Mine abnormal event real-time identification method and system based on timing characteristics

By constructing a temporal knowledge graph to perform spatiotemporal alignment and semantic annotation of multimodal data in mines, the entity of safety element and its attribute characteristics are identified, solving the problem of multimodal data processing in mine safety monitoring systems, realizing accurate characterization and prediction of mine safety risks, and improving the level of intelligence in mine safety management and emergency response capabilities.

CN121365241BActive Publication Date: 2026-03-24BEIJING YANGGUANG JINLI TECH DEV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-23
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Existing technologies cannot comprehensively consider the spatiotemporal correlation and interactive effects between multimodal data, resulting in mine safety monitoring systems being unable to accurately grasp the overall situation and evolution of safety risks. Furthermore, risk propagation path analysis has limitations and cannot dynamically reflect changes in the strength of correlation between safety element entities.

Method used

By constructing a temporal knowledge graph, spatiotemporal alignment and semantic annotation of multimodal monitoring data are performed to identify safety element entities and their attribute characteristics, establish association mapping between entities, calculate dynamic association weights, analyze risk propagation paths, generate differentiated early warning strategies, and establish a closed-loop tracking system for early warning response.

Benefits of technology

It enables precise characterization and prediction of mine safety risks, improves the accuracy and timeliness of risk warnings, and enhances the intelligence level of mine safety management and emergency response capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121365241B_ABST
    Figure CN121365241B_ABST
Patent Text Reader

Abstract

The application provides a mine abnormal event real-time identification method and system based on time sequence characteristics, relates to the technical field of pattern recognition, and comprises the following steps: constructing a time sequence knowledge graph by performing space-time alignment and semantic labeling on multi-modal monitoring data; calculating dynamic correlation weights between entities, and analyzing risk propagation paths; predicting risk situations based on historical evolution rules; and dynamically generating a differentiated early warning strategy and establishing a closed-loop tracking system. The application can realize early identification, accurate prediction and efficient disposal of mine safety risks, and improves the mine safety management level.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to pattern recognition technology, and more particularly to a method and system for real-time identification of abnormal events in mines based on time-series features. Background Technology

[0002] As mining depths increase and production scale expands, the risks and challenges facing mine safety are becoming increasingly severe. Safety risks in the mining environment are characterized by their high degree of concealment, suddenness, and rapid spread; once a safety accident occurs, it often results in significant casualties and property damage. Currently, mine safety monitoring systems have widely deployed various sensors to collect real-time environmental parameters such as temperature, humidity, gas concentration, dust concentration, and wind speed, providing data support for safe production. Traditional mine safety monitoring mainly relies on threshold alarms, triggering an alarm when a certain indicator exceeds a preset threshold. With the development of the Internet of Things, big data, and artificial intelligence technologies, mine safety monitoring systems are gradually evolving towards intelligence, networking, and integration. Through the analysis and mining of massive amounts of monitoring data, safety hazards can be detected in a timely manner, preventing accidents from occurring.

[0003] Existing technologies primarily focus on anomaly detection using single sensors or parameters, making it difficult to comprehensively consider the spatiotemporal correlations and interactions between multimodal data. This results in an inability to accurately grasp the overall situation and evolution patterns of safety risks. Traditional methods often process various monitoring data in isolation, lacking in-depth analysis of the relationships between safety-related entities. This makes it difficult to construct a systematic knowledge structure that reflects the complex environment of mines, thus affecting the early identification of abnormal events.

[0004] Existing technologies have limitations in analyzing risk propagation paths. Most employ static risk assessment models, failing to dynamically reflect changes in the strength of correlations between security entities across different time windows. This makes it difficult to accurately characterize the propagation characteristics and evolutionary trends of risks in the spatiotemporal dimensions. Consequently, security managers struggle to anticipate the development direction and scope of potential risks, hindering their ability to implement targeted preventative measures. Summary of the Invention

[0005] This invention provides a method and system for real-time identification of abnormal events in mines based on time-series features, which can solve the problems in the prior art.

[0006] A first aspect of this invention provides a method for real-time identification of mine anomaly events based on time-series features, comprising:

[0007] Acquire multimodal monitoring data collected by distributed sensors in the mine, perform spatiotemporal alignment and semantic annotation on the multimodal monitoring data, analyze and identify safety element entities and their attribute features, and construct a temporal knowledge graph based on the safety element entities and their attribute features;

[0008] In the time-series knowledge graph, an association mapping between entities is established, and the dynamic association weight between entities under different time windows is calculated; based on the dynamic association weight, the propagation path of security risks is analyzed to obtain a set of risk propagation links;

[0009] For each link in the risk propagation link set, the risk development trend is obtained through recursive calculation, and based on the historical evolution pattern in the time series knowledge graph, the risk situation in future time steps is predicted to generate risk prediction results.

[0010] Based on the correlation between the risk prediction results and the risk propagation chain, differentiated early warning strategies are dynamically generated; at the same time, a closed-loop tracking system for early warning response is established, incorporating early warning results, handling processes, and actual effects into the decision-making basis for system optimization, and forming a continuously optimized early warning and emergency management ecosystem by deeply exploring the emergency management practices of various regions.

[0011] The multimodal monitoring data is spatiotemporally aligned and semantically labeled. Safety element entities and their attribute features are analyzed and identified. A temporal knowledge graph is constructed based on the safety element entities and their attribute features, including:

[0012] The data streams of different modes in the multimodal monitoring data are time-series calibrated according to timestamps, and the data collected from different spatial nodes are spatially registered based on the spatial location mapping relationship to obtain a unified data representation after spatiotemporal alignment.

[0013] The data items in the unified data representation are semantically parsed using a pre-trained domain knowledge base and ontology model to identify the entity type, relationship type between entities, and entity attributes corresponding to the data items. The accuracy of the annotation results is ensured through consistency verification and conflict resolution, resulting in normalized data after semantic annotation.

[0014] Security element entities are identified from the normalized data after semantic annotation, and based on the entity type, the relationship type between entities and the entity attributes, the corresponding static attribute features and dynamic behavior features are extracted for each security element entity to construct an entity-feature mapping set.

[0015] An initial temporal knowledge graph is constructed based on the security element entities and their corresponding entity-feature mapping sets. The topological integrity of the initial temporal knowledge graph is verified by using the relationship types between entities, isolated nodes and broken paths in the graph are identified, and missing entity relationships are filled in by combining relationship reasoning rules, thus forming a complete temporal knowledge graph.

[0016] An initial temporal knowledge graph is constructed based on the security element entities and their corresponding entity-feature mapping sets. The topological integrity of the initial temporal knowledge graph is verified using the entity relationship types, identifying isolated nodes and broken paths in the graph, including:

[0017] The security element entities are treated as a set of nodes, and each node is assigned an attribute vector according to the entity-feature mapping set; a set of directed edges between nodes is constructed based on the relationship types between entities, and a relationship strength metric and temporal evolution constraints are attached to each directed edge; the set of nodes, the attribute vectors, and the set of directed edges are combined to form the topology of the initial temporal knowledge graph.

[0018] The initial temporal knowledge graph is subjected to topological integrity verification. The in-degree and out-degree of each node are calculated by traversing the set of directed edges. Nodes with both in-degree and out-degree of zero are identified as isolated nodes. Broken paths caused by the lack of necessary intermediate nodes are detected by path connectivity analysis.

[0019] For isolated nodes identified in the topology integrity verification, potential associations are queried in the domain ontology model based on the entity relationship type, and association edges are added to the isolated nodes according to the query results to eliminate the isolated state;

[0020] For the broken paths identified in the topological integrity verification, the semantic correlation between the starting point and the ending point of the path is analyzed, and the missing intermediate entities and their correlations are inferred using relational reasoning rules. The broken paths are then completed in the initial temporal knowledge graph.

[0021] In the time-series knowledge graph, an association mapping between entities is established, and the dynamic association weights between entities under different time windows are calculated. Based on the dynamic association weights, the propagation path of security risks is analyzed, and a set of risk propagation links is obtained, including:

[0022] Entity nodes and their edge relationships are extracted from the temporal knowledge graph. An association mapping matrix between entities is established based on semantic type and directionality. For different time windows, the dynamic association weight matrix between entities is calculated through a time-aware graph attention mechanism based on the state change sequence of entities within the time window and the causal dependency between entities.

[0023] Based on the dynamic association weight matrix, the corresponding entity pairs in the association mapping matrix are weighted and assigned weights, and the entity nodes, the edge relationships and their weights are combined to form a weighted graph structure associated with a time window.

[0024] In the weighted graph structure, the identified risk source node is selected as the starting point. Edges with weights exceeding the preset propagation threshold are filtered based on dynamic association weights. The propagation trajectory of risk from the source node to the downstream node is tracked by a path search strategy that combines breadth-first traversal and depth-first traversal. Multiple paths involved in the propagation trajectory are aggregated and deduplicated to finally obtain a set of risk propagation links.

[0025] A path search strategy combining breadth-first search and depth-first search is used to track the propagation trajectory of risk from the source node to downstream nodes, and the multiple paths involved in the propagation trajectory are aggregated and deduplicated, including:

[0026] A path search strategy combining breadth-first traversal and depth-first traversal is used to track the propagation trajectory of risk from the source node to downstream nodes. The breadth-first traversal is based on a node queue, which visits all adjacent nodes of each level in turn to construct the propagation range of the risk at the current level and obtain the node set of each level. The depth-first traversal is based on a node stack, which prioritizes exploring the vertical extension direction of a single path along the weighted edge until the propagation termination condition is reached, and obtains the node sequence of each extension path.

[0027] Based on the node sequence, in each iteration, the breadth-first traversal is first executed to determine the hierarchical propagation range, the depth-first traversal is executed to explore the extension path of each node, the propagation trajectory is integrated, and multiple paths involved in the propagation trajectory are aggregated and deduplicated.

[0028] For each link in the aforementioned risk propagation link set, the risk development trend is calculated recursively, and based on the historical evolution patterns in the aforementioned time-series knowledge graph, the risk situation at future time steps is predicted, generating risk prediction results including:

[0029] For each link in the risk propagation link set, a state transition matrix is ​​constructed based on the weight relationship between adjacent nodes in the link, and a state transition probability distribution is trained by combining the historical state sequence of the nodes. The development trend value and trend confidence of the risk on the corresponding link are obtained through the recursive operation of chain conditional probability. For each node, its sensitivity coefficient in the link propagation process is calculated, and the development trend value is optimized based on the sensitivity coefficient to obtain an optimized trend value that takes into account the degree of influence of the node.

[0030] In the time-series knowledge graph, identify historical propagation paths and their evolutionary characteristics that are similar to the corresponding links, calculate the structural similarity and state similarity between the current link and the historical paths, and determine the evolutionary contribution of each historical path based on the structural similarity and the state similarity; construct the evolutionary rules of historical paths based on the evolutionary contributions; associate and integrate the optimization trend value with the evolutionary rules, and combine the trend confidence to predict the risk situation in future time steps, generating risk prediction results.

[0031] Based on the correlation between the risk prediction results and the risk propagation chain, differentiated early warning strategies are dynamically generated; simultaneously, a closed-loop tracking system for early warning response is established, incorporating early warning results, handling processes, and actual effects into the decision-making basis for system optimization, and deeply exploring the emergency management practices of various regions, including:

[0032] Based on the correlation between the risk prediction results and the risk propagation links, early warning response rules are determined according to the risk level and propagation range of different links. Multi-level risk thresholds are set, and the risk thresholds are dynamically adjusted based on the spatiotemporal evolution characteristics of risk propagation to generate differentiated early warning strategies.

[0033] The differentiated early warning strategy generates early warning information according to the early warning response rules, records the emergency response process and actual response effect of each early warning as optimization data, and performs time-series matching between the early warning information and the optimization data; calculates the early warning accuracy and response effectiveness based on the results of the time-series matching, and makes targeted improvements to the early warning response rules; incorporates the early warning results, response process and actual effect in the optimization data into the decision-making basis for system optimization, and deeply mines the emergency management practice experience of various regions.

[0034] A second aspect of the present invention provides a real-time identification system for mine anomaly events based on time-series features, comprising:

[0035] The acquisition unit is used to acquire multimodal monitoring data collected by distributed sensors in the mine, perform spatiotemporal alignment and semantic annotation on the multimodal monitoring data, analyze and identify safety element entities and their attribute features, and construct a temporal knowledge graph based on the safety element entities and their attribute features.

[0036] The analysis unit is used to establish the association mapping between entities in the time-series knowledge graph and calculate the dynamic association weight between entities under different time windows; based on the dynamic association weight, the propagation path of security risks is analyzed to obtain a set of risk propagation links;

[0037] The prediction unit is used to calculate the risk development trend for each link in the risk propagation link set through recursive calculation, and predict the risk situation in future time steps based on the historical evolution law in the time series knowledge graph, and generate risk prediction results.

[0038] The optimization unit is used to dynamically generate differentiated early warning strategies based on the correlation between the risk prediction results and the risk propagation chain; at the same time, it establishes a closed-loop tracking system for early warning response, incorporates early warning results, handling process and actual effect into the decision-making basis for system optimization, and forms a continuously optimized early warning and emergency management ecosystem by deeply mining the emergency management practice experience of various regions.

[0039] A third aspect of the present invention provides an electronic device, comprising:

[0040] processor;

[0041] Memory used to store processor-executable instructions;

[0042] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.

[0043] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.

[0044] The beneficial effects of this application are as follows:

[0045] By constructing a temporal knowledge graph, the multimodal monitoring data of the mine is spatiotemporally aligned and semantically labeled, which enables the effective identification and structured expression of safety element entities and their attribute features, and solves the problem that traditional methods are difficult to handle multi-source heterogeneous data.

[0046] The innovative establishment of a dynamic correlation weighting mechanism between entities can accurately characterize the dynamic characteristics of safety risk propagation under different time windows, which is more in line with the actual situation of mine risk evolution than the traditional static model.

[0047] The recursive calculation method based on the risk propagation link set, combined with historical evolution patterns for prediction, significantly improves the accuracy and timeliness of risk warning and avoids the shortcomings of traditional single-point monitoring in failing to detect complex risk associations.

[0048] A differentiated early warning strategy generation mechanism and a closed-loop tracking system were created, organically combining early warning results, handling processes, and actual effects, forming a continuously self-optimizing early warning and emergency management ecosystem, which effectively improved the intelligence level of mine safety management and emergency response capabilities. Attached Figure Description

[0049] Figure 1 This is a flowchart illustrating the real-time identification method for mine anomaly events based on time-series features according to an embodiment of the present invention.

[0050] Figure 2 This is a flowchart of a risk propagation situation prediction model based on historical states, as described in an embodiment of the present invention. Detailed Implementation

[0051] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0052] The technical solution of the present invention will be described in detail below with reference to specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0053] Figure 1 This is a flowchart illustrating the real-time identification method for mine anomaly events based on time-series features according to an embodiment of the present invention. Figure 1 As shown, the method includes:

[0054] Acquire multimodal monitoring data collected by distributed sensors in the mine, perform spatiotemporal alignment and semantic annotation on the multimodal monitoring data, analyze and identify safety element entities and their attribute features, and construct a temporal knowledge graph based on the safety element entities and their attribute features;

[0055] In the time-series knowledge graph, an association mapping between entities is established, and the dynamic association weight between entities under different time windows is calculated; based on the dynamic association weight, the propagation path of security risks is analyzed to obtain a set of risk propagation links;

[0056] For each link in the risk propagation link set, the risk development trend is obtained through recursive calculation, and based on the historical evolution pattern in the time series knowledge graph, the risk situation in future time steps is predicted to generate risk prediction results.

[0057] Based on the correlation between the risk prediction results and the risk propagation chain, differentiated early warning strategies are dynamically generated; at the same time, a closed-loop tracking system for early warning response is established, incorporating early warning results, handling processes, and actual effects into the decision-making basis for system optimization, and forming a continuously optimized early warning and emergency management ecosystem by deeply exploring the emergency management practices of various regions.

[0058] In one optional implementation, the multimodal monitoring data is spatiotemporally aligned and semantically annotated to analyze and identify security element entities and their attribute features. Constructing a temporal knowledge graph based on the security element entities and their attribute features includes:

[0059] The data streams of different modes in the multimodal monitoring data are time-series calibrated according to timestamps, and the data collected from different spatial nodes are spatially registered based on the spatial location mapping relationship to obtain a unified data representation after spatiotemporal alignment.

[0060] The data items in the unified data representation are semantically parsed using a pre-trained domain knowledge base and ontology model to identify the entity type, relationship type between entities, and entity attributes corresponding to the data items. The accuracy of the annotation results is ensured through consistency verification and conflict resolution, resulting in normalized data after semantic annotation.

[0061] Security element entities are identified from the normalized data after semantic annotation, and based on the entity type, the relationship type between entities and the entity attributes, the corresponding static attribute features and dynamic behavior features are extracted for each security element entity to construct an entity-feature mapping set.

[0062] An initial temporal knowledge graph is constructed based on the security element entities and their corresponding entity-feature mapping sets. The topological integrity of the initial temporal knowledge graph is verified by using the relationship types between entities, isolated nodes and broken paths in the graph are identified, and missing entity relationships are filled in by combining relationship reasoning rules, thus forming a complete temporal knowledge graph.

[0063] The spatiotemporal alignment process of multimodal monitoring data achieves data fusion by establishing a unified time reference and spatial coordinate system. Data collected by each sensor node carries a GPS timestamp with millisecond-level accuracy, while simultaneously recording the device's local clock deviation. The timing calibration module receives raw data streams from devices such as vibration sensors, gas detectors, thermometers, hygrometers, and cameras. Each data packet contains fields such as device identifier, timestamp, data type, sampled value, and quality marker. The calibration algorithm synchronizes clocks based on a network time protocol, calculates the deviation between each device and the reference clock, and performs linear correction on all timestamps. When a time jump or abnormal drift is detected, the system activates a time interpolation mechanism, using adjacent normal time points for linear or cubic spline interpolation compensation. Spatial registration is based on a pre-established three-dimensional coordinate system of the mine. Each sensor node has a fixed spatial location code, including roadway number, distance from the starting point in meters, and relative height. The registration algorithm spatially interpolates similar measurement data from different spatial locations according to distance weights, generating a continuous data field covering the entire monitoring area. The interpolation radius is set to 50 meters. When there are fewer than 3 sensors within 50 meters of a point, the search radius is expanded to 100 meters. The spatiotemporally aligned data is stored in a standardized format, including standardized timestamps, 3D coordinates, data type identifiers, numerical values, confidence levels, and other fields, forming a unified data representation.

[0064] The semantic annotation process utilizes a pre-built ontology library for mine safety to perform data semantic parsing. This library includes core concept categories such as equipment entities, environmental parameters, safety status, and abnormal events, as well as their hierarchical and attribute relationships. The semantic parsing engine receives a unified data representation and first performs preliminary entity type identification based on data type and source equipment. Vibration data corresponds to equipment vibration entities, gas concentration corresponds to gas environment entities, and image data corresponds to visual scene entities. Entity relationship identification is achieved through a relationship extraction algorithm based on a predefined relationship template library, including relationship types such as "located," "influence," "contains," and "preceding." The relationship extraction process considers spatiotemporal proximity; when two entities are temporally adjacent and their spatial distance is less than a preset threshold, a potential association is established. Entity attribute extraction covers numerical and symbolic attributes. Numerical attributes include measured values, rates of change, and fluctuation amplitudes, while symbolic attributes include equipment status, anomaly type, and severity. The consistency verification module checks the logical rationality of the annotation results, verifies the matching relationship between entity types and attribute values, identifies contradictory annotations, and triggers a conflict resolution mechanism. The conflict resolution strategy is based on confidence-weighted voting, prioritizing high-confidence annotations. For conflicting annotations with similar confidence levels, domain expert rules are introduced for arbitration. After semantic annotation is completed, normalized data is generated, with each data record containing complete semantic information such as entity identifier, type label, attribute list, relationship pointers, and confidence score.

[0065] Safety element entity identification involves screening entities directly related to mine safety from standardized data. These entities include key safety components such as ventilation equipment, gas monitoring points, personnel locations, transportation equipment, and power supply systems. The identification algorithm filters based on entity type labels and safety importance scores. The scoring mechanism considers factors such as the entity's impact on safety accidents, regulatory attention, and the frequency of association with historical accidents. Each safety element entity extracts two sets of features: static attribute features and dynamic behavioral features. Static attribute features describe the entity's inherent attributes, including information that does not change over time, such as equipment model, rated parameters, installation location, and maintenance cycle. Dynamic behavioral features reflect changes in the entity's operating status, including time-varying features such as real-time measurements, trends, operating modes, and abnormal indicators. The feature extraction process employs a sliding time window mechanism with a window length of 1 hour and a sliding step of 15 minutes to ensure that features can capture short-term fluctuations and long-term trends. For numerical features, extracted statistics include mean, variance, maximum, minimum, and rate of change; for symbolic features, statistical state distribution and transition frequency are extracted. The entity-feature mapping set is organized in key-value pairs, where the key is a unique identifier for the entity and the value is a feature vector. The vector dimension is dynamically adjusted according to the entity type and typically contains 20 to 50 feature components.

[0066] The temporal knowledge graph is constructed based on a graph structure representation of security element entities and their feature mapping relationships. The initial graph uses entities as nodes and relationships between entities as edges. Node attributes include entity identifier, type, static features, and current dynamic features, while edge attributes record metadata such as relationship type, strength, and establishment time. The graph construction process first creates nodes corresponding to all security element entities, and then establishes edge connections based on the relationship types between entities identified in the semantic annotation stage. Relationship types include physical connection, logical dependency, spatial proximity, and functional collaboration, each with a different weight calculation method. The weight of physical connection relationships is based on connection strength, logical dependency relationships on the degree of dependency, spatial proximity relationships on the inverse of distance, and functional collaboration relationships on the frequency of collaboration. Topological integrity verification uses a graph traversal algorithm to detect graph connectivity and identify isolated nodes and broken subgraphs. Isolated nodes refer to entity nodes without any edge connections, and broken paths refer to situations where necessary connections between key entities are missing. Relationship reasoning rules are defined based on the domain knowledge base and include logical constraints such as transitivity rules, symmetry rules, and hierarchical rules. The transitivity rule states that if entity A influences entity B and entity B influences entity C, then entity A indirectly influences entity C. The symmetry rule states that if entity A and entity B are spatially adjacent, then entity B and entity A are also spatially adjacent. The inference engine derives potential missing relationships based on existing relationships and inference rules. Newly derived relationships are added to the graph with lower confidence, and the process continues through multiple rounds of iterative inference until the graph topology is stable.

[0067] In one optional implementation, an initial temporal knowledge graph is constructed based on the security element entities and their corresponding entity-feature mapping sets. The topological integrity of the initial temporal knowledge graph is then verified using the entity relationship types. Identifying isolated nodes and broken paths in the graph includes:

[0068] The security element entities are treated as a set of nodes, and each node is assigned an attribute vector according to the entity-feature mapping set; a set of directed edges between nodes is constructed based on the relationship types between entities, and a relationship strength metric and temporal evolution constraints are attached to each directed edge; the set of nodes, the attribute vectors, and the set of directed edges are combined to form the topology of the initial temporal knowledge graph.

[0069] The initial temporal knowledge graph is subjected to topological integrity verification. The in-degree and out-degree of each node are calculated by traversing the set of directed edges. Nodes with both in-degree and out-degree of zero are identified as isolated nodes. Broken paths caused by the lack of necessary intermediate nodes are detected by path connectivity analysis.

[0070] For isolated nodes identified in the topology integrity verification, potential associations are queried in the domain ontology model based on the entity relationship type, and association edges are added to the isolated nodes according to the query results to eliminate the isolated state;

[0071] For the broken paths identified in the topological integrity verification, the semantic correlation between the starting point and the ending point of the path is analyzed, and the missing intermediate entities and their correlations are inferred using relational reasoning rules. The broken paths are then completed in the initial temporal knowledge graph.

[0072] The initial temporal knowledge graph construction process organizes safety element entities and relationship information through a graph data structure. The node set construction module receives a list of safety element entities and creates a graph node object for each entity. The node object contains basic fields such as a unique entity identifier, entity type label, and creation timestamp. The attribute vector assignment process adds a multi-dimensional feature vector to each node based on the entity-feature mapping set. The vector length is dynamically determined according to the entity type. The gas monitoring entity vector contains 32 features such as concentration value, rate of change, and alarm threshold; the ventilation equipment entity vector contains 28 features such as air volume, power, and operating status; and the personnel positioning entity vector contains 15 features such as location coordinates, movement speed, and dwell time. The attribute vectors are stored using floating-point arrays, and the numerical range is normalized and mapped to the interval between 0 and 1. Missing feature values ​​are marked with -1. The node attribute update mechanism supports two modes: incremental update and full replacement. Incremental update only modifies the changed feature components, while full replacement rewrites the entire attribute vector. The update operation records the timestamp and version number for change tracking.

[0073] A directed edge set is constructed to establish connections between nodes based on the relationship types between entities. Edge objects contain core fields such as source node identifier, target node identifier, relationship type code, and creation time. Relationship type encoding uses integer enumeration: physical connection is encoded as 1, logical dependency as 2, spatial proximity as 3, functional collaboration as 4, and causal influence as 5. Relationship strength metric calculation considers the matching degree between relationship type and entity characteristics. Physical connection strength is calculated based on connection bandwidth and transmission delay; logical dependency strength is calculated based on dependency frequency and importance weight; spatial proximity strength is calculated based on the reciprocal of distance and reachability; functional collaboration strength is calculated based on collaboration effect and historical success rate; and causal influence strength is calculated based on influence range and propagation speed. Strength values ​​are limited to the range of 0.1 to 1, with precision maintained to three decimal places. Temporal evolution constraints describe the changes in relationships over time, including temporal attributes such as effective time, failure time, periodic patterns, and trends. The effective and expiration times are stored in timestamp format. The periodic mode supports predefined modes such as daily, weekly, and monthly cycles. The trend of change includes type identifiers such as increasing, decreasing, fluctuating, and stable.

[0074] The topology combination process integrates the node set, attribute vectors, and directed edge set into a complete graph data structure. The graph uses an adjacency list representation, with each node maintaining an outgoing edge list and an incoming edge list. The edge lists are sorted by the target node identifier to support fast lookup. Graph metadata records statistical information such as the total number of nodes, the total number of edges, creation time, and last update time. The graph indexing mechanism establishes a hash mapping from node identifiers to memory addresses, an index mapping from edge relationships to edge objects, and a grouping mapping from entity types to node lists, supporting efficient access in multiple query modes. Graph serialization uses a compact binary format for storage, node attribute vectors use compressed encoding to reduce storage space, and edge relationships use differential encoding to optimize storage efficiency. The graph loading process supports a lazy loading strategy, prioritizing the loading of core nodes and frequently accessed edges, and loading detailed attribute information and low-frequency edge relationships as needed.

[0075] Topological integrity verification uses a graph traversal algorithm to detect the connectivity and integrity of the graph structure. The in-degree and out-degree calculation module traverses the set of directed edges, counting the number of out-degrees of each node as an edge start point and the number of in-degrees as an edge end point. The degree statistics are stored in the degree field of the node object, including information such as in-degree value, out-degree value, and total degree. The isolated node identification algorithm checks the in-degree and out-degree of each node. When both the in-degree and out-degree values ​​of a node are 0, the node is marked as an isolated node. The isolated node list maintains the identifier and discovery time of isolated nodes and supports grouping statistics according to dimensions such as entity type and importance. Path connectivity analysis uses a depth-first search algorithm to detect connected components in the graph and identify a subset of nodes that cannot be reached from each other by edge paths. The broken path detection algorithm is based on critical path analysis to identify situations where important entities lack necessary intermediate connections. Critical paths are defined as the key information transmission paths in the security monitoring process, including paths from monitoring equipment to the control center, alarm signals to response equipment, and personnel locations to safety exits. The criteria for determining a broken path include situations such as the path length exceeding the expected threshold, path interruption causing information to be unable to be transmitted, and missing key nodes causing process interruption.

[0076] The process of supplementing relationships between isolated nodes is based on querying potential relationship connections using the domain ontology model. The ontology query module receives the entity type and attribute features of isolated nodes and searches for relevant relationship patterns in a pre-built domain ontology knowledge base. The ontology knowledge base stores relationship rules between entity types in the form of triples, including elements such as subject type, relationship type, and object type. The query algorithm supports both exact matching and fuzzy matching modes. Exact matching requires that the entity types be completely identical, while fuzzy matching allows matching of parent or child classes of entity types. The potential relationship score is calculated based on factors such as the frequency of the relationship in the ontology, the importance weight of the relationship, and the similarity of entity features. The candidate relationship list is sorted in descending order of score, and relationships with scores exceeding a threshold are selected as supplementation candidates. The edge supplementation operation creates new edge connections for isolated nodes, and the relationship strength of the new edges is set to a low initial value, to be adjusted later for verification. The supplementation process records an operation log, including supplementation time, supplementation basis, confidence level, etc., supporting subsequent relationship verification and adjustment.

[0077] The broken path completion process identifies missing intermediate entities and relationships through semantic relevance analysis and relational reasoning. Semantic relevance analysis of the path's start and end points calculates similarity based on the semantic vectors of the entities. These semantic vectors are mapped to high-dimensional vector representations of entity names and attribute features using a pre-trained word embedding model. Cosine similarity is used for similarity calculation, with similarity values ​​ranging from 0 to 1. Entity pairs with similarity exceeding 0.8 are considered to have strong semantic relationships. Relational reasoning rules are constructed based on domain expert knowledge and historical data statistics, including transitive reasoning, combinatorial reasoning, and hierarchical reasoning patterns. Transitive reasoning rules describe that if entity A is connected to entity B through relation R1 and entity B is connected to entity C through relation R2, then entity A is connected to entity C through a combination of relations R1 and R2. Combinatorial reasoning rules derive composite relationships based on multiple simple relations, while hierarchical reasoning rules derive hierarchical relationships based on the hierarchical structure of entities. The reasoning engine employs a forward-chain reasoning strategy, gradually deriving new relations from known relations, with the reasoning depth limited to 5 levels to avoid infinite reasoning. Missing intermediate entity inference is based on path analysis and entity matching. When there is a semantic relationship between the start and end points of a path but no direct connection, intermediate entity candidates are searched. Intermediate entity candidates are selected from existing graph nodes and are required to have a potential relationship with both the start and end points.

[0078] In one optional implementation, an association mapping between entities is established in the temporal knowledge graph, and dynamic association weights between entities are calculated under different time windows; based on the dynamic association weights, the propagation path of security risks is analyzed to obtain a risk propagation link set including:

[0079] Entity nodes and their edge relationships are extracted from the temporal knowledge graph. An association mapping matrix between entities is established based on semantic type and directionality. For different time windows, the dynamic association weight matrix between entities is calculated through a time-aware graph attention mechanism based on the state change sequence of entities within the time window and the causal dependency between entities.

[0080] Based on the dynamic association weight matrix, the corresponding entity pairs in the association mapping matrix are weighted and assigned weights, and the entity nodes, the edge relationships and their weights are combined to form a weighted graph structure associated with a time window.

[0081] In the weighted graph structure, the identified risk source node is selected as the starting point. Edges with weights exceeding the preset propagation threshold are filtered based on dynamic association weights. The propagation trajectory of risk from the source node to the downstream node is tracked by a path search strategy that combines breadth-first traversal and depth-first traversal. Multiple paths involved in the propagation trajectory are aggregated and deduplicated to finally obtain a set of risk propagation links.

[0082] The association mapping matrix construction process extracts entity nodes and edge relationship data structures from the temporal knowledge graph. The entity node extraction module traverses the graph node set to obtain basic information such as a unique identifier, entity type label, creation timestamp, and attribute vector for each node. Node identifiers use 64-bit integer encoding. Entity type labels include predefined enumeration values ​​such as equipment, personnel, environment, and control. The attribute vector dimensions are dynamically determined based on the entity type: equipment entity attribute vectors contain 32 features, personnel entity attribute vectors contain 18 features, environment entity attribute vectors contain 24 features, and control entity attribute vectors contain 28 features. The edge relationship extraction module traverses the graph edge set to obtain relationship attributes such as source node identifier, target node identifier, relationship type encoding, relationship strength value, and creation time. Relationship type encoding uses integer enumeration: physical connection relationships are encoded as 1, logical dependency relationships as 2, spatial proximity relationships as 3, functional collaboration relationships as 4, and causal influence relationships as 5. Relationship strength values ​​are limited to the range of 0.1 to 1.0, with precision maintained to three decimal places.

[0083] Semantic type mapping establishes semantic association rules between entities based on entity type labels. These rules are stored in a two-dimensional association table, where the row index represents the source entity type, the column index represents the target entity type, and the table element value represents the semantic association strength. The semantic association strength between equipment and environment entities is set to 0.8, between personnel and control entities to 0.7, between entities of the same type to 0.9, and between unrelated entities to 0.1. The directionality establishment process determines the directional weights between entities based on the directional nature of edge relationships. The weight for positive relationships is set to 1.0, while the weight for negative relationships is differentiated according to the relationship type: physical connection negative weight is 0.6, logical dependency negative weight is 0.3, spatial proximity negative weight is 0.9, functional collaboration negative weight is 0.7, and causal influence negative weight is 0.2. The association mapping matrix adopts a sparse matrix storage format. The matrix dimension is equal to the total number of entity nodes. The matrix element value is the product of semantic association strength and directional weight. Matrix element values ​​below 0.05 are marked as sparse elements and are not stored, reducing memory usage and improving access efficiency.

[0084] The time window segmentation strategy determines the window boundaries and sliding step size based on the time dimension information of the temporal knowledge graph. The time window length is adjustable from 15 minutes to 240 minutes, with a default value of 60 minutes. The sliding step size is set from 25% to 50% of the window length, with a default value of 15 minutes. The window boundary alignment strategy adopts natural time boundary alignment, aligning the start time to the hour or half-hour, and extending the end time according to the window length. The entity state change sequence extraction module collects the historical change history of attribute vectors within each time window for entity nodes. The state change sequence is stored in a list format of timestamp-value pairs, with timestamp precision at the second level and values ​​being normalized attribute vector component values. State change detection is based on the difference in attribute values ​​between adjacent time points. Changes with a difference exceeding a threshold of 0.05 are marked as significant change events, and these events include information such as change time, change attribute, change magnitude, and change direction.

[0085] Causal dependency identification establishes a causal dependency matrix between entities based on the causal influence types in edge relationships. This matrix is ​​represented as an adjacency matrix of a directed graph, with each element representing a weight indicating the strength of the causal relationship. The calculation of causal relationship strength considers both direct and indirect relationships. The strength of a direct causal relationship is equal to the strength of the edge relationship, while the strength of an indirect causal relationship is calculated through path propagation attenuation, with an attenuation coefficient set to 0.8 and a propagation path length limited to three hops. The causal dependency delay parameter is determined based on historical data statistical analysis. Different types of entities exhibit varying causal propagation delays: the average delay for equipment failure propagating to environmental parameters is 180 seconds, for personnel anomalies propagating to control commands is 120 seconds, and for environmental changes propagating to equipment status is 240 seconds. The standard deviation of the delay parameter is set to 30% of the average value.

[0086] The temporal-aware graph attention mechanism employs a multi-head attention architecture to calculate the dynamic association weights between entities. Eight attention heads are used, each with 64 dimensions. The query vector generates the entity's current state vector and historical state change sequence; the key vector generates the entity's historical state sequence and causal dependency strength; and the value vector generates the entity's attribute vector and semantic type encoding. Attention weights are calculated by the dot product of the query and key vectors, followed by scaling and softmax normalization to obtain the attention score. The scaling factor is set to the square root of the attention head dimension, i.e., 8.0. Temporal position encoding uses sine and cosine functions to encode time positions, with a 128-dimensional encoding dimension. The encoding frequency parameter is set to a logarithmically uniform distribution within the range of 0.0001 to 10.0.

[0087] The dynamic association weight calculation integrates the outputs of multiple attention heads, mapping the multi-head attention outputs to the final association weight values ​​through a linear transformation layer. The weight parameters of the linear transformation layer are obtained through pre-training, with training data including historical time-series graph data and manually labeled association strength tags. Association weight normalization ensures that weight values ​​are within the range of 0 to 1; associations with weight values ​​below 0.1 are considered weak associations, and those with weight values ​​above 0.7 are considered strong associations. A time decay mechanism exponentially decays the association weights at historical time points, with a decay rate set to 0.95, meaning the association weight decays by 5% per time step. The dynamic association weight matrix update frequency is consistent with the time window sliding frequency, updating the weight matrix every 15 minutes, and maintaining the precision of matrix element values ​​to four decimal places.

[0088] The weighted graph structure construction process assigns weight values ​​from the dynamic association weight matrix to the corresponding entity pair positions in the association mapping matrix. The weight assignment strategy uses an overwrite update method, where newly calculated dynamic weight values ​​directly replace the original static weight values. Weight fusion rules are differentiated based on weight type; static semantic weights and dynamic association weights are fused through a weighted average, with static weights accounting for 30% and dynamic weights accounting for 70%. An edge weight threshold filtering mechanism removes weakly associated edges with weight values ​​below 0.08, reducing graph structure complexity and improving subsequent path search efficiency. The weighted graph uses an adjacency list storage structure, with each node maintaining an outgoing edge list and an incoming edge list. The edge lists are sorted in descending order of weight value for easy access to high-weight edges.

[0089] Node importance assessment calculates node importance scores based on multiple dimensions, including node degree, total weights, and centrality. The degree score is a weighted sum of in-degree and out-degree; the total weights are the cumulative weights of all adjacent edges; and the centrality score uses a weighted combination of betweenness centrality and proximity centrality. Node importance scores are normalized to the range of 0 to 1. Nodes with scores above 0.8 are marked as critical nodes, and those below 0.2 are marked as edge nodes. Graph connectivity verification uses a strongly connected component decomposition algorithm to detect the connectivity characteristics of the weighted graph. Indicators such as the number of strongly connected components, the largest component size, and the number of isolated nodes are used to evaluate the quality of the graph structure.

[0090] Risk source nodes are selected based on the mapping relationship between identified security risk events and their corresponding entity nodes. Risk events include equipment failure, personnel violations, environmental anomalies, and control failures, each corresponding to a specific entity type and attribute characteristic pattern. Equipment failure risk source nodes are characterized by equipment-type entities with status attribute values ​​exceeding the upper limit of the normal range; personnel violation risk source nodes are characterized by personnel-type entities with location attributes deviating from the predetermined path; environmental anomaly risk source nodes are characterized by environmental-type entities with monitoring parameters exceeding safety thresholds; and control failure risk source nodes are characterized by control-type entities with response times exceeding expected values. Risk source node confidence assessment is based on risk feature matching and historical risk statistics, with confidence values ​​ranging from 0 to 1. Nodes with a confidence value exceeding 0.6 are identified as risk source origins.

[0091] The propagation threshold is set based on statistical analysis of historical risk propagation cases, with an adjustable range of 0.15 to 0.45 and a default value of 0.25. The dynamic threshold adjustment mechanism adaptively adjusts according to the current system risk level: at high risk levels, the threshold is reduced by 10% to enhance sensitivity, while at low risk levels, the threshold is increased by 15% to reduce false alarms. The edge weight selection process starts with the adjacent edges of the risk source node, selecting edges with weights exceeding the propagation threshold as valid propagation paths. The selection results are stored in a candidate propagation edge list, sorted in descending order of weight value.

[0092] The breadth-first search strategy starts from the risk source node and expands outwards layer by layer. Each layer includes all reachable nodes at the current distance, and the traversal depth is limited to 6 layers to avoid over-propagation. A queue data structure maintains a list of nodes to be visited. When a node is enqueued, its arrival path and accumulated weight are recorded; when a node is dequeued, its adjacent nodes are expanded and the path information is updated. The depth-first search strategy delves deeply along a single path until a termination condition is reached. Termination conditions include reaching the maximum depth, the accumulated weight falling below a threshold, or encountering a visited node. A stack data structure maintains the current path state and supports path backtracking and branch exploration.

[0093] The path search strategy combines breadth-first search and depth-first search. First, breadth-first search identifies all propagation regions, then depth-first search refines the specific propagation paths within each region. Path weights are calculated based on the geometric mean of edge weights within the path, preventing a single high-weight edge from obscuring the overall propagation capability of the path. Path length constraints limit propagation paths to no more than 8 hops, and path weight constraints require an average path weight of at least 0.12.

[0094] The propagation trajectory record includes a complete node sequence and an edge weight sequence. The node sequence records the identifiers of the entity nodes traversed by the propagation path, and the edge weight sequence records the dynamic weight value of each edge in the path. Trajectory evaluation metrics include path length, average weight, propagation delay, and influence range. The influence range is calculated based on the importance score and connectivity of the path's endpoint node. The multi-path aggregation process is based on path similarity calculation and cluster analysis. Path similarity is calculated through node overlap and weight correlation; paths with a similarity greater than 0.75 are grouped into the same cluster.

[0095] Deduplication is based on hash matching between the path's origin and destination pairs and the set of intermediate nodes. Only one identical path is retained, while partially overlapping paths are selected and retained based on evaluation metrics. The final risk propagation link set contains the filtered and deduplicated valid propagation paths. Each link records attributes such as the source node, target node, sequence of intermediate nodes, path weight, propagation delay, and confidence level. The link set is sorted according to the degree of risk impact, calculated based on factors such as the importance of the target node, path weight, and propagation speed. The sorting result is used to determine the risk response priority.

[0096] In one optional implementation, a path search strategy combining breadth-first traversal and depth-first traversal is used to track the propagation trajectory of risk from the source node to downstream nodes, and the aggregation and deduplication of multiple paths involved in the propagation trajectory includes:

[0097] A path search strategy combining breadth-first traversal and depth-first traversal is used to track the propagation trajectory of risk from the source node to downstream nodes. The breadth-first traversal is based on a node queue, which visits all adjacent nodes of each level in turn to construct the propagation range of the risk at the current level and obtain the node set of each level. The depth-first traversal is based on a node stack, which prioritizes exploring the vertical extension direction of a single path along the weighted edge until the propagation termination condition is reached, and obtains the node sequence of each extension path.

[0098] Based on the node sequence, in each iteration, the breadth-first traversal is first executed to determine the hierarchical propagation range, the depth-first traversal is executed to explore the extension path of each node, the propagation trajectory is integrated, and multiple paths involved in the propagation trajectory are aggregated and deduplicated.

[0099] Construct a network graph structure that reflects the relationships between nodes, where each node represents an entity, edges represent the relationships between entities, and the weight of the edges represents the strength or probability of risk propagation. In this network graph structure, risk propagation starts from one or more source nodes and spreads downstream along the edges.

[0100] In actual implementation, the set of source nodes for risk is identified, and these nodes are marked as the starting point for risk propagation. Simultaneously, termination conditions for risk propagation are set, such as a propagation depth threshold, a cumulative risk value threshold, or a specific target set of nodes.

[0101] For tracking risk propagation, a strategy combining breadth-first search (BFS) and depth-first search (DFS) is employed. BFS, based on node queue operations, is primarily used to construct the risk propagation range for each level. Specifically, the source node is added to the queue, then dequeued sequentially, and all its adjacent nodes are visited and added back to the queue. This process is repeated until the queue is empty or the propagation termination condition is met. In each iteration, the nodes in the queue constitute the propagation range for the current level, forming a hierarchical node set.

[0102] For each level of node set, a depth-first traversal is applied to explore the extension paths starting from the current level node. Depth-first traversal is based on node stack operations, prioritizing the exploration of the vertical extension direction of a single path along high-weight edges. Specifically, nodes at the current level are pushed onto the stack in sequence, then a node is popped from the top of the stack, its adjacent nodes are visited, and nodes connected by edges with higher weights are prioritized for further exploration until the propagation termination condition is met or further extension is impossible. In this way, each path from the source node to the termination node constitutes a node sequence, representing a trajectory of risk propagation.

[0103] In practical applications, different weight calculation rules can be defined for each edge. For example, in a financial risk propagation network, the weight of an edge can be calculated based on the transaction amount, shareholding ratio, or frequency of business transactions; in an epidemic propagation network, the weight of an edge can be calculated based on the frequency of personnel movement, spatial distance, or duration of contact.

[0104] In each iteration, a breadth-first traversal is performed to determine the propagation range of the current level, and a depth-first traversal is performed on each node in that level to explore its extension paths. This combined strategy fully leverages the advantage of breadth-first traversal in covering all propagation paths, while utilizing the characteristic of depth-first traversal to quickly locate high-risk propagation paths.

[0105] After obtaining all propagation paths, these paths need to be aggregated and deduplicated. Since risk propagation networks often contain loops or multiple paths connecting the same nodes, directly outputting all paths would lead to redundant results. The aggregation and deduplication process first groups the paths together, grouping paths with the same start and end points together. Then, within each group, deduplication is performed based on the path's node composition and propagation weight, retaining the most representative path or the path with the highest risk propagation probability.

[0106] Aggregation deduplication can be implemented based on a hash table structure, using key features of the path (such as start point, end point, path length, key nodes, etc.) as hash keys, and similar paths are mapped to the same hash bucket. For paths within each hash bucket, it is determined whether these paths need to be merged or filtered according to predefined similarity calculation rules. For example, the path with the highest cumulative risk weight can be retained, or multiple similar paths can be merged into a representative path.

[0107] Throughout the process, a global set of propagation trajectories is maintained, newly discovered paths are continuously added to this set, and the set is periodically aggregated and deduplicated. The final output set of propagation trajectories represents the propagation path of the risk from the source node to each downstream node, which can be used for subsequent risk assessment and prevention and control decisions.

[0108] This method enables the efficient identification of critical paths and nodes in risk propagation within complex networks, providing decision support for risk management. For example, in supply chain risk analysis, it can identify how upstream supplier risks are transmitted to core enterprises and assess the risk intensity of different propagation paths; in financial systemic risk analysis, it can track how crises at specific financial institutions spread throughout the entire financial network through asset-liability linkages, liability-liability linkages, and other means.

[0109] In summary, by combining breadth-first search and depth-first search strategies with path aggregation and deduplication, we can effectively track and analyze the risk propagation trajectory in complex networks, providing a scientific basis for risk prevention and control.

[0110] In one optional implementation, for each link in the risk propagation link set, the risk development trend is calculated recursively, and based on the historical evolution patterns in the time-series knowledge graph, the risk situation at future time steps is predicted, generating risk prediction results including:

[0111] For each link in the risk propagation link set, a state transition matrix is ​​constructed based on the weight relationship between adjacent nodes in the link, and a state transition probability distribution is trained by combining the historical state sequence of the nodes. The development trend value and trend confidence of the risk on the corresponding link are obtained through the recursive operation of chain conditional probability. For each node, its sensitivity coefficient in the link propagation process is calculated, and the development trend value is optimized based on the sensitivity coefficient to obtain an optimized trend value that takes into account the degree of influence of the node.

[0112] In the time-series knowledge graph, identify historical propagation paths and their evolutionary characteristics that are similar to the corresponding links, calculate the structural similarity and state similarity between the current link and the historical paths, and determine the evolutionary contribution of each historical path based on the structural similarity and the state similarity; construct the evolutionary rules of historical paths based on the evolutionary contributions; associate and integrate the optimization trend value with the evolutionary rules, and combine the trend confidence to predict the risk situation in future time steps, generating risk prediction results.

[0113] The state transition matrix construction process establishes a probabilistic model for node state transitions based on the weight relationships between adjacent nodes in the risk propagation link. The matrix dimension equals the number of state categories of nodes in the link. Node state classification adopts a three-state model, including normal state, warning state, and abnormal state, with state codes of 0, 1, and 2, respectively. The adjacent node weight relationship extraction module obtains the dynamic association weights between node pairs from the link data structure. The weight values ​​range from 0.1 to 1.0, maintaining precision to three decimal places. The state transition probability calculation is based on the normalization of weight values, normalizing the weights of the same source node pointing to different target nodes to ensure that the sum of transition probabilities equals 1.0. The transition probability matrix adopts a sparse storage format, and transitions with probability values ​​below 0.05 are marked as unreachable transitions to reduce computational complexity.

[0114] The node historical state sequence extraction module collects state change records for each node over the past 30 days from the temporal knowledge graph. State records include attributes such as timestamp, state value, duration, and reason for transition. The historical state sequence is arranged chronologically, with timestamps accurate to the minute level, state values ​​encoded as integers, and duration in minutes. The state transition probability distribution training employs maximum likelihood estimation, calculating transition probabilities based on historical state transition frequency statistics. Training data preprocessing includes missing value imputation, outlier detection, and sequence alignment. Missing values ​​are imputed using a forward imputation strategy, outliers are identified using a 3x standard deviation rule and replaced with the sequence mean, and sequence alignment is performed using linear interpolation based on timestamps.

[0115] The training process employs a sliding window strategy with a window length of 7 days and a sliding step size of 1 day. Each state transition event within a window serves as a training sample. State transition frequency statistics are based on a conditional probability framework, counting the frequency of transitions to each target state given a source state. The frequency matrix is ​​row-normalized to obtain the probability distribution. Laplace smoothing is used for smoothing, adding a pseudo-count of 0.01 to zero-frequency transitions to avoid zero-probability cases. The probability distribution is validated using a chi-square test to assess the goodness of fit, with a significance level set at 0.05. Distributions that pass the test are used for subsequent recursive calculations.

[0116] The chain-based conditional probability recursion operation calculates the propagation probability of risk along the link based on the Markov chain model. The recursion process starts from the starting node of the link and progressively calculates the state probability distribution of each subsequent node. The recursion formula is based on matrix multiplication of the current node's state probability and the state transition matrix to obtain the state probability vector of the next node. The recursion step size is consistent with the link length, and the maximum recursion depth is limited to 10 steps to avoid computational divergence. The probability vector is normalized to ensure that the sum of probabilities equals 1.0, and the normalization error tolerance is set to 0.001.

[0117] The trend value is calculated based on the probability of abnormal states at the link's endpoint. An abnormal state probability exceeding 0.3 is considered a high-risk trend, a probability between 0.1 and 0.3 is considered a medium-risk trend, and a probability below 0.1 is considered a low-risk trend. The trend value is represented by a continuous number from 0 to 1, and the calculation formula is the abnormal state probability multiplied by the path propagation coefficient. The path propagation coefficient is calculated based on the link length and average weight. The propagation coefficient is set to 0.8 for links with more than 5 nodes, 0.9 for links with 3 to 5 nodes, and 1.0 for links with fewer than 3 nodes.

[0118] The trend confidence assessment is calculated based on a combination of historical prediction accuracy and current data integrity. Historical prediction accuracy is obtained by comparing the predicted results with the actual results over the past 90 days, and the accuracy is calculated as a percentage with integer decimals. The data integrity assessment is based on the missing rate and latency rate of the node status data in the link. Data integrity with a missing rate below 5% and a latency rate below 10% is rated as excellent, with a corresponding confidence coefficient of 1.0. Data integrity with a missing rate between 5% and 15% or a latency rate between 10% and 25% is rated as good, with a corresponding confidence coefficient of 0.85. Data integrity with a missing rate exceeding 15% or a latency rate exceeding 25% is rated as average, with a corresponding confidence coefficient of 0.7.

[0119] The node sensitivity coefficient is calculated based on the statistical performance of nodes in historical risk events. The sensitivity coefficient reflects the degree of impact of node state changes on downstream nodes. Sensitivity statistics use the mutual information method to quantify the correlation strength between node state changes and downstream node state changes. Nodes with mutual information values ​​higher than 0.6 have a sensitivity coefficient of 1.2, nodes with mutual information values ​​between 0.3 and 0.6 have a sensitivity coefficient of 1.0, and nodes with mutual information values ​​lower than 0.3 have a sensitivity coefficient of 0.8. Node type sensitivity correction is based on the inherent characteristics of different entity types: equipment nodes have a sensitivity correction coefficient of 1.1, personnel nodes have a sensitivity correction coefficient of 0.9, environmental nodes have a sensitivity correction coefficient of 1.0, and control nodes have a sensitivity correction coefficient of 1.2.

[0120] The trend value optimization process involves weighted fusion of the original trend value and the sensitivity coefficients of each node in the link. Weight allocation is based on the importance of each node's position in the link: the starting node has a weight of 0.3, intermediate nodes have their remaining weights evenly distributed, and the ending node has a weight of 0.2. The optimized trend value is calculated using a weighted average method, multiplying the original trend value by the product of each node's sensitivity coefficient and its corresponding weight, and then summing the results. The result is limited to the range of 0 to 1. The optimization process also considers the influence of the link topology: the optimization coefficient for a linear link structure is 1.0, for a branch link structure it is 0.9, and for a ring link structure it is 1.1.

[0121] The historical propagation path identification module searches the temporal knowledge graph for historical paths with similar characteristics to the current link, covering historical data from the past 180 days. Path similarity evaluation is based on a comprehensive calculation of structural similarity and state similarity. Structural similarity uses a graph editing distance algorithm to calculate the topological differences between two paths, with the distance value normalized to the range of 0 to 1; the similarity equals 1 minus the normalized distance value. State similarity uses a dynamic time warping algorithm to calculate the similarity of the node state sequences in the path. Sequence alignment is based on minimum cost path search, with the cost function considering state value differences and time offset penalties.

[0122] The structural similarity calculation process represents the path as a combination of node and edge sequences. Node similarity is calculated based on entity type matching and attribute similarity: a perfect entity type match scores 1.0, similar types score 0.6, and unrelated types score 0.1. Edge similarity is calculated based on relation type matching and weight difference: edges with matching relation types and a weight difference less than 0.2 have a similarity of 0.9, edges with matching relation types but a weight difference greater than 0.2 have a similarity of 0.6, and edges with mismatched relation types have a similarity of 0.2. The overall structural similarity of the path is a weighted average of node and edge similarities, with node weights accounting for 60% and edge weights accounting for 40%.

[0123] State similarity is calculated based on the Pearson correlation coefficient of the state sequences of corresponding nodes in the path. State sequences with an absolute correlation coefficient greater than 0.8 have a similarity of 0.9, those with an absolute correlation coefficient between 0.5 and 0.8 have a similarity of 0.7, and those with an absolute correlation coefficient less than 0.5 have a similarity of 0.3. Sequence length difference correction uses a negative exponential function of the length ratio; the further the length ratio deviates from 1.0, the smaller the correction coefficient, with a minimum correction coefficient limit of 0.5. Temporal alignment quality is evaluated based on the ratio of the total cost of the alignment path to the sequence length. Alignment quality with a ratio less than 0.3 is excellent, with a ratio between 0.3 and 0.7 being good, and with a ratio greater than 0.7 being average.

[0124] Evolutionary contribution calculation is based on the geometric mean of structural and state similarity. Historical paths with a geometric mean greater than 0.7 have high evolutionary contributions, those with a geometric mean between 0.4 and 0.7 have medium contributions, and those with a geometric mean less than 0.4 have low contributions. Contribution weight allocation is based on an exponential decay function, with more recent historical paths receiving higher weights. The decay coefficient is set to 0.95, meaning the weight decays by 5% daily. Evolutionary contribution normalization ensures that the sum of all historical path contribution weights equals 1.0; paths with a weight below 0.05 after normalization are excluded from contribution calculation.

[0125] Historical path evolution patterns are extracted based on statistical analysis of evolutionary features from high-contribution historical paths. These features include path length changes, node state transition patterns, propagation delay distribution, and endpoint state probabilities. Path length changes are statistically analyzed to show the expansion or contraction trends of historical paths during evolution. A path length expansion rate exceeding 60% is considered to indicate an expansion pattern, a contraction rate exceeding 60% is considered to indicate a contraction pattern, and a rate between 40% and 60% is considered to indicate stable path length. Node state transition patterns are extracted from frequently occurring state transition sequences in historical paths. Patterns with a frequency exceeding 30% are marked as typical patterns and used for current link evolution prediction.

[0126] The propagation delay distribution is statistically analyzed to show the time distribution of risk propagation from the starting point to the endpoint along the historical path. The delay distribution is represented by a histogram, with 20 bins set and the bin width automatically determined based on the delay range. Delay distribution characteristic parameters include mean, standard deviation, skewness, and kurtosis. The mean reflects the average propagation delay, the standard deviation reflects delay variability, skewness reflects distribution symmetry, and kurtosis reflects the sharpness of the distribution. The endpoint state probability is statistically analyzed to show the final state distribution of the endpoint nodes along the historical path. The probabilities of normal state, warning state, and abnormal state are calculated separately, with probability values ​​maintained to two decimal places.

[0127] The integration process weights and merges optimized trend values ​​with historical evolution patterns. The fusion weights are determined based on the confidence level of the trend and the reliability of the evolution pattern. When the trend confidence level is higher than 0.8 and the reliability of the evolution pattern is higher than 0.7, the weight of the optimized trend value is set to 0.6, and the weight of the evolution pattern is set to 0.4. When the trend confidence level is lower than 0.6 or the reliability of the evolution pattern is lower than 0.5, the weight of the optimized trend value is set to 0.8, and the weight of the evolution pattern is set to 0.2. The fusion result undergoes a nonlinear transformation using the sigmoid function to enhance the discriminative power and stability of the prediction results.

[0128] Future time-step risk situation prediction calculates the risk probability distribution for the next 1 hour, 3 hours, 6 hours, 12 hours, and 24 hours based on the fusion results. The prediction time step is 15 minutes, with a maximum prediction duration of 48 hours. A four-level risk situation classification is used: low risk corresponds to a probability of 0 to 0.25, low-to-medium risk to 0.25 to 0.5, medium-to-high risk to 0.5 to 0.75, and high risk to 0.75 to 1.0. The prediction uncertainty assessment is based on the prediction confidence interval, with a confidence level set at 95%. The width of the confidence interval reflects the magnitude of the prediction uncertainty.

[0129] The risk prediction results include information such as the prediction time series, risk level series, confidence level series, and key influencing factors, with the data format using JSON structured representation. The prediction result validation module evaluates the prediction accuracy through backtesting on historical data over the past 30 days. Evaluation metrics include accuracy, recall, precision, and F1 score. The target values ​​are set at 85% or higher for accuracy, 80% or higher for recall, 75% or higher for precision, and 80% or higher for F1 score.

[0130] In one optional implementation, differentiated early warning strategies are dynamically generated based on the correlation between the risk prediction results and the risk propagation chain; simultaneously, a closed-loop tracking system for early warning response is established, incorporating early warning results, handling processes, and actual effects into the decision-making basis for system optimization, and deeply exploring the emergency management practices of various regions, including:

[0131] Based on the correlation between the risk prediction results and the risk propagation links, early warning response rules are determined according to the risk level and propagation range of different links. Multi-level risk thresholds are set, and the risk thresholds are dynamically adjusted based on the spatiotemporal evolution characteristics of risk propagation to generate differentiated early warning strategies.

[0132] The differentiated early warning strategy generates early warning information according to the early warning response rules, records the emergency response process and actual response effect of each early warning as optimization data, and performs time-series matching between the early warning information and the optimization data; calculates the early warning accuracy and response effectiveness based on the results of the time-series matching, and makes targeted improvements to the early warning response rules; incorporates the early warning results, response process and actual effect in the optimization data into the decision-making basis for system optimization, and deeply mines the emergency management practice experience of various regions.

[0133] like Figure 2 As shown, the method includes:

[0134] The correlation degree calculation is based on the coupling analysis of risk prediction results and risk propagation links. The correlation degree quantification module extracts attributes such as risk level, impact range, and time window from the risk prediction results and performs multi-dimensional matching with features such as the length, weight, and node type of the risk propagation link. The correlation strength calculation uses the weighted Euclidean distance method to comprehensively evaluate the correlation between the predicted risk level and the average weight of the link, the matching degree between the predicted impact range and the number of links, and the consistency between the predicted time window and the propagation delay of the link. The correlation calculation is based on the Pearson correlation coefficient. A coefficient absolute value greater than 0.7 is considered a strong correlation, a coefficient absolute value between 0.4 and 0.7 is considered a moderate correlation, and a coefficient absolute value less than 0.4 is considered a weak correlation. The matching degree evaluation uses the cosine similarity algorithm. A similarity greater than 0.8 is considered a high match, a similarity between 0.5 and 0.8 is considered a moderate match, and a similarity less than 0.5 is considered a low match.

[0135] The risk level classification establishes a four-level risk level system based on the link propagation capability and potential impact. Level 1 risk corresponds to an average link weight greater than 0.8 and involves more than 3 key nodes; Level 2 risk corresponds to an average link weight between 0.6 and 0.8 and involves 2 to 3 key nodes; Level 3 risk corresponds to an average link weight between 0.4 and 0.6 and involves 1 to 2 key nodes; and Level 4 risk corresponds to an average link weight less than 0.4 or no key nodes. Key node identification is based on a comprehensive evaluation of indicators such as node importance score, connectivity, and historical risk frequency. Nodes with an importance score greater than 0.8 and a connectivity greater than 10 are marked as Level 1 key nodes, and nodes with an importance score between 0.6 and 0.8 and a connectivity between 5 and 10 are marked as Level 2 key nodes.

[0136] The propagation range is determined based on the link topology and the impact diffusion model, calculating the spatial and temporal boundaries of risk propagation. The spatial boundary is determined by the influence radius of the link's endpoint nodes, taking into account factors such as node type, connection strength, and physical distance. The influence radius for equipment nodes is set to an adjustable range of 200 to 500 meters; for personnel nodes, it is set to an adjustable range of 50 to 150 meters; for environmental nodes, it is set to an adjustable range of 300 to 800 meters; and for control nodes, it is set to an adjustable range of 100 to 300 meters. The temporal boundary is calculated based on the link propagation delay and the risk diffusion rate. The propagation delay is obtained by statistically analyzing historical data to obtain the average value and standard deviation, and the diffusion rate is determined by a correction factor based on the risk type and environmental conditions.

[0137] The early warning response rules establish a decision matrix based on risk level and spread range. The decision matrix has a 4×4 structure, with row indices representing risk levels and column indices representing spread range levels. Matrix elements are early warning response strategy codes. Level 1 risk with widespread spread corresponds to an immediate response strategy, with a response time limit of 5 minutes and the highest response level, involving measures such as personnel evacuation, equipment shutdown, and emergency coordination. Level 2 risk with moderate spread corresponds to a rapid response strategy, with a response time limit of 15 minutes and a high response level, involving measures such as on-site control, equipment inspection, and personnel deployment. Level 3 risk with limited spread corresponds to a standard response strategy, with a response time limit of 30 minutes and a medium response level, involving measures such as status monitoring, preventative maintenance, and personnel alerts.

[0138] The multi-tiered risk threshold system is based on the cascading and cumulative effects of risk propagation, comprising three levels: node-level thresholds, link-level thresholds, and region-level thresholds. Node-level thresholds are set based on the degree of abnormality of a single node's status; a deviation of two standard deviations from the normal range triggers a node warning, and a deviation of three standard deviations triggers a node alarm. Link-level thresholds are set based on the proportion of abnormal nodes and the propagation speed within a link; a proportion of abnormal nodes exceeding 30% or a propagation speed exceeding 1.5 times the average triggers a link warning, and a proportion exceeding 50% or a propagation speed exceeding twice the average triggers a link alarm. Region-level thresholds are set based on the number of active links and risk density within a region; an active link exceeding 40% of the total number of links in the region or a risk density exceeding 0.6 triggers a region-wide warning.

[0139] The dynamic adjustment mechanism updates threshold parameters in real time based on the spatiotemporal evolution characteristics of risk propagation. Temporal evolution characteristics include dimensions such as risk development speed, duration, and periodicity; spatial evolution characteristics include dimensions such as propagation direction, diffusion range, and aggregation degree. Risk development speed is calculated using the risk level change rate over a continuous time window. A change rate exceeding 0.2 per hour is considered rapid development, a change rate between 0.1 and 0.2 is considered moderate development, and a change rate less than 0.1 is considered slow development. In cases of rapid development, the threshold is lowered by 20% to increase sensitivity; in cases of slow development, the threshold is raised by 10% to reduce false alarms. Duration is used to track the length of time a risk remains at a high level; for long-term risks exceeding 2 hours, the threshold is raised by 15% to avoid fatigue warnings.

[0140] The propagation direction analysis calculates the dominant direction of risk propagation based on the spatial coordinates and temporal activation sequence of link nodes. The propagation direction is represented by angles ranging from 0 to 360 degrees with a precision of 1 degree. Propagation direction stability is assessed using the standard deviation of the direction vector; a standard deviation less than 30 degrees indicates a stable direction, while a standard deviation exceeding 60 degrees indicates a scattered direction. The risk propagation threshold for stable directions is adjusted based on the statistical characteristics of historical cases propagating in the same direction; the threshold for scattered directions remains at its default setting to avoid over-adjustment. The rate of change in the diffusion range is calculated through the change in the radius of influence at continuous time points. A rate of change greater than 1.2 per hour indicates rapid diffusion, while a rate of change less than 0.8 per hour indicates a contraction trend. In cases of rapid diffusion, the regional threshold is reduced by 25%.

[0141] The differentiated early warning strategy generation system establishes a strategy template library based on factors such as risk type, propagation characteristics, and scope of impact. Each template includes elements such as early warning level, response time, response measures, resource allocation, and coordination mechanisms. Early warning levels are divided into four levels: alert, warning, alarm, and emergency. The alert level corresponds to low-risk, low-impact scenarios; the warning level corresponds to medium-risk or locally impactful scenarios; the alarm level corresponds to high-risk or widely impactful scenarios; and the emergency level corresponds to extremely high-risk or globally impactful scenarios. Response time allocation is determined based on the early warning level and the urgency of propagation: 60 minutes for the alert level, 30 minutes for the warning level, 15 minutes for the alarm level, and 5 minutes for the emergency level.

[0142] Differentiated response measures are implemented based on the type of risk source and the characteristics of its propagation path. For equipment failure risks, measures include equipment isolation, backup startup, and maintenance dispatch. For personnel violation risks, measures include personnel interviews, access restrictions, and enhanced training. For environmental anomaly risks, measures include environmental regulation, enhanced monitoring, and upgraded protection. For control failure risks, measures include manual takeover, logic reset, and system switching. Resource allocation optimization is based on historical response experience and dynamic allocation of current resources. Human resource allocation considers the matching degree of professional skills and geographical convenience, while equipment resource allocation considers the suitability of equipment performance and the cost-effectiveness of scheduling.

[0143] The early warning information generation module constructs structured early warning messages based on differentiated early warning strategies and early warning response rules. Each message includes fields such as a unique identifier, generation time, risk level, impact range, warning content, handling recommendations, response time limit, and contact information. The unique identifier is generated using a combination of timestamp and random number to ensure global uniqueness and traceability. The risk level is represented by both numerical and textual data, with numerical values ​​ranging from 1 to 4 corresponding to textual descriptions of low, medium, high, and extremely high. The impact range is represented by geographic coordinates and an impact radius, with coordinate accuracy at the meter level and impact radius accuracy at 10-meter levels. The early warning content is generated using a template, with template variables dynamically populated fields including risk type, location of occurrence, consequences, and urgency.

[0144] The emergency response process is recorded using a full lifecycle tracking mechanism, meticulously documenting the entire process from warning triggering to risk elimination. The data structure includes fields such as response stage, personnel involved, start time, end time, implemented measures, resource consumption, and intermediate results. The response stage is divided into five standard phases: reception confirmation, on-site response, measure execution, effect evaluation, and resource recovery. Each phase records detailed timelines and key events. Personnel information includes identification attributes such as personnel number, name, position, professional skills, and contact information. Implementation measures are recorded using structured coding, with standardized storage of information such as measure type, specific content, execution parameters, and quality standards.

[0145] The actual effectiveness of the response is evaluated using a framework that combines quantitative indicators with qualitative assessments. Quantitative indicators include measurable dimensions such as risk elimination time, resource consumption costs, impact range control, and personnel safety. Risk elimination time is the total time from warning triggering to the risk level decreasing to a safe level, with minute-level precision; the target control time is determined based on the risk level. Resource consumption costs include a comprehensive calculation of labor costs, equipment costs, material costs, and opportunity costs; cost accounting is based on standardized unit prices and actual consumption. The effectiveness of impact range control is assessed by the ratio of the final impact range to the expected impact range; a ratio less than 1.0 indicates effective control, while a ratio greater than 1.5 indicates control failure.

[0146] The time-series matching algorithm performs precise matching based on the timestamps of the warning information and the optimized data, with a matching accuracy at the minute level. The matching time window is set to a 30-minute range before and after the warning is triggered. The matching rule is based on the nearest neighbor principle, finding the closest handling record and effect evaluation for each warning information. For many-to-one matching, a time distance-weighted average method is used to merge handling data; for one-to-many matching, the record with the best handling effect is selected as the matching result. The matching quality is evaluated based on dimensions such as time interval, content relevance, and logical consistency. Matches with a time interval of less than 10 minutes and a content relevance greater than 0.8 are considered of excellent quality.

[0147] The accuracy rate of early warnings is calculated based on the confusion matrix to statistically analyze the hit rate of early warnings. The accuracy rate equals the number of correct early warnings divided by the total number of early warnings. The calculation period is weekly, with a target accuracy rate of over 85%. The false positive rate is the proportion of false alarms to total early warnings, with a target false positive rate below 10%. The false negative rate is the proportion of missed risks to actual risks, with a target false negative rate below 5%. The effectiveness of response is evaluated based on comprehensive indicators such as risk elimination efficiency, resource utilization efficiency, and secondary risk control. Risk elimination efficiency is the ratio of actual elimination time to standard elimination time, and resource utilization efficiency is the ratio of standard resource consumption to actual resource consumption.

[0148] The early warning response rules are improved through targeted optimization based on accuracy and effectiveness analysis results. For early warning types with an accuracy rate below 80%, threshold parameters are recalibrated, and response measures with an effectiveness rate below 75% are redesigned with new handling procedures. Rule improvement employs machine learning methods to mine optimization patterns from historical data. Feature engineering extracts multi-dimensional variables such as risk features, handling features, and effect features. The random forest algorithm is used to build the rule optimization model for model training. Model validation uses cross-validation to evaluate the optimization effect, with a validation accuracy target of over 90%.

[0149] Emergency management practice experience mining involves in-depth analysis of historical response cases in different regions. Regional division is based on a regional labeling system established according to dimensions such as geographical location, industry type, and risk characteristics. The experience extraction algorithm employs association rule mining to identify the correlation patterns between response measures and their effects, with a support threshold set at 0.1, a confidence threshold at 0.7, and a lift threshold at 1.2. Experience knowledge is represented and stored in a rule base, with rules containing elements such as preconditions, actions, and expected results. Rule priority is determined based on historical validation results.

[0150] A second aspect of the present invention provides a real-time identification system for mine anomaly events based on time-series features, comprising:

[0151] The acquisition unit is used to acquire multimodal monitoring data collected by distributed sensors in the mine, perform spatiotemporal alignment and semantic annotation on the multimodal monitoring data, analyze and identify safety element entities and their attribute features, and construct a temporal knowledge graph based on the safety element entities and their attribute features.

[0152] The analysis unit is used to establish the association mapping between entities in the time-series knowledge graph and calculate the dynamic association weight between entities under different time windows; based on the dynamic association weight, the propagation path of security risks is analyzed to obtain a set of risk propagation links;

[0153] The prediction unit is used to calculate the risk development trend for each link in the risk propagation link set through recursive calculation, and predict the risk situation in future time steps based on the historical evolution law in the time series knowledge graph, and generate risk prediction results.

[0154] The optimization unit is used to dynamically generate differentiated early warning strategies based on the correlation between the risk prediction results and the risk propagation chain; at the same time, it establishes a closed-loop tracking system for early warning response, incorporates early warning results, handling process and actual effect into the decision-making basis for system optimization, and forms a continuously optimized early warning and emergency management ecosystem by deeply mining the emergency management practice experience of various regions.

[0155] A third aspect of the present invention provides an electronic device, comprising:

[0156] processor;

[0157] Memory used to store processor-executable instructions;

[0158] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.

[0159] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.

[0160] This invention can be a method, apparatus, system, and / or computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for performing various aspects of the invention.

[0161] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for real-time identification of abnormal events in mines based on time-series features, characterized in that, include: Acquire multimodal monitoring data collected by distributed sensors in the mine, perform spatiotemporal alignment and semantic annotation on the multimodal monitoring data, analyze and identify safety element entities and their attribute features, and construct a temporal knowledge graph based on the safety element entities and attribute features, including: The data streams of different modes in the multimodal monitoring data are time-series calibrated according to timestamps, and the data collected from different spatial nodes are spatially registered based on the spatial location mapping relationship to obtain a unified data representation after spatiotemporal alignment. The data items in the unified data representation are semantically parsed using a pre-trained domain knowledge base and ontology model to identify the entity type, relationship type between entities, and entity attributes corresponding to the data items. The accuracy of the annotation results is ensured through consistency verification and conflict resolution, resulting in normalized data after semantic annotation. Security element entities are identified from the normalized data after semantic annotation, and based on the entity type, the relationship type between entities and the entity attributes, the corresponding static attribute features and dynamic behavior features are extracted for each security element entity to construct an entity-feature mapping set. An initial temporal knowledge graph is constructed based on the security element entities and their corresponding entity-feature mapping sets. The topological integrity of the initial temporal knowledge graph is verified by using the relationship types between entities. Isolated nodes and broken paths in the graph are identified. Missing entity relationships are filled in by combining relationship reasoning rules, and finally a complete temporal knowledge graph is formed. Establish an association mapping between entities in the time-series knowledge graph and calculate the dynamic association weights between entities under different time windows; The propagation path of security risks is analyzed based on the dynamic association weights to obtain a set of risk propagation links; For each link in the risk propagation link set, the risk development trend is calculated recursively, and based on the historical evolution patterns in the time-series knowledge graph, the risk situation at future time steps is predicted, generating risk prediction results, including: For each link in the risk propagation link set, a state transition matrix is ​​constructed based on the weight relationship between adjacent nodes in the link, and a state transition probability distribution is trained by combining the historical state sequence of the nodes. The development trend value and trend confidence of the risk on the corresponding link are obtained through the recursive operation of chain conditional probability. For each node, its sensitivity coefficient in the link propagation process is calculated, and the development trend value is optimized based on the sensitivity coefficient to obtain an optimized trend value that takes into account the degree of influence of the node. In the time-series knowledge graph, identify historical propagation paths and their evolutionary characteristics that are similar to the corresponding links; calculate the structural similarity and state similarity between the current link and the historical paths; and determine the evolutionary contribution of each historical path based on the structural similarity and the state similarity. Construct the evolutionary rules of historical paths based on the evolutionary contributions; integrate the optimization trend value with the evolutionary rules; and combine the trend confidence to predict the risk situation in future time steps, generating risk prediction results. Based on the correlation between the risk prediction results and the risk propagation chain, a differentiated early warning strategy is dynamically generated; At the same time, a closed-loop tracking system for early warning response will be established, incorporating early warning results, handling processes, and actual effects into the decision-making basis for system optimization. Furthermore, by deeply exploring the practical experience of emergency management in various regions, a continuously optimized early warning and emergency management ecosystem will be formed.

2. The method according to claim 1, characterized in that, An initial temporal knowledge graph is constructed based on the security element entities and their corresponding entity-feature mapping sets. The topological integrity of the initial temporal knowledge graph is verified using the entity relationship types, identifying isolated nodes and broken paths in the graph, including: The security element entities are treated as a set of nodes, and an attribute vector is assigned to each node based on the entity-feature mapping set; Based on the types of relationships between entities, a set of directed edges between nodes is constructed, and a relationship strength metric and temporal evolution constraints are attached to each directed edge; The set of nodes, the attribute vectors, and the set of directed edges are combined to form the topological structure of the initial temporal knowledge graph; The initial temporal knowledge graph is subjected to topological integrity verification. The in-degree and out-degree of each node are calculated by traversing the set of directed edges. Nodes with both in-degree and out-degree of zero are identified as isolated nodes. Broken paths caused by the lack of necessary intermediate nodes are detected by path connectivity analysis. For isolated nodes identified in the topology integrity verification, potential associations are queried in the domain ontology model based on the entity relationship type, and association edges are added to the isolated nodes according to the query results to eliminate the isolated state; For the broken paths identified in the topological integrity verification, the semantic correlation between the starting point and the ending point of the path is analyzed, and the missing intermediate entities and their correlations are inferred using relational reasoning rules. The broken paths are then completed in the initial temporal knowledge graph.

3. The method according to claim 1, characterized in that, Establish an association mapping between entities in the time-series knowledge graph and calculate the dynamic association weights between entities under different time windows; Based on the dynamic correlation weights, the propagation path of security risks is analyzed, resulting in a set of risk propagation links including: Entity nodes and their edge relationships are extracted from the temporal knowledge graph. An association mapping matrix between entities is established based on semantic type and directionality. For different time windows, the dynamic association weight matrix between entities is calculated through a time-aware graph attention mechanism based on the state change sequence of entities within the time window and the causal dependency between entities. Based on the dynamic association weight matrix, the corresponding entity pairs in the association mapping matrix are weighted and assigned weights, and the entity nodes, the edge relationships and their weights are combined to form a weighted graph structure associated with a time window. In the weighted graph structure, the identified risk source node is selected as the starting point. Edges with weights exceeding the preset propagation threshold are filtered based on dynamic association weights. The propagation trajectory of risk from the source node to the downstream node is tracked by a path search strategy that combines breadth-first traversal and depth-first traversal. Multiple paths involved in the propagation trajectory are aggregated and deduplicated to finally obtain a set of risk propagation links.

4. The method according to claim 3, characterized in that, A path search strategy combining breadth-first search and depth-first search is used to track the propagation trajectory of risk from the source node to downstream nodes, and the multiple paths involved in the propagation trajectory are aggregated and deduplicated, including: The path search strategy combining breadth-first traversal and depth-first traversal is used to track the propagation trajectory of risk from the source node to the downstream node. The breadth-first traversal is based on the node queue, which visits all adjacent nodes of each level in turn to construct the propagation range of risk in the current level and obtain the node set of each level. The depth-first traversal is based on the node stack, which continuously explores the vertical extension direction of a single path along the weighted edge until the propagation termination condition is met, thus obtaining the node sequence of each extension path. Based on the node sequence, in each iteration, the breadth-first traversal is first executed to determine the hierarchical propagation range, the depth-first traversal is executed to explore the extension path of each node, the propagation trajectory is integrated, and multiple paths involved in the propagation trajectory are aggregated and deduplicated.

5. The method according to claim 1, characterized in that, Establish a closed-loop tracking system for early warning response, incorporating early warning results, handling processes, and actual effects into the decision-making basis for system optimization. Furthermore, by deeply exploring the practical experience of emergency management in various regions, a continuously optimized early warning and emergency management ecosystem will be formed, including: Establish a closed-loop tracking system for early warning response. For each early warning event, construct a time-series feature sequence. Record the early warning trigger time, response timeliness, and response level as the early warning result. Record the personnel configuration, emergency resource scheduling, and response steps as the response process. Record the degree of risk elimination, target recovery status, and subsequent monitoring data as the actual effect. Establish a correlation mapping between the early warning result, the response process, and the actual effect based on the time-series feature sequence to form a closed-loop data link. Historical early warning events are extracted from the closed-loop data link and grouped according to regional attributes and early warning type. Timeliness indicators and effectiveness evaluation indicators are calculated for the early warning response data in each group. Highly efficient handling cases with the highest effectiveness evaluation indicators are selected. Based on the highly efficient handling cases, the early warning response links are analyzed, and the combination patterns of the handling steps and the configuration characteristics of the emergency resource scheduling are explored. The early warning results, the handling process, and the actual effects are used as the decision-making basis for system optimization. By deeply exploring the practical experience of emergency management in various regions, we can identify the differences in regional early warning responses from the decision-making basis, extract optimization directions for response plans adapted to each region, continuously improve early warning response strategies, and form a continuously optimized early warning and emergency management ecosystem.

6. A real-time identification system for mine anomaly events based on time-series features, used to implement the method of any one of claims 1-5, characterized in that, include: The acquisition unit is used to acquire multimodal monitoring data collected by distributed sensors in the mine, perform spatiotemporal alignment and semantic annotation on the multimodal monitoring data, analyze and identify safety element entities and their attribute features, and construct a temporal knowledge graph based on the safety element entities and their attribute features. The analysis unit is used to establish the association mapping between entities in the time-series knowledge graph and to calculate the dynamic association weight between entities under different time windows; The propagation path of security risks is analyzed based on the dynamic association weights to obtain a set of risk propagation links; The prediction unit is used to calculate the risk development trend for each link in the risk propagation link set through recursive calculation, and predict the risk situation in future time steps based on the historical evolution law in the time series knowledge graph, and generate risk prediction results. The optimization unit is used to dynamically generate differentiated early warning strategies based on the correlation between the risk prediction results and the risk propagation chain. At the same time, a closed-loop tracking system for early warning response will be established, incorporating early warning results, handling processes, and actual effects into the decision-making basis for system optimization. Furthermore, by deeply exploring the practical experience of emergency management in various regions, a continuously optimized early warning and emergency management ecosystem will be formed.

7. An electronic device, characterized in that, include: processor; Memory used to store processor-executable instructions; The processor is configured to invoke instructions stored in the memory to execute the method according to any one of claims 1 to 5.

8. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, they implement the method described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Mine ventilation dynamic regulation and control method and system based on space-time diagram convolutional network

    CN120234746A

  • Mine ecological risk prediction method and system based on artificial intelligence

    CN120278532A