An autonomous security monitoring method and system based on dynamic threat fields
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-23
- Publication Date
- 2026-04-03
AI Technical Summary
Existing security monitoring technologies are prone to false alarms and missed alarms, have difficulty distinguishing between threatening behaviors and normal activities, lack multi-unit collaborative response, cannot dynamically assess threats in complex environments in real time, and have high computational resource requirements.
By capturing the threat load of unknown targets through behavioral entropy analysis, a threat potential energy field for multi-agent perception is constructed, a field gradient-driven agent strategy is generated, threat load mitigation and barrier establishment are carried out, and the core model parameters are optimized through meta-learning.
It enables sensitive adaptation to environmental changes, achieves global collaborative response, improves security and real-time threat assessment capabilities, and reduces computing resource requirements.
Smart Images

Figure CN120977059B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of security monitoring technology, specifically relating to an autonomous security monitoring method and system based on a dynamic threat field. Background Technology
[0002] Existing security monitoring technologies mainly include video surveillance, motion detection, intrusion detection systems, and machine learning-based behavioral analysis. Video surveillance relies on manual monitoring or simple motion triggers, making it prone to false alarms and false negatives, and it cannot interpret behavioral semantics. Motion detection technology is sensitive to environmental changes and struggles to distinguish between threatening behaviors and normal activities. Intrusion detection systems are mostly rule-based or signature-based, lacking adaptability to unknown threats. Machine learning-based methods require large amounts of labeled data for training, have weak model generalization capabilities, and high computational resource requirements. Furthermore, existing technologies often employ centralized architectures, resulting in high response latency, a lack of multi-unit collaboration, and an inability to dynamically assess threats and coordinate responses in real time in complex environments. For example, traditional monitoring systems cannot handle gradual changes in behavioral patterns or coordinated attacks, and parameter adjustments rely on experience, leading to inefficiency. Summary of the Invention
[0003] To address the aforementioned problems in the existing technology, this invention provides an autonomous security monitoring method and system based on a dynamic threat field.
[0004] The objective of this invention can be achieved through the following technical solutions:
[0005] An autonomous security monitoring method based on a dynamic threat field, the implementation of which includes the following steps:
[0006] Step S1: Capture unknown targets and obtain the threat load of the unknown targets based on behavioral entropy analysis;
[0007] Step S2: Perform multi-agent perception based on the threat payload and obtain the total threat field strength to form a threat potential energy field;
[0008] Step S3: Generate an agent strategy driven by the field gradient based on the threat potential field and send it to the agent;
[0009] Step S4: Perform threat load mitigation and barrier establishment based on the agent's strategy;
[0010] Step S5: Optimize core model parameters through meta-learning.
[0011] Preferably, the behavioral entropy analysis in step S1 specifically includes:
[0012] Obtain the behavioral micro-state entropy of the unknown target;
[0013] The threat charge is obtained based on the behavioral microstate entropy, mathematically described as follows: ,in, Threat load for unknown target i, Let k be the rate of change of the threat load with time t, and k be a transformation constant greater than 0. Let i be the microstate entropy of the behavior of the unknown target i.
[0014] Preferably, the acquisition of the behavioral micro-state entropy specifically involves:
[0015] Define microstates, which include velocity state, rate of change of direction, and interaction state;
[0016] By reviewing all microstate samples within a preset time period, the probability of each microstate occurring is obtained, and the entropy of the behavioral microstate is obtained.
[0017] Preferably, the multi-agent perception in step S2 specifically includes:
[0018] Obtain the coordinates of the unknown target; preset the inherent risk value of the environment; based on the coordinates of the unknown target and the inherent risk value, obtain the total threat field strength, mathematically described as follows: ,in, Let r be the total threat field strength at position r at time t. Let r be the inherent risk value at position r, and n be the number of unknown targets. For the threat load of an unknown target i at time t, Let be the path distance from the unknown target i to position r. To sense the attenuation distance.
[0019] Preferably, step S3 specifically includes:
[0020] Obtain the agent's location, and based on the agent's location, obtain the total threat field strength at the agent's location;
[0021] Obtaining the agent's decision vector and generating the agent's policy can be mathematically described as follows: ,in, Let be the decision vector. The total threat field strength at the location of the agent. for The length of the mold, The gradient of the total threat field strength. A randomly generated vector. It is a constant. This is a random disturbance term.
[0022] Preferably, step S4 specifically includes:
[0023] The threat load mitigation specifically involves: the agent moving to the vicinity of the unknown target according to the agent strategy, and applying a negative threat load locally to offset the threat load generated by the unknown target; the barrier establishment specifically involves: after receiving a warning that the total threat field strength is too high, the barrier agent moves to an alternative path leading to the core area, using its own existence to increase the inherent risk value of the path it is on, thus preventing the unknown target from approaching.
[0024] Preferably, step S5 specifically includes:
[0025] Based on the total threat field strength at the previous moment and the current field attenuation coefficient value, the predicted rate of change of field strength is calculated through simulation; based on the total threat field strength at the previous moment and the current actual measured total threat field strength, the actual rate of change of field strength is calculated; based on the predicted rate of change of field strength and the actual rate of change of field strength, the adjustment amount of the field attenuation coefficient is obtained, mathematically described as follows: ,in, This is the adjustment amount for the field attenuation coefficient. The meta-learning rate, For the predicted rate of change of field strength, This represents the actual rate of change of the field strength.
[0026] An autonomous security monitoring system based on a dynamic threat field is used to execute the autonomous security monitoring method based on the dynamic threat field described above, including a behavior entropy analysis module, a multi-agent perception module, an agent policy generation module, and a decision-making and optimization module.
[0027] The behavior entropy analysis module is used to capture unknown targets and obtain the threat load of the unknown targets based on behavior entropy analysis;
[0028] The multi-agent perception module is used to perform multi-agent perception based on the threat charge and obtain the total threat field strength, forming a threat potential energy field.
[0029] The agent policy generation module is used to generate an agent policy driven by the field gradient based on the threat potential field, and then send it to the agent.
[0030] The decision-making and optimization module is used to resolve threat loads and establish barriers based on the agent's strategy; and to optimize core model parameters through meta-learning.
[0031] The beneficial effects of this invention are as follows:
[0032] (1) Threat load is assessed in real time through behavioral entropy analysis, and the system sensitivity is dynamically adjusted without learning parameters, which can adapt well to environmental changes.
[0033] (2) A threat potential field is constructed through multi-agent perception, and the agents move along the field gradient to achieve a coordinated response covering the whole.
[0034] (3) Threats are mitigated through threat load mitigation mechanisms, and barriers are established to block critical paths, significantly improving overall security. Attached Figure Description
[0035] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings.
[0036] Figure 1 This is a flowchart illustrating the steps of an autonomous security monitoring method based on a dynamic threat field according to the present invention. Detailed Implementation
[0037] To better understand the invention, various aspects of the invention will be described in more detail with reference to the accompanying drawings. It should be understood that these detailed descriptions are merely illustrative of exemplary embodiments of the invention and are not intended to limit the scope of the invention in any way. Throughout the specification, the expression "and / or" includes any and all combinations of one or more of the associated listed items. As used herein, the terms "approximately," "about," and similar terms are used as expressions of approximation, not as expressions of degree, and are intended to describe inherent deviations in measured or calculated values that will be recognized by those skilled in the art. Furthermore, the order in which the steps are described in this invention does not necessarily indicate the order in which these steps occur in actual operation, unless otherwise expressly defined or deduced from the context.
[0038] It should also be understood that expressions such as "comprising," "including," "having," "containing," and / or "comprising" are open-ended rather than closed-ended expressions in this specification, indicating the presence of the stated features, elements, and / or components, but not excluding the presence of one or more other features, elements, components, and / or combinations thereof. Furthermore, when expressions such as "at least one of..." appear after a list of listed features, they modify the entire list of features, not just individual elements in the list. Additionally, when describing embodiments of the invention, the word "may" is used to mean "one or more embodiments of the invention." And the term "exemplary" is intended to refer to examples or illustrations.
[0039] Unless otherwise specified, all terms used herein (including engineering and technical terms) shall have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. It should also be understood that, unless expressly stated herein, terms defined in common dictionaries shall be interpreted as having the meaning consistent with their meaning in the context of the relevant art, and not in an idealized or overly formalized sense.
[0040] It should be noted that, unless otherwise specified, the embodiments and features described in this invention can be combined with each other. The invention will now be described in detail with reference to the accompanying drawings and embodiments.
[0041] Example 1:
[0042] Please see Figure 1 An autonomous security monitoring method based on a dynamic threat field includes:
[0043] Step S1: Capture unknown targets through monitoring systems, etc., and obtain the threat load of the unknown targets based on behavioral entropy analysis;
[0044] Step S2: Perform multi-agent perception based on the threat payload and obtain the total threat field strength to form a continuous threat potential energy field;
[0045] Step S3: Generate an agent strategy driven by the field gradient based on the threat potential field and send it to the agent;
[0046] Step S4: Perform threat load mitigation and barrier establishment based on the agent's strategy;
[0047] Step S5: Optimize core model parameters through meta-learning; During the monitoring process, it is necessary to pre-set the field attenuation coefficient to determine the rate at which the threat field strength decays with distance. If the field attenuation coefficient is set too large, the system will be insensitive to threats from afar, while if it is set too small, it will cause the system to be overly sensitive to threats. Therefore, it is necessary to continuously optimize the field attenuation coefficient according to the actual situation.
[0048] In this embodiment, the behavioral entropy analysis specifically refers to:
[0049] S101: Obtain the behavioral micro-state entropy of the unknown target (that is, decompose the behavior of the unknown target within a short time window, such as speed, acceleration, orientation, interaction with objects, etc., into a series of micro-states and calculate their information entropy. High entropy indicates random and aimless behavior; low entropy indicates ordered and patterned behavior).
[0050] S102: The threat load is obtained based on the behavioral micro-state entropy, mathematically described as follows: ,in, Threat load (dimensionless) for unknown target i. Let k be the rate of change of the threat load with time t, and k be a transformation constant greater than 0. Let i be the micro-state entropy of the behavior of an unknown target i; for example, when the behavior of an unknown target changes from aimless wandering (high entropy value) to a targeted professional action (low entropy value), Negative, leading to A positive value indicates an increase in the threat load of the unknown target.
[0051] In this embodiment, the acquisition of the behavioral micro-state entropy specifically involves:
[0052] S101-1: Define microstates, which are the decomposition of the behavior of an unknown target into several measurable dimensions and sampled once within a very short time window (e.g., once per second). The microstates include, but are not limited to, velocity state, rate of change of direction, and interaction state.
[0053] S101-2: Review all microstate samples within a preset time period (e.g., within 10 seconds), obtain the probability of each microstate occurring, and apply the formula... The micro-state entropy of the behavior is obtained, where, For the behavior's microstate entropy, Entropy represents the probability of a microstate occurring. A high entropy value indicates completely random behavior with equal probability for each state, while a low entropy value indicates highly consistent behavior (e.g., consistently walking slowly). Example: Define microstates as speed states (stationary, walking slowly, walking fast, running), direction change rates (stable, turning slowly, turning fast), and interaction states (none, attempting to open a door, using a tool). Reviewing 10 microstate samples within 10 seconds, with microstates of [walking slowly, walking slowly, stationary, walking slowly, walking fast, stationary, walking slowly, walking slowly, stationary, using a tool], we can obtain the probability of each microstate occurring. "Stationary" occurs 3 times. By analogy, the behavioral micro-state entropy can eventually be obtained.
[0054] In this embodiment, the multi-agent perception specifically refers to:
[0055] S201: Obtain the coordinates of unknown targets through multi-agent sensors (cameras, robots, etc.);
[0056] S202: Preset inherent risk value of the environment, used to reflect the inherent value or vulnerability of different locations (e.g., the inherent risk value of the core service room is 1, and the inherent risk value of the ordinary laboratory is 0.3, etc.).
[0057] S203: The total threat field strength is obtained based on the unknown target coordinates and the inherent risk value, mathematically described as follows: ,in, The total threat field strength at position r at time t (the higher the value, the more dangerous the position). Let r be the inherent risk value at position r, and n be the number of unknown targets. For the threat load of an unknown target i at time t, Let be the path distance from the unknown target i to the location r (not a straight line distance, and physical obstacles such as walls and access control need to be considered). To perceive attenuation distance, a characteristic distance characterizing the threat's influence.
[0058] In this embodiment, step S3 can be implemented through the following steps:
[0059] S301: Obtain the location of the agent (generally a mobile robot), and obtain the total threat field strength at the location of the agent based on the agent's location;
[0060] S302: Obtain the agent's decision vector and generate the agent's policy, mathematically described as follows: ,in, This is the decision vector (indicating the direction of movement of the agent). The total threat field strength at the location of the agent. for The length of the mold, The gradient of the total threat field strength (pointing to the direction of the highest threat field strength, the agent reaches the most dangerous place along the path of the fastest threat growth). It is a randomly generated vector with a completely random direction and a fixed size of 1. It is a very small constant (e.g., 0.1). As a random perturbation term (to avoid all agents getting trapped in local optima), the agent moves according to the decision vector, and its speed depends on the size of the threat.
[0061] In this embodiment, step S4 can be implemented through the following steps:
[0062] The threat load mitigation specifically involves the agent moving to the vicinity of the unknown target according to the agent strategy and applying a negative threat load locally (such as strong light illumination, issuing warning sounds, etc.) to counteract the threat load generated by the unknown target. The barrier establishment specifically involves the barrier agent moving to an alternate path leading to the core area (i.e., the area with a high inherent risk value) after receiving a warning that the total threat field strength is too high, using its own existence to increase the inherent risk value of the path it is on, thus preventing the unknown target from approaching.
[0063] In this embodiment, step S5 can be implemented through the following steps:
[0064] Based on the total threat field strength at the previous moment and the current field attenuation coefficient value, the predicted rate of change of field strength is calculated through simulation; based on the total threat field strength at the previous moment and the current actual measured total threat field strength, the actual rate of change of field strength is calculated; based on the predicted rate of change of field strength and the actual rate of change of field strength, the adjustment amount of the field attenuation coefficient is obtained, mathematically described as follows: ,in, This is the adjustment amount for the field attenuation coefficient. The meta-learning rate, For the predicted rate of change of field strength, This represents the actual rate of change of the field strength.
[0065] Example 2:
[0066] An autonomous security monitoring system based on a dynamic threat field includes a behavior entropy analysis module, a multi-agent perception module, an agent policy generation module, and a decision-making and optimization module.
[0067] The behavior entropy analysis module is used to capture unknown targets through monitoring systems and other means, and to obtain the threat load of the unknown targets based on behavior entropy analysis;
[0068] The multi-agent perception module is used to perform multi-agent perception based on the threat payload and obtain the total threat field strength, forming a continuous threat potential energy field.
[0069] The agent policy generation module is used to generate an agent policy driven by the field gradient based on the threat potential field, and then send it to the agent.
[0070] The decision-making and optimization module is used to resolve threat load and establish a barrier based on the agent's strategy; it optimizes the core model parameters through meta-learning; during the monitoring process, it is necessary to pre-set the field attenuation coefficient to determine the rate at which the threat field strength decreases with distance. If the field attenuation coefficient is set too large, the system will be insensitive to distant threats, while if it is set too small, it will cause the system to be overly sensitive to threats. Therefore, it is necessary to continuously optimize the field attenuation coefficient according to the actual situation.
[0071] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any simple modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.
Claims
1. An autonomous security monitoring method based on a dynamic threat field, characterized in that, The implementation of the autonomous security monitoring method based on dynamic threat fields includes the following steps: Step S1: Capture the unknown target and obtain the threat load of the unknown target based on behavioral entropy analysis. Specifically, the behavioral entropy analysis involves: obtaining the behavioral micro-state entropy of the unknown target; and obtaining the threat load based on the behavioral micro-state entropy, mathematically described as follows: ,in, Threat load for unknown target i, Let k be the rate of change of the threat load with time t, and k be a transformation constant greater than 0. The microstate entropy of the behavior of the unknown target i; Step S2: Perform multi-agent perception based on the threat payload and obtain the total threat field strength to form a threat potential energy field; Step S3: Generate an agent strategy driven by the field gradient based on the threat potential field and send it to the agent; Step S4: Threat load mitigation and barrier establishment are performed based on the agent strategy; the threat load mitigation specifically involves the agent moving to the vicinity of the unknown target according to the agent strategy and applying a negative threat load locally to offset the threat load generated by the unknown target; the barrier establishment specifically involves the barrier agent moving to an alternative path leading to the core area after receiving a warning that the total threat field strength is too high, thereby increasing the inherent risk value of the path it is on to prevent the unknown target from approaching. Step S5: Optimize core model parameters through meta-learning.
2. The autonomous security monitoring method based on a dynamic threat field according to claim 1, characterized in that, The acquisition of the behavioral micro-state entropy is specifically as follows: Define microstates, which include velocity state, rate of change of direction, and interaction state; By reviewing all microstate samples within a preset time period, the probability of each microstate occurring is obtained, and the entropy of the behavioral microstate is obtained.
3. The autonomous security monitoring method based on a dynamic threat field according to claim 1, characterized in that, The multi-agent perception in step S2 specifically refers to: Obtain the coordinates of the unknown target; preset the inherent risk value of the environment; based on the coordinates of the unknown target and the inherent risk value, obtain the total threat field strength, mathematically described as follows: ,in, Let r be the total threat field strength at position r at time t. Let r be the inherent risk value at position r, and n be the number of unknown targets. For the threat load of an unknown target i at time t, Let be the path distance from the unknown target i to position r. To sense the attenuation distance.
4. The autonomous security monitoring method based on a dynamic threat field according to claim 1, characterized in that, Step S3 specifically includes: Obtain the agent's location, and based on the agent's location, obtain the total threat field strength at the agent's location; Obtaining the agent's decision vector and generating the agent's policy can be mathematically described as follows: ,in, Let be the decision vector. The total threat field strength at the location of the agent. for The length of the mold, The gradient of the total threat field strength. A randomly generated vector. It is a constant. This is a random disturbance term.
5. The autonomous security monitoring method based on a dynamic threat field according to claim 1, characterized in that, Step S5 specifically includes: Based on the total threat field strength at the previous moment and the current field attenuation coefficient value, the predicted rate of change of field strength is calculated through simulation; based on the total threat field strength at the previous moment and the current actual measured total threat field strength, the actual rate of change of field strength is calculated; based on the predicted rate of change of field strength and the actual rate of change of field strength, the adjustment amount of the field attenuation coefficient is obtained, mathematically described as follows: ,in, This is the adjustment amount for the field attenuation coefficient. The meta-learning rate, For the predicted rate of change of field strength, This represents the actual rate of change of the field strength.
6. An autonomous security monitoring system based on a dynamic threat field, characterized in that, The system is applied to the autonomous security monitoring method based on dynamic threat field as described in any one of claims 1-5, including a behavior entropy analysis module, a multi-agent perception module, an agent policy generation module, and a decision and optimization module; The behavior entropy analysis module is used to capture unknown targets and obtain the threat load of the unknown targets based on behavior entropy analysis; The multi-agent perception module is used to perform multi-agent perception based on the threat charge and obtain the total threat field strength, forming a threat potential energy field. The agent policy generation module is used to generate an agent policy driven by the field gradient based on the threat potential field, and then send it to the agent. The decision-making and optimization module is used to resolve threat loads and establish barriers based on the agent's strategy; and to optimize core model parameters through meta-learning.
Citation Information
Patent Citations
Intelligent agent confrontation method based on artificial intelligence
CN115936055A
Behavior intention prediction method based on multi-target threat situation and GRU network
CN120372444A
Unmanned aerial vehicle active protection method and system for power system aiming at security threats
CN120631023A