A security early warning method, device and medium for analyzing abnormal behavior trajectories
Patent Information
- Application Number
- CN202511459106.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-13
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2045-10-13
AI Technical Summary
[0005]本申请的目的是提供一种异常行为轨迹分析的安全预警方法、设备及介质,用以解决现有技术中存在由于依赖单一模态数据源、建模能力不足以及缺乏推理机制,导致行为轨迹信息碎片化、异常行为识别准确性和实时性较低,进一步影响了系统在复杂场景下对潜在风险行为的高效预警与响应调度能力的技术问题
[0017]本申请中提供的技术方案,至少具有如下技术效果或优点:通过实现基于多源感知融合的行为轨迹全息建模与异常行为智能识别的技术目标,达到提升行为判定准确率、增强异常预警及时性、支撑动态安全响应调度的技术效果。
Smart Images

Figure CN120995402B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of security early warning technology, and in particular to a security early warning method, device and medium for abnormal behavior trajectory analysis. Background Technology
[0002] In the current development of public safety governance, key area protection, and intelligent patrol systems, behavioral trajectory analysis technology is gradually becoming a core support for proactive safety early warning and emergency response dispatch. Especially in scenarios such as urban security monitoring, transportation hub security management, and enterprise / institutional park security, behavioral recognition and abnormal behavior detection systems based on video surveillance and multi-source sensing devices have been initially applied. Existing technologies typically extract the walking paths of target personnel from video streams, and then combine target detection algorithms and facial recognition models to confirm the person's identity, thereby assisting managers in discovering potential threatening behaviors and improving security capabilities. However, existing technologies still have many limitations and key issues in practical applications.
[0003] Currently, most systems rely on single-modal data sources, such as video surveillance, infrared imaging, or access control attendance records, for behavioral trajectory recognition. They lack multi-source sensing fusion methods, making it difficult to obtain continuous, complete, and structured trajectory data. This fragmented trajectory information is insufficient to support high-precision judgment of complex behavioral patterns and prediction of evolutionary trends. Secondly, most existing behavior discrimination methods are based on static rule matching or traditional machine learning models, lacking deep modeling capabilities for the coupling relationships between temporal evolution, spatial transfer, and identity features. This leads to problems such as lag, misjudgment, or missed detection in abnormal behavior detection. Furthermore, current systems generally emphasize recognition over reasoning. Even when an abnormal behavior, such as loitering or abnormal dwelling, is detected, there is a lack of further causal reasoning and influencing factor identification mechanisms, failing to support priority response and resource scheduling in intelligent decision-making.
[0004] In summary, existing technologies suffer from technical problems such as reliance on a single modal data source, insufficient modeling capabilities, and a lack of reasoning mechanisms. These problems lead to fragmented behavioral trajectory information, low accuracy and real-time performance in identifying abnormal behaviors, and further affect the system's ability to efficiently warn and respond to potential risky behaviors in complex scenarios. Summary of the Invention
[0005] The purpose of this application is to provide a security early warning method, device and medium for abnormal behavior trajectory analysis, in order to solve the technical problems in the prior art that, due to reliance on a single modal data source, insufficient modeling capabilities and lack of reasoning mechanisms, behavior trajectory information is fragmented, the accuracy and real-time performance of abnormal behavior identification are low, and this further affects the system's ability to efficiently warn and respond to potential risk behaviors in complex scenarios.
[0006] In view of the above problems, this application provides a security early warning method, device and medium for abnormal behavior trajectory analysis.
[0007] Firstly, this application provides a security early warning method for abnormal behavior trajectory analysis, implemented through a security early warning device for abnormal behavior trajectory analysis, comprising: collecting behavior trajectory data of a target area through a multi-source sensing device; extracting multi-dimensional features from the behavior trajectory dataset, wherein the multi-dimensional features include trajectory spatiotemporal distribution features, speed change features, and dwell frequency features; determining anomalies in the trajectory spatiotemporal distribution features and speed change features according to the dwell frequency features, and constructing an abnormal behavior determination vector; performing loitering pattern recognition based on the abnormal behavior determination vector to determine the abnormal behavior level; triggering a graded early warning mechanism according to the abnormal behavior level; generating an abnormal behavior alarm signal according to the graded early warning mechanism, combining it with the electronic fence information of the target area to generate a security early warning report and pushing it to a monitoring terminal.
[0008] Preferably, the security early warning method for abnormal behavior trajectory analysis further includes: collecting data by traversing the target area using multi-source sensing devices to obtain a multi-source sensing dataset, wherein the multi-source sensing dataset includes continuous video stream data, target positioning sequence, and identity verification information; performing human body recognition based on the continuous video stream data to extract skeleton key point data; performing motion analysis based on the target positioning sequence to obtain motion feature data; performing identity identification based on the identity verification information to generate identity tag data; and performing spatiotemporal data fusion of the skeleton key point data, the motion feature data, and the identity tag data to generate the behavior trajectory dataset.
[0009] Preferably, the safety early warning method for abnormal behavior trajectory analysis further includes: dividing the target area into multiple sub-networks, mapping the skeleton key point data to the multiple sub-networks to obtain point density distribution data; performing dwell calculation based on the point density distribution data to obtain a regional dwell index, constructing a spatiotemporal distribution matrix, mapping the regional dwell index to the spatiotemporal distribution matrix for feature analysis to obtain trajectory spatiotemporal distribution features; performing adjacent displacement calculation based on the motion feature data to obtain an instantaneous velocity sequence; performing smoothing processing according to the instantaneous velocity sequence to construct a velocity change rate histogram, traversing the velocity change rate histogram to monitor the frequency of continuous changes, and obtaining velocity change features; performing dwell analysis on the behavior trajectory dataset according to the regional dwell index and the velocity change features to determine multiple dwell hotspot areas; drawing a dwell frequency heatmap based on the multiple dwell hotspot areas and the identity tag data, and performing feature encoding according to the dwell frequency heatmap to determine the dwell frequency features.
[0010] Preferably, the safety early warning method for abnormal behavior trajectory analysis further includes: performing time decay analysis based on the dwell frequency characteristics to generate a dwell frequency index, wherein the dwell frequency index includes a dynamic dwell weight; performing regional sensitivity correction on the trajectory spatiotemporal distribution characteristics based on the dynamic dwell weight to generate a spatiotemporal anomaly coefficient; performing path analysis based on the spatiotemporal anomaly coefficient to determine the path complexity; performing time-series correlation between the dwell frequency characteristics and the speed change characteristics to obtain a time-series correlation coefficient; performing speed fluctuation analysis based on the time-series correlation coefficient to obtain a speed fluctuation coefficient; performing anomaly judgment on the speed fluctuation coefficient according to the dwell frequency index and the path complexity to obtain an anomaly judgment result; and performing multi-dimensional behavior processing on the anomaly judgment result to construct the abnormal behavior judgment vector.
[0011] Preferably, the safety early warning method for abnormal behavior trajectory analysis further includes: retrieving historical behavior trajectory record logs of the target area, traversing the historical behavior trajectory record logs to extract normal trajectory samples, and constructing a normal behavior trajectory sample database; performing benchmark analysis based on the normal behavior trajectory sample database to determine trajectory feature benchmark distribution data; performing deviation analysis on the abnormal behavior judgment vector according to the trajectory feature benchmark distribution data to determine the abnormal deviation degree; setting a deviation critical threshold, and activating a wandering mode when the abnormal deviation degree is greater than the deviation critical threshold, performing trajectory abnormality impact analysis through the wandering mode to determine the set of dominant influencing factors; and classifying the abnormal behavior level according to the set of dominant influencing factors.
[0012] Preferably, the safety early warning method for abnormal behavior trajectory analysis further includes: performing regression calculations based on the trajectory feature baseline distribution data to construct a threshold baseline, and setting a deviation threshold according to the threshold baseline; comparing and judging the abnormal deviation degree according to the deviation threshold, and activating the wandering mode when the abnormal deviation degree is greater than the deviation threshold; performing causal inference on the abnormal behavior judgment vector through the wandering mode to determine multiple influencing factors; and performing dominant analysis on the multiple influencing factors to determine the set of dominant influencing factors.
[0013] Preferably, the security early warning method for abnormal behavior trajectory analysis further includes: extracting abnormal trajectory segments through the hierarchical early warning mechanism for spatiotemporal backtracking to generate a three-dimensional trajectory reconstruction map; constructing a profile based on the three-dimensional trajectory reconstruction map and the identity tag data to generate a profile of a suspicious person; performing behavioral correlation analysis based on the profile of the suspicious person to generate a behavioral correlation map; introducing a historical case library of the target area; performing similarity matching based on the behavioral correlation map and the historical case library to generate a risk probability assessment value; and adding the risk probability assessment value to the alarm signal.
[0014] Preferably, the security early warning method for abnormal behavior trajectory analysis further includes: performing perimeter protection analysis on the target area, constructing a defense level matrix, protecting the target area based on the defense level matrix, and constructing electronic fence information; performing defense feasibility analysis on the alarm signal according to the electronic fence information, generating defense feasibility results, the defense feasibility results including active defense parameters and passive defense parameters; when the defense feasibility result is the active defense parameter, generating a first security early warning report, setting an information push priority based on the risk probability assessment value, and pushing the security early warning report to the monitoring terminal according to the information push priority; when the defense feasibility result is the passive defense parameter, generating a second security early warning report, pushing it to the monitoring terminal, and initiating emergency personnel control instructions.
[0015] Secondly, this application also provides a security early warning device for abnormal behavior trajectory analysis, used to execute a security early warning method for abnormal behavior trajectory analysis as described in the first aspect, comprising: a behavior trajectory data acquisition module, used to acquire behavior trajectory data of a target area through a multi-source sensing device, and extract multi-dimensional features from the behavior trajectory dataset, wherein the multi-dimensional features include trajectory spatiotemporal distribution features, speed change features, and dwell frequency features; an anomaly determination module, used to determine anomalies in the trajectory spatiotemporal distribution features and speed change features according to the dwell frequency features, and construct an abnormal behavior determination vector; a loitering pattern recognition module, used to perform loitering pattern recognition based on the abnormal behavior determination vector, determine the abnormal behavior level, and trigger a graded early warning mechanism according to the abnormal behavior level; and a report push module, used to generate an abnormal behavior alarm signal according to the graded early warning mechanism, combine it with the electronic fence information of the target area to generate a security early warning report, and push it to the monitoring terminal.
[0016] Thirdly, a computer-readable storage medium storing a computer program, which, when executed, implements the steps of the security early warning method for abnormal behavior trajectory analysis as described in any one of the first aspects above.
[0017] The technical solution provided in this application has at least the following technical effects or advantages: by achieving the technical goal of holographic modeling of behavior trajectory and intelligent recognition of abnormal behavior based on multi-source perception fusion, it achieves the technical effects of improving the accuracy of behavior judgment, enhancing the timeliness of abnormal warning, and supporting dynamic safety response scheduling.
[0018] The above description is merely an overview of the technical solution of this application. To better understand the technical means of this application and to facilitate its implementation according to the description, and to make the above and other objects, features, and advantages of this application more apparent, specific embodiments of this application are described below. It should be understood that the content described in this section is not intended to identify key or important features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent through the following description. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely exemplary. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0020] Figure 1 This is a flowchart illustrating a security early warning method for abnormal behavior trajectory analysis according to this application; Figure 2 This is a schematic diagram of the structure of a safety early warning device for abnormal behavior trajectory analysis according to this application.
[0021] Figure labeling: 1. Behavior trajectory data acquisition module; 2. Anomaly detection module; 3. Loitering pattern recognition module; 4. Report push module. Detailed Implementation
[0022] This application provides a security early warning method, device, and medium for abnormal behavior trajectory analysis. It addresses the technical problems in existing technologies where reliance on a single modal data source, insufficient modeling capabilities, and a lack of reasoning mechanisms lead to fragmented behavior trajectory information, low accuracy and real-time performance in abnormal behavior identification, and further impact the system's ability to efficiently warn and respond to potential risky behaviors in complex scenarios. The application achieves the technical goal of holographic modeling of behavior trajectories and intelligent identification of abnormal behaviors based on multi-source perception fusion, thereby improving the accuracy of behavior judgment, enhancing the timeliness of abnormal warnings, and supporting dynamic security response scheduling.
[0023] The technical solutions of this application will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. It should be understood that this application is not limited to the exemplary embodiments described herein. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application. It should also be noted that, for ease of description, only the parts related to this application are shown in the accompanying drawings, not all of them.
[0024] Example 1, please refer to the appendix. Figure 1 This application provides a security early warning method for abnormal behavior trajectory analysis, applied to a security early warning device for abnormal behavior trajectory analysis, specifically including the following steps: S1: Collect behavioral trajectory data of the target area through multi-source sensing devices, and extract multi-dimensional features from the behavioral trajectory dataset. The multi-dimensional features include trajectory spatiotemporal distribution features, speed change features, and dwell frequency features.
[0025] Furthermore, this application also includes: S11: collecting data by traversing the target area through a multi-source sensing device to obtain a multi-source sensing dataset, wherein the multi-source sensing dataset includes continuous video stream data, target positioning sequence, and identity verification information; S12: performing human body recognition based on the continuous video stream data and extracting skeleton key point data; S13: performing motion analysis based on the target positioning sequence to obtain motion feature data; S14: performing identity identification based on the identity verification information and generating identity tag data; S15: performing spatiotemporal data fusion of the skeleton key point data, the motion feature data, and the identity tag data to generate the behavior trajectory dataset.
[0026] Furthermore, this application also includes: S16: dividing the target area into multiple sub-networks, mapping the skeleton key point data to the multiple sub-networks, and obtaining point density distribution data; S17: performing dwell calculation based on the point density distribution data to obtain a regional dwell index, constructing a spatiotemporal distribution matrix, mapping the regional dwell index to the spatiotemporal distribution matrix for feature analysis, and obtaining trajectory spatiotemporal distribution features; S18: performing adjacent displacement calculation based on the motion feature data to obtain an instantaneous velocity sequence; S19: performing smoothing processing according to the instantaneous velocity sequence, constructing a velocity change rate histogram, traversing the velocity change rate histogram to monitor the frequency of continuous changes, and obtaining velocity change features; S110: performing dwell analysis on the behavioral trajectory dataset according to the regional dwell index and the velocity change features to determine multiple dwell hotspot areas; S111: drawing a dwell frequency heatmap based on the multiple dwell hotspot areas and the identity tag data, performing feature encoding according to the dwell frequency heatmap, and determining the dwell frequency features.
[0027] Specifically, the target area is the region where abnormal behavior trajectory analysis is to be performed. Multi-source sensing devices consist of multiple sensors, such as surveillance cameras, radar, infrared thermal imagers, and Bluetooth positioning devices. Data is collected by traversing the target area using multi-source sensing devices, collecting data from all targets within the target area to obtain a multi-source sensing dataset. The multi-source sensing dataset includes continuous video stream data, target location sequences, and authentication information. Continuous video stream data is a sequence of dynamic images continuously captured by devices such as surveillance cameras; the target location sequence is provided by GPS, UWB, or WiFi positioning systems, recording the spatial location information of each target at different times; authentication information may include card swipe data, facial recognition results, or mobile phone MAC addresses, used to identify and confirm the identity of the target individual.
[0028] Next, human body recognition is performed based on continuous video stream data, using image processing and computer vision techniques to determine the presence of a human body in the image. Human body recognition includes convolutional neural networks, YOLO series models, etc. After recognition, key skeletal point data is further extracted, that is, the coordinate information of major joints in the human skeletal structure such as the head, shoulders, knees, and ankles is identified, which helps to more accurately determine a person's posture, movement, and behavior. Motion analysis is performed using the target localization sequence. Motion analysis obtains its velocity, acceleration, path direction, and other feature information by calculating the target's positional changes between consecutive time points, which is the motion feature data. The collected identity verification information is identified by comparing it with records in the database to confirm the identity of the target individual. When the human body recognition result and the identity identification result deviate within a preset threshold, a first-level risk scan is immediately triggered, generating an initial alarm signal and entering the behavior trajectory monitoring state.
[0029] Finally, the skeleton key point data, motion feature data, and identity tag data are fused spatiotemporally. Spatiotemporal fusion refers to integrating data from different times and sources into a unified data structure that includes both time dimensions and spatial coordinates and identity attributes. This ultimately generates a complete behavioral trajectory dataset, which can depict the movement path, behavioral posture, and identity background of each individual within a certain time period, laying the foundation for subsequent behavioral analysis and anomaly warning. Simultaneously with the generation of the behavioral trajectory dataset, anomaly confidence values are dynamically calculated based on data fluctuation amplitude. When the confidence value exceeds a tiered threshold, a multi-level warning module is triggered, initiating corresponding protection mechanisms in a tiered response manner. Table 1 shows a partial record of the most recent behavioral trajectory data.
[0030] Table 1: Partial Record Table of Recent Behavioral Trajectory Data
[0031] The target area is divided into multiple sub-networks. A sub-network refers to dividing the entire monitoring range according to a fixed spatial grid or logical area, such as dividing a shopping mall into multiple independent shop areas or passageways. The acquired skeletal keypoint data is then mapped onto the sub-networks, that is, projecting the joint coordinates of the human body at different times onto specific sub-regions. By counting the number of keypoints in each sub-region, point density distribution data is obtained, which reflects the density of human activity in a certain area over a certain period of time.
[0032] After obtaining the point density distribution, dwell time calculations are performed based on the density data to determine the time and frequency of human stay in a specific area, resulting in a regional dwell time index. This index quantifies the intensity and duration of gatherings of individuals or groups in a particular area. Next, a spatiotemporal distribution matrix is constructed, organizing the regional dwell time index along both temporal and spatial dimensions to better illustrate human usage of different areas at different times. Through statistical analysis and feature extraction of the spatiotemporal distribution matrix, the final trajectory spatiotemporal distribution characteristics are derived, describing the movement distribution and activity frequency of people throughout the area. Based on the trajectory spatiotemporal distribution characteristics, a dynamic comparison is performed with a historical security pattern database. When the deviation exceeds a warning threshold, an alarm is automatically generated and pushed to the monitoring terminal according to the area's protection priority.
[0033] Simultaneously, adjacent displacements are calculated using the obtained motion characteristic data. This involves using the finite difference method to calculate the distance of position change between two consecutive time points, resulting in an instantaneous velocity sequence that reflects the person's movement speed at each moment. To avoid extreme values in the instantaneous velocity sequence due to jitter or errors, the sequence is smoothed to remove abnormal fluctuations. A velocity change rate histogram is then constructed to statistically analyze the distribution of velocity change amplitudes. The frequency of velocity changes is analyzed by sequentially examining the velocity change rate histogram to obtain velocity change characteristics. This helps determine whether the person in the target area is rapidly crossing the area or exhibiting loitering or lingering behavior. If the velocity change characteristics show a continuous low-speed loitering pattern, proactive defense parameters, such as audible and visual warnings or real-time broadcast intervention, are immediately invoked to achieve a behavioral-level proactive protection response.
[0034] Next, the regional dwell time index is combined with speed change characteristics to conduct dwell time analysis. For example, only when a person stays in a certain area for a relatively long time and moves slowly is it considered a valid dwell point. This further identifies multiple dwelling hotspots, representing the main activity locations of people, such as lobbies, elevator entrances, or specific exhibition booths. For these dwelling hotspots, a protection feasibility analysis is performed using electronic fence information to generate corresponding defense feasibility results for subsequent security early warning decisions.
[0035] After identifying hotspot areas, identity tag data is introduced to statistically analyze the number of visits and duration of stay for individuals with different identities in these areas, creating a heatmap of dwell frequency. A heatmap is an image that represents activity frequency using color intensity; the color intensity values of the dwell frequency heatmap are dynamically adjusted based on the product of the number of visits and the duration of stay. Finally, feature encoding is performed based on the dwell frequency heatmap, converting the dwell frequency of each area in the heatmap into standardized vector features to determine the dwell frequency characteristics, providing crucial input for subsequent abnormal behavior identification. Based on the feature encoding results and defense feasibility assessments, a final security warning report is generated, including a risk probability assessment value and push priority. This report is then pushed to monitoring terminals according to an information grading strategy, achieving a complete security protection closed loop from detection and assessment to tiered warnings.
[0036] S2: Based on the dwell frequency characteristics, perform anomaly determination on the trajectory spatiotemporal distribution characteristics and the speed change characteristics, and construct an abnormal behavior determination vector.
[0037] Furthermore, this application also includes: S21: performing time decay analysis based on the dwell frequency characteristics to generate a dwell frequency index, wherein the dwell frequency index includes a dynamic dwell weight; S22: performing regional sensitivity correction on the trajectory spatiotemporal distribution characteristics based on the dynamic dwell weight to generate a spatiotemporal anomaly coefficient; S23: performing path analysis based on the spatiotemporal anomaly coefficient to determine the path complexity; S24: performing time-series correlation between the dwell frequency characteristics and the speed change characteristics to obtain a time-series correlation coefficient, and performing speed fluctuation analysis based on the time-series correlation coefficient to obtain a speed fluctuation coefficient; S25: performing anomaly determination on the speed fluctuation coefficient according to the dwell frequency index and the path complexity to obtain anomaly determination results, and performing multi-dimensional behavior processing on the anomaly determination results to construct the anomaly behavior determination vector.
[0038] Specifically, time decay analysis is performed on the frequency of stay characteristics. Time decay analysis introduces a time dimension when statistically analyzing the frequency of an individual's stay in a certain area, giving greater weight to more recent stays than earlier ones, generating a stay frequency index. This index includes dynamic stay weights, reflecting the intensity of an individual's recent attention or stay in a particular area; the more recent the stay, the higher the weight. Based on these dynamic stay weights, multi-level early warning judgments can be automatically triggered. When an individual's stay weight in a key area exceeds a preset threshold, a level one or level two early warning signal is generated as the trigger for abnormal behavior monitoring.
[0039] After obtaining the dynamic dwell time weights, these weights are applied to the spatiotemporal distribution characteristics of the trajectory, and the weights of each region are adjusted. Regions that have appeared frequently recently are assigned higher sensitivity coefficients to highlight key areas in an individual's recent behavior. A spatiotemporal anomaly coefficient is generated after the adjustment to measure whether an individual exhibits abnormal activity patterns that differ from the majority at a specific time and place. Combining electronic fence information and a regional protection level matrix, areas with spatiotemporal anomaly coefficients exceeding the warning threshold are marked as key protection zones, and monitoring terminals are automatically dispatched to send alarms.
[0040] After obtaining the spatiotemporal anomaly coefficients, further path analysis is conducted. Path analysis refers to identifying the individual's movement route within the target area and determining whether there are abnormal detours, frequent backtracking, or irregular crossing behaviors. Based on the complexity of the behavior, path complexity is calculated, reflecting the nonlinearity and degree of change of the path. When the path complexity reaches a preset threshold, a behavior anomaly tiered response is triggered, and active or passive defense measures can be implemented according to the tier settings.
[0041] Subsequently, the frequency of dwell time and speed change characteristics are correlated over time. This involves pairing the two types of data along a timeline to calculate a time-series correlation coefficient, which measures whether speed changes are synchronized with dwelling behavior. For example, if someone both slows down and dwells frequently within a certain time period, it suggests a possible intrinsic link between these two behaviors. Speed fluctuation analysis yields a speed fluctuation coefficient, representing the stability of a person's speed during movement; greater fluctuations indicate more abnormal behavior. Combining the speed fluctuation coefficient with dynamic dwell weights allows for further assessment of warning levels. Based on predefined levels, abnormal behavior can be pushed to monitoring terminals or triggered by automatic intervention devices, such as audible and visual alarms or access control restrictions.
[0042] Finally, the frequency of stay, path complexity, and speed fluctuation coefficient are jointly analyzed. Anomalies are identified by setting thresholds, yielding anomaly detection results. These results undergo further multi-dimensional behavioral processing, integrating data from more dimensions (such as identity information, time characteristics, and historical behavior) to construct an anomaly behavior determination vector. This vector can serve as the final input for security alerts or behavioral profiling. The anomaly behavior determination vector, combined with electronic fence constraints and a tiered alert strategy, generates a final security alert report. This report includes risk level, alert grade, and push priority, and can trigger active or passive defense measures, achieving a complete closed loop from anomaly detection to security response.
[0043] S3: Based on the abnormal behavior judgment vector, perform loitering pattern recognition, determine the level of abnormal behavior, and trigger a graded early warning mechanism according to the level of abnormal behavior.
[0044] Furthermore, this application also includes: S31: retrieving historical behavior trajectory record logs of the target area, traversing the historical behavior trajectory record logs to extract normal trajectory samples, and constructing a normal behavior trajectory sample database; S32: performing benchmark analysis based on the normal behavior trajectory sample database to determine trajectory feature benchmark distribution data; S33: performing deviation analysis on the abnormal behavior judgment vector according to the trajectory feature benchmark distribution data to determine the abnormal deviation degree; S34: setting a deviation critical threshold, and when the abnormal deviation degree is greater than the deviation critical threshold, activating a wandering mode, and performing trajectory abnormality impact analysis through the wandering mode to determine the set of dominant influencing factors; S35: classifying the abnormal behavior level according to the set of dominant influencing factors.
[0045] Furthermore, this application also includes: S341: performing regression calculation based on the trajectory feature baseline distribution data to construct a threshold baseline, and setting a deviation critical threshold according to the threshold baseline; S342: comparing and judging the abnormal deviation degree according to the deviation critical threshold, and activating the wandering mode when the abnormal deviation degree is greater than the deviation critical threshold; S343: performing causal inference on the abnormal behavior judgment vector through the wandering mode to determine multiple influencing factors; S344: performing dominant analysis on the multiple influencing factors to determine the set of dominant influencing factors.
[0046] Specifically, historical behavior trajectory logs of the target area are retrieved. These logs contain data on a person's movement within the target area over a historical period, including timestamps, location information, speed changes, and dwell time. By sequentially accessing these logs, data samples exhibiting normal behavioral characteristics—these are designated as normal trajectory samples—and used to construct a standard reference database of normal behavior trajectory samples. The security level information for each trajectory sample in this database is then labeled for future reference when triggering alerts based on abnormal behavior.
[0047] Statistical modeling is performed based on a database of normal behavioral trajectories to form baseline distribution data for trajectory features. This baseline distribution data refers to the probability distribution or numerical range established for multiple behavioral characteristics such as path complexity, dwell frequency, and speed fluctuations, thereby obtaining typical behavioral patterns of normal individuals within the target area. Based on this baseline distribution data, tiered thresholds can be set to trigger warnings corresponding to different levels of abnormal behavior, such as low, medium, and high levels.
[0048] Next, the obtained abnormal behavior judgment vector is compared with the trajectory feature baseline distribution data to perform deviation analysis and calculate the degree of deviation, which is used as the abnormal deviation degree. The abnormal deviation degree measures the degree of difference between the current behavior and historical normal behavior. When the abnormal deviation degree exceeds a preset threshold, a graded early warning mechanism is automatically triggered. The early warning level is determined based on the deviation magnitude, and a preliminary alarm signal is generated.
[0049] Regression calculations are performed based on trajectory feature baseline distribution data to construct a dynamically changing threshold baseline. Regression calculation is a mathematical modeling process that fits a function to the trajectory feature baseline distribution data, constructing a baseline for judging whether behavior is normal—the threshold baseline. Using the threshold baseline, deviation thresholds can be set according to standard behavior in different scenarios to measure the boundary of abnormal behavior; for example, when path complexity exceeds a set threshold, it is considered a deviation from normal behavior. The threshold baseline, combined with the electronic fence protection level matrix, can dynamically adjust the deviation thresholds for different areas, making early warnings more accurate.
[0050] Next, the deviation from the critical threshold is used to compare and judge the degree of abnormal deviation of the current behavior. If the abnormal deviation exceeds the set critical threshold, the loitering mode in the behavior monitoring mechanism can be triggered. Loitering mode refers to switching to a working state for more detailed analysis of abnormal behavior, used to identify risky behaviors such as unintentional movement and prolonged stay. When loitering mode is triggered, a corresponding graded early warning signal is generated, and a decision is made based on the preset active or passive defense strategy to decide whether to push it to the monitoring terminal or trigger security intervention.
[0051] In the loitering mode, further analysis is conducted on the factors involved in the current abnormal behavior, and causal inference is performed on the abnormal behavior judgment vector. Causal inference includes judgment factors such as spatial factors (electronic fence distance, monitoring blind zone coverage), temporal factors (time period anomaly coefficient, duration ratio), and behavioral factors (velocity variability, path fractal dimension), identifying multiple influencing factors. Based on the results of influencing factor identification, the electronic fence response level, monitoring area patrol priority, or behavioral intervention strategy are adjusted to achieve closed-loop early warning.
[0052] Finally, a dominant factor analysis is performed on all identified influencing factors to determine the factors that have the greatest impact on the current abnormal behavior. Dominant factor analysis typically involves statistical weighting, information gain ranking, or feature contribution rate analysis, ultimately extracting a set of dominant influencing factors from multiple factors. For example, when spatial factors are dominant, the electronic fence defense level is increased and the monitoring view layout is optimized; when temporal factors are dominant, the patrol frequency and response readiness level for that time period are adjusted; and when behavioral factors are dominant, a deep learning model is activated to retrieve abnormal patterns across scenarios. The set of dominant influencing factors is also used to determine the type of early warning strategy, such as active defense triggering, passive defense recording, or hybrid mode execution.
[0053] Finally, the abnormal behavior is classified according to the set of dominant influencing factors. Classification refers to dividing the degree of abnormality of behavior into several levels, such as low risk, medium risk, and high risk, to form a final abnormal behavior level, which is then used in the dynamic early warning system to trigger the corresponding level of response mechanism.
[0054] A tiered early warning mechanism is triggered based on the level of abnormal behavior. This mechanism is a system that automatically takes corresponding response measures for different levels of abnormal behavior, including information prompts, early warning reporting, behavior locking, and coordinated control. Each level of abnormal behavior represents the degree of risk or urgency of the event. For example, a relatively stable but prolonged abnormal stay could be classified as medium risk, while frequent speed changes, abnormal path turns, and proximity to sensitive areas might be marked as high risk.
[0055] S4: Generate an abnormal behavior alarm signal based on the hierarchical early warning mechanism, combine it with the electronic fence information of the target area to generate a security early warning report, and push it to the monitoring terminal.
[0056] Furthermore, this application also includes: S41: extracting abnormal trajectory segments through the hierarchical early warning mechanism for spatiotemporal backtracking to generate a three-dimensional trajectory reconstruction map; S42: constructing a profile based on the three-dimensional trajectory reconstruction map and the identity tag data to generate a profile of suspicious persons, and performing behavioral correlation analysis based on the profile of suspicious persons to generate a behavioral correlation map; S43: introducing a historical case library of the target area, performing similarity matching based on the behavioral correlation map and the historical case library to generate a risk probability assessment value, and adding the risk probability assessment value to the alarm signal.
[0057] Furthermore, this application also includes: S44: performing perimeter protection analysis on the target area, constructing a defense level matrix, protecting the target area based on the defense level matrix, and constructing electronic fence information; S45: performing defense feasibility analysis on the alarm signal according to the electronic fence information, generating defense feasibility results, the defense feasibility results including active defense parameters and passive defense parameters; S46: when the defense feasibility result is the active defense parameter, generating a first security warning report, setting an information push priority based on the risk probability assessment value, and pushing the security warning report to the monitoring terminal according to the information push priority; S47: when the defense feasibility result is the passive defense parameter, generating a second security warning report, pushing it to the monitoring terminal, and initiating emergency personnel control instructions.
[0058] Specifically, once an abnormal behavior level is detected and a tiered early warning mechanism is triggered, spatiotemporal retrospective analysis will be performed on the relevant abnormal trajectory segments. An abnormal trajectory segment refers to a person's movement path deemed abnormal within a certain time period. Spatiotemporal retrospective analysis involves remapping the abnormal trajectory segments back to the original spatiotemporal coordinate system to analyze the behavioral development process from both temporal and spatial dimensions, generating a three-dimensional trajectory reconstruction map. This means reconstructing the individual's movement trajectory at a specific location and time within a three-dimensional model, making the behavioral path more intuitively presented.
[0059] Next, the 3D trajectory reconstruction map is combined with identity tag data to construct a profile, generating a profile of a suspicious person, which comprehensively depicts the characteristics of the individual exhibiting suspicious behavior. Subsequently, behavioral correlation analysis is conducted based on the profile of the suspicious person, identifying the connections between them and other behaviors, individuals, or events, constructing a behavioral correlation graph. The behavioral correlation graph is a multi-node, multi-sided structure that describes the mutual influence between individual behaviors; for example, if someone's trajectory overlaps with another person's before entering a specific area, or if other individuals with similar paths appear before and after a certain behavior occurs.
[0060] Subsequently, a historical case database for the target area is introduced. This database stores known past behavioral events and related trajectories, maps, and conclusions. Similarity matching is performed between the current behavioral correlation map and the historical case database, determining the degree of similarity between the current situation and past events in dimensions such as trajectory patterns, behavioral patterns, and individual characteristics. The calculated result is the risk probability assessment value, used to quantify whether the current behavior is likely to trigger a security incident. Finally, the risk probability assessment value is appended to the alarm signal, so that the alarm information not only includes whether something is abnormal, but also a quantitative judgment of the severity of the risk.
[0061] Before protecting the target area, a perimeter protection analysis is conducted. This analysis identifies and assesses risk paths that may be compromised, approached, or damaged along the target area's boundaries. For example, a construction site's boundaries might include walls, entrances / exits, and blind spots. Next, a defense level matrix is constructed, comprising three levels of protection parameters: perimeter defense, three-dimensional monitoring, and bio-blocking. These parameters represent the security levels of different areas or passageways, and can be determined based on risk level, traffic frequency, or historical alarm data. Then, based on the defense level matrix, a protection layout is implemented for the entire target area, ultimately generating electronic fence information. This involves setting up a logical defense line at the target area's boundary using virtual means, and utilizing sensing devices to monitor intrusion or boundary-crossing behavior inside and outside the electronic fence.
[0062] Then, based on the electronic fence information, a defense feasibility analysis is performed on the triggered alarm signals to determine whether corresponding defense measures can be successfully activated under the current alarm conditions. The output of the analysis is the defense feasibility result, which includes two categories: active defense parameters and passive defense parameters.
[0063] Active defense parameters refer to protective measures that can be proactively taken. Active defense proves that the current anomaly is within a controllable range, that the trajectory of the anomaly is known, and that the identity of the anomaly personnel is known. Passive defense parameters, on the other hand, indicate that the current anomaly is outside a controllable range and awaits human intervention. When the defense feasibility result is determined to be an active defense parameter, a first security warning report is generated, summarizing the details of the alarm event, risk level, and related trajectory information, and setting the information push priority based on the risk probability assessment value. The information push priority indicates the alarm speed and transmission method of the first security warning report. Conversely, when the defense feasibility result is determined to be a passive defense parameter, a second security warning report is generated and immediately pushed to the monitoring terminal. At the same time, an emergency personnel control command will be initiated, dispatching on-site security personnel to the incident area, setting up a containment route, or notifying the superior authority to implement further decisions.
[0064] In summary, the security early warning method for abnormal behavior trajectory analysis provided in this application has the following technical effects: by achieving the technical goal of holographic modeling of behavior trajectory and intelligent recognition of abnormal behavior based on multi-source perception fusion, it can improve the accuracy of behavior judgment, enhance the timeliness of abnormal early warning, and support dynamic security response scheduling.
[0065] Example 2: Based on the same inventive concept as the security early warning method for abnormal behavior trajectory analysis in the foregoing examples, this application also provides a security early warning device for abnormal behavior trajectory analysis. Please refer to the appendix. Figure 2The system includes: a behavior trajectory data acquisition module 1, used to acquire behavior trajectory data of a target area through multi-source sensing devices, and extract multi-dimensional features from the behavior trajectory dataset, including trajectory spatiotemporal distribution features, speed change features, and dwell frequency features; an anomaly determination module 2, used to determine anomalies in the trajectory spatiotemporal distribution features and speed change features according to the dwell frequency features, and construct an abnormal behavior determination vector; a loitering pattern recognition module 3, used to perform loitering pattern recognition based on the abnormal behavior determination vector, determine the abnormal behavior level, and trigger a graded early warning mechanism according to the abnormal behavior level; and a report push module 4, used to generate an abnormal behavior alarm signal according to the graded early warning mechanism, combine it with the electronic fence information of the target area to generate a safety early warning report, and push it to the monitoring terminal.
[0066] Furthermore, the aforementioned security early warning device for abnormal behavior trajectory analysis is also used for: collecting data by traversing the target area through a multi-source sensing device to obtain a multi-source sensing dataset, wherein the multi-source sensing dataset includes continuous video stream data, target positioning sequence, and identity verification information; performing human body recognition based on the continuous video stream data to extract skeleton key point data; performing motion analysis based on the target positioning sequence to obtain motion feature data; performing identity identification based on the identity verification information to generate identity tag data; and performing spatiotemporal data fusion of the skeleton key point data, the motion feature data, and the identity tag data to generate the behavior trajectory dataset.
[0067] Furthermore, the aforementioned security early warning device for abnormal behavior trajectory analysis is also used for: dividing the target area into multiple sub-networks, mapping the skeleton key point data to the multiple sub-networks to obtain point density distribution data; performing dwell calculation based on the point density distribution data to obtain a regional dwell index, constructing a spatiotemporal distribution matrix, mapping the regional dwell index to the spatiotemporal distribution matrix for feature analysis to obtain trajectory spatiotemporal distribution features; performing adjacent displacement calculation based on the motion feature data to obtain an instantaneous velocity sequence; performing smoothing processing according to the instantaneous velocity sequence to construct a velocity change rate histogram, traversing the velocity change rate histogram to monitor the frequency of continuous changes, and obtaining velocity change features; performing dwell analysis on the behavior trajectory dataset according to the regional dwell index and the velocity change features to determine multiple dwell hotspot areas; drawing a dwell frequency heatmap based on the multiple dwell hotspot areas and the identity tag data, and performing feature encoding according to the dwell frequency heatmap to determine the dwell frequency features.
[0068] Furthermore, the safety early warning device for abnormal behavior trajectory analysis is also used for: performing time decay analysis based on the dwell frequency characteristics to generate a dwell frequency index, wherein the dwell frequency index includes a dynamic dwell weight; performing regional sensitivity correction on the trajectory spatiotemporal distribution characteristics based on the dynamic dwell weight to generate a spatiotemporal anomaly coefficient; performing path analysis based on the spatiotemporal anomaly coefficient to determine the path complexity; performing time-series correlation between the dwell frequency characteristics and the speed change characteristics to obtain a time-series correlation coefficient; performing speed fluctuation analysis based on the time-series correlation coefficient to obtain a speed fluctuation coefficient; performing anomaly judgment on the speed fluctuation coefficient according to the dwell frequency index and the path complexity to obtain an anomaly judgment result; and performing multi-dimensional behavior processing on the anomaly judgment result to construct the abnormal behavior judgment vector.
[0069] Furthermore, the aforementioned security early warning device for abnormal behavior trajectory analysis is also used for: retrieving historical behavior trajectory record logs of the target area, traversing the historical behavior trajectory record logs to extract normal trajectory samples, and constructing a normal behavior trajectory sample database; performing benchmark analysis based on the normal behavior trajectory sample database to determine trajectory feature benchmark distribution data; performing deviation analysis on the abnormal behavior judgment vector according to the trajectory feature benchmark distribution data to determine the abnormal deviation degree; setting a deviation critical threshold, and activating a wandering mode when the abnormal deviation degree is greater than the deviation critical threshold, performing trajectory abnormality impact analysis through the wandering mode to determine the set of dominant influencing factors; and classifying the abnormal behavior level according to the set of dominant influencing factors.
[0070] Furthermore, the aforementioned safety early warning device for abnormal behavior trajectory analysis is also used for: performing regression calculations based on the trajectory feature baseline distribution data to construct a threshold baseline; setting a deviation threshold according to the threshold baseline; comparing and judging the abnormal deviation degree according to the deviation threshold; activating the wandering mode when the abnormal deviation degree is greater than the deviation threshold; performing causal inference on the abnormal behavior judgment vector through the wandering mode to determine multiple influencing factors; and performing dominant analysis on the multiple influencing factors to determine the set of dominant influencing factors.
[0071] Furthermore, the security early warning device for abnormal behavior trajectory analysis is also used for: extracting abnormal trajectory fragments through the hierarchical early warning mechanism for spatiotemporal backtracking to generate a three-dimensional trajectory reconstruction map; constructing a profile based on the three-dimensional trajectory reconstruction map and the identity tag data to generate a profile of a suspicious person; performing behavioral correlation analysis based on the profile of the suspicious person to generate a behavioral correlation map; introducing a historical case library of the target area; performing similarity matching based on the behavioral correlation map and the historical case library to generate a risk probability assessment value; and adding the risk probability assessment value to the alarm signal.
[0072] Furthermore, the aforementioned security early warning device for abnormal behavior trajectory analysis is also used for: performing perimeter protection analysis on the target area, constructing a defense level matrix, protecting the target area based on the defense level matrix, and constructing electronic fence information; performing defense feasibility analysis on the alarm signal according to the electronic fence information, generating defense feasibility results, the defense feasibility results including active defense parameters and passive defense parameters; when the defense feasibility result is the active defense parameter, generating a first security early warning report, setting an information push priority based on the risk probability assessment value, and pushing the security early warning report to the monitoring terminal according to the information push priority; when the defense feasibility result is the passive defense parameter, generating a second security early warning report, pushing it to the monitoring terminal, and initiating emergency personnel control commands.
[0073] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The security early warning method and specific examples of abnormal behavior trajectory analysis in the aforementioned embodiment one are also applicable to the security early warning device of abnormal behavior trajectory analysis in this embodiment. Through the foregoing detailed description of the security early warning method of abnormal behavior trajectory analysis, those skilled in the art can clearly understand the security early warning device of abnormal behavior trajectory analysis in this embodiment. Therefore, for the sake of brevity, it will not be described in detail here.
[0074] Example 3: Based on the same inventive concept as the security early warning method for abnormal behavior trajectory analysis in the foregoing examples, this application also provides a computer-readable storage medium storing a computer program, which, when executed, implements the steps of the security early warning method for abnormal behavior trajectory analysis described in any one of the above examples.
[0075] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0076] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of this application and its equivalents, this application also intends to include such modifications and variations.
Claims
1. A security early warning method for abnormal behavior trajectory analysis, characterized in that, The method includes: Behavioral trajectory data of the target area is collected by multi-source sensing devices, and multi-dimensional features are extracted from the behavioral trajectory dataset. The multi-dimensional features include trajectory spatiotemporal distribution features, speed change features, and dwell frequency features. Based on the dwell frequency characteristics, anomaly detection is performed on the trajectory spatiotemporal distribution characteristics and the velocity change characteristics to construct an abnormal behavior detection vector, including: Based on the dwell frequency characteristics, a time decay analysis is performed to generate a dwell frequency index, which includes a dynamic dwell weight. Based on the dynamic dwell weight, the spatiotemporal distribution characteristics of the trajectory are corrected for regional sensitivity, and a spatiotemporal anomaly coefficient is generated. Path analysis is performed based on the spatiotemporal anomaly coefficients to determine the path complexity; The dwell frequency feature and the speed change feature are correlated in time to obtain the time correlation coefficient. Based on the time correlation coefficient, speed fluctuation analysis is performed to obtain the speed fluctuation coefficient. The speed fluctuation coefficient is anomaly determined by combining the dwell frequency index with the path complexity, and the anomaly determination result is obtained. The anomaly determination result is then subjected to multi-dimensional behavior processing to construct the anomaly behavior determination vector. Based on the abnormal behavior determination vector, a loitering pattern is identified to determine the level of abnormal behavior. A tiered early warning mechanism is then triggered according to the abnormal behavior level, including: Retrieve historical behavior trajectory records in the target area, iterate through the historical behavior trajectory records to extract normal trajectory samples, and construct a normal behavior trajectory sample database. Based on the normal behavior trajectory sample database, benchmark analysis is performed to determine the baseline distribution data of trajectory features; The deviation analysis is performed on the abnormal behavior judgment vector based on the trajectory feature baseline distribution data to determine the degree of abnormal deviation. A deviation threshold is set. When the abnormal deviation exceeds the deviation threshold, a wandering mode is activated. The trajectory anomaly impact analysis is performed through the wandering mode to determine the set of dominant influencing factors. The abnormal behavior level is determined by classifying the levels according to the set of dominant influencing factors. Based on the aforementioned hierarchical early warning mechanism, an abnormal behavior alarm signal is generated. Combined with the electronic fence information of the target area, a security early warning report is generated and pushed to the monitoring terminal.
2. The security early warning method for abnormal behavior trajectory analysis as described in claim 1, characterized in that, Methods for collecting behavioral trajectory data of a target area using multi-source sensing devices include: Data is collected by traversing the target area using multi-source sensing devices to obtain a multi-source sensing dataset, which includes continuous video stream data, target positioning sequence, and identity verification information. Human body recognition is performed based on the continuous video stream data, and skeleton key point data is extracted; Motion analysis is performed based on the target localization sequence to obtain motion feature data; Based on the authentication information, identity is identified, and identity tag data is generated; The skeleton key point data, the motion feature data, and the identity tag data are fused in a spatiotemporal manner to generate the behavior trajectory dataset.
3. The security early warning method for abnormal behavior trajectory analysis as described in claim 2, characterized in that, Multi-dimensional feature extraction is performed on the behavioral trajectory dataset, including trajectory spatiotemporal distribution features, speed change features, and dwell frequency features. The method includes: The target region is divided into multiple sub-networks, and the skeleton key point data is mapped to the multiple sub-networks to obtain point density distribution data. Based on the point density distribution data, the dwell time is calculated to obtain the regional dwell time index, a spatiotemporal distribution matrix is constructed, and the regional dwell time index is mapped to the spatiotemporal distribution matrix for feature analysis to obtain the trajectory spatiotemporal distribution features. Based on the motion feature data, adjacent displacements are calculated to obtain an instantaneous velocity sequence; The instantaneous velocity sequence is smoothed to construct a velocity change rate histogram. The frequency of continuous changes is monitored by traversing the velocity change rate histogram to obtain velocity change characteristics. Based on the regional dwelling index and the speed change characteristics, a dwelling analysis was performed on the behavioral trajectory dataset to identify multiple dwelling hotspot areas; A heatmap of dwell frequency is drawn based on the multiple dwelling hotspot areas and the identity tag data. Feature encoding is performed based on the dwell frequency heatmap to determine the dwell frequency feature.
4. The security early warning method for abnormal behavior trajectory analysis as described in claim 1, characterized in that, A deviation threshold is set. When the abnormal deviation exceeds the deviation threshold, a wandering mode is activated. Trajectory anomaly impact analysis is performed using the wandering mode to determine the set of dominant influencing factors. The method includes: Regression calculations are performed based on the trajectory feature baseline distribution data to construct a threshold baseline, and a deviation critical threshold is set according to the threshold baseline. The abnormal deviation is compared and judged according to the deviation threshold. When the abnormal deviation is greater than the deviation threshold, the lingering mode is activated. By using the lingering pattern to perform causal reasoning on the abnormal behavior judgment vector, multiple influencing factors are identified. The dominant influencing factors are analyzed to determine the set of dominant influencing factors.
5. A security early warning method for abnormal behavior trajectory analysis as described in claim 2, characterized in that, The method for generating abnormal behavior alarm signals based on the aforementioned hierarchical early warning mechanism includes: The abnormal trajectory segments are extracted through the hierarchical early warning mechanism for spatiotemporal backtracking, generating a three-dimensional trajectory reconstruction map. Based on the three-dimensional trajectory reconstruction map and the identity tag data, a profile is constructed to generate a profile of a suspicious person. Based on the profile of the suspicious person, a behavioral association analysis is performed to generate a behavioral association map. A historical case library of the target area is introduced, and similarity matching is performed based on the behavior association graph and the historical case library to generate a risk probability assessment value. The risk probability assessment value is then added to the alarm signal.
6. The security early warning method for abnormal behavior trajectory analysis as described in claim 5, characterized in that, Abnormal behavior alarm signals are combined with electronic fence information of the target area to generate a security warning report and push it to the monitoring terminal. Methods include: Perform perimeter protection analysis on the target area, construct a defense level matrix, protect the target area based on the defense level matrix, and construct electronic fence information; Based on the electronic fence information, a defense feasibility analysis is performed on the alarm signal to generate a defense feasibility result, which includes active defense parameters and passive defense parameters. When the feasible defense result is the active defense parameter, a first security warning report is generated, and the information push priority is set based on the risk probability assessment value. The security warning report is then pushed to the monitoring terminal according to the information push priority. If the feasible result of the defense is the passive defense parameter, a second security warning report is generated, pushed to the monitoring terminal, and an emergency personnel control command is initiated.
7. A security early warning device for analyzing abnormal behavior trajectories, characterized in that, The steps for implementing the security early warning method for abnormal behavior trajectory analysis according to any one of claims 1 to 6 include: The behavior trajectory data acquisition module is used to collect behavior trajectory data of the target area through multi-source sensing devices, and to extract multi-dimensional features from the behavior trajectory dataset. The multi-dimensional features include trajectory spatiotemporal distribution features, speed change features, and dwell frequency features. The anomaly detection module is used to detect anomalies in the trajectory spatiotemporal distribution features and the speed change features based on the dwell frequency features, and to construct an abnormal behavior detection vector. The loitering pattern recognition module is used to recognize loitering patterns based on the abnormal behavior judgment vector, determine the level of abnormal behavior, and trigger a graded early warning mechanism according to the level of abnormal behavior. The report push module is used to generate an abnormal behavior alarm signal based on the hierarchical early warning mechanism, combine it with the electronic fence information of the target area to generate a safety early warning report, and push it to the monitoring terminal.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed, implements the steps of a security early warning method for abnormal behavior trajectory analysis as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Aerial target activity rule prediction method
CN114330509A
Smart park safety management method and system based on AI visual identification
CN120339947A