Safety monitoring management method and system based on Internet of Things

By deploying AI chips at the edge and building a spatiotemporal perception network in the cloud, the problem of response delay and false alarms in existing industrial safety monitoring systems has been solved. This approach enables efficient and accurate safety decision-making and dynamic adaptation capabilities, thereby improving the security and reliability of the system.

CN120932176APending Publication Date: 2025-11-11ZHUHAI HAOYU TECH CO LTD

Patent Information

Application Number
CN202511026488.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-24
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing industrial safety monitoring systems suffer from problems such as high response delays, frequent false alarms, inability to dynamically adapt to equipment aging and process changes, and information silos in high-risk scenarios, resulting in long response times and many decision-making blind spots in the handling of major accidents.

Method used

AI chips are deployed at the edge for lightweight model screening, and a spatiotemporal perception network is built in the cloud to integrate multimodal evidence chains. Root cause localization and digital twin simulation are performed by combining causal graphs and knowledge graphs to form a closed-loop optimization system.

Benefits of technology

It achieves millisecond-level response and efficient decision-making, reduces the false negative rate of complex fault identification, improves the timeliness of security defense and the scientific and comprehensive nature of decision-making, and possesses human-like dynamic evolutionary capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120932176A_ABST
    Figure CN120932176A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of safety monitoring, in particular to a safety monitoring management method and system based on the Internet of Things, and the method comprises edge intelligent perception, multi-mode cognitive fusion, danger reasoning and root cause positioning, digital twinborn decision deduction and alarm intelligent merging and response. Compared with the technical defects that in the prior art, response delay is high and key alarms are prone to being missed due to the fact that cloud centralized processing is relied on, a special AI reasoning chip is deployed on the edge side to execute lightweight model real-time preliminary screening, and high-value feature data are uploaded only after abnormity is confirmed; meanwhile, constructing a space-time sensing network deep fusion multi-modal evidence chain at the cloud; according to the architecture, a decision chain of industrial dangerous events from perception to cognition is shortened to be within a second level, collaborative optimization of millisecond-level local blocking of major risks and cloud deep analysis is realized, and the security defense timeliness and reliability of high-risk scenes are greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security monitoring technology, and in particular to a security monitoring and management method and system based on the Internet of Things. Background Technology

[0002] The industrial safety monitoring field is undergoing a transformation from traditional manual inspections to intelligent Internet of Things (IoT) systems. This is particularly true in high-risk scenarios such as chemical plants, power grids, and oil and gas pipelines, where there is an urgent need for minute-level responses to equipment malfunctions, environmental risks, and human violations. While current mainstream solutions have incorporated video surveillance and sensor networks, they largely remain at the level of single-point data alarms, lacking the ability to collaboratively recognize and predictively decide on complex risks.

[0003] Existing technologies have significant drawbacks: edge computing nodes only perform simple threshold checks, and critical alarms are often lost due to network latency; cloud analytics rely on single-modal data streams, and the spatiotemporal misalignment of video and sensor features leads to frequent false alarms; root cause diagnosis is mostly based on expert experience bases and cannot dynamically adapt to equipment aging and process changes; and response decisions lack pre-trial verification mechanisms, with manually formulated plans often causing secondary accidents. More importantly, the fragmentation of each link creates information silos, requiring multiple levels of manual confirmation from risk perception to response execution, and the handling of major incidents still takes tens of minutes.

[0004] This invention proposes an integrated "perception-cognition-decision-evolution" solution: deploying AI chips at the edge to achieve millisecond-level initial event screening; constructing a spatiotemporal perception network in the cloud to fuse multimodal evidence chains; locating hidden faults based on causal graphs and knowledge graphs; quantifying the effectiveness of contingency plans through digital twin simulations; and ultimately forming a closed-loop optimization system. This architecture reconstructs the core logic of security monitoring—transforming passive response into proactive immunity, enabling the industrial security defense system to possess, for the first time, a human-like dynamic evolutionary capability. Summary of the Invention

[0005] To overcome the problems mentioned in the background art, the present invention proposes a security monitoring and management method and system based on the Internet of Things.

[0006] The technical solution of this invention is: a security monitoring and management method based on the Internet of Things, comprising the following steps: S11: Edge intelligent perception, which collects multi-source perception data in real time through edge computing nodes deployed in the monitoring area, including video streams, equipment vibration signals, and environmental parameters; and uses the edge computing nodes equipped with dedicated AI inference chips to run a lightweight neural network model to perform target behavior recognition and equipment anomaly detection, generate structured event data and upload it. S12: Multimodal cognitive fusion constructs a spatiotemporal perception network in the cloud and uses graph neural networks to model the spatial topological relationships of sensor nodes; it fuses video features, device time-series data streams and environmental parameters through a cross-modal attention mechanism to output a multidimensional risk vector and associated device identifiers; S13: Hazard reasoning and root cause localization, based on the structural causal model to analyze the event chain dependency, call the equipment maintenance records and process parameter library in the knowledge graph, calculate the probability distribution of the root cause of the failure and generate predictive maintenance suggestions; S14: Digital twin decision simulation maps real-time monitoring data to a digital twin, injects risk boundary conditions, simulates risk diffusion paths and equipment chain reactions through a physical engine, quantifies and evaluates the cost-benefit matrix of response strategies, and outputs the optimal set of operating instructions. S15: Intelligent alarm merging and response, using spectral clustering algorithm to construct alarm event cause-effect graph, aggregating strongly correlated alarms into composite events; triggering contingency plan executors and generating AR auxiliary work orders according to confidence level; S16: Compare the actual response results with the digital twin simulation data, and dynamically adjust the equipment lifecycle model and risk assessment threshold in the knowledge graph.

[0007] As a preferred option, the specific rules for performing edge intelligent sensing include: A11: The lightweight neural network model is a pruned and quantized YOLOv5s object detection model and a bidirectional LSTM time series analysis model; A12: Dynamically adjust the sensor sampling frequency: When an anomaly is detected, the sampling rate is increased from the baseline 1Hz to 100Hz; A13: Upload the compressed feature vector only when the anomaly confidence level exceeds the preset threshold or the event type belongs to the critical list.

[0008] As a preferred option, when performing multimodal cognitive fusion, the specific steps include: S21: Graph topology construction. Based on the physical connection relationships and spatial coordinates between devices, a topology graph of device nodes is constructed, where: each node represents a monitoring device entity, and the node feature vector includes device type, installation location coordinates, and operating status code; the attributes of the connection edges between nodes include at least one of pipe diameter, cable current carrying capacity, and signal transmission delay. S22: Spatiotemporal feature embedding, using a graph neural network to process the topological graph, calculating the node embedding vector, and its node update formula is: ; in, This represents the embedding vector of node v at layer l. Let v be the set of adjacent nodes. The self-weight matrix, This is the adjacency weight matrix. This represents the feature vector of the adjacent node u at the l-th layer. Represents a non-linear activation function; S23: Cross-modal alignment maps video feature streams, device timing parameters, and environmental monitoring data to a unified spatiotemporal coordinate system; S24: Attention Fusion, which utilizes cross-modal attention mechanisms to fuse heterogeneous data sources; S25: Composite risk identification, inputting fused features to a multilayer perceptron classifier, and outputting risk probabilities, wherein the risk type includes at least one of equipment overload, media leakage, and illegal intrusion; S26: False positive suppression rule, which reduces the confidence weight of risks triggered by single-source data. Specifically, if only video feature detection is abnormal, the output confidence is corrected as follows: If both video feature anomalies and device parameters exceeding thresholds are met simultaneously, the confidence level is increased to: ,in, This is the corrected confidence level. This represents the confidence level before correction.

[0009] Preferably, when mapping video feature streams, device timing parameters, and environmental monitoring data to a unified spatiotemporal coordinate system, the specific steps include: A21: Time alignment is achieved by using a dynamic time warping algorithm to compensate for timestamp discrepancies in heterogeneous data. The warping function is defined as follows: ; in, For the optimal alignment path Let i be the matching point between the video frame timestamp i and the sensor data timestamp j. Let be the absolute time of the i-th video frame. Let be the absolute time of the j-th sensor data. For time Video feature vector at the location, For time Sensor feature vector at the location; A22: Spatial registration, which projects the device's spatial coordinates onto the video frame coordinate system using the camera parameter matrix.

[0010] Preferably, when using cross-modal attention mechanisms to fuse heterogeneous data sources, the specific methods include: S31: Use video features as the query vector and device parameters as the key vector; S32: Attention weight calculation, the principle formula is as follows: ; in, The importance weights of video features at time step t, For the video feature vector at time step t, The query transformation matrix for video features. Let be the sensor feature vector at time step t. The key transformation matrix is ​​a feature of the sensor. Scaling factor This represents the matrix transpose operation; S33: Feature fusion generation, the principle formula is: ; in, The fused feature vector The graph network embedding features of the target device v.

[0011] As a preferred method, when conducting hazard reasoning and root cause localization, the specific steps include: S41: Cause-effect graph construction: Based on the equipment fault tree topology and process dependencies, construct a directed cause-effect graph containing three types of nodes; S42: Bayesian back reasoning, input the observed abnormal event, traverse all possible root cause nodes in the causal graph, call the device historical failure frequency in the knowledge graph to calculate the root cause probability, and output a list of root causes sorted by probability. S43: Dynamic priority weighting, retrieves the recommended maintenance cycle from the knowledge graph to obtain the equipment maintenance record; calculates the proportion of equipment whose actual service time exceeds the recommended cycle, and the weighting rule is to increase the priority weight of the root cause probability of equipment that has exceeded its service life. S44: Predictive maintenance generation. Based on the root cause type, it calls the predefined rule base in the knowledge graph and outputs maintenance instructions in triple format. The maintenance instructions in triple format include the faulty component, confidence probability, and operation instructions.

[0012] Preferably, when constructing a directed causal graph containing three types of nodes, the three types of nodes include: A31: Observation Node: Real-time sensor data; A32: Hidden variable nodes: Equipment material aging degree, corrosion rate; A33: Intervention Node: Manual Operation Instructions.

[0013] As a preferred approach, when conducting digital twin decision-making simulations, the specific steps include: S51: Real-time data mapping synchronizes the device status data collected by the edge sensing layer to the digital twin, establishing a dynamic mirror relationship with the physical device; S52: Risk boundary injection, receives risk parameters output by the multimodal fusion layer, and marks the influence range of the risk source in the twin with a dynamic radius model, wherein the risk radius is calculated in real time based on the material properties; S53: Physics engine simulation, calls the computational fluid dynamics engine to simulate the risk diffusion path, inputs medium physical parameters and environmental parameters, outputs a concentration distribution cloud map updated every 5 seconds; at the same time, it performs equipment chain reaction analysis to predict secondary risks caused by intervention operations; S54: Cost-benefit quantitative assessment, constructing a multi-dimensional assessment system, and scoring the contingency plan according to preset weights; S55: Select the highest-scoring plan to generate a triplet operation instruction, including specific actions, expected effects and verification conditions.

[0014] As a preferred approach, when constructing a multi-dimensional evaluation system and scoring the contingency plans according to preset weights, the specific steps are as follows: A41: Stop-loss time weight 0.6: The time from the start of the operation to the resolution of the risk (in seconds); A42: Economic loss weight 0.3: the sum of equipment damage costs and production losses; A43: Secondary risk weight 0.1: Probability of new failures occurring.

[0015] An IoT-based security monitoring and management system includes: The edge perception module is used to collect multi-source data in real time through nodes with dedicated AI chips, perform target recognition and anomaly detection using lightweight models, generate structured event data, and dynamically adjust the sampling rate. The multimodal fusion module is used to build a spatiotemporal awareness network in the cloud. It fuses video, device and environmental data through a cross-modal attention mechanism, outputs a multi-dimensional risk vector and suppresses single-source misjudgments. The Dangerous Reasoning Module is used to parse event chains based on a structural causal model, calculate root cause probabilities by combining maintenance records from a knowledge graph, and generate predictive maintenance instructions. The digital twin simulation module is used to map device data to the twin in real time, inject dynamic risk radius, simulate diffusion path and chain reaction through physics engine, quantify the evaluation of contingency plan and output the optimal instruction set; The alarm management module is used to merge and associate alarms into composite events using a spectral clustering algorithm, and trigger automatic actuators and AR-assisted work orders according to confidence level. The knowledge optimization module is used to compare the actual response with the twin simulation results, dynamically calibrate the device lifecycle model and risk threshold in the knowledge graph, and realize the continuous evolution of the system.

[0016] The beneficial effects of this invention are: 1. Compared with the technical shortcomings of existing technologies that rely on centralized cloud processing, resulting in high response latency and easy loss of critical alarms, this solution deploys a dedicated AI inference chip at the edge to perform real-time preliminary screening using a lightweight model, uploading high-value feature data only after anomaly confirmation; at the same time, it constructs a spatiotemporal perception network in the cloud to deeply integrate a multimodal evidence chain; this architecture shortens the decision chain from perception to cognition of industrial hazardous events to within seconds, achieving millisecond-level local blocking of major risks and collaborative optimization of deep cloud analysis, significantly improving the timeliness and reliability of security defense in high-risk scenarios; 2. Compared to existing technologies, which suffer from high misjudgment rates due to single-source data and strong reliance on human experience leading to frequent blind spots in safety decision-making, this solution explicitly models the coupling relationships between devices using graph neural networks with physical topological constraints. It also dynamically allocates the weights of video and sensor evidence using a cross-modal attention mechanism. Furthermore, it injects dynamic risk boundaries into digital twins for physical simulation and pre-playing, quantitatively assessing the economic costs and cascading risks of multiple contingency plans. This mechanism significantly reduces the false alarm rate of complex fault identification and can accurately generate handling instructions that balance safety and efficiency, thus reconstructing the scientific and comprehensive nature of industrial safety decision-making. 3. Compared to the inherent limitations of existing static knowledge models, which are difficult to adapt to dynamic changes such as equipment aging and process updates, this solution continuously compares the differences between twin simulations and actual handling effects in the alarm response closed loop, and autonomously calibrates the equipment life cycle prediction curve and risk judgment threshold based on deviation data; at the same time, through the dynamic priority weighting mechanism of equipment exceeding its service life, it drives the maintenance rules in the knowledge graph to iterate in real time; this design enables the system to have human-like experience accumulation capabilities, continuously optimize the accuracy of fault prediction and the effectiveness of contingency plans during continuous operation, and realize the qualitative upgrade of the safety management system from static defense to dynamic immunity. Attached Figure Description

[0017] Figure 1 The diagram shown is a flowchart of the Internet of Things-based security monitoring and management method of the present invention. Figure 2 The diagram shown is a schematic representation of the structure of the Internet of Things-based security monitoring and management system of the present invention. Detailed Implementation

[0018] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0019] Please see Figures 1-2 This invention provides an embodiment: a security monitoring and management method based on the Internet of Things, comprising the following steps: S11: Edge intelligent perception, which collects multi-source perception data in real time through edge computing nodes deployed in the monitoring area, including video streams, equipment vibration signals, and environmental parameters; and uses the edge computing nodes equipped with dedicated AI inference chips to run a lightweight neural network model to perform target behavior recognition and equipment anomaly detection, generate structured event data and upload it. S12: Multimodal cognitive fusion constructs a spatiotemporal perception network in the cloud and uses graph neural networks to model the spatial topological relationships of sensor nodes; it fuses video features, device time-series data streams and environmental parameters through a cross-modal attention mechanism to output a multidimensional risk vector and associated device identifiers; S13: Hazard reasoning and root cause localization, based on the structural causal model to analyze the event chain dependency, call the equipment maintenance records and process parameter library in the knowledge graph, calculate the probability distribution of the root cause of the failure and generate predictive maintenance suggestions; S14: Digital twin decision simulation maps real-time monitoring data to a digital twin, injects risk boundary conditions, simulates risk diffusion paths and equipment chain reactions through a physical engine, quantifies and evaluates the cost-benefit matrix of response strategies, and outputs the optimal set of operating instructions. S15: Intelligent alarm merging and response, using spectral clustering algorithm to construct alarm event cause-effect graph, aggregating strongly correlated alarms into composite events; triggering contingency plan executors and generating AR auxiliary work orders according to confidence level; S16: Compare the actual response results with the digital twin simulation data, and dynamically adjust the equipment lifecycle model and risk assessment threshold in the knowledge graph.

[0020] As described above, this invention achieves millisecond-level initial screening of multi-source data through edge intelligent perception, and constructs a spatiotemporal perception network by combining cloud-based multimodal fusion to eliminate single-source misjudgments; it utilizes hazard reasoning to locate root causes and digital twin inference to pre-verify strategies, and optimizes response efficiency through alarm merging, ultimately forming a knowledge closed-loop self-optimization mechanism, significantly improving the real-time performance (response <200ms), accuracy (false alarm rate <5%), decision reliability (pre-plan verification pass rate 92%), and system adaptability (fault prediction accuracy improved by 37%) of safety monitoring.

[0021] As a preferred option, the specific rules for performing edge intelligent sensing include: A11: The lightweight neural network model is a pruned and quantized YOLOv5s object detection model and a bidirectional LSTM time series analysis model; A12: Dynamically adjust the sensor sampling frequency: When an anomaly is detected, the sampling rate is increased from the baseline 1Hz to 100Hz; A13: Upload the compressed feature vector only when the anomaly confidence level exceeds the preset threshold or the event type belongs to the critical list.

[0022] As described above, this invention, by limiting the combination of YOLOv5s+LSTM lightweight model and dynamic sampling rules (1Hz→100Hz), ensures a critical event capture rate of >99% while reducing edge computing load by 50%, and reduces bandwidth usage by 83% through compressed feature transmission, thus solving the bottleneck problem of computing power and bandwidth in traditional edge nodes.

[0023] As a preferred option, when performing multimodal cognitive fusion, the specific steps include: S21: Graph topology construction. Based on the physical connection relationships and spatial coordinates between devices, a topology graph of device nodes is constructed, where: each node represents a monitoring device entity, and the node feature vector includes device type, installation location coordinates, and operating status code; the attributes of the connection edges between nodes include at least one of pipe diameter, cable current carrying capacity, and signal transmission delay. S22: Spatiotemporal feature embedding, using a graph neural network to process the topological graph, calculating the node embedding vector, and its node update formula is: ; in, This represents the embedding vector of node v at layer l. Let v be the set of adjacent nodes. The self-weight matrix, This is the adjacency weight matrix. This represents the feature vector of the adjacent node u at the l-th layer. Represents a non-linear activation function; S23: Cross-modal alignment maps video feature streams, device timing parameters, and environmental monitoring data to a unified spatiotemporal coordinate system; S24: Attention Fusion, which utilizes cross-modal attention mechanisms to fuse heterogeneous data sources; S25: Composite risk identification, inputting fused features to a multilayer perceptron classifier, and outputting risk probabilities, wherein the risk type includes at least one of equipment overload, media leakage, and illegal intrusion; S26: False positive suppression rule, which reduces the confidence weight of risks triggered by single-source data. Specifically, if only video feature detection is abnormal, the output confidence is corrected as follows: If both video feature anomalies and device parameters exceeding thresholds are met simultaneously, the confidence level is increased to: ,in, This is the corrected confidence level. This represents the confidence level before correction.

[0024] As described above, this invention constrains the GNN embedding process by constructing a topology graph with physical attributes (pipe diameter / cable current carrying capacity), and combines cross-modal attention and false positive suppression rules to improve the accuracy of composite risk identification from 68% to 96%, especially reducing the false negative rate by 41% in early equipment failure scenarios.

[0025] Preferably, when mapping video feature streams, device timing parameters, and environmental monitoring data to a unified spatiotemporal coordinate system, the specific steps include: A21: Time alignment is achieved by using a dynamic time warping algorithm to compensate for timestamp discrepancies in heterogeneous data. The warping function is defined as follows: ; in, For the optimal alignment path Let i be the matching point between the video frame timestamp i and the sensor data timestamp j. Let be the absolute time of the i-th video frame. Let be the absolute time of the j-th sensor data. For time Video feature vector at the location, For time Sensor feature vector at the location; A22: Spatial registration, which projects the device's spatial coordinates onto the video frame coordinate system using the camera parameter matrix.

[0026] As described above, this invention compensates for heterogeneous data timestamp deviations by employing the DTW algorithm (tolerating ±500ms dynamic delay) and achieves millimeter-level spatial registration through camera parameters, ensuring that the video and sensor data alignment error is <0.1 seconds / 5cm, thus eliminating feature misalignment problems caused by mechanical vibration transmission.

[0027] Preferably, when using cross-modal attention mechanisms to fuse heterogeneous data sources, the specific methods include: S31: Use video features as the query vector and device parameters as the key vector; S32: Attention weight calculation, the principle formula is as follows: ; in, The importance weights of video features at time step t, For the video feature vector at time step t, The query transformation matrix for video features. Let be the sensor feature vector at time step t. The key transformation matrix is ​​a feature of the sensor. Scaling factor This represents the matrix transpose operation; S33: Feature fusion generation, the principle formula is: ; in, The fused feature vector The graph network embedding features of the target device v.

[0028] As described above, this invention achieves dynamic allocation of the contribution of video and sensor evidence in chemical leakage scenarios through query-key vector transformation and topological embedding feature weighting (with formula limitation) (e.g., flame video weight 0.92 + gas concentration weight 0.15), thereby improving the interpretability of fusion decision by 90%.

[0029] As a preferred method, when conducting hazard reasoning and root cause localization, the specific steps include: S41: Cause-effect graph construction: Based on the equipment fault tree topology and process dependencies, construct a directed cause-effect graph containing three types of nodes; S42: Bayesian back reasoning, input the observed abnormal event, traverse all possible root cause nodes in the causal graph, call the device historical failure frequency in the knowledge graph to calculate the root cause probability, and output a list of root causes sorted by probability. S43: Dynamic priority weighting, retrieves the recommended maintenance cycle from the knowledge graph to obtain the equipment maintenance record; calculates the proportion of equipment whose actual service time exceeds the recommended cycle, and the weighting rule is to increase the priority weight of the root cause probability of equipment that has exceeded its service life. S44: Predictive maintenance generation. Based on the root cause type, it calls the predefined rule base in the knowledge graph and outputs maintenance instructions in triple format. The maintenance instructions in triple format include the faulty component, confidence probability, and operation instructions.

[0030] As described above, this invention reduces the diagnosis speed of latent faults such as seal aging from 45 minutes to 20 seconds by using Bayesian back-reasoning and weighted rules for extended service life, and increases the executability rate of maintenance suggestions from 68% to 95% (the triplet instruction is directly associated with the spare parts library and process specifications).

[0031] Preferably, when constructing a directed causal graph containing three types of nodes, the three types of nodes include: A31: Observation Node: Real-time sensor data; A32: Hidden variable nodes: Equipment material aging degree, corrosion rate; A33: Intervention Node: Manual Operation Instructions.

[0032] As described above, this invention, by defining a ternary structure of observation nodes, latent variable nodes, and intervention nodes, reveals the coupling effect of modeling equipment degradation, environmental corrosion, and human operation, achieving a root cause localization accuracy of 97.3% in oil pump failure cases.

[0033] As a preferred approach, when conducting digital twin decision-making simulations, the specific steps include: S51: Real-time data mapping synchronizes the device status data collected by the edge sensing layer to the digital twin, establishing a dynamic mirror relationship with the physical device; S52: Risk boundary injection, receives risk parameters output by the multimodal fusion layer, and marks the influence range of the risk source in the twin with a dynamic radius model, wherein the risk radius is calculated in real time based on the material properties; S53: Physics engine simulation, calls the computational fluid dynamics engine to simulate the risk diffusion path, inputs medium physical parameters and environmental parameters, outputs a concentration distribution cloud map updated every 5 seconds; at the same time, it performs equipment chain reaction analysis to predict secondary risks caused by intervention operations; S54: Cost-benefit quantitative assessment, constructing a multi-dimensional assessment system, and scoring the contingency plan according to preset weights; S55: Select the highest-scoring plan to generate a triplet operation instruction, including specific actions, expected effects and verification conditions.

[0034] As described above, this invention reduces the error in predicting the leakage impact range from ±35% to ±8% and the time required for contingency plan verification from 30 minutes to 15 seconds by using a dynamic radius model (R=k√(leakage amount / safe concentration)) and CFD physical simulation, thus avoiding the blindness of manual decision-making.

[0035] As a preferred approach, when constructing a multi-dimensional evaluation system and scoring the contingency plans according to preset weights, the specific steps are as follows: A41: Stop-loss time weight 0.6: The time from the start of the operation to the resolution of the risk (in seconds); A42: Economic loss weight 0.3: the sum of equipment damage costs and production losses; A43: Secondary risk weight 0.1: Probability of new failures occurring.

[0036] As described above, this invention, by setting three-dimensional quantitative indicators (stop-loss time / economic loss / secondary risk) with weights of 0.6 / 0.3 / 0.1, reduced the economic loss of accident handling plans by 62% and the incidence of secondary risks by <7% in actual tests at 10 chemical plants.

[0037] An IoT-based security monitoring and management system includes: The edge perception module is used to collect multi-source data in real time through nodes with dedicated AI chips, perform target recognition and anomaly detection using lightweight models, generate structured event data, and dynamically adjust the sampling rate. The multimodal fusion module is used to build a spatiotemporal awareness network in the cloud. It fuses video, device and environmental data through a cross-modal attention mechanism, outputs a multi-dimensional risk vector and suppresses single-source misjudgments. The Dangerous Reasoning Module is used to parse event chains based on a structural causal model, calculate root cause probabilities by combining maintenance records from a knowledge graph, and generate predictive maintenance instructions. The digital twin simulation module is used to map device data to the twin in real time, inject dynamic risk radius, simulate diffusion path and chain reaction through physics engine, quantify the evaluation of contingency plan and output the optimal instruction set; The alarm management module is used to merge and associate alarms into composite events using a spectral clustering algorithm, and trigger automatic actuators and AR-assisted work orders according to confidence level. The knowledge optimization module is used to compare the actual response with the twin simulation results, dynamically calibrate the device lifecycle model and risk threshold in the knowledge graph, and realize the continuous evolution of the system.

[0038] As described above, this invention achieves full-link collaboration between edge, cloud, decision-making, and optimization through modular design: the edge perception module improves computing power utilization by 3 times; the twin simulation module supports parallel simulation of 50 plans; and the knowledge optimization module reduces the error rate of the equipment life model by 12% per quarter, forming a continuous evolutionary closed loop.

[0039] Example 1: Handling of a benzene leak accident at a chemical plant This system is deployed in the catalytic cracking unit area of ​​a large-scale refinery. The edge sensing module collects video streams (thermal imaging cameras) and gas sensor data in real time through nodes equipped with NPU chips. When the benzene concentration is detected to suddenly rise from 50ppm to 520ppm (threshold 200ppm), the YOLOv5s model identifies the white mist-like leakage source at the V101 flange of the storage tank within 150ms. Simultaneously, it triggers the LSTM model to increase the sampling rate of the vibration sensor to 100Hz, captures the abnormal 20Hz high-frequency vibration waveform, compresses the features, and uploads them to the cloud.

[0040] The multimodal fusion module constructs a topology map (GNN modeling) including storage tanks / pipelines / valves. It aligns the thermal image temperature peak (312℃) with the vibration spectrum timestamp using the DTW algorithm, and assigns a video weight of 0.92 and a sensor weight of 0.87 through a cross-modal attention mechanism. The fusion identifies the risk of "benzene leakage due to seal failure" (98.7% probability). The hazard reasoning module retrieves the knowledge graph: the flange seal has been in service for 14 months (standard cycle 12 months). Bayesian back-calculation determines the seal aging probability to be 94.3%, and after dynamic weighting, outputs a triple instruction: <Sealing ring, 0.99, for pressurized sealing and leak plugging> The digital twin simulation module, using parameters of a benzene leakage rate of 22 L / min and a wind speed of 3 m / s, dynamically calculated a risk radius R = 8.2 m. CFD simulation showed that closing the upstream valve V201 could control the liquid flow within 40 seconds, but would trigger a 32% risk of negative pressure in the downstream pump. After a cost-benefit assessment (with a weighting of 0.6 for stoppage time), the proposed solution scored 91 points, superior to the start-up neutralization system (76 points). The alarm management module grouped gas alarms, abnormal vibrations, and video alarms into "Leakage Event #101," automatically triggering a valve closure command and pushing an AR work order to the maintenance team. AR Guidelines: Locate flange bolt B4 → Install leak-sealing clamp → Confirm pressure < 0.3 MPa Post-treatment monitoring showed that the actual leakage was 15% less than the simulation. The knowledge optimization module adjusted the sealing ring life model from 12 months to 10 months and lowered the vibration threshold by 5 Hz.

[0041] Example 2: Overheating fault in high-voltage substation cables This system is used in State Grid's 500kV substations. The edge sensing module uses an infrared camera to identify when the temperature of a cable joint rises from 85℃ to 142℃. The AI ​​chip runs a lightweight ResNet model to locate the hot spot (coordinates X35, Y82). At the same time, the current sensor detects that the third harmonic distortion rate exceeds the limit, and the dynamic sampling rate is increased to 1kHz to capture transient inrush current.

[0042] The multimodal fusion module establishes an electrical topology including transformers, circuit breakers, and cables. A GNN embedding layer explicitly models the conduction relationship between cable current carrying capacity and joint temperature. Spatial registration maps infrared coordinates to a GIS map. Cross-modal attention-weighted temperature features (0.89) and harmonic features (0.94) identify the risk of "joint oxidation leading to poor contact." The hazard reasoning module retrieves information from the knowledge graph: the joint was last maintained 5 years ago (recommended interval 3 years). Bayesian probability calculation shows an oxidation degradation probability of 89.7%. The output is weighted after the overdue period. <Cable connector J7, 0.96, replace during off-peak hours at night> The digital twin simulation module incorporates risk parameters: ambient temperature 40℃, load rate 92%, and CFD simulation of the heat spread path indicates that adjacent cables will ignite within 6 hours. Two contingency plans are evaluated: Contingency Plan A: Immediate power outage for replacement → Economic loss (power outage penalty ¥1.2 million) Rating: 68 Contingency Plan B: Replace after transferring 70% of the load → Stop loss time 105 minutes but zero loss score 92 Generate optimal instructions: Operation: Start load scheduling → Set water mist cooling in isolation zone J7 → Replace at 00:00 The alarm management module aggregates temperature / harmonic / infrared alarms into "Overload Event #205". The system automatically executes load scheduling instructions, and AR work orders guide the installation of temporary cooling covers. In actual handling, the load transfer time is 18 minutes shorter than in simulation. The knowledge optimization module shortens the maintenance cycle of similar connectors to 2.5 years and increases the harmonic distortion weighting coefficient.

[0043] The embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the present invention is not limited to the above embodiments. Within the scope of knowledge possessed by those skilled in the art, various changes can be made without departing from the spirit of the present invention.

Claims

1. A security monitoring and management method based on the Internet of Things, characterized in that: Includes the following steps: S11: Edge intelligent perception, which collects multi-source perception data in real time through edge computing nodes deployed in the monitoring area, including video streams, equipment vibration signals, and environmental parameters; and uses the edge computing nodes equipped with dedicated AI inference chips to run a lightweight neural network model to perform target behavior recognition and equipment anomaly detection, generate structured event data and upload it. S12: Multimodal cognitive fusion constructs a spatiotemporal perception network in the cloud and uses graph neural networks to model the spatial topological relationships of sensor nodes; it fuses video features, device time-series data streams and environmental parameters through a cross-modal attention mechanism to output a multidimensional risk vector and associated device identifiers; S13: Hazard reasoning and root cause localization, based on the structural causal model to analyze the event chain dependency, call the equipment maintenance records and process parameter library in the knowledge graph, calculate the probability distribution of the root cause of the failure and generate predictive maintenance suggestions; S14: Digital twin decision simulation maps real-time monitoring data to a digital twin, injects risk boundary conditions, simulates risk diffusion paths and equipment chain reactions through a physical engine, quantifies and evaluates the cost-benefit matrix of response strategies, and outputs the optimal set of operating instructions. S15: Intelligent alarm merging and response, using spectral clustering algorithm to construct alarm event cause-effect graph, aggregating strongly correlated alarms into composite events; triggering contingency plan executors and generating AR auxiliary work orders according to confidence level; S16: Compare the actual response results with the digital twin simulation data, and dynamically adjust the equipment lifecycle model and risk assessment threshold in the knowledge graph.

2. The security monitoring and management method based on the Internet of Things according to claim 1, characterized in that: When performing edge intelligence sensing, the specific rules include: A11: The lightweight neural network model is a pruned and quantized YOLOv5s object detection model and a bidirectional LSTM time series analysis model; A12: Dynamically adjust the sensor sampling frequency: When an anomaly is detected, the sampling rate is increased from the baseline 1Hz to 100Hz; A13: Upload the compressed feature vector only when the anomaly confidence level exceeds the preset threshold or the event type belongs to the critical list.

3. The security monitoring and management method based on the Internet of Things according to claim 2, characterized in that: When performing multimodal cognitive fusion, the specific steps include: S21: Graph topology construction. Based on the physical connection relationships and spatial coordinates between devices, a topology graph of device nodes is constructed, where: each node represents a monitoring device entity, and the node feature vector includes device type, installation location coordinates, and operating status code; the attributes of the connection edges between nodes include at least one of pipe diameter, cable current carrying capacity, and signal transmission delay. S22: Spatiotemporal feature embedding, which uses graph neural networks to process the topological graph and calculates node embedding vectors; S23: Cross-modal alignment maps video feature streams, device timing parameters, and environmental monitoring data to a unified spatiotemporal coordinate system; S24: Attention Fusion, which utilizes cross-modal attention mechanisms to fuse heterogeneous data sources; S25: Composite risk identification, inputting fused features to a multilayer perceptron classifier, and outputting risk probabilities, wherein the risk type includes at least one of equipment overload, media leakage, and illegal intrusion; S26: Misjudgment suppression rule, which reduces the confidence weight of risks triggered by single-source data.

4. The security monitoring and management method based on the Internet of Things according to claim 3, characterized in that: When mapping video feature streams, device timing parameters, and environmental monitoring data to a unified spatiotemporal coordinate system, the specific steps include: A21: Time alignment, using a dynamic time warping algorithm to compensate for timestamp discrepancies in heterogeneous data; A22: Spatial registration, which projects the device's spatial coordinates onto the video frame coordinate system using the camera parameter matrix.

5. The security monitoring and management method based on the Internet of Things according to claim 4, characterized in that: When using cross-modal attention mechanisms to fuse heterogeneous data sources, the specific steps include: S31: Use video features as the query vector and device parameters as the key vector; S32: Attention weight calculation, the principle formula is as follows: ; in, The importance weights of video features at time step t, For the video feature vector at time step t, The query transformation matrix for video features. Let be the sensor feature vector at time step t. The key transformation matrix is ​​a feature of the sensor. Scaling factor This represents the matrix transpose operation; S33: Feature fusion generation, the principle formula is: ; in, The fused feature vector The graph network embedding features of the target device v.

6. The security monitoring and management method based on the Internet of Things according to claim 5, characterized in that: When conducting hazard reasoning and root cause localization, the specific steps include: S41: Cause-effect graph construction: Based on the equipment fault tree topology and process dependencies, construct a directed cause-effect graph containing three types of nodes; S42: Bayesian back reasoning, input the observed abnormal event, traverse all possible root cause nodes in the causal graph, call the device historical failure frequency in the knowledge graph to calculate the root cause probability, and output a list of root causes sorted by probability. S43: Dynamic priority weighting, retrieves the recommended maintenance cycle from the knowledge graph to obtain the equipment maintenance record; calculates the proportion of equipment whose actual service time exceeds the recommended cycle, and the weighting rule is to increase the priority weight of the root cause probability of equipment that has exceeded its service life. S44: Predictive maintenance generation. Based on the root cause type, it calls the predefined rule base in the knowledge graph and outputs maintenance instructions in triple format. The maintenance instructions in triple format include the faulty component, confidence probability, and operation instructions.

7. A security monitoring and management method based on the Internet of Things according to claim 6, characterized in that: When constructing a directed causal graph containing three types of nodes, the three types of nodes include: A31: Observation Node: Real-time sensor data; A32: Hidden variable nodes: Equipment material aging degree, corrosion rate; A33: Intervention Node: Manual Operation Instructions.

8. A security monitoring and management method based on the Internet of Things according to claim 7, characterized in that: The specific aspects of conducting digital twin decision simulations include: S51: Real-time data mapping synchronizes the device status data collected by the edge sensing layer to the digital twin, establishing a dynamic mirror relationship with the physical device; S52: Risk boundary injection, receives risk parameters output by the multimodal fusion layer, and marks the influence range of the risk source in the twin with a dynamic radius model, wherein the risk radius is calculated in real time based on the material properties; S53: Physics engine simulation, calls the computational fluid dynamics engine to simulate the risk diffusion path, inputs medium physical parameters and environmental parameters, outputs a concentration distribution cloud map updated every 5 seconds; at the same time, it performs equipment chain reaction analysis to predict secondary risks caused by intervention operations; S54: Cost-benefit quantitative assessment, constructing a multi-dimensional assessment system, and scoring the contingency plan according to preset weights; S55: Select the highest-scoring plan to generate a triplet operation instruction, including specific actions, expected effects and verification conditions.

9. A security monitoring and management method based on the Internet of Things according to claim 8, characterized in that: When constructing a multi-dimensional evaluation system and scoring the contingency plan according to preset weights, the specific steps are as follows: A41: Stop-loss time weight 0.6: The time from the start of the operation to the resolution of the risk (in seconds); A42: Economic loss weight 0.3: the sum of equipment damage costs and production losses; A43: Secondary risk weight 0.1: Probability of new failures occurring.

10. A security monitoring and management system based on the Internet of Things, characterized in that: include: The edge perception module is used to collect multi-source data in real time through nodes with dedicated AI chips, perform target recognition and anomaly detection using lightweight models, generate structured event data, and dynamically adjust the sampling rate. The multimodal fusion module is used to build a spatiotemporal awareness network in the cloud. It fuses video, device and environmental data through a cross-modal attention mechanism, outputs a multi-dimensional risk vector and suppresses single-source misjudgments. The Dangerous Reasoning Module is used to parse event chains based on a structural causal model, calculate root cause probabilities by combining maintenance records from a knowledge graph, and generate predictive maintenance instructions. The digital twin simulation module is used to map device data to the twin in real time, inject dynamic risk radius, simulate diffusion path and chain reaction through physics engine, quantify the evaluation of contingency plan and output the optimal instruction set; The alarm management module is used to merge and associate alarms into composite events using a spectral clustering algorithm, and trigger automatic actuators and AR-assisted work orders according to confidence level. The knowledge optimization module is used to compare the actual response with the twin simulation results, dynamically calibrate the device lifecycle model and risk threshold in the knowledge graph, and realize the continuous evolution of the system.

Citation Information

Patent Citations

  • Looped network unit monitoring method and system based on Internet of Things

    CN119891567A

  • Miner safety early warning system based on UWB and AI cameras

    CN120159527A

  • Coal-fired power plant safety monitoring system and method

    CN120258602A

  • Multi-protocol transmission text data monitoring and warning method and system

    CN120321267A

  • Multi-data-source rapid grading and screening system and method for security and protection

    CN120337154A

Cited By

  • Intelligent safety monitoring and dynamic risk management and control system and method for polyvinyl chloride polymerization section

    CN121526312A

  • Dynamic reconstruction method and system for control loop of abnormal event flow causal inference

    CN121541630A

  • Iron tower basic environment data fusion control method and system for low-temperature environment

    CN121578684A

  • Cascade failure assessment method for underground water supply pipeline structure

    CN121765878A

  • Logistics collaborative scheduling method and system based on security risk event driving

    CN121882728A