Multi-access-control lightweight anomaly detection method, system and device based on edge calculation
By using a lightweight anomaly detection method for multi-access control systems based on edge computing, real-time feature fusion and lightweight model detection of multimodal sensor data are achieved. This solves the problem of high false alarm rate in traditional access control systems in multi-dimensional information fusion and cross-modal data collaborative verification, and improves the real-time response capability and security of access control systems.
Patent Information
- Application Number
- CN202511578230.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-31
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2045-10-31
AI Technical Summary
Traditional access control systems suffer from high false alarm rates in multi-dimensional information fusion and cross-modal data collaborative verification, especially in complex anomaly scenarios, making them difficult to effectively identify and resulting in insufficient security protection capabilities.
A lightweight anomaly detection method for multi-access control based on edge computing is adopted. Real-time detection is achieved through feature fusion of multimodal sensor data and a lightweight edge-side model. By collecting multimodal sensor data, feature extraction and fusion are performed, and a lightweight neural network is used for real-time anomaly detection. Collaborative analysis and global response optimization are carried out at regional edge nodes, and incremental update packages are generated for model optimization.
It significantly reduces the response latency of traditional cloud-based centralized processing, reduces bandwidth resource consumption, improves detection accuracy and attack robustness, reduces operation and maintenance costs, extends equipment lifespan, and realizes a closed-loop mechanism from risk perception to collaborative defense.
Smart Images

Figure CN121170933A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the technical field of access control, and in particular to a lightweight anomaly detection method, system and device for multi-access control based on edge computing. Background Technology
[0002] With the deep integration of IoT technology and edge computing, modern smart parks, transportation hubs, and other scenarios place higher demands on the security capabilities of access control systems, requiring multi-dimensional perception, real-time response, and dynamic linkage. Current access control anomaly detection technologies face significant technical bottlenecks in practical deployments: traditional systems often rely on isolated judgments using single-modal sensors, making it difficult to effectively integrate multi-dimensional information such as biometrics, behavioral trajectories, and stress distribution. Especially in complex anomaly scenarios such as tailgating and unauthorized access, the lack of cross-modal data collaborative verification mechanisms leads to excessively high false alarm rates. Summary of the Invention
[0003] The main objective of this invention is to provide a lightweight anomaly detection method, system, and device for multi-access control based on edge computing, which can significantly reduce the model iteration cycle while maintaining detection accuracy, and overcome the high bandwidth consumption of the traditional full update mode.
[0004] To achieve the above objectives, this invention provides a lightweight anomaly detection method for multi-access control systems based on edge computing, comprising: Acquire multimodal sensing data from the access control terminal, and extract features based on the multimodal sensing data to obtain fused feature information; Based on the anomaly detection model of the access control terminal, real-time anomaly detection is performed on the fused feature information to obtain access control anomaly status information, which is then uploaded to the regional edge node. Based on the regional edge nodes, multiple access control abnormal status information are collaboratively analyzed to obtain multiple regional abnormal information; Global anomaly statistics are performed on the anomaly information of multiple regions to obtain global collaborative response information. The global collaborative response information is then distributed to each access control terminal through the region edge node to update the terminal response, resulting in an optimized and updated anomaly detection model.
[0005] Furthermore, the step of acquiring multimodal sensing data from the access control terminal and performing feature extraction based on the multimodal sensing data to obtain fused feature information includes: Data stream identification is performed on the multimodal sensing data to obtain video frame data, infrared sensing data, RFID data, and pressure distribution data; Target tracking and detection are performed on the video frame data to obtain personnel movement trajectory data; Based on the personnel movement trajectory data, personnel behavior characteristics are analyzed to obtain a behavior characteristic sequence; The infrared sensing data is decomposed into multiple scales to obtain a thermal signal feature sequence; The identity information is verified based on the RFID data to obtain identity feature data; Dynamic feature extraction is performed on the pressure distribution data to obtain a pressure feature sequence; Correlation analysis is performed on the behavioral feature sequence, thermal signal feature sequence, and pressure feature sequence to obtain multimodal combination information; The multimodal combination information and the identity feature data are subjected to hierarchical feature fusion to obtain the fused feature information.
[0006] Furthermore, the anomaly detection model based on the access control terminal performs real-time anomaly detection on the fused feature information to obtain access control anomaly status information, and uploads it to the regional edge node, including: Based on the feature layer of the anomaly detection model, the fused feature information is subjected to feature layering processing to obtain multi-level feature data; The multi-level feature data is input into the anomaly detection layer of the anomaly detection model for anomaly analysis to obtain a comprehensive anomaly probability value. The comprehensive anomaly probability value is input into the optimization layer of the anomaly detection model for anomaly classification and false alarm filtering to obtain anomaly type information; The comprehensive anomaly probability value and the anomaly type information are compressed, encoded, and packaged to obtain the access control anomaly status information; The access control abnormal status information is encrypted and uploaded to the edge node of the region.
[0007] Further, the step of inputting the multi-level feature data into the anomaly detection layer of the anomaly detection model for anomaly analysis to obtain a comprehensive anomaly probability value includes: The multi-level feature data is decomposed to obtain bottom-level behavioral data, middle-level state data, and high-level semantic data. The anomaly detection layer's pattern recognition sublayer performs abnormal behavior pattern matching on the underlying behavior data to obtain an abnormal behavior probability value. The state evaluation sublayer of the anomaly detection layer performs state transition analysis and multidimensional state quantification on the middle layer state data to obtain the state anomaly probability value. The decision sublayer of the anomaly detection layer performs multi-level semantic association classification on the high-level semantic data to obtain semantic anomaly probability values. The comprehensive anomaly probability value is obtained by multi-dimensionally fusing the behavioral anomaly probability value, the state anomaly probability value, and the semantic anomaly probability value.
[0008] Furthermore, the step of collaboratively analyzing multiple access control anomaly status information based on the regional edge nodes to obtain multiple regional anomaly information, and uploading the regional anomaly information to the cloud server, includes: The multiple access control anomaly status information received by the edge nodes of the region are summarized and organized to obtain a region anomaly dataset; Based on the regional anomaly dataset, multiple access control terminals are collaboratively associated regionally to obtain regional association information; An anomaly severity classification assessment is performed on the aforementioned regional association information to obtain preliminary anomaly level data; Based on the preliminary anomaly level data, the regional anomaly level of the edge nodes of the region is assessed to obtain the regional anomaly information.
[0009] Further, the step of performing global anomaly statistics on multiple regional anomaly information to obtain global collaborative response information, and distributing the global collaborative response information to each access control terminal through the regional edge node for terminal response update, to obtain an optimized and updated anomaly detection model, includes: The abnormal information from multiple regions is grouped and classified to obtain the regional abnormality distribution structure; Propagation path analysis is performed on the abnormal distribution structure of the region to obtain the inter-regional abnormal diffusion probability network; Anomaly chain evaluation is performed based on the inter-regional anomaly propagation probability network to obtain global collaborative response information; Based on the global collaborative response information, node anomaly handling is performed on multiple regional edge nodes to construct a node collaborative task; The regional scheduling and linkage optimization of the node collaborative tasks is performed to obtain regional collaborative scheduling instructions; The regional collaborative scheduling instructions are deployed in a hierarchical manner to obtain gradient response parameters; The anomaly detection model is optimized and updated based on the gradient response parameters and the regional collaborative scheduling instructions to obtain the optimized and updated anomaly detection model.
[0010] Furthermore, the step of constructing a node collaboration task by performing node anomaly handling on multiple regional edge nodes based on the global collaborative response information includes: Based on the global collaborative response information, the anomaly degree of multiple edge nodes in the region is assessed to obtain node anomaly distribution data; Based on the abnormal node distribution data, spatial location association is performed on multiple edge nodes of the region to obtain node location information; Based on the node location information, node tasks are allocated to the global collaborative response information to obtain a resource allocation scheme; Based on the resource allocation scheme, limit judgments are made on the edge nodes of the region to obtain the task execution range order; Work is assigned to the edge nodes of the region according to the order of task execution scope to obtain the node collaborative tasks.
[0011] This invention also provides a lightweight anomaly detection system for multi-access control systems based on edge computing, applied to any one of the aforementioned lightweight anomaly detection methods for multi-access control systems based on edge computing, comprising: The acquisition module is used to acquire multimodal sensing data from the access control terminal and perform feature extraction based on the multimodal sensing data to obtain fused feature information. The analysis module is used to perform real-time anomaly detection on the fused feature information based on the anomaly detection model of the access control terminal, obtain access control anomaly status information, and upload it to the regional edge node; The association module is used to perform collaborative analysis on multiple access control abnormal status information based on the regional edge nodes to obtain multiple regional abnormal information; The processing module is used to perform global anomaly statistics on multiple regional anomaly information to obtain global collaborative response information, and distribute the global collaborative response information to each access control terminal through the regional edge node to update the terminal response and obtain an optimized and updated anomaly detection model.
[0012] The present invention also provides a lightweight anomaly detection device for multi-access control based on edge computing, comprising: Memory, used to store programs; A processor is configured to execute the program to implement the various steps of the lightweight anomaly detection method for multi-access control based on edge computing as described in any one of claims 1-7.
[0013] The lightweight anomaly detection method, system, and device for multi-access control systems based on edge computing provided by this invention have the following beneficial effects: By fusing features from multimodal sensor data and using lightweight edge-side models for real-time inference, the response latency caused by traditional centralized cloud processing is significantly reduced. Combined with the correlation of regional edge nodes, cross-access control anomaly propagation path prediction is achieved, effectively solving the false alarm and missed alarm problems caused by the limitations of single-point detection perspectives. Differential update packets generated using incremental learning algorithms are rapidly transmitted back for deployment via encrypted channels, significantly compressing the model iteration cycle while maintaining detection accuracy and overcoming the high bandwidth consumption of traditional full-update modes. Based on the access control device knowledge-sharing network, new access nodes can inherit the system's existing detection capabilities, reducing the waste of computing power caused by repeated training. Furthermore, an integrated triple protection system of data verification, transmission encryption, and anomaly circuit breaking ensures the security of biometric data while dynamically optimizing the detection model, forming a closed-loop mechanism from risk perception to collaborative defense. This systematically improves the real-time response capability and attack robustness of the access control system, reducing maintenance costs while extending the effective lifespan of the equipment. Attached Figure Description
[0014] Figure 1 This is a flowchart of a lightweight anomaly detection method for multi-access control systems based on edge computing, provided for this invention. Figure 2 This is a structural diagram of a lightweight anomaly detection system for multi-access control based on edge computing provided by the present invention; Figure 3 This is a structural diagram of a lightweight anomaly detection device for multi-access control based on edge computing, provided for the present invention.
[0015] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0016] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0017] The present invention will now be further described in conjunction with the accompanying drawings and specific embodiments.
[0018] Reference Figure 1 As shown, this invention provides a lightweight anomaly detection method for multi-access control systems based on edge computing, comprising: Step S1: Acquire multimodal sensor data from the access control terminal, and extract features based on the multimodal sensor data to obtain fused feature information; Step S2: Based on the anomaly detection model of the access control terminal, perform real-time anomaly detection on the fused feature information to obtain access control anomaly status information, and upload it to the regional edge node; Step S3: Perform collaborative analysis of access control anomaly status information based on regional edge nodes to obtain anomaly information for multiple regions; Step S4: Perform global anomaly statistics on anomaly information in multiple areas to obtain global collaborative response information, and distribute the global collaborative response information to each access control terminal through the regional edge node for terminal response update, thereby obtaining the optimized and updated anomaly detection model.
[0019] Based on the steps described above, the detailed process is as follows: Step S1: Multimodal sensing data acquisition and feature extraction stage. This stage utilizes a heterogeneous sensor array to achieve simultaneous acquisition and structured processing of multidimensional sensing data. Visual sensors (such as RGB-D cameras) deployed in the access control terminal capture raw video streams of facial features, body contours, and behavioral trajectories. Simultaneously, a pressure sensor array acquires time-series data of plantar pressure distribution, and an RFID reader obtains encrypted information about identity credentials. The preprocessing unit employs a spatiotemporal alignment algorithm to perform timestamp calibration and spatial coordinate mapping on the multi-source data, eliminating observation biases caused by differences in sensor physical locations. The feature extraction engine designs dedicated processing channels for different modalities: visual data is processed using a lightweight convolutional network (such as the GhostNet architecture) to extract 128-dimensional facial feature vectors and motion trajectory encoding; pressure data undergoes wavelet transform to extract pressure distribution features within the gait cycle; and RFID data is encrypted and decrypted asymmetrically before being associated with a personnel access database. Multimodal features are fused in the embedding space to construct a multidimensional feature vector containing identity, behavior, and environmental state. Cross-modal information complementarity is achieved through feature-level fusion strategies (such as attention weighting mechanisms), providing robust feature input for subsequent detection models.
[0020] Step S2: Real-time anomaly detection stage of the access control terminal employs a lightweight neural network model optimized for edge computing to achieve millisecond-level inference. The detection model deployed on the terminal device is based on the MobileNetV3 architecture, with channel pruning and quantization compression, and the model parameter size is controlled within 1.5MB to adapt to the constraints of embedded hardware resources. After the input multi-dimensional fused feature vector is forward-propagated through the model, the output anomaly probability value and classification result (such as tailgating intrusion, exceeding permission limits, etc.) are output. The model inference process uses operator fusion technology to optimize the computation graph and utilizes hardware acceleration units (such as NPU) to achieve parallel computing, with the time for a single inference controlled within 80ms. After the detection result is encrypted and signed through a Trusted Execution Environment (TEE), the feature summary of the abnormal event (including spatiotemporal stamp, anomaly type, and confidence level) is uploaded to the regional edge node. Non-abnormal data generates structured logs locally, which are temporarily stored through a circular buffer and periodically synchronized to the regional node. The terminal device has a built-in self-supervised fine-tuning module that dynamically adjusts the model bias term parameters based on the local data distribution to achieve a limited degree of personalized adaptation.
[0021] Step S3: In the regional collaborative analysis phase, edge nodes construct anomaly propagation maps across access control systems and implement dynamic risk assessment. After receiving anomaly summary data from all access control terminals within its jurisdiction, the regional edge server constructs a topological relationship model between access control nodes using a spatiotemporal correlation engine. A graph neural network (GNN) is used to model the propagation path of abnormal events, analyzing the diffusion patterns of abnormal behavior in physical space (such as the temporal correlation of anomaly triggering in continuous access control systems). The risk level assessment module integrates an LSTM temporal prediction unit and an attention mechanism to calculate the regional anomaly index: based on a risk baseline trained on historical data and the spatiotemporal density and type weights of real-time abnormal events, a three-level risk label (low, medium, and high) is jointly derived, outputting a risk label. For high-risk events, a regional linkage protocol is triggered, sending enhanced detection commands (such as increasing the frame rate sampling of cameras or the verification frequency of RFID) to adjacent access control terminals. The collaborative analysis results are fed back to each access control terminal through a lightweight encrypted channel, driving the local model to adjust the detection sensitivity threshold.
[0022] Step S4: Global Anomaly Response and Model Evolution Stage. The cloud service center enables cross-regional collaboration and continuous optimization of the detection model. The cloud aggregates anomaly statistical features uploaded by edge nodes in each region and uses a distributed stream processing framework (such as Apache Flink) to mine global anomaly patterns and identify complex threats such as cross-regional collaborative attacks. The model evolution engine employs a federated learning framework, performing distributed training based on feature summary data from each region to generate incremental model update packages (Δ parameter sets). The update packages use differential privacy mechanisms to add noise to protect data privacy and employ model watermarking technology to ensure transmission integrity. After receiving the update packages, regional edge nodes use knowledge distillation technology to transfer knowledge from the global model to their local detection models, while retaining terminal-specific parameters to balance generalization and specificity requirements. Terminal devices automatically perform hot model updates during idle periods, using A / B testing to verify the performance metrics of the new model and ensure that the update process does not affect the continuity of real-time detection. The iteratively optimized detection model forms a closed-loop learning chain of "terminal fine-tuning - regional collaboration - global evolution," continuously improving its adaptability to new anomaly patterns.
[0023] This invention provides a lightweight anomaly detection method for multi-access control systems based on edge computing. By fusing features from multimodal sensor data and real-time inference using a lightweight edge-side model, it significantly reduces response latency caused by traditional centralized cloud processing. Combined with the correlation of regional edge nodes, it enables cross-access control anomaly propagation path prediction, effectively solving the problem of false alarms and missed alarms caused by the limitations of single-point detection. Differential update packets generated using an incremental learning algorithm are rapidly transmitted back for deployment via an encrypted channel, significantly compressing the model iteration cycle while maintaining detection accuracy and overcoming the high bandwidth consumption of traditional full-update modes. Based on a knowledge-sharing network for access control devices, new access nodes can inherit the system's existing detection capabilities, reducing the waste of computing power caused by repeated training. Furthermore, an integrated triple protection system of data verification, transmission encryption, and anomaly circuit breaking ensures the security of biometric data while dynamically optimizing the detection model, forming a closed-loop mechanism from risk perception to collaborative defense. This systematically improves the real-time response capability and attack robustness of the access control system, reducing maintenance costs while extending the effective lifespan of the equipment.
[0024] In one embodiment, multimodal sensing data from an access control terminal is acquired, and feature extraction is performed based on the multimodal sensing data to obtain fused feature information, including: The heterogeneous sensors deployed in the access control terminal operate synchronously via a dedicated data acquisition protocol. Video sensors capture 1920×1080 resolution video frame data at a frame rate of at least 25fps. The infrared thermal imaging unit generates 640×480 resolution infrared sensing data at a sampling rate of 10Hz. The RFID reader acquires identification tag information in the 13.56MHz band with millisecond-level response speed. The pressure-sensitive floor mat array generates 16-channel pressure distribution data at a sampling frequency of 100Hz. The data stream identification module establishes a spatiotemporal correlation mapping table for four types of data based on a timestamp alignment mechanism. The time synchronization error between video frame data and pressure distribution data is controlled within ±3ms to ensure the timing consistency of subsequent multimodal analysis. Data verification rules require that each sensor data packet must contain a complete timestamp sequence, device identifier, and checksum. Data packets that fail the CRC check will be marked as invalid data and trigger the sensor self-test program.
[0025] The improved YOLOv5-DeepSORT joint detection framework, based on video frame data input, employs an adaptive anchor box mechanism in its target detection module, maintaining a recall rate of over 95% in densely populated scenes. The tracking algorithm incorporates an optical flow feature compensation mechanism; when a target is briefly occluded, its position is predicted using optical flow vectors from adjacent frames, ensuring trajectory continuity. In the motion trajectory data generation stage, the system records the two-dimensional planar coordinates (x, y), motion velocity v, and orientation angle θ for each target, constructing a spatiotemporal trajectory matrix. Trajectory anomaly detection rules are set: when the target's velocity change rate Δv / Δt exceeds 3 m / s² or the motion direction abruptly changes by more than 90 degrees, a trajectory anomaly marker is triggered. The final output personnel motion trajectory data includes the target ID, timestamp sequence, and motion parameter feature vectors.
[0026] The behavioral feature analysis module based on motion trajectory data employs a sliding window mechanism, extracting 12-dimensional behavioral features every 5 seconds, including average speed, acceleration variance, motion path curvature, and dwell time percentage. The feature extraction process incorporates a Dynamic Time Warping (DTW) algorithm to eliminate feature shifts caused by individual gait differences. Abnormal behavior detection rules use a dual threshold: a primary threshold filters feature values deviating from normal patterns based on the 3σ principle, while a secondary threshold detects joint anomalies across multiple features using an isolated forest algorithm. The output behavioral feature sequence is a timestamp-aligned matrix structure, with each feature vector accompanied by a confidence score for subsequent multimodal decision fusion.
[0027] After denoising preprocessing, the infrared sensing data is decomposed into multiple scales using an improved Discrete Wavelet Transform (DWT). A 5-level decomposition is performed using the db4 wavelet basis function to extract approximation and detail coefficients at each scale. The rules for constructing the thermal signal feature sequence require statistical analysis of the energy proportion of each frequency band within a 1-second time window, forming a feature vector containing the low-frequency energy ratio and high-frequency fluctuation intensity. Abnormal thermal signal detection conditions are set: when the energy value of a specific frequency band (3-5Hz) exceeds 200% of the baseline level for 10 consecutive seconds, it is determined to be an abnormal heat source. A spatial mapping relationship is established between the processed thermal signal feature sequence and the video data; the thermal signal location information is mapped to the video coordinate system through a coordinate transformation matrix.
[0028] The RFID data verification process employs a two-factor authentication mechanism. First, the tag's EPC code is read and matched against a database whitelist, with a matching threshold set to a Hamming distance ≤ 2. Tags that pass the initial verification proceed to the second-level authentication stage, using a challenge-response protocol to verify the tag's dynamic key. Identity feature data records include fields such as employee number, access level, and last access time. Anomaly detection rules are defined as follows: if the same tag is repeatedly swiped more than 3 times within 30 seconds, an anti-tailgating warning is triggered; if an unauthorized tag attempts to access the site, a security event log is generated. Verified identity feature data is associated with video targets, using the Hungarian algorithm to solve the multi-target ID matching problem.
[0029] After baseline calibration, pressure distribution data was processed using a sliding window Fourier transform (SWFT) to extract time-frequency features. The window size was set to 128 sampling points (1.28 seconds), and the step size was 64 sampling points. A dynamic feature extraction module calculated the pressure center trajectory, foot contact area change rate, and symmetry index for each channel, constructing a 9-dimensional pressure feature vector. Abnormal pressure pattern recognition conditions included: a sustained unilateral pressure percentage exceeding 75% and a pressure center drift velocity exceeding 0.2 m / s. The pressure feature sequence was spatiotemporally aligned with video behavioral features, and a dynamic time warping algorithm was used to eliminate phase shifts caused by step frequency differences.
[0030] The feature fusion engine receives behavioral feature sequences, heat signal feature sequences, and stress feature sequences, and employs a multi-head attention mechanism to achieve dynamic weighting of cross-modal features. The correlation analysis module measures the consistency of feature distribution across modalities based on KL divergence. When the mutual information between features is detected to be below a preset conflict threshold, a credibility compensation mechanism is activated: exponentially decaying weights are applied to low-correlation features, while simultaneously enhancing the feature contribution of high-credibility modalities. The hierarchical fusion architecture comprises a three-level processing flow: the initial fusion stage concatenates the three sets of feature vectors along the channel dimension to generate a 256-dimensional combined vector containing spatiotemporal context information; the intermediate fusion stage parses the temporal dependencies of feature sequences through bidirectional gated recurrent units, capturing the dynamic pattern evolution across windows; the final fusion stage introduces the permission level parameter of identity feature data, employing a permission-sensitive weighted fusion strategy—dynamically adjusting the influence of identity features in decision-making based on the user's permission level, with the weight corresponding to higher permission levels exhibiting a non-linear growth trend to ensure the accuracy of detecting abnormal behavior of privileged personnel. After the fusion process is completed, the fused feature information is output, including the multimodal confidence score matrix, the probability distribution of anomaly type and the three-dimensional spatial positioning coordinates. The fused feature information is encapsulated using Protobuf binary encoding to ensure structural consistency and parsing efficiency during cross-node transmission.
[0031] This embodiment effectively integrates multi-dimensional information such as visual trajectories, biometrics, and environmental signals through hierarchical feature fusion and spatiotemporal alignment mechanisms of multimodal sensor data, improving the comprehensiveness and accuracy of anomaly detection. Based on an improved target tracking algorithm and dynamic time warping technology, it maintains continuous and stable motion trajectory analysis capabilities in densely populated scenes, overcoming the shortcomings of traditional single-modal detection which is susceptible to environmental interference. An attention-weighted multimodal decision fusion strategy adaptively balances the credibility weights of each sensor channel, reducing the risk of misjudgment due to feature conflicts. Strict synchronization verification and encrypted transmission mechanisms for heterogeneous data streams ensure the integrity and privacy of sensitive biometric data throughout the entire processing flow. A hierarchical feature extraction architecture, combined with hardware acceleration optimization, enables efficient real-time analysis under conditions of limited edge computing resources, forming a complete protective closed loop from local anomaly perception to global collaborative response.
[0032] In one embodiment, an anomaly detection model based on the access control terminal performs real-time anomaly detection on the fused feature information to obtain access control anomaly status information, which is then uploaded to the regional edge node, including: The fused feature information refers to the multidimensional data collected from the access control terminal, including facial recognition confidence, card swipe record time interval, access control opening and closing frequency, and ambient temperature and humidity. The feature layer is the first part of the anomaly detection model, employing a lightweight, deeply separable convolutional network to extract features from the input data in a hierarchical manner. This network consists of three layers: a shallow feature extraction layer, a mid-level feature fusion layer, and a deep feature abstraction layer.
[0033] The shallow feature extraction layer uses 3×3 convolutional kernels to perform preliminary feature extraction on the raw data, capturing low-level spatiotemporal features, such as the instantaneous state changes of access control switches. The mid-level feature fusion layer uses dilated convolutions to expand the receptive field and combines the time-series information of access control events to extract mid-level features, such as multiple consecutive abnormal card swipes. The deep feature abstraction layer uses global average pooling to compress feature dimensions and generate high-level semantic features, such as long-term abnormal behavioral patterns.
[0034] The output of feature layer processing is multi-level feature data, containing feature vectors with different levels of abstraction. Preset rules include: a fixed convolution kernel stride of 1 for shallow feature extraction to ensure temporal continuity; dilated convolutions with a dilation rate of 2 for mid-level feature fusion to avoid information loss; and pooling windows in deep feature abstraction layers with the same size as the input feature map to ensure global information preservation.
[0035] The anomaly detection layer employs a multi-head anomaly scoring module based on an attention mechanism. This module consists of three parallel sub-networks, processing shallow, mid-level, and deep feature data respectively. Each sub-network contains a self-attention unit and a fully connected layer. The self-attention unit calculates the correlation weights within the features, and the fully connected layer outputs the anomaly probability score for each level.
[0036] Shallow feature data uses self-attention units to calculate anomaly weights in the time dimension, such as the degree of anomaly in frequent card-swiping behavior within a short period. Mid-level feature data uses self-attention units to analyze dependencies between feature channels, such as the correlation between facial recognition failure and abnormal temperature increases. Deep feature data uses self-attention units to focus on long-term pattern deviations, such as access control triggering during non-working hours for several consecutive days.
[0037] The outputs of the three sub-networks are weighted and fused to generate a comprehensive anomaly probability value. The weights are determined by optimizing the historical access control data during the training process. Preset conditions include: the weight of the anomaly score of shallow features does not exceed 0.3 to prevent interference from instantaneous noise; the weights of the middle and deep features are dynamically adjusted according to the type of access control terminal (e.g., giving higher weights to deep features in high-security areas).
[0038] The optimization layer comprises a two-tiered processing mechanism: a threshold classifier and a false alarm filtering rule base. The threshold classifier dynamically adjusts the anomaly detection threshold based on the access control scenario; for example, the threshold for office areas is set to 0.7, and the threshold for data centers is set to 0.5. When the overall anomaly probability value exceeds the threshold, a primary anomaly flag is triggered.
[0039] The false alarm filtering rule base loads predefined scenario rules, including: Time period rule: Frequent card swipes during working hours are not considered abnormal; Equipment linkage rules: Access control opening when a fire alarm is triggered is not considered an anomaly; Personnel whitelist rules: Uncommon access is automatically granted to personnel with high-level permissions.
[0040] The optimization layer outputs the final abnormal state information, including the abnormality type (such as forced entry, tailgating), abnormality level (levels 1-3), and confidence level. Preset rules require that events of abnormality level 3 must contain at least two levels of characteristic abnormality evidence.
[0041] The compression encoding module employs a combination of differential encoding and Huffman coding. The overall anomaly probability value is quantized into an 8-bit integer, and text fields in access control anomaly status information (such as anomaly type) are converted into dictionary indices. For unchanged fields in consecutive frames, only the difference is transmitted. The preset compression rate is no less than 60%, ensuring that the size of a single message is less than 1KB.
[0042] The packaged access control anomaly status information is encapsulated in TLV (Type-Length-Value) format, including a header identifier, data body, and CRC checksum. The data body fields are arranged according to priority, with information of higher anomaly level placed at the beginning of the transmission sequence.
[0043] After the access control terminal generates compressed abnormal status information, the system enters the encryption and uploading phase. The entire process uses the Chinese national cryptographic algorithm SM4 for data encryption. This algorithm operates as a block cipher, using a 128-bit key to encrypt data in blocks. The encryption module employs Counter Mode (CTR), which allows the algorithm to process data in a streaming manner, avoiding the latency issues that may arise from traditional block ciphers. Each encryption operation generates an independent 16-byte initialization vector, which is bound to the ciphertext for transmission, ensuring that the same plaintext encrypted at different times produces completely different ciphertext outputs.
[0044] Key management employs a dynamic session mechanism, uniformly coordinated by the regional edge nodes. Each edge node has a built-in key distribution service that pushes a new SM4 session key to each access control terminal every 24 hours or when a security threat is detected, via an SM2 asymmetric encryption channel. Terminal devices temporarily store the currently valid key in memory; any attempt to write the key to persistent storage triggers a security circuit breaker. When the encryption module starts, it first verifies the key's validity. If the key has expired or the decryption failure count has exceeded the limit, the terminal automatically initiates a key update request.
[0045] Data transmission relies on the MQTT protocol and establishes a communication link over a TLS 1.3 encrypted channel. Each access control terminal completes two-way certificate authentication during the initialization phase to ensure the trustworthiness of both communicating parties. Message topics adopt a three-tiered hierarchical structure: the first tier, the area ID, identifies the location of the building complex; the second tier, the terminal ID, specifies the exact access control device; and the third tier, the anomaly level, prioritizes data processing. This design enables the message broker at the edge node to implement differentiated routing based on the topic hierarchy, with high-level anomaly information directly pushed to the real-time processing queue, while low-level data enters the buffer channel.
[0046] The message payload is structured and includes four core fields: timestamp, encrypted data, initialization vector, and key version number. The timestamp is accurate to milliseconds and conforms to the ISO 8601 standard, providing an accurate time reference for subsequent data analysis. The key version number is linked to the key management database of the edge nodes to ensure rapid matching of the correct session key during decryption. The entire data packet has a QoS level set in the MQTT protocol. Messages with an anomaly level of 3 are forced to use QoS 2 to ensure reliable transmission, while other levels dynamically adjust the QoS level according to network conditions.
[0047] A dedicated message processing cluster is deployed on the edge nodes, and the cluster nodes allocate message processing tasks using a consistent hashing algorithm. When encrypted data arrives, the processing node first extracts the key version number and retrieves the corresponding key from the distributed cache. The decryption process strictly follows the procedure of first verifying the validity of the initialization vector and then performing SM4 decryption; failure in any step will trigger an alarm. Decrypted data must undergo CRC checksum verification; data packets that fail the checksum verification will trigger a retransmission mechanism, and the terminal device will be marked as abnormal. For terminals that fail the checksum verification three times consecutively, the system automatically adds them to the isolation list and notifies security personnel to intervene and investigate.
[0048] Successfully decrypted anomaly information is injected into the stream processing engine, which adds metadata such as the processing node ID and reception time according to preset rules. The timestamp service uses a multi-node clock source synchronized with NTP to ensure consistency of time records in a distributed environment. Finally, data is partitioned and stored by region-time dimension, with high-level anomaly information written to both in-memory database and persistent storage, achieving dual guarantees of fast querying and long-term retention. The storage layer adopts a columnar data structure, optimizing the efficiency of batch queries based on time ranges and providing foundational support for subsequent aggregation analysis.
[0049] Strict traffic control strategies are implemented in the network transmission process. A single terminal device is limited to uploading a maximum of 5 abnormal messages per second; any exceeding this limit are temporarily stored in a priority queue. In the event of a network outage, the terminal device automatically switches to local caching mode, and retransmits data in descending order of abnormality level once the connection is restored. Edge nodes monitor the transmission latency of all connections. For level 3 abnormal messages with a transmission latency exceeding 200 milliseconds, or level 1-2 messages with a latency exceeding 500 milliseconds, a network quality alarm is automatically triggered, and a backup transmission channel is activated.
[0050] The entire encrypted transmission chain is protected by multiple layers of security. In addition to TLS encryption at the transport layer, application layer data is further protected by the SM4 algorithm, forming a double encryption barrier. The key management system implements full lifecycle monitoring, recording the operation fingerprint in the audit log for each key update. Edge nodes regularly perform key rotation drills to ensure that a full-domain key update can be completed within one minute in an emergency. All security events are linked to a unified threat analysis platform, which uses machine learning algorithms to identify potential coordinated attack patterns.
[0051] During the data persistence phase, the storage system adopts the write-ahead logging technique to ensure data integrity. Each exception record is attached with a digital signature to prevent illegal tampering after storage. The hot and cold data hierarchical storage strategy stores the latest data with high-frequency access in the SSD storage pool, while historical data is automatically archived to large-capacity mechanical hard disks. This architecture effectively controls the storage cost while ensuring real-time query performance. The data retention policy is set differently according to the exception level. Ordinary exception data is retained for 30 days, while exception data related to security incidents is retained permanently.
[0052] During operation, performance metrics are continuously collected, including key data such as encryption latency, transmission success rate, and decryption failure rate. These metrics are reported to the operation and maintenance center through an independent monitoring channel to form a real-time assessment of the running health status. When the exception rate of any link exceeds the threshold, the system automatically triggers the fuse mechanism to reduce the data processing load until manual intervention. All encryption transmission modules have the ability of gray-scale upgrade, and can complete the upgrade of security patches or algorithms without affecting business continuity.
[0053] In this embodiment, through the lightweight anomaly detection method for multi-door access based on edge computing, efficient and accurate door access anomaly detection and reporting can be achieved. By adopting the feature hierarchical processing mechanism, the fused feature information is decomposed into feature data at different levels, enhancing the recognition ability of instantaneous anomalies and long-term behavior pattern anomalies, and improving the comprehensiveness and accuracy of detection. The anomaly detection layer combines the multi-head attention mechanism to dynamically adjust the weights of features at each level, effectively reducing the false alarm rate while ensuring the priority response to high-threat events. The threshold classification and false alarm filtering rule library in the optimization layer further improve the reliability of anomaly determination, avoiding misjudgment caused by environmental interference or normal behavior. The compression coding module adopts differential coding and Huffman coding strategies, significantly reducing the data transmission volume, reducing the network bandwidth occupancy, and ensuring the complete transmission of key information. The encrypted upload mechanism adopts dynamic key management and lightweight national cryptography algorithms to ensure the security of door access anomaly status information during transmission and prevent data leakage or tampering. The overall solution relies on the edge computing architecture to achieve lightweight deployment of door access terminals, reduce the cloud computing pressure, meet the real-time requirements, and is suitable for the intelligent management of large-scale door access systems.
[0054] In one embodiment, the multi-level feature data is input into the anomaly detection layer of the anomaly detection model for anomaly analysis to obtain a comprehensive anomaly probability value, including: Multi-level feature data refers to a multi-level feature set formed after preliminary processing of raw data collected from the access control system. This includes bottom-level behavioral data, mid-level state data, and high-level semantic data. Bottom-level behavioral data describes the real-time operational behavior of the access control equipment, such as card swiping frequency, door opening duration, and personnel passage speed. Mid-level state data reflects the operating status of the access control system, such as device online rate, communication latency, and resource utilization. High-level semantic data describes the semantic information of the access control scenario from a higher dimension, such as the legitimacy of personnel identity, the rationality of passage time, and area access permissions.
[0055] The feature decomposition process is implemented through predefined feature extraction rules. Low-level behavioral data is extracted through time series analysis, such as counting the number of card swipes per unit time or the duration of door opening actions; mid-level state data is calculated from system logs and resource monitoring data, such as the frequency of changes in device online status or fluctuations in communication latency; high-level semantic data is combined with the access control system's access policies and personnel information database, for example, determining whether the current access behavior conforms to preset permission rules. The output of feature decomposition is a structured representation of these three types of feature data, providing input for subsequent anomaly detection.
[0056] The pattern recognition sublayer is responsible for analyzing the underlying behavioral data to detect any abnormal behavioral patterns. Abnormal behavioral patterns refer to sequences that significantly deviate from normal access control operations, such as repeated card swipes within a short period, abnormally rapid passage, or prolonged failure to trigger a door closing signal. The pattern recognition sublayer performs matching using a pre-trained lightweight behavioral model trained on historical normal behavioral data, capable of identifying common abnormal patterns.
[0057] The calculation of the abnormal behavior probability value is based on the confidence level of the matching results. For example, if the time interval of a detected card swipe is significantly lower than the historical average, a higher abnormal probability value is assigned; if the behavior sequence completely conforms to the normal pattern, the abnormal probability value is zero. The preset rules of the pattern recognition sublayer include time thresholds, frequency thresholds, and action continuity rules. For example, after a single card swipe, the door opening action must be completed within 5 seconds, otherwise it is considered abnormal. The output of the abnormal behavior probability value provides the basis for subsequent multi-dimensional fusion.
[0058] The state assessment sublayer performs state transition analysis and multidimensional state quantification on mid-level state data. State transition analysis refers to the process by which an access control system switches from one operating state to another, such as a device suddenly going offline from online, or communication latency abruptly changing from low to high. Multidimensional state quantification, on the other hand, numerically evaluates multiple dimensions of the system state (such as stability, response speed, and resource utilization).
[0059] The calculation of the anomaly probability value is based on the rationality and magnitude of the state change. For example, a rapid drop in device online rate from 100% to 50% may trigger a high anomaly probability value; fluctuations in communication latency within the historical normal range result in a lower anomaly probability value. The preset rules of the state assessment sublayer include state mutation thresholds, stability scoring rules, and resource utilization thresholds; for example, a device being offline for more than 30 seconds is considered an anomaly. The output of the state anomaly probability value reflects the health of the system's operating state.
[0060] The decision-making sub-layer processes high-level semantic data and determines the semantic rationality of access behavior through multi-level semantic association classification. Multi-level semantic association classification refers to matching access behavior with the semantic rules of the access control system at multiple levels, such as whether the person's identity is legitimate, whether the access time is within the allowed range, and whether the access area complies with the permission settings.
[0061] The semantic anomaly probability value is calculated based on the degree of violation of semantic rules. For example, unauthorized personnel attempting to enter a high-privilege area will trigger a high anomaly probability value; legitimate personnel passing through outside of working hours may generate a medium anomaly probability value. The preset rules of the decision sub-layer include permission matching rules, time window rules, and area access rules. For example, working hours on weekdays are 8:00-18:00, and access outside this time period is considered abnormal. The output of the semantic anomaly probability value provides high-level semantic support for comprehensive anomaly analysis.
[0062] The comprehensive anomaly probability value is the final anomaly score obtained by fusing behavioral anomaly probability values, state anomaly probability values, and semantic anomaly probability values. Multi-dimensional fusion employs a weighted summation or non-linear combination method, with the specific weights adjusted according to the actual needs of the access control system. For example, the behavioral anomaly probability value might account for 30%, the state anomaly probability value for 20%, and the semantic anomaly probability value for 50%.
[0063] The calculation of the overall anomaly probability value also considers the correlation between various dimensions. For example, if both the behavioral sequence and semantic correlation show anomalies, the overall anomaly probability value will be significantly higher; if only the state transition is abnormal while other dimensions are normal, the overall anomaly probability value may be lower. The preset conditions for the fusion rules include weight allocation rules, correlation enhancement rules, and threshold triggering rules; for example, an alarm is triggered if the overall anomaly probability value exceeds 70%. The output of the overall anomaly probability value provides a basis for real-time decision-making in the access control system.
[0064] The execution process begins with input of multi-level feature data, which is then decomposed into three categories of feature data. The pattern recognition sublayer outputs behavioral anomaly probability values, the state evaluation sublayer outputs state anomaly probability values, and the decision sublayer outputs semantic anomaly probability values. Finally, the multi-dimensional fusion module generates a comprehensive anomaly probability value, completing the anomaly detection process.
[0065] The probability value for behavioral anomalies ranges from 0 to 1, with higher values indicating a greater likelihood of abnormal behavior. The probability value for state anomalies reflects the degree of abnormality in the system state, with higher values indicating more severe state anomalies. The probability value for semantic anomalies indicates the degree of deviation between access behavior and semantic rules, with higher values indicating more obvious semantic violations. The final output of the comprehensive anomaly probability values is used to trigger alarms or further manual review to ensure the security and reliability of the access control system.
[0066] This embodiment decomposes multi-level feature data into low-level behavioral data, mid-level state data, and high-level semantic data, and combines this with multi-sub-layer collaborative analysis of the anomaly detection layer. This method can comprehensively cover different anomaly dimensions of the access control system, significantly improving the accuracy and reliability of detection. The pattern recognition sub-layer's real-time matching of low-level behavioral data can quickly identify abnormal behavior patterns, reduce false alarms and false negatives, and improve the real-time response capability of the access control system. The state assessment sub-layer effectively monitors the operating status of the access control equipment through state transition analysis and multi-dimensional state quantification, promptly detecting potential system faults or abnormal fluctuations, enhancing system stability and maintainability. The decision-making sub-layer, based on multi-level association classification of high-level semantic data, can accurately determine the legality of access behavior, avoiding security risks caused by violations of permissions or time rules.
[0067] In one embodiment, collaborative analysis of access control anomaly status information based on regional edge nodes is performed to obtain multiple regional anomaly information, which is then uploaded to a cloud server, including: Access control anomaly status information refers to abnormal event data detected by the access control terminal during operation, including unauthorized entry, equipment failure, network interruption, and duplicate card swipes. Each access control terminal monitors its own status in real time through local sensors and logic judgment modules. When an anomaly is detected, it generates access control anomaly status information and sends it to its corresponding area edge node. The area edge node refers to the computing device deployed at the edge of the access control system network, responsible for receiving, processing, and collaboratively analyzing data from multiple access control terminals.
[0068] Suppose an office building has 50 access control terminals deployed on different floors and at various entrances. Each terminal checks its own status every minute, and if an anomaly is detected, it immediately sends access control anomaly status information to the area edge node. For example, terminal A detects three consecutive invalid card swipe attempts, terminal B detects a door magnetic sensor malfunction, and terminal C experiences data upload failure due to network latency. This anomaly information is transmitted to the area edge node in a structured data format (such as JSON), containing fields such as anomaly type, occurrence time, and access control terminal ID.
[0069] After receiving all access control anomaly status information, the area edge node performs preliminary verification, eliminating duplicate or incorrectly formatted data to ensure the accuracy of subsequent analysis. The verified data then enters the aggregation and processing stage.
[0070] A regional anomaly dataset refers to a data set obtained by a regional edge node through structured integration of multiple access control anomaly status information received. This dataset not only contains the original anomaly information but also adds statistical features and spatiotemporal correlation features to facilitate subsequent collaborative analysis.
[0071] In this embodiment, the area edge node groups the received access control anomaly status information by time window (e.g., 10 minutes) and counts the frequency of various anomalies within each time window. For example, in the past 10 minutes, access control terminal A reported 3 invalid card swipes, access control terminal B reported 1 device malfunction, and access control terminal D reported 2 network interruptions. The area edge node organizes this data into a table and supplements it with the physical location information of the access control terminals (e.g., floor, area number).
[0072] The generation of regional anomaly datasets also involves the extraction of anomaly features. For example, if multiple access control terminals on the same floor report invalid card swipes within a short period of time, it may indicate a coordinated attack. Regional edge nodes further enrich the content of the regional anomaly dataset by calculating the spatiotemporal density (such as the number of anomalies per unit area) and type distribution (such as the proportion of device malfunctions and network anomalies) of anomaly events.
[0073] Regional correlation information refers to a mathematical matrix describing the degree of correlation between abnormal states of multiple access control terminals, used to quantify the synergy of abnormal events from different access control terminals. The rows and columns of this matrix represent the access control terminals, and the values of the matrix elements indicate the correlation strength between the abnormal states of two access control terminals.
[0074] In this embodiment, the area edge nodes calculate the anomaly correlation degree between access control terminals based on the area anomaly dataset. The calculation rules for the correlation degree include: Time proximity: If the time interval between abnormal events of two access control terminals is less than a threshold (e.g., 30 seconds), the correlation increases.
[0075] Spatial proximity: If two access control terminals are located on the same floor or in adjacent areas, the correlation increases.
[0076] Similarity of anomaly types: If two access control terminals report the same anomaly type (e.g., both are invalid card swipes), the correlation increases.
[0077] For example, if access control terminals A and B are located on the same floor and both report invalid card swipes within 10 seconds, their correlation is set to 0.8; if access control terminals C and D are located on different floors and have different anomaly types, their correlation is set to 0.1. The final generated area correlation information is a 50×50 symmetric matrix used to describe the abnormal correlation relationships between all access control terminals.
[0078] Preliminary anomaly level data refers to the anomaly level score assigned to each access control terminal or area after analyzing the regional correlation information. This score reflects the severity and risk of spread of the anomaly event.
[0079] In this embodiment, graph theory is used to analyze the regional association information of the edge nodes. Each access control terminal is treated as a node in the graph, and the association degree is used as the weight of the edge to construct an anomaly association graph. By calculating the degree centrality of a node (i.e., the sum of the weights of the edges connected to that node), the scope of the anomaly impact of each access control terminal is evaluated. For example, access control terminal A has a degree centrality of 3.5, while access control terminal B has a degree centrality of 1.2, indicating that anomalies in access control terminal A are more likely to affect other terminals.
[0080] Furthermore, the degree centrality of the region edge nodes is classified according to preset rules: Low risk (0-1): Isolated anomaly, no immediate action required.
[0081] Medium risk (1-3): Local anomalies, follow-up development needs to be monitored.
[0082] High risk (>3): Collaboration anomaly, possibly due to systemic attack or malfunction.
[0083] Access control terminal A scored 3.5, classifying it as high-risk, while access control terminal B scored 1.2, classifying it as medium-risk. These scores constitute preliminary anomaly level data.
[0084] Regional anomaly information refers to the anomaly level label assigned to an entire region (such as a floor or building) after a comprehensive assessment of the preliminary anomaly level data. This information is used to guide global decision-making by the cloud server.
[0085] In this embodiment, the area edge node counts the proportion of high-risk access control terminals within the area. If the proportion exceeds a threshold (e.g., 20%), the area anomaly level is rated as "severe"; if the proportion is between 5% and 20%, it is rated as "warning"; and if it is below 5%, it is rated as "normal". For example, if 12 out of 50 access control terminals on a certain floor are high-risk, the proportion is 24%, therefore the area anomaly information for that floor is rated as "severe".
[0086] Anomaly information in the area is ultimately uploaded to the cloud server, triggering corresponding alarms or emergency measures. For example, a "serious" level may cause the cloud server to notify security personnel to intervene or automatically close access to the relevant area.
[0087] This embodiment utilizes regional edge nodes to collaboratively analyze access control anomaly status information. It integrates anomaly data from multiple access control terminals to form a regional anomaly dataset, thereby avoiding misjudgments caused by false alarms or missed alarms from a single terminal and improving the accuracy of anomaly detection. Based on the calculation of regional correlation information, it can quantify the anomaly correlation between different access control terminals, identify potential coordinated attacks or systemic failures, and enhance the global awareness of anomaly events. Employing an anomaly severity grading assessment method, it can dynamically adjust the anomaly level of access control terminals, avoiding insufficient sensitivity or excessive alarms caused by fixed thresholds, making anomaly detection more refined. Finally, the regional anomaly information is uploaded to a cloud server, which can trigger targeted emergency responses, such as automatically locking high-risk areas or notifying security personnel to intervene, improving the real-time nature and effectiveness of security management. This solution achieves lightweight analysis through edge computing, reducing the cloud computing burden and network transmission latency, making it suitable for real-time monitoring of large-scale access control systems.
[0088] In one embodiment, global anomaly statistics are performed on anomaly information from multiple regions to obtain global collaborative response information. This global collaborative response information is then distributed to various access control terminals via regional edge nodes for terminal response updates, resulting in an optimized and updated anomaly detection model, including: Anomaly information from multiple areas originates from anomaly event data reported by various access control terminals, including indicators such as anomaly type, frequency of occurrence, and duration. Each area edge node collects data from access control terminals within its jurisdiction in real time and classifies and statistically analyzes it according to preset anomaly level classification rules (e.g., low, medium, and high levels). The anomaly level classification rules are based on thresholds trained from historical data; for example, low-level anomalies are triggered 1-2 times per hour, medium-level anomalies 3-5 times per hour, and high-level anomalies more than 5 times per hour. Area edge nodes group access control terminals of the same anomaly level together, forming an area anomaly distribution structure. This structure is stored in the form of a graph, where nodes represent access control terminals and edges represent anomaly correlations.
[0089] The output of the regional anomaly distribution structure is an anomaly distribution map, where each node is labeled with its anomaly level and the edges are labeled with their anomaly correlation strength. For example, if access control terminals A, B, and C in a certain region all report high-level anomalies and are geographically adjacent, then these nodes form a high-anomaly density cluster in the map.
[0090] Regional edge nodes upload the regional anomaly distribution structure to the central coordination node, which then analyzes the anomaly propagation paths between different regions. This propagation path analysis is based on the physical layout of access control terminals and the temporal correlation of anomaly events. For example, if a high-level anomaly in region 1 occurs earlier than an anomaly in region 2, and both regions have personnel movement records at their access control terminals, then it is determined that the anomaly may have spread from region 1 to region 2.
[0091] The anomaly propagation probability network between regions is represented as a directed graph, where nodes represent regions and edges represent anomaly propagation probabilities. The calculation of the propagation probability relies on a pre-defined propagation model, such as a Markov chain model based on historical anomaly propagation data. If the anomaly propagation probability from region 1 to region 2 is 0.7, it indicates that this path has a high risk of anomaly propagation.
[0092] The central coordination node performs anomaly chain assessment based on the anomaly propagation probability network between regions. The goal of the chain assessment is to identify potential anomaly propagation chains, such as high-probability paths from region 1 to region 2 to region 3. The assessment rules include a propagation probability threshold (e.g., ≥0.5) and anomaly level superposition effects (e.g., probability-weighted increase when higher-level anomalies propagate).
[0093] The global collaborative response information includes key anomaly propagation paths, a list of affected areas, and recommended response strategies. For example, if a high-level anomaly in region 1 is detected that may spread to regions 2 and 3, a collaborative response instruction is generated, requiring the edge nodes of these three regions to coordinate their responses.
[0094] The quantification formula for anomaly propagation is as follows: Indicates the diffusion probability of adjacent regions. Let i be the anomaly level of each region (e.g., low=1, medium=2, high=3). is the anomaly level weight coefficient (usually set to 0.2), n: the total number of regions on the path (e.g., when region 1→region 2→region 3, n=3, and the number of consecutive terms is n-1=2).
[0095] , is the product of the diffusion probabilities of all adjacent regions along the path, reflecting the "basic diffusion probability" of the entire path.
[0096] Based on the WDP calculation results, the system automatically generates global collaborative response information, including key anomaly propagation paths, a list of affected areas, and tiered response strategies. For example, when WDP ≥ 1, a coordinated response is triggered: Area 1 enhances monitoring (e.g., dual authentication), Area 2 dynamically blocks unauthorized access, and Area 3 initiates the highest level of control (e.g., closing some access control points and conducting manual verification). If WDP ≥ 1.5, the response is further escalated to an emergency plan, such as global resource scheduling or cross-regional collaborative blocking.
[0097] After receiving the global collaborative response information, the regional edge nodes construct node collaborative tasks according to the instructions. The tasks include anomaly suppression measures (such as strengthening access control verification), data collection optimization (such as increasing the data reporting frequency of anomaly areas), and resource allocation (such as allocating more computing resources to high-anomaly areas).
[0098] The generation of node collaboration tasks relies on preset task templates. For example, task templates for high-level anomalies include "real-time monitoring + dynamic interception + data encryption". Edge nodes fill in specific parameters according to the template, such as adjusting the monitoring frequency to once per second and setting the interception rules to dual authentication.
[0099] The central coordinating node performs regional scheduling and linkage optimization for node collaborative tasks. The optimization objective is to minimize the impact range of anomalies while balancing the computational load on edge nodes. Scheduling rules include priority allocation (higher anomaly levels prioritized) and resource balancing strategies (to avoid overloading individual nodes).
[0100] Regional collaborative scheduling instructions are issued in the form of a task list. For example, the instructions may be to instruct the edge nodes of region 1 to perform real-time monitoring, the edge nodes of region 2 to start dynamic interception, and the edge nodes of region 3 to perform data backup.
[0101] Regional coordinated dispatch instructions are further deployed in a hierarchical manner as gradient response parameters. Gradient response parameters classify response levels according to the anomaly level and the risk of spread. For example, Level 1 response (the highest level) is for directly affected areas, and Level 2 response is for potentially spread areas.
[0102] The deployment rules for gradient response parameters include the correspondence between response levels and resource allocation. For example, 80% of edge computing resources are allocated to the Level 1 response region, and 50% to the Level 2 response region.
[0103] Regional edge nodes adjust the parameters of their local anomaly detection models based on gradient response parameters and regional collaborative scheduling instructions. Parameter optimization is based on a feedback mechanism; for example, access control terminal data from high-anomaly areas are given higher weights, and the model focuses on these data during retraining.
[0104] The output of the optimized and updated anomaly detection model is new detection rules and thresholds. For example, the anomaly frequency threshold of the original model is adjusted from 3 times per hour to 2 times per hour to improve the sensitivity to potential anomalies.
[0105] In this embodiment, through the combination of edge computing and multi-access control collaboration mechanism, lightweight and efficient anomaly detection and response are achieved. By grouping and classifying the anomaly information of multiple regions, a regional anomaly distribution structure is formed, which can intuitively reflect the anomaly distribution characteristics and improve the accuracy and pertinence of anomaly recognition. The construction of the inter-regional anomaly diffusion probability network predicts the anomaly propagation trend based on the analysis of the propagation path, deploys prevention and control measures in advance, and effectively inhibits the anomaly diffusion. The generation of global collaborative response information integrates the anomaly data of multiple regions through chain evaluation to achieve cross-regional linkage response and prevent local anomalies from escalating into global risks. The construction of node collaborative tasks and the optimization of regional collaborative scheduling instructions ensure the reasonable allocation of edge computing resources, avoid single-point overload, and improve the overall stability of the system. The hierarchical deployment of gradient response parameters dynamically adjusts the response intensity according to the anomaly level, optimizing the consumption of computing resources while ensuring safety. The continuous optimization and update of the anomaly detection model adjust the detection parameters based on real-time feedback, enhance the adaptability of the model to different anomaly scenarios, and improve the detection accuracy and response speed.
[0106] In one embodiment, node anomaly handling construction is performed on multiple regional edge nodes according to the global collaborative response information to obtain node collaborative tasks, including: In the edge computing environment, multiple regional edge nodes (referring to the edge computing devices distributed in the access control system, responsible for local data processing and anomaly detection) collect access control status data in real time, including card swiping records, face recognition results, device heartbeat signals, etc. When an anomaly event (such as illegal intrusion, device offline, frequent incorrect authentication) is detected by a certain regional edge node, the node generates a local anomaly report and uploads it to the collaborative analysis center. The collaborative analysis center aggregates the anomaly reports of all regional edge nodes and generates global collaborative response information (comprehensive data reflecting the distribution, type, and severity of anomaly events in the entire system) in combination with historical data and preset rules (such as anomaly frequency threshold, device association rules).
[0107] The global collaborative response information includes anomaly type encoding, occurrence time, region identifier, and preliminary confidence score. Based on this information, the system evaluates the anomaly degree of multiple regional edge nodes (calculating the anomaly weight of each node based on anomaly frequency, influence range, and historical behavior patterns) and outputs node anomaly distribution data (a structured data table recording the anomaly score and ranking of each node). For example, if a certain node triggers multiple illegal intrusion alarms in a short period of time, its anomaly score is significantly higher than other nodes.
[0108] The abnormal node distribution data is further used to analyze the spatial location associations of multiple regional edge nodes (referring to determining the dependency or linkage between nodes through geographical or logical topological relationships). The system's preset rules include: physical distance thresholds (e.g., adjacent access control devices within 10 meters are considered associated nodes) and logical grouping rules (access control devices on the same floor are grouped into the same logical group). Based on these rules, node location information (a matrix or graph describing the spatial relationships between nodes) is constructed, marking which nodes need to collaboratively handle the same abnormal event.
[0109] Based on node location information, the system allocates node tasks according to global collaborative response information (dynamically assigning anomaly handling tasks to the most suitable node combination). When generating the resource allocation plan (a detailed schedule defining the task types and resource allocation for each node), the following conditions are followed: nodes with high anomaly scores are given priority for high-priority tasks; related nodes share a portion of the computational load; and resource allocation does not exceed the node's remaining computing capacity limit. For example, in densely populated anomaly areas, multiple edge nodes collaboratively perform video analysis, while in low-anomaly areas, only basic status monitoring is performed.
[0110] The resource allocation scheme is further used to perform limit judgments on edge nodes (checking whether the node's computing resources and network bandwidth meet the task requirements). The system presets hardware performance thresholds (such as CPU utilization not exceeding 80% and memory usage below 90%). If a node's resources are insufficient, its task scope is adjusted or a neighboring node is triggered to take over. The limit judgment outputs the task execution scope order (defining a list of priorities and boundary conditions for node task execution), ensuring that high-priority anomalies are handled by nodes with sufficient resources.
[0111] Work is allocated to edge nodes in the region according to the order of task execution, generating node collaborative tasks (specific instruction sets, including task type, execution time, data interaction protocol, etc.). For example, node A is responsible for real-time video analysis and sharing the results with node B, while node B executes aggregated alarms and uploads them to the cloud. Collaborative tasks are distributed through the edge computing network, and each node synchronously executes detection, communication, or resource scheduling operations according to the instructions, achieving lightweight anomaly detection (completing multi-node joint analysis with low computational overhead).
[0112] After the node collaborative task is executed, each regional edge node feeds back the processing results (such as anomaly confirmation and equipment recovery status) to the collaborative analysis center. The center updates the global collaborative response information, forming a closed-loop control. For example, if an anomaly is confirmed as a false alarm after collaborative processing, the system automatically lowers the anomaly score of the relevant nodes and optimizes the subsequent resource allocation logic.
[0113] This embodiment achieves rapid collaborative response from multiple access control systems by dynamically evaluating abnormal node distribution data, constructing node location information, generating resource allocation schemes, and determining the order of task execution. Pre-defined rules (such as anomaly scoring formulas, spatial correlation thresholds, and resource limit conditions) ensure efficient system operation in an edge computing environment while preventing overload of single nodes. The lightweight design of node collaborative tasks reduces data transmission volume, improves real-time performance, and is suitable for large-scale access control networks.
[0114] Reference Figure 2 As shown, the present invention also provides a lightweight anomaly detection system for multi-access control systems based on edge computing, applicable to any of the above-mentioned lightweight anomaly detection methods for multi-access control systems based on edge computing, comprising: The acquisition module is used to acquire multimodal sensor data from the access control terminal and perform feature extraction based on the multimodal sensor data to obtain fused feature information. The analysis module is used to perform real-time anomaly detection on the fused feature information based on the anomaly detection model of the access control terminal, obtain access control anomaly status information, and upload it to the regional edge node. The association module is used to perform collaborative analysis of access control anomaly status information based on regional edge nodes to obtain anomaly information from multiple regions. The processing module is used to perform global anomaly statistics on anomaly information from multiple areas, obtain global collaborative response information, and distribute the global collaborative response information to each access control terminal through the regional edge node for terminal response update, thereby obtaining an optimized and updated anomaly detection model.
[0115] This invention provides a lightweight anomaly detection system for multi-access control systems based on edge computing. By fusing features from multimodal sensor data and real-time inference using a lightweight edge-side model, it significantly reduces response latency caused by traditional centralized cloud processing. Combined with the correlation of regional edge nodes, it enables cross-access control anomaly propagation path prediction, effectively solving the problem of false alarms and missed alarms caused by the limitations of single-point detection. Differential update packets generated using incremental learning algorithms are rapidly transmitted back for deployment via an encrypted channel, significantly compressing the model iteration cycle while maintaining detection accuracy and overcoming the high bandwidth consumption of traditional full-update modes. Based on a knowledge-sharing network for access control devices, new access nodes can inherit the system's existing detection capabilities, reducing the waste of computing power caused by repeated training. Furthermore, an integrated triple protection system of data verification, transmission encryption, and anomaly circuit breaking ensures the security of biometric data while dynamically optimizing the detection model, forming a closed-loop mechanism from risk perception to collaborative defense. This systematically improves the real-time response capability and attack robustness of the access control system, reducing maintenance costs while extending the effective lifespan of the equipment.
[0116] Reference Figure 2As shown, the present invention also provides a lightweight anomaly detection device for multi-access control systems based on edge computing, comprising: Memory, used to store programs; A processor is used to execute programs to implement the various steps of a lightweight anomaly detection method for multi-access control based on edge computing, which includes any of the above-mentioned methods.
[0117] In this embodiment, the processor and memory can be connected via a bus or other means. The memory may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as read-only memory, flash memory, hard disk, or solid-state drive. The processor may be a general-purpose processor, such as a central processing unit, digital signal processor, application-specific integrated circuit, or one or more integrated circuits configured to implement embodiments of the present invention.
[0118] It should be noted that those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the system and each module described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0119] The above description is merely a preferred embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. An edge-computing-based multi-gateway lightweight anomaly detection method, characterized in that, The method comprises the following steps: acquiring multi-modal sensor data of an access control terminal, and performing feature extraction based on the multi-modal sensor data to obtain fusion feature information; performing real-time anomaly detection on the fusion feature information based on an anomaly detection model of the access control terminal to obtain access control anomaly state information, and uploading the access control anomaly state information to a regional edge node; performing collaborative analysis on a plurality of the access control anomaly state information based on the regional edge node to obtain a plurality of regional anomaly information; performing global anomaly statistics on a plurality of the regional anomaly information to obtain global collaborative response information, and distributing the global collaborative response information to each of the access control terminals through the regional edge node for terminal response update to obtain an updated anomaly detection model.
2. The edge computing-based multi-gateway lightweight anomaly detection method according to claim 1, characterized in that, The method comprises the following steps: performing data stream recognition on the multi-modal sensor data to obtain video frame data, infrared sensing data, RFID data, and pressure distribution data; performing target tracking detection on the video frame data to obtain personnel motion trajectory data; performing personnel behavior feature analysis according to the personnel motion trajectory data to obtain a behavior feature sequence; performing multi-scale decomposition on the infrared sensing data to obtain a thermal signal feature sequence; performing identity information verification according to the RFID data to obtain identity feature data; performing dynamic feature extraction on the pressure distribution data to obtain a pressure feature sequence; performing correlation analysis according to the behavior feature sequence, the thermal signal feature sequence, and the pressure feature sequence to obtain multi-modal combination information; performing hierarchical feature fusion on the multi-modal combination information and the identity feature data to obtain the fusion feature information. 3.The edge computing based multi-gateway lightweight anomaly detection method according to claim 1, characterized in that, The method comprises the following steps: performing feature hierarchical processing on the fusion feature information based on a feature layer of the anomaly detection model to obtain multi-level feature data; inputting the multi-level feature data into an anomaly detection layer of the anomaly detection model for anomaly analysis to obtain a comprehensive anomaly probability value; inputting the comprehensive anomaly probability value into an optimization layer of the anomaly detection model for anomaly classification and false alarm filtering to obtain anomaly type information; compressing and encoding the comprehensive anomaly probability value and the anomaly type information to pack the access control anomaly state information; encrypting and uploading the access control anomaly state information to the regional edge node.
4. The edge computing based multi-gateway lightweight anomaly detection method according to claim 3, characterized in that, The method comprises the following steps: performing feature decomposition on the multi-level feature data to obtain bottom-layer behavior data, middle-layer state data, and high-layer semantic data; performing abnormal behavior pattern matching on the bottom-layer behavior data through a pattern recognition sub-layer of the anomaly detection layer to obtain a behavior anomaly probability value; performing state transition analysis and multi-dimensional state quantization on the middle-layer state data through a state evaluation sub-layer of the anomaly detection layer to obtain a state anomaly probability value; The high-level semantic data is classified by a decision sub-layer of the anomaly detection layer to obtain a semantic anomaly probability value; The comprehensive anomaly probability value is obtained by multi-dimensional fusion according to the behavior anomaly probability value, the state anomaly probability value and the semantic anomaly probability value.
5. The edge computing based multi-gateway lightweight anomaly detection method according to claim 1, characterized in that, The regional edge node is based on the regional edge node, and the plurality of access control abnormal state information is cooperatively analyzed to obtain a plurality of regional anomaly information, and the regional anomaly information is uploaded to a cloud server, comprising: The plurality of access control abnormal state information received by the regional edge node is summarized to obtain a regional anomaly data set; The plurality of access control terminals are cooperatively associated according to the regional anomaly data set to obtain regional association information; The regional association information is evaluated by an abnormal degree classification to obtain preliminary abnormal level data; The regional edge node is evaluated according to the preliminary abnormal level data to obtain a plurality of regional anomaly information.
6. The edge computing based multi-gateway lightweight anomaly detection method according to claim 1, characterized in that, The global anomaly statistics of the plurality of regional anomaly information is obtained, and the global cooperative response information is distributed to each access control terminal through the regional edge node to update the terminal response, and the optimized updated anomaly detection model is obtained, comprising: The plurality of regional anomaly information is grouped and classified to obtain a regional anomaly distribution structure; The regional anomaly distribution structure is analyzed to obtain an inter-regional anomaly diffusion probability network; The global cooperative response information is obtained by evaluating the inter-regional anomaly diffusion probability network; The node cooperative task is obtained by constructing the node abnormal processing of the plurality of regional edge nodes according to the global cooperative response information; The regional cooperative scheduling instruction is obtained by optimizing the regional scheduling linkage of the node cooperative task; The gradient response parameter is obtained by classifying and deploying the regional cooperative scheduling instruction; The anomaly detection model is updated by optimizing the parameters according to the gradient response parameter and the regional cooperative scheduling instruction, and the optimized updated anomaly detection model is obtained.
7. The edge computing based multi-gateway lightweight anomaly detection method according to claim 6, characterized in that, The node cooperative task is obtained by constructing the node abnormal processing of the plurality of regional edge nodes according to the global cooperative response information, comprising: The node anomaly distribution data is obtained by evaluating the abnormal degree of the plurality of regional edge nodes according to the global cooperative response information; The node position information is obtained by associating the spatial position of the plurality of regional edge nodes according to the node anomaly distribution data; The resource allocation scheme is obtained by distributing the node task of the global cooperative response information according to the node position information; The task execution range order is obtained by limiting the regional edge node according to the resource allocation scheme; The node cooperative task is obtained by distributing the work of the regional edge node according to the task execution range order.
8. An edge computing-based multi-gateway lightweight anomaly detection system, characterized in that, The method is applied to the multi-access control lightweight anomaly detection method based on edge computing in any one of claims 1-7, comprising: The collection module is used for acquiring multi-modal sensor data of the access control terminal, and performing feature extraction based on the multi-modal sensor data to obtain fusion feature information; The analysis module is used for performing real-time anomaly detection on the fusion feature information based on an anomaly detection model of the access control terminal, obtaining access control anomaly state information, and uploading to a regional edge node; The correlation module is used for performing collaborative analysis on a plurality of the access control anomaly state information based on the regional edge node to obtain a plurality of regional anomaly information; The processing module is used for performing global anomaly statistics on a plurality of the regional anomaly information to obtain global collaborative response information, and distributing the global collaborative response information to each of the access control terminals through the regional edge node for terminal response update to obtain an optimized updated anomaly detection model.
9. An edge computing-based multi-gateway lightweight anomaly detection device, characterized in that, Comprise: A memory for storing a program; A processor for executing the program to implement each step of the multi-access control lightweight anomaly detection method based on edge computing according to any one of claims 1-7.
Citation Information
Patent Citations
Method and system for processing abnormity of industrial network equipment
CN112506167A
Intelligent access control management method and system based on multi-mode identification and Internet of Things technology
CN118968665A
Intelligent electric meter anomaly detection method and system based on federal differential privacy and attention mechanism
CN120670825A
An intelligent system for the joint detection of anomalies in distributed systems
DE202024105884U1
An intelligent system for detecting anomalies in IOT networks using edge computing and deep learning
DE202025102503U1