Operation site risk real-time intervention method and system based on cloud side-end collaborative architecture

Through a cloud-edge-device collaborative architecture, edge nodes perform real-time data analysis and intervention, while the cloud performs model optimization. This solves the problems of poor real-time performance, high cost, and poor adaptability in existing technologies, and realizes a security management system with low latency response, network adaptability, and cost optimization.

CN121526318APending Publication Date: 2026-02-13BEIJING DATANG SITUO INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511685385.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-18
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

Existing technologies suffer from problems such as poor real-time performance and high cost in pure cloud solutions, and poor model adaptability and lack of global optimization capabilities in pure edge solutions.

Method used

By adopting a cloud-edge-device collaborative architecture, edge computing nodes perform real-time data analysis and intervention, while the cloud performs model optimization, forming a data-driven intelligent closed loop.

Benefits of technology

It enables low-latency real-time intervention, network adaptability and business continuity, reduces operating costs, and continuously optimizes the risk identification model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121526318A_ABST
    Figure CN121526318A_ABST
Patent Text Reader

Abstract

The invention discloses an operation site risk real-time intervention method and system based on a cloud side-end collaborative architecture, and belongs to the technical field of safety production management and computers. The method comprises the following steps: an edge computing node deployed in a working site receives a field data stream from one or more data acquisition terminals; the edge computing node analyzes the field data flow by using a locally loaded risk identification model so as to identify a preset risk event; when a risk event is recognized, the edge computing node locally generates an intervention instruction and sends the intervention instruction to an on-site intervention device under the condition of not depending on a real-time instruction issued by the cloud management platform, and the intervention device comprises alarm equipment, an operation equipment controller or an intelligent environment controller; the intervention actions such as alarming, changing the running state of equipment, cutting off the power supply of the equipment or improving the field environment are executed; and meanwhile, the edge computing node generates structured risk data related to the risk event and uploads the structured risk data to the cloud management platform. And the cloud management platform gathers data from one or more edge computing nodes, trains or optimizes a risk identification model based on the gathered data, and distributes the updated model to the edge computing nodes to realize iterative updating of the risk identification model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of computer technology and safety production management technology. Specifically, it relates to a method and system for real-time risk identification and automated intervention in industrial, construction, and other work sites based on a cloud-edge-device collaborative architecture. Background Technology

[0002] In numerous industries such as petrochemicals, construction, power line inspection, and warehousing and logistics, various potential safety risks often exist at work sites, such as personnel violations (e.g., not wearing safety helmets, entering hazardous areas), abnormal equipment conditions, and leaks of harmful gases. Traditional safety management methods mainly rely on manual inspections and post-incident traceability, which suffers from problems such as untimely response, incomplete regulatory coverage, and high labor costs.

[0003] With the development of artificial intelligence and Internet of Things technologies, intelligent risk identification using video surveillance and sensors has become a hot topic in research and application. Currently, the mainstream technical solutions mainly fall into two categories:

[0004] The first approach is a "pure cloud" architecture. This solution uploads all on-site video and sensor data to a cloud server, where the powerful computing resources of the cloud perform centralized AI analysis and decision-making. Its advantages include the ability to train models using global data, resulting in a high level of intelligence and easy unified management. However, its disadvantages are also significant: 1) Poor real-time performance: The entire process from data upload to the cloud and subsequent command issuance involves unavoidable network latency. For emergency risks requiring second-level or even sub-second-level responses (such as personnel about to be caught in a machine), this latency can prevent timely intervention and lead to serious consequences; 2) Strong network dependency: If the network connection between the on-site and cloud is interrupted or unstable, the entire security monitoring system will malfunction; 3) High cost: Continuous uploading of large amounts of raw video data consumes significant network bandwidth and cloud storage resources, resulting in high operating costs.

[0005] The second approach is a "pure edge" or "endpoint" architecture. This solution deploys AI models directly on edge computing devices or smart cameras in the field, enabling local data processing and analysis. The advantages of this approach are fast response times, no reliance on wide area network connections, and guaranteed business continuity. However, its disadvantages are: 1) Edge devices have limited computing power, making it difficult to support complex, high-precision AI models; 2) Each edge node acts as a unit that cannot share data and learning experience; models are usually pre-built, making it difficult to learn and iteratively optimize using newly generated risk data, resulting in a decreased ability to identify new risk scenarios and poor adaptability; 3) It lacks a global perspective, making it difficult to conduct cross-regional, multi-dimensional risk correlation analysis and macro-level security situation assessment.

[0006] Therefore, how to combine the advantages of cloud and edge computing to build a work site safety management system that can ensure real-time risk intervention, continuously optimize models, and reduce operating costs is a technical problem that needs to be solved in the current technology field. Summary of the Invention

[0007] The purpose of this invention is to provide a method and system for real-time intervention of workplace risks based on a cloud-edge-device collaborative architecture, in order to solve the technical problems of poor real-time performance and high cost of pure cloud solutions, and poor model adaptability and lack of global optimization capabilities of pure edge solutions in the prior art.

[0008] To achieve the above objectives, this invention provides a method for real-time intervention of workplace risks based on a cloud-edge-device collaborative architecture, comprising:

[0009] The following steps are performed by an edge computing node deployed at the work site:

[0010] Receives real-time field data streams collected by at least one data acquisition terminal at the work site;

[0011] Based on the risk identification model stored locally on the edge computing node, the on-site data stream is analyzed in real time to determine whether a preset risk event exists;

[0012] In addition, in response to the determination that the risk event exists, the edge computing node generates an intervention command without relying on a cloud management platform to issue real-time instructions for the risk event, and sends the intervention command to at least one intervention device deployed at the work site to drive the intervention device to perform an intervention action;

[0013] Structured risk data corresponding to the risk event is generated, and the structured risk data is uploaded to the cloud management platform via the network.

[0014] As a preferred embodiment, prior to the step of receiving the field data stream, the method further includes: the edge computing node receiving and loading the risk identification model from the cloud management platform via the network.

[0015] In a preferred embodiment, the structured risk data includes at least one of the following: timestamp of the risk event, geographic location information, risk event type, identification of personnel or equipment associated with the risk event, and fragments of the original field data stream associated with the risk event for verification or corroboration of the risk event.

[0016] In a preferred embodiment, the intervention device includes at least one of an audible and visual alarm, a voice broadcasting device, or an equipment controller; the intervention command is used to trigger the audible and visual alarm to issue an audible and visual alarm, drive the voice broadcasting device to broadcast a preset voice alarm message, or send a control signal to the associated work equipment or environmental control equipment through the equipment controller to change its operating status, cut off its power supply, or change the environmental parameters of the work site.

[0017] As a preferred embodiment, the method further includes: when the network connection between the edge computing node and the cloud management platform is interrupted, temporarily storing the generated structured risk data in the local storage of the edge computing node; and uploading the temporarily stored structured risk data to the cloud management platform after the network connection is restored.

[0018] This invention also provides a real-time intervention system for workplace risks based on a cloud-edge-device collaborative architecture, comprising:

[0019] At least one data acquisition terminal deployed at the work site is used to collect on-site data streams in real time;

[0020] A cloud-based management platform;

[0021] And, an edge computing node deployed at the work site and communicating with the data acquisition terminal and the cloud management platform, the edge computing node comprising:

[0022] A data receiving module, configured to receive the field data stream from the data acquisition terminal;

[0023] A real-time analysis module is connected to the data receiving module and configured to perform real-time analysis of the on-site data stream based on a locally stored risk identification model in order to determine whether a preset risk event exists.

[0024] A local intervention module is connected to the real-time analysis module and configured to generate an intervention command in response to the real-time analysis module's determination that the risk event exists, without relying on the real-time instructions of the cloud management platform, and send the intervention command to at least one intervention device deployed at the work site.

[0025] Additionally, a data processing and uploading module is connected to the real-time analysis module and configured to generate structured risk data corresponding to the risk event in response to the real-time analysis module determining the existence of the risk event, and upload the structured risk data to the cloud management platform via the network.

[0026] This invention also provides a method for on-site risk management based on a cloud-edge-device collaborative architecture, wherein a cloud management platform performs the following steps:

[0027] Receive structured risk data corresponding to risk events from one or more edge computing nodes deployed at at least one work site;

[0028] Based on the aggregated structured risk data, a risk identification model is trained or optimized to generate an updated risk identification model.

[0029] In addition, the updated risk identification model is distributed to the one or more edge computing nodes so that the edge computing nodes can update the risk identification model stored locally. Beneficial effects

[0030] Compared with existing technologies, the technical solution provided in this application, by deploying risk identification and intervention decisions at the edge while utilizing the cloud for model optimization, produces the following beneficial effects:

[0031] Low-latency real-time intervention: In this invention, risk identification and intervention command generation are both completed locally on edge computing nodes at the work site, forming a local processing closed loop that does not rely on real-time communication with the cloud. This approach avoids network latency caused by data traveling to and from the cloud, thus shortening the time from the occurrence of a risk event to the response of the on-site intervention device compared to a pure cloud solution, and improving the timeliness of intervention. In particular, when intervention actions include active environmental improvement measures such as starting exhaust fans and spraying dust suppression, or when mechanical power is urgently cut off when personnel are identified as being at risk of being involved, this low-latency response helps to control the situation on site before it escalates, avoiding casualties or major equipment damage.

[0032] Network adaptability and business continuity: Because the core risk identification and intervention functions are closed-loop at the edge, this system can still operate independently even if the network connection between the field and the cloud is interrupted or unstable, ensuring that the core field security protection functions are not interrupted. Edge nodes can cache risk data generated during network outages locally and upload it after the network is restored, ensuring data integrity.

[0033] Continuous optimization of the risk identification model: This invention generates structured, lightweight data (such as alarm type, time, screenshots, etc.) from risk events discovered on-site via edge nodes and uploads it to the cloud. The cloud platform aggregates real-world risk data from all work sites, forming a high-quality risk sample library. Using this library, the AI ​​model can be continuously trained, fine-tuned, and optimized, and the better-performing model can then be distributed to all edge nodes. This forms a data-driven, continuously optimized intelligent closed loop, solving the problem of poor model adaptability in purely edge-based solutions.

[0034] Reduced operating costs: Unlike pure cloud solutions that require uploading massive amounts of raw video streams, this invention primarily uploads lightweight structured risk data and a small number of keyframes or short video clips, significantly reducing data transmission volume compared to raw video streams. This saves on WAN bandwidth and cloud storage costs, making large-scale deployment more economically feasible.

[0035] In summary, this invention achieves low-latency response and continuous optimization of risk identification capabilities for on-site risk intervention by performing real-time analysis and local intervention at the edge, and optimizing and distributing models in the cloud, while reducing the network and storage overhead of the system. Attached Figure Description

[0036] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below.

[0037] Figure 1 This is a schematic diagram of a real-time intervention system for on-site risks based on a cloud-edge-device collaborative architecture, according to an embodiment of the present invention.

[0038] Figure 2 This is a flowchart illustrating a method for real-time intervention of workplace risks based on a cloud-edge-device collaborative architecture, according to an embodiment of the present invention.

[0039] Figure 3 This is a schematic diagram of the internal functional modules of an edge computing node according to an embodiment of the present invention.

[0040] Figure label explanations: 100 Cloud management platform; 110 Data aggregation and analysis module; 120 Model training and distribution module; 200 Edge computing node; 210 Data receiving module; 220 Algorithm loading module; 230 Real-time analysis module; 240 Local intervention module; 250 Data processing and uploading module; 260 Local storage module; 300 Data acquisition terminal; 310 Camera; 320 Sensor; 400 Intervention device; 410 Audible and visual alarm; 420 Voice broadcasting device; 430 Intelligent environment controller Detailed Implementation

[0041] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.

[0042] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments.

[0043] It should be understood that the term "real-time" in this application means that the system's response time from data collection to intervention can meet the safety requirements of specific operational scenarios. For example, under typical hardware configurations and operational environments, it is usually in the range of hundreds of milliseconds to several seconds, which is lower than the latency of several seconds or even longer in traditional cloud solutions.

[0044] The “on-site data stream” mentioned in this application may include, but is not limited to: video data streams collected by cameras, environmental parameter data collected by various sensors (such as gas sensors, temperature sensors, pressure sensors, etc.), vital sign data reported by smart devices worn by workers (such as smart bracelets), or work status data uploaded by work tools, etc.

[0045] The “preset risk events” mentioned in this application can be defined according to different work scenarios, and their categories may include, but are not limited to: personnel violations (such as failure to wear personal protective equipment (PPE) as required, personnel entering dangerous areas, personnel falling to the ground, and lack of edge protection for working at heights), environmental anomalies (such as smoke and fire, gas leaks, and water accumulation), and equipment status (such as equipment overspeeding and unauthorized start-up).

[0046] like Figure 1 As shown, this application provides a cloud-edge-device collaborative architecture, including a cloud management platform 100, an edge computing node 200, and terminal devices (including a data acquisition terminal 300 and an intervention device 400). The data acquisition terminal 300 transmits on-site data to the edge computing node 200. The edge computing node 200 analyzes the data locally and can directly send instructions to the intervention device 400 to form a local intervention closed loop. The intervention device 400 can be a device that issues warning signals, such as an audible and visual alarm 410 or a voice broadcasting device 420; it can also be a device capable of performing physical control, such as a work equipment controller for stopping or slowing down machinery, or a smart circuit breaker that can directly cut off the power supply to the equipment; it can also be an intelligent environmental controller 430 for improving the on-site environment. For example, this controller can be connected to an exhaust fan, a water curtain sprinkler system, an inert gas injection valve, etc., to automatically perform environmental treatment when a gas leak or dust exceeds the standard. At the same time, the edge computing node 200 communicates with the cloud management platform 100 through a network to upload structured risk data and download updated risk identification models.

[0047] The cloud management platform 100 is typically deployed on a public or private cloud server and includes a data aggregation and analysis module 110 and a model training and distribution module 120. The data aggregation and analysis module 110 is responsible for receiving, storing, and managing all structured risk data uploaded by edge nodes, and provides functions such as data retrieval, statistical analysis, and report generation. The model training and distribution module 120 utilizes the aggregated data to train or optimize the risk identification model using machine learning algorithms (such as transfer learning, incremental learning, federated learning, etc.), and then distributes the updated model to the edge computing nodes 200.

[0048] As a specific implementation method, the cloud management platform 100 can also provide a human-computer interaction interface for security managers to review risk events reported by edge nodes (especially accompanying images or video clips) and label them as 'correctly identified', 'false alarm', or 'missed'. These manually labeled samples will be prioritized for use in the model training and distribution module 120 to fine-tune the risk identification model, thereby specifically improving the model's accuracy in specific scenarios.

[0049] like Figure 3 As shown, the edge computing node 200 is a computing device deployed at the work site. It can be any hardware device with the required data processing, storage, and communication capabilities, such as an industrial control computer, an embedded AI box, or a server with a certain computing power. Its internal functional modules include:

[0050] Data receiving module 210: responsible for receiving data streams from data acquisition terminals 300 such as camera 310 and sensor 320.

[0051] Algorithm loading module 220: Responsible for downloading the risk identification model from the cloud management platform 100 and loading it into memory for use by the real-time analysis module 230. It is also responsible for receiving new models from the cloud and updating them.

[0052] Real-time analysis module 230: This is the core of the edge computing node. It calls the loaded risk identification model to perform reasoning analysis on the real-time data stream and output the judgment results of risk events.

[0053] Local intervention module 240: When it receives a risk event alarm from the real-time analysis module 230, the module will immediately generate and send an intervention command to the corresponding intervention device 400 according to the preset rules.

[0054] Data processing and uploading module 250: When a risk event occurs, this module is responsible for packaging event information (such as type, time, location) and related evidence (such as screenshots, short videos, sensor readings) into a structured data format (such as JSON), and then uploading it to the cloud management platform 100 via the network.

[0055] Local storage module 260: Used to store risk identification models, system logs, and structured risk data to be uploaded temporarily in the event of a network outage.

[0056] Example 1

[0057] Please see Figure 1 This embodiment discloses a real-time intervention system for on-site risks based on a cloud-edge-device collaborative architecture.

[0058] Please combine Figure 2 and Figure 3 The method flow of the present invention will be further explained below.

[0059] Step S201: The algorithm loading module 220 of the edge computing node 200 connects to the model training and distribution module 120 of the cloud management platform 100 via the network, downloads the risk identification model suitable for the current operation scenario, and loads it locally.

[0060] Step S202: The data receiving module 210 continuously receives field data streams from the field camera 310 and various sensors 320.

[0061] Step S203: The real-time analysis module 230 calls the locally loaded risk identification model to perform real-time inference on the received data stream.

[0062] Step S204: If the real-time analysis module 230 determines that a risk event exists, the process proceeds to steps S205 and S206.

[0063] Step S205: The local intervention module 240 immediately generates an intervention command and sends it to the on-site intervention device 400 (such as the sound and light alarm device 410 and the voice broadcast device 420).

[0064] Step S206: The data processing and uploading module 250 generates structured data containing details of the risk event and uploads it to the data aggregation and analysis module 110 of the cloud management platform 100 via the network.

[0065] This embodiment uses a confined space operation scenario as an example for illustration:

[0066] Sensors 320 for monitoring toxic gases (such as hydrogen sulfide, H2S) and cameras 310 for monitoring supervisors were deployed at the work site. Edge computing nodes 200 locally loaded a "gas concentration exceeding standard model" and a "personnel absenteeism identification model".

[0067] At a certain moment, the H2S concentration rose to 15 ppm (the safety threshold is 10 ppm). The real-time analysis module 230 immediately identified a "gas concentration exceeding the standard" risk event.

[0068] Local intervention module 240 then executes the combined intervention actions:

[0069] Alarm personnel: Send instructions to the on-site audible and visual alarm 410 and voice broadcasting device 420 to sound the alarm and broadcast "Hydrogen sulfide concentration exceeds the standard, please evacuate immediately!"

[0070] Proactive response: Simultaneously, a start command is sent to the intelligent environmental controller 430 connected to the ventilation duct of the work space to automatically turn on the powerful exhaust fan and force ventilation to quickly reduce the concentration of toxic gases.

[0071] Meanwhile, the data processing and uploading module 250 generates a JSON-formatted data entry: {"time": "2025-07-18T10:30:05", "node_id": "EDGE001", "event": "H2S_over_limit", "evidence": {"type": "sensor_reading", "value": "15ppm"}, "actions_taken": ["alarm_triggered", "ventilation_activated"]}, and uploads it to the cloud.

[0072] In this embodiment, if the network connection between the edge computing node 200 and the cloud management platform 100 is interrupted after the edge computing node 200 generates the JSON data, the data processing and uploading module 250 will temporarily store the JSON data in the local storage module 260. When the network connection is restored, the module will automatically detect and upload the temporarily stored data to the cloud to ensure data integrity.

[0073] Example 2

[0074] This embodiment uses a high-altitude operation scenario as an example for illustration.

[0075] The work site is a construction site. Edge computing node 200 is deployed in the site's monitoring room, which is loaded with a "safety helmet wearing recognition model" and a "missing edge protection recognition model". Camera 310 covers the main high-altitude work platforms.

[0076] Before work begins, workers enter the construction site through a facial recognition gate. The real-time analysis module 230 of the edge computing node 200 first performs a "pre-work safety check" process, analyzing the video stream of personnel entering the work area to determine whether they are wearing safety helmets correctly. If someone is found not to be wearing a helmet, the local intervention module 240 activates the voice broadcast device 420 at the gate to prompt "Please wear a safety helmet before entering" and prohibits them from passing. This process is a local closed loop and does not require cloud intervention.

[0077] During the operation, camera 310 captured footage of a section of the edge protection fence being accidentally removed. Real-time analysis module 230 identified the risk of "missing edge protection." Local intervention module 240 immediately activated the audible and visual alarm 410 near the work platform, emitting high-frequency flashing and an alarm sound to alert nearby personnel. Simultaneously, data processing and uploading module 250 uploaded structured data, including a screenshot of the missing fence location, to cloud management platform 100. Safety management personnel received the alarm on the cloud platform's web interface and could view the on-site screenshot, allowing them to dispatch personnel for repairs.

[0078] After a period of time, the cloud-based model training and distribution module 120 collected a large number of manually verified "false alarms" (such as mistaking objects shaped like safety helmets for safety helmets) and "missed alarms" uploaded by edge nodes at various construction sites. It then fine-tuned the "safety helmet wearing recognition model," generating version v2.0. Subsequently, the model training and distribution module 120 distributed the v2.0 model to the edge computing nodes 200 at all construction sites. Upon receiving the new model, the algorithm loading module 220 on the edge computing nodes automatically updated the model. The specific update method can be preset; for example, performing a "cold update" (i.e., stopping related services, replacing the model file, and then restarting the service) during off-peak hours, or performing a "hot update" (i.e., dynamically replacing the model instance in memory with the new version during runtime) without interrupting the current monitoring task, to ensure business continuity. After the update, the accuracy of safety helmet recognition by the edge nodes improved.

[0079] Example 3

[0080] This embodiment uses the safety protection scenario of rotating equipment in a machining workshop as an example for illustration.

[0081] The work site is a machining workshop equipped with CNC lathes. An edge computing node 200 is deployed within the workshop, loaded with a "personnel hazard proximity recognition model." This model can identify whether a person's limbs (such as hands or arms) have intruded into a pre-defined hazardous working area (electronic fence) of the lathe. A wide-angle camera 310 is monitoring the lathe. The intervention device 400 is an equipment controller connected to the lathe's main power contactor or emergency stop control circuit.

[0082] During normal operation, the lathe rotates at high speed to process the workpiece. At one point, without stopping the machine, an operator reached out to clear away the chips, and his arm crossed the red safety warning line set in the camera's field of view.

[0083] Upon receiving the video frame, the real-time analysis module 230 of the edge computing node 200 immediately uses the "personnel dangerous approach recognition model" to determine the serious risk event of "personnel limbs intruding into the dangerous area".

[0084] Due to the urgency of the event, the local intervention module 240 immediately generates a high-priority intervention command and sends a disconnect signal to the lathe's emergency stop control loop via the equipment controller.

[0085] The command was executed within tens of milliseconds, and the lathe spindle motor was immediately powered off and braked, stopping the rotation before the operator's arm could touch the rotating parts, thus preventing a serious mechanical injury accident.

[0086] Meanwhile, the local intervention module 240 activates the audible and visual alarm 410 in the workshop, emitting a piercing alarm to alert all personnel on site. The data processing and uploading module 250 packages and uploads structured data, including event type, timestamp, and keyframe screenshots of the moment a person's arm intrudes, to the cloud management platform 100 for accident recording and subsequent safety training analysis.

[0087] This embodiment fully demonstrates the advantages of the present invention in low-latency closed-loop intervention, and has important practical value in preventing similar high-risk human-computer interaction problems.

[0088] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for real-time intervention of operational risks based on a cloud-edge-device collaborative architecture, characterized in that, include: The following steps are performed by an edge computing node deployed at the work site: Receives real-time field data streams collected by at least one data acquisition terminal at the work site; Based on the risk identification model stored locally on the edge computing node, the on-site data stream is analyzed in real time to determine whether a preset risk event exists; In addition, in response to the determination that the risk event exists, the edge computing node generates an intervention command without relying on a cloud management platform to issue real-time instructions for the risk event, and sends the intervention command to at least one intervention device deployed at the work site to drive the intervention device to perform an intervention action; Structured risk data corresponding to the risk event is generated, and the structured risk data is uploaded to the cloud management platform via the network.

2. The method according to claim 1, characterized in that, Prior to the step of receiving the field data stream, the method further includes: The edge computing node receives and loads the risk identification model from the cloud management platform via the network.

3. The method according to claim 1, characterized in that, The structured risk data includes at least one of the following: timestamp of the risk event, geographical location information, risk event type, identification of personnel or equipment associated with the risk event, and fragments of the original field data stream associated with the risk event for verification or corroboration of the risk event.

4. The method according to claim 1, characterized in that, The intervention device includes at least one of an audible and visual alarm, a voice broadcasting device, or an equipment controller; the intervention command is used to trigger the audible and visual alarm to issue an audible and visual alarm, drive the voice broadcasting device to broadcast a preset voice alarm message, or send a control signal to the associated operating equipment or environmental control equipment through the equipment controller to change its operating status, cut off its power supply, or change the environmental parameters of the work site.

5. The method according to claim 1, characterized in that, Also includes: When the network connection between the edge computing node and the cloud management platform is interrupted, the generated structured risk data is temporarily stored in the local storage of the edge computing node. Furthermore, after the network connection is restored, the temporarily stored structured risk data will be uploaded to the cloud management platform.

6. The method according to claim 2, characterized in that, Also includes: The edge computing node periodically or in response to instructions from the cloud management platform receives an updated risk identification model distributed by the cloud management platform. as well as, The locally stored risk identification model is updated using the updated risk identification model.

7. The method according to claim 1, characterized in that, Prior to the step of receiving the field data stream, the method further includes: The edge computing node analyzes the on-site data stream representing the implementation of safety measures before the operation based on the risk identification model, in order to determine whether the safety measures are compliant. Furthermore, after determining that the safety measures are compliant, the real-time analysis module is controlled to initiate subsequent risk monitoring of the operational process.

8. A real-time intervention system for on-site risks based on a cloud-edge-device collaborative architecture, characterized in that, include: At least one data acquisition terminal deployed at the work site is used to collect on-site data streams in real time; A cloud-based management platform; And, an edge computing node deployed at the work site and communicating with the data acquisition terminal and the cloud management platform, the edge computing node comprising: A data receiving module, configured to receive the field data stream from the data acquisition terminal; A real-time analysis module is connected to the data receiving module and configured to perform real-time analysis of the on-site data stream based on a locally stored risk identification model in order to determine whether a preset risk event exists. A local intervention module is connected to the real-time analysis module and configured to generate an intervention command in response to the real-time analysis module's determination that the risk event exists, without relying on the real-time instructions of the cloud management platform, and send the intervention command to at least one intervention device deployed at the work site. Additionally, a data processing and uploading module is connected to the real-time analysis module and configured to generate structured risk data corresponding to the risk event in response to the real-time analysis module determining the existence of the risk event, and upload the structured risk data to the cloud management platform via the network.

9. The system according to claim 8, characterized in that, The edge computing node also includes: An algorithm loading module is configured to receive and load the risk identification model from the cloud management platform to the local machine of the edge computing node.

10. The system according to claim 8, characterized in that, The data processing and uploading module is further configured to include at least one of the following information when generating the structured risk data: the timestamp of the risk event, geographical location information, risk event type, personnel or equipment identifier associated with the risk event, and a fragment of the original field data stream associated with the risk event for verification or corroboration of the risk event.

11. The system according to claim 8, characterized in that, The cloud management platform includes: A data aggregation and analysis module is configured to receive and store structured risk data from the edge computing nodes; In addition, a model training and distribution module is configured to train or optimize the risk identification model based on the data stored in the data aggregation and analysis module to generate an updated model, and distribute the updated model to the edge computing node.

12. The system according to claim 11, characterized in that, The model training and distribution module is further configured to fine-tune the risk identification model based on false alarm or missed alarm event samples in the structured risk data that have been manually reviewed and confirmed.

13. The system according to claim 8, characterized in that, The real-time analysis module is also configured to: Before the operation begins, the on-site data stream representing the implementation of safety measures is analyzed to determine whether the safety measures are compliant. After determining that the safety measures are compliant, the real-time analysis module is controlled to start the subsequent operation risk monitoring process.

14. A method for on-site risk management based on a cloud-edge-device collaborative architecture, characterized in that, The following steps are performed by a cloud management platform: Receive structured risk data corresponding to risk events from one or more edge computing nodes deployed at at least one work site; Based on the aggregated structured risk data, a risk identification model is trained or optimized to generate an updated risk identification model. In addition, the updated risk identification model is distributed to the one or more edge computing nodes so that the edge computing nodes can update the risk identification model stored locally.