Methods and devices for security risk assessment of public networks and personnel behavior

By employing multimodal data fusion and dynamic feature fusion methods, the limitations of single-dimensional assessment in community safety risk assessment are overcome. This enables spatiotemporal correlation analysis of network and behavioral data, enhancing the globality and real-time nature of risk assessment, and improving its accuracy and timeliness.

CN121119693BActive Publication Date: 2026-07-17BI SHENGYUN (WUHAN) INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BI SHENGYUN (WUHAN) INFORMATION TECH CO LTD
Filing Date
2025-08-27
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing community security risk assessment methods often focus on a single dimension, resulting in fragmented risk assessments. This makes it difficult to capture the dynamic relationship between cyber threats and behavioral risks, and the reliance on static models leads to delayed and inaccurate risk warnings.

Method used

By fusing multimodal data from community public networks and personnel behavior data, a community safety map is constructed. Spatiotemporal correlation analysis is performed using target graph neural networks, feature fusion is combined with spatiotemporal graph convolutional networks, and a two-way risk assessment model is used to conduct a collaborative quantitative assessment of network and behavioral risks.

Benefits of technology

It enables spatiotemporal correlation analysis and dynamic feature fusion of network and behavioral data, significantly improving the globality and real-time nature of risk assessment, breaking through the limitations of traditional single-dimensional assessment, and improving the accuracy and timeliness of risk assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121119693B_ABST
    Figure CN121119693B_ABST
Patent Text Reader

Abstract

This application discloses a method and apparatus for assessing security risks of public networks and personnel behavior. The method includes: multimodal data fusion of public network data and personnel behavior data of community public networks to construct a community security map; spatiotemporal correlation analysis of the community security map using a target graph neural network to obtain a dynamic correlation map; generation of a dynamic risk map using a spatiotemporal graph convolutional network and the dynamic correlation map; and bidirectional risk assessment using a bidirectional risk assessment model and the dynamic risk map to determine network risk assessment values ​​and behavioral risk assessment values, and, combined with risk correlation coefficients, to determine the security risk assessment value of the target community. Through this approach, spatiotemporal correlation analysis and dynamic feature fusion of network and behavioral data are achieved, significantly improving the globality and real-time nature of risk assessment; and the synergistic quantification of network risk and behavioral risk overcomes the limitations of traditional single-dimensional assessment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of unmanned aerial vehicle (UAV) technology, and in particular to methods and apparatus for assessing security risks of public networks and human behavior. Background Technology

[0002] Current community security risk assessment methods generally suffer from the following technical deficiencies: traditional solutions often focus on a single dimension (such as analyzing only cyberattacks or abnormal resident behavior), resulting in fragmented risk assessments and difficulty in capturing the dynamic correlation between cyber threats and behavioral risks; existing systems rely on static models, leading to delayed and inaccurate risk warnings. Summary of the Invention

[0003] The main purpose of this application is to provide a method and device for assessing the security risks of public networks and human behavior, aiming to solve the technical problem of how to effectively integrate community public network and resident behavior data, realize two-way dynamic assessment of network-side and behavior-side risks, accurately locate high-risk areas, and coordinate defense.

[0004] To achieve the above objectives, this application proposes a method for assessing the security risks of public networks and personnel behavior, the method comprising:

[0005] Multimodal data fusion is performed on public network data from the community's public network and personnel behavior data from the community to construct a community security map;

[0006] Spatiotemporal correlation analysis of the community security map is performed using a target graph neural network to obtain a dynamic correlation map;

[0007] A spatiotemporal feature fusion method is used to perform spatiotemporal feature fusion on the aforementioned correlation dynamic graph to generate a dynamic risk graph;

[0008] A two-way risk assessment is conducted using the two-way risk assessment model and the dynamic risk map to determine the network risk assessment value and the behavioral risk assessment value.

[0009] The risk correlation coefficient is determined based on the dynamic risk map, and the security risk assessment value of the target community is determined based on the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value.

[0010] In one embodiment, the step of multimodal data fusion of public network data from the community's public network and behavioral data of community personnel to construct a community security map includes:

[0011] Feature extraction is performed on the public network data of the community public network and the personnel behavior data of the community personnel to obtain the network data features corresponding to the public network data and the behavioral data features corresponding to the personnel behavior data.

[0012] Define the graph structure based on the entity and relationship information of the target community, and determine the community graph structure;

[0013] The network data features and the behavioral data features are weighted using an attention mechanism to obtain weighted network data features and weighted behavioral data features;

[0014] The weighted network data features and weighted behavioral data features are mapped to a preset graph embedding space to obtain the corresponding graph embedding representation;

[0015] Multimodal data fusion is performed based on the community graph structure and the graph embedding representation to construct a community security graph containing network nodes and behavioral nodes, wherein the network nodes represent entities in the community public network and the behavioral nodes represent the behaviors of community members.

[0016] In one embodiment, the step of fusing spatiotemporal features of the correlation dynamic graph using a spatiotemporal graph convolutional network to generate a dynamic risk graph includes:

[0017] A spatial adjacency matrix is ​​generated based on the node relationship data corresponding to the aforementioned dynamic graph.

[0018] A spatiotemporal feature matrix is ​​generated based on the aforementioned correlation dynamic graph, the aforementioned public network data, and the aforementioned personnel behavior data;

[0019] The spatiotemporal feature fusion of the correlation dynamic graph is performed by a spatiotemporal graph convolutional network, the spatial adjacency matrix, and the spatiotemporal feature matrix, and a dynamic risk graph is generated based on the fusion result.

[0020] In one embodiment, the step of fusing spatiotemporal features of the correlation dynamic graph through a spatiotemporal graph convolutional network, the spatial adjacency matrix, and the spatiotemporal feature matrix, and generating a dynamic risk graph based on the fusion result, includes:

[0021] Spatial features are extracted from the spatiotemporal feature matrix through the convolutional layers of the spatiotemporal graph convolutional network to obtain a spatial feature map;

[0022] The spatial feature map is aggregated based on the spatial adjacency matrix to obtain the aggregated spatial feature map.

[0023] The aggregated spatial feature map is input into the temporal convolutional layer of the spatiotemporal graph convolutional network, and temporal features are extracted based on the temporal dimension information to obtain the spatiotemporal fusion feature map.

[0024] Based on the spatiotemporal fusion feature map, risk scores are performed on the nodes of the correlation dynamic map to generate a node risk score matrix;

[0025] Based on the node risk scoring matrix, the correlation dynamic graph is visualized to generate a dynamic risk graph containing risk distribution information.

[0026] In one embodiment, the step of determining the network risk assessment value and the behavioral risk assessment value by performing a two-way risk assessment using the two-way risk assessment model and the dynamic risk map includes:

[0027] Based on the edge relation density and node attribute importance of the dynamic risk graph, calculate the network risk weight of each node;

[0028] Using fuzzy set theory, the fuzzy membership degree of each node is determined based on the network risk weight and historical risk data of each node. The fuzzy membership degree represents the probability that a node belongs to different risk levels.

[0029] A network risk assessment model is constructed based on the network risk weights and fuzzy membership degrees of each node;

[0030] The network risk assessment value of each node in the dynamic risk map is determined by the network risk assessment model.

[0031] Based on the network risk assessment values ​​of each node, the network risk assessment value of the community public network is determined;

[0032] Behavioral risk assessment is performed based on the spatiotemporal characteristics of the entities corresponding to the dynamic risk map, the cross-modal association information corresponding to the dynamic risk map, and the two-way risk assessment model to determine the behavioral risk assessment value.

[0033] In one embodiment, the step of performing behavioral risk assessment based on the spatiotemporal characteristics of the entities corresponding to the dynamic risk map, the cross-modal association information corresponding to the dynamic risk map, and the bidirectional risk assessment model to determine the behavioral risk assessment value includes:

[0034] Based on the historical behavior data of the behavior nodes in the dynamic risk map, extract the behavior feature sequence;

[0035] Spatiotemporal feature analysis is performed on the behavioral feature sequence to obtain the spatiotemporal feature vector of the behavioral node;

[0036] Based on the spatiotemporal feature vectors of behavioral nodes in the dynamic risk map and the spatiotemporal features of the entities corresponding to the dynamic risk map, cross-modal feature fusion is performed to obtain the fused behavioral feature vectors.

[0037] A two-way risk assessment model is constructed using the support vector machine algorithm based on the fused behavioral feature vectors and the cross-modal association information corresponding to the dynamic risk map;

[0038] The preliminary risk assessment value of the behavioral nodes in the dynamic risk map is determined by the bidirectional risk assessment model.

[0039] Based on the preliminary risk assessment value of the behavioral nodes and the mutual influence relationship between the behavioral nodes in the dynamic risk map, risk transmission analysis is performed to obtain the adjusted behavioral risk assessment value.

[0040] Based on the adjusted behavioral risk assessment values, the behavioral risk assessment values ​​of community personnel are determined.

[0041] In one embodiment, the step of determining the risk correlation coefficient based on the dynamic risk map, and determining the security risk assessment value of the target community based on the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value includes:

[0042] Based on the association path information in the dynamic risk map, identify the associations between different network nodes and behavioral nodes;

[0043] The correlation between different network nodes and behavioral nodes is quantified by using a spatiotemporal analysis algorithm to obtain an index of correlation strength.

[0044] Based on the correlation strength index and the spatiotemporal characteristics of the dynamic risk map, a machine learning algorithm is used to calculate the risk correlation coefficient.

[0045] The target dynamic weight is determined by weighting the network risk assessment value and the behavioral risk assessment value.

[0046] The risk value is calculated based on the target dynamic weight, the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value to determine the security risk assessment value of the target community.

[0047] In one embodiment, before the step of performing spatiotemporal correlation analysis on the community security graph using a target graph neural network to obtain a correlation dynamic graph, the method further includes:

[0048] The classifier is trained using local network data and local behavior data to obtain a local classification model and the local model parameters corresponding to the local classification model.

[0049] Send local model parameters to the central server so that the central server can calculate global model parameters based on the sample size of each community node and the local model parameters of each community node and then feed them back.

[0050] The graph neural network is initialized based on the global model parameters to obtain the target graph neural network.

[0051] In one embodiment, after the steps of determining the risk correlation coefficient based on the dynamic risk map, and determining the security risk assessment value of the target community based on the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value, the method further includes:

[0052] When the security risk assessment value of the target community exceeds a preset threshold, the security risk assessment value is mapped to the dynamic risk map, and the risk candidate area of ​​the target community is determined based on the mapping result;

[0053] The associated nodes of the risk candidate region are determined based on the risk candidate region and the dynamic risk map;

[0054] Community early warning information is generated based on the risk candidate areas and the associated nodes, and the community early warning information is pushed out.

[0055] Furthermore, to achieve the above objectives, this application also proposes a security risk assessment device for public networks and personnel behavior, the device comprising:

[0056] The module is used to perform multimodal data fusion on public network data and community personnel behavior data to construct a community security map;

[0057] The analysis module is used to perform spatiotemporal correlation analysis on the community security map through a target graph neural network to obtain a correlation dynamic map;

[0058] The generation module is used to perform spatiotemporal feature fusion on the correlation dynamic map through a spatiotemporal graph convolutional network to generate a dynamic risk map;

[0059] The assessment module is used to conduct a two-way risk assessment using the two-way risk assessment model and the dynamic risk map, and to determine the network risk assessment value and the behavioral risk assessment value.

[0060] The processing module is used to determine the risk correlation coefficient based on the dynamic risk map, and to determine the security risk assessment value of the target community based on the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value.

[0061] This application constructs a community security map by fusing multimodal data from public network data and behavioral data of community personnel. It then performs spatiotemporal correlation analysis on the community security map using a target graph neural network to obtain a dynamic correlation map. Finally, it fuses spatiotemporal features of the dynamic correlation map using a spatiotemporal graph convolutional network to generate a dynamic risk map. A bidirectional risk assessment is performed using a two-way risk assessment model and the dynamic risk map to determine network risk assessment values ​​and behavioral risk assessment values. Based on the dynamic risk map, a risk correlation coefficient is determined, and the security risk assessment value of the target community is determined based on the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value. Through this method, the community security map is constructed by multimodal data fusion. Combining a target graph neural network and a spatiotemporal graph convolutional network, it achieves spatiotemporal correlation analysis and dynamic feature fusion of network and behavioral data, significantly improving the globality and real-time performance of risk assessment. The bidirectional risk assessment model overcomes the limitations of traditional single-dimensional assessment by synergistically quantifying network risk and behavioral risk. Attached Figure Description

[0062] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0063] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0064] Figure 1 A flowchart illustrating the first embodiment of the security risk assessment method for public networks and personnel behavior in this application;

[0065] Figure 2 A flowchart illustrating the second embodiment of the security risk assessment method for public networks and personnel behavior in this application;

[0066] Figure 3 This is a schematic diagram of the module structure of the security risk assessment device for public networks and personnel behavior according to an embodiment of this application.

[0067] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0068] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.

[0069] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.

[0070] The main solution of this application embodiment is as follows: Multimodal data fusion is performed on public network data of the community public network and personnel behavior data of community personnel to construct a community security map; spatiotemporal correlation analysis is performed on the community security map using a target graph neural network to obtain a dynamic correlation map; spatiotemporal feature fusion is performed on the dynamic correlation map using a spatiotemporal graph convolutional network to generate a dynamic risk map; bidirectional risk assessment is performed using a bidirectional risk assessment model and the dynamic risk map to determine network risk assessment values ​​and behavioral risk assessment values; risk correlation coefficients are determined based on the dynamic risk map, and the security risk assessment value of the target community is determined based on the risk correlation coefficients, the network risk assessment value, and the behavioral risk assessment value.

[0071] Current community security risk assessment methods generally suffer from the following technical deficiencies: traditional solutions often focus on a single dimension (such as analyzing only cyberattacks or abnormal resident behavior), resulting in fragmented risk assessments and difficulty in capturing the dynamic correlation between cyber threats and behavioral risks; existing systems rely on static models, leading to delayed and inaccurate risk warnings.

[0072] This application provides a solution that constructs a community security graph through multimodal data fusion. By combining target graph neural networks and spatiotemporal graph convolutional networks, it realizes the spatiotemporal correlation analysis and dynamic feature fusion of network and behavioral data, which significantly improves the globality and real-time performance of risk assessment. The two-way risk assessment model breaks through the limitations of traditional single-dimensional assessment by synergistically quantifying network risk and behavioral risk.

[0073] It should be noted that the executing entity in this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or a public network and personnel behavior security risk assessment device capable of performing the above functions. The following description uses a public network and personnel behavior security risk assessment device as the executing entity to illustrate this embodiment and the subsequent embodiments.

[0074] Based on this, embodiments of this application provide a method for assessing security risks of public networks and personnel behavior, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the security risk assessment method for public networks and personnel behavior in this application.

[0075] In this embodiment, the security risk assessment method for public networks and personnel behavior includes steps S10 to S50:

[0076] Step S10: Perform multimodal data fusion on public network data of the community public network and personnel behavior data of community personnel to construct a community security map.

[0077] It should be noted that public network data includes information such as network traffic, access logs, abnormal login information, and device status of devices within the community. Personnel behavior data is resident behavior data collected through a series of devices such as cameras, access control systems, and mobile apps, including but not limited to location trajectories, cluster density, and abnormal behavior.

[0078] It is understandable that a community security graph representing community entities can be obtained by associating network nodes (IPs, devices) of public network data with behavioral entities (resident IDs, events) of personnel behavior data through a graph structure (such as Neo4j). For example, an edge represents "resident A accessed IP B", and node attributes include network risk characteristics (such as vulnerability severity) and behavioral characteristics (such as cluster density).

[0079] In one feasible implementation, step S10 may include steps A11 to A15:

[0080] Step A11: Extract features from the public network data of the community public network and the personnel behavior data of community personnel respectively to obtain the network data features corresponding to the public network data and the behavior data features corresponding to the personnel behavior data.

[0081] It should be noted that LSTM (Long Short-Term Memory) or other methods are used to extract features from public network data, thereby obtaining the network data features corresponding to the public network data. In this embodiment, the following formula can be used for feature extraction: ,in Information such as traffic rate, protocol type, and source IP anomaly level.

[0082] It is understandable that YOLOv8 is used to detect targets, LSTM is used to model behavioral sequences, and other methods are used to extract features from personnel behavior data, thereby obtaining the behavioral data features corresponding to the personnel behavior data. YOLOv8 (You Only Look Once version 8) is an advanced deep learning model in the field of object detection, used to detect and classify different targets in images or videos in real time. In this embodiment, the following formula can be used for feature extraction: ,in , The behavioral characteristics (such as position, time, etc.) of time step t.

[0083] Step A12: Define the graph structure based on the entity and relationship information of the target community to determine the community graph structure.

[0084] It should be noted that the entity information of the target community is used to define the node types in the graph, including but not limited to IP, device, resident, and event; the relationship information is used to define the edge types in the graph, including but not limited to access, aggregation, and participation, thus obtaining the community graph structure, which is the corresponding main structure when building the knowledge graph later.

[0085] Step A13: Use an attention mechanism to weight the network data features and the behavioral data features to obtain weighted network data features and weighted behavioral data features.

[0086] It should be noted that the attention mechanism assesses the importance of network data features and behavioral data features, assigning different weights to different features to highlight key information and suppress non-key information. The weighted network data features and weighted behavioral data features more accurately reflect the actual situation of community public networks and personnel behavior, providing a reliable data foundation for subsequent network mapping and risk assessment.

[0087] Step A14: Map the weighted network data features and weighted behavioral data features to a preset graph embedding space to obtain the corresponding graph embedding representation.

[0088] It should be noted that graph embedding representation transforms network data features and behavioral data features into vector representations of nodes and edges in a graph structure. These vector representations preserve the structural and relational information of the original data, facilitating subsequent graph construction and risk assessment. By mapping weighted network data features and weighted behavioral data features to a predefined graph embedding space, low-dimensional vector representations of community public networks and personnel behaviors can be obtained, thereby achieving data dimensionality reduction and feature extraction, and improving data processing efficiency and accuracy.

[0089] Step A15: Perform multimodal data fusion based on the community graph structure and the graph embedding representation to construct a community security graph containing network nodes and behavior nodes, wherein the network nodes represent entities in the community public network and the behavior nodes represent the behavior of community personnel.

[0090] It should be noted that the construction of the community security graph achieves comprehensive coverage and correlation analysis of the community's public network and personnel behavior. In the graph, network nodes and behavioral nodes are interconnected through edges, forming a complex network structure that reflects the relationships and interaction patterns between various entities within the community. The community security graph can be updated subsequently using real-time network data and real-time behavioral data.

[0091] Step S20: Perform spatiotemporal correlation analysis on the community security map using a target graph neural network to obtain a correlation dynamic map.

[0092] It should be noted that the target graph neural network is used to capture the spatiotemporal dependencies between nodes. It analyzes the spatiotemporal correlation between network attacks and behaviors, such as the co-occurrence probability of data breaches and abnormal resident access behavior. Based on the analysis results, a community security graph containing spatiotemporal correlations can be obtained, i.e., a dynamic correlation graph. In this embodiment, a GNN (Graph Neural Network) is used as the target graph neural network, but other neural networks can also be used; this embodiment is not limited to this.

[0093] In one feasible implementation, step S20 may include steps B11-B13:

[0094] Step B11: Train the classifier using local network data and local behavior data to obtain a local classification model and the local model parameters corresponding to the local classification model.

[0095] It should be noted that local network data refers to historical public network data existing in the target community, and local behavioral data refers to historical behavioral data existing in the target community. The target community independently trains models or classifiers using local network data and local behavioral data, generates local model parameters, and sends the local model parameters to the central server.

[0096] Step B12: Send local model parameters to the central server so that the central server can calculate global model parameters based on the sample size of each community node and the local model parameters of each community node and then feed them back.

[0097] It should be noted that the target community sends its local model parameters to the central server. The central server calculates the global model parameters using the sample size corresponding to the community node that uploaded the model parameters and the local model parameters corresponding to all community nodes, and then distributes them to each community. In this embodiment, the formula for calculating the global model parameters can be: ,in For the first Sample size of each community node For the first Local model parameters for each community node.

[0098] Step B13: Initialize the graph neural network according to the global model parameters to obtain the target graph neural network.

[0099] It should be noted that after receiving the global model parameters from the central server, the target community initializes the graph neural network to obtain the target graph neural network, and also needs to initialize the spatiotemporal graph convolutional network. The initialization method can be: 1. Parameter matching: ... 1. Directly assign values ​​to parameters that match the structure of the graph neural network / spatiotemporal graph convolutional network. 2. Structure adaptation: Parameter mapping: If the model structure is different, it is necessary to... The initial layer is mapped to a graph neural network / spatiotemporal graph convolutional network (e.g., through linear transformation or truncation). Partial initialization: only some parameters are transferred (e.g., the embedding layer weights of the global model), and the remaining parameters are randomly initialized. Key parameter preservation: parameters in the global model that capture common features across communities (e.g., general patterns of relationships between nodes) are preserved. In this embodiment, to protect community-related data and avoid privacy leaks, Laplacian noise can also be added to the model output using differential privacy.

[0100] Step S30: Perform spatiotemporal feature fusion on the correlation dynamic map using a spatiotemporal graph convolutional network to generate a dynamic risk map.

[0101] It should be noted that by combining the spatial adjacency matrix and the spatiotemporal feature matrix, features are fused in both time and space dimensions through a spatiotemporal graph convolutional network to generate a more comprehensive dynamic risk representation. The correlation dynamic graph containing this more comprehensive dynamic risk representation is called the dynamic risk graph. In this embodiment, the spatiotemporal feature matrix includes spatial and temporal dimensions, and the spatial adjacency matrix is ​​used to represent the spatial relationships at different time steps (e.g., a certain IP is associated with multiple residential devices at time t).

[0102] Step S40: Perform a two-way risk assessment using the two-way risk assessment model and the dynamic risk map to determine the network risk assessment value and the behavioral risk assessment value.

[0103] It should be noted that the two-way risk assessment model includes a network-side risk assessment model and a behavior-side risk assessment model. The network-side risk assessment model is built based on fuzzy mathematics and is used to combine dynamic risk maps to conduct network-side risk assessment, thereby obtaining the network risk assessment value. The behavioral risk assessment model is built on a game theory model and is used to perform behavioral risk assessment by combining dynamic risk maps, thereby obtaining behavioral risk assessment values. In this embodiment, the values ​​of both network risk assessment and behavioral risk assessment range from 0 to 1, with higher values ​​indicating more severe risks.

[0104] In one feasible implementation, step S40 may include steps C11 to C16:

[0105] Step C11: Calculate the network risk weight of each node based on the edge relation density and the importance of node attributes in the dynamic risk graph.

[0106] It should be noted that edge relationships refer to the connection methods or relationship types between nodes in a dynamic risk graph, such as "access" or "aggregation." Node attributes refer to the feature description information corresponding to each node, such as the relationship type, like "access" or "aggregation." These relationships are crucial for understanding the interactions between different entities.

[0107] As can be understood, edge density refers to the proportion of edges connected to a particular node out of the total number of edges, reflecting the importance of that node in the network. The importance of node attributes is determined by the importance and influence of the information they represent. For example, certain key attributes (such as vulnerability severity or abnormal behavior) may have a significant impact on risk assessment results.

[0108] Specifically, network risk weight represents the magnitude of risk borne by each node in the network and is an important basis for subsequent network risk assessment. In this embodiment, the calculation formula for network risk weight can be: W(i) = f(D(i), A(i)), where W(i) represents the network risk weight of node i, D(i) represents the edge relation density of node i, A(i) represents the importance of node attributes of node i, and f represents the function for calculating network risk weight based on edge relation density and the importance of node attributes. The specific form of this function can be set according to the actual situation.

[0109] Step C12: Using fuzzy set theory, determine the fuzzy membership degree of each node based on the network risk weight and historical risk data of each node, where the fuzzy membership degree represents the probability that a node belongs to different risk levels.

[0110] It should be noted that fuzzy set theory is a mathematical tool for handling uncertainties and fuzzy problems. By defining fuzzy sets and membership functions, the degree to which a node belongs to different risk levels can be described. In this embodiment, the calculation of fuzzy membership degree takes into account the network risk weight and historical risk data of the node, making the risk assessment results more accurate and reliable. The higher the fuzzy membership degree, the greater the probability that the node belongs to the corresponding risk level, thus providing an important basis for subsequent risk assessment.

[0111] It is understandable that fuzzy membership is a risk level value assigned to each node or edge based on its network risk weight and historical risk data. This value represents the probability distribution of a node or edge at different risk levels and is used for subsequent risk assessment and decision-making. In this embodiment, the formula for calculating fuzzy membership can be: μ(i,j) = g(W(i), H(i, j)), where μ(i, j) represents the fuzzy membership of node i belonging to risk level j, W(i) represents the network risk weight of node i, H(i, j) represents the frequency or probability of node i belonging to risk level j in historical risk data, and g represents the function for calculating fuzzy membership based on network risk weight and historical risk data. The specific form of this function can be set according to the actual situation.

[0112] Step C13: Construct a network risk assessment model based on the network risk weights and fuzzy membership degrees of each node.

[0113] It should be noted that the network risk assessment model is constructed based on fuzzy mathematics and is used to evaluate the risk level of each node in the network. This model combines the network risk weights and fuzzy membership degrees of nodes, enabling it to more accurately reflect the risk distribution within the network. In this embodiment, the construction process of the network risk assessment model includes steps such as determining assessment indicators, establishing an assessment system, and selecting assessment methods, ultimately yielding a network risk assessment value used to measure the overall risk level of the network.

[0114] Step C14: Determine the network risk assessment value of each node in the dynamic risk map using the network risk assessment model.

[0115] It should be noted that the network risk assessment value reflects the magnitude of the risk faced by each node in the network and is an important basis for subsequent risk management and control. In this embodiment, the network risk assessment value ranges from 0 to 1, with higher values ​​indicating more severe risks.

[0116] Step C15: Determine the network risk assessment value of the community public network based on the network risk assessment value of each node.

[0117] It should be noted that the network risk assessment value of the community public network is a comprehensive assessment of the overall risk level of the community public network. In this embodiment, the network risk assessment value of the community public network can be obtained by weighted averaging of the network risk assessment values ​​of each node. The weights can be determined according to the importance of each node in the network, for example, by setting weights based on indicators such as degree centrality and betweenness centrality of nodes. In this way, an assessment value reflecting the overall risk level of the community public network can be obtained, providing an important reference for subsequent risk management and control measures.

[0118] Step C16: Conduct behavioral risk assessment based on the spatiotemporal characteristics of the entities corresponding to the dynamic risk map, the cross-modal association information corresponding to the dynamic risk map, and the two-way risk assessment model, and determine the behavioral risk assessment value.

[0119] It should be noted that the spatiotemporal characteristics of entities refer to the characteristic behavior of events or residents recorded in the dynamic risk map at specific times and locations. Cross-module correlation information refers to the relationship analysis between different types of data sources (such as video surveillance and network traffic logs) to find risk clues that are difficult to detect with a single data source.

[0120] Understandably, when considering behavioral risk, a game scenario can be set up where participants include potential threat makers (e.g., criminals) and defenders (e.g., community administrators). Each participant has different strategy options; for example, criminals can choose whether to commit a certain act (e.g., illegal assembly), while administrators can choose to increase patrols or surveillance. A payoff matrix can be designed for this game scenario to quantify the gains or losses under different strategy combinations. For instance, if criminals choose not to take any action and administrators maintain the status quo, neither party incurs additional costs or gains; however, if criminals decide to commit acts of vandalism and administrators fail to take effective preventative measures, it could lead to significant economic losses and social instability. Concepts from game theory, such as Nash equilibrium, can be used to find the optimal strategy combination. Nash equilibrium states that, given the strategies of other participants remain unchanged, no party can achieve a better outcome by unilaterally changing their own strategy. Finding this point helps determine the most likely outcome and thus assess the corresponding risk level. Therefore, in this embodiment, the behavioral risk assessment value of the target community is obtained by calculating the importance of the entity's spatiotemporal characteristics, the correlation of cross-modal association information, and the prediction results of the game theory model in the two-way risk assessment model.

[0121] In one feasible implementation, step C16 may include: extracting behavioral feature sequences based on historical behavioral data of behavioral nodes in the dynamic risk map; performing spatiotemporal feature analysis on the behavioral feature sequences to obtain spatiotemporal feature vectors of the behavioral nodes; performing cross-modal feature fusion based on the spatiotemporal feature vectors of the behavioral nodes in the dynamic risk map and the spatiotemporal features of the entities corresponding to the dynamic risk map to obtain fused behavioral feature vectors; constructing a bidirectional risk assessment model using a support vector machine algorithm based on the fused behavioral feature vectors and the cross-modal association information corresponding to the dynamic risk map; determining preliminary risk assessment values ​​of the behavioral nodes in the dynamic risk map through the bidirectional risk assessment model; performing risk transmission analysis based on the preliminary risk assessment values ​​of the behavioral nodes and the mutual influence relationships between the behavioral nodes in the dynamic risk map to obtain adjusted behavioral risk assessment values; and determining behavioral risk assessment values ​​of community personnel based on the adjusted behavioral risk assessment values.

[0122] It should be noted that in this embodiment, the calculation process of the behavioral risk assessment value comprehensively considers the historical behavioral data, spatiotemporal characteristics, cross-modal correlation information, and mutual influence relationships between behavioral nodes, making the assessment results more comprehensive and accurate. Through spatiotemporal feature analysis of behavioral feature sequences, the temporal evolution and spatial distribution patterns of behavior can be captured, thereby revealing potential risk patterns. Cross-modal feature fusion fully utilizes the complementarity between different types of data sources, improving the sensitivity and specificity of risk assessment. The application of the support vector machine algorithm enables the risk assessment model to automatically learn and identify key features related to risk, thereby improving the accuracy and efficiency of the assessment. Risk transmission analysis further considers the mutual influence relationships between behavioral nodes, enabling the assessment results to more realistically reflect the actual situation of behavioral risk among community members.

[0123] It is understood that a behavioral feature sequence is composed of a series of behavioral nodes arranged in chronological order. Each behavioral node contains the timestamp, location, type, and related feature descriptions of the behavior. By performing spatiotemporal feature analysis on these behavioral feature sequences, the temporal evolution patterns and spatial distribution characteristics of the behavior can be revealed, thus providing an important basis for risk assessment. In this embodiment, the specific methods for spatiotemporal feature analysis can employ techniques such as time series analysis and spatial clustering analysis to extract key information from the behavioral feature sequences.

[0124] Spatiotemporal feature analysis involves processing and analyzing timestamps and location information in behavioral feature sequences to reveal the temporal evolution patterns and spatial distribution characteristics of behaviors. In this embodiment, time series analysis can be used to capture the changing trends of behaviors over time, such as whether the frequency of a certain behavior has increased or decreased within a certain time period. Spatial clustering analysis can be used to identify spatial clustering patterns of behaviors, such as whether a certain risky behavior frequently occurs in certain locations. By combining the results of time series analysis and spatial clustering analysis, a spatiotemporal feature vector of the behavioral node can be obtained. This vector contains key information on the temporal evolution and spatial distribution of the behavior, providing an important basis for subsequent risk assessment. In this embodiment, the specific form of the spatiotemporal feature vector can be set according to actual conditions, such as including indicators such as the temporal evolution trend of the behavior and the degree of spatial clustering.

[0125] Cross-modal feature fusion refers to the integration and consolidation of information from different data sources or different modalities to form a more comprehensive and accurate risk representation. In this embodiment, cross-modal feature fusion fuses the spatiotemporal feature vectors of behavioral nodes in a dynamic risk map with the spatiotemporal features of entities, while also combining the cross-modal association information corresponding to the dynamic risk map to obtain a fused behavioral feature vector. Through cross-modal feature fusion, the complementarity between different types of data sources can be fully utilized, improving the comprehensiveness and accuracy of risk assessment. In this embodiment, the specific method of cross-modal feature fusion can employ deep learning algorithms, such as convolutional neural networks (CNNs) or recurrent neural networks (RNNs), to achieve effective extraction and fusion of information from different modalities. In this way, a risk feature vector that integrates multiple information sources can be obtained, providing richer and more accurate input for subsequent risk assessment.

[0126] In this implementation, a bidirectional risk assessment model is constructed using the Support Vector Machine (SVM) algorithm, based on the fused behavioral feature vectors and cross-modal correlation information corresponding to the dynamic risk map. As a powerful classification and regression tool, the SVM algorithm can automatically learn and identify key risk-related features, thereby predicting the risk level given an input. In this embodiment, the application of the SVM algorithm enables the risk assessment model to automatically adapt to different types of data sources and features, improving the accuracy and generalization ability of the assessment. Specifically, the SVM algorithm finds an optimal hyperplane to distinguish data points of different categories, minimizing the classification error. In the risk assessment scenario, this means the algorithm can learn the data features that best distinguish between high-risk and low-risk behaviors, thus achieving accurate risk prediction. By training the SVM model, a function that can predict behavioral risk assessment values ​​based on the input feature vectors can be obtained.

[0127] As is understandable, risk transmission analysis refers to analyzing the interrelationships between behavioral nodes to assess the propagation and diffusion of risk among different nodes. In this embodiment, risk transmission analysis considers both direct and indirect connections between behavioral nodes. By simulating the propagation path and speed of risk, the potential impact of risk on the safety of community personnel can be assessed. Risk transmission analysis can employ graph theory and network analysis methods, treating behavioral nodes as nodes in a network and the interrelationships between them as edges. By calculating indicators such as the shortest path and betweenness centrality between nodes, the propagation patterns and key nodes of risk in the network can be revealed. In this way, an analytical result reflecting the risk transmission situation can be obtained.

[0128] Step S50: Determine the risk correlation coefficient based on the dynamic risk map, and determine the security risk assessment value of the target community based on the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value.

[0129] It should be noted that the risk correlation coefficient To quantify the synergistic threat between network-side and behavioral-side risks, a payoff matrix can be constructed using a dynamic risk graph, from which risk correlation coefficients can be extracted. These risk correlation coefficients... The system calculates collaborative threats and performs a comprehensive risk assessment by combining the weights and risk values ​​corresponding to network-side and behavioral-side risks, ultimately yielding the following result.

[0130] In one feasible implementation, step S50 may include steps D11 to D15:

[0131] Step D11: Identify the relationships between different network nodes and behavioral nodes based on the associated path information in the dynamic risk graph.

[0132] It should be noted that association path information refers to the paths connecting different nodes (including network nodes and behavioral nodes) in a network. These paths reveal the interdependencies and relationships between nodes. In this embodiment, the connections and interactions between network nodes and behavioral nodes can be visually observed through a dynamic risk graph, thereby identifying their correlations. This correlation is crucial for understanding how risks propagate and evolve between networks and human behavior.

[0133] Optionally, a payoff matrix is ​​constructed based on the identified correlations to quantify the risk synergy threat between different network nodes and behavioral nodes. The payoff matrix is ​​a matrix used to describe the potential gains or losses of each node under different strategy combinations. The construction of the payoff matrix is ​​based on the correlation path information in the dynamic risk graph. By setting the gain or loss values ​​under different strategy combinations, the degree of risk synergy threat between network nodes and behavioral nodes can be quantified.

[0134] Step D12: Quantify the correlation between different network nodes and behavioral nodes using a spatiotemporal analysis algorithm to obtain a correlation strength index.

[0135] It should be noted that the correlation strength index is used to measure the degree of connection between different network nodes and behavioral nodes. In this embodiment, the identified correlations can be further quantified using a spatiotemporal analysis algorithm to obtain a specific numerical index that reflects the strength of the connection between nodes. This quantification helps to more accurately assess the propagation and diffusion of risks among different nodes.

[0136] Step D13: Based on the correlation strength index and the spatiotemporal characteristics of the dynamic risk map, a machine learning algorithm is used to calculate the risk correlation coefficient.

[0137] It should be noted that the risk correlation coefficient is an indicator that integrates multiple factors, reflecting the degree of interaction and mutual influence between network-side risks and behavioral-side risks. In this embodiment, the choice of machine learning algorithm can be determined according to the actual situation; for example, regression algorithms, classification algorithms, or clustering algorithms can be used to achieve accurate calculation of the risk correlation coefficient. Through the calculation by the machine learning algorithm, a numerical indicator that reflects the degree of risk correlation can be obtained.

[0138] Step D14: Calculate the target dynamic weight based on the network risk assessment value and the behavioral risk assessment value. The formula for calculating the target dynamic weight is as follows:

[0139]

[0140] in, For the target dynamic weight, These are the network risk assessment value and the behavioral risk assessment value, respectively. It is a very small positive number.

[0141] It should be noted that the smallest positive number To prevent the denominator from being zero, the target dynamic weight is calculated using network risk assessment value and behavioral risk assessment value. When the network risk assessment value increases, the target dynamic weight... Automatically increase the priority of responding to network-side threats; and vice versa.

[0142] Step D15: Calculate the risk value based on the target dynamic weight, the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value to determine the security risk assessment value of the target community. The formula for calculating the security risk assessment value is as follows:

[0143]

[0144] in, This is a safety risk assessment value. This is the risk correlation coefficient.

[0145] It should be noted that by introducing a synergy effect term... The calculation of security risk assessment values ​​ensures that when both network-side and behavioral-side risks are high, the risk values ​​are non-linearly superimposed (e.g., when a DDoS attack and a crowd gathering occur simultaneously, the risk is far higher than the sum of the individual risks).

[0146] In one possible implementation, steps E11 to E13 may be included after step S50:

[0147] Step E11: When the security risk assessment value of the target community exceeds a preset threshold, the security risk assessment value is mapped to the dynamic risk map, and the risk candidate area of ​​the target community is determined based on the mapping result.

[0148] It should be noted that when the security risk assessment value of the target community exceeds a preset threshold (e.g., 0.8), the security risk assessment value will be... Mapping the data to spatial nodes (such as buildings and areas) of a dynamic risk map and assigning safety risk assessment values... Areas exceeding a preset threshold are designated as risk candidate areas.

[0149] Step E12: Determine the associated nodes of the risk candidate region based on the risk candidate region and the dynamic risk map.

[0150] Step E13: Generate community early warning information based on the risk candidate areas and the associated nodes, and push the community early warning information.

[0151] It should be noted that, based on the spatial adjacency matrix of the dynamic risk graph, associated nodes of risk candidate areas are identified (such as the physical / logical path between the IP address of the network attack source and the area where people gather). The risk propagation direction is analyzed through spatiotemporal graph convolutional networks, prioritizing key nodes on the propagation path (such as adjacent areas in the direction of infection source spread). Information such as risk candidate areas, associated nodes of risk candidate areas, and key nodes is aggregated to generate community early warning information, which is then pushed to administrators, enabling them to implement security control measures in the target community.

[0152] This embodiment constructs a community security map by fusing multimodal data from public network data and behavioral data of community personnel. A target graph neural network is then used to perform spatiotemporal correlation analysis on the community security map, resulting in a dynamic correlation map. A spatiotemporal feature fusion is performed on the dynamic correlation map using a spatiotemporal graph convolutional network to generate a dynamic risk map. A bidirectional risk assessment is then performed using a two-way risk assessment model and the dynamic risk map to determine network risk assessment values ​​and behavioral risk assessment values. A risk correlation coefficient is determined based on the dynamic risk map, and the security risk assessment value of the target community is determined based on the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value. Through this method, the community security map is constructed using multimodal data fusion. Combining a target graph neural network and a spatiotemporal graph convolutional network, spatiotemporal correlation analysis and dynamic feature fusion of network and behavioral data are achieved, significantly improving the globality and real-time performance of risk assessment. The bidirectional risk assessment model overcomes the limitations of traditional single-dimensional assessment by synergistically quantifying network risk and behavioral risk.

[0153] Based on the first embodiment of this application, in the second embodiment of this application, the content that is the same as or similar to that in the first embodiment described above can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 2 The security risk assessment method for public networks and personnel behavior further includes steps S301 to S303 in step S30:

[0154] Step S301: Generate a spatial adjacency matrix based on the node relationship data corresponding to the correlation dynamic graph.

[0155] It should be noted that node relationship data includes, but is not limited to, node data, edge relationship data, and node attribute information. Node data includes, but is not limited to, network nodes, behavioral entities, and other entities. Edge relationship data includes, but is not limited to, network relationships, behavioral relationships, and cross-modal relationships. Network nodes include, for example, devices and IP addresses within the community; behavioral entities include, for example, resident IDs and events; other entities include, for example, cameras and public places; network relationships include, for example, the attribution relationship between devices and IPs, and the access relationship between IPs; behavioral relationships include, for example, the participation relationship between residents and events, and the association between residents and geographical locations; cross-modal relationships include, for example, the association between network behaviors and residents, and the association between events and geographical locations.

[0156] It is understandable that by generating a spatial adjacency matrix representing the spatial relationships at different time steps through the node relationship data corresponding to the correlation dynamic graph, spatial correlation information between nodes can be provided for subsequent spatiotemporal feature fusion, thereby supporting two-way risk assessment and defense strategy optimization.

[0157] Step S302: Generate a spatiotemporal feature matrix based on the correlation dynamic graph, the public network data, and the personnel behavior data.

[0158] It should be noted that the spatiotemporal feature matrix includes spatial and temporal dimensions. The spatial dimension is composed of node embedding vectors from the correlation dynamic graph, representing the static attributes of the nodes (such as the anomaly degree of IP addresses and residents' behavioral patterns). The temporal dimension is composed of the temporal characteristics of network traffic in public network data and the behavioral sequences of personnel behavior data.

[0159] Step S303: Perform spatiotemporal feature fusion on the correlation dynamic graph using a spatiotemporal graph convolutional network, the spatial adjacency matrix, and the spatiotemporal feature matrix, and generate a dynamic risk graph based on the fusion result. The specific formula for spatiotemporal feature fusion is as follows:

[0160]

[0161] in, The result is the fusion result, where X is the spatiotemporal feature matrix. Let T be the spatial adjacency matrix, and T be the time series eigenvector. These are the weight matrices for the first and second level linear transformations, respectively. These are the first-level bias term and the second-level bias term, respectively. It is a non-linear activation function. K is a learnable activation function, K is a one-dimensional convolutional kernel, and TCN is a temporal convolutional layer.

[0162] It should be noted that the spatiotemporal graph convolutional network is used for joint modeling of spatiotemporal features, capturing the dynamic changes and propagation patterns of risks in the spatiotemporal dimension, and outputting node-level risk state vectors. The spatiotemporal features and risk state vectors are visualized and labeled on the dynamic graph of correlation, thereby obtaining a dynamic risk graph.

[0163] Understandably, temporal convolutional layers Explicitly modeling time-dimensional feature changes (such as fluctuations in attack frequency over time) enhances the ability to capture dynamic risks. This is a weight matrix for the time dimension, used to learn dynamic patterns of time features.

[0164] In practical implementation, learnable activation functions Spatial adjacency matrix used for dynamically weighting different time steps For example, assigning higher weights during peak attack periods (such as late at night). This is the attention weight matrix, used to learn the spatial adjacency matrix. The importance of These are learnable context vectors used for final normalization. Non-linear activation function. It can be ReLU, Sigmoid, or other activation functions, which enhance the model's ability to model complex patterns by introducing nonlinearity.

[0165] It should be noted that the weight matrix of the first-layer linear transformation is used to extract basic features (such as linear combinations of node attributes); the weight matrix of the second-layer linear transformation is used to perform a non-linear mapping on the fused features to generate the final output. The bias term is used to avoid center bias in the linear transformation and improve the model's expressive power.

[0166] Understandably, when performing spatiotemporal feature fusion, the spatiotemporal graph convolutional network can fuse the spatial adjacency matrix and the spatiotemporal feature matrix through weight matrix, bias term, attention mechanism and temporal convolution, dynamically adapt to the feature importance of different time periods (such as higher risk of behavior at night), and capture temporal dependencies (such as the fluctuation of attack frequency over time), and finally obtain a dynamic risk map that contains a more comprehensive dynamic risk representation.

[0167] In this embodiment, the spatio-temporal graph convolutional network ST-GCN (Spatio-Temporal Graph Convolutional Network) is selected, but other neural networks can also be used; this embodiment is not limited in this regard. By processing the spatial adjacency matrix and spatio-temporal feature matrix through the spatio-temporal graph convolutional network, the complex spatio-temporal dependencies between different entities (such as residents and devices) within the community can be captured. This fusion not only considers the spatial connectivity between entities (who is connected to whom) but also incorporates change patterns in the temporal dimension (such as abnormal traffic flow or crowd gathering trends over a certain period of time). This allows risk assessment to be no longer limited to a single moment or location, but to conduct a comprehensive analysis in both time and space dimensions. Combining public network data (such as traffic rate and protocol type) with personnel behavior data (such as location trajectory and gathering density) can identify complex threats that are difficult to detect with a single data source. For example, the simultaneous occurrence of network attack activities and abnormal crowd gatherings in a certain area may indicate deeper security risks. Through comprehensive analysis of multimodal data, these potential risk points can be located more accurately.

[0168] In one feasible implementation, step S303 may further include: extracting spatial features from the spatiotemporal feature matrix through the convolutional layer of the spatiotemporal graph convolutional network to obtain a spatial feature map; performing neighborhood aggregation on the spatial feature map according to the spatial adjacency matrix to obtain an aggregated spatial feature map; inputting the aggregated spatial feature map into the temporal convolutional layer of the spatiotemporal graph convolutional network and extracting temporal features based on temporal dimension information to obtain a spatiotemporal fusion feature map; performing risk scoring on the nodes of the correlation dynamic graph according to the spatiotemporal fusion feature map to generate a node risk scoring matrix; and performing visualization processing on the correlation dynamic graph according to the node risk scoring matrix to generate a dynamic risk graph containing risk distribution information.

[0169] It should be noted that spatial feature extraction mainly captures the spatial relationships between nodes, that is, which nodes are related to each other. Through the operation of convolutional layers, spatial feature maps can be extracted, which reflect the spatial relationship patterns between nodes.

[0170] Understandably, neighborhood aggregation is a further processing of the spatial feature map based on the spatial adjacency matrix. It aggregates the neighborhood information of each node to obtain the aggregated spatial feature map. This process enhances the spatial correlation between nodes, enabling the model to better understand the mutual influence between nodes.

[0171] Temporal feature extraction captures information about changes over time, such as fluctuations in network traffic and changes in human behavior over time. Through temporal convolutional layers, temporal features can be extracted, reflecting the state changes of nodes at different time steps.

[0172] It is worth noting that the spatiotemporal fusion feature map combines spatial and temporal features to obtain a feature map that contains both spatial correlation information and temporal variation information. This process enables the model to simultaneously consider the spatial correlation and temporal dependency between nodes, thereby providing a more comprehensive understanding of the risk distribution within the community.

[0173] Node risk scoring assigns a risk score to each node in the dynamic graph of interconnectedness, generating a node risk score matrix. This score reflects the risk status of each node at the current moment, providing a basis for subsequent risk warning and control.

[0174] Visualization processing involves visualizing the node risk scoring matrix to generate a dynamic risk map containing risk distribution information. This map intuitively displays the risk distribution within the community, enabling administrators to quickly identify potential risk points and take appropriate control measures.

[0175] This embodiment generates a spatial adjacency matrix based on the node relationship data corresponding to the dynamic correlation graph; generates a spatiotemporal feature matrix based on the dynamic correlation graph, the public network data, and the personnel behavior data; performs spatiotemporal feature fusion on the dynamic correlation graph using a spatiotemporal graph convolutional network, the spatial adjacency matrix, and the spatiotemporal feature matrix, and generates a dynamic risk graph based on the fusion result. Through this method, comprehensive risk assessment in the spatiotemporal dimensions is achieved, and the ability to identify complex threats is improved.

[0176] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the security risk assessment method for public networks and personnel behavior in this application. Any simple modifications based on this technical concept are within the scope of protection of this application.

[0177] This application also provides a security risk assessment device for public networks and personnel behavior; please refer to... Figure 3 The security risk assessment device for public networks and personnel behavior includes:

[0178] Module 10 is used to perform multimodal data fusion of public network data from the community public network and personnel behavior data from the community to construct a community security map.

[0179] Analysis module 20 is used to perform spatiotemporal correlation analysis on the community security map through a target graph neural network to obtain a correlation dynamic map.

[0180] The generation module 30 is used to perform spatiotemporal feature fusion on the correlation dynamic map through a spatiotemporal graph convolutional network to generate a dynamic risk map.

[0181] The assessment module 40 is used to conduct a two-way risk assessment using the two-way risk assessment model and the dynamic risk map, and to determine the network risk assessment value and the behavioral risk assessment value.

[0182] The processing module 50 is used to determine the risk correlation coefficient based on the dynamic risk map, and to determine the security risk assessment value of the target community based on the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value.

[0183] The public network and personnel behavior security risk assessment device provided in this application, employing the public network and personnel behavior security risk assessment method in the above embodiments, can solve the technical problem of how to effectively integrate community public network and resident behavior data, achieve bidirectional dynamic assessment of network-side and behavior-side risks, accurately locate high-risk areas, and coordinate defense. Compared with the prior art, the beneficial effects of the public network and personnel behavior security risk assessment device provided in this application are the same as those of the public network and personnel behavior security risk assessment method provided in the above embodiments, and other technical features in the public network and personnel behavior security risk assessment device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.

[0184] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.

Claims

1. A method for assessing security risks of public networks and personnel behavior, characterized in that, The method includes: Multimodal data fusion is performed on public network data from the community's public network and personnel behavior data from the community to construct a community security map; Spatiotemporal correlation analysis of the community security map is performed using a target graph neural network to obtain a dynamic correlation map; A spatiotemporal feature fusion method is used to perform spatiotemporal feature fusion on the aforementioned correlation dynamic graph to generate a dynamic risk graph; A two-way risk assessment is conducted using the two-way risk assessment model and the dynamic risk map to determine the network risk assessment value and the behavioral risk assessment value. The risk correlation coefficient is determined based on the dynamic risk map, and the security risk assessment value of the target community is determined based on the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value. The steps for constructing a community security map by multimodal data fusion of public network data from the community's public network and behavioral data of community personnel include: Feature extraction is performed on the public network data of the community public network and the personnel behavior data of the community personnel to obtain the network data features corresponding to the public network data and the behavioral data features corresponding to the personnel behavior data. Define the graph structure based on the entity and relationship information of the target community, and determine the community graph structure; The network data features and the behavioral data features are weighted using an attention mechanism to obtain weighted network data features and weighted behavioral data features; The weighted network data features and weighted behavioral data features are mapped to a preset graph embedding space to obtain the corresponding graph embedding representation; Multimodal data fusion is performed based on the community graph structure and the graph embedding representation to construct a community security graph containing network nodes and behavioral nodes, wherein the network nodes represent entities in the community public network and the behavioral nodes represent residents and events; The step of fusing spatiotemporal features of the correlated dynamic graph using a spatiotemporal graph convolutional network to generate a dynamic risk graph includes: A spatial adjacency matrix is ​​generated based on the node relationship data corresponding to the aforementioned dynamic graph. A spatiotemporal feature matrix is ​​generated based on the aforementioned correlation dynamic graph, the aforementioned public network data, and the aforementioned personnel behavior data; Spatial features are extracted from the spatiotemporal feature matrix through the convolutional layers of the spatiotemporal graph convolutional network to obtain a spatial feature map; The spatial feature map is aggregated based on the spatial adjacency matrix to obtain the aggregated spatial feature map. The aggregated spatial feature map is input into the temporal convolutional layer of the spatiotemporal graph convolutional network, and temporal features are extracted based on the temporal dimension information to obtain the spatiotemporal fusion feature map. Based on the spatiotemporal fusion feature map, risk scores are performed on the nodes of the correlation dynamic map to generate a node risk score matrix; Based on the node risk scoring matrix, the correlation dynamic graph is visualized to generate a dynamic risk graph containing risk distribution information; The step of conducting a two-way risk assessment using the two-way risk assessment model and the dynamic risk map to determine the network risk assessment value and the behavioral risk assessment value includes: Based on the edge relation density and node attribute importance of the dynamic risk graph, calculate the network risk weight of each node; Using fuzzy set theory, the fuzzy membership degree of each node is determined based on the network risk weight and historical risk data of each node. The fuzzy membership degree represents the probability that a node belongs to different risk levels. A network risk assessment model is constructed based on the network risk weights and fuzzy membership degrees of each node; The network risk assessment value of each node in the dynamic risk map is determined by the network risk assessment model. Based on the network risk assessment values ​​of each node, the network risk assessment value of the community public network is determined; Based on the historical behavior data of the behavior nodes in the dynamic risk map, extract the behavior feature sequence; Spatiotemporal feature analysis is performed on the behavioral feature sequence to obtain the spatiotemporal feature vector of the behavioral node; Based on the spatiotemporal feature vectors of behavioral nodes in the dynamic risk map and the spatiotemporal features of the entities corresponding to the dynamic risk map, cross-modal feature fusion is performed to obtain the fused behavioral feature vectors. A two-way risk assessment model is constructed using the support vector machine algorithm based on the fused behavioral feature vectors and the cross-modal association information corresponding to the dynamic risk map; The preliminary risk assessment value of the behavioral nodes in the dynamic risk map is determined by the bidirectional risk assessment model. Based on the preliminary risk assessment value of the behavioral nodes and the mutual influence relationship between the behavioral nodes in the dynamic risk map, risk transmission analysis is performed to obtain the adjusted behavioral risk assessment value. Based on the adjusted behavioral risk assessment values, determine the behavioral risk assessment values ​​for community personnel; The steps of determining the risk correlation coefficient based on the dynamic risk map, and determining the security risk assessment value of the target community based on the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value include: Based on the association path information in the dynamic risk map, identify the associations between different network nodes and behavioral nodes; The correlation between different network nodes and behavioral nodes is quantified by using a spatiotemporal analysis algorithm to obtain an index of correlation strength. Based on the correlation strength index and the spatiotemporal characteristics of the dynamic risk map, a machine learning algorithm is used to calculate the risk correlation coefficient. The target dynamic weight is determined by weighting the network risk assessment value and the behavioral risk assessment value, wherein the calculation formula for the target dynamic weight is as follows; ; in, For the target dynamic weight, , These are the network risk assessment value and the behavioral risk assessment value, respectively. It is a very small positive number; The risk value is calculated based on the target dynamic weight, the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value to determine the security risk assessment value of the target community.

2. The method as described in claim 1, characterized in that, Before the step of performing spatiotemporal correlation analysis on the community security graph using a target graph neural network to obtain a correlation dynamic graph, the method further includes: The classifier is trained using local network data and local behavior data to obtain a local classification model and the local model parameters corresponding to the local classification model. Send local model parameters to the central server so that the central server can calculate global model parameters based on the sample size of each community node and the local model parameters of each community node and then feed them back. The graph neural network is initialized based on the global model parameters to obtain the target graph neural network.

3. The method as described in claim 1, characterized in that, Following the steps of determining the risk correlation coefficient based on the dynamic risk map, and determining the security risk assessment value of the target community based on the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value, the method further includes: When the security risk assessment value of the target community exceeds a preset threshold, the security risk assessment value is mapped to the dynamic risk map, and the risk candidate area of ​​the target community is determined based on the mapping result; The associated nodes of the risk candidate region are determined based on the risk candidate region and the dynamic risk map; Community early warning information is generated based on the risk candidate areas and the associated nodes, and the community early warning information is pushed out.

4. A security risk assessment device for public networks and personnel behavior, characterized in that, The security risk assessment device for public networks and personnel behavior includes: The module is used to perform multimodal data fusion on public network data and community personnel behavior data to construct a community security map; The analysis module is used to perform spatiotemporal correlation analysis on the community security map through a target graph neural network to obtain a correlation dynamic map; The generation module is used to perform spatiotemporal feature fusion on the correlation dynamic map through a spatiotemporal graph convolutional network to generate a dynamic risk map; The assessment module is used to conduct a two-way risk assessment using the two-way risk assessment model and the dynamic risk map, and to determine the network risk assessment value and the behavioral risk assessment value. The processing module is used to determine the risk correlation coefficient based on the dynamic risk map, and to determine the security risk assessment value of the target community based on the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value. The construction module is further configured to extract features from public network data and behavioral data of community personnel, respectively, to obtain network data features corresponding to the public network data and behavioral data features corresponding to the behavioral data; define a graph structure based on entity and relationship information of the target community to determine the community graph structure; apply an attention mechanism to weight the network data features and behavioral data features to obtain weighted network data features and weighted behavioral data features; map the weighted network data features and weighted behavioral data features to a preset graph embedding space to obtain the corresponding graph embedding representation; and perform multimodal data fusion based on the community graph structure and the graph embedding representation to construct a community security graph containing network nodes and behavioral nodes, wherein the network nodes represent entities in the community public network, and the behavioral nodes represent residents and events; The generation module is further configured to: generate a spatial adjacency matrix based on the node relationship data corresponding to the relational dynamic graph; generate a spatiotemporal feature matrix based on the relational dynamic graph, the public network data, and the personnel behavior data; extract spatial features from the spatiotemporal feature matrix through the convolutional layer of the spatiotemporal graph convolutional network to obtain a spatial feature map; perform neighborhood aggregation on the spatial feature map based on the spatial adjacency matrix to obtain an aggregated spatial feature map; input the aggregated spatial feature map into the temporal convolutional layer of the spatiotemporal graph convolutional network and extract temporal features based on the time dimension information to obtain a spatiotemporal fusion feature map; perform risk scoring on the nodes of the relational dynamic graph based on the spatiotemporal fusion feature map to generate a node risk scoring matrix; and perform visualization processing on the relational dynamic graph based on the node risk scoring matrix to generate a dynamic risk graph containing risk distribution information. The evaluation module is further configured to: calculate the network risk weight of each node based on the edge relation density and the importance of node attributes in the dynamic risk graph; determine the fuzzy membership degree of each node using fuzzy set theory based on the network risk weight and historical risk data, where the fuzzy membership degree represents the probability that a node belongs to different risk levels; construct a network risk assessment model based on the network risk weight and fuzzy membership degree of each node; determine the network risk assessment value of each node in the dynamic risk graph using the network risk assessment model; determine the network risk assessment value of the community public network based on the network risk assessment value of each node; extract behavioral feature sequences based on the historical behavioral data of behavioral nodes in the dynamic risk graph; and perform spatiotemporal feature analysis on the behavioral feature sequences. The process involves analyzing and obtaining the spatiotemporal feature vectors of behavioral nodes. Based on the spatiotemporal feature vectors of behavioral nodes in the dynamic risk map and the spatiotemporal features of the entities corresponding to the dynamic risk map, cross-modal feature fusion is performed to obtain the fused behavioral feature vectors. A support vector machine algorithm is used to construct a bidirectional risk assessment model based on the fused behavioral feature vectors and the cross-modal association information corresponding to the dynamic risk map. The bidirectional risk assessment model is used to determine the preliminary risk assessment values ​​of behavioral nodes in the dynamic risk map. Based on the preliminary risk assessment values ​​of the behavioral nodes and the mutual influence relationships between behavioral nodes in the dynamic risk map, risk transmission analysis is performed to obtain adjusted behavioral risk assessment values. Finally, based on the adjusted behavioral risk assessment values, the behavioral risk assessment values ​​of community personnel are determined. The processing module is further configured to: identify the correlation between different network nodes and behavioral nodes based on the correlation path information in the dynamic risk map; quantify the correlation between different network nodes and behavioral nodes using a spatiotemporal analysis algorithm to obtain a correlation strength index; calculate the risk correlation coefficient using a machine learning algorithm based on the correlation strength index and the spatiotemporal feature information of the dynamic risk map; and determine the target dynamic weight by calculating the weights based on the network risk assessment value and the behavioral risk assessment value, wherein the calculation formula for the target dynamic weight is as follows; ; in, For the target dynamic weight, , These are the network risk assessment value and the behavioral risk assessment value, respectively. It is a very small positive number; The risk value is calculated based on the target dynamic weight, the risk correlation coefficient, the network risk assessment value, and the behavioral risk assessment value to determine the security risk assessment value of the target community.

Citation Information

Patent Citations

  • Coal mine fire and gas disaster multi-modal knowledge base construction and optimization method

    CN119322857A

  • Interference resource planning method based on knowledge graph and space-time diagram convolutional neural network, medium and equipment

    CN120106199A