnormality detection error signal and calculating a static compensation value through a sliding average filtering method;

[0049] Adjusting the reference probability threshold in the abnormal probability calculation function according to the static compensation value;

[0050] Identifying the dynamic interference component in the risk assessment error signal and extracting an effective correction parameter through an adaptive filtering algorithm;

[0051] Adjusting the level judgment threshold in the risk level division matrix according to the effective correction parameter;

[0052] Replacing the original model parameters with the updated abnormal probability calculation function and risk level division matrix.

[0053] Preferably, the method further comprises the following initialization operations before the system is started, including:

[0054] Parsing the environmental feature identifier and behavior pattern coding segment in the scene type coding corresponding to the target scene to generate a scene feature description vector;

[0055] Inputting the scene feature description vector into the preloaded scene configuration database for multidimensional matching retrieval to filter out a candidate reference configuration set with a matching degree exceeding an adaptation threshold with the current scene type coding.

[0056] performing the following operations on each candidate reference configuration in the candidate reference configuration set: extracting the average abnormality detection rate and risk level accuracy in its historical application record, calculating a comprehensive configuration performance score;

[0057] According to the comprehensive configuration performance score, the candidate reference configuration set is prioritized, and the candidate reference configuration with the highest score is selected as the optimal reference environment parameter template;

[0058] extracting a behavior pattern reference set with configuration correlation with the optimal reference environment parameter template from the scene configuration database;

[0059] For each pattern data in the behavior pattern reference set, the synergy of the pattern feature and the environment parameter is verified, and the abnormal pattern with feature conflict or parameter contradiction is eliminated to generate an optimized behavior pattern reference set;

[0060] According to the historical running stability index of each optimized behavior pattern reference in the optimized behavior pattern reference set, the optimized behavior pattern reference with the smallest fluctuation index is selected as the optimal behavior pattern reference;

[0061] The optimal reference environment parameter template and the optimal behavior pattern reference are configured in time sequence to generate a reference parameter configuration of the initial feature set.

[0062] Preferably, the synergy verification of the pattern feature and the environment parameter for each pattern data in the behavior pattern reference set comprises:

[0063] Extracting the feature data of a single to-be-verified pattern from the behavior pattern reference set, and synchronously acquiring the environment parameter sequence in the optimal reference environment parameter template that is time-aligned with the to-be-verified pattern;

[0064] According to the change node of the environment parameter sequence, a corresponding synergy time marker is labeled on the to-be-verified pattern to generate a pattern feature curve with time sequence identification;

[0065] Traversing each synergy time marker in the pattern feature curve with time sequence identification, detecting whether the feature change rate in its adjacent time window exceeds a preset mutation threshold, and identifying an abnormal time window with feature mutation;

[0066] When an abnormal time window is identified, the environment parameter value of the corresponding time node in the optimal reference environment parameter template is traced back, and it is judged whether the change direction of the environment parameter value has a reverse effect on the direction of the feature mutation;

[0067] If the reverse influence intensity exceeds the conflict threshold, the abnormal time window is marked as a parameter conflict region, and a starting position and a duration of the parameter conflict region in a mode characteristic curve are calculated;

[0068] According to the starting position and the duration of the parameter conflict region, a characteristic correction window is demarcated on the to-be-verified mode, and a replacement characteristic smooth segment is generated based on correction records of the same conflict in a historical characteristic library;

[0069] The replacement characteristic smooth segment is inserted into the characteristic correction window, an optimized behavior mode curve is generated, and abnormal data points overlapping the parameter conflict region in the original mode characteristic curve are deleted;

[0070] The optimized behavior mode curves in the behavior mode reference set that have completed the replacement insertion operation are subjected to integrity verification, and residual curves still containing uncorrected conflict regions are removed;

[0071] The optimized behavior mode curves passing the verification are merged into the optimized behavior mode benchmark set.

[0072] Preferably, the determination threshold of each early warning level in the phased updating of the abnormal response strategy comprises:

[0073] A stage interval of threshold updating is determined based on the change rate of the environmental parameter sequence, and a total adjustment interval is divided into at least three continuous sub-adjustment stages;

[0074] A corresponding threshold adjustment step is allocated to each sub-adjustment stage, and the threshold adjustment step is increased by a preset proportion with the progress of the stage;

[0075] After each sub-adjustment stage is executed, the deviation rate of the average abnormal probability of the current stage from the target probability interval is collected;

[0076] If the deviation rate is less than the stage threshold, the next sub-adjustment stage is entered; if the deviation rate is greater than or equal to the stage threshold, the current updating process is paused and the parameter recalibration of the abnormal probability calculation function is triggered;

[0077] After all the sub-adjustment stages are completed, the determination threshold of each early warning level is subjected to final verification to ensure that the difference between adjacent level thresholds meets the preset gradient requirement.

[0078] Compared with the prior art, the present application has the following beneficial effects:

[0079] By collecting real-time context data in the target monitoring scene, an initial feature set containing environmental parameter sequences and behavior pattern maps is generated, changing the limitations of traditional anomaly detection relying on single-dimensional data. This multi-dimensional data collection method can fully capture the dynamic changes in the monitoring scene, whether it is the subtle fluctuations of environmental parameters or the complex correlations of behavior patterns, which can be effectively included in the detection range, making the basic data of anomaly detection more rich and comprehensive.

[0080] In terms of model construction, the first detection model and the second detection model are constructed according to the environmental parameter sequence and the behavior pattern map, respectively, which are adapted to the scene type, so that the model can better fit the characteristics of different scenes. The first detection model contains a dynamic correlation function between environmental indicators and anomaly probability, and the second detection model contains a nonlinear mapping rule between behavior features and risk levels. This targeted model design allows different types of feature data to be processed in the most suitable way, avoiding the poor adaptability of traditional general models in specific scenes and improving the recognition accuracy of the model for abnormal features.

[0081] Based on the context deviation data and feature fluctuation coefficient data in the real-time monitoring process, the corresponding target model is triggered and dynamic warning instructions are generated, realizing the flexible switching of the detection model. When the deviation of environmental parameters in the monitoring data exceeds the normal range, the first detection model is triggered accurately; when the feature fluctuation coefficient of the behavior pattern is abnormal, the second detection model responds in time. This dynamic triggering mechanism allows anomaly detection to adjust the detection focus according to real-time conditions, avoiding the false negative or false positive situations of traditional fixed models in complex scenes, and enhancing the real-time and pertinence of anomaly detection.

[0082] The dynamic warning instructions are pushed to the execution module to adjust the trigger threshold of the abnormal response strategy or the priority of the risk disposal process, realizing the dynamic optimization of abnormal response. Under different warning levels, the execution module can flexibly adjust the response strategy according to the instructions. When the warning level is high, the trigger threshold is reduced and the disposal process priority is increased to speed up the response; when the warning level is low, the trigger threshold is appropriately increased and the disposal process order is adjusted to avoid unnecessary consumption of resources. This dynamic adjustment mechanism makes the abnormal response more suitable for the actual risk situation, improving the operation efficiency of the entire monitoring system.

[0083] The method drives by context perception, and the association between environmental parameters and behavior patterns is included in the detection logic, so that the anomaly detection is no longer isolated parameter judgment or behavior recognition, but comprehensive consideration of the mutual influence of various factors in the scene. In industrial production, the change of equipment environment and operation behavior specification can be considered at the same time, in intelligent security, the risk can be judged by combining personnel behavior and environmental change, in environmental monitoring, the anomaly can be evaluated by associating natural factors and human activities, so that more accurate anomaly detection and early warning can be realized in various scenes. BRIEF DESCRIPTION OF DRAWINGS

[0084] Figure 1 The working principle diagram of the context perception driven multi-dimensional anomaly detection and early warning method described in the application;

[0085] Figure 2 The flowchart for generating the initial feature set;

[0086] Figure 3 The flowchart for early warning effect calibration and model optimization;

[0087] Figure 4 The flowchart for probability distribution rule and grade weight coefficient adjustment;

[0088] Figure 5 The flowchart for system initialization and baseline configuration generation. DETAILED DESCRIPTION

[0089] The technical solutions in the embodiments of the application will be described clearly and completely below with reference to the drawings in the embodiments of the application. Obviously, the described embodiments are only part of the embodiments of the application, not all. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the application.

[0090] Please refer to Figures 1-5 The application provides a context perception driven multi-dimensional anomaly detection and early warning method, which comprises:

[0091] Collecting real-time context data in a target monitoring scene to generate an initial feature set, the initial feature set including an environmental parameter sequence and a behavior pattern graph;

[0092] According to the environmental parameter sequence in the initial feature set, a first detection model adapted to the scene type is constructed, the first detection model including a dynamic association function of environmental indicators and anomaly probability;

[0093] According to the behavior pattern graph in the initial feature set, a second detection model adapted to the scene type is constructed, the second detection model including a nonlinear mapping rule of behavior characteristics and risk level;

[0094] Based on the context deviation data and the feature fluctuation coefficient data in the real-time monitoring process, a target model in the first detection model or the second detection model is triggered, and a dynamic early warning instruction is generated through the target model;

[0095] The dynamic early warning instruction is pushed to an execution module of the monitoring system, and a trigger threshold of an abnormal response strategy or a priority of a risk disposal process is adjusted.

[0096] Embodiment 1:

[0097] The environment state data of the target scene in the monitoring period is synchronously collected by the multi-source perception device, and the environment state data includes a physical parameter time sequence stream and a logic state code set. The multi-source perception device covers temperature sensors, humidity sensors, infrared detectors, motion capture devices, etc. These devices work cooperatively according to a preset sampling frequency, so as to ensure that the dynamic changes of the target scene can be comprehensively captured in the monitoring period. The physical parameter time sequence stream is composed of continuously collected physical quantities, such as a temperature time sequence stream formed by temperature values at different time points, a humidity time sequence stream formed by humidity values, etc. These data are indexed by time stamps, and constitute a continuous data stream. The logic state code set is a coded representation of discrete events or states in the scene, for example, the running state of a device can be coded as “001” to represent normal operation, “010” to represent standby, and “100” to represent failure, and the occupancy of an area can be coded as “1” to represent someone and “0” to represent no one, etc. These codes are arranged in chronological order, forming a logic state sequence corresponding to the physical parameter time sequence stream.

[0098] In the synchronous collection process of the multi-source perception device, for the massive environment state data (including the physical parameter time sequence stream and the logic state code set), a distributed file system is used for storage, a stream processing framework such as Spark Streaming is used to realize real-time reception and preliminary processing of high-concurrency data, a data sharding technology is used to divide the continuous physical parameter time sequence stream into a data set that can be processed in parallel according to a time window, a preset data cleaning rule (such as eliminating sensor abnormal drift data and supplementing missing logic state codes) is used for batch processing, and a distributed computing node is used to extract feature data of different sub-scene units in parallel, so as to greatly improve the processing efficiency of the massive context data and provide efficient data support for subsequent generation of an initial feature set.

[0099] According to the characteristic interval in the time sequence flow of the physical parameter, the target scene is divided into at least two sub-scene units, and each sub-scene unit is assigned a corresponding initial monitoring threshold range and risk assessment reference value. The division of the characteristic interval is based on the distribution characteristics of the physical parameter. For example, in a large warehouse, according to the distribution of the temperature parameter, the region with a temperature of 25-30°C can be divided into a characteristic interval, and the region with a temperature of 30-35°C can be divided into another characteristic interval, each of which corresponds to a sub-scene unit. After the division is completed, for each sub-scene unit, the initial monitoring threshold range is determined in combination with its functional attributes and historical monitoring data. For example, for a sub-scene unit storing flammable goods in the warehouse, the initial monitoring threshold range of the temperature can be set to 20-28°C, and for a general goods storage area, the initial monitoring threshold range of the temperature can be set to 18-32°C. The risk assessment reference value is determined according to the value of the goods in the sub-scene unit, the influence range after the occurrence of an anomaly, and other factors. The higher the value and the greater the influence range of the sub-scene unit, the lower the risk assessment reference value is set, so as to improve the attention to the area.

[0100] The historical environmental correction parameters and behavior characteristic compensation coefficients matching each sub-scene unit are extracted from the preset feature library. The preset feature library stores historical data in different scenes and different time periods, including environmental correction parameters and behavior characteristic compensation coefficients of past same or similar sub-scene units under various conditions. In the extraction process, by comparing the characteristic interval, functional attributes and other information of the current sub-scene unit with the information recorded in the preset feature library, the historical data with the highest similarity are filtered out, and the corresponding historical environmental correction parameters and behavior characteristic compensation coefficients are extracted. For example, for a sub-scene unit with a temperature characteristic interval of 25-30°C in the current warehouse, the historical environmental correction parameters of the same temperature interval sub-scene unit in the past warehouse of the same type are found from the preset feature library, such as the temperature correction value caused by seasonal changes, and the behavior characteristic compensation coefficients, such as the behavior correction coefficient of personnel in the area.

[0101] The historical environment correction parameters are processed by spatio-temporal alignment to generate a sequence of optimized environment parameters corresponding to each sub-scene unit. The spatio-temporal alignment processing includes two parts: time alignment and space alignment. Time alignment is to calibrate the historical environment correction parameters collected at different times according to the time axis, eliminate time deviation, for example, adjust the correction parameters collected at the same time period on different dates in the past to the same time dimension for processing. Space alignment is to map the parameters collected at different positions to the corresponding spatial coordinates according to the spatial layout of the sub-scene unit, ensuring the consistency of the parameters in space, for example, for the environment correction parameters of different shelf areas in the warehouse, the spatial position relationship of the shelves is integrated to make the parameters accurately reflect the environment correction of different spatial points in the sub-scene unit. After spatio-temporal alignment processing, the historical environment correction parameters and the real-time environment data of the current sub-scene unit are consistent in time and space, and then the optimized environment parameter sequence is integrated and generated, which can more accurately reflect the environmental characteristics of the sub-scene unit.

[0102] The behavior feature compensation coefficient is processed by trend smoothing to generate an optimized behavior pattern map corresponding to each sub-scene unit. The behavior feature compensation coefficient may be affected by various random factors and have certain fluctuations. Trend smoothing is to eliminate these random fluctuations and highlight the overall trend of the behavior feature. In the processing process, the moving average method can be used to select a certain time window, calculate the average of the behavior feature compensation coefficients in the window, obtain the smoothed coefficient value, arrange these smoothed coefficient values in time order, and form a preliminary behavior pattern map. Then, the abnormal points in the map are corrected, for example, when the coefficient value at a certain time and the coefficient value at the adjacent time differ too much and have no reasonable explanation, the abnormal point is replaced by the average value of the adjacent time coefficient value, and finally an optimized behavior pattern map is generated, which can clearly show the change trend of the behavior feature in the sub-scene unit.

[0103] According to the optimized environment parameter sequence and the optimized behavior pattern atlas of each sub-scene unit, an initial feature set is fused. In the fusion process, the optimized environment parameter sequence and the optimized behavior pattern atlas of each sub-scene unit are taken as basic elements, and are integrated according to the spatial position relationship and the logical association of the sub-scene units in the target scene. For example, in the warehouse scene, the optimized environment parameter sequence and the optimized behavior pattern atlas of each shelf area are combined according to the arrangement order of the shelves, and the mutual influence between different sub-scene units is considered, such as the environment parameter changes of adjacent shelf areas may influence each other, and the influence relationship needs to be considered in the fusion. Through such fusion processing, the scattered sub-scene unit features are integrated into a unified whole, forming an initial feature set that can comprehensively and accurately reflect the initial state of the target monitoring scene. The set contains all key feature information of the target scene in terms of environment and behavior, and provides basic data for subsequent model construction and anomaly detection.

[0104] Embodiment 2

[0105] The optimized environment parameter sequence is input into a preset rule inference engine, and the rule inference engine includes multiple groups of initial rules, each group of rules corresponding to an association relationship between an environment parameter and an abnormal situation. Through multiple rounds of condition matching, the rule weight is iteratively updated. In each round of matching, the data in the optimized environment parameter sequence is compared with the rules in the rule inference engine, and the weight of the corresponding rule is adjusted according to the matching degree. The higher the matching degree, the more the weight increases, and vice versa. After multiple iterations, an abnormal probability calculation function in the first detection model is generated, which is the target model in the first detection model.

[0106] The optimized behavior pattern atlas is input into a statistical feature extraction module, and the statistical feature extraction module uses a feature dimension reduction algorithm to process the behavior features in the atlas. The feature dimension reduction algorithm can reduce the feature dimension and retain the key information, and by screening out the key behavior indicators that have a greater impact on the risk level, a risk level division matrix in the second detection model is generated, which is the target model in the second detection model.

[0107] After the rule inference engine and the statistical feature extraction module are stable, the core parameter vectors in the abnormal probability calculation function and the risk level division matrix are extracted, respectively. The core parameter vector is a key parameter set that determines the output result of the model, and contains the most representative parameters in the function and the matrix.

[0108] The core parameter vector is analyzed for relevance with the real-time collected environment state data, and the applicability of the first detection model and the second detection model is verified by calculating the correlation between the two. When the relevance analysis result is lower than the preset threshold, the matching conditions of the rule reasoning engine are re-adjusted, such as modifying the trigger threshold of the rule, adding or deleting part of the rule, and adjusting the dimension reduction parameters of the statistical feature extraction module, such as changing the iteration number of the dimension reduction algorithm, adjusting the threshold of feature screening, and the like, until the core parameter vector meets the applicability condition.

[0109] Based on the context deviation degree data and the feature fluctuation coefficient data in the real-time monitoring process, the target model in the first detection model or the second detection model is triggered, and the process of generating a dynamic early warning instruction is as follows:

[0110] The context deviation degree change curve and the feature fluctuation coefficient amplitude in the real-time tracking monitoring process are monitored. The context deviation degree change curve is obtained by calculating the deviation degree of the real-time context data from the normal context data, and can intuitively reflect the change trend of the context; the feature fluctuation coefficient amplitude is a quantitative representation of the fluctuation size of the feature data.

[0111] When the context deviation degree change curve exceeds the first trigger threshold and the feature fluctuation coefficient amplitude is in the preset safe interval, it indicates that the current anomaly is mainly caused by the environmental parameter anomaly, and at this time the anomaly probability calculation function in the first detection model is triggered. According to the probability distribution rule in the anomaly probability calculation function, combined with the real-time environmental parameter data, the probability of anomaly occurrence is calculated, and then a dynamic threshold adjustment instruction of the anomaly response strategy is generated, which is used to adjust the determination threshold of each early warning level in the anomaly response strategy.

[0112] When the feature fluctuation coefficient amplitude exceeds the second trigger threshold and the context deviation degree change curve is in the preset stable interval, it indicates that the anomaly is mainly caused by the abnormal behavior mode, and at this time the risk level division matrix in the second detection model is triggered. According to the level determination rule in the risk level division matrix, the real-time behavior feature data is analyzed to determine the corresponding risk level, and a dynamic priority adjustment instruction of the risk disposal process is generated, which is used to adjust the execution order of the risk disposal process.

[0113] If the context deviation degree change curve and the feature fluctuation coefficient amplitude exceed the trigger threshold at the same time, it indicates that both the environment and the behavior are abnormal, at this time the dynamic threshold adjustment instruction generated by the first detection model is preferentially executed, and after the threshold of the anomaly response strategy is updated, the adjustment instruction of the second detection model is executed, to ensure the orderliness and effectiveness of the anomaly processing.

[0114] Embodiment 3:

[0115] The phase interval of threshold updating is determined based on the change rate of the sequence of environmental parameters, which is calculated by the change amount of the environmental parameters per unit time. The greater the change rate, the shorter the phase interval is set to quickly adapt to the dramatic changes in the environment. For example, when the environmental temperature rises by 5°C in 1 minute, the phase interval can be set to 10 seconds; while when the temperature rises by only 1°C in 1 minute, the phase interval can be set to 30 seconds. According to the determined phase interval, the total adjustment interval is divided into at least three consecutive sub-adjustment phases, and the total adjustment interval is the range of the threshold value that needs to be adjusted, such as adjusting from the initial threshold value 50 to the target threshold value 70, the total adjustment interval is 20, and if it is divided into three sub-adjustment phases, the adjustment interval of each sub-adjustment phase can be further allocated according to the phase interval and the change rate.

[0116] A corresponding threshold adjustment step is allocated to each sub-adjustment phase, and the threshold adjustment step is increased by a preset proportion as the phase progresses. The preset proportion can be determined according to historical adjustment data, such as increasing by a proportion of 1.2 times, the step of the first sub-adjustment phase is 2, the step of the second sub-adjustment phase is 2.4, the step of the third sub-adjustment phase is 2.88, etc. After each sub-adjustment phase is executed, the deviation rate of the average of the abnormal probability of the current phase and the target probability interval is collected, and the calculation formula of the deviation rate is:

[0117]

[0118] Wherein, represents the deviation rate, represents the average of the abnormal probability of the current phase, represents the middle value of the target probability interval.

[0119] If the deviation rate is less than the phase threshold value, the next sub-adjustment phase is entered; if the deviation rate is greater than or equal to the phase threshold value, the current updating process is suspended and the parameter recalibration of the abnormal probability calculation function is triggered. During the parameter recalibration process, the weight coefficients and reference parameters in the abnormal probability calculation function are re-adjusted to improve the prediction accuracy of the function. After all the sub-adjustment phases are completed, the final check is performed on the determination threshold values of each warning level to check whether the difference between the adjacent level threshold values meets the preset gradient requirement, such as the threshold value difference between the adjacent two levels needs to be kept above 5 to ensure that the warning level division is clear and avoids confusion.

[0120] After each threshold update, real-time anomaly probability data is collected and analyzed for deviation from the predicted value of the anomaly probability calculation function. Deviation analysis is achieved by calculating the difference between real-time anomaly probability data and the predicted value. If the deviation value continues to decrease, it indicates that the current threshold adjustment direction is correct, and the direction is maintained until the target probability interval is reached. If the deviation value shows an upward trend, it indicates that the current adjustment direction has a problem, and the decision threshold needs to be adjusted in the opposite direction, and the parameter optimization of the anomaly probability calculation function is triggered again. Parameter optimization includes adjusting the feature weights and threshold coefficients in the function to reduce the prediction deviation.

[0121] According to the priority parameter in the dynamic priority adjustment instruction, the execution order of the risk disposal process in different scenarios is dynamically configured. The priority parameter is determined according to the risk level division matrix. The higher the risk level, the larger the corresponding priority parameter, and the earlier the execution order of the disposal process. In the priority adjustment process, the risk disposal effect is monitored in real time through the state feedback mechanism. The state feedback mechanism evaluates whether the risk is effectively controlled by collecting environmental parameters and behavior pattern data after disposal. According to the monitoring results, the level weight in the risk level division matrix is dynamically updated. The update of the level weight is based on the comparison result of the disposal effect and the expected effect. If the disposal effect of a certain risk level is better than expected, the level weight is appropriately increased, and vice versa.

[0122] Through the above process, the trigger threshold of the abnormal response strategy and the priority of the risk disposal process can be adjusted in time according to the dynamic early warning instruction, so that the monitoring system can quickly and accurately respond to different types of abnormal situations, and improve the effectiveness of anomaly detection and early warning.

[0123] Embodiment 4:

[0124] The final anomaly mitigation data and risk level retest results after the early warning disposal are collected. Taking the monitoring of a production workshop in a smart factory as an example, when the system issues a warning for temperature anomaly in a certain area and performs temperature reduction disposal, the final anomaly mitigation data includes the temperature recovery value of the area after disposal, the time required for temperature stabilization, etc. The risk level retest result is to reevaluate the risk level of the area after disposal, such as from high risk to medium risk or low risk.

[0125] The final anomaly mitigation data is compared with the predicted mitigation range of the first detection model to generate an anomaly detection error signal. Assuming that the first detection model predicts that the temperature of the area will recover to 25-28°C after disposal, and the actual final temperature stabilizes at 29°C, the difference between the two will be recorded as part of the anomaly detection error signal, which contains the deviation information between the model prediction and the actual result.

[0126] The risk level retest result is consistent with the expected level standard of the second detection model to generate a risk assessment error signal. If the second detection model expects the risk level after treatment to be low risk, but the retest result is medium risk, there is an evaluation deviation, which is quantified as a specific value in the risk assessment error signal.

[0127] According to the system deviation component in the abnormality detection error signal, the probability distribution rule in the first detection model is adjusted. The system deviation component refers to the long-term existing and regular deviation, for example, the first detection model always underestimates the temperature value after abnormality relief, in which case the temperature-related parameters in the probability distribution rule need to be corrected to make the model prediction closer to the actual situation.

[0128] According to the random fluctuation component in the risk assessment error signal, the level weight coefficient in the second detection model is optimized. The random fluctuation component refers to the occasional and irregular deviation, for example, the risk level evaluation deviates due to temporary personnel operation in a retest, at which time the level weight coefficient is adjusted to reduce the influence of accidental factors on risk level division.

[0129] The adjusted probability distribution rule and level weight coefficient are updated to the historical feature library of the initial feature set in synchronization, so that subsequent model construction can be based on updated historical data, maintaining the adaptability of the model.

[0130] The process of adjusting the probability distribution rule and the level weight coefficient includes:

[0131] The static deviation component in the abnormality detection error signal is identified, and a static compensation value is calculated by a moving average filtering method. The moving average filtering method filters out short-term fluctuations by averaging the error signal over a period of time, and extracts the static deviation component, for example, the model prediction value is always 2°C lower than the actual value in continuous multiple detections, then the static deviation component is 2°C, and the corresponding static compensation value is also 2°C.

[0132] According to the static compensation value, the reference probability threshold in the abnormal probability calculation function is adjusted. If the static compensation value is positive, it means that the model tends to underestimate the abnormal probability, and the reference probability threshold needs to be increased; if the static compensation value is negative, the reference probability threshold is decreased to balance the prediction results of the model.

[0133] The dynamic interference component in the risk assessment error signal is identified, and an effective correction parameter is extracted by an adaptive filtering algorithm. The adaptive filtering algorithm can automatically adjust the filtering parameters according to the changes of the interference signal, effectively separate the dynamic interference component, for example, the risk assessment deviation caused by temporary equipment failure, and extract the corresponding correction parameter from it.

[0134] The level determination threshold in the risk level division matrix is adjusted according to the effective correction parameter. If the effective correction parameter indicates that the risk level corresponding to a certain behavior feature is overestimated, the level determination threshold corresponding to the feature is increased to reduce false positives; if it is underestimated, the level determination threshold is reduced to improve detection sensitivity.

[0135] The updated abnormal probability calculation function and risk level division matrix are substituted for the original model parameters to complete the real-time updating of the model, ensuring that subsequent anomaly detection and risk assessment can be based on a more accurate model.

[0136] Embodiment 5:

[0137] The environment feature identifier and behavior pattern coding segment in the scene type coding corresponding to the target scene are parsed to generate a scene feature description vector. The scene type coding is a sequence of characters containing key information of the scene, wherein the environment feature identifier records physical environment attributes of the scene, such as space size, ventilation condition, and device distribution density; the behavior pattern coding segment records common behavior subjects and behavior rules in the scene, such as personnel flow frequency and device operation period. During the parsing process, these identifiers and coding segments are converted into quantifiable numerical values to form a scene feature description vector according to a preset dimension, and each dimension corresponds to a quantified value of a specific feature.

[0138] The scene feature description vector is input into the preloaded scene configuration database for multidimensional matching retrieval to filter a candidate reference configuration set with a matching degree exceeding an adaptation threshold with the current scene type coding. The scene configuration database stores a large amount of configuration information of historical scenes, and each piece of configuration information contains a corresponding scene feature description vector and complete parameter configuration. During multidimensional matching retrieval, the similarity between the current scene feature description vector and historical scenes in the database is calculated from multiple dimensions such as environment features, behavior patterns, and scene size, and historical configuration information with a similarity higher than the adaptation threshold is included in the candidate reference configuration set.

[0139] For each candidate reference configuration in the candidate reference configuration set, the following operations are performed: the average abnormal detection rate and risk level accuracy rate in its historical application record are extracted, and a comprehensive configuration performance score is calculated. The average abnormal detection rate is the ratio of the number of successfully detected abnormalities to the actual number of abnormalities in the historical application of the configuration, and the risk level accuracy rate is the proportion of the determination results of the risk level of the configuration consistent with the actual risk level. The comprehensive configuration performance score is obtained by weighted calculation of the two indicators, and the weights are set according to the emphasis degree of the scene on abnormal detection and risk assessment.

[0140] The candidate benchmark configuration set is prioritized according to the comprehensive configuration performance score, and the candidate benchmark configuration with the highest score is selected as the optimal benchmark environment parameter template. The optimal benchmark environment parameter template contains key parameters such as benchmark values, fluctuation ranges, and monitoring frequencies of environment parameters in the scene.

[0141] A set of behavior pattern references with configuration correlation to the optimal benchmark environment parameter template is extracted from the scene configuration database. Configuration correlation refers to the synergistic change relationship between behavior patterns and environment parameters in historical applications, such as common personnel behavior patterns under specific environment parameters and device operation modes.

[0142] The synergistic verification of pattern features and environment parameters is performed on each pattern data in the behavior pattern reference set, as follows:

[0143] The feature data of a single to-be-verified pattern is extracted from the behavior pattern reference set, and the environment parameter sequence that is time-aligned with the to-be-verified pattern in the optimal benchmark environment parameter template is synchronously obtained. Time alignment ensures that the occurrence time of the behavior pattern is consistent with the acquisition time of the corresponding environment parameter, such as the behavior pattern data of personnel entering a certain area corresponding to the temperature, humidity, and other environment parameters of the same time in that area.

[0144] According to the change nodes of the environment parameter sequence, corresponding synergistic time markers are labeled on the to-be-verified pattern to generate a pattern feature curve with time sequence identification. The change nodes of the environment parameter sequence are time points at which the environment parameter has a significant change, such as the time at which the temperature suddenly rises by 5°C. At this time, a synergistic time marker is labeled on the corresponding behavior pattern curve to clearly indicate the time correlation between environment change and behavior pattern change.

[0145] Each synergistic time marker in the pattern feature curve with time sequence identification is traversed to detect whether the feature change rate in its adjacent time window exceeds a preset mutation threshold, and abnormal time windows with feature mutations are identified. The adjacent time window is a fixed time length before and after the synergistic time marker, such as 10 seconds before the marker to 10 seconds after the marker. The feature change rate is the ratio of the change amplitude of the behavior feature to the time in the window, and the preset mutation threshold is set according to the fluctuation range of the historical behavior feature.

[0146] When an abnormal time window is identified, the environment parameter value at the corresponding time node in the optimal benchmark environment parameter template is traced back to determine whether the change direction of the environment parameter value has a reverse effect on the direction of the feature mutation. Reverse effect refers to the situation where the change trend of the environment parameter should suppress the mutation of the behavior feature but actually promotes the mutation, or the situation where the change trend should promote the mutation but actually suppresses the mutation, such as when the environment temperature rises, the personnel should reduce the stay time in the high-temperature area, but if the behavior pattern shows that the stay time increases, it is determined that there is a reverse effect.

[0147] If the reverse influence intensity exceeds the conflict threshold, the abnormal time window is marked as a parameter conflict region, and the starting position and duration of the parameter conflict region in the mode characteristic curve are calculated. The reverse influence intensity is obtained by quantifying the influence of environmental parameter changes on the mutation of behavior characteristics, and the conflict threshold is set according to the requirement of the scene for parameter synergy.

[0148] According to the starting position and duration of the parameter conflict region, a characteristic correction window is drawn on the to-be-verified mode, and a replacement characteristic smooth segment is generated based on the correction records of similar conflicts in the historical characteristic library. The duration of the characteristic correction window is consistent with the duration of the parameter conflict region, and the replacement characteristic smooth segment is generated by referring to the correction method of similar conflicts in history, such as correcting the mutated behavior characteristic value to a smooth curve consistent with the trend of environmental parameter changes.

[0149] The replacement characteristic smooth segment is inserted into the characteristic correction window to generate an optimized behavior mode curve, and the abnormal data points in the original mode characteristic curve that overlap with the parameter conflict region are deleted.

[0150] The integrity of all optimized behavior mode curves in the behavior mode reference set that have completed the replacement insertion operation is checked, and the residual curves that still contain uncorrected conflict regions are removed. The integrity check is implemented by checking whether there are unmarked abnormal time windows or parameter conflict regions in the curve.

[0151] The optimized behavior mode curves that pass the verification are merged into an optimized behavior mode benchmark set.

[0152] According to the historical running stability indicators of each optimized behavior mode benchmark in the optimized behavior mode benchmark set, the optimized behavior mode benchmark with the smallest fluctuation index is selected as the optimal behavior mode benchmark. The historical running stability indicators include the fluctuation amplitude of the mode curve, the duration stability, etc., and the fluctuation index is a comprehensive quantitative value of these indicators. The smaller the fluctuation index, the more stable the mode.

[0153] The optimal benchmark environmental parameter template and the optimal behavior mode benchmark are configured and time-aligned to generate a benchmark parameter configuration of the initial characteristic set. The configuration time alignment adjusts the time axis of the parameters to ensure the synchronization of the environmental parameters and the behavior mode in the time dimension, so that the benchmark parameter configuration can accurately reflect the synergy relationship between the environment and the behavior under the initial state of the scene.

[0154] It is to be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting; it is not intended to exclude myriad other embodiments of the present application that other inventors can develop based on the same general inventive concepts embodied by the described embodiments. That is, although the present application is described in terms of particular embodiments and implementations, it is to be understood that the terminology used is for the purpose of descriptive clarity and that it is intended to be limited only by the words recited in the appended claims. It is to be understood that the terms such as first and second, etc., merely are used to differentiate one from another without necessarily implying or requiring any actual relationship or order between them. Moreover, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can also include other elements not expressly listed or inherent to such process, method, article, or apparatus.

[0155] While the embodiments of the application have been shown and described herein, it is to be understood that the application is not limited to these embodiments. Rather, many modifications, changes, substitutions, and alterations can be made thereto without departing from the spirit and scope of the present application as defined by the appended claims and their equivalents.

Claims

1. A context-aware, multi-dimensional anomaly detection and early warning method, characterized in that, The method includes: Collect real-time contextual data in the target monitoring scene to generate an initial feature set, which includes an environmental parameter sequence and a behavior pattern map; Based on the environmental parameter sequence in the initial feature set, a first detection model adapted to the scene type is constructed. The first detection model includes a dynamic correlation function between environmental indicators and anomaly probability. Based on the behavioral pattern map in the initial feature set, a second detection model adapted to the scene type is constructed. The second detection model includes a non-linear mapping rule between behavioral features and risk levels. Based on the context deviation data and characteristic fluctuation coefficient data during real-time monitoring, the target model in the first detection model or the second detection model is triggered, and a dynamic early warning instruction is generated through the target model. The dynamic early warning command is pushed to the execution module of the monitoring system to adjust the trigger threshold of the abnormal response strategy or the priority of the risk handling process; Constructing a first detection model and a second detection model, including: The optimized environmental parameter sequence is input into the preset rule inference engine, and the rule weights are updated iteratively through multiple rounds of condition matching to generate the anomaly probability calculation function in the first detection model. The anomaly probability calculation function is the target model in the first detection model. The optimized behavior pattern map is input into the statistical feature extraction module, and key behavior indicators are screened through a feature dimensionality reduction algorithm to generate a risk level classification matrix in the second detection model; the risk level classification matrix is ​​the target model in the second detection model. After the rule reasoning engine and statistical feature extraction module have stabilized, the core parameter vectors in the anomaly probability calculation function and risk level classification matrix are extracted respectively. The correlation analysis between the core parameter vector and the real-time collected environmental state data is performed to verify the applicability of the first detection model and the second detection model. When the correlation analysis result is lower than the preset threshold, the matching conditions of the rule reasoning engine and the dimensionality reduction parameters of the statistical feature extraction module are readjusted until the core parameter vector meets the applicability conditions. The method, based on context deviation data and characteristic fluctuation coefficient data during real-time monitoring, triggers the target model in the first or second detection model, and generates a dynamic early warning instruction through the target model, including: Real-time tracking and monitoring of the context deviation change curve and characteristic fluctuation coefficient amplitude during the process; When the context deviation change curve exceeds the first trigger threshold and the feature fluctuation coefficient amplitude is within a preset safe range, the anomaly probability calculation function in the first detection model is triggered. Based on the probability distribution rules in the anomaly probability calculation function, a dynamic threshold adjustment instruction for the anomaly response strategy is generated. When the amplitude of the characteristic fluctuation coefficient exceeds the second trigger threshold and the context deviation change curve is in the preset stable range, the risk level division matrix in the second detection model is triggered. Based on the risk level classification matrix, a dynamic priority adjustment instruction for the risk handling process is generated. If the context deviation change curve and the characteristic fluctuation coefficient amplitude both exceed the trigger threshold, the dynamic threshold adjustment instruction generated by the first detection model will be executed first, and the adjustment instruction of the second detection model will be delayed until the abnormal response strategy completes the threshold update.

2. The context-aware, multi-dimensional anomaly detection and early warning method according to claim 1, characterized in that, The real-time context data collected in the target monitoring scenario is used to generate an initial feature set, including: The environmental status data of the target scene is collected synchronously by multi-source sensing devices during the monitoring period. The environmental status data includes a physical parameter time series and a logical state encoding set. Based on the characteristic intervals in the time-series physical parameters, the target scene is divided into at least two sub-scene units, and each sub-scene unit is assigned a corresponding initial monitoring threshold range and risk assessment benchmark value. Extract historical environment correction parameters and behavioral feature compensation coefficients that match each sub-scene unit from the preset feature library; The historical environment correction parameters are spatiotemporally aligned to generate an optimized environment parameter sequence for each sub-scene unit; The behavior feature compensation coefficients are subjected to trend smoothing processing to generate an optimized behavior pattern map corresponding to each sub-scene unit; The initial feature set is generated by fusing the optimized environmental parameter sequence and optimized behavior pattern map of each sub-scene unit.

3. The context-aware, multi-dimensional anomaly detection and early warning method according to claim 1, characterized in that, The step of pushing the dynamic early warning command to the execution module of the monitoring system and adjusting the trigger threshold of the abnormal response strategy or the priority of the risk handling process includes: Based on the threshold compensation value in the dynamic threshold adjustment instruction, the judgment threshold of each early warning level in the abnormal response strategy is updated in stages. After each threshold update, real-time anomaly probability data is collected and compared with the predicted value of the anomaly probability calculation function for deviation analysis. If the deviation value continues to decrease, maintain the current threshold adjustment direction until the target probability range is reached; If the deviation value shows an upward trend, the judgment threshold is adjusted in reverse and the parameter optimization of the anomaly probability calculation function is retried; Based on the priority parameter in the dynamic priority adjustment instruction, the execution order of the risk handling process is dynamically configured in different scenarios. During the priority adjustment process, the effectiveness of risk management is monitored in real time through a status feedback mechanism, and the level weights in the risk level classification matrix are dynamically updated based on the monitoring results.

4. The context-aware, multi-dimensional anomaly detection and early warning method according to claim 1, characterized in that, The method also includes an effect calibration phase after the execution of the dynamic early warning command, which includes the following operations: Collect final anomaly mitigation data and risk level retest results after the early warning and response are completed; The final anomaly mitigation data is compared with the predicted mitigation range of the first detection model to generate an anomaly detection error signal. The consistency analysis of the risk level retest results with the expected level standard of the second detection model is performed to generate a risk assessment error signal; Adjust the probability distribution rules in the first detection model based on the system deviation component in the anomaly detection error signal; Based on the random fluctuation component in the risk assessment error signal, optimize the level weight coefficient in the second detection model; The adjusted probability distribution rules and grade weight coefficients are synchronously updated to the historical feature library of the initial feature set.

5. The context-aware, multi-dimensional anomaly detection and early warning method according to claim 4, characterized in that, The process of adjusting the probability distribution rules and rank weight coefficients includes: Identify the static deviation component in the anomaly detection error signal and calculate the static compensation value using the moving average filtering method; Adjust the baseline probability threshold in the anomaly probability calculation function according to the static compensation value; Identify the dynamic interference components in the risk assessment error signal and extract effective correction parameters using an adaptive filtering algorithm; Adjust the risk level classification threshold in the risk level classification matrix according to the effective correction parameters; Replace the original model parameters with the updated anomaly probability calculation function and risk level classification matrix.

6. The context-aware, multi-dimensional anomaly detection and early warning method according to claim 1, characterized in that, The method further includes performing the following initialization operations before system startup, including: Parse the environmental feature identifiers and behavioral pattern encoding segments in the scene type encoding corresponding to the target scene to generate a scene feature description vector; The scene feature description vector is input into the preloaded scene configuration database for multi-dimensional matching and retrieval, and a candidate baseline configuration set with a matching degree exceeding the adaptation threshold is obtained. For each candidate baseline configuration in the candidate baseline configuration set, perform the following operations: extract the average anomaly detection rate and risk level accuracy from its historical application records, and calculate the comprehensive configuration performance score; Based on the comprehensive configuration performance score, the candidate baseline configuration set is prioritized and the candidate baseline configuration with the highest score is selected as the optimal baseline environment parameter template. Extract a set of behavioral pattern references from the scenario configuration database that are related to the optimal baseline environment parameter template; For each pattern data in the behavioral pattern reference set, the synergy between pattern features and environmental parameters is verified, and abnormal patterns with feature conflicts or parameter contradictions are eliminated to generate an optimized behavioral pattern benchmark set. Based on the historical operational stability indicators of each optimized behavior pattern benchmark in the optimized behavior pattern benchmark set, the optimized behavior pattern benchmark with the smallest volatility index is selected as the optimal behavior pattern benchmark. The optimal baseline environment parameter template and the optimal behavior pattern baseline are configured and aligned in time sequence to generate the baseline parameter configuration for the initial feature set.

7. The context-aware, multi-dimensional anomaly detection and early warning method according to claim 6, characterized in that, The verification of the synergy between pattern features and environmental parameters for each pattern data in the behavioral pattern reference set includes: Extract feature data of a single pattern to be verified from the behavioral pattern reference set, and simultaneously obtain the environmental parameter sequence in the optimal benchmark environmental parameter template that is time-aligned with the pattern to be verified; Based on the change nodes of the environmental parameter sequence, corresponding collaborative time markers are marked on the mode to be verified to generate a mode feature curve with time sequence identifier; Traverse each collaborative time marker in the pattern feature curve with time sequence identifier, detect whether the feature change rate in its adjacent time window exceeds a preset mutation threshold, and identify abnormal time windows with feature mutations. When an abnormal time window is identified, the environmental parameter values ​​at the corresponding time node in the optimal baseline environmental parameter template are traced back to determine whether the direction of change of the environmental parameter values ​​has an adverse effect on the direction of feature mutation. If the intensity of the adverse effect exceeds the conflict threshold, the abnormal time window is marked as a parameter conflict region, and the starting position and duration of the parameter conflict region in the pattern feature curve are calculated. Based on the starting position and duration of the parameter conflict region, a feature correction window is defined on the mode to be verified, and a replacement feature smoothing segment is generated based on the correction records of similar conflicts in the historical feature library. The alternative feature smoothing segment is inserted into the feature correction window to generate an optimized behavior pattern curve, and abnormal data points that overlap with the parameter conflict area in the original pattern feature curve are deleted. Perform integrity verification on all optimized behavior pattern curves that have completed the substitution insertion operation in the behavior pattern reference set, and remove residual curves that still contain uncorrected conflict areas. The validated optimized behavior pattern curves are merged into the optimized behavior pattern benchmark set.

8. The context-aware, multi-dimensional anomaly detection and early warning method according to claim 3, characterized in that, The threshold values ​​for each warning level in the phased update anomaly response strategy include: The threshold update stage interval is determined based on the rate of change of the environmental parameter sequence, and the total adjustment interval is divided into at least three consecutive sub-adjustment stages. Each sub-adjustment stage is assigned a corresponding threshold adjustment step size, and the threshold adjustment step size increases by a preset ratio as the stage progresses. After each sub-adjustment phase is completed, the deviation rate between the mean anomaly probability of the current phase and the target probability interval is collected. If the deviation rate is less than the stage threshold, proceed to the next sub-adjustment stage; if the deviation rate is greater than or equal to the stage threshold, pause the current update process and trigger parameter recalibration of the anomaly probability calculation function. After all sub-adjustment stages are completed, a final verification is performed on the judgment thresholds for each warning level to ensure that the difference between adjacent level thresholds meets the preset gradient requirements.

Citation Information

Patent Citations

  • Airport boundary intrusion detection and alarm linkage system

    CN119007417A

  • Method for gas gate station monitoring based on smart gas platform and internet of things system thereof

    US20240153374A1