Visual analysis method and system for security and protection monitoring data

By performing causal detection and delay compensation on multi-source asynchronous data streams in security monitoring systems and constructing a dynamic causal relationship graph, the technical challenge of causal relationship identification of asynchronous data streams in security monitoring systems is solved, and efficient causal inference and security threat discovery are achieved.

CN120808233APending Publication Date: 2025-10-17SHENZHEN BINGYITONG INFORMATION TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510911622.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-02
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

Existing security monitoring systems face technical challenges in time synchronization, spatial correlation and semantic understanding in the fusion of multi-source heterogeneous data. In particular, it is difficult to effectively handle the correlation between asynchronous data streams in complex environments.

Method used

By asynchronously collecting data streams from video surveillance, infrared sensors, and access control systems in the security monitoring system, a multi-source asynchronous data stream set is generated. A set of causal detection operators is used to perform cross-stream correlation calculations, generate a set of potential causal event pairs, and perform causal probability calculations and delay compensation. Finally, a dynamic causal relationship map is constructed.

Benefits of technology

It realizes the intuitive dynamic display of the causal chain of asynchronous data flow, enhances the ability to discover potential security threats, solves the problem of resource competition, ensures the accuracy and consistency of causal inference results, and reduces the error rate of causal relationship identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120808233A_ABST
    Figure CN120808233A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data visualization, and discloses a visual analysis method and system for security and protection monitoring data, and the method comprises the steps: carrying out the asynchronous collection of a video monitoring data stream, an infrared sensor data stream, an access control system data stream and an audio collection data stream in a security and protection monitoring system, and obtaining a multi-source asynchronous data stream set; generating a potential causal event pair set based on the multi-source asynchronous data stream set, and creating a time window allocation table according to the potential causal event pair set; performing causal probability calculation on the multi-source asynchronous data stream set to obtain a multi-dimensional causal probability propagation matrix; and asynchronous time delay compensation and causal chain visualization are performed on the multi-dimensional causal probability propagation matrix based on the time window allocation table to obtain a dynamic causal relationship graph, so that visual dynamic display of the causal chain of the asynchronous data stream is realized, and brand new monitoring situation awareness experience is provided for security personnel.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data visualization, and particularly relates to a security monitoring data visualization analysis method and system. BACKGROUND

[0002] Current security monitoring systems generally use multi-source heterogeneous data fusion technology to integrate data streams generated by various monitoring devices such as video monitoring, infrared sensors, access control systems, and audio acquisition, and build a comprehensive security protection network. However, these multi-source data streams have significant technical challenges in time synchronization, spatial correlation, and semantic understanding, especially in complex practical application environments, where the data collection frequency, transmission delay, and processing capacity of different devices differ greatly, making it difficult for traditional synchronous data fusion methods to effectively handle the correlation between asynchronous data streams. SUMMARY

[0003] The present application provides a security monitoring data visualization analysis method and system, which realizes intuitive and dynamic display of asynchronous data stream causal chains and provides security personnel with a new monitoring situation awareness experience.

[0004] The present application provides a security monitoring data visualization analysis method, which includes: Asynchronous collection of video monitoring data streams, infrared sensor data streams, access control system data streams, and audio acquisition data streams in a security monitoring system to obtain a multi-source asynchronous data stream set; Generating a set of potential causal event pairs based on the multi-source asynchronous data stream set, and creating a time window allocation table according to the set of potential causal event pairs; Causal probability calculation of the multi-source asynchronous data stream set to obtain a multi-dimensional causal probability propagation matrix; Asynchronous time delay compensation and causal chain visualization of the multi-dimensional causal probability propagation matrix based on the time window allocation table to obtain a dynamic causal relationship graph.

[0005] In combination with the first aspect, in a first implementation manner of the first aspect of the present application, the asynchronous collection of video monitoring data streams, infrared sensor data streams, access control system data streams, and audio acquisition data streams in a security monitoring system to obtain a multi-source asynchronous data stream set includes: Respectively assigning data stream identifiers and recording original time stamps to video monitoring data streams, infrared sensor data streams, access control system data streams, and audio acquisition data streams in a security monitoring system to obtain an identified data stream set; Asynchronous data stream buffer queue construction and sliding window maintenance processing are performed on the video monitoring data stream, the infrared sensor data stream, the access control system data stream and the audio acquisition data stream based on the identified data stream set, to obtain a cache window matrix. Standardized conversion is performed on the video monitoring data stream, the infrared sensor data stream, the access control system data stream and the audio acquisition data stream according to the cache window matrix, to obtain a multi-source asynchronous data stream set.

[0006] In combination with the first aspect, in a second implementation manner of the first aspect of the application, generating a set of potential causal event pairs based on the multi-source asynchronous data stream set, and creating a time window allocation table according to the set of potential causal event pairs, comprises: Building a set of causal detection operators based on the multi-source asynchronous data stream set; Performing cross-stream correlation calculation on the multi-source asynchronous data stream set according to the set of causal detection operators, to obtain a time delay response correlation matrix; According to the time delay response correlation matrix, performing exceeding judgment on a causal correlation threshold and quantifying causal strength, to obtain a set of causal event pair candidates, and performing time logic consistency verification, spatial topology rationality verification and statistical confidence verification based on the set of causal event pair candidates, to obtain a set of potential causal event pairs; According to the set of potential causal event pairs, time multiplexing scheduling is performed on asynchronous data stream resources, to obtain a time window allocation table.

[0007] In combination with the first aspect, in a third implementation manner of the first aspect of the application, performing cross-stream correlation calculation on the multi-source asynchronous data stream set according to the set of causal detection operators, to obtain a time delay response correlation matrix, comprises: Inputting the set of causal detection operators into a time delay scanning module, and setting a time delay range and deploying operators on the multi-source asynchronous data stream set in the time delay scanning module, to obtain a set of time delay scanning configuration parameters; Based on the set of time delay scanning configuration parameters, performing time delay response strength calculation between data streams on the multi-source asynchronous data stream set, to obtain a cross-stream response strength matrix; According to the cross-stream response strength matrix, performing correlation quantification and strength normalization on the multi-source asynchronous data stream set, to obtain a time delay response correlation matrix.

[0008] In combination with the first aspect, in a fourth implementation manner of the first aspect of the application, performing time multiplexing scheduling on asynchronous data stream resources according to the set of potential causal event pairs, to obtain a time window allocation table, comprises: perform causal driving window duration calculation on the causal time delay characteristic and the causal strength weight of each causal event pair in the set of potential causal event pairs, to obtain a set of adaptive window parameters; perform comprehensive priority calculation of causal strength weighting, time delay reciprocal weighting and data quality weighting based on the set of adaptive window parameters, to obtain a priority queue; perform causal conflict identification and minimum causal time delay offset adjustment on the causal inference tasks that access the same asynchronous data stream at the same time according to the priority queue, to obtain a conflict-free scheduling scheme; perform exclusive access mapping and time slice allocation of the causal inference tasks and the asynchronous data stream resources based on the conflict-free scheduling scheme, to obtain a time window allocation table.

[0009] In a fifth implementation manner of the first aspect, the performing causal conflict identification and minimum causal time delay offset adjustment on the causal inference tasks that access the same asynchronous data stream at the same time according to the priority queue, to obtain a conflict-free scheduling scheme, comprises: perform overlapping interval detection and causal conflict marking on the asynchronous data stream access time window based on the causal inference tasks in the priority queue, to obtain a set of conflict task pairs; perform priority grouping and adjustment according to the priority weight and the causal time delay characteristic of each conflict task pair in the set of conflict task pairs, to obtain a priority adjustment strategy; generate a set of causal time delay offset parameters based on offset calculation of the minimum causal time delay and time window relocation of low-priority tasks for the priority adjustment strategy; perform time window reallocation and conflict elimination verification on the priority queue based on the set of causal time delay offset parameters, to obtain a conflict-free scheduling scheme.

[0010] In a sixth implementation manner of the first aspect, the performing causal probability calculation on the set of multi-source asynchronous data streams, to obtain a multi-dimensional causal probability propagation matrix, comprises: perform adaptive selection of a Bayesian causal chain analysis strategy and a Markov causal dependence inference strategy based on the set of multi-source asynchronous data streams, to obtain a strategy configuration scheme; input the set of multi-source asynchronous data streams into a Bayesian causal chain analysis module to perform causal network node construction, directed edge relationship establishment and conditional probability distribution calculation, to obtain a first probability matrix; input the set of multi-source asynchronous data streams into a Markov causal dependence inference module to perform state space definition, state transition matrix establishment and transition probability calculation, to obtain a second probability matrix; According to the strategy configuration scheme, the first probability matrix and the second probability matrix are subjected to probability domain mapping and weight fusion, so as to obtain a multi-dimensional causal probability propagation matrix.

[0011] In combination with the first aspect, in a seventh implementation manner of the first aspect of the application, the asynchronous time delay compensation and the causal chain visualization are performed on the multi-dimensional causal probability propagation matrix based on the time window allocation table, so as to obtain a dynamic causal relationship graph, including: The reference time delay calculation, the time delay deviation quantization and the time delay correction matrix construction are performed according to the local time delay parameters of each asynchronous data stream in the time window allocation table, so as to obtain a set of asynchronous time delay compensation parameters; Based on the set of asynchronous time delay compensation parameters, the time delay difference threshold judgment and the forward time window sliding compensation are performed on the multi-dimensional causal probability propagation matrix, so as to obtain a time delay correction causal probability matrix; Based on the time delay correction causal probability matrix, the multi-dimensional time delay mode weighted fusion and the causal correlation strength calculation are performed, so as to obtain a causal correlation probability matrix; According to the causal correlation probability matrix, the causal chain visualization is performed, so as to obtain a dynamic causal relationship graph.

[0012] In combination with the first aspect, in an eighth implementation manner of the first aspect of the application, the causal chain visualization is performed according to the causal correlation probability matrix, so as to obtain a dynamic causal relationship graph, including: Based on the causal correlation probability matrix, the three-dimensional causal graph space construction and the causal event node mapping are performed, so as to obtain a three-dimensional causal node graph; According to the three-dimensional causal node graph, the correlation relationship between causal events is subjected to directed edge construction, particle flow effect generation and causal propagation path animation rendering, so as to obtain a dynamic causal chain connection graph; Based on the dynamic causal chain connection graph, the incremental update calculation, the force-directed layout optimization and the node position rearrangement are performed, so as to obtain a layout-optimized causal relationship graph; Based on the layout-optimized causal relationship graph, the global view rendering, the local view focusing and the time axis view switching are performed, so as to obtain a dynamic causal relationship graph.

[0013] The second aspect of the application provides a visual analysis system for security monitoring data. The asynchronous acquisition module is configured to acquire video monitoring data streams, infrared sensor data streams, access control system data streams and audio acquisition data streams in a security monitoring system asynchronously, so as to obtain a set of multi-source asynchronous data streams. The creation module is configured to generate a set of potential causal event pairs based on the set of multi-source asynchronous data streams, and create a time window allocation table according to the set of potential causal event pairs. A computing module is configured to perform causal probability calculation on the set of multi-source asynchronous data streams to obtain a multi-dimensional causal probability propagation matrix. A visualizing module is configured to perform asynchronous time delay compensation and causal chain visualization on the multi-dimensional causal probability propagation matrix based on the time window allocation table to obtain a dynamic causal relationship atlas.

[0014] Compared with the prior art, the application has the following beneficial effects: through the independent data stream identifier allocation and original timestamp reservation mechanism, the information loss problem caused by traditional forced time alignment is avoided, the original timing characteristics of different monitoring devices can be accurately captured by the system, the cross-stream correlation calculation technology based on the set of causal detection operators breaks through the limitations of traditional time correlation analysis, and complex causal event pairs in an asynchronous environment can be identified, thereby significantly enhancing the discovery ability of the system to potential security threats. Through the time division multiplexing scheduling strategy and the priority sorting mechanism, conflict-free access of asynchronous data stream resources is realized, the resource competition problem in the multi-task concurrent processing in the traditional method is solved, and the accuracy and consistency of the causal inference result are ensured. Through the adaptive selection mechanism of Bayesian causal chain analysis and Markov causal dependence inference, the system can intelligently switch the inference strategy according to the data characteristics and environmental conditions, and good inference performance can be maintained in the high confidence requirement and data sparse environment. Based on the time delay correction matrix and the forward time window sliding compensation algorithm, the misjudgment problem of the cross-device asynchronous event causal relationship is effectively solved, the compensation parameters are dynamically adjusted through the Bayesian update mechanism, and the error rate of the causal relationship identification is greatly reduced. A three-dimensional atlas space including the time dimension, the spatial position dimension and the causal strength dimension is constructed, the particle flow effect and the force-directed layout optimization are combined, the intuitive dynamic display of the asynchronous data stream causal chain is realized, and a new monitoring situation awareness experience is provided for security personnel. BRIEF DESCRIPTION OF DRAWINGS

[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, brief descriptions will be given to the drawings needed to be used in the embodiments or prior art descriptions. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0016] The structures, proportions, sizes, etc. shown in the drawings of the present specification are only used to cooperate with the content disclosed in the present specification, to enable those skilled in the art to understand and read, and are not used to limit the defined conditions under which the present application can be implemented, so they do not have technical significance. Any modification of structure, change of proportion relationship or adjustment of size, without affecting the effects and purposes that can be achieved by the present application, should still fall within the scope of the technical content disclosed by the present application.

[0017] Figure 1 is a flowchart of a security monitoring data visualization analysis method provided by an embodiment of the present application; Figure 2 is a structural schematic block diagram of a security monitoring data visualization analysis system provided by an embodiment of the present application. DETAILED DESCRIPTION

[0018] The technical solutions in the embodiments of the present application will be clearly and completely described with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of the present application.

[0019] The flowchart shown in the drawings is only an example and does not necessarily include all contents and operations / steps, nor does it necessarily be executed in the described order. For example, some operations / steps can be decomposed, combined or partially merged, so that the actual execution order can be changed according to the actual situation.

[0020] It should also be understood that the terms used in the present application specification are only for the purpose of describing specific embodiments and are not intended to limit the present application. As used in the present application specification and the appended claims, the singular forms "a", "an" and "the" are intended to include the plural forms unless the context clearly indicates otherwise.

[0021] It should be further understood that the term "and / or" used in the present application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes these combinations. Please refer to Figure 1 One embodiment of the security monitoring data visualization analysis method in the embodiments of the present application includes: Step 100, asynchronously collecting video monitoring data stream, infrared sensor data stream, access control system data stream and audio acquisition data stream in a security monitoring system to obtain a multi-source asynchronous data stream set; It can be understood that the execution subject of the present application can be a security monitoring data visualization analysis system, and can also be a terminal or a server, which is not limited here. The embodiments of the present application take the server as the execution subject for example.

[0022] Specifically, in the security monitoring environment, the video monitoring data stream, the infrared sensor data stream, the access control system data stream and the audio acquisition data stream are respectively allocated with independent identifiers and recorded with original time stamps, wherein each type of data source is assigned a unique data stream identifier to realize the identification of data source attribution and time characteristics in an asynchronous environment. Each data stream retains the time stamp generated by its local clock when collected, ensuring that the sampling frequency, trigger timing and collection mechanism between different types of sensing devices are not forced to align by a unified clock, thereby constructing a set of identified data streams with source independence and time asynchrony. For each type of identified data stream, a dedicated asynchronous data stream buffer queue is constructed, and a sliding window mechanism is introduced to dynamically intercept and continuously maintain the data in the time dimension. For each type of data stream, a fixed capacity buffer window interval is set to continuously collect valid data points in the last N time segments, forming a structured buffer window matrix. The buffer window matrix carries the behavior trajectory of each type of data in the continuous time period, and manages the cache update of multiple data sources in a distributed manner, avoiding resource conflicts or access delays caused by the number of data sources and bandwidth occupation. The formed buffer window matrix is subjected to standardization conversion processing, mainly by uniformly normalizing different sampling frequencies, data formats, physical units and data quality parameters, mapping the original data from a heterogeneous state to a common intermediate representation structure. The standardization conversion process extracts the core features of each data stream within the current sliding window, including data type label, device spatial coordinates, data quality score level and time granularity meta information, and on this basis, through a unified encoding mechanism, the video frame, infrared heat value, access control status marker and audio waveform sequence are structure transcoded. Through the standardization mechanism, data of different sources, different sampling models and different representation dimensions are finally encapsulated into intermediate data objects with a unified interface format, which can be commonly parsed and inferred, and finally output as a set of multi-source asynchronous data streams.

[0023] Step 200, generating a set of potential causal event pairs based on the set of multi-source asynchronous data streams, and creating a time window allocation table according to the set of potential causal event pairs; Specifically, a set of causal detection operators suitable for asynchronous information correlation analysis is established based on a set of multi-source asynchronous data streams. The set of operators has time sensitivity and cross-data-source collaborative processing capability, and can simulate the response propagation mode of different events on the time axis. Each causal detection operator is for a pair of asynchronous data streams and includes a response kernel function with time delay modulation and amplitude attenuation characteristics. The main goal is to capture the causal response trajectory that appears in the target data after a certain type of source event occurs. By controlling parameters such as decay rate, response period, and phase characteristics, the detection sensitivity of weak causal connections is enhanced. The set of causal detection operators is applied to all combinations of pairs of multi-source data streams. By cross-computing each pair of data streams, a response function sequence is generated, and a time delay response correlation matrix is constructed. The matrix reflects the response intensity and coupling degree of each source-target data stream combination at different time delays, and records the time of occurrence of each pair of response peaks, the corresponding delay value, and the amplitude size. On this basis, a causal correlation threshold is set and an exceeding judgment operation is performed to filter out signal pairs whose response function values significantly exceed the background noise in a certain delay interval. These signal pairs are determined as candidate combinations of causal event pairs, and a causal strength quantification mechanism is introduced to give quantitative scores to these candidate pairs. Based on the candidate set of causal event pairs, three verifications are performed, including time logic consistency verification to confirm that the event occurrence order of cause before effect is not violated, spatial topology rationality verification to ensure that the causal event propagation on the physical path has reachability and reasonable delay, and statistical confidence verification to evaluate the significance level of the event pair in a large amount of sample data. Through the three verification processes, a set of verified potential causal event pairs is selected. According to the set of potential causal event pairs, a time division multiplexing scheduling mechanism for asynchronous data streams is designed based on the time delay characteristics and causal strength between event pairs. A time window allocation table is constructed using a priority-based time period division strategy. The allocation table takes event pairs as the basic scheduling unit and allocates non-conflicting inference time intervals to each event pair. The scheduling strategy not only considers the time width and computing resources required for inference, but also optimizes the scheduling order through a priority mechanism to ensure that important events are allocated windows first. In the case of resource overlap, time offset or delay shift strategies are used to solve window conflict problems. Finally, a time window allocation table is generated, listing the use period, duration, priority level, and other parameters of each data stream pair in its causal window.

[0024] Step 300, causal probability calculation is performed on the set of multi-source asynchronous data streams to obtain a multi-dimensional causal probability propagation matrix; Specifically, based on the multi-source asynchronous data stream set, the execution strategy selection module analyzes and judges the current data environment, and according to the characteristic parameters such as data magnitude, event trigger frequency, sparsity and time sequence continuity of state transition mode, an adaptive strategy configuration selection is performed between the Bayesian causal chain analysis strategy and the Markov causal dependence inference strategy, so as to determine the calculation path combination most suitable for the current data structure. After the strategy selection is determined, the multi-source asynchronous data stream set is input into the Bayesian causal chain analysis module, and the prior relationship modeling capability is used to construct a causal network, wherein each identified monitoring event constitutes a network node, and a directed edge relationship is constructed based on the joint probability between the source-event and the target event. In this process, the conditional probability distribution between nodes is modeled, that is, the probability of the occurrence of the target event under the condition of the occurrence of the source event is calculated, the network parameters of the causal chain are continuously updated by the maximum posterior estimation method, and the first probability matrix based on the event node is formed by combining the historical frequency and the logical relationship, which describes the conditional probability intensity on the causal transmission chain between different events. The multi-source asynchronous data stream set is input into the Markov causal dependence inference module, and the state space of the monitoring scene is defined in the module, the feature mode in the data is mapped into a finite state set, and then a state transition matrix is established to represent the probability relationship of the transition from a state to another state under a given time or causal context. In this process, the state sequence is constructed according to the time sequence slice, and the transition rule between states is statistically inferred to generate a second probability matrix, which reflects the causal dependence relationship based on the time sequence transition chain. This matrix is more suitable for processing monitoring data streams with characteristics such as periodicity, periodicity or mode change. The first probability matrix and the second probability matrix are mapped in the probability domain and fused according to the strategy configuration scheme. The probability domain mapping function uniformly converts and normalizes the scale of the matrix structure from two different sources, ensuring that the conditional probability and the state transition probability are calculated in the same numerical space, and then the two are fused into a unified structure of a multi-dimensional causal probability propagation matrix through a strategy weight coefficient. The fusion method adopts linear weighting, Bayesian weighted average or confidence reconstruction mechanism, and finally forms a high-dimensional, high-confidence and time sequence explanation capable causal probability propagation result matrix. Each element in the matrix reflects the strength of the causal relationship between a source event and a target event, and combined with its time sequence evolution path and state driving characteristics, it reflects the propagation trajectory of the causal influence in the whole system dynamic process.

[0025] Step 400, asynchronous time delay compensation and causal chain visualization are performed on the multi-dimensional causal probability propagation matrix based on the time window allocation table, and a dynamic causal relationship graph is obtained.

[0026] Specifically, the local latency parameters of each asynchronous data stream in the time window assignment table are extracted and analyzed, and a unified time reference benchmark across devices is constructed based on the time labels therein. The minimum value of the latency parameters in all data streams is selected as the global benchmark latency, and based on this reference, the latency deviation of each data stream relative to the benchmark is calculated to form a quantized latency deviation matrix, which reflects the deviation of each data source from the benchmark time point in the time dimension. On this basis, a latency correction matrix is constructed to describe the relative delay amount between different data streams under bidirectional or multidirectional association. This correction matrix, together with the benchmark latency and deviation information, constitutes the asynchronous latency compensation parameter set. The asynchronous latency compensation parameter set is applied to the multidimensional causal probability propagation matrix, and a threshold judgment mechanism is set to determine whether the latency difference between different data pairs exceeds the allowable range. When it is detected that the latency difference of a certain data pair exceeds the set threshold, a forward time window sliding compensation operation is performed on the data stream with the later time, so as to adjust the event occurrence time, so that the logical position of the event in the causal sequence is consistent with the actual causal relationship. The compensation operation is based on an adaptive time window strategy, dynamically sets the sliding amplitude according to the size of the latency deviation, and performs position remapping and probability value adjustment on the related elements in the original propagation matrix, and outputs the latency correction causal probability matrix after unified time correction processing. Based on the latency correction causal probability matrix, weighted fusion calculation of the multidimensional latency mode is performed. The goal of this step is to absorb the causal relationship representation information under multiple latency scenarios, and integrate the probability structures constructed by different time compensation modes according to their credibility. The system configures dynamic weights for different time compensation paths according to the uncertainty parameters and signal response significance levels in the compensation process, and performs weighted superposition and normalization on the matrix according to the weights, to obtain a causal association probability matrix. According to the causal association probability matrix, the causal chain is visualized, and based on the preset joint mapping mechanism of the time, space and probability domains, a dynamic graph structure is constructed. In this process, the causal events are taken as the graph nodes, the causal strength is taken as the edge weight, and the latency information is taken as the flow direction identifier. According to the three-dimensional graph parameters, the event logic and time sequence evolution are fused and rendered, and the causal transmission path is displayed in a perceptible form by using various visual symbols such as node position, edge transparency, color coding and animation particles. At the same time, the real-time updating mechanism of the graph is supported. When the causal association structure changes dynamically with the input data, the graph automatically updates the structure, updates the weights and reconstructs the layout, and finally forms a dynamic causal relationship graph with multi-dimensional information expression capability, dynamic response characteristics and real-time evolution capability.

[0027] In a specific embodiment, the process of step 100 can specifically include the following steps: The video monitoring data stream, the infrared sensor data stream, the access control system data stream and the audio acquisition data stream in the security and protection monitoring system are respectively subjected to data stream identifier allocation and original time stamp recording to obtain an identified data stream set; The video monitoring data stream, the infrared sensor data stream, the access control system data stream and the audio acquisition data stream are subjected to asynchronous data stream buffer queue construction and sliding window maintenance processing based on the identified data stream set to obtain a buffer window matrix. The video monitoring data stream, the infrared sensor data stream, the access control system data stream and the audio acquisition data stream are subjected to standardized conversion according to the buffer window matrix to obtain a multi-source asynchronous data stream set.

[0028] Specifically, the data streams from different subsystems are identified to establish identifiable basic data units across devices, protocols, and time domains. The system assigns independent data stream identifiers to video monitoring data streams, infrared sensor data streams, access control system data streams, and audio acquisition data streams, respectively. Each identifier contains type information, physical source device code, and space code of the corresponding acquisition area, as well as a data stream version control field. At the same time of identifier allocation, the system adds a local timestamp to each raw data record based on the local clock system of each type of data acquisition device. The timestamp records the exact time of data generation rather than the network transmission and reception time, ensuring the independence and authenticity of the sampling time of the data within the entire system, and forming an identified data stream set with data source labels and original time characteristics. A dedicated data cache queue is established for each type of data stream, which serves as a temporary buffer to reduce the access pressure on the main processing module, and realizes the continuity maintenance and time window aggregation of data through a structured sliding window mechanism. In actual operation, the parameters of the sliding window are adaptively adjusted according to the sampling period, data density, and event triggering probability of each device. The window length covers multiple sampling periods to ensure that valid information can be captured completely under conditions of data rhythm fluctuation or delay jitter. The core data structure of the sliding window includes window number, start and end time labels, index reference of data within the window, and feature digest cache, forming a cache window matrix. The matrix is organized in a two-dimensional structure, with one dimension being different data source identifiers and the other dimension being time axis discrete windows. The matrix unit stores the local data segment, statistical description value, and quality score information in the current window. Standardized conversion processing is performed on the cached and structured data streams of various types to map the original data from heterogeneous formats to a unified internal intermediate representation structure, to adapt to the general processing interface of causal inference, visual modeling, and linkage analysis. In this step, the content structure and semantic attributes of the data are automatically identified according to the data type. For example, video data streams are parsed into image frame sequences and additional inter-frame difference metrics are added, infrared data is converted into thermal intensity distribution time series, access control data is identified as a binary state transition stream or a personnel access event sequence, and audio data is reconstructed in the form of short-time Fourier transform frequency spectrum slices. After content decoding and semantic mapping, the data streams are subjected to sampling frequency regularization, time label reconstruction, outlier removal, and numerical normalization processing to ensure the comparability and alignment of each data segment in the same internal processing platform. To ensure that the complete context information of each data unit is retained, source identifier, spatial coordinates, time window label, and quality confidence metadata are added to each standardized data segment to construct an intermediate object data set. After identification, asynchronous caching, and standardized conversion, the data streams of various types are integrated into a unified structure of a multi-source asynchronous data stream set.

[0029] In a specific embodiment, the process of performing step 200 can specifically include the following steps: Building a set of causal detection operators based on the set of multi-source asynchronous data streams; Performing cross-stream correlation calculation on the set of multi-source asynchronous data streams according to the set of causal detection operators to obtain a time-delay response correlation matrix; Performing exceeding judgment on a causal correlation threshold and quantifying causal strength according to the time-delay response correlation matrix to obtain a candidate set of causal event pairs, and performing time logic consistency verification, spatial topology rationality verification and statistical confidence verification based on the candidate set of causal event pairs to obtain a set of potential causal event pairs; Performing time-division multiplexing scheduling on asynchronous data stream resources according to the set of potential causal event pairs to obtain a time window allocation table.

[0030] Specifically, a set of causal detection operators with time delay sensitivity, frequency adjustability and directionality are constructed based on the multi-source asynchronous data stream set, so as to capture the trigger-response behavior existing between various data streams in the time delay domain, and formalize it into a function template or convolution kernel function with mathematical expression ability. The causal detection operator adopts a parameterized expression structure, the core of which includes the reference transmission time, the time delay detection range, the amplitude attenuation model and the phase shift characteristics, and the typical forms include the time delay Gaussian kernel with exponential decay characteristics, the bandpass modulated pulse or the sinusoidal modulated envelope function. Each detection operator is regarded as a causal exciter that slides and scans in the time domain, which sends a trigger signal on the source data stream and monitors the amplitude, occurrence time and similarity of the corresponding response signal on the target data stream, so as to complete a cross-stream causal excitation-response detection operation. After the set of detection operators is constructed, the set is applied to all combinations of the multi-source asynchronous data stream set, that is, a set of preset or adaptively selected detection operators are applied for sliding calculation between each possible source event data stream and target event data stream, and through the integral, convolution or cross-correlation calculation of the interaction response in the time window of the source signal and the target signal, a set of time delay response function curves representing the causal correlation strength is obtained. The system extracts key feature quantities such as response peak value, response time and response width from these curves, and organizes them into a structured time delay response correlation matrix according to the data stream pairs. Each matrix element records the optimal time delay response value of the source stream and the target stream under the given detection parameters. According to the time delay response correlation matrix, the correlation values in the matrix are discriminated item by item according to the preset causal correlation threshold, and the data pairs whose response values exceed the threshold are preliminarily judged as data pairs with causal contact potential and are used as candidate combinations of causal event pairs to enter the screening process. In order to enhance the credibility of causal recognition, three verification operations are performed on all candidate event pairs: time logic consistency verification, which requires that the source event time in all causal event pairs must be earlier than or equal to the target event time, and if the reverse time causality occurs, it is directly excluded; then the spatial topology rationality verification is performed, the system analyzes whether there is a reasonable physical propagation path between the event pairs based on the preset device space connection graph and whether it can propagate within the corresponding time delay under the given propagation speed, and if there is no effective connection path or the propagation time is not consistent, it is marked as an invalid pair; statistical confidence verification is performed on each candidate event pair, which specifically calculates the response consistency and repeatability of the event pair in multiple time windows and multiple sampling periods, and calculates its confidence score based on the background noise model and random event probability model, and only keeps the event pairs with confidence higher than the set threshold to form a set of potential causal event pairs. Based on the set of potential causal event pairs, resource scheduling operation is performed. Based on the asynchronous causal time division multiplexing strategy, under the premise of ensuring the concurrency and independence of the inference task, a unique and non-overlapping data access time window is specified for each pair of causal events.In the specific scheduling process, the time window size required by each causal event pair is calculated, which is adjusted according to the time delay span between events and the causal strength. The greater the strength, the longer the time window to ensure the integrity of the causal conduction information. A priority queue is constructed for all event pairs. The calculation of priority not only considers the causal strength, but also integrates data quality scores, event occurrence frequency, network resource load and other factors to obtain the window allocation priority level through a weighted model. The system checks whether multiple event pairs access the same data stream in the same time period through a conflict detection algorithm. When a conflict is found, the low-priority window is automatically shifted forward or backward for a certain period of time until the conflict is resolved. Finally, the system constructs a time window allocation table, which includes the window start time, duration, access data stream identifier and window priority level of each event pair.

[0031] In a specific embodiment, the process of performing cross-stream correlation calculation on the set of multi-source asynchronous data streams according to the set of causal detection operators to obtain the time delay response correlation matrix can specifically include the following steps: Input the set of causal detection operators into the time delay scanning module, and set the time delay range and deploy the operators in the time delay scanning module to obtain a set of time delay scanning configuration parameters. Based on the set of time delay scanning configuration parameters, calculate the time delay response strength between the set of multi-source asynchronous data streams to obtain a cross-stream response strength matrix. According to the cross-stream response strength matrix, quantize the correlation and normalize the strength of the set of multi-source asynchronous data streams to obtain a time delay response correlation matrix.

[0032] Specifically, the causal probe operator set is input into the time delay scanning module. The time delay scanning module performs range setting and operator arrangement strategy on the entire multi-source data stream set according to the structural parameter characteristics of the received causal probe operator. The strategy involves the deployment density and span control of the operator in the time domain, and the deployment strategy of the operator in the event space, including which group of source-target data stream pairs the operator should be deployed between, the starting time point of the deployment, the scanning granularity and the termination condition and other elements. Therefore, the system analyzes the frequency response characteristics, probe sensitivity adjustment coefficient and applicable data type of each probe operator, and then sets a globally covered but adaptable time delay scanning interval by analyzing the structural characteristics, time tag distribution and asynchronous degree of the current data stream set. The scanning interval is bounded by the minimum response time delay and the maximum probe time delay, and the time step of operator deployment is determined by the sampling period, the sliding window width and the system computing power. After the above parameters are set, all operators and time delay interval configurations are collectively summarized as a time delay scanning configuration parameter set, which limits the probe time delay range, operator deployment method and scanning rhythm between each data stream pair. Based on the time delay scanning configuration parameter set, the system performs a full-coverage response strength calculation operation on the multi-source asynchronous data stream set one by one. The core of the operation is to take the source-target data stream pair as the basic processing unit, scan each pair of data streams according to the set time delay range, deploy the corresponding causal probe operator at each time delay step, complete the excitation-response process calculation in each sliding time window, and record the corresponding response strength index. The response strength is obtained by performing convolution, cross-correlation or feature matching calculation on the causal probe operator and the data segment in the corresponding time window. The calculation result reflects the potential dynamic correlation degree between two asynchronous data streams under a certain time delay offset. During the scanning process, the system continuously moves the scanning window forward and dynamically adjusts the operator parameters to adapt to the data frequency changes and structural fluctuations, finally forming a set of response curves about response strength and time delay offset between each source-target data pair. The system extracts the maximum response value, maximum response position, response width and secondary peak intensity from these response curves, and fills them into the cross-stream response strength matrix according to the combination mode of the data stream pair, constructing a matrix structure with data source number as row and target number as column. Each cell in the matrix corresponds to the maximum response strength value obtained by a data stream pair at its optimal time delay. According to the cross-stream response strength matrix, the system performs quantitative analysis of causal correlation degree and normalization processing of strength value. In the quantitative analysis process, a correlation discrimination function is applied to the response strength value. The function not only determines whether it has causal potential according to the absolute size of the strength value itself, but also combines the response continuity, stability and background noise distribution in the adjacent time delay interval to give each strength value a confidence correction factor.For example, if a data pair has high response peaks in multiple time delay intervals, it is considered a stable causal path and is given a higher weight. Conversely, if it only has a high response at isolated times and lacks continuity, it is considered an accidental peak and its confidence is weakened. In order to make the intensity values between all data flow pairs comparable, the values in the entire cross-flow response intensity matrix are normalized. The maximum value normalization or Z-score standardization method is used to compress all response intensities to a relative dimension consistent interval, eliminating structural bias caused by differences in device type, data source signal-to-noise ratio, or event frequency. The time delay response correlation matrix is obtained.

[0033] In a specific embodiment, the process of performing step-bylenesscheduling of asynchronous data stream resources according to the set of potential causal event pairs to obtain a time window allocation table can specifically include the following steps: Based on the causal delay characteristics and causal intensity weights of each causal event pair in the set of potential causal event pairs, the causal driving window duration is calculated to obtain a set of adaptive window parameters; Based on the set of adaptive window parameters, the integrated priority calculation of causal intensity weighting, time delay reciprocal weighting and data quality weighting is performed to obtain a priority queue; According to the priority queue, causal conflict recognition and minimum causal time delay offset adjustment are performed on causal inference tasks that simultaneously access the same asynchronous data stream to obtain a conflict-free scheduling scheme; Based on the conflict-free scheduling scheme, exclusive access mapping and time slice allocation of causal inference tasks and asynchronous data stream resources are performed to obtain a time window allocation table.

[0034] Specifically, the adaptive calculation of the driving window duration is driven by the causal time delay characteristics and the causal strength weight parameters contained in each pair of potential causal event pairs, and the window duration period is configured for different event pairs to conform to their causal propagation behavior characteristics. For each event pair, the causal time delay and the corresponding strength score identified in the response matrix are extracted, and then a weighted calculation formula controlled by an adjustable coefficient is introduced to dynamically calculate the window duration, which is proportional to the time delay and inversely proportional to the strength, thereby embodying the dual constraint logic of "the longer the propagation distance, the more time should be left, and the stronger the response, the tighter the time should be". The mechanism is regulated by a parameter group to adapt to the different requirements of the trade-off strategy between response integrity and resource occupation in different application scenarios, and the output result constitutes an adaptive window parameter set, which contains information such as event pair identification, duration, and starting estimated time. Based on the adaptive window parameter set, a unified priority sorting mechanism is established for all event pairs. The priority calculation uses a three-factor weighted model, which is based on the causal strength weight, the reciprocal of the causal time delay, and the data quality score. The system extracts the strength score of each event pair, which represents the more reliable the causal path and the greater the inference benefit, so it is given a higher priority. Then the causal time delay is extracted, and the system takes its reciprocal as the causal propagation urgency measure, because shorter causal paths are more likely to be confirmed in time, so they should be scheduled first. A data quality factor is introduced, which is composed of multiple parameters such as data integrity, sampling density, and signal-to-noise ratio, to reflect the availability and confidence of the corresponding event pair at the data level. The system weights and sums the above three types of indicators with a set of adjustable weight coefficients to form the comprehensive priority score of the event pair, and sorts all event pairs in descending order to build a priority sorting queue. According to the priority sorting queue, the causal conflict detection and scheduling optimization are carried out. The system checks each event pair in the priority queue and identifies all data stream access conflicts that exist in resource competition. The basis for conflict identification is: if the time windows scheduled by two event pairs overlap in time and they have at least one common stream identifier in the accessed data stream set, it is determined as a scheduling conflict. For the detected conflict pairs, the system prioritizes the time window of the high-priority event pair, while the low-priority event pair adopts the "minimum causal time delay offset adjustment" strategy, which calculates an acceptable minimum shiftable distance based on the causal time delay of the current event pair, so that its new time window after shifting can still cover the causal propagation effective interval while avoiding overlapping with the high-priority window. If an event pair encounters scheduling conflicts multiple times, the system allows it to gradually accumulate time offset until it is allocated to a conflict-free window, while continuously maintaining dynamic evaluation of causal effectiveness during multiple rounds of offset to ensure that the timeliness of the event is not lost due to excessive delay.In all conflicts are resolved one by one and complete offset adjustment system to the final formation of event pair-window mapping relationship summary, the construction of scheduling results of structured expression form, namely time window allocation table. The table with event pair as the main index field, record its final scheduled time interval, the allocation of asynchronous data stream resources list, window start and end time, access rights attributes and scheduling priority level information such as. Each scheduling entry binding exclusive access flag, ensure that in the window period, its corresponding data stream is only the event pair of causal inference task access, will not be shared with any other event pair resources, so as to minimize the problem of concurrent interference and data mutual exclusion.

[0035] In a specific embodiment, the execution step according to the priority queue of the same asynchronous data stream for causal inference task for causal conflict identification and minimum causal delay offset adjustment, get no conflict scheduling scheme process can specifically include the following steps: Based on the priority queue of the causal inference task for asynchronous data stream access time window overlap interval detection and causal conflict marking, get conflict task pair set; According to the priority weight and causal delay characteristics of each conflict task pair in the conflict task pair set, priority grouping and adjustment, get priority adjustment strategy; For priority adjustment strategy, based on the offset amount of causal delay minimum value calculation and low priority task time window relocation generation causal delay offset parameter set; Based on the causal delay offset parameter set for priority queue time window reassignment and conflict elimination verification, get no conflict scheduling scheme.

[0036] Specifically, the start and end time of each task's time window and the asynchronous data stream set required for exclusive access are extracted, and then all task windows are compared with each other in the time domain. If it is detected that the windows of any two tasks overlap in time and there is an intersection in the set of data streams accessed simultaneously, it is determined that there is a time resource access conflict. It is recorded which data stream the conflict occurs on, and the numbers of the task pair, the corresponding time window parameters and the conflict data stream identifier are summarized as a structured conflict event object. All such conflict events are collected into a conflict task pair set. Each conflict task pair is grouped and locally sorted according to the cause and effect priority, and the scheduling order between conflict pairs is locally solved while maintaining the overall priority structure. The system extracts the priority weight value of each conflict task pair in the initial sorting queue, and extracts the corresponding causal delay parameter as an auxiliary reference dimension. According to the priority weight value, the high-priority tasks are retained in the current scheduling position, and the low-priority tasks are marked as adjustable objects. If the priority weight difference between the two tasks is not enough to significantly distinguish the order, the system will refer to the causal delay value. If a task has a shorter causal propagation time, it is considered more sensitive in logic and should be processed first. Therefore, the system allows slight adjustments to the initial sorting structure in these boundary scenarios, thereby forming a priority adjustment strategy. Based on the priority adjustment strategy, the system performs a causal delay minimum value offset calculation mechanism, and generates the time window relocation parameters of the low-priority task based on this. The offset calculation process first locates the time window start and end positions and the required data stream of the high-priority task in the conflict task pair, then extracts the causal delay parameter of the task, calculates the shortest intervention time gap that the task can tolerate under the premise of ensuring the validity of the causal chain logic, and then defines a minimum safe offset for the low-priority task in this unit. The minimum offset is greater than the shortest response time in the causal propagation process to prevent the task from being unable to effectively cover its causal input path after window overlap. According to the offset value, the time window of the low-priority task is moved backward as a whole, and its start position and end time in the scheduling table are recalculated while keeping its original access data stream set unchanged to minimize scheduling disturbance. All offset calculation results are packaged into a causal delay offset parameter set, each record containing the adjusted task number, the corresponding offset value, the original time window position and the target relocation window interval, forming a time scheduling correction instruction set. The causal delay offset parameter set is used as input to perform window redistribution and conflict elimination verification operations on the original priority sorting queue. This operation updates and replaces the time window of the specified task in the original scheduling queue by applying each offset instruction in turn, and reconstructs the resource mapping structure of the task to the data stream.The system starts the conflict detection verification mechanism after reassigning the window, scans again whether there is still an overlapping intersection between all tasks in the current scheduling table, and automatically triggers the secondary offset mechanism when it is found that there are still unresolved conflicts, and continues to perform offset adjustment until all conflicts are resolved. To ensure that the conflict elimination process does not introduce circular conflicts and chain delay problems, the maximum tolerance number and logical integrity check are set for each round of offset execution to ensure that the adjustment range is controlled and the causal structure time sequence logic is not damaged. After all conflicts are verified to be resolved, the system marks the current state as a conflict-free scheduling scheme, and generates the final time window allocation table and task scheduling table, including the position of each causal task in the execution cycle, the access resource list, the actual use time interval and the scheduling stability index, etc.

[0037] In a specific embodiment, the process of performing step 300 can specifically include the following steps: Adaptive selection of Bayesian causal chain analysis strategy and Markov causal dependence inference strategy based on the set of multi-source asynchronous data streams, to obtain a strategy configuration scheme; Input the set of multi-source asynchronous data streams into the Bayesian causal chain analysis module to construct the causal network node, establish the directed edge relationship and calculate the conditional probability distribution, to obtain a first probability matrix; Input the set of multi-source asynchronous data streams into the Markov causal dependence inference module to define the state space, establish the state transition matrix and calculate the transition probability, to obtain a second probability matrix; According to the strategy configuration scheme, perform probability domain mapping and weight fusion on the first probability matrix and the second probability matrix, to obtain a multi-dimensional causal probability propagation matrix.

[0038] Specifically, the structural characteristics and statistical properties of a multi-source asynchronous data stream set are analyzed, which contains video image events, infrared thermal data, access control state records, and audio voiceprint information, and there are significant differences between these data in terms of time synchronization, event sparsity, and state separability. Therefore, a round of adaptive evaluation is performed on these data, and multiple indicators including data dimension number, sampling frequency difference, cross-source time alignment error, event trigger frequency, and state dispersion degree are calculated, and a strategy decision rule tree is constructed based on this. In the rule tree, when the system determines that the data has the characteristics of high-frequency synchronization, obvious causal path, and clear event chain, the Bayesian causal chain analysis strategy is preferred; when the data presents strong discontinuity, state transition between events, and lack of stable causal chain structure, the Markov causal dependence inference strategy is preferred; in most general scenarios, the system allows the fusion strategy mode, that is, the two models run in parallel, and the unified inference output is formed through weight fusion. The adaptive judgment process outputs a strategy configuration scheme. The multi-source asynchronous data stream set is input into the Bayesian causal chain analysis module to construct an event-driven causal network model. In this module, all identifiable monitoring events are discretized and defined as nodes in the causal network, each node representing an explicit event unit or attribute state, such as "door opening", "temperature rise in a certain area", or "appearance of a specific abnormal sound in audio". Then, the system establishes directed edge relationships between event pairs based on the time sequence of event occurrence, trigger logic, and common distribution in multiple observations. These edges represent potential causal paths, with the direction pointing from the "cause" to the "result". Subsequently, for each pair of event nodes in the network structure, the conditional probability distribution is calculated based on the conditional statistical frequency, obtaining the occurrence probability of each target event given the occurrence of the source event. Through methods such as maximum posterior estimation, structure score optimization, and iterative learning, the node connection and edge weight distribution are continuously optimized to form a first probability matrix centered on conditional probability. Each element of this matrix represents the causal influence strength of a source event on a target event. At the same time, the multi-source asynchronous data stream set is input into the Markov causal dependence inference module in parallel. This module is suitable for modeling the monitoring environment as a series of state spaces and establishing statistical dependence relationships between state transitions. In this module, the system converts various continuous or discrete data streams into a set of finite state spaces through methods such as vector quantization, threshold segmentation, and clustering division, forming state spaces, each of which represents a device or sensor at a certain observation level. Based on the event time series, the transition process between different states in adjacent time periods is learned, and the transition probability matrix is calculated. Each element of this matrix represents the probability of transitioning from state s i to state s jIn the frequency distribution of all observation periods, a state transition matrix is constructed, where each element represents the probability of transition from state i to state j. The system combines the prior state distribution and transition chain length during inference, applies Markov chain Monte Carlo method, maximum likelihood estimation or variational optimization technique to solve parameters, and finally generates a second probability matrix with state logic dependent characteristics, which is suitable for complex scenarios with strong state sparsity, invisible causal path between events but evolutionary rules. According to the strategy configuration scheme, the first probability matrix and the second probability matrix are mapped in the probability domain and the weight is fused to construct a multi-dimensional causal probability propagation matrix. In the probability domain mapping stage, by establishing an event-state mapping rule library, the definition of event nodes in the Bayesian network is mapped to the state space in the Markov model, the semantic alignment of event states is completed through vector embedding, similarity matching or graph structure alignment mechanism, and the probability scales of the two are standardized to make them in the same probability value space. On this basis, according to the fusion weight in the strategy configuration, the weighted superposition operation is performed on the first probability matrix and the second probability matrix to obtain the fused propagation matrix. Each single element of the matrix represents the probability value of a pair of events or states being observed as having a causal evolution trend in the system.

[0039] In a specific embodiment, the process of performing step 400 can specifically include the following steps: According to the local delay parameters of each asynchronous data stream in the time window allocation table, the reference delay calculation, delay deviation quantization and delay correction matrix construction are performed to obtain a set of asynchronous delay compensation parameters; Based on the set of asynchronous delay compensation parameters, the multi-dimensional causal probability propagation matrix is subjected to delay difference threshold value judgment and forward time window sliding compensation to obtain a delay corrected causal probability matrix; Based on the delay corrected causal probability matrix, multi-dimensional delay mode weighted fusion and causal correlation strength calculation are performed to obtain a causal correlation probability matrix; According to the causal correlation probability matrix, the causal chain visualization is performed to obtain a dynamic causal relationship graph.

[0040] Specifically, the local time delay parameter extraction and collection process is performed on all asynchronous data streams recorded in the time window allocation table, and based on this, the reference time delay calculation, time delay deviation quantification and time delay correction matrix construction are performed to form the asynchronous time delay compensation parameter set for unified compensation control. In this phase, the system extracts the local sampling time label, time synchronization offset record and network delay estimate bound to each data stream participating in the causal inference task, and takes the minimum effective time value in all data streams as the global reference, thereby establishing a unified time reference. By comparing the original time parameters of each data stream with the reference time value, the relative offset is calculated, and the relative time deviation between all data streams is arranged into a time delay deviation matrix. Then the time delay correction matrix is formed, and the adjustable compensation modulation factor is used as a dynamic control reference to form the asynchronous time delay compensation parameter set, which includes the reference time, offset data, correction modification parameters and adjustment factor. The compensation parameter set is applied to the original multi-dimensional causal probability propagation matrix to evaluate and correct the time delay difference of all recorded event pairs. In the process of traversing the propagation matrix, the system compares the time source of each group of event pairs in turn to judge whether there is a difference in the collection time between the source data stream and the target data stream, and compares it with the threshold parameter accordingly. If it exceeds the effective time tolerance range set by the system, it is considered that there is a significant time delay deviation. The system performs forward time window sliding compensation for such event pairs, that is, by shifting the inference time window forward on the time axis by a certain compensation length, so that the event occurrence time is closer to the inference start time of its causal source event. To avoid the discontinuity caused by window jumping, the system introduces a dynamic adjustment mechanism for the compensation step size to maintain time consistency within the continuous inference period during window sliding. After completing the time displacement operation, the system marks the updated causal propagation matrix as the time delay correction causal probability matrix. Based on the time delay correction causal probability matrix, multi-dimensional time delay mode weighted fusion is performed to enhance the adaptability and comprehensive interpretation ability of the causal values in the matrix to the response behavior under different time perspectives. The system constructs multiple reference models based on historical observation data, each model generates a set of independent propagation matrix copies based on different time window strategies, and each copy calculates the causal relationship strength from its time compensation perspective. The system then constructs a weighted synthesis mechanism with these copies as input, determines the weight of each copy participating in fusion according to its response accuracy, result stability and observation period confidence level, and outputs the integrated causal correlation probability matrix. The causal correlation probability matrix is input into the visualization rendering module to generate a dynamic causal relationship graph. The causal relationship between each pair of events is represented as a directed edge in the graph, and each event node is mapped to the coordinate position in the three-dimensional graph space according to the time sequence and spatial positioning. At the same time, the edge structure of the graph is bound with the causal probability value and response strength information to define the line thickness, transparency and color change.The system presents the propagation direction and speed of the causal signal in the form of particle animation or optical flow, uses color changes to represent the impact of the event, and reflects the centrality of the event in the global graph through node brightness or size. A timeline support module is constructed for the graph, allowing users to slide along the timeline to view the evolution of causal structures in different time periods, or to backtrack the causal link paths before and after key event points, supporting interactive functions such as structure filtering, node focusing, and path tracking. The system uses a dynamic incremental update strategy to maintain the graph structure, adding nodes and edges for newly identified events, and gradually performing graphical fading processing for expired event paths, thereby avoiding visual disturbances caused by graph jumps and improving the coherence and readability of the graph. At the same time, multi-view windows can be defined based on spatial regions, event categories, and time ranges, allowing for dynamic multi-angle display combining local chain analysis and global topology observation.

[0041] In a specific embodiment, the process of performing step visualizing causal chains based on the causal correlation probability matrix to obtain a dynamic causal relationship graph can specifically include the following steps: Based on the causal correlation probability matrix, a three-dimensional causal graph space is constructed and causal event nodes are mapped to obtain a three-dimensional causal node graph. According to the three-dimensional causal node graph, the correlation between causal events is constructed, particle flow effects are generated, and causal propagation paths are animated to obtain a dynamic causal chain connection graph. Based on the dynamic causal chain connection graph, incremental update calculation, force-directed layout optimization, and node position rearrangement are performed to obtain a layout-optimized causal relationship graph. Based on the layout-optimized causal relationship graph, global view rendering, local view focusing, and timeline view switching are performed to obtain a dynamic causal relationship graph.

[0042] Specifically, according to the causal probability intensity information in the causal correlation probability matrix and the semantic relationship of the event pair, the basic unit of the causal graph atlas is established in the three-dimensional space, that is, the spatial mapping and layout initialization of the event node, forming a three-dimensional causal node graph atlas. The process takes the causal correlation probability matrix as input, where each row of the matrix represents the source event, each column represents the target event, and the value of the corresponding cell represents the causal influence strength between the two. When constructing the atlas, the system takes all participating events as nodes in the atlas, and assigns each node a unique identifier, event semantic label, event space position code, and time attribute value. The position of the node in the three-dimensional causal graph space is distributed in the x-axis through the linear stretching method based on the event time dimension, the event belongs to the region or device level in the y-axis, and the causal strength or event frequency is stacked as the z-axis dimension, forming a three-dimensional node distribution field with time-space-probability triple semantic. In order to avoid node overlap and occlusion, pre-layout coordinate constraints or initial expansion factors based on event cluster density are introduced to expand the dense area, so that each causal event node has an independent distinguishable graphical placeholder in the three-dimensional view. According to the three-dimensional causal node graph atlas, directed edges are constructed for the event pairs in it, thereby connecting the causal paths between nodes, and combining the causal strength value and propagation delay parameter to generate particle flow effect to enhance the dynamic expressiveness of the causal chain. For each pair of event nodes with high causal probability value, the system constructs a directed edge from the source event to the target event, and adds directional identifier, edge weight attribute, propagation delay information and other attributes to the edge, forming a propagable path data structure. In the atlas rendering engine, the directed edge is expressed through detailed graphics, the thickness of the line represents the causal strength, the color gradient represents the difference in event type, and the transparency of the edge is associated with the confidence of the correlation probability, forming a highly informational connection visualization unit. To enhance the user's perception of the causal propagation process, a particle flow animation is superimposed on the directed edge, where the particles flow along the causal chain direction, and their speed and density are controlled by the propagation delay and strength of the event pair. Through the control of the time axis, the system supports dynamic adjustment of the particle flow speed and the animation rhythm of the time process, making the causal propagation process continuous and realistic, and under the control of user interaction, the particle chain segment can be paused, reversed, accelerated or enlarged, forming a dynamic causal chain connection atlas. Based on the dynamic causal chain connection atlas, incremental update calculation, force-directed layout optimization and node position rearrangement are performed to realize the dynamic steady-state reconstruction of the atlas structure. When the system receives a new round of causal analysis output or detects changes in existing causal relationships, it will trigger the atlas incremental update module, which compares the previous version of the atlas with the current causal matrix change content, and only performs differential operation and local atlas structure update on the newly added, deleted or updated nodes and edges, thereby reducing the burden of atlas redrawing and the risk of structure stability damage.After the structure is updated, the current graph is laid out and optimized through a force-directed graph algorithm, specifically including three types of force field parameters joint iteration of repulsion between nodes (avoiding overlap), attraction of causal edges (maintaining connection), and three-dimensional tension balance (controlling graph volume). By continuously calculating the stress between nodes and adjusting their relative positions in three-dimensional space, the visual distance between nodes is balanced, the causal chain path is clear, and the global topology layout is orderly. If there are still node stacking or over-dense conditions in some local areas, the system starts the local position rearrangement mechanism for the area, extracts and expands subgraphs according to event type, frequency or device ownership, and improves node recognition and graph structure permeability. After the above processing is completed, the causal relationship graph is formed after layout optimization. Taking the layout-optimized causal relationship graph as the rendering core carrier, the multi-view graph presentation module is started, and based on user operation requirements or system strategy, the global view rendering, local view focusing and time axis view switching are executed to output the dynamic causal relationship graph. In the global view mode, the whole graph is displayed in a unified three-dimensional coordinate system, retaining the complete connection relationship of all nodes and edges, which is suitable for observing the overall causal structure and path aggregation distribution; in the local view focusing mode, the system allows the user to select an event node or path as the focus, automatically expanding the predecessor causal chain, subsequent response path and all connection edges of the node, and highlighting the focus area through graph jitter suppression and path highlighting mechanism, which is suitable for tracing the cause of the event, understanding the linkage logic or debugging the causal error; the time axis view mode displays the dynamic evolution process of the causal events in frames based on time progress, the system extracts snapshots of the graph structure according to time window slices and serializes them, and plays back the causal chain evolution process continuously and traces the event evolution through the time scroll bar, thereby realizing the temporal understanding of the causal relationship. The three view modes can be dynamically switched, or the graph changes in different scales can be displayed side by side in the same interactive interface, and finally the dynamic causal relationship graph is output.

[0043] The visualization analysis method of the security monitoring data in the embodiment of the application is described above, and the visualization analysis system of the security monitoring data in the embodiment of the application is described below. Please refer to Figure 2 The visualization analysis system of the security monitoring data in the embodiment of the application includes one embodiment: The asynchronous acquisition module 11 is configured to acquire video monitoring data stream, infrared sensor data stream, access control system data stream and audio acquisition data stream in the security monitoring system asynchronously, and obtain a multi-source asynchronous data stream set. The creation module 12 is configured to generate a set of potential causal event pairs based on the multi-source asynchronous data stream set, and create a time window distribution table according to the set of potential causal event pairs. The calculation module 13 is configured to calculate the causal probability of the multi-source asynchronous data stream set, and obtain a multi-dimensional causal probability propagation matrix. The visualization module 14 is used for asynchronous time delay compensation and causal chain visualization of the multi-dimensional causal probability propagation matrix based on the time window allocation table, to obtain a dynamic causal relationship atlas.

[0044] Through the cooperation of the above-mentioned various components, through the independent data stream identifier allocation and original timestamp preservation mechanism, the information loss problem caused by the traditional forced time alignment is avoided, so that the system can accurately capture the original timing characteristics of different monitoring devices, the cross-stream correlation calculation technology based on the causal detection operator set breaks through the limitations of traditional time correlation analysis, and can identify complex causal event pairs in an asynchronous environment, thereby significantly enhancing the discovery ability of the system to potential security threats. The time division multiplexing scheduling strategy and priority sorting mechanism are adopted to realize the conflict-free access of asynchronous data stream resources, solve the resource competition problem in the multi-task concurrent processing of the traditional method, and ensure the accuracy and consistency of the causal inference result. Through the adaptive selection mechanism of Bayesian causal chain analysis and Markov causal dependence inference, the system can intelligently switch the inference strategy according to the data characteristics and environmental conditions, and can maintain good inference performance in high confidence requirement and data sparse environment. Based on the time delay correction matrix and the forward time window sliding compensation algorithm, the cross-device asynchronous event causal relationship misjudgment problem is effectively solved, and the compensation parameters are dynamically adjusted through the Bayesian update mechanism, thereby greatly reducing the error rate of causal relationship identification. A three-dimensional atlas space including time dimension, spatial position dimension and causal strength dimension is constructed, and the particle flow effect and force-directed layout optimization are combined to realize the intuitive dynamic display of the asynchronous data stream causal chain, thereby providing a new monitoring situation awareness experience for security personnel.

[0045] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the above-mentioned system, system and unit can refer to the corresponding process in the foregoing method embodiments, which will not be described herein.

[0046] The integrated unit, if realized in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing an electronic device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the embodiments of the present application. The foregoing storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0047] The above-described and above-embodied examples are merely used to illustrate the technical solutions of the present application, but not to limit the same; although the present application has been described in detail with reference to the foregoing examples, those ordinarily skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing examples, or make equivalent replacement to some technical features therein; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A visual analysis method for security monitoring data, characterized in that: include: Asynchronously collect video surveillance data streams, infrared sensor data streams, access control system data streams, and audio acquisition data streams in a security monitoring system to obtain a multi-source asynchronous data stream set; Generating a set of potential causal event pairs based on the multi-source asynchronous data stream set, and creating a time window allocation table according to the set of potential causal event pairs; Performing causal probability calculation on the multi-source asynchronous data stream set to obtain a multi-dimensional causal probability propagation matrix; Based on the time window allocation table, asynchronous delay compensation and causal chain visualization are performed on the multi-dimensional causal probability propagation matrix to obtain a dynamic causal relationship graph.

2. The visual analysis method for security monitoring data according to claim 1, characterized in that: The asynchronous acquisition of the video surveillance data stream, the infrared sensor data stream, the access control system data stream and the audio acquisition data stream in the security monitoring system to obtain a multi-source asynchronous data stream set includes: Assign data stream identifiers and record original timestamps for the video surveillance data stream, infrared sensor data stream, access control system data stream, and audio acquisition data stream in the security monitoring system, respectively, to obtain an identified data stream set; Based on the identified data stream set, asynchronous data stream cache queue construction and sliding window maintenance processing are performed on the video surveillance data stream, the infrared sensor data stream, the access control system data stream, and the audio acquisition data stream to obtain a cache window matrix; The video surveillance data stream, the infrared sensor data stream, the access control system data stream and the audio acquisition data stream are standardized and converted according to the cache window matrix to obtain a multi-source asynchronous data stream set.

3. The visual analysis method for security monitoring data according to claim 1, characterized in that: Generating a set of potential causal event pairs based on the multi-source asynchronous data stream set, and creating a time window allocation table according to the set of potential causal event pairs, includes: Constructing a causal detection operator set based on the multi-source asynchronous data stream set; Performing cross-flow correlation calculation on the multi-source asynchronous data flow set according to the causal detection operator set to obtain a delay response correlation matrix; Performing exceedance judgment and quantification of causal correlation thresholds based on the time delay response correlation matrix to obtain a candidate set of causal event pairs, and performing temporal logic consistency verification, spatial topology rationality verification, and statistical confidence verification based on the candidate set of causal events to obtain a set of potential causal event pairs; Time-division multiplexing scheduling is performed on asynchronous data stream resources according to the potential causal event pair set to obtain a time window allocation table.

4. The visual analysis method for security monitoring data according to claim 3, characterized in that: The performing cross-flow correlation calculation on the multi-source asynchronous data flow set according to the causal detection operator set to obtain a delay response correlation matrix includes: Inputting the causal detection operator set into a delay scanning module, performing delay range setting and operator deployment on the multi-source asynchronous data stream set in the delay scanning module to obtain a delay scanning configuration parameter set; Based on the delay scan configuration parameter set, calculating the inter-data stream delay response strength of the multi-source asynchronous data stream set to obtain a cross-stream response strength matrix; According to the cross-flow response strength matrix, correlation quantization and strength normalization are performed on the multi-source asynchronous data flow set to obtain a delay response correlation matrix.

5. The visual analysis method for security monitoring data according to claim 3, characterized in that: The time-division multiplexing scheduling of the asynchronous data stream resources according to the potential causal event pair set to obtain a time window allocation table includes: Calculating the duration of a causal driving window based on the causal delay characteristics and causal strength weight of each causal event pair in the set of potential causal event pairs to obtain an adaptive window parameter set; Performing a comprehensive priority calculation based on the adaptive window parameter set by weighting causal strength, inverse delay, and data quality to obtain a priority sorting queue; Performing causal conflict identification and minimum causal delay offset adjustment on causal inference tasks that simultaneously access the same asynchronous data stream according to the priority sorting queue to obtain a conflict-free scheduling solution; Based on the conflict-free scheduling scheme, exclusive access mapping and time segment allocation of causal inference tasks and asynchronous data flow resources are performed to obtain a time window allocation table.

6. The visual analysis method for security monitoring data according to claim 5, characterized in that: The method of performing causal conflict identification and minimum causal delay offset adjustment on causal inference tasks that simultaneously access the same asynchronous data stream according to the priority sorting queue to obtain a conflict-free scheduling scheme includes: Performing overlapping interval detection and causal conflict marking on asynchronous data stream access time windows based on the causal inference tasks in the priority sorting queue to obtain a set of conflicting task pairs; Priority grouping and adjustment are performed according to the priority weight and causal delay characteristics of each conflicting task pair in the conflicting task pair set to obtain a priority adjustment strategy; For the priority adjustment strategy, a causal delay offset parameter set is generated based on the offset calculation of the minimum causal delay and the relocation of the low priority task time window; Based on the causal delay offset parameter set, time windows are reallocated and conflict elimination verification is performed on the priority sorting queue to obtain a conflict-free scheduling solution.

7. The visual analysis method for security monitoring data according to claim 1, characterized in that: The causal probability calculation is performed on the multi-source asynchronous data stream set to obtain a multi-dimensional causal probability propagation matrix, including: Adaptively selecting a Bayesian causal chain analysis strategy and a Markovian causal dependency inference strategy based on the multi-source asynchronous data stream set to obtain a strategy configuration scheme; Inputting the multi-source asynchronous data stream set into the Bayesian causal chain analysis module to construct causal network nodes, establish directed edge relationships, and calculate conditional probability distribution to obtain a first probability matrix; Inputting the multi-source asynchronous data stream set into a Markov causal dependency inference module to perform state space definition, state transition matrix establishment, and transition probability calculation to obtain a second probability matrix; The first probability matrix and the second probability matrix are subjected to probability domain mapping and weight fusion according to the strategy configuration scheme to obtain a multi-dimensional causal probability propagation matrix.

8. The visual analysis method for security monitoring data according to claim 1, characterized in that: The asynchronous delay compensation and causal chain visualization are performed on the multi-dimensional causal probability propagation matrix based on the time window allocation table to obtain a dynamic causal relationship graph, including: performing reference delay calculation, delay deviation quantification, and delay correction matrix construction according to the local delay parameters of each asynchronous data flow in the time window allocation table to obtain an asynchronous delay compensation parameter set; Based on the asynchronous delay compensation parameter set, performing delay difference exceeding threshold judgment and forward time window sliding compensation on the multidimensional causal probability propagation matrix to obtain a delay correction causal probability matrix; Based on the delay correction causal probability matrix, multi-dimensional delay pattern weighted fusion and causal correlation strength calculation are performed to obtain a causal correlation probability matrix; The causal chain is visualized according to the causal association probability matrix to obtain a dynamic causal relationship map.

9. The visual analysis method for security monitoring data according to claim 8, characterized in that: The causal chain visualization is performed according to the causal association probability matrix to obtain a dynamic causal relationship map, including: Based on the causal association probability matrix, a three-dimensional causal graph space is constructed and causal event nodes are mapped to obtain a three-dimensional causal node graph; According to the three-dimensional causal node graph, directed edges are constructed for the association relationships between causal events, particle flow effects are generated, and causal propagation path animation is rendered to obtain a dynamic causal chain connection graph; Performing incremental update calculation, force-directed layout optimization, and node position rearrangement based on the dynamic causal chain connection graph to obtain a layout optimized causal relationship graph; Based on the layout optimization causal relationship map, global view rendering, local view focusing and timeline view switching are performed to obtain a dynamic causal relationship map.

10. A visual analysis system for security monitoring data, characterized in that: A method for visually analyzing security monitoring data according to any one of claims 1 to 9, wherein the visually analyzing security monitoring data system comprises: Asynchronous acquisition module, used to asynchronously acquire video surveillance data stream, infrared sensor data stream, access control system data stream and audio acquisition data stream in the security monitoring system to obtain a multi-source asynchronous data stream set; A creation module, configured to generate a set of potential causal event pairs based on the multi-source asynchronous data stream set, and create a time window allocation table according to the set of potential causal event pairs; A calculation module, configured to perform causal probability calculation on the multi-source asynchronous data stream set to obtain a multi-dimensional causal probability propagation matrix; A visualization module is used to perform asynchronous delay compensation and causal chain visualization on the multi-dimensional causal probability propagation matrix based on the time window allocation table to obtain a dynamic causal relationship map.

Citation Information

Patent Citations

  • Data acquisition and processing method and system for visual monitoring of fire-fighting data

    CN118377805A

  • Security alarm information data interaction system and method

    CN118486152A

  • E-commerce intelligent operation monitoring and collaborative decision-making method based on big data analysis

    CN119539920A

  • Intelligent security monitoring and responding method for power generation enterprise

    CN119783043A

  • Cloud monitoring service operation and maintenance dynamic optimization system and method based on AI intelligent agent

    CN120223501A

Cited By

  • Monitoring system for judging video behavior based on deep learning

    CN121392739A

  • Heterogeneous unmanned cluster multi-modal multi-layer task modeling method and device

    CN121477647A

  • Mining area carbon emission factor data acquisition method and system

    CN121524170A

  • A method and system for collecting carbon emission factor data in mining areas

    CN121524170B