Railway freight yard abnormity alarm method and system based on multi-source data fusion
By integrating multi-source data and dynamic reliability assessment, and combining the response behavior of on-duty personnel, the railway freight yard safety monitoring system effectively identifies complex anomalies, reduces false alarm rates, improves alarm accuracy and response efficiency, and optimizes the human-computer interaction experience.
Patent Information
- Application Number
- CN202511892355.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-16
- Publication Date
- 2026-02-10
AI Technical Summary
Existing railway freight yard safety monitoring systems are susceptible to environmental interference, minor equipment defects, and human judgment biases in complex industrial environments, resulting in high false alarm rates, high risk of missed alarms, and difficulty in effectively identifying complex anomalies.
By using multi-source data fusion technology, raw data from various monitoring devices is collected, analyzed in real time, and initially assessed for reliability. Combined with data on the response behavior of on-duty personnel, alarm strategies are dynamically adjusted, novel composite disturbance patterns are identified and triggered for in-depth verification, and the system's learning and updates are optimized.
It significantly improves the accuracy and response efficiency of railway freight yard anomaly alarms, reduces false alarm rate, enhances attention to real threats, reduces the burden on duty personnel, and optimizes human-computer interaction experience.
Smart Images

Figure CN121505803A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of railway freight yard safety monitoring technology, and more specifically, to a railway freight yard anomaly alarm method and system based on multi-source data fusion. Background Technology
[0002] In the field of railway freight yard security monitoring, traditional solutions mainly rely on various independently operating monitoring devices, such as high-definition video cameras, perimeter vibration-damping fiber optic cables, and RFID systems, to identify anomalies through the analysis of a single data source. However, in the complex industrial environment, this single-data-source analysis model faces severe challenges. A typical problem is the interaction between minor equipment defects and environmental factors. For example, after a camera housing is slightly dented by a gravel impact, rainwater will linger at the dent, forming dynamically changing droplets. These droplets, under light, will produce continuously changing reflective points, and the changes in pixel intensity and pattern are sufficient to trigger the motion detection threshold of the video analysis system, causing the system to misjudge optical interference as abnormal moving targets. Similarly, after long-term burial, the junction box of the vibration-damping fiber optic cable system may experience a decline in sealing, allowing rainwater to seep in and alter the dielectric properties of the local circuitry, introducing low-amplitude background noise into the vibration signal and reducing the system's ability to identify genuine, weak intrusion signals.
[0003] Furthermore, the unique physical environment of railway freight yards presents new challenges. The large stacks of metal containers severely shield RFID signals; even when tags are damaged, causing signal anomalies, the system often attributes this to normal signal attenuation. This complex interference, resulting from environmental factors, minor equipment defects, and physical shielding, is difficult to distinguish effectively using traditional single-data-source judgment criteria, leading to a continuous stream of low-confidence false alarms. More seriously, a large number of false alarms can trigger "alarm fatigue" among on-duty personnel. Faced with repetitive, non-threatening alarms, on-duty personnel subconsciously lower alarm priority, slow down processing, and even categorize alarms as routine interference. This human judgment bias and system defects create a vicious cycle, providing opportunities for intruders. When intruders exploit the complex lighting conditions at night, the system is limited by its own detection capabilities and struggles to effectively identify genuine threats due to decreased vigilance among on-duty personnel.
[0004] Therefore, existing technologies lack the ability to intelligently identify complex interferences and cannot effectively cope with complex abnormal situations caused by the combined effects of environmental factors, equipment defects, human judgment bias, and physical shielding. Summary of the Invention
[0005] To address the shortcomings of existing technologies, this application provides a railway freight yard anomaly alarm method and system based on multi-source data fusion. This addresses the technical problems of railway freight yards in complex industrial environments, where the independent alarm capability of a single monitoring system is limited, and the system is susceptible to environmental interference, minor equipment defects, human alarm fatigue, and physical obstruction, resulting in high false alarm rates, high risk of missed alarms, and difficulty in effectively identifying complex and compound anomalies.
[0006] Firstly, this application provides a railway freight yard anomaly alarm method based on multi-source data fusion, including: We continuously collect raw data from various types of monitoring equipment in the railway freight yard and perform real-time analysis on the raw data, initially classifying it into multiple independent abnormal signals. An initial confidence score is obtained by performing an initial confidence assessment on each independent anomalous signal, and the initial confidence score is adjusted based on the interference characteristics acquired in real time, auxiliary environmental data, and cross-sensor correlation. Record the response behavior data of the on-duty personnel to each abnormal alarm, and analyze the alarm fatigue status of the on-duty personnel based on the response behavior data; Based on the adjusted initial confidence score and alarm fatigue status, the presentation strategy for abnormal alarms is dynamically adjusted. This presentation strategy includes: for individual abnormal signals whose adjusted initial confidence score is lower than the preset confidence score, reducing their alarm priority or automatically filtering them; for individual abnormal signals whose adjusted initial confidence score is not lower than the preset confidence score, increasing their alarm attention; and when the on-duty personnel are in an alarm fatigue state, increasing the duration or repetition frequency of the alarm and requiring the on-duty personnel to confirm.
[0007] The above solution enables in-depth fusion analysis of multi-source data. By combining alarm credibility with the fatigue status of on-duty personnel, the alarm presentation strategy can be dynamically adjusted, effectively reducing the interference of false alarms on on-duty personnel and increasing attention to real threats. This overcomes the limitations of alarms from a single data source and significantly improves the accuracy and response efficiency of anomaly alarms in railway freight yards.
[0008] Furthermore, the method also includes: Extract time, space, and feature vector information from the raw data to form atomic event feature vectors; The similarity between the atomic event feature vector and the known environmental interference features in the preset environmental interference feature library is calculated. If the similarity between the atomic event feature vector and all known environmental interference features is lower than the novelty judgment threshold, it is initially marked as a candidate novel mode. If the atomic event feature vectors constituting a candidate novel mode have a correlation in time or space below a preset correlation threshold, then they are ultimately marked as a novel composite perturbation mode. When a novel composite disturbance pattern is identified, a deep verification process is triggered, guiding on-duty personnel to conduct a deep verification.
[0009] Based on the above, this application also proposes that when a novel composite disturbance pattern is identified, the steps to trigger a deep verification process and guide on-duty personnel to conduct a deep verification include: Show the on-duty personnel the raw time-series data charts and video playbacks of the associated sensors and provide a structured checklist. The on-duty personnel are required to compare each item and submit the check results. The on-duty personnel's check behavior data is continuously monitored. Based on the check behavior data and the preset behavior reference standards, the on-duty personnel's dependence index is calculated. When the verification result is a false alarm, the suppression tendency of the novel composite perturbation mode is gradually increased and its initial confidence score is decreased; when the verification result is a true alarm, the suppression tendency of the novel composite perturbation mode is decreased and its initial confidence score is increased. When a novel composite disturbance pattern is consistently marked as a false alarm by multiple duty personnel whose dependency index is lower than a preset dependency threshold within a preset time, and its atomic event feature vector is lower than a preset stability value, the novel composite disturbance pattern is added to the environmental disturbance feature library.
[0010] In some preferred embodiments, when the verification result is a false alarm, the following steps are performed: When the verification result is a false alarm and the dependency index is higher than the preset dependency threshold, the reverse verification process is triggered. The reverse verification process includes multi-person cross-validation and high-risk deviation alerts; Multi-person cross-validation involves pushing unprocessed alarm instances similar to novel composite perturbation patterns to another on-duty personnel with a dependency index below a preset dependency threshold for in-depth verification, thus obtaining secondary verification results; High-risk deviation alerts include mandatory notification of security experts to intervene when the results of the initial verification are inconsistent with the results of the secondary verification.
[0011] Based on the above, this application further proposes that when the verification result is true, the following steps be performed: The atomic event feature vectors of novel composite perturbation patterns that are confirmed as true reports are continuously analyzed and compared with all templates in the pre-set intrusion imitation behavior sequence template library to calculate the potential imitation index. When the potential imitation index reaches the preset imitation threshold, the novel composite perturbation pattern is marked as a suspected evolutionary imitation behavior, the preset highest level alarm is activated, and the original data, analysis results, and potential imitation index of the novel composite perturbation pattern are pushed to security experts for manual review. Based on the results of manual review, suspected evolving imitation behaviors are added to the preset intrusion imitation behavior sequence template library as new intrusion imitation behavior sequence templates or variations of existing templates. All intrusion imitation behavior sequence templates in the template library are periodically updated adaptively.
[0012] In one implementation, the response behavior data includes the response time of the on-duty personnel and the final processing result of the on-duty personnel on the alarm; The steps for analyzing the alarm fatigue status of on-duty personnel based on response behavior data include: For alarms with a confidence level below the preset level, if the proportion of false alarms exceeds the preset false alarm threshold and the response time exceeds the preset first response time, the alarm is judged to be in a state of fatigue. For alarms that are not below the preset confidence level, if the final processing result is that the frequency of verification operations is lower than the preset verification threshold or the response time exceeds the preset second response time, it is judged to be an alarm fatigue state.
[0013] In another implementation, for a single abnormal signal whose adjusted initial confidence score is lower than the preset confidence score, the priority of its alarm is reduced or it is automatically filtered, including: displaying the alarm text information in an auxiliary area with a soft color, without emitting an audible alarm or popping up a forced window; when the same sensor triggers multiple false alarms with a confidence score lower than the preset confidence score within a preset monitoring time and there is no other sensor to corroborate it, an alarm filtering record is only generated in the background and not presented to the on-duty personnel. For a single abnormal signal whose adjusted initial confidence score is not lower than the preset confidence score, the attention given to its alarm is increased by: when it is detected that the duty personnel are in a state of alarm fatigue, the alarm text information and monitoring screen are forcibly presented by means of full-screen flashing, highlighting, or voice prompt, and the duty personnel are required to confirm within a preset confirmation time.
[0014] Based on the above, this application further proposes that, after the initial classification into multiple independent abnormal signals, the following steps are included: Atomic anomaly features are extracted from independent anomaly signals and their credibility scores are calculated. The spatiotemporal and logical correlations between atomic anomaly features are identified through the event chain causal reasoning engine to form a composite anomaly event chain and its comprehensive credibility is calculated. When the comprehensive credibility of the composite anomaly event chain reaches the preset alarm threshold, a preset level alarm is triggered.
[0015] More specifically, in some implementation schemes, atomic anomaly features include timestamps and geographic coordinates; Identifying the spatiotemporal and logical correlations between atomic anomaly features through the event chain causal reasoning engine includes: the event chain causal reasoning engine examines the correlation between atomic anomaly features on timestamps and geographic coordinates based on preset causal rules, which include feature co-occurrence patterns, temporal correlations, and spatial proximity conditions; When calculating the overall credibility of a complex chain of anomalous events, a weighted calculation is performed based on the credibility scores of each atomic anomalous feature and the weights of preset causal rules.
[0016] Secondly, this application proposes a railway freight yard anomaly alarm system based on multi-source data fusion, used to execute the above-mentioned hoist opening stroke data processing method. The system includes: The data collection and processing module is used to continuously collect raw data from various types of monitoring equipment in the railway freight yard, and to perform real-time analysis on the raw data, initially classifying it into multiple independent abnormal signals. The initial credibility assessment module is used to perform an initial credibility assessment on each independent anomalous signal, obtain an initial credibility score, and adjust the initial credibility score based on the real-time acquired interference characteristics, auxiliary environmental data, and cross-sensor correlation. The response analysis module is used to record the response behavior data of the on-duty personnel to each abnormal alarm, and to analyze the alarm fatigue status of the on-duty personnel based on the response behavior data; The alarm presentation strategy adjustment module is used to dynamically adjust the presentation strategy of abnormal alarms based on the adjusted initial confidence score and alarm fatigue state. The presentation strategy includes: reducing the alarm priority or automatically filtering a single abnormal signal whose adjusted initial confidence score is lower than the preset confidence score; increasing the alarm attention of a single abnormal signal whose adjusted initial confidence score is not lower than the preset confidence score; and increasing the alarm duration or repetition frequency when the on-duty personnel are in an alarm fatigue state, and requiring the on-duty personnel to confirm.
[0017] In summary, this application provides a method and system for anomaly alarm in railway freight yards based on multi-source data fusion. The method continuously collects and analyzes raw data from multiple monitoring devices in real time, initially classifying them into independent anomaly signals and performing an initial confidence assessment on these signals. Based on this, the method dynamically adjusts the initial confidence score according to real-time acquired interference characteristics, auxiliary environmental data, and cross-sensor correlations. This effectively addresses the problem of false alarms from a single data source caused by environmental factors (such as rain and shadows) and minor equipment defects (such as damage to camera housings and water leakage in junction boxes), significantly improving the accuracy of anomaly signal identification. Attached Figure Description
[0018] Figure 1This is a flowchart illustrating a railway freight yard anomaly alarm method based on multi-source data fusion, provided as an embodiment of this application.
[0019] Figure 2 This is a schematic diagram of the structure of a railway freight yard anomaly alarm system based on multi-source data fusion, provided as an embodiment of this application.
[0020] Labeling Explanation: 210, Data Collection and Processing Module; 220, Initial Credibility Assessment Module; 230, Response Analysis Module; 240, Alarm Presentation Strategy Adjustment Module. Detailed Implementation
[0021] The technical solutions of this application will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this application, and not all embodiments. The components of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0022] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0023] Traditional railway freight yard security monitoring systems often struggle to distinguish between genuine anomalies and false alarms when faced with complex environmental interference, minor equipment defects, and operator fatigue. This results in a high false alarm rate, reducing operator vigilance and potentially masking actual intrusion events. These systems typically rely on a single data source for judgment, lacking the ability to integrate and analyze multi-source information and failing to adequately consider the impact of human factors on alarm processing efficiency, thus creating significant vulnerabilities in the overall security protection system.
[0024] Firstly, referring to Figure 1 This application proposes a method for alarming anomalies in railway freight yards based on multi-source data fusion, including: S1. Continuously collect raw data from various types of monitoring equipment in the railway freight yard, and perform real-time analysis on the raw data, initially classifying it into multiple independent abnormal signals; S2. Perform an initial confidence assessment on each independent anomalous signal to obtain an initial confidence score, and adjust the initial confidence score based on the real-time acquired interference characteristics, auxiliary environmental data, and cross-sensor correlation. S3. Record the response behavior data of the on-duty personnel to each abnormal alarm, and analyze the alarm fatigue status of the on-duty personnel based on the response behavior data; S4. Based on the adjusted initial confidence score and alarm fatigue state, dynamically adjust the presentation strategy of abnormal alarms. The presentation strategy includes: for a single abnormal signal whose adjusted initial confidence score is lower than the preset confidence score, reduce its alarm priority or perform automatic filtering; for a single abnormal signal whose adjusted initial confidence score is not lower than the preset confidence score, increase its alarm attention; when the on-duty personnel are in an alarm fatigue state, increase the duration or repetition frequency of the alarm and require the on-duty personnel to confirm.
[0025] Raw data refers to the unprocessed initial information stream directly obtained from various monitoring devices, such as video streams, vibration signals, and RFID tag data. Independent anomaly signals refer to discrete events or data patterns that may indicate abnormal situations, identified through preliminary analysis of a single raw data source.
[0026] Initial credibility assessment refers to making a preliminary reliability judgment on each independent anomalous signal, assigning it a quantified initial credibility score, which reflects the likelihood that the signal is a genuine anomaly. Interference characteristics refer to environmental or equipment factors that may lead to false alarms, such as rain, changes in light, and equipment aging. Auxiliary environmental data can include weather information, yard operation plans, and equipment operating status, providing contextual information for judging anomalous signals. Cross-sensor correlation refers to the mutual corroboration relationship between data from different types of sensors in time, space, or logic; for example, the spatiotemporal consistency between personnel movement detected by video surveillance and abnormal vibration detected by perimeter vibration fiber optic cables.
[0027] Response behavior data refers to the operational records generated by on-duty personnel when handling alarms, including response time and processing results (such as confirmation, ignoring, false alarm marking, etc.). Alarm fatigue refers to the psychological and physiological state of on-duty personnel, resulting from prolonged handling of a large number of low-quality or false alarms, leading to decreased vigilance, sluggish reactions, or reduced processing efficiency. Presentation strategy refers to the method and intensity of displaying abnormal alarms to on-duty personnel, including alarm priority, display method, duration, repetition frequency, and whether mandatory confirmation is required.
[0028] The overall working principle of this application lies in constructing an intelligent anomaly alarm closed-loop system. First, by continuously collecting and initially analyzing multi-source raw data, the system can capture potential anomaly information from different dimensions, forming multiple independent anomaly signals. These signals then enter a dynamic reliability assessment process, which considers not only the characteristics of the signal itself but also real-time environmental interference, auxiliary environmental data, and cross-sensor correlations, thereby making a more comprehensive and accurate judgment on the authenticity of each signal and obtaining an adjusted initial reliability score. This step effectively solves the problems of traditional single-data source judgment being susceptible to interference and having a high false alarm rate.
[0029] Simultaneously, the system records and analyzes the response behavior data of on-duty personnel to alarms in parallel to assess their alarm fatigue status in real time. This mechanism overcomes the limitations of traditional systems that only focus on the technical aspects and ignore human factors, providing crucial personnel status information for subsequent alarm presentation strategies.
[0030] Ultimately, the system combines the adjusted initial confidence score with the alarm fatigue level of on-duty personnel to dynamically adjust the presentation strategy for abnormal alarms. For low-confidence signals, the system lowers their alarm priority or performs automatic filtering to avoid invalid alarms interfering with on-duty personnel, thereby reducing alarm fatigue. For high-confidence signals, the system increases their attention to ensure that important alarms are handled promptly and effectively. More importantly, when on-duty personnel are in a state of alarm fatigue, the system proactively increases the duration or repetition frequency of alarms and requires mandatory confirmation to counteract the decreased vigilance caused by fatigue and ensure that critical information is not overlooked.
[0031] Through the synergistic effect of multi-source data fusion, dynamic credibility assessment, alarm fatigue analysis, and intelligent presentation strategies, this application can effectively distinguish between real anomalies and false alarms, reduce the false alarm rate, and improve the accuracy and reliability of alarms. Simultaneously, by perceiving the status of on-duty personnel and adaptively adjusting alarm presentation, this application optimizes the human-computer interaction experience, reduces the burden on on-duty personnel, and significantly improves their response efficiency and vigilance to real threats. This comprehensive solution enables railway freight yards to achieve more efficient, intelligent, and reliable anomaly alarms and security protection when facing complex and ever-changing security threats.
[0032] In this regard, this application further proposes that the above-mentioned method also includes: Extract time, space, and feature vector information from the raw data to form atomic event feature vectors; The similarity between the atomic event feature vector and the known environmental interference features in the preset environmental interference feature library is calculated. If the similarity between the atomic event feature vector and all known environmental interference features is lower than the novelty judgment threshold, it is initially marked as a candidate novel mode. If the atomic event feature vectors constituting a candidate novel mode have a correlation in time or space below a preset correlation threshold, then they are ultimately marked as a novel composite perturbation mode. When a novel composite disturbance pattern is identified, a deep verification process is triggered, guiding on-duty personnel to conduct a deep verification.
[0033] Specifically, temporal, spatial, and feature vector information is extracted from the raw data to form atomic event feature vectors. The raw data can be understood as the raw input stream from various types of monitoring equipment within the railway freight yard (e.g., but not limited to, video surveillance cameras, infrared sensors, radar, acoustic sensors, etc.). Temporal information refers to the precise timestamp of the event, and spatial information refers to the specific geographical coordinates or area identifier of the event. Feature vector information refers to the set of numerical or symbolic values obtained from the raw data through feature extraction algorithms (e.g., image recognition algorithms, motion trajectory analysis algorithms, sound spectrum analysis algorithms, etc.) that characterize the essential attributes of the event. An atomic event feature vector is a relatively independent event description unit with the smallest granularity extracted from a single or local portion of the raw data. Its purpose is to unify heterogeneous raw data into a computable and comparable structured representation, laying the foundation for subsequent pattern recognition.
[0034] Furthermore, the similarity between the atomic event feature vector and known environmental interference features in a pre-defined environmental interference feature library is calculated. The pre-defined environmental interference feature library is a pre-built and continuously updated database that stores a large number of known and common environmental interference events (e.g., wind blowing leaves, rain and snow, small animal activity, normal vehicle or pedestrian traffic). Similarity calculation can employ various mathematical or machine learning methods, such as cosine similarity, Euclidean distance, support vector machine (SVM), or neural network models. Its purpose is to quantify the degree of matching between the current atomic event feature vector and known interference features in the library, thereby distinguishing between normal environmental interference and potential anomalies.
[0035] Based on this, if the similarity between an atomic event feature vector and all known environmental interference features is below the novelty threshold, it is initially marked as a candidate novelty pattern. The novelty threshold is a preset value used to define the lower limit of similarity. When the similarity between an atomic event feature vector and all known environmental interference features is very low, i.e., below the threshold, it indicates that the event may not belong to any known environmental interference, and is therefore initially identified as a candidate novelty pattern that may represent a novelty anomaly. The purpose is to initially screen out potential new events that do not match the existing knowledge base.
[0036] Furthermore, if the feature vectors of multiple atomic events constituting a candidate novel pattern exhibit a temporal or spatial correlation below a preset correlation threshold, they are ultimately labeled as a novel composite perturbation pattern. The preset correlation threshold measures the tightness of multiple candidate novel patterns in the temporal dimension (e.g., time interval between occurrences) or spatial dimension (e.g., geographical distance). Through this spatiotemporal correlation analysis, single, isolated candidate novel patterns can be aggregated to form more structured and complex novel composite perturbation patterns. The aim is to confirm the authenticity and complexity of novel patterns through multi-source, multi-time-point correlation analysis, effectively eliminate misjudgments of single events, and improve the accuracy of novel pattern identification.
[0037] Ultimately, when a novel composite disturbance pattern is identified, a deep verification process is triggered, guiding on-duty personnel to conduct an in-depth review. This deep verification process is a specially designed, more detailed and thorough verification procedure than conventional alarm handling. Because novel composite disturbance patterns are events that the system has not yet identified or classified, it cannot automatically determine their nature; therefore, human intervention is required for high-precision confirmation. Guiding on-duty personnel to conduct in-depth verification means that the system provides necessary information and tools (e.g., raw data from associated sensors, video playback, structured checklists, etc.) to guide on-duty personnel in manually analyzing and confirming the novel composite disturbance pattern. Its purpose is to ensure that these potentially critical but unknown events receive timely and accurate human review, providing a basis for subsequent system learning and updates.
[0038] As a specific implementation, suppose that in a railway freight yard, a previously unrecorded activity of a small drone hovering at low altitude in a specific area suddenly occurs. Traditional alarm systems might misjudge this as ordinary bird activity or sensor malfunction, thus lowering the alarm priority or filtering it out altogether. However, in the solution of this application, raw data from various monitoring devices such as video surveillance and radar are extracted into atomic event feature vectors. When these feature vectors are compared with known features such as bird flight and windblown debris in a preset environmental interference feature library, the similarity is found to be below the novelty judgment threshold, and therefore they are initially marked as candidate novel patterns. As the drone continues to hover in the specific area, multiple sensors will detect these candidate novel patterns within a similar time and space range. There is a spatiotemporal correlation between them below a preset association threshold, and they are ultimately marked as novel composite disturbance patterns. At this time, the system will immediately trigger a deep verification process, showing the on-duty personnel the real-time video of the drone activity, radar trajectory map, and other raw data, and providing a structured verification checklist. By manually verifying the information, on-duty personnel can quickly confirm that this is a novel and potential intrusion and take appropriate countermeasures, thus avoiding the risk of missed detection that may occur with traditional systems.
[0039] In some of the embodiments described above in this application, the system can identify novel composite disturbance patterns and trigger a deep verification process to guide on-duty personnel to conduct verification. However, in its implementation, simply triggering the deep verification process and guiding on-duty personnel to conduct verification may not fully utilize the professional judgment of on-duty personnel to optimize the system's identification capabilities, nor does it provide a complete mechanism for handling verification results, especially feedback on false alarms or true alarms, and how to effectively integrate this feedback into the system's adaptive learning. This may lead to difficulties in continuously improving the system's accuracy in identifying novel patterns, and may even increase alarm fatigue among on-duty personnel due to repeated false alarms.
[0040] In response, this application further proposes the following steps for triggering a deep verification process and guiding on-duty personnel to conduct a deep verification when a novel composite disturbance pattern is identified: Show the on-duty personnel the raw time-series data charts and video playbacks of the associated sensors and provide a structured checklist. The on-duty personnel are required to compare each item and submit the check results. The on-duty personnel's check behavior data is continuously monitored. Based on the check behavior data and the preset behavior reference standards, the on-duty personnel's dependence index is calculated. When the verification result is a false alarm, the suppression tendency of the novel composite perturbation mode is gradually increased and its initial confidence score is decreased; when the verification result is a true alarm, the suppression tendency of the novel composite perturbation mode is decreased and its initial confidence score is increased. When a novel composite disturbance pattern is consistently marked as a false alarm by multiple duty personnel whose dependency index is lower than a preset dependency threshold within a preset time, and its atomic event feature vector is lower than a preset stability value, the novel composite disturbance pattern is added to the environmental disturbance feature library.
[0041] Specifically, when the system identifies a novel composite disturbance pattern, to ensure the comprehensiveness and accuracy of the verification, it displays raw time-series data charts and video playbacks of the sensors associated with the pattern to the on-duty personnel. This allows them to intuitively understand the detailed situation before and after the event. Simultaneously, a structured verification checklist is provided, guiding on-duty personnel to compare anomalies item by item according to preset steps and standards, and submit the verification results. During this process, the system continuously monitors the on-duty personnel's verification behavior data, such as verification duration, number of sensors checked, and operation sequence, and calculates the on-duty personnel's dependence index based on preset behavioral reference standards. This index reflects the degree of reliance on system prompts during the verification process, helping to assess their independent judgment ability and verification quality.
[0042] Based on the verification results submitted by on-duty personnel, the system adaptively adjusts itself. Specifically, when the verification result is a false alarm, the system gradually increases the suppression tendency of the novel composite perturbation pattern and decreases its initial confidence score. This means that the system will be more cautious when encountering similar patterns in the future, reducing the possibility of false alarms. Conversely, when the verification result is a true alarm, the system decreases the suppression tendency of the novel composite perturbation pattern and increases its initial confidence score, thereby enhancing the system's ability to identify and respond to real anomalies. This dynamic adjustment mechanism allows the system to continuously learn and optimize based on human feedback.
[0043] If the verification result is a false alarm, perform the following steps: When the verification result is a false alarm and the dependency index is higher than the preset dependency threshold, the reverse verification process is triggered. The reverse verification process includes multi-person cross-validation and high-risk deviation alerts; Multi-person cross-validation involves pushing unprocessed alarm instances similar to novel composite perturbation patterns to another on-duty personnel with a dependency index below a preset dependency threshold for in-depth verification, thus obtaining secondary verification results; High-risk deviation alerts include mandatory notification of security experts to intervene when the results of the initial verification are inconsistent with the results of the secondary verification.
[0044] Specifically, when a staff member's verification result for a novel composite disturbance pattern is marked as a false alarm, the system will further determine the staff member's dependency index. The dependency index is calculated based on the staff member's verification behavior data and preset behavioral reference standards, and is used to measure the degree of reliance the staff member places on system prompts during the verification process. If the staff member's dependency index is higher than a preset dependency threshold, it indicates that their judgment may have high uncertainty or potential bias. In this case, to ensure the accuracy of the false alarm judgment, the system will trigger a reverse verification process.
[0045] The reverse verification process aims to reduce the risk of false alarms by introducing additional verification mechanisms. This process mainly consists of two components: multi-person cross-validation and high-risk deviation alerts.
[0046] Multi-person cross-validation refers to the system pushing alarm instances that are similar to the novel composite perturbation patterns currently marked as false alarms but have not yet been processed to another on-duty personnel for in-depth verification. These similar alarm instances can be understood as events that are highly similar to the original alarm in terms of time, space, and feature vectors. The dependency index of the selected other on-duty personnel must be below a preset dependency threshold to ensure the high independence and reliability of their verification results. This personnel will then conduct a secondary verification according to the in-depth verification process and submit the secondary verification results.
[0047] Furthermore, the high-risk deviation alarm refers to the system's mandatory notification of security experts to intervene when the initial verification result (false alarm) differs from the secondary verification result. This mandatory notification can include, but is not limited to, sending emergency notifications, popping up high-priority alarm windows, and providing immediate alerts via telephone or SMS, ensuring that security experts can quickly address and intervene. The purpose of security expert intervention is to make a final ruling on the discrepancies in verification results, avoiding potential risks caused by misjudgments.
[0048] When a novel composite perturbation pattern is confirmed as a true report, subsequent alarm processing is primarily optimized by reducing its suppression tendency and increasing its initial credibility score. However, in practical applications, some anomalous behaviors may not be isolated events but rather complex, evolving, or mimicking known intrusion patterns. Simply adjusting the credibility score may fail to identify and effectively respond to such highly threatening evolving mimicry behaviors in a timely manner, thus posing security risks. To address this, this application further proposes a scheme that, when the verification result is a true report, can deeply analyze and identify potential evolving mimicry behaviors to improve the system's perception and response capabilities to complex threats.
[0049] When the verification result is true, perform the following steps: The atomic event feature vectors of novel composite perturbation patterns that are confirmed as true reports are continuously analyzed and compared with all templates in the pre-set intrusion imitation behavior sequence template library to calculate the potential imitation index. When the potential imitation index reaches the preset imitation threshold, the novel composite perturbation pattern is marked as a suspected evolutionary imitation behavior, the preset highest level alarm is activated, and the original data, analysis results, and potential imitation index of the novel composite perturbation pattern are pushed to security experts for manual review. Based on the results of manual review, suspected evolving imitation behaviors are added to the preset intrusion imitation behavior sequence template library as new intrusion imitation behavior sequence templates or variations of existing templates. All intrusion imitation behavior sequence templates in the template library are periodically updated adaptively.
[0050] Specifically, when the deep verification process confirms a novel composite perturbation pattern as a genuine report, the system will no longer simply adjust its confidence score, but will conduct a more in-depth analysis. "Continuously analyzing the atomic event feature vectors of novel composite perturbation patterns confirmed as genuine reports" means that the system will extract and deeply analyze the smallest identifiable unit constituting the genuine report event—the atomic event feature vector. These vectors contain the event's temporal, spatial, and specific characteristic information. The aim is to understand the essence of anomalous behavior at a fine-grained level.
[0051] Furthermore, the atomic event feature vector is compared with all templates in a pre-defined intrusion imitation behavior sequence template library to calculate a potential imitation index. This library stores feature templates of known or historical intrusion behavior patterns, attack chains, or malicious activity sequences. By calculating the similarity or pattern matching between the atomic event feature vector of the current real event and these templates, the similarity between the current event and known intrusion patterns can be quantified, thus obtaining a potential imitation index. This index reflects the likelihood that the current abnormal behavior imitates known intrusion patterns.
[0052] When the potential imitation index reaches a preset imitation threshold, it indicates that the current reported event is highly likely to be an imitation or evolving intrusion behavior. At this point, the system will immediately mark the novel composite perturbation pattern as a suspected evolving imitation behavior and activate the preset highest-level alert to ensure that this high-risk event receives the highest priority attention and handling. Simultaneously, the raw data, analysis results, and potential imitation index of the novel composite perturbation pattern will be pushed to security experts for manual review, enabling them to make professional judgments and decisions based on comprehensive information.
[0053] Ultimately, based on the manual review by security experts, if the suspected evolving imitation behavior is confirmed to be a new intrusion pattern or a variant of an existing pattern, it will be added as a new intrusion imitation behavior sequence template or a variant of an existing template to the preset intrusion imitation behavior sequence template library. This aims to continuously enrich and update the system's threat intelligence database, enabling it to identify more diverse and complex attack patterns. To maintain the effectiveness and timeliness of the template library, the system will also periodically perform adaptive updates to all intrusion imitation behavior sequence templates in the library, ensuring that the templates reflect the latest threat landscape and attack techniques.
[0054] The steps for analyzing the alarm fatigue status of on-duty personnel based on response behavior data include: For alarms with a confidence level below the preset level, if the proportion of false alarms exceeds the preset false alarm threshold and the response time exceeds the preset first response time, the alarm is judged to be in a state of fatigue. For alarms that are not below the preset confidence level, if the final processing result is that the frequency of verification operations is lower than the preset verification threshold or the response time exceeds the preset second response time, it is judged to be an alarm fatigue state.
[0055] Specifically, response behavior data refers to the action data recorded by the system after the on-duty personnel receive an abnormal alarm. Response time refers to the time elapsed from when the alarm is issued to when the on-duty personnel first interact with the alarm (e.g., click to view, confirm, close, etc.). Final processing result refers to the final judgment recorded by the system after the on-duty personnel have processed the alarm, such as false alarm, true alarm, or verification operation.
[0056] Furthermore, the analysis of alarm fatigue is based on this response behavior data. Specifically, for abnormal signals whose initial confidence scores are adjusted to be lower than the preset confidence level, if the proportion of the on-duty personnel marking their final processing results as false alarms exceeds the preset false alarm threshold, and their response time exceeds the preset first response time, the system will determine that the on-duty personnel may be in an alarm fatigue state. This usually occurs when a large number of low-confidence alarms cause on-duty personnel to become complacent, tending to quickly mark them as false alarms, or responding slowly due to the excessive number of alarms.
[0057] On the other hand, for abnormal signals whose initial confidence scores, after adjustment, do not fall below the preset confidence level, if the frequency of verification operations performed by on-duty personnel is lower than the preset verification threshold, or if their response time exceeds the preset second response time, the system will also determine that the on-duty personnel may be in a state of alarm fatigue. This indicates that the on-duty personnel may have decreased attention to important alarms, failed to verify them in a timely or sufficient manner, or become sluggish due to long working hours.
[0058] Specifically, the aforementioned strategy for dynamically adjusting the presentation of abnormal alarms can be further refined to achieve more sophisticated alarm management and interaction with on-duty personnel.
[0059] The above-mentioned measures for reducing the alarm priority or automatically filtering a single abnormal signal whose adjusted initial confidence score is lower than the preset confidence score include: displaying the alarm text information in a soft color in an auxiliary area, without emitting an audible alarm or popping up a forced window; when the same sensor triggers multiple false alarms with a confidence score lower than the preset confidence score within a preset monitoring time and there is no corroboration from other sensors, an alarm filtering record is only generated in the background and not presented to the on-duty personnel. For individual abnormal signals whose adjusted initial confidence score is not lower than the preset confidence score, the above-mentioned measures to increase the attention of their alarms include: when it is detected that the duty personnel are in a state of alarm fatigue, the alarm text information and monitoring screen are forcibly presented by means of full-screen flashing, highlighting, or voice prompts, and the duty personnel are required to confirm within a preset confirmation time.
[0060] Specifically, when the adjusted initial confidence score of an abnormal signal is lower than the preset confidence score, it indicates that the authenticity or importance of the abnormal event is low. In this case, to avoid unnecessary interference with on-duty personnel, the alarm presentation is designed to be low-priority. Specifically, the alarm text information can be displayed in a soft color, such as gray or light blue, in an auxiliary area of the monitoring interface, rather than the main display area. Simultaneously, no sound alarm is emitted, and no mandatory alarm window pops up, to reduce the visual and auditory impact on on-duty personnel. Furthermore, when the same sensor triggers multiple false alarms below the preset confidence score within a preset monitoring time, such as 5 minutes, and no other sensor data can corroborate the authenticity of the abnormal event, the system will determine it as a high-probability false alarm. In this case, the alarm will only generate an alarm filtering record in the background and will not be presented to on-duty personnel, thereby effectively reducing the interference of invalid alarms on on-duty personnel.
[0061] On the other hand, when the adjusted initial confidence score of an abnormal signal is not lower than the preset confidence score, it indicates that the abnormal event has a high degree of authenticity or importance, requiring close attention from on-duty personnel. Especially when on-duty personnel are detected to be in a state of alarm fatigue, the presentation of alarms is designed to be mandatory and highly noticeable to ensure that important alarms are not ignored. Specifically, the alarm text information and associated monitoring screen can be forcibly presented to on-duty personnel through full-screen flashing, highlighting, or voice prompts. For example, the screen can flash periodically, the alarm text can be highlighted in a striking red, or an alarm can be issued through a pre-recorded voice prompt. Simultaneously, the system will require on-duty personnel to confirm the alarm within a preset confirmation time, such as 30 seconds, to ensure that they have noticed and addressed the important alarm. This measure aims to overcome the problem of alarm neglect that may occur due to on-duty personnel fatigue, ensuring that critical abnormal events are responded to promptly.
[0062] In some embodiments described above, this application proposes a railway freight yard anomaly alarm method based on multi-source data fusion. This method continuously collects raw data from various types of monitoring equipment and performs real-time analysis, initially classifying the raw data into multiple independent anomaly signals. Then, it performs an initial credibility assessment on each independent anomaly signal and dynamically adjusts the alarm presentation strategy. However, in actual railway freight yard monitoring scenarios, many high-risk anomalies are not composed of a single independent anomaly signal, but rather complex events formed by multiple seemingly independent anomaly signals that are spatiotemporally or logically interconnected and co-evolving. Focusing only on independent anomaly signals may lead to untimely or inaccurate identification of these complex anomaly events, thus affecting the effectiveness and comprehensiveness of the early warning. Therefore, this application further proposes, after the initial classification into multiple independent anomaly signals, to identify the deep correlations between these independent anomaly signals to form a composite anomaly event chain, thereby capturing and providing early warnings of complex anomalies more comprehensively and accurately.
[0063] Following the initial classification into multiple independent anomalous signals described above, the process also includes: Atomic anomaly features are extracted from independent anomaly signals and their credibility scores are calculated. The spatiotemporal and logical correlations between atomic anomaly features are identified through the event chain causal reasoning engine to form a composite anomaly event chain and its comprehensive credibility is calculated. When the comprehensive credibility of the composite anomaly event chain reaches the preset alarm threshold, a preset level alarm is triggered.
[0064] Specifically, after obtaining multiple independent anomalous signals that have been initially classified, it is necessary to further extract atomic anomalous features from these signals. Atomic anomalous features can be understood as the basic, smallest-grained units of anomalous information that constitute an independent anomalous signal. For example, they may include the timestamp of the anomalous occurrence, geographical coordinates, anomalous type (such as motion detection, area intrusion, equipment failure, etc.), and anomalous intensity. The purpose of extracting these atomic anomalous features is to facilitate more refined correlation analysis later. Simultaneously, a confidence score is calculated for each extracted atomic anomalous feature. This score reflects the likelihood that the atomic anomalous feature is a genuine anomalous feature, and its calculation can be based on factors such as the quality of the original data, sensor type, and historical false alarm rate.
[0065] The event chain causal reasoning engine is an intelligent module used to analyze and understand causal relationships and correlation patterns between events. This engine is configured to identify the spatiotemporal and logical correlations between atomic anomaly features. Spatiotemporal correlation refers to the proximity or sequence of different atomic anomaly features in time or space; for example, multiple anomalies occurring in close geographical locations within a short period. Logical correlation refers to a certain business logic or causal relationship between different atomic anomaly features; for example, after an access control system is illegally opened, movement of people is subsequently detected in the same area. The engine analyzes these atomic anomaly features using pre-defined causal rules or machine learning models to discover potential correlation patterns between them.
[0066] Therefore, by identifying spatiotemporal and logical correlations, interconnected atomic anomaly features can be linked together to form a complex anomaly event chain. A complex anomaly event chain represents a higher-level anomaly scenario composed of multiple atomic anomaly events; for example, illegal intrusion might consist of atomic anomaly features such as wall climbing, area intrusion, and target movement. For each formed complex anomaly event chain, its overall credibility needs to be calculated. This overall credibility can be calculated based on the credibility scores of each atomic anomaly feature constituting the event chain, combined with factors such as their correlation strength and the weight of causal rules, to more accurately assess the authenticity of the entire complex anomaly event chain.
[0067] When the overall credibility of a complex chain of abnormal events reaches a preset alarm threshold, the chain is considered sufficiently authentic to trigger an alarm. At this point, the system will trigger a preset alarm level. This alarm level can be set based on the potential harm of the complex chain of abnormal events; for example, high-risk events trigger the highest level alarm, and low-risk events trigger a lower level alarm.
[0068] To further clarify the specific composition of atomic anomaly features, the identification mechanism of the event chain causal reasoning engine, and the calculation method of comprehensive credibility, this application elaborates on these aspects in detail.
[0069] Atomic anomaly features include timestamps and geographic coordinates; Identifying the spatiotemporal and logical correlations between atomic anomaly features through the event chain causal reasoning engine includes: the event chain causal reasoning engine examines the correlation between atomic anomaly features on timestamps and geographic coordinates based on preset causal rules, which include feature co-occurrence patterns, temporal correlations, and spatial proximity conditions; When calculating the overall credibility of a complex chain of anomalous events, a weighted calculation is performed based on the credibility scores of each atomic anomalous feature and the weights of preset causal rules.
[0070] Specifically, atomic anomaly features can be understood as the basic units constituting complex anomalous events. They include timestamps and geographic coordinates, aiming to accurately record the time and spatial location of the anomalous event. The timestamp precisely marks the moment the anomalous event occurred, for example, accurate to the millisecond or second level, to support subsequent time-series correlation analysis. Geographic coordinates indicate the specific location of the anomalous event within the railway freight yard; for example, they can use latitude and longitude, area codes, or specific equipment numbers to support spatial proximity analysis.
[0071] Furthermore, the event chain causal reasoning engine is configured to identify the spatiotemporal and logical correlations between atomic anomaly features. Specifically, the engine examines atomic anomaly features based on pre-defined causal rules. Pre-defined causal rules are a series of logical conditions that define potential correlation patterns between anomaly events, which can include feature co-occurrence patterns, temporal correlations, and spatial proximity conditions. For example, a feature co-occurrence pattern refers to the pattern of multiple specific atomic anomaly features appearing simultaneously within a specific time or spatial range; temporal correlation refers to the pattern of different atomic anomaly features occurring in a specific temporal order; and spatial proximity refers to the correlation between different atomic anomaly features within a specific spatial distance. When multiple sensors report anomalies in the same area within a short period (spatial proximity), or when an anomaly always occurs alongside another specific anomaly (feature co-occurrence pattern), or when an anomaly always occurs before another anomaly (temporal correlation), these can all be defined as pre-defined causal rules.
[0072] Furthermore, the overall credibility of the composite anomaly chain is calculated by weighting the credibility scores of each atomic anomaly feature with the weights of predefined causal rules. This means that the credibility of each atomic anomaly feature and its matching degree with the predefined causal rules both affect the overall credibility of the final composite anomaly chain. For example, if an atomic anomaly feature has a high credibility and it matches a high-weight causal rule well, then its contribution to the overall credibility of the composite anomaly chain will be greater.
[0073] Secondly, referring to Figure 2 This application also proposes a railway freight yard anomaly alarm system based on multi-source data fusion, which is used to execute the above-mentioned railway freight yard anomaly alarm method based on multi-source data fusion.
[0074] The system includes: The data collection and processing module 210 is used to continuously collect raw data from various types of monitoring equipment in the railway freight yard, and to perform real-time analysis on the raw data, initially classifying it into multiple independent abnormal signals. The initial credibility assessment module 220 is used to perform an initial credibility assessment on each independent anomalous signal, obtain an initial credibility score, and adjust the initial credibility score based on the real-time acquired interference characteristics, auxiliary environmental data, and cross-sensor correlation. The response analysis module 230 is used to record the response behavior data of the duty personnel to each abnormal alarm, and to analyze the alarm fatigue status of the duty personnel based on the response behavior data. The alarm presentation strategy adjustment module 240 is used to dynamically adjust the presentation strategy of abnormal alarms based on the adjusted initial confidence score and alarm fatigue state. The presentation strategy includes: reducing the alarm priority or automatically filtering a single abnormal signal whose adjusted initial confidence score is lower than the preset confidence score; increasing the alarm attention of a single abnormal signal whose adjusted initial confidence score is not lower than the preset confidence score; and increasing the alarm duration or repetition frequency when the on-duty personnel are in an alarm fatigue state, and requiring the on-duty personnel to confirm.
[0075] The data collection and processing module 210 can be understood as the system's front-end data interface and preprocessing unit. Its main function is to continuously acquire raw data from various monitoring devices within the railway freight yard, such as video surveillance, sensors, and access control systems. After being collected, this raw data undergoes real-time analysis and preliminary processing to identify potential anomalies and preliminarily classify them as independent abnormal signals. For example, when video surveillance detects abnormal movement or sensor data exceeds the normal range, this information is preliminarily identified as an independent abnormal signal.
[0076] The initial credibility assessment module 220 is responsible for evaluating the credibility of each initially categorized independent anomalous signal. Specifically, this module assigns an initial credibility score to each independent anomalous signal to quantify its likelihood of being a genuine anomaly. To improve the accuracy of the assessment, this module also acquires and considers various auxiliary information in real time, including environmental interference characteristics (such as weather and lighting changes), auxiliary environmental data (such as yard operation plans and equipment maintenance records), and cross-sensor correlations (such as multiple sensors reporting anomalies simultaneously). Based on this information, the initial credibility score is dynamically adjusted to more accurately reflect the authenticity of the anomalous signal.
[0077] The primary function of the response analysis module 230 is to record and analyze the response behavior of on-duty personnel to abnormal alarms. This includes the response time of the on-duty personnel and the final processing result of the alarm (such as confirmation, false alarm marking, etc.). By continuously monitoring and analyzing this response behavior data, the alarm fatigue status of on-duty personnel can be assessed. For example, if the false alarm rate of low-confidence alarms is too high or the response time is too long, it may indicate that the on-duty personnel are in a state of alarm fatigue.
[0078] The alarm presentation strategy adjustment module 240 is one of the core decision-making units of the system. It dynamically adjusts the presentation strategy of abnormal alarms based on the adjusted initial confidence score and the alarm fatigue state of the on-duty personnel. Specifically, for individual abnormal signals with an adjusted confidence score lower than the preset confidence level, the module will reduce their alarm priority or automatically filter them to minimize interference from invalid alarms to the on-duty personnel. Conversely, for individual abnormal signals with a confidence score not lower than the preset confidence level, their alarm attention will be increased to ensure that important alarms are handled promptly and effectively. Furthermore, when the system determines that the on-duty personnel are in an alarm fatigue state, the module will adopt a more forceful alarm approach, such as increasing the alarm duration or repetition frequency, and requiring the on-duty personnel to confirm, ensuring that even in a fatigued state, the on-duty personnel receive sufficient attention.
[0079] The above are merely embodiments of this application and are not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A method for alarming anomalies in railway freight yards based on multi-source data fusion, characterized in that, include: Raw data from various types of monitoring equipment within the railway freight yard is continuously collected and analyzed in real time, initially classified into multiple independent abnormal signals; An initial confidence score is obtained by performing an initial confidence assessment on each of the independent anomalous signals, and the initial confidence score is adjusted based on the interference characteristics acquired in real time, auxiliary environmental data, and cross-sensor correlation. Record the response behavior data of the on-duty personnel to each abnormal alarm, and analyze the alarm fatigue status of the on-duty personnel based on the response behavior data; Based on the adjusted initial confidence score and the alarm fatigue state, the presentation strategy of abnormal alarms is dynamically adjusted. The presentation strategy includes: for individual abnormal signals whose adjusted initial confidence score is lower than a preset confidence score, the alarm priority is reduced or they are automatically filtered. For individual abnormal signals whose adjusted initial confidence score is not lower than the preset confidence score, increase the alert level of their alarms; when the on-duty personnel are in a state of alarm fatigue, increase the duration or repetition frequency of the alarms and require the on-duty personnel to confirm.
2. The railway freight yard anomaly alarm method based on multi-source data fusion according to claim 1, characterized in that, The method further includes: Temporal, spatial, and feature vector information is extracted from the raw data to form atomic event feature vectors; The similarity between the atomic event feature vector and the known environmental interference features in the preset environmental interference feature library is calculated. If the similarity between the atomic event feature vector and all the known environmental interference features is lower than the novelty judgment threshold, then it is initially marked as a candidate novel mode; If there is a correlation in time or space between the multiple atomic event feature vectors that constitute the candidate novel mode, which is lower than a preset correlation threshold, then it is finally marked as a novel composite perturbation mode. When the novel composite disturbance pattern is identified, a deep verification process is triggered to guide the on-duty personnel to conduct a deep verification.
3. The railway freight yard anomaly alarm method based on multi-source data fusion according to claim 2, characterized in that, The steps for triggering a deep verification process and guiding on-duty personnel to conduct a deep verification when the novel composite disturbance pattern is identified include: Show the on-duty personnel the raw time-series data charts and video playbacks of the associated sensors and provide a structured checklist. The on-duty personnel are required to compare each item and submit the check results. The on-duty personnel's check behavior data is continuously monitored. Based on the check behavior data and the preset behavior reference standards, the on-duty personnel's dependence index is calculated. When the verification result is a false positive, the suppression tendency of the novel composite perturbation mode is gradually increased and its initial confidence score is decreased; when the verification result is a true positive, the suppression tendency of the novel composite perturbation mode is decreased and its initial confidence score is increased. When the novel composite disturbance pattern is consistently marked as a false alarm by multiple duty personnel whose dependency index is lower than the preset dependency threshold within a preset time, and its atomic event feature vector is lower than the preset stability value, the novel composite disturbance pattern is added to the environmental disturbance feature library.
4. The railway freight yard anomaly alarm method based on multi-source data fusion according to claim 3, characterized in that, If the verification result is a false alarm, perform the following steps: When the verification result is a false alarm and the dependency index is higher than the preset dependency threshold, a reverse verification process is triggered. The reverse verification process includes multi-person cross-verification and high-risk deviation alerts; The multi-person cross-validation includes pushing unprocessed alarm instances similar to the novel composite perturbation pattern to another on-duty personnel whose dependency index is lower than the preset dependency threshold for in-depth verification, and obtaining a secondary verification result; The high-risk deviation alert includes a mandatory notification to security experts to intervene when the verification result is inconsistent with the secondary verification result.
5. The railway freight yard anomaly alarm method based on multi-source data fusion according to claim 3, characterized in that, When the verification result is true, perform the following steps: The atomic event feature vectors of the novel composite perturbation patterns that are confirmed as true reports are continuously analyzed and compared with all templates in the preset intrusion imitation behavior sequence template library to calculate the potential imitation index. When the potential imitation index reaches the preset imitation threshold, the novel composite perturbation pattern is marked as a suspected evolutionary imitation behavior, the preset highest level alarm is activated, and the original data, analysis results, and potential imitation index of the novel composite perturbation pattern are pushed to security experts for manual review. Based on the results of the manual review, the suspected evolving imitation behavior is added to the preset intrusion imitation behavior sequence template library as a new intrusion imitation behavior sequence template or a variant of an existing template, and all intrusion imitation behavior sequence templates in the template library are periodically updated adaptively.
6. The railway freight yard anomaly alarm method based on multi-source data fusion according to claim 1, characterized in that, The response behavior data includes the response time of the on-duty personnel and the final processing result of the on-duty personnel on the alarm; The step of analyzing the alarm fatigue status of on-duty personnel based on the response behavior data includes: For alarms with a confidence level lower than the preset confidence level, if the proportion of false alarms in the final processing result exceeds the preset false alarm threshold and the response time exceeds the preset first response time, the alarm is judged to be in a fatigue state. For alarms that are not below the preset confidence level, if the final processing result is that the frequency of verification operations is lower than the preset verification threshold or the response time exceeds the preset second response time, the alarm is judged to be in a fatigue state.
7. The railway freight yard anomaly alarm method based on multi-source data fusion according to claim 1, characterized in that, The step of reducing the alarm priority or automatically filtering the individual abnormal signals whose adjusted initial confidence score is lower than the preset confidence score includes: displaying the alarm text information in an auxiliary area with a soft color, without emitting an audible alarm or popping up a forced window; when the same sensor triggers multiple false alarms lower than the preset confidence score within a preset monitoring time and there is no corroboration from other sensors, an alarm filtering record is only generated in the background and not presented to the on-duty personnel. The method of increasing the attention of alarms for individual abnormal signals whose adjusted initial confidence score is not lower than the preset confidence score includes: when it is detected that the duty personnel are in the state of alarm fatigue, forcibly presenting the text information and monitoring screen of the alarm by means of full-screen flashing, highlighting or voice prompt, and requiring the duty personnel to confirm within a preset confirmation time.
8. The railway freight yard anomaly alarm method based on multi-source data fusion according to claim 1, characterized in that, Following the initial classification into multiple independent anomalous signals, the following steps are included: Atomic anomaly features are extracted from the independent anomaly signals and their credibility scores are calculated. The spatiotemporal and logical correlations between the atomic anomaly features are identified through the event chain causal reasoning engine to form a composite anomaly event chain and its comprehensive credibility is calculated. When the comprehensive credibility of the composite anomaly event chain reaches a preset alarm threshold, a preset level alarm is triggered.
9. A railway freight yard anomaly alarm method based on multi-source data fusion according to claim 8, characterized in that, The atomic anomaly features include timestamps and geographic coordinates; The step of identifying the spatiotemporal and logical correlations between the atomic anomaly features through the event chain causal reasoning engine includes: the event chain causal reasoning engine checks the correlation between the atomic anomaly features on the timestamp and the geographic coordinates based on preset causal rules, the preset causal rules including feature co-occurrence patterns, temporal correlations and spatial proximity conditions; When calculating the overall credibility of the composite abnormal event chain, a weighted calculation is performed based on the credibility score of each atomic abnormal feature and the weight of the preset causal rule.
10. A railway freight yard anomaly alarm system based on multi-source data fusion, used to execute the railway freight yard anomaly alarm method based on multi-source data fusion as described in any one of claims 1 to 9, characterized in that, The system includes: The data collection and processing module is used to continuously collect raw data from various types of monitoring equipment in the railway freight yard, and to perform real-time analysis on the raw data, initially classifying it into multiple independent abnormal signals; An initial credibility assessment module is used to perform an initial credibility assessment on each of the independent anomalous signals to obtain an initial credibility score, and to adjust the initial credibility score based on the interference characteristics, auxiliary environmental data, and cross-sensor correlation acquired in real time. The response analysis module is used to record the response behavior data of the duty personnel to each abnormal alarm, and to analyze the alarm fatigue status of the duty personnel based on the response behavior data. The alarm presentation strategy adjustment module is used to dynamically adjust the presentation strategy of abnormal alarms based on the adjusted initial confidence score and the alarm fatigue state. The presentation strategy includes: reducing the alarm priority or automatically filtering a single abnormal signal whose adjusted initial confidence score is lower than a preset confidence score; increasing the alarm attention of a single abnormal signal whose adjusted initial confidence score is not lower than the preset confidence score; and increasing the alarm duration or repetition frequency when the on-duty personnel are in the alarm fatigue state, and requiring the on-duty personnel to confirm.
Citation Information
Cited By
An adaptive environment alarm and status indication system for a battery production plant
CN122336962B