Intrusion early warning method and system based on digital twinning

By constructing a digital twin of community security and using reinforcement learning algorithms, a security intrusion early warning model is generated, which solves the limitations of traditional security methods in terms of accuracy and dynamic strategy generation, and achieves efficient and accurate intrusion early warning and defense.

CN121640665AInactive Publication Date: 2026-03-10SHENZHEN ZHISIQIN NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-20
Publication Date
2026-03-10
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional community security methods have limitations in digital scenario construction, intelligent early warning accuracy, and dynamic strategy generation, resulting in delayed response and waste of resources, making it difficult to meet the needs of efficient and precise security.

Method used

By constructing a digital twin of community security and combining reinforcement learning and chaotic algorithms, a security intrusion early warning model is generated, including modules for anomaly diagnosis, real-time rendering, and intrusion game theory, to generate real-time security intrusion early warning and defense strategies.

Benefits of technology

It improves the accuracy and practicality of security intrusion early warning strategies, reduces the false alarm rate of anomaly detection, and enhances the accuracy of early warning and strategies for community security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121640665A_ABST
    Figure CN121640665A_ABST
Patent Text Reader

Abstract

The invention provides an intrusion early warning method and system based on digital twinning, and the method comprises the steps: carrying out the data collection of a community security area, carrying out the data preprocessing, obtaining a community security data set, building a community security digital twinning body based on the community security data set, generating an ideal community security data set, and carrying out the early warning of the intrusion. A security intrusion early warning model is constructed based on reinforcement learning and a chaos algorithm, pre-training is performed in combination with a community security data set and an ideal community security data set, and by training the security intrusion early warning model, the accuracy of the security intrusion early warning model on anomaly detection and the practicability and accuracy of a generation scheme are improved. Acquiring a real-time community security data set, inputting the real-time community security data set into the security intrusion early warning model to perform real-time security intrusion early warning, acquiring an intrusion early warning result, performing security intrusion game reasoning on the intrusion early warning result based on a security intrusion game mechanism, and acquiring a security intrusion prevention scheme. Based on the method, the early warning precision of community security and protection and the practicability and accuracy of the generation strategy are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, in particular to an intrusion early warning method and system based on digital twinning. BACKGROUND

[0002] At present, with the acceleration of urbanization and the expansion of community scale, community residents gradually increase the demand for real-time and accuracy of community security. However, the traditional community security scheme mostly relies on manual inspection and fixed parameter monitoring equipment to build community security defense line, often relies on manual experience to make abnormal judgment and formulate corresponding defense strategy. This method mode is often difficult to adapt to complex and changeable security scene.

[0003] The limitations of the traditional community security method mainly lie in the following aspects: on the one hand, the community scene restoration capability has certain limitations, the traditional method mostly relies on single two-dimensional camera image monitoring, which often cannot accurately map the three-dimensional geometric structure of the community, and often ignores the material and lighting characteristics of the building itself, resulting in low accuracy of community security monitoring; on the other hand, the strategy generation method often refers to the preset template, which cannot dynamically adjust the strategy according to the real-time abnormal type and security resource state, and the resource scheduling mostly relies on manual experience, which has high response time and is difficult to deal with complex intrusion behaviors such as camouflage and device interference, lacks dynamic game reasoning based on reinforcement learning, and often makes the generated security defense scheme less effective.

[0004] In summary, the traditional community security method has certain limitations in the aspects of digital scene construction, intelligent early warning accuracy and dynamic strategy generation, resulting in community security response lag, serious resource waste, and difficulty in meeting the needs of community for efficient and accurate security. SUMMARY

[0005] In view of the above-mentioned problems, in combination with the first aspect of the present application, the present application embodiment provides an intrusion early warning method based on digital twinning, which comprises: Data acquisition and preprocessing are performed on the community security area to obtain a community security dataset; A community security digital twin is constructed based on the community security dataset to generate an ideal community security dataset; An intrusion early warning model is constructed based on reinforcement learning and chaos algorithm, and pre-trained in combination with the community security dataset and the ideal community security dataset; A real-time community security dataset is obtained and input into the intrusion early warning model for real-time intrusion early warning to obtain an intrusion early warning result; An intrusion early warning result is obtained based on an intrusion game mechanism for intrusion game reasoning of the intrusion early warning result to obtain an intrusion defense scheme.

[0006] As a further scheme of the present application, a community security digital twin is constructed based on the community security dataset, and an ideal community security dataset is generated, including: For the community structure data contained in the community security dataset, bilateral filtering is used for denoising, and a voxel grid method is used for down-sampling to construct a lightweight community three-dimensional geometric model; Based on the community environment data contained in the community security dataset, a community ideal lighting distribution model is constructed, and the security facility data in the community security dataset is mapped into the lightweight community three-dimensional geometric model to construct a community security digital twin; According to the community security digital twin, an ideal community security dataset is generated.

[0007] As a further scheme of the present application, a security intrusion early warning model is constructed based on reinforcement learning and chaos algorithm, and pre-trained in combination with the community security dataset and the ideal community security dataset, including: The security intrusion early warning model includes an anomaly diagnosis module, a real-time rendering module, and an intrusion game module; The anomaly diagnosis module is constructed based on deep Q network and chaos algorithm, and pre-trained in combination with the community security dataset and the ideal community security dataset; The real-time rendering module is constructed based on meta-learning and chaos algorithm, and pre-trained on the real-time rendering module; The intrusion game module is constructed based on deep reinforcement learning and Monte Carlo algorithm, and pre-trained on the intrusion game module.

[0008] As a further scheme of the present application, an anomaly diagnosis module is constructed based on deep Q network and chaos algorithm, and pre-trained in combination with the community security dataset and the ideal community security dataset, including: ResNet50 is used to extract deep features from the security image data of the community security dataset and the ideal community security dataset, respectively, to obtain a security feature set, and chaos disturbance is injected into the security feature set based on the chaos algorithm to generate a security feature training set; A security feature matrix is constructed based on the security feature training set, a preliminary deviation loss corresponding to the community security dataset and the ideal community security dataset is obtained according to the security feature matrix, and the preliminary deviation loss is filtered for noise in combination with propensity score matching to generate deviation loss data; The deviation loss data and the community environment data in the community security dataset are input into the deep Q network, and iteration is performed according to a preset reward function to generate a dynamic anomaly judgment threshold; According to the dynamic anomaly judgment threshold and the deviation loss data, anomaly judgment is performed to generate an anomaly judgment type and corresponding anomaly coordinates.

[0009] As a further scheme of the present application, a real-time rendering module is constructed based on meta-learning and a chaos algorithm, and the real-time rendering module is pre-trained, comprising: The ideal community security data set is disturbed by the chaos algorithm to generate a rendering training data set, and the rendering training data set is clustered to generate a first rendering training data set with security intrusion anomalies and a second rendering training data set under normal conditions; The rendering image is generated according to the first rendering training data set, and iterative training is performed according to the L1 loss function until the preset first rendering module training condition is met to end the initial training; The second rendering training data set is input into the real-time rendering module to generate expected rendering image data, and the expected rendering image data and the abnormal image data contained in the second rendering training data set are input into the anomaly diagnosis module to obtain corresponding bias loss data; According to the bias loss data, the corresponding parameters in the real-time rendering module are adjusted, the bias loss data after adjusting the parameters is obtained, if the bias loss data after adjusting the parameters reaches the preset threshold, the training is ended, if the preset threshold is not reached, the corresponding parameters are adjusted again until the preset threshold is reached.

[0010] As a further scheme of the present application, an intrusion game module is constructed based on deep reinforcement learning and a Monte Carlo algorithm, and the intrusion game module is pre-trained, comprising: An end-to-end policy optimization algorithm is used to construct a security intrusion intelligent agent, logical rationality prior constraints are injected into the security intrusion intelligent agent, security intrusion cases are extracted from a preset security intrusion case database to generate a security intrusion training set and a resource scheduling training set; The security intrusion training set is input into the security intrusion intelligent agent to simulate security intrusion, and iterative training is performed according to a preset loss function until the security intrusion simulation data meets the security intrusion training condition to end the training; A propensity score matching algorithm and a Monte Carlo algorithm are used to construct a security scheduling intelligent agent, the resource scheduling training set is input into the security scheduling intelligent agent to simulate security scheduling, security scheduling simulation data is generated, the security scheduling simulation data is evaluated according to a preset security efficiency evaluation rule, if the result of the efficiency evaluation meets the preset standard, the training is ended, if the preset standard is not met, the security scheduling simulation data is iteratively optimized until the result of the efficiency evaluation meets the preset standard.

[0011] As a further scheme of the present application, a real-time community security data set is obtained, and a security intrusion early warning model is input to perform real-time security intrusion early warning to obtain an intrusion early warning result, comprising: Input the real-time community security data set into the security intrusion early warning model, and based on the abnormal diagnosis module and the real-time rendering module in the security intrusion early warning module, the type of security intrusion is judged and the real-time rendering of security image is generated, and the intrusion early warning result is generated. The intrusion early warning result at least includes the security intrusion type, the security intrusion location and the real-time rendering security intrusion image.

[0012] As a further scheme of the present application, based on the security intrusion game mechanism, the intrusion early warning result is subjected to security intrusion game reasoning to obtain a security intrusion defense scheme, which includes: The intrusion early warning result is input into the intrusion game module in the security intrusion early warning module, and the intrusion game module generates an original security dispatch action set based on the intrusion early warning result. Based on the propensity score matching algorithm, the security efficiency value of each security dispatch action in the original security dispatch action set is obtained, the security dispatch action with a security efficiency value lower than a preset security efficiency threshold is eliminated, and a security dispatch action set is generated. Based on the Monte Carlo algorithm, the security dispatch action set is subjected to reasoning game, and the efficiency is evaluated in combination with the preset security efficiency evaluation rule to generate a security intrusion defense scheme.

[0013] As a further scheme of the present application, data collection is performed on the community security area, and data preprocessing is performed to obtain a community security data set, which includes: While collecting data from the community security area, the collected original data is subjected to timestamp alignment and format standardization processing, abnormal data points are detected and interpolated and repaired by machine learning algorithm, and abnormal data points are removed. The community three-dimensional space structure data of the community security area is collected, the collected original data is divided into a regular voxel grid, and the community three-dimensional space structure features of each voxel position are encoded by a multilayer perception machine to generate a community three-dimensional space structure encoding set, and the community structure data is output as the community three-dimensional space structure encoding set. The environment data of the community security area is collected to obtain community meteorological data and community illumination data, the community illumination data is encoded by a fully connected neural network to generate a community illumination encoding set composed of illumination direction vectors and illumination intensity data, and the community environment data is output as the community meteorological data, community illumination data and community illumination encoding set. The data of the security facilities of the community security area is collected to obtain security camera parameter data and security camera image data, and the security camera image data is trained and learned by a convolutional neural network to output a community material encoding set, and the security facility data is output as the security camera parameter data, security camera image data and community material encoding set. The community structure data, community environment data, and security facility data are packaged into a community security dataset for output.

[0014] Furthermore, embodiments of the present invention also provide an intrusion warning system based on digital twins, comprising: The data acquisition module is used to collect data from the community security area and preprocess the collected raw data to generate a community security dataset. The data simulation module is used to construct a digital twin of community security based on the community security dataset and generate an ideal community security dataset. The model building module is used to build a security intrusion early warning model and pre-train the security intrusion early warning model by combining a community security dataset and an ideal community security dataset. An intrusion warning module is used to provide real-time security intrusion warnings for the community and obtain the intrusion warning results. The scheme generation module, the method generation module is used to perform security intrusion game reasoning on the intrusion warning result based on the security intrusion game mechanism, and generate a security intrusion defense scheme.

[0015] Compared with the prior art, the present invention has the following beneficial effects: Data was collected from community security areas and preprocessed to obtain a community security dataset. A digital twin of the community security was constructed based on the dataset, generating an ideal community security dataset. By collecting multi-dimensional community security data, three types of coding sets were generated: a community three-dimensional spatial structure coding set, a community lighting coding set, and a community material coding set. These coding sets provide a data foundation for the pre-training of subsequent security intrusion early warning models. A security intrusion early warning model is constructed based on reinforcement learning and chaotic algorithms, and pre-trained using community security datasets and ideal community security datasets. The security intrusion early warning model includes three sub-modules: an anomaly diagnosis module, a real-time rendering module, and an intrusion game module. The anomaly diagnosis module is constructed and trained by combining deep Q-networks and chaotic algorithms, thereby improving the sensitivity of the security intrusion early warning model to hidden anomalies and reducing the false alarm rate of anomaly detection. The real-time rendering module is constructed by combining meta-learning and chaotic algorithms, thereby balancing the accuracy of real-time rendering with the real-time performance of anomaly detection. The intrusion game module is constructed by combining deep reinforcement learning and Monte Carlo algorithms. The intrusion game module simulates real community security intrusion behavior, synchronously generates corresponding defense strategies, and filters them according to corresponding rules, thereby ensuring that the generated defense strategies are consistent with the actual community security scenario. The system acquires a real-time community security dataset and inputs it into a security intrusion early warning model to generate real-time security intrusion warnings. It then obtains the intrusion warning results and performs security intrusion game reasoning based on the security intrusion game mechanism to obtain security intrusion defense schemes. This improves the accuracy of community security early warnings and the practicality and accuracy of the generated strategies. Attached Figure Description

[0016] Figure 1 This is a flowchart of the steps of an intrusion early warning method based on digital twins according to the present invention; Figure 2 This is a schematic diagram of an intrusion warning model based on digital twins in this invention. Figure 3 This is a schematic diagram of an intrusion early warning system based on digital twins according to the present invention. Detailed Implementation

[0017] The present invention will now be described in detail with reference to the accompanying drawings. Figure 1 This is a flowchart illustrating the steps of an intrusion early warning method based on digital twins according to the present invention. Figure 2 This is a schematic diagram of an intrusion warning model based on digital twins according to the present invention. The following is a detailed introduction to this intrusion warning method based on digital twins.

[0018] Step S1: Collect data from the community security area and perform data preprocessing to obtain the community security dataset.

[0019] Specifically, while collecting data on community security areas, the collected raw data is timestamped and standardized in format. Machine learning algorithms are used to detect abnormal data points and perform interpolation repair and anomaly removal.

[0020] In this embodiment, step S1 includes: Step S11: Obtain community structure data and perform data preprocessing.

[0021] Specifically, the community security area is subjected to three-dimensional spatial structure data collection. The collected raw data is divided into regular voxel grids, and the three-dimensional spatial structure features of each voxel location are encoded by a multilayer perceptron to generate a community three-dimensional spatial structure encoding set. The community three-dimensional spatial structure encoding set is then output as community structure data.

[0022] In one possible embodiment, data on the entire community security area is collected. The entire community security area specifically includes the community walls, community entrances and exits, roads throughout the community, and community buildings in key areas. For example, the community walls include perimeter protection walls and isolation walls for key locations; the community entrances and exits include pedestrian access gates and vehicle access control systems; the roads throughout the community include main roads, branch roads, and parking lot access; and the community buildings include the facades of residential buildings and public facility buildings.

[0023] A 3D laser scanner is used to acquire point cloud data corresponding to the collection area. The point cloud data is analyzed to obtain spatial information such as the topography and building outlines of the community. The distance and average distance between each point in the point cloud data and its neighboring points are calculated. Points whose distance values ​​deviate from the average distance and exceed a preset threshold are identified as outliers and removed to eliminate noise interference during the laser scanning process. Voxel grid filtering is used for downsampling to generate initial community structure data.

[0024] Understandably, point cloud segmentation algorithms are used to distinguish different scene elements in the initial community structure data, retaining only the geometric information data used to describe the three-dimensional structure of the community. For example, random sampling consensus algorithms are used to distinguish unstructured scene elements of the community such as vegetation and vehicles, while retaining structured scene elements such as building walls and road surfaces. Outliers in the initial community structure data are removed by statistical filtering, and a three-dimensional geometric model of the community is constructed based on the Poisson reconstruction algorithm.

[0025] A dynamic octree voxelization method is used to divide the 3D geometric model of the community into voxel meshes, and the 3D coordinates corresponding to each voxel mesh unit are obtained. For example, regular voxel mesh units with a side length of 5cm are used to divide the 3D geometric model of the community into voxel meshes. The 3D coordinates of each voxel mesh unit and its corresponding neighborhood geometric features are input into a multilayer perceptron. The input data is processed by three fully connected layers in the multilayer perceptron, and the output is a volume density value in the range of [0, 1]. This volume density value is used to characterize the probability that an entity exists at the corresponding position in the 3D geometric model of the community. A value of 1 indicates that the current voxel mesh unit is a completely filled entity space, and a value of 0 indicates that the current voxel mesh unit is empty. Empty spaces, for example, in a 3D geometric model of a community, there is a closed metal security door. For the voxel mesh cells that make up the area of ​​the security door, the corresponding volume density values ​​obtained after calculation by a multilayer perceptron are mostly close to 1, indicating that the corresponding area in the 3D geometric model of the community is almost completely filled by the metal security door entity. For the corridor area outside the security door, the calculated volume density values ​​of the voxel mesh cells are mostly close to 0, such as 0.02, which means that most of the space is empty. If a fire extinguisher is placed in the corridor, assuming that the volume density value of the voxel mesh cells corresponding to the area where the fire extinguisher is located is around 0.7, it indicates that there may be an entity in that space.

[0026] Step S12: Obtain community environmental data and perform data preprocessing.

[0027] Specifically, by using a pre-set set of environmental sensors, the light intensity and weather conditions of the entire community are collected in real time to obtain community weather data and community light data. The community light data is then encoded using a fully connected neural network to generate a community light coding set consisting of light direction vectors and light intensity data. The community weather data, community light data, and community light coding set are then output as community environmental data.

[0028] In one possible embodiment, light source information data corresponding to different time periods in the community is acquired. For example, a panoramic image of the community containing sky and light source information is captured using a fisheye camera. Light source information data is extracted from the panoramic image using edge detection and feature extraction algorithms. A multimodal data fusion algorithm is then used to fuse the community illumination data with the light source information data to obtain a community fused illumination dataset. This dataset is then input into a fully connected neural network and encoded using a ReLU activation function to generate a community illumination coding set containing illumination direction vectors and illumination intensity. For example, a certain community illumination coding set might contain the code {[θ=270°, φ=45°], 320 lux}, indicating that the light source is coming from due west at a 45° elevation angle. Simultaneously, the illumination intensity corresponding to this code is 320 lux. Based on a preset community environment brightness discrimination rule, the current community environment brightness is determined to be at a moderately low level, close to the natural illumination intensity at dusk.

[0029] Step S13: Obtain security facility data and perform data preprocessing.

[0030] Specifically, data is collected on security facilities in community security areas to obtain security camera parameter data and security camera image data. The security camera parameter data includes internal and external parameters of the camera, such as focal length and distortion coefficient, which are internal parameters of the camera, and position and orientation, which are external parameters of the camera. For the security camera image data, Zhang's calibration method is used. By taking multiple sets of calibration board images from different angles, the least squares method is used to optimize and solve the problem, thereby calibrating the parameters to ensure the accuracy of the camera imaging.

[0031] By collecting security camera video data showing abnormal behaviors such as climbing over walls, illegal entry, and suspicious loitering through manual inspections and historical security intrusion records, this data is defined as anomalous sample data. This anomalous sample data undergoes multi-angle and multi-lighting condition enhancement processing to simulate security intrusion behavior under different environmental conditions. For example, a ±15° rotational perturbation is applied to the image data in the anomalous sample data to simulate the behavior of abnormal behavior from different perspectives; a ±20% brightness perturbation is applied to the anomalous sample data to simulate security camera video data under different lighting conditions, thereby expanding the diversity of the data.

[0032] The security camera image data is trained and learned by a convolutional neural network, and a community material encoding set consisting of three physically based rendering parameters: reflectivity, roughness, and metallicity is output. The security camera parameter data, security camera image data, and community material encoding set are then output as security facility data.

[0033] Understandably, by using hyperspectral imaging equipment to collect the spectral data of materials throughout the community, spectral reflectance data of different material surfaces within the community can be obtained, such as spectral reflectance data of common building materials like concrete, metal, and glass. The spectral reflectance data is then normalized using a minimum-maximum normalization method, mapping the values ​​of the spectral reflectance data to the [0, 1] interval. Texture image extraction is performed on security camera image data, and features are extracted from the extracted texture images using the SIFT feature extraction algorithm and the FAST corner detection algorithm to generate scene texture data.

[0034] The spectral reflectance data and scene texture data are input into a convolutional neural network, which outputs normalized reflectance, roughness, and metallicity. Reflectance describes the specular reflection intensity of different material surfaces; for example, the reflectance of red brick is approximately 0.33, and that of gray brick is approximately 0.23. In metallic materials, the reflectance range of stainless steel is [0.55, 0.65], and that of ordinary glass is [0.78, 0.82]. Roughness describes the degree of microscopic undulation on the surface of different materials; for example, in brick and stone materials… Since the material itself has a porous structure, its roughness can be represented as 0.8. For metal structures such as metal doors, the roughness can be represented as 0.2 because the surface of the structure has been precision machined. The metallicity is used to distinguish whether the material is conductive. For example, metal is a highly conductive material, so its corresponding metallicity is set to 1.0. Painting operations on the surface of metal reduce its conductivity, and for such materials, the metallicity can be set to a value between (0,1). For completely non-conductive materials such as bricks and rubber, the conductivity is set to 0.

[0035] Step S14: Generate a community security dataset.

[0036] Specifically, based on mutual information calculation, the mutual information values ​​of the codes within each pair of the community 3D spatial structure coding set, the community lighting coding set, and the community material coding set are obtained, and codes with mutual information values ​​lower than a preset threshold are eliminated. For example, the mutual information values ​​between corresponding codes between the community 3D spatial structure coding set and the community lighting coding set, the community 3D spatial structure coding set and the community material coding set, and the community lighting coding set and the community material coding set cannot exceed 0.1.

[0037] The community structure data, community environment data, and security facility data are packaged into a community security dataset for output.

[0038] Step S2: Construct a digital twin of community security based on the community security dataset to generate an ideal community security dataset.

[0039] Specifically, the community 3D geometric model constructed in step S11 is lightweighted to generate a lightweight community 3D geometric model. An ideal community lighting distribution model is constructed based on the community environment data contained in the community security dataset. The security facility data in the community security dataset is mapped to the lightweight community 3D geometric model to construct a community security digital twin. An ideal community security dataset is then generated based on the community security digital twin.

[0040] In this embodiment, step S2 includes: Step S21: Generate a lightweight community 3D geometric model.

[0041] Specifically, the edge-folding algorithm is used in conjunction with a pre-set simplification threshold to fold the edges of the community's 3D geometric model and construct a lightweight community 3D geometric model. For example, for non-critical structures such as wall decoration textures and green plant details, the corresponding triangle facet deletion rate is set to no more than 40%; for critical structures such as wall edges, entrance and exit door frames, and camera installation positions, the corresponding triangle facet retention rate is set to no less than 80%.

[0042] Step S22: Construct an ideal light distribution model for the community.

[0043] Specifically, the parallel light direction is adjusted based on the solar altitude angle contained in the community environmental data, and the ambient light intensity is dynamically adjusted according to the light intensity to simulate sunlight. For example, to simulate the shadow projection effect of the sun at noon on the summer solstice, assuming that the solar altitude angle is 73°, the parallel light direction is adjusted at this time, and the ambient light intensity is set to 800 lux. Based on the above operations and combined with the pre-input simulated sunrise and sunset times, the parallel light direction and ambient light intensity are dynamically adjusted during the simulation to achieve all-weather dynamic simulation of sunlight.

[0044] For the community street light system, the on / off time and illumination range of the street lights are set, and a brightness fluctuation of [10%, 15%] is applied according to the aging degree of the street lights to simulate the lighting facilities. For example, the on / off time of the street lights is set to 18:00 to 6:00, the illumination range of each street light is set to 15 meters, the luminous intensity of the street lights is set to 200 lux, and point light sources are used to simulate the diffuse lighting effect of the street lights, thereby realizing the simulation of street lights and other lighting facilities.

[0045] A mapping table between weather and illumination is established based on community environmental data. Ambient light parameters are dynamically adjusted according to different weather conditions. For example, on rainy days, the ambient light reflectance coefficient is reduced by 30%, and raindrop refraction simulation is enabled to make the scene appear dark and wet. On snowy days, the ambient light scattering coefficient is increased by 20% to simulate the diffuse reflection of light in the snow scene. At the same time, multiple illumination parameter templates are preset for extreme weather such as fog and sandstorms to achieve coupled simulation between weather and illumination.

[0046] An ideal light distribution model for the community is constructed based on the aforementioned solar illumination simulation, lighting facility simulation, and coupling simulation between the image and the light.

[0047] Step S23: Construct a digital twin of community security and generate an ideal community security dataset.

[0048] A community security digital twin is constructed based on a lightweight 3D geometric model of the community and an ideal lighting distribution model of the community. Based on the community security digital twin, ideal community structure data, ideal community environment data, and ideal security facility data are generated to create an ideal community security dataset. The data format and data type of the ideal community security dataset are consistent with those of the community security dataset. The ideal community security dataset can be regarded as a community security dataset under ideal conditions. For example, in reality, security cameras in communities may have aging circuits or be in disrepair, which may lead to certain deviations in the collected community security dataset. The ideal community security dataset, on the other hand, represents the community security dataset collected under the ideal condition that the community's security facilities are free from any faults or defects.

[0049] Step S3: Construct a security intrusion early warning model based on reinforcement learning and chaotic algorithms, and pre-train it using a community security dataset and an ideal community security dataset.

[0050] Specifically, the security intrusion early warning model includes an anomaly diagnosis module, a real-time rendering module, and an intrusion game theory module.

[0051] In this embodiment, step S3 includes: Step S31: Construct an anomaly diagnosis module based on deep Q-network and chaotic algorithm, and pre-train it using community security dataset and ideal community security dataset.

[0052] Specifically, ResNet50 is used to extract deep features from security image data in both the community security dataset and the ideal community security dataset to obtain a security feature set. Then, based on a chaos algorithm, chaotic perturbations are injected into the security feature set to generate a security feature training set.

[0053] A security feature matrix is ​​constructed based on the security feature training set. The preliminary deviation loss corresponding to the community security dataset and the ideal community security dataset is obtained based on the security feature matrix. The preliminary deviation loss is then filtered for noise by combining the propensity score matching to generate deviation loss data.

[0054] The deviation loss data and community environment data from the community security dataset are input into a deep Q-network, and the network is iterated according to a preset reward function to generate a dynamic anomaly detection threshold.

[0055] Anomalies are determined based on the dynamic anomaly determination threshold and deviation loss data, generating anomaly determination types and corresponding anomaly coordinates.

[0056] In one possible embodiment, a normal community security dataset and an ideal community security dataset are collected from historical data. A normal training set is generated using a chaotic algorithm and input into the anomaly diagnosis module for initial pre-training. During the training process, four evaluation indicators are monitored: shadow matching degree, illumination gradient deviation, reflection similarity, and single-frame feature extraction time. The evaluation indicators are iteratively trained until they reach preset thresholds. The iterative training ends when the corresponding preset thresholds are reached. For example, the preset thresholds for shadow matching degree are 91%, illumination gradient deviation are 4.6%, reflection similarity are 93%, and single-frame feature extraction time is 16ms.

[0057] A community security dataset showing anomalies in historical data and an ideal community security dataset are collected. An anomaly training set is generated using a chaotic algorithm and input into the anomaly diagnosis module after initial pre-training for secondary training. The secondary training employs an iterative training strategy combining a deep Q-network and a chaotic optimization algorithm. During iterative training, multiple sets of data are randomly selected from the anomaly training set and input into the feature extraction layer of the anomaly diagnosis module to obtain feature differences. An action is selected based on an ε-greedy policy, and the reward value corresponding to that action is calculated simultaneously. The corresponding weights of the deep Q-network are updated using a temporal difference algorithm. For example, the initial value of ε for the ε-greedy policy is set to 0.3, and ε is constrained to decay by 0.05 every 100 training iterations. Assume the action selected from the preset action space is "reduce the shadow detection threshold from 83%..." If the error rate is increased to 84%, and after this action, the result of four consecutive anomaly detections is 3 correct warnings and 1 false alarm, then the corresponding reward value is 10×3-8×1=22, where 10 is the reward score for a correct warning and 8 is the penalty score for a false alarm. Using a preset loss function as the optimization objective, the loss value output by the loss function is propagated backward along the network structure through the backpropagation algorithm. The contribution of each parameter in the deep Q network to the loss value output by the loss function is calculated, and then the corresponding network parameters are adjusted. This allows the anomaly diagnosis module to output better decision actions when faced with similar community security dataset inputs, reducing the false alarm rate and increasing the number of correct warnings, thereby enhancing the practicality of the model in community security scenarios.

[0058] Data that was not pre-trained is extracted from the normal training set and the abnormal training set and input into the abnormal diagnosis module for abnormality judgment. The abnormality judgment accuracy, abnormal point location error and single module processing time are obtained. If the abnormality judgment accuracy, abnormal point location error and single module processing time reach the predetermined standard, the pre-training is judged to be qualified. If the predetermined standard is not reached, the pre-training is repeated until the predetermined standard is reached.

[0059] Step S32: Construct a real-time rendering module based on meta-learning and chaotic algorithms, and pre-train the real-time rendering module.

[0060] Specifically, a chaotic perturbation is applied to the ideal community security dataset using a chaotic algorithm to generate a rendering training dataset. The rendering training dataset is then clustered to generate a first rendering training dataset with security intrusion anomalies and a second rendering training dataset with normal conditions.

[0061] Rendered images are generated based on the first rendering training dataset, and iterative training is performed based on the L1 loss function until the preset training conditions of the first rendering module are met, thus ending the initial training.

[0062] The second rendering training dataset is input into the real-time rendering module after the initial training to generate the expected rendering image data. The expected rendering image data and the abnormal image data contained in the second rendering training dataset are input into the anomaly diagnosis module to obtain the corresponding deviation loss data.

[0063] The corresponding parameters in the real-time rendering module are adjusted based on the deviation loss data, and the deviation loss data after the adjustment is obtained. If the deviation loss data after the adjustment reaches a preset threshold, the training ends. If it does not reach the preset threshold, the corresponding parameters are readjusted until the preset threshold is reached.

[0064] In one possible embodiment, multiple sets of first rendering training datasets covering the entire community are generated based on a community security digital twin combined with a community 3D spatial structure encoding set, a community lighting encoding set, and a community material encoding set. The data in the first rendering training dataset is in the form of {virtual image, virtual image coordinates, viewpoint parameters}. The virtual image coordinates represent the coordinate position of the generated virtual image within the community security digital twin, and the viewpoint parameters represent the camera viewpoint corresponding to the virtual image. For example, the time parameter can be represented as [300 meters from the wall, azimuth 180°, pitch 10°, distance 10 meters]. A chaotic perturbation is applied to the first rendering training dataset using a chaotic algorithm to generate a second rendering training dataset. Multiple sets of data are randomly selected from the first rendering training dataset, and the virtual image coordinates and viewpoint parameters are input into the real-time rendering module to generate the expected virtual image. The expected virtual image and the corresponding virtual image are input together into the anomaly diagnosis module to calculate the difference loss between them, such as using MSE bias loss*. The difference loss is calculated as 0.6 + cross-entropy classification loss * 0.4. If the difference loss does not meet expectations, it is backpropagated to the real-time rendering module to update the combined weights and values ​​of the community 3D spatial structure encoding set, community lighting encoding set, and community material encoding set. For example, the reflectivity value of red bricks in the community material encoding set is adjusted from 0.45 to 0.44, the illumination intensity in the community lighting encoding set is adjusted from 800 lux to 780 lux, and the combined weights of the community 3D spatial structure encoding set, community lighting encoding set, and community material encoding set are adjusted from 6:2:2 to 5:3:2. The expected virtual image is regenerated based on the adjusted community 3D spatial structure encoding set, community lighting encoding set, and community material encoding set. The expected virtual image and the corresponding virtual image are then input into the anomaly diagnosis module for difference loss calculation. The difference loss between the expected virtual image and the virtual image is gradually reduced through iterative training until the difference loss meets expectations, at which point the training ends.

[0065] Step S33: Construct an intrusion game module based on deep reinforcement learning and Monte Carlo algorithm, and pre-train the intrusion game module.

[0066] In this embodiment, step S33 includes: Step S33-1: Build and train the security intrusion intelligent agent.

[0067] Specifically, a near-end strategy optimization algorithm is used to construct a security intrusion agent, and pre-set logical rationality prior constraints are injected into the security intrusion agent. Security intrusion cases are extracted from a pre-set security intrusion case database to generate a security intrusion training set.

[0068] The security intrusion training set is input into the security intrusion agent to simulate security intrusion, generate security intrusion simulation data, and iteratively train according to the preset loss function until the security intrusion simulation data meets the security intrusion training conditions and the training ends.

[0069] In one possible embodiment, a state space is defined for the security intrusion agent. For example, the state space can be defined as [intruder coordinates, intrusion distance, security resource scheduling distance, terrain type, remaining intrusion time, probability of being detected], where the intruder coordinates represent the current coordinates of the simulated intruder, the intrusion distance represents the distance between the simulated intruder and the abnormal trigger point, the security resource scheduling distance represents the distance between the simulated intruder and the community security resources, the terrain type includes roads, walls, and buildings, the remaining intrusion time represents the estimated time remaining until the simulated intruder breaks through the community security defense line, and the probability of being detected represents the probability that the simulated intruder will be detected by the security resources.

[0070] Define the action space of the security intrusion agent. For example, define the action space as [movement direction, movement speed, concealment action, discrete value, reward coefficient], where the movement direction is a continuous value in the range of [0°, 360°] with a step size of 1°, used to describe the turning angle of the simulated intruder; the movement speed is a continuous value in the range of [0.5, 1.2] m / s with a step size of 0.1 m / s, used to reflect the movement speed of the simulated intruder; the concealment action includes three actions: standing still, low-profile movement, and normal movement, and the three actions correspond to three discrete values ​​and three reward coefficients of 0.5, 1.0, and 0.8, respectively. The standing still action is used to describe the simulated intruder making suspicious observations; the low-profile movement action is used to describe the simulated intruder attempting to evade monitoring; and the normal movement action serves as a baseline reference.

[0071] Define a reward function for the security intrusion agent and obtain the reward value through the reward function. For example, assume the reward function is 8*(1-current simulated intruder's distance from the target point / initial distance)-10*detection probability-5*(actual movement time / expected movement time)+3*covery action coefficient. Simulate an intruder moving from an anomaly point (120,350) to a residential building (100,350), with an initial distance of 20m, a current simulated intruder's distance from the target point of 10m, a detection probability of 10%, an actual movement time of 5s, and an expected movement time of 4s. Simulate the intruder performing low-posture movement during the movement, with a corresponding reward coefficient of 1.0. Then the reward value = 8*(1-10 / 20)-10*0.1-5*(5 / 4)+3*1.0=-0.25. Add terrain constraints to the security intrusion agent, for example, walls cannot be crossed. If a situation occurs where the intruder crosses a wall during the simulation, a reward value penalty of -20 is applied.

[0072] Security intrusion cases are extracted from a pre-defined security intrusion case database. These cases are then combined with a community security digital twin to generate a security intrusion training set and a resource scheduling training set. The data in the security intrusion training set is represented as {intrusion origin, intrusion path, intrusion target point, success / failure label}. Iterative training of the security intrusion agent is performed based on a near-end policy optimization algorithm. During iteration, trajectory data after inputting the security intrusion training set into the security intrusion agent is collected. An advantage function and a reward function are calculated based on the collected trajectory data. The advantage function uses generalized advantage estimation. The weights in the near-end policy optimization algorithm are updated based on the calculated advantage function and a pre-defined loss function, resulting in higher rewards for the simulated intrusion trajectories generated by the security intrusion agent. This makes the simulated intrusion trajectories closer to real intrusion trajectories. Simultaneously, the generated simulated intrusion trajectories are compensated and corrected using intrusion paths from the security intrusion training set, thus ending the security intrusion agent training.

[0073] Step S33-2: Construct and train the security dispatch intelligent agent.

[0074] Specifically, a security scheduling intelligent agent is constructed using a propensity score matching algorithm and a Monte Carlo algorithm. The resource scheduling training set is input into the security scheduling intelligent agent to perform security scheduling simulation, generating security scheduling simulation data. The security scheduling simulation data is evaluated according to preset security performance evaluation rules. If the performance evaluation result meets the preset standard, the training ends. If the preset standard is not met, the security scheduling simulation data is iteratively optimized until the performance evaluation result meets the preset standard.

[0075] In one possible embodiment, a propensity score matching algorithm is used to calculate the causal effect value between security resource scheduling actions and defense effectiveness. The formula for calculating the causal effect value can be expressed as follows: ,in, As a binary variable, it represents the defensive effect. The time indicates a successful defense. This indicates a failed defense; Used to describe the execution status of security resource scheduling actions. This indicates the execution of a scheduling action. This indicates that the action was not executed. For covariate-based The obtained prediction propensity score is used to describe the probability of performing security resource scheduling actions. Valid scheduling actions with a causal effect value of not less than 0.5 are selected, such as scheduling cameras around anomaly points. The causal effect value corresponding to this security resource scheduling action is 0.8. Invalid scheduling actions with a causal effect value of less than 0.5 are excluded, such as scheduling security personnel far away from anomaly points. The causal effect value corresponding to this security resource scheduling action is 0.1, so this invalid scheduling action is removed.

[0076] Based on the Monte Carlo algorithm, the selected effective scheduling actions are inferred to generate threat confirmation probability, intrusion prevention probability, and response time. The threat confirmation probability is represented by the probability that the camera covers an abnormal area; the intrusion prevention probability is represented by the probability that the security personnel arrive at the abnormal point in less time than the security intruder breaks through the community security defense line. The threat confirmation probability, intrusion prevention probability, and response time are weighted and fused based on a preset weight ratio to generate a scheduling strategy score.

[0077] Security intrusion cases are extracted from a pre-set security intrusion case database to generate a resource scheduling training set. This training set is then input into a security scheduling intelligent body for pre-training. Based on the training set, the intelligent body generates anomaly regions and various combinations of security resource scheduling actions. These combinations include both effective and ineffective scheduling actions. Monte Carlo simulations are performed on the security resource scheduling actions within each combination to obtain corresponding causal effect values ​​and scheduling strategy scores. Based on these scores, thresholds are calculated for the corresponding causal effect values, and parameter weights within the scheduling strategy scores are optimized until the data generated by the intelligent body meets expectations. For example, the accuracy rate of selecting effective scheduling action combinations is required to be no less than 85%, and the time taken for a single simulation is less than 0.5 seconds.

[0078] Step S4: Obtain the real-time community security dataset and input it into the security intrusion warning model to perform real-time security intrusion warning and obtain the intrusion warning results.

[0079] Specifically, the real-time community security dataset is input into the security intrusion early warning model. Based on the anomaly diagnosis module and real-time rendering module within the security intrusion early warning module, the security intrusion type is determined and the security image is rendered in real time to generate an intrusion early warning result. The intrusion early warning result includes at least the security intrusion type, the security intrusion location, and the real-time rendered security intrusion image.

[0080] Step S5: Based on the security intrusion game mechanism, perform security intrusion game reasoning on the intrusion warning results to obtain a security intrusion defense plan.

[0081] Specifically, the intrusion warning result is input into the intrusion game module within the security intrusion warning model. The intrusion game module generates an original security scheduling action set based on the intrusion warning result. It obtains the security effectiveness value of each security scheduling action in the original security scheduling action set through a propensity score matching algorithm. The security effectiveness value represents the causal effect value of the security scheduling action. Security scheduling actions with security effectiveness values ​​lower than a preset security effectiveness threshold are removed, generating a security scheduling action set. The security scheduling action set is then subjected to reasoning game based on the Monte Carlo algorithm to generate a corresponding scheduling strategy score. Finally, the security scheduling action set is evaluated for effectiveness in conjunction with preset security effectiveness evaluation rules to generate a security intrusion defense scheme.

[0082] Figure 3 This is a schematic diagram of an intrusion early warning system based on digital twins according to the present invention.

[0083] Specifically, an intrusion warning system based on digital twins includes: The data acquisition module is used to collect data from the community security area and preprocess the collected raw data to generate a community security dataset.

[0084] The data simulation module is used to construct a digital twin of community security based on the community security dataset and generate an ideal community security dataset.

[0085] The model building module is used to build a security intrusion early warning model and pre-train the security intrusion early warning model by combining the community security dataset and the ideal community security dataset.

[0086] An intrusion warning module is used to provide real-time security intrusion warnings for the community and obtain the intrusion warning results.

[0087] The scheme generation module, the method generation module is used to perform security intrusion game reasoning on the intrusion warning result based on the security intrusion game mechanism, and generate a security intrusion defense scheme.

[0088] The specific usage and function of this embodiment are explained below: First, data is collected from the community security area and preprocessed to obtain a community security dataset. Based on the community security dataset, a digital twin of the community security is constructed to generate an ideal community security dataset. Multi-dimensional data is collected from the entire community security area, and three types of coding sets are generated based on the collected multi-dimensional data: community three-dimensional spatial structure coding set, community lighting coding set, and community material coding set. The community security dataset and the coding sets provide a data foundation for the pre-training of the subsequent security intrusion early warning model. Next, a security intrusion early warning model is constructed based on reinforcement learning and chaotic algorithms. This model is pre-trained using a community security dataset and an ideal community security dataset. The model comprises three sub-modules: an anomaly diagnosis module, a real-time rendering module, and an intrusion game theory module. The anomaly diagnosis module is constructed and trained using a combination of deep Q-networks and chaotic algorithms, thereby improving the model's sensitivity to hidden anomalies and reducing the false alarm rate. The real-time rendering module is constructed using a combination of meta-learning and chaotic algorithms, achieving a balance between the accuracy of real-time rendering and the real-time performance of anomaly detection. The intrusion game theory module is constructed using a combination of deep reinforcement learning and Monte Carlo algorithms. This module simulates real-world community security intrusion behaviors, synchronously generating corresponding defense strategies and filtering them according to relevant rules, ensuring that the generated defense strategies closely match actual community security scenarios. Finally, a real-time community security dataset is obtained and input into the security intrusion early warning model for real-time security intrusion early warning. The intrusion early warning results are obtained, and security intrusion game reasoning is performed on the intrusion early warning results based on the security intrusion game mechanism to obtain security intrusion defense schemes, thereby improving the early warning accuracy of community security and the practicality and accuracy of the generated strategies.

[0089] It should be understood that, in the embodiments of the present invention, the order of the above-mentioned process numbers does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0090] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.

[0091] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A digital-twin-based intrusion early warning method, characterized in that, The method comprises the following steps: Data collection and preprocessing are performed on the community security area to obtain a community security dataset; A community security digital twin is constructed based on the community security dataset to generate an ideal community security dataset; An intrusion warning model is constructed based on reinforcement learning and chaos algorithm, and pre-trained in combination with the community security dataset and the ideal community security dataset; Real-time community security data is obtained and input into the intrusion warning model for real-time intrusion warning, and an intrusion warning result is obtained; An intrusion defense scheme is obtained based on the intrusion game mechanism.

2. The intrusion early warning method based on digital twinning according to claim 1, characterized in that, The community security digital twin is constructed based on the community security dataset to generate an ideal community security dataset, comprising: The community structure data contained in the community security dataset is denoised using bilateral filtering and down-sampled using the voxel grid method to construct a lightweight community three-dimensional geometric model; A community ideal lighting distribution model is constructed based on the community environment data contained in the community security dataset, and the security facility data in the community security dataset is mapped into the lightweight community three-dimensional geometric model to construct the community security digital twin; The ideal community security dataset is generated based on the community security digital twin.

3. The intrusion early warning method based on digital twinning according to claim 1, characterized in that, The intrusion warning model is constructed based on reinforcement learning and chaos algorithm, and pre-trained in combination with the community security dataset and the ideal community security dataset, comprising: The intrusion warning model includes an anomaly diagnosis module, a real-time rendering module, and an intrusion game module; The anomaly diagnosis module is constructed based on deep Q network and chaos algorithm, and pre-trained in combination with the community security dataset and the ideal community security dataset; The real-time rendering module is constructed based on meta-learning and chaos algorithm, and pre-trained; The intrusion game module is constructed based on deep reinforcement learning and Monte Carlo algorithm, and pre-trained.

4. The intrusion early warning method based on digital twinning according to claim 3, characterized in that, The anomaly diagnosis module is constructed based on deep Q network and chaos algorithm, and pre-trained in combination with the community security dataset and the ideal community security dataset, comprising: ResNet50 is used to extract deep features from the security image data of the community security dataset and the ideal community security dataset to obtain a security feature set, and chaos disturbance is injected into the security feature set based on the chaos algorithm to generate a security feature training set; A security feature matrix is constructed based on the security feature training set, a preliminary bias loss corresponding to the community security dataset and the ideal community security dataset is obtained according to the security feature matrix, and the preliminary bias loss is filtered to generate bias loss data in combination with propensity score matching; The bias loss data and the community environment data in the community security dataset are input into the deep Q network, and iteration is performed according to a preset reward function to generate a dynamic anomaly judgment threshold; Anomaly judgment is performed according to the dynamic anomaly judgment threshold and the bias loss data to generate an anomaly judgment type and corresponding anomaly coordinates.

5. The intrusion early warning method based on digital twinning according to claim 3, characterized in that, The real-time rendering module is constructed based on meta-learning and chaos algorithm, and pre-trained, comprising: The ideal community security data set is disturbed by a chaos algorithm to generate a rendered training data set, and the rendered training data set is clustered to generate a first rendered training data set with security intrusion anomalies and a second rendered training data set with normal conditions; A rendered image is generated according to the first rendered training data set, and iterative training is performed according to an L1 loss function until a preset first rendering module training condition is met to end the initial training; The second rendered training data set is input into the real-time rendering module after the initial training to generate expected rendered image data, the expected rendered image data and abnormal image data contained in the second rendered training data set are input into an anomaly diagnosis module to obtain corresponding bias loss data; According to the bias loss data, the corresponding parameters in the real-time rendering module are adjusted to obtain the bias loss data after adjusting the parameters, and if the bias loss data after adjusting the parameters reaches a preset threshold, the training is ended, and if the preset threshold is not reached, the corresponding parameters are adjusted again until the preset threshold is reached.

6. The intrusion early warning method based on digital twinning according to claim 3, characterized in that, An intrusion game module is constructed based on deep reinforcement learning and Monte Carlo algorithm, and the intrusion game module is pre-trained, including: An end-to-end policy optimization algorithm is used to construct a security intrusion intelligent agent, logical rationality prior constraints are injected into the security intrusion intelligent agent, security intrusion cases are extracted from a preset security intrusion case database to generate a security intrusion training set and a resource scheduling training set; The security intrusion training set is input into the security intrusion intelligent agent to simulate security intrusion, and the security intrusion simulation data is generated, and iterative training is performed according to a preset loss function until the security intrusion simulation data meets the security intrusion training condition to end the training; A propensity score matching algorithm and a Monte Carlo algorithm are used to construct a security scheduling intelligent agent, the resource scheduling training set is input into the security scheduling intelligent agent to simulate security scheduling, security scheduling simulation data is generated, and the security scheduling simulation data is evaluated according to a preset security efficiency evaluation rule, if the result of the efficiency evaluation meets the preset standard, the training is ended, if the preset standard is not met, the security scheduling simulation data is iteratively optimized until the result of the efficiency evaluation meets the preset standard.

7. The intrusion early warning method based on digital twinning according to claim 1, characterized in that, A real-time community security data set is obtained, and a security intrusion early warning model is input to perform real-time security intrusion early warning to obtain an intrusion early warning result, including: The real-time community security data set is input into the security intrusion early warning model, and the security intrusion type is determined and the security image is rendered in real time based on the anomaly diagnosis module and the real-time rendering module in the security intrusion early warning module to generate the intrusion early warning result; The intrusion early warning result at least includes the security intrusion type, the security intrusion location, and the real-time rendered security intrusion image.

8. The intrusion early warning method based on digital twinning according to claim 1, characterized in that, Based on the security intrusion game mechanism, the intrusion early warning result is reasoned to obtain a security intrusion defense scheme, including: The intrusion early warning result is input into the intrusion game module in the security intrusion early warning module, and the intrusion game module generates an original security scheduling action set based on the intrusion early warning result; Obtain the security effectiveness value of each security dispatch action in the original security dispatch action set based on a propensity score matching algorithm, eliminate the security dispatch action whose security effectiveness value is lower than a preset security effectiveness threshold, and generate a security dispatch action set; Reason and game based on the security dispatch action set by using a Monte Carlo algorithm, and perform effectiveness evaluation in combination with a preset security effectiveness evaluation rule to generate a security intrusion defense scheme.

9. The intrusion early warning method based on digital twinning according to claim 1, characterized in that, Data collection is performed on the community security area, and data preprocessing is performed to obtain a community security data set, including: While collecting data on the community security area, the collected raw data is timestamped and standardized, and abnormal data points are detected and repaired by interpolation and excluded by using a machine learning algorithm; The community three-dimensional spatial structure data of the community security area is collected, the collected raw data is divided into a regular voxel grid, and the community three-dimensional spatial structure features of each voxel position are encoded by using a multilayer perception machine to generate a community three-dimensional spatial structure code set, which is output as community structure data; The community environment data of the community security area is collected to obtain community meteorological data and community illumination data, the community illumination data is encoded by using a fully connected neural network to generate a community illumination code set composed of illumination direction vectors and illumination intensity data, and the community meteorological data, community illumination data and community illumination code set are output as community environment data; The security facilities data of the community security area is collected to obtain security camera parameter data and security camera image data, and the security camera image data is trained and learned by using a convolutional neural network to output a community material code set, and the security camera parameter data, security camera image data and community material code set are output as security facility data; The community structure data, community environment data and security facility data are packaged as a community security data set for output.

10. A digital-twin-based intrusion alerting system for implementing the method of any one of claims 1 to 9, characterized in that, It includes: The data acquisition module is used for collecting data on the community security area, and preprocessing the collected raw data to generate a community security data set; The data simulation module is used for constructing a community security digital twin based on the community security data set to generate an ideal community security data set; The model construction module is used for constructing a security intrusion early warning model, and pre-training the security intrusion early warning model in combination with the community security data set and the ideal community security data set; The intrusion early warning module is used for real-time security intrusion early warning of the community and obtaining an intrusion early warning result; The scheme generation module is used for security intrusion game reasoning of the intrusion early warning result based on a security intrusion game mechanism to generate a security intrusion defense scheme.