Distributed fiber optic vibration event detection method and system

By collecting data through distributed optical fiber sensing units and decomposing it in the time and frequency domain, a vibration energy transfer matrix and a causal dependency graph are constructed to identify cross-regional vibration events. This solves the problems of difficulty in determining the location of intrusion sources and high false alarm rates in existing technologies, and achieves efficient security protection.

CN121829735BActive Publication Date: 2026-07-07BEIJING GUANYU INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610049807.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-15
Publication Date
2026-07-07
Estimated Expiration
2046-01-15

AI Technical Summary

Technical Problem

Existing distributed fiber optic vibration sensing systems struggle to identify complex cross-regional intrusion behavior patterns, cannot accurately locate intrusion sources, are susceptible to environmental interference leading to high false alarm rates, and lack temporal and spatial correlation analysis of vibration events.

Method used

Vibration signals are collected by distributed optical fiber sensing units, decomposed in the time and frequency domains, and a vibration energy transfer matrix and causal dependency graph are constructed to identify cross-regional vibration events and generate regional cascade response commands to control protective equipment for coordinated protection.

Benefits of technology

It improves the system's ability to identify real intrusion events, reduces environmental noise interference and false alarm rate, enhances the system's adaptability and robustness in complex environments, and achieves accurate location and efficient protection of intrusion source location and movement trajectory.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121829735B_ABST
    Figure CN121829735B_ABST
Patent Text Reader

Abstract

The application provides a distributed optical fiber vibration event detection method and system, relates to the technical field of detection, and comprises the following steps: collecting vibration signals with time domain waveforms and spatial identifiers through a distributed optical fiber, performing time-frequency domain decomposition to extract a characteristic vector, constructing a vibration energy transmission matrix to perform traceability analysis, establishing an inter-regional vibration response causal dependence graph to identify a linkage intrusion event and determine an intrusion source position and a trajectory, and further generating a regional cascade response instruction. The application realizes accurate identification and tracking of cross-regional intrusion behaviors, and improves the sensing capability and linkage response efficiency of a protection system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of detection technology, and in particular to a method and system for detecting distributed optical fiber vibration events. Background Technology

[0002] Distributed fiber optic sensing technology utilizes optical fibers as sensing elements to achieve real-time sensing of physical quantities such as vibration, temperature, and stress in a wide-area, long-distance environment. Distributed fiber optic vibration sensing systems, in particular, are widely used in security protection fields such as perimeter protection, pipeline safety monitoring, and railway and highway monitoring due to their advantages of high sensitivity, resistance to electromagnetic interference, and long-distance distributed deployment. Traditional distributed fiber optic vibration sensing systems typically use a single sensor to collect vibration signals, and then use signal processing technology to detect and identify vibration events to trigger alarms for intrusion attempts.

[0003] Existing technologies primarily target vibration events at single points or in single spatial areas, lacking the ability to comprehensively analyze multi-area interconnected vibration events and thus struggling to effectively identify complex cross-area intrusion behavior patterns. When an intruder moves from one area to another, the system often treats these as multiple independent events, failing to correlate and identify a complete intrusion trajectory.

[0004] Traditional vibration event detection methods often rely on simple threshold judgments or feature analysis of single areas, failing to fully consider the spatial propagation characteristics of vibration energy and making it difficult to accurately distinguish between real intrusion events and environmental interference. In complex environments, vibration interference caused by natural factors such as wind and rain can lead to a high false alarm rate, reducing the reliability of the protection system.

[0005] Existing technologies lack the ability to analyze the temporal and spatial correlations of vibration events, making it impossible to construct a causal network for vibration propagation. This makes it difficult for the system to trace the source of vibration, especially when multiple vibration events occur simultaneously. It is impossible to accurately locate the true source of intrusion or predict the possible direction of intruder movement based on the propagation patterns of vibration, thus affecting the early warning capability and protection efficiency of the protection system. Summary of the Invention

[0006] The present invention provides a distributed optical fiber vibration event detection method and system, which can solve the problems in the prior art.

[0007] A first aspect of the present invention provides a distributed optical fiber vibration event detection method, comprising:

[0008] Vibration signals from multiple spatial regions are collected by distributed optical fiber sensing units deployed along a preset path. The vibration signals include time-domain waveforms and spatial location identifiers.

[0009] The vibration signal is decomposed in the time-frequency domain to extract feature vectors reflecting the vibration mode, and the feature vectors are mapped to corresponding spatial regions according to the spatial location identifiers to form a regional feature set;

[0010] For multiple spatial regions in the aforementioned regional feature set, a transfer matrix of vibration energy is constructed among these regions. This transfer matrix characterizes the diffusion path and energy distribution ratio of vibration energy from the source region to adjacent regions. Based on this transfer matrix, energy flow source tracing analysis is performed on the feature vectors of different spatial regions to identify cross-regional vibration events with a common energy source.

[0011] A causal dependency graph of vibration response between regions is established. In the causal dependency graph, nodes represent spatial regions, edges represent vibration transmission relationships between regions, and edge weights represent the temporal sequence of vibration transmission. Linked intrusion events are identified by searching for subgraph structures that satisfy a preset topological pattern in the causal dependency graph. The spatial location and movement trajectory of the intrusion source are determined based on the topological position of the nodes in the subgraph structure. The topological pattern is defined by a region access sequence that characterizes the intrusion behavior.

[0012] Based on the spatial location and movement trajectory of the linked intrusion event, a regional cascade response command is generated. The regional cascade response command is used to control the protective equipment corresponding to the multiple spatial regions to perform linked protective actions.

[0013] The vibration signal is decomposed in the time-frequency domain to extract feature vectors reflecting the vibration mode. These feature vectors are then mapped to corresponding spatial regions based on the spatial location identifiers, forming a regional feature set including:

[0014] The vibration signal is decomposed into a multi-resolution time-frequency domain to obtain a time-frequency distribution matrix characterizing the evolution of different frequency components over time. The time axis of the time-frequency distribution matrix corresponds to the sampling time of the vibration signal, the frequency axis corresponds to the spectral components of the vibration signal, and the matrix element values ​​correspond to the energy amplitude of the frequency component at a certain time.

[0015] Statistical and morphological features characterizing vibration modes are extracted from the time-frequency distribution matrix. The statistical features include energy distribution statistics of the time-frequency distribution matrix in the time and frequency dimensions, and the morphological features include geometric shape description parameters of energy concentration regions in the time-frequency distribution matrix. The statistical features and the morphological features are combined to form the feature vector.

[0016] The spatial region corresponding to the vibration signal is determined based on the spatial location identifier, and the feature vector is mapped to the spatial region and stored in the region feature set.

[0017] Based on the transfer matrix, energy flow source analysis is performed on the feature vectors of different spatial regions to identify cross-regional vibration events with a common energy source, including:

[0018] Based on the diffusion path and energy distribution ratio represented in the transfer matrix, for the feature vector of each spatial region, the reverse transfer path of the vibration energy received by the spatial region in the transfer matrix is ​​calculated. The reverse transfer path is composed of the node sequence of the spatial region tracing back to the source region along the reverse edge of the transfer matrix, thus obtaining the set of candidate energy source regions corresponding to the spatial region.

[0019] The intersection operation is performed on the set of candidate energy source regions to identify common source regions that appear simultaneously in multiple spatial regions. Multiple spatial regions with the same common source region are grouped into candidate cross-regional vibration event groups.

[0020] For the candidate cross-regional vibration event group, the theoretical energy distribution after the feature vector of the common source region is transmitted to each spatial region in the group through the transfer matrix is ​​calculated. The consistency of the theoretical energy distribution with the actual feature vector of each spatial region is checked. When the consistency check passes, the candidate cross-regional vibration event group is confirmed as a cross-regional vibration event with a common energy source.

[0021] The reverse transmission path of the vibration energy received in this spatial region in the transmission matrix includes:

[0022] Transpose the transfer matrix to obtain the inverse transfer matrix. The row index of the inverse transfer matrix represents the energy receiving region, the column index represents the energy supply region, and the matrix element values ​​represent the energy distribution ratio from the energy supply region to the energy receiving region.

[0023] For the target spatial region, extract the row vectors in the inverse transfer matrix with the target spatial region as the row index. The column element values ​​of the row vectors represent the energy contribution of different energy supply regions to the target spatial region. Based on the energy contribution, select energy supply regions whose energy contribution exceeds a preset contribution threshold as first-level source regions.

[0024] The first-level source region is used as the new target spatial region. The energy contribution calculation steps are repeated to obtain the second-level source region to the Nth-level source region in sequence. When the energy contribution of a certain source region is all lower than the preset contribution threshold or reaches the preset traceability depth limit, the recursion is terminated. The region sequence from the target spatial region to the terminal source region is used as the reverse transmission path, and the terminal source region is included in the energy source candidate region set.

[0025] Linked intrusion events are identified by searching for subgraph structures that satisfy a preset topological pattern in the causal dependency graph, and the spatial location and movement trajectory of the intrusion source are determined based on the topological location of nodes in the subgraph structure, including:

[0026] In the causal dependency graph, all node combinations are traversed, and candidate subgraph structures composed of nodes and edges in each node combination are extracted. The candidate subgraph structures are compared with the preset topology pattern for structural isomorphism. It is determined whether the candidate subgraph structure can be decomposed into atomic topology combinations contained in the preset topology pattern and whether the splicing relationship between each atomic topology conforms to the primitive combination rules.

[0027] When the candidate subgraph structure meets the structural isomorphism comparison condition, the candidate subgraph structure is marked as a matching subgraph structure, and the cross-regional vibration event corresponding to the matching subgraph structure is marked as a linkage intrusion event.

[0028] Based on the serial splicing order of the atomic topology and the temporal order of the edge weights within each atomic topology, the nodes in the matching subgraph structure are temporally sorted to obtain the temporal access sequence of the nodes. The spatial region corresponding to the earliest node in the temporal access sequence is determined as the spatial location of the intrusion source. The spatial regions corresponding to each node in the temporal access sequence are connected in temporal order to form the movement trajectory of the intrusion source.

[0029] The preset topology modes include:

[0030] The topological element library and element combination rules are defined based on the characteristics of intrusion behavior.

[0031] The topology primitive library contains atomic topology structures that represent basic intrusion actions. Each atomic topology structure consists of a fixed number of nodes and edges with a fixed connection method.

[0032] The primitive combination rules define the splicing methods and connection conditions of multiple atomic topologies. The splicing methods include serial splicing and parallel splicing, and the connection conditions include the attribute matching requirements of nodes at the splicing interface and the continuity requirements of edge weights.

[0033] Multiple atomic topological structures are combined according to the primitive combination rules to generate a composite topological pattern.

[0034] The generation of regional cascaded response commands based on the spatial location and movement trajectory of the linked intrusion event includes:

[0035] The motion direction vector and motion speed parameter of the intrusion object are calculated based on the temporal access sequence of each spatial region in the motion trajectory. The motion direction vector is obtained by calculating the spatial coordinate difference between temporally adjacent spatial regions, and the motion speed parameter is obtained by calculating the ratio of the spatial distance between temporally adjacent spatial regions to the time interval.

[0036] All spatial regions in the motion trajectory are marked as response coverage areas, which include historical spatial regions in the motion trajectory where intrusion events have occurred. A temporal position index is calculated for each response coverage area, which represents the temporal order in which the response coverage area was accessed during the intrusion process.

[0037] Regional response instructions are generated sequentially for each response coverage area according to the order of the time-series position index. Each regional response instruction includes a target area identifier, a response start time, and a response action type. The target area identifier points to the corresponding response coverage area. The response start time is calculated based on the time-series position index of the response coverage area and the current time. The response action type is determined based on the position attribute of the response coverage area in the motion trajectory. All regional response instructions are organized into regional cascaded response instructions according to the order of the response start times.

[0038] A second aspect of the present invention provides a distributed optical fiber vibration event detection system, comprising:

[0039] The first unit is used to collect vibration signals from multiple spatial regions through distributed optical fiber sensing units deployed along a preset path. The vibration signals include time-domain waveforms and spatial location identifiers.

[0040] The second unit is used to perform time-frequency domain decomposition on the vibration signal, extract feature vectors reflecting the vibration mode, and map the feature vectors to the corresponding spatial regions according to the spatial location identifiers to form a regional feature set;

[0041] The third unit is used to construct a transmission matrix of vibration energy among multiple spatial regions in the set of regional features. The transmission matrix represents the diffusion path and energy distribution ratio of vibration energy from the source region to adjacent regions. Based on the transmission matrix, energy flow source analysis is performed on the feature vectors of different spatial regions to identify cross-regional vibration events with a common energy source.

[0042] The fourth unit is used to establish a causal dependency graph of vibration response between regions. The nodes of the causal dependency graph represent spatial regions, the edges represent the vibration transmission relationship between regions, and the edge weights represent the temporal sequence of vibration transmission. Linked intrusion events are identified by searching for subgraph structures that satisfy a preset topological pattern in the causal dependency graph. The spatial location and movement trajectory of the intrusion source are determined based on the topological position of the nodes in the subgraph structure. The topological pattern is defined by a region access sequence that characterizes the intrusion behavior.

[0043] The fifth unit is used to generate a regional cascade response command based on the spatial location and movement trajectory of the linked intrusion event. The regional cascade response command is used to control the protective devices corresponding to the multiple spatial regions to perform linked protective actions.

[0044] A third aspect of the present invention provides an electronic device, comprising:

[0045] processor;

[0046] Memory used to store processor-executable instructions;

[0047] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.

[0048] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.

[0049] The beneficial effects of this application are as follows:

[0050] By analyzing the vibration energy transfer matrix and energy flow direction, the vibration source and vibration transmission path can be effectively distinguished, which improves the system's ability to identify real intrusion events, reduces environmental noise interference and false alarm rate, and enhances the system's adaptability and robustness in complex environments.

[0051] The intrusion event analysis method based on causal dependency graphs can accurately identify cross-regional linked intrusion events and determine the location and trajectory of the intrusion source. It realizes the transformation from single-point vibration detection to regional intrusion behavior understanding, and improves the system's intelligence level and security protection capabilities.

[0052] The regional cascade response mechanism enables protective equipment to coordinate protection based on the location and movement trajectory of intruders. Compared with the traditional independent triggering method, it improves the response speed and targeting of the protection system, reduces system resource consumption, and achieves precise and efficient security protection. Attached Figure Description

[0053] Figure 1This is a flowchart illustrating the distributed optical fiber vibration event detection method according to an embodiment of the present invention;

[0054] Figure 2 This is a flowchart of the vibration signal time-frequency domain feature extraction and spatial mapping processing according to an embodiment of the present invention. Detailed Implementation

[0055] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0056] The technical solution of the present invention will be described in detail below with reference to specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0057] Figure 1 This is a flowchart illustrating the distributed optical fiber vibration event detection method according to an embodiment of the present invention, as shown below. Figure 1 As shown, the method includes:

[0058] Vibration signals from multiple spatial regions are collected by distributed optical fiber sensing units deployed along a preset path. The vibration signals include time-domain waveforms and spatial location identifiers.

[0059] The vibration signal is decomposed in the time-frequency domain to extract feature vectors reflecting the vibration mode, and the feature vectors are mapped to corresponding spatial regions according to the spatial location identifiers to form a regional feature set;

[0060] For multiple spatial regions in the aforementioned regional feature set, a transfer matrix of vibration energy is constructed among these regions. This transfer matrix characterizes the diffusion path and energy distribution ratio of vibration energy from the source region to adjacent regions. Based on this transfer matrix, energy flow source tracing analysis is performed on the feature vectors of different spatial regions to identify cross-regional vibration events with a common energy source.

[0061] A causal dependency graph of vibration response between regions is established. In the causal dependency graph, nodes represent spatial regions, edges represent vibration transmission relationships between regions, and edge weights represent the temporal sequence of vibration transmission. Linked intrusion events are identified by searching for subgraph structures that satisfy a preset topological pattern in the causal dependency graph. The spatial location and movement trajectory of the intrusion source are determined based on the topological position of the nodes in the subgraph structure. The topological pattern is defined by a region access sequence that characterizes the intrusion behavior.

[0062] Based on the spatial location and movement trajectory of the linked intrusion event, a regional cascade response command is generated. The regional cascade response command is used to control the protective equipment corresponding to the multiple spatial regions to perform linked protective actions.

[0063] In one optional implementation, the vibration signal is decomposed in the time-frequency domain to extract feature vectors reflecting the vibration mode, and the feature vectors are mapped to corresponding spatial regions according to the spatial location identifier to form a regional feature set, including:

[0064] The vibration signal is decomposed into a multi-resolution time-frequency domain to obtain a time-frequency distribution matrix characterizing the evolution of different frequency components over time. The time axis of the time-frequency distribution matrix corresponds to the sampling time of the vibration signal, the frequency axis corresponds to the spectral components of the vibration signal, and the matrix element values ​​correspond to the energy amplitude of the frequency component at a certain time.

[0065] Statistical and morphological features characterizing vibration modes are extracted from the time-frequency distribution matrix. The statistical features include energy distribution statistics of the time-frequency distribution matrix in the time and frequency dimensions, and the morphological features include geometric shape description parameters of energy concentration regions in the time-frequency distribution matrix. The statistical features and the morphological features are combined to form the feature vector.

[0066] The spatial region corresponding to the vibration signal is determined based on the spatial location identifier, and the feature vector is mapped to the spatial region and stored in the region feature set.

[0067] like Figure 2 As shown, the method includes:

[0068] The vibration signal acquired by the distributed fiber optic sensing unit is processed by a multi-resolution time-frequency domain decomposition module. This module uses a continuous wavelet transform algorithm to achieve time-frequency domain decomposition of the signal. The wavelet transform uses the Morlet complex wavelet as the mother wavelet function, with a center frequency parameter set to 0.849, a shape parameter set to 5, and a scale factor ranging from 1 to 256, covering a frequency range of 0.1 Hz to 1000 Hz. The sampling frequency of the input vibration signal is fixed at 2048 Hz, and the signal length processed each time is 2048 sampling points, corresponding to a 1-second time window. During the wavelet transform, the algorithm calculates wavelet coefficients for each scale factor and calculates the time-frequency response point-by-point using a sliding window method, generating a 2048×128 time-frequency distribution matrix. The rows of this matrix correspond to the time axis, the columns correspond to the frequency axis, and the matrix element value is the square of the modulus of the wavelet coefficient, directly representing the energy amplitude at the corresponding time-frequency point.

[0069] After the time-frequency distribution matrix is ​​generated, the statistical feature extraction module calculates the energy distribution statistics in both the time and frequency dimensions. In the time dimension statistical processing, for each time sampling point, four parameters are calculated: the sum of energy, standard deviation, skewness, and kurtosis for all frequency components. The sum of energy is obtained by summing all frequency components at that time point; the standard deviation reflects the dispersion of energy in the frequency dimension; skewness describes the asymmetry of energy distribution; and kurtosis characterizes the sharpness of energy distribution. In the frequency dimension statistical processing, for each frequency component, four parameters are calculated over the entire time period: cumulative energy, peak time, duration, and rate of change. The cumulative energy is obtained by summing the energy of that frequency component at all time points; the peak time records the time position where the maximum energy value occurs; the duration counts the length of time the energy exceeds the average value; and the rate of change is calculated using the root mean square of the energy difference between adjacent time points.

[0070] The morphological feature extraction module focuses on analyzing the geometric characteristics of energy concentration regions in the time-frequency distribution matrix. Energy concentration region identification employs an adaptive threshold segmentation method, with the threshold set to the global energy average plus 1.5 times the standard deviation. Connected region detection uses the four-neighborhood connectivity criterion, identifying connected regions with an area greater than 16 pixels as effective energy concentration regions. For each identified region, six geometric shape description parameters are calculated: region area, bounding box aspect ratio, centroid coordinates, principal axis tilt angle, circularity, and convexity. The region area is directly calculated by counting the number of pixels within the connected region; the bounding box aspect ratio is calculated using the aspect ratio of the minimum bounding rectangle; the centroid coordinates are determined using an area-weighted average method; the principal axis tilt angle is calculated using the eigenvectors of the covariance matrix; circularity is defined as the ratio of the region area to the area of ​​the circumcircle; and convexity is measured by the ratio of the region area to the area of ​​the convex hull.

[0071] The feature vector construction module combines the extracted statistical and morphological features into a standardized feature vector according to a fixed format. The feature vector is designed as a 72-dimensional floating-point array, with the first 36 dimensions storing statistical features and the last 36 dimensions storing morphological features. The statistical feature part includes 18 time-dimensional statistics and 18 frequency-dimensional statistics. Each type of statistics includes basic statistical parameters such as mean, variance, maximum, and minimum, as well as higher-order moment statistical parameters. The morphological feature part records a maximum of 6 most significant energy concentration regions, sorted by region area. Each region's 6 geometric parameters occupy 6 dimensions. If the actual number of detected regions is less than 6, the remaining dimensions are filled with zero values. All values ​​in the feature vector are normalized, maintaining a floating-point precision of 32 bits, and the numerical range is normalized to the interval between 0 and 1.

[0072] The spatial region mapping module determines the corresponding spatial region affiliation based on the spatial location identifier carried by the vibration signal. The spatial location identifier is represented by the absolute position from the fiber optic origin, in meters, with an accuracy of 0.1 meters. Spatial regions are divided using an equal-length segmentation strategy, with each region covering a 100-meter fiber optic length, and regions are numbered consecutively starting from 1. Given a spatial location identifier, the corresponding region number is calculated by dividing the position by 100 and rounding up. When establishing the mapping relationship, the feature vector is packaged and stored along with metadata such as region number, detection time, and signal quality assessment. Signal quality assessment is calculated using the signal-to-noise ratio (SNR); feature vectors with an SNR below 10 dB are marked as low-quality data.

[0073] The regional feature set is stored and indexed using a distributed hash table structure, with the regional ID as the primary key, supporting efficient data insertion, querying, and updating operations. Each region's corresponding data record contains a feature vector array, a timestamp sequence, quality assessment markers, and statistical summary information. The data storage format uses binary compression encoding, with each feature vector record being approximately 320 bytes in size. The storage system supports real-time data writing and batch querying of historical data. The data retention strategy is set to a rolling window mode, retaining all data from the most recent 72 hours; data exceeding the time window is compressed and archived. A memory caching mechanism retains the most recent 6 hours' hot data, improving query response speed for frequently accessed regions.

[0074] The system requires at least 8GB of RAM, a quad-core processor, and 500GB of storage. Its concurrent processing capability supports 32 fiber optic signals simultaneously, with processing latency for each signal controlled within 50 milliseconds. Data consistency is guaranteed through a read-write lock mechanism, and write operations utilize asynchronous batch commits to reduce storage system load. Fault tolerance mechanisms include data verification, automatic retries, and degradation handling to ensure the system continues to operate normally even in the event of partial hardware failure.

[0075] In a practical application, suppose the fiber optic sensing unit detects a vibration event at a location of 750 meters. The acquired signal has a dominant frequency of 45 Hz, an amplitude of 0.8 volts, and a duration of 1.2 seconds. After multi-resolution time-frequency domain decomposition, the generated time-frequency distribution matrix shows that the energy is mainly concentrated in the frequency range of 40 Hz to 50 Hz and the time range of 0.3 seconds to 1.5 seconds. Statistical feature extraction results show that the energy centroid is located at 0.9 seconds in the time dimension and at 46 Hz in the frequency dimension. Morphological features identify three significant energy concentration regions, with the largest region having an area of ​​1024 pixels, an aspect ratio of 3.2, and a principal axis tilt angle of 12 degrees. The combined 72-dimensional feature vector is mapped to region number 8 and stored in the region feature set. The signal quality of this record is assessed as excellent, with a signal-to-noise ratio of 28 dB.

[0076] In one optional implementation, energy flow source analysis is performed on the feature vectors of different spatial regions based on the transfer matrix to identify cross-regional vibration events with a common energy source, including:

[0077] Based on the diffusion path and energy distribution ratio represented in the transfer matrix, for the feature vector of each spatial region, the reverse transfer path of the vibration energy received by the spatial region in the transfer matrix is ​​calculated. The reverse transfer path is composed of the node sequence of the spatial region tracing back to the source region along the reverse edge of the transfer matrix, thus obtaining the set of candidate energy source regions corresponding to the spatial region.

[0078] The intersection operation is performed on the set of candidate energy source regions to identify common source regions that appear simultaneously in multiple spatial regions. Multiple spatial regions with the same common source region are grouped into candidate cross-regional vibration event groups.

[0079] For the candidate cross-regional vibration event group, the theoretical energy distribution after the feature vector of the common source region is transmitted to each spatial region in the group through the transfer matrix is ​​calculated. The consistency of the theoretical energy distribution with the actual feature vector of each spatial region is checked. When the consistency check passes, the candidate cross-regional vibration event group is confirmed as a cross-regional vibration event with a common energy source.

[0080] The energy flow source tracing analysis module receives the transfer matrix and feature vectors of each spatial region as input data, and realizes the source tracing of vibration energy through reverse transfer path calculation. The transfer matrix adopts a sparse matrix storage format with a matrix dimension of N×N, where N is the total number of spatial regions, and the matrix element values ​​represent the energy transfer coefficient from the source region to the target region, with values ​​ranging from 0 to 1. The reverse transfer path calculation module performs a reverse graph traversal algorithm for each spatial region. Starting from the target region node, it performs a depth-first search along the reverse edges of the transfer matrix, with the search depth limited to 8 layers to avoid overcomputation. The reverse edge is defined as the connection in the opposite direction to the non-zero element in the transfer matrix. That is, if the matrix element M[i][j] is greater than the threshold 0.01, then there exists a reverse edge from region j to region i, with a weight of the reciprocal of M[i][j].

[0081] During the reverse propagation path tracing process, the algorithm maintains an array of access markers and a cumulative path weight value to prevent loop formation and repeated visits. The cumulative path weight is calculated by multiplying the weights along each edge of the path; further searching of the path is terminated when the cumulative weight falls below 0.001. The energy source candidate region set for each spatial region contains all source region nodes reachable via the reverse propagation path. Each candidate source region in the set records its shortest path length to the target region, maximum propagation weight, and number of paths. Candidate region selection employs a comprehensive scoring mechanism, considering the reciprocal of the path length, propagation weight, and path redundancy. Regions with a score exceeding 0.5 are included in the valid candidate set.

[0082] The intersection operation module performs set theory operations on the candidate energy source regions of multiple spatial regions to identify common source regions. The intersection operation uses a hash table data structure to optimize computational efficiency, using the candidate source region number as the key to count the frequency of that region in each spatial region's candidate set. A common source region is defined as a candidate source region whose frequency exceeds half of the number of spatial regions participating in the intersection operation; that is, if six spatial regions participate in the operation, a candidate source region appearing at least three times is identified as a common source region. The weight of the common source region is calculated by weighted averaging the scores of that source region across all spatial regions, with the weight allocation determined based on the signal strength of the feature vectors of each spatial region.

[0083] The candidate cross-regional vibration event group construction module groups spatial regions based on the identification results of common source regions. The merging algorithm uses a disjoint-set data structure. Initially, each spatial region is grouped independently. When two regions share the same common source region, a merging operation is performed. The merging criteria require that the weight difference of the common source regions is less than 0.2, and the difference in the average path length from the common source region to each region does not exceed 2 layers. The validity of the candidate cross-regional vibration event group is verified through consistency checks on the number of regions within the group and the time window. The number of regions within the group is no less than 2 and no more than 10, and the time difference in the detection of vibration events in each region is controlled within 5 seconds.

[0084] The theoretical energy distribution calculation module calculates the expected energy distribution of each spatial region based on the eigenvectors of the common source region and the transfer matrix. The calculation process employs matrix-vector multiplication, taking the 72-dimensional eigenvectors of the common source region as input and performing a linear transformation on the corresponding row vectors of the transfer matrix to obtain the theoretical eigenvectors of the target region. Each element of the transfer matrix incorporates an attenuation factor in the calculation. The attenuation factor is determined based on the spatial distance and the length of the transfer path; it decreases by 0.05 for every 100-meter increase in distance and by 0.1 for every additional layer along the path. The components of each dimension of the theoretical eigenvector are calculated by multiplying the corresponding components of the source region's eigenvectors by the transfer coefficients, and the calculation results are preserved to four decimal places.

[0085] The consistency verification module compares the similarity between the theoretical energy distribution and the actual feature vectors, using both cosine similarity and Euclidean distance as evaluation metrics. Cosine similarity is calculated by dividing the inner product of the theoretical and actual feature vectors by the product of their respective magnitudes, with a value ranging from -1 to 1, and a similarity threshold set to 0.8. Euclidean distance is calculated by taking the square root of the sum of the squares of the differences between the corresponding components of the theoretical and actual feature vectors, with a distance threshold set to 20% of the feature vector's magnitude. The consistency verification passes when the cosine similarity is greater than 0.8 and the Euclidean distance is less than the threshold, and the matching degree of the energy-concentrated frequency bands in the feature vectors exceeds 85%.

[0086] The cross-regional vibration event confirmation module performs final verification and marking of candidate event groups that have passed the consistency check. The verification process includes timing consistency checks, energy conservation verification, and physical plausibility judgment. The timing consistency check verifies whether the detection time of vibration events in each region conforms to the physical laws of energy propagation, with the propagation speed reference value set at 3000 meters per second. The energy conservation verification compares the total energy in the common source area with the sum of the energy received in each target area, with the error range controlled within 15%. The physical plausibility judgment excludes event groups with a propagation distance exceeding 10 kilometers or whose propagation path crosses more than 5 intermediate areas.

[0087] The data caching mechanism employs an LRU strategy to manage the sparse representation of the transfer matrix and intermediate computation results, with a cache capacity set at 1GB and a cache hit rate maintained above 85%. Concurrent processing supports simultaneous processing of analysis tasks for 16 candidate event groups, with each task allocated independent computation threads and memory space to avoid data contention. Anomaly handling mechanisms include matrix singularity detection, numerical overflow protection, and memory leak monitoring to ensure long-term operational stability.

[0088] In a practical application, assuming the transfer matrix is ​​a 50×50 sparse matrix with 15% non-zero elements, each row contains an average of 7.5 valid transfer paths. Vibration events were detected simultaneously in regions 12, 23, and 31, with time intervals of 0 seconds, 1.2 seconds, and 2.8 seconds, respectively. Reverse transfer path calculation revealed 5, 4, and 6 candidate energy source regions for the three regions, respectively. Intersection analysis identified regions 8 and 15 as common source regions. Region 8 had a weight score of 0.92, and region 15 had a weight score of 0.76; therefore, region 8 was selected as the primary common source region. Theoretical energy distribution calculations showed that after the feature vector of region 8 was transferred through the transfer matrix, the cosine similarity between the theoretical feature vectors of region 8 and the actual detection results in regions 12, 23, and 31 was 0.87, 0.84, and 0.89, respectively, and the Euclidean distances were 0.12, 0.16, and 0.14, respectively, all meeting the consistency verification threshold requirements. The timing consistency check confirmed that the detection time in each region met the expected propagation speed of 3000 meters per second, and finally confirmed that the candidate cross-regional vibration event group was a cross-regional vibration event with a common energy source.

[0089] In one optional implementation, calculating the reverse transmission path of the vibration energy received in the spatial region within the transmission matrix includes:

[0090] Transpose the transfer matrix to obtain the inverse transfer matrix. The row index of the inverse transfer matrix represents the energy receiving region, the column index represents the energy supply region, and the matrix element values ​​represent the energy distribution ratio from the energy supply region to the energy receiving region.

[0091] For the target spatial region, extract the row vectors in the inverse transfer matrix with the target spatial region as the row index. The column element values ​​of the row vectors represent the energy contribution of different energy supply regions to the target spatial region. Based on the energy contribution, select energy supply regions whose energy contribution exceeds a preset contribution threshold as first-level source regions.

[0092] The first-level source region is used as the new target spatial region. The energy contribution calculation steps are repeated to obtain the second-level source region to the Nth-level source region in sequence. When the energy contribution of a certain source region is all lower than the preset contribution threshold or reaches the preset traceability depth limit, the recursion is terminated. The region sequence from the target spatial region to the terminal source region is used as the reverse transmission path, and the terminal source region is included in the energy source candidate region set.

[0093] The reverse transfer path calculation module receives the transfer matrix as input data. The transfer matrix is ​​stored as a two-dimensional array of double-precision floating-point numbers, with a dimension of M×M, where M represents the total number of spatial regions within the fiber optic monitoring range. The matrix transpose module performs a transpose operation on the transfer matrix to generate the reverse transfer matrix. The transpose process is achieved by swapping row and column indices; that is, the element in the i-th row and j-th column of the original matrix becomes the element in the j-th row and i-th column of the reverse transfer matrix. The data structure of the reverse transfer matrix maintains the same storage format as the original transfer matrix, and the numerical precision of the matrix element values ​​is maintained at 6 decimal places, with the value range limited to 0 to 1. The transpose operation uses a block matrix algorithm to optimize memory access efficiency, with the block size set to 64×64 to adapt to the processor cache line size and reduce cache miss rate.

[0094] After the reverse transfer matrix is ​​generated, the row vector extraction module performs data extraction operations on the specified target spatial region. The target spatial region is specified by an integer region identifier, with values ​​ranging from 1 to M, corresponding to the row indices of the reverse transfer matrix. Row vector extraction accesses the corresponding row data of the reverse transfer matrix using direct memory addressing. The length of the extracted row vector is equal to the number of columns M, and the vector elements are arranged in column index order. The values ​​of each column element in the row vector represent the energy contribution of different energy supply regions to the target spatial region; the contribution value reflects the efficiency and intensity of energy transfer from the supply region to the target region. The extracted row vector data is stored in a one-dimensional floating-point array, with the array index corresponding to the identifier of the energy supply region.

[0095] The energy contribution filtering module performs a threshold filtering operation on the extracted row vectors to identify energy supply areas that meet the contribution requirements. The preset contribution threshold is set to 0.05, meaning supply areas with an energy contribution below 5% are filtered out. The filtering algorithm iterates through all elements of the row vectors, recording the array index of elements with values ​​greater than the preset contribution threshold in the candidate area list. The candidate area list is stored using a dynamic array data structure, supporting runtime capacity expansion, with an initial capacity of 16 elements. During the filtering process, the specific contribution value of each candidate area is recorded for subsequent priority sorting and weight calculation. The filtering results form a first-level source area set, containing area identifiers and corresponding energy contribution values.

[0096] The recursive tracing module treats each region in the first-level source region set as a new target spatial region, repeatedly performing energy contribution calculation and screening processes. The recursive algorithm employs a depth-first search strategy, maintaining a tracing depth counter to prevent infinite recursion. A preset upper limit for tracing depth is set to 8 levels, determined based on the effective propagation distance and attenuation characteristics of vibration energy in the fiber optic sensor network. During recursion, the algorithm assigns an independent candidate region list and contribution array for each tracing level, avoiding data overwriting and confusion. The recursive state is managed using a stack data structure, where each stack element contains the currently processed region identifier, tracing level, parent region information, and cumulative contribution.

[0097] During the calculation of the second-level source region, the algorithm repeatedly performs row vector extraction and contribution filtering operations for each region in the first-level source region set. A parent-child relationship mapping is established between the calculated second-level source regions and the first-level source regions. This mapping information is stored in an associative array, where the key is the child region identifier and the corresponding value is the parent region identifier. The cumulative contribution is calculated by multiplying the contributions of each level along the path, reflecting the overall efficiency of energy transfer from the source region to the target region. The filtering thresholds for the second-level and subsequent levels of source regions employ a dynamic adjustment strategy, decreasing with tracing depth. The threshold for the k-th level is calculated as the initial threshold divided by the square root of k.

[0098] The recursive termination condition judgment module monitors the energy contribution distribution and tracing depth status of the current level source region. When the contribution of all candidate regions in a certain level source region is lower than the preset contribution threshold for the corresponding level, the algorithm determines that it is a natural termination condition and stops further recursive tracing. When the tracing depth reaches the preset upper limit, a forced termination condition is triggered to prevent excessive consumption of computing resources. The termination judgment adopts a dual-check mechanism, that is, termination is triggered if either the contribution condition or the depth condition is met simultaneously. Abnormal termination conditions include matrix singular value detection failure, memory allocation error, and numerical calculation overflow. When abnormal termination is triggered, the algorithm returns part of the calculation results and records the error status.

[0099] The reverse propagation path construction module generates a complete path sequence from the target spatial region to the terminal source region based on the results of recursive tracing. The path sequence is stored using a linked list data structure, where each node contains a region identifier, contribution value, tracing level, and a pointer to the next node. Path construction is implemented using a backtracking algorithm, starting from the terminal source region and traversing backwards along the parent-child relationship mapping to the target spatial region. During backtracking, statistical indicators such as the total path length, cumulative contribution, and average contribution are calculated for path quality evaluation and ranking. When multiple paths coexist, they are arranged in descending order of cumulative contribution, and the top 5 paths with the highest contribution are retained as valid reverse propagation paths.

[0100] The energy source candidate region set construction module collects the terminal source regions of all reverse propagation paths, forming a set of energy source candidate regions for the target space region. The candidate region set is implemented using a hash set data structure, automatically removing duplicate region identifiers to ensure the uniqueness of set elements. Each candidate region in the set records attribute information such as its occurrence frequency in different paths, highest contribution value, and average contribution value. The comprehensive score of the candidate region is calculated by a weighted average of occurrence frequency weight, highest contribution weight, and path length weight, with weight coefficients set to 0.4, 0.4, and 0.2, respectively. The score calculation results are used for priority ranking of candidate regions and subsequent intersection operations.

[0101] The memory management module is responsible for dynamic memory allocation and release during recursive computation. It employs memory pool technology to pre-allocate large contiguous blocks of memory, reducing frequent memory allocation and deallocation operations. The memory pool size is estimated based on the maximum trace depth and the number of spatial regions, reserving 20% ​​buffer space to handle peak demand. The garbage collection mechanism periodically cleans up unused memory blocks, with a collection cycle set to trigger once every 100 target regions processed. The memory usage monitoring module tracks current memory usage and peak usage, triggering memory defragmentation and cache cleanup operations when memory usage exceeds 80%.

[0102] The concurrent processing support module allows parallel execution of reverse propagation path calculations for multiple target spatial regions, employing a thread pool model to manage computational tasks. The thread pool size is set to twice the number of processor cores, and task scheduling uses a work-stealing algorithm to balance the load across threads. Data isolation between threads is achieved through thread-local storage, avoiding shared data contention and lock contention. A task execution timeout is set to 30 seconds; upon timeout, the task automatically terminates and returns partial computation results to prevent abnormal tasks from blocking the overall processing flow.

[0103] In a practical application, assume the transfer matrix is ​​a 20×20 dense matrix, and the target spatial region is region 15. After transposing the matrix to generate the inverse transfer matrix, extracting the 15th row vector yields 20 energy contribution values. Regions 3, 7, 12, and 18 have contributions of 0.12, 0.08, 0.15, and 0.06 respectively, all exceeding the preset threshold of 0.05, forming the first-level source region set. During the recursive calculation of the second level, the row vector of region 3 shows contributions of 0.18 and 0.11 for regions 1 and 5, respectively; the row vector of region 7 shows a contribution of 0.09 for region 2; the row vector of region 12 shows contributions of 0.22 and 0.07 for regions 4 and 9, respectively; and the row vector of region 18 shows a contribution of 0.13 for region 6. In the third-level recursion, the contributions of all candidate regions fall below the adjusted threshold of 0.029, triggering the natural termination condition. Four reverse propagation paths were ultimately generated: region 15 to region 1, region 15 to region 2, region 15 to region 4, and region 15 to region 6. The corresponding energy source candidate region set includes four candidate source regions: region 1, region 2, region 4, and region 6.

[0104] In one optional implementation, identifying linked intrusion events by searching for subgraph structures that satisfy a preset topological pattern in the causal dependency graph, and determining the spatial location and movement trajectory of the intrusion source based on the topological location of nodes in the subgraph structure includes:

[0105] In the causal dependency graph, all node combinations are traversed, and candidate subgraph structures composed of nodes and edges in each node combination are extracted. The candidate subgraph structures are compared with the preset topology pattern for structural isomorphism. It is determined whether the candidate subgraph structure can be decomposed into atomic topology combinations contained in the preset topology pattern and whether the splicing relationship between each atomic topology conforms to the primitive combination rules.

[0106] When the candidate subgraph structure meets the structural isomorphism comparison condition, the candidate subgraph structure is marked as a matching subgraph structure, and the cross-regional vibration event corresponding to the matching subgraph structure is marked as a linkage intrusion event.

[0107] Based on the serial splicing order of the atomic topology and the temporal order of the edge weights within each atomic topology, the nodes in the matching subgraph structure are temporally sorted to obtain the temporal access sequence of the nodes. The spatial region corresponding to the earliest node in the temporal access sequence is determined as the spatial location of the intrusion source. The spatial regions corresponding to each node in the temporal access sequence are connected in temporal order to form the movement trajectory of the intrusion source.

[0108] The subgraph search module receives a causal dependency graph as input data. This graph is stored using an adjacency list data structure. The node set N contains M vibration event nodes, and the edge set E contains directed edges and their weights. The node combination traversal algorithm starts with a subset of nodes of size 2 and gradually expands to the complete set containing all nodes. The traversal process is implemented using binary incrementing methods from combinatorics. Each node combination is represented by a bitmask, the length of which is equal to the total number of nodes M. A bit of 1 at the i-th bit indicates that the i-th node is selected. The traversal algorithm maintains an integer variable representing the current combination state, incrementing from 1 to 2^M minus 1 to ensure coverage of all node combinations. The size of each node combination is limited to between 2 and 20 nodes to avoid excessive computational complexity caused by combination explosion.

[0109] The candidate subgraph structure extraction module constructs the corresponding subgraph data structure based on the selected node combinations. The subgraph construction process traverses all edges connecting the selected nodes in the original graph, adding edges that meet the criteria to the edge set of the candidate subgraph. The edge selection criteria require that both the starting and ending nodes of the edge belong to the current node combination, ensuring the connectivity and integrity of the candidate subgraph. The candidate subgraph uses the same adjacency list storage format as the original graph, and the node identifiers are remapped to a continuous integer sequence from 0 to the number of nodes in the subgraph minus 1, facilitating subsequent structure comparison algorithms. The edge weight information of the subgraph is fully preserved, including attribute fields such as timestamp, strength value, and confidence level. The weight data is stored as double-precision floating-point numbers, with precision maintained to 6 decimal places.

[0110] The preset topology pattern definition module maintains typical graph structure templates for intrusion behaviors. These templates contain two core components: atomic topology structures and primitive combination rules. Atomic topology structures include four basic types: chain structures, star structures, ring structures, and tree structures. Each type defines the range of the number of nodes, edge direction constraints, and connection relationship patterns. Chain structures require nodes to be connected sequentially to form directed paths, with the number of nodes limited to 3 to 8. Star structures contain a central node and multiple leaf nodes, with the number of leaf nodes limited to 2 to 6. All edges point to or originate from the central node. Ring structures require all nodes to form closed directed loops, with the number of nodes limited to 3 to 6. Tree structures allow branching but prohibit loops, and their depth is limited to 4 levels.

[0111] The primitive combination rules define the legal splicing methods between atomic topologies, including three basic modes: serial splicing, parallel splicing, and nested splicing. Serial splicing requires the output node of the preceding atomic structure to coincide with the input node of the following atomic structure, forming a temporal transmission relationship. Parallel splicing allows multiple atomic structures to share input or output nodes, representing simultaneous parallel intrusions. Nested splicing supports the embedding of small-scale atomic structures within large-scale atomic structures, forming hierarchical composite intrusion patterns. The splicing rules are defined through a constraint matrix, where matrix element values ​​represent a compatibility score between two atomic structures, ranging from 0 to 1. Scores higher than 0.7 indicate a compatible splicing relationship.

[0112] The structural isomorphism comparison module matches candidate subgraph structures with preset topological patterns, employing a graph isomorphism-based subgraph matching algorithm. The algorithm comprises two core steps: node label mapping and edge relationship verification. Node label mapping establishes a one-to-one correspondence between candidate subgraph nodes and template nodes, considering topological attribute constraints such as degree, in-degree, and out-degree. Edge relationship verification checks whether the mapped edge set is completely identical to the template edge set, including edge direction, weight range, and connectivity. Isomorphism judgment uses a backtracking search algorithm, with the search depth limited to the number of nodes in the candidate subgraph. Backtracking conditions include node mapping conflicts, edge relationship mismatches, and attribute constraint violations.

[0113] The atomic topology decomposition algorithm divides candidate subgraphs into combinations of atomic structures defined in a preset topological pattern. The decomposition process employs a graph partitioning algorithm, prioritizing the identification of substructures with clear boundary features, such as leaf nodes with a degree of 1, high-degree center nodes, and sets of nodes forming strongly connected components. The algorithm maintains a list of unassigned nodes and a list of identified atomic structures, iteratively performing node assignment and structure verification operations until all nodes are assigned to suitable atomic structures. The decomposition results are recorded using an atomic structure identifier array, where the array index corresponds to the node number of the candidate subgraph, and the array element value represents the atomic structure number to which that node belongs. Decomposition failure conditions include the existence of unclassifiable isolated nodes, internal connections within atomic structures not conforming to the definition, and conflicts arising from node assignments.

[0114] The primitive combination rule verification module checks whether the combinations of atomic topological structures obtained from decomposition conform to preset splicing relationship constraints. The verification algorithm constructs an adjacency graph between atomic structures, where nodes represent atomic structures and edges represent the connections between atomic structures. Adjacency relationships are determined by analyzing edge connections across atomic structures, i.e., edges where the starting and ending nodes belong to different atomic structures. The verification process queries the corresponding compatibility score in the constraint matrix and calculates the product of the scores of all adjacency relationships as the overall matching degree index. The matching degree threshold is set to 0.6; candidate subgraphs below the threshold are judged to not conform to the primitive combination rules, the matching process terminates, and a failure status is returned.

[0115] The matching subgraph structure marking module identifies and records candidate subgraphs that pass structural isomorphism comparison and primitive combination rule verification. The marking information includes attribute fields such as the node list, edge list, corresponding atomic topological structure decomposition results, and matching degree score of the matching subgraph. Matching subgraphs are indexed using unique identifiers, consisting of a timestamp and a sequence number, ensuring global uniqueness. The marking process simultaneously updates the cross-regional vibration event status corresponding to the matching subgraph, changing the event type from ordinary vibration event to linked intrusion event. The status update operation is guaranteed to be atomic, avoiding data inconsistencies caused by concurrent access.

[0116] The linked intrusion event identification module determines the intrusion attributes of cross-regional vibration events based on the labeling results of the matching subgraph structure. The identification algorithm traverses all nodes in the matching subgraph, extracting detailed vibration event information corresponding to each node, including event occurrence time, spatial location coordinates, vibration intensity, and frequency characteristics. The confidence assessment of intrusion events comprehensively considers factors such as matching score, subgraph size, and time span. The confidence calculation uses a weighted average method with weight coefficients of 0.5, 0.3, and 0.2. Linked intrusion events with a confidence score higher than 0.8 are marked as high-risk events, triggering a real-time alarm mechanism and a detailed analysis process.

[0117] The temporal sorting module sorts the nodes in the matching subgraph based on the serial splicing order of the atomic topology and the temporal information of the edge weights. The sorting algorithm involves determining temporal relationships at two levels: At the atomic structure level, sorting is based on the serial splicing order, establishing a partial order according to the predecessor-successor relationships defined in the primitive combination rules. Within an atomic structure, node sorting is based on the timestamp information in the edge weights, with timestamp precision at the millisecond level. The sorting algorithm employs a stable sorting method to ensure that the relative positions of nodes with the same timestamp remain unchanged. Temporal relationships across atomic structures are determined through the weight information of the connecting edges; the timestamps of the connecting edges represent the timing of energy transfer or causal dependencies.

[0118] The temporal access sequence construction module organizes the sorted nodes into a linear sequence in chronological order. Each element in the sequence contains a node identifier, timestamp, spatial coordinates, and atomic structure attribution information. The sequence construction process handles concurrent events with the same timestamp, arranged lexicographically by spatial location to ensure the determinism and reproducibility of the sequence. The time span of the access sequence is calculated as the difference between the timestamps of the last node and the first node, with a time span limited to within 10 minutes. Sequences exceeding this limit are marked as abnormal intrusion patterns. The time interval statistics between adjacent nodes in the sequence are used for intrusion speed and movement pattern analysis; the average time interval and standard deviation are recorded as characteristic parameters of the intrusion behavior.

[0119] The intrusion source spatial location determination module identifies the earliest node in the temporal access sequence as the starting point of the intrusion. The location determination algorithm traverses all nodes in the sequence, compares the timestamp values ​​of the nodes, and selects the node with the smallest timestamp as the intrusion source node. The spatial location coordinates of the intrusion source node are represented using two-dimensional coordinates with meter-level precision, and the origin is set to the southwest corner of the monitoring area. The validity verification of the location coordinates checks whether the coordinate values ​​are within the boundary range of the monitoring area; coordinates outside the boundary are marked as outliers and trigger a data correction process. The confidence assessment of the intrusion source location is based on the integrity of the temporal access sequence and the continuity of the time intervals. The confidence calculation results are used for subsequent trajectory analysis and prediction algorithms.

[0120] The motion trajectory construction module connects the spatial regions corresponding to each node in the temporal access sequence in chronological order to form the motion path of the intrusion source. The trajectory construction algorithm visits the nodes in the sequence sequentially, extracts the spatial coordinates of the nodes, and calculates the straight-line distance and motion direction angle between adjacent nodes. The trajectory path is represented by polyline segments, with each polyline segment corresponding to the motion process between two adjacent nodes in the sequence. The motion speed is calculated by dividing the length of the polyline segment by the corresponding time interval. The reasonableness check of the speed value is based on the typical motion speed range of personnel or vehicles; speed values ​​exceeding the reasonable range are marked as jumping motion or sensor anomalies.

[0121] In practical applications, the causal dependency graph contains 12 nodes representing cross-regional vibration events, numbered N1 to N12. Edge weights include timestamps and intensity values. The preset topology defines a chain-like atomic structure requiring four nodes connected in series, and a star-shaped atomic structure requiring one central node connecting three leaf nodes. Candidate subgraph structures are extracted from node combinations N1, N3, N7, N9, N11, and N12, containing five directed edges: N1 to N3, N3 to N7, N7 to N9, N9 to N11, and N3 to N12. Structural isomorphism comparison identifies that this candidate subgraph can be decomposed into a chain-like atomic structure N1-N3-N7-N9-N11 and a branch node N12. The atomic topology decomposition result is chain structure number 1 and independent node number 2. The temporal ordering is based on edge weight timestamps. The timestamps for N1 are 08:15:23.150, N3 is 08:15:28.300, N7 is 08:15:34.680, N9 is 08:15:41.220, N11 is 08:15:47.890, and N12 is 08:15:29.100. The sorted temporal access sequence is N1-N3-N12-N7-N9-N11. The spatial location of the intrusion source is determined to be the coordinate point (125.6, 78.3) corresponding to N1. The movement trajectory contains 5 path segments with a total length of 167.8 meters, an average movement speed of 1.2 meters per second, and a trajectory time span of 24.74 seconds. It is ultimately marked as a high-confidence linked intrusion event.

[0122] In one optional implementation, the preset topology mode includes:

[0123] The topological element library and element combination rules are defined based on the characteristics of intrusion behavior.

[0124] The topology primitive library contains atomic topology structures that represent basic intrusion actions. Each atomic topology structure consists of a fixed number of nodes and edges with a fixed connection method.

[0125] The primitive combination rules define the splicing methods and connection conditions of multiple atomic topologies. The splicing methods include serial splicing and parallel splicing, and the connection conditions include the attribute matching requirements of nodes at the splicing interface and the continuity requirements of edge weights.

[0126] Multiple atomic topological structures are combined according to the primitive combination rules to generate a composite topological pattern.

[0127] Common network attack behaviors are decomposed to extract basic operational units, such as port scanning, privilege escalation, and data theft. A corresponding atomic topology is established for each basic operation. Taking port scanning as an example, its atomic topology contains two nodes: an attack source node and a target node, connected by weighted edges, where the weight represents the scan intensity. Attack source node attributes include IP address, operating system type, and activity time; target node attributes include IP address, list of open ports, and service type. To represent different scanning techniques, edge attributes also include scan type (SYN scan, FIN scan, etc.), packet count, and time interval.

[0128] The atomic topology for privilege escalation consists of three nodes: the attack source node, the target system node, and the escalated node. The attack source node connects to the target system node via an edge indicating an attempt to escalate privileges, and the target system node connects to the escalated node via an edge indicating a change in privileges. Node attributes include privilege level (regular user, administrator, system level), operating system version, and vulnerability information; edge attributes include privilege escalation method (vulnerability exploitation, password cracking) and success rate.

[0129] The atomic topology of data theft consists of three nodes: the attacker node, the data source node, and the data destination node. These three nodes are connected sequentially via data transmission edges, forming a data flow path. Node attributes include storage capacity, data type, and encryption status; edge attributes include transmission protocol, data volume, and transmission rate.

[0130] The primitive combination rules define the splicing methods and connection conditions of atomic topologies. Splicing methods include serial splicing and parallel splicing. Serial splicing is suitable for representing sequential actions in an attack chain, such as performing port scanning first, then exploiting vulnerabilities, and finally escalating privileges. Parallel splicing is suitable for representing multiple actions performed simultaneously by an attacker, such as scanning or exploiting multiple target systems at the same time.

[0131] Connection conditions include the attribute matching requirements of nodes at the splicing interface and the continuity requirements of edge weights. The node attribute matching requirement ensures the rationality of the splicing; for example, the target node of the port scan atomic topology and the target node of the vulnerability exploit atomic topology must have the same IP address and port information. The edge weight continuity requirement ensures the temporal coherence of the action sequence; for example, the timestamp of a subsequent action must be greater than the timestamp of a preceding action.

[0132] Taking APT attacks as an example, this illustrates the generation process of composite topology patterns. APT attacks typically include five stages: reconnaissance, initial intrusion, privilege escalation, lateral movement, and data theft. The corresponding atomic topologies are: scanning topology, exploitation topology, privilege escalation topology, lateral movement topology, and data theft topology.

[0133] In practice, the scanning topology connects the attack source node (IP: 192.168.1.100) to the target node (IP: 192.168.2.50, open ports: 22, 80, 443) via a scanning edge. The scanning edge attributes are {Type: TCP SYN scan, Number of packets: 1000, Time interval: 0.5 seconds}. The exploit topology includes the attack source node, the target node, and the exploit result node. The attack source node (IP: 192.168.1.100) connects to the target node (IP: 192.168.2.50, Service: Web application, Vulnerability type: SQL injection) via an exploit edge. The target node connects to the exploit result node (Status: Success, Access Permissions: Normal User) via an execution result edge.

[0134] To serially concatenate the scanning topology and the exploit topology, the following conditions must be met: the target node of the scanning topology and the target node of the exploit topology have the same IP address (192.168.2.50); ​​the open ports discovered by the scanning topology include the port (80) required for exploitation; and the completion timestamp of the scanning action (2023-05-10 10:15:30) is earlier than the start timestamp of the exploit action (2023-05-10 10:20:45).

[0135] The exploit topology and privilege escalation topology are concatenated sequentially. The privilege level of the attack source node (ordinary user) in the privilege escalation topology is matched with the privilege level obtained by the exploit result node in the exploit topology. After privilege escalation, the privilege level is raised from ordinary user to administrator, exploiting the system kernel vulnerability CVE-2023-1234.

[0136] To characterize the behavior of attackers targeting multiple systems simultaneously, multiple scanning topologies can be spliced ​​together in parallel. For example, if an attacker scans three targets simultaneously: 192.168.2.50, 192.168.2.51, and 192.168.2.52, by splicing the three scanning topologies in parallel, they can share the same attack source node (IP: 192.168.1.100), forming a star topology structure of attack source against multiple targets.

[0137] In complex intrusion scenarios, multiple lateral movements are involved. These lateral movement topologies are sequentially pieced together to represent the attacker's jump from one infected host to another. With each lateral movement, the attack source node is updated to the new infected host, and the target node becomes the next attack target. For example, an attacker might move laterally from 192.168.2.50 (administrator privileges) to 192.168.2.100 (domain controller), utilizing a credential transfer attack method.

[0138] By systematically defining the topology graph element library and graph element combination rules, various complex intrusion behavior topology patterns can be flexibly constructed, providing an effective pattern matching foundation for network security situation awareness and intrusion detection.

[0139] In one optional implementation, generating a regional cascading response command based on the spatial location and movement trajectory of the linked intrusion event includes:

[0140] The motion direction vector and motion speed parameter of the intrusion object are calculated based on the temporal access sequence of each spatial region in the motion trajectory. The motion direction vector is obtained by calculating the spatial coordinate difference between temporally adjacent spatial regions, and the motion speed parameter is obtained by calculating the ratio of the spatial distance between temporally adjacent spatial regions to the time interval.

[0141] All spatial regions in the motion trajectory are marked as response coverage areas, which include historical spatial regions in the motion trajectory where intrusion events have occurred. A temporal position index is calculated for each response coverage area, which represents the temporal order in which the response coverage area was accessed during the intrusion process.

[0142] Regional response instructions are generated sequentially for each response coverage area according to the order of the time-series position index. Each regional response instruction includes a target area identifier, a response start time, and a response action type. The target area identifier points to the corresponding response coverage area. The response start time is calculated based on the time-series position index of the response coverage area and the current time. The response action type is determined based on the position attribute of the response coverage area in the motion trajectory. All regional response instructions are organized into regional cascaded response instructions according to the order of the response start times.

[0143] The motion parameter calculation module receives motion trajectory data from linked intrusion events as input. This trajectory data is stored using a temporal spatial region sequence data structure. Each spatial region record contains three core fields: region identifier, spatial coordinates, and timestamp. Spatial coordinates are represented in a two-dimensional Cartesian coordinate system with decimeter-level precision. The X-axis and Y-axis values ​​are limited to 0-2000 meters and 0-1500 meters, respectively. Timestamps are stored in Unix timestamp format with millisecond-level precision, supporting microsecond-level time difference calculations. The temporal access sequence is implemented using a doubly linked list data structure. Each linked list node contains spatial region information and pointers to its predecessor and successor nodes, facilitating fast access and traversal of adjacent regions.

[0144] The motion direction vector calculation algorithm traverses adjacent spatial region pairs in the temporal access sequence, calculating the spatial coordinate difference between the subsequent region and the preceding region as the components of the direction vector. The X component of the direction vector equals the X coordinate of the subsequent region minus the X coordinate of the preceding region, and the Y component equals the Y coordinate of the subsequent region minus the Y coordinate of the preceding region. The calculated direction vector is stored in a double-precision floating-point array, with an array length equal to the length of the temporal access sequence minus 1, corresponding to the number of adjacent region pairs. Normalization of the direction vector is achieved by calculating the vector magnitude and dividing each component by the magnitude. The normalized direction vector has a fixed magnitude of 1, facilitating subsequent angle calculations and direction comparisons. Abnormal direction vectors are detected using a magnitude threshold; direction vectors with a magnitude less than 0.1 meters are marked as stationary.

[0145] The motion speed parameter calculation module calculates the instantaneous motion speed of the intruding object based on the spatial distance and time interval between temporally adjacent spatial regions. The spatial distance is calculated using the Euclidean distance formula, which is the square root of the sum of the squares of the coordinate differences between two points, maintaining distance accuracy at the centimeter level. The time interval is obtained by subtracting the timestamp of the preceding region from the timestamp of the subsequent region. The validity check of the time interval requires an interval value greater than 100 milliseconds and less than 60 seconds; intervals outside this range are marked as abnormal data. Motion speed is equal to the spatial distance divided by the time interval, with the speed unit being meters per second (m / s). The value range is limited to between 0.1 and 20 m / s, conforming to the typical motion speed characteristics of people and vehicles. The speed data is processed using a moving average filter, with the sliding window size set to three adjacent region pairs. The filtered speed curve is smoother, reducing the impact of sensor noise and positioning errors.

[0146] The response coverage area marking module marks all spatial regions in the motion trajectory as target areas requiring response operations. The marking process iterates through each spatial region node in the temporal access sequence, extracting region identifiers and adding them to the response coverage area set. The response coverage area set is implemented using a hash set data structure, automatically removing duplicate region identifiers to ensure each spatial region is marked only once. Each response coverage area in the set is associated with a region status record, which includes attribute fields such as intrusion detection time, response readiness status, actuator availability, and communication connection status. Historical spatial region identification is based on a comparison between the intrusion event's occurrence time and the current time. Spatial regions whose occurrence time is earlier than the current time are classified as historical spatial regions, while those whose occurrence time is later than the current time are classified as predicted spatial regions.

[0147] The temporal location index calculation module assigns an index value to each response coverage area, representing the order in which it was accessed during the intrusion process. The index calculation algorithm traverses the temporal access sequence, recording the position of each spatial region in the sequence, with the location index incrementing from 1. For recurring spatial regions, the earliest occurrence position is used as the temporal location index to ensure the uniqueness of the index value and temporal consistency. The index value is stored as a 16-bit unsigned integer, supporting an index range of up to 65,535 spatial regions. A mapping relationship is established between the temporal location index and the response coverage area identifier. The mapping table is stored using a hash table data structure, supporting index query operations with O(1) time complexity. Abnormal index detection includes situations such as index values ​​exceeding a reasonable range, duplicate index allocation, and inconsistencies between the index and the temporal order. Abnormal indexes trigger data repair processes and alarm notifications.

[0148] The regional response instruction generation module creates corresponding response instructions for each response coverage area in ascending order of temporal position index. The instruction generation algorithm maintains a priority queue data structure, with queue elements sorted by temporal position index to ensure instructions are generated in the correct temporal order. Each regional response instruction contains three required fields: target area identifier, response initiation time, and response action type. The instruction data structure uses a structure definition, supporting serialization and network transmission requirements. The target area identifier directly references the area identifier of the response coverage area. The identifier uses 32-bit unsigned integer encoding, supporting an identifier space of up to 4.2 billion areas. The unique identifier of the instruction is generated by combining a timestamp and a sequence number, ensuring global uniqueness and traceability.

[0149] The response start time calculation algorithm determines the instruction execution time based on the temporal location index of the response coverage area and the current time. The calculation process considers factors such as the startup delay of the responding device, communication transmission latency, and instruction processing time, with the overall response latency set at 500 milliseconds. For historical spatial regions, the response start time is set to the current time plus the basic response latency, achieving immediate response. For predicted spatial regions, the response start time is calculated by subtracting the response preparation time from the expected arrival time of the intrusion target. The preparation time includes the time consumed by equipment warm-up, sensor calibration, and actuator positioning. The time calculation accuracy is in the millisecond range, and the time format adopts the ISO8601 standard for easy cross-platform compatibility and logging. Abnormal time detection includes situations such as a start time earlier than the current time, incorrect time format, and times exceeding a reasonable range.

[0150] The response action type determination module selects an appropriate response strategy based on the positional attributes of the response coverage area within the motion trajectory. The positional attribute analysis algorithm calculates the relative position of the response coverage area within the temporal access sequence, including three basic types: starting position, intermediate position, and ending position. The starting position corresponds to the region with a temporal position index of 1, employing intrusion source localization and initial interception action types. The intermediate position corresponds to the region with an index value between 2 and the sequence length minus 1, employing tracking and monitoring and path blocking action types. The ending position corresponds to the region with an index value equal to the sequence length, employing final interception and evidence collection action types. Action type encoding uses an 8-bit enumeration value, supporting 256 different response action definitions. Special positional attributes include branch nodes, convergence nodes, and loop nodes, corresponding to one-to-many, many-to-one, and cyclical access trajectory characteristics, respectively, triggering corresponding special response action types.

[0151] The regional cascading response instruction organization module arranges all regional response instructions according to their chronological order of initiation, forming a complete cascading response instruction sequence. The sorting algorithm employs a stable sorting strategy, ensuring that instructions with the same initiation time are arranged in the order of generation, avoiding ambiguity in execution order. Cascading response instructions are stored using a dynamic array data structure, supporting runtime instruction insertion, deletion, and modification operations. Version control of the instruction sequence is achieved through version numbers and checksums. The version number increments with each modification, and the checksum is used to check the completeness and consistency of the instruction content. The execution scheduling of cascading response instructions uses a time-wheel algorithm with a precision of 10 milliseconds, supporting precise timing control and concurrent execution.

[0152] The instruction execution monitoring module tracks the execution status and effect feedback of regional cascade response instructions, and maintains instruction execution logs and performance statistics. Execution status includes five basic states: pending execution, executing, successful execution, failed execution, and timeout. State transitions are implemented using a finite state machine model. The execution timeout threshold is set to 30 seconds; timeout instructions are automatically marked as failed and a retry mechanism is triggered. The retry strategy uses an exponential backoff algorithm, with a retry interval starting at 1 second, doubling after each retry, and a maximum of 3 retries. Execution effect feedback is evaluated through status reports from response devices and sensor data changes; the feedback information is used for instruction execution quality assessment and parameter optimization.

[0153] The concurrent execution support module handles the parallel execution requirements of response instructions from multiple regions, employing a concurrent model of thread pools and task queues. The thread pool size is set to twice the number of processor cores, and the task queue is implemented using a priority queue, with task priority calculated based on the response start time and region importance. Concurrency control is implemented through read-write locks and semaphores to avoid race conditions for shared resources by multiple threads. Resource allocation adopts a fair scheduling strategy to prevent response instructions from certain regions from waiting for execution for extended periods. Exception handling includes handling situations such as abnormal thread exit, task execution deadlock, and resource exhaustion, triggering corresponding recovery mechanisms and degradation strategies.

[0154] In practical application cases, the intrusion trajectory contains a temporal access sequence of 6 spatial regions, with region identifiers R15, R23, R31, R18, R27, and R35, corresponding to spatial coordinates (120.5, 85.3), (135.2, 92.7), (148.9, 101.2), (162.1, 108.8), (175.6, 115.9), and (189.3, 123.4), and timestamps of 08:15:23.150, 08:15:28.680, 08:15:34.920, 08:15:41.560, 08:15:48.230, and 08:15:55.120, respectively. The motion direction vector was calculated to have five vector components: (14.7, 7.4), (13.7, 8.5), (13.2, 7.6), (13.5, 7.1), and (13.7, 7.5). The normalized magnitude of each direction vector was 1.0. The motion velocity parameters were calculated to have five instantaneous velocity values: 2.94, 2.87, 2.76, 2.83, and 2.89 m / s. The velocity values ​​after moving average filtering were 2.91, 2.82, 2.82, and 2.86 m / s. The response coverage area markers included all six spatial regions, with temporal position indices of 1, 2, 3, 4, 5, and 6. The regional response command generates six commands, with target regional identifiers corresponding to R15 to R35 respectively. The response start time is calculated as the current time 08:20:10.000 plus a base delay of 500 milliseconds. The response action types are initial interception, tracking monitoring, tracking monitoring, tracking monitoring, tracking monitoring, and final interception. The regional cascading response commands are ordered according to their start times, forming a complete six-command cascading sequence. The total execution time span is 32 seconds, the command execution success rate reaches 100%, and the average response latency is 485 milliseconds.

[0155] A second aspect of the present invention provides a distributed optical fiber vibration event detection system, comprising:

[0156] The first unit is used to collect vibration signals from multiple spatial regions through distributed optical fiber sensing units deployed along a preset path. The vibration signals include time-domain waveforms and spatial location identifiers.

[0157] The second unit is used to perform time-frequency domain decomposition on the vibration signal, extract feature vectors reflecting the vibration mode, and map the feature vectors to the corresponding spatial regions according to the spatial location identifiers to form a regional feature set;

[0158] The third unit is used to construct a transmission matrix of vibration energy among multiple spatial regions in the set of regional features. The transmission matrix represents the diffusion path and energy distribution ratio of vibration energy from the source region to adjacent regions. Based on the transmission matrix, energy flow source analysis is performed on the feature vectors of different spatial regions to identify cross-regional vibration events with a common energy source.

[0159] The fourth unit is used to establish a causal dependency graph of vibration response between regions. The nodes of the causal dependency graph represent spatial regions, the edges represent the vibration transmission relationship between regions, and the edge weights represent the temporal sequence of vibration transmission. Linked intrusion events are identified by searching for subgraph structures that satisfy a preset topological pattern in the causal dependency graph. The spatial location and movement trajectory of the intrusion source are determined based on the topological position of the nodes in the subgraph structure. The topological pattern is defined by a region access sequence that characterizes the intrusion behavior.

[0160] The fifth unit is used to generate a regional cascade response command based on the spatial location and movement trajectory of the linked intrusion event. The regional cascade response command is used to control the protective devices corresponding to the multiple spatial regions to perform linked protective actions.

[0161] A third aspect of the present invention provides an electronic device, comprising:

[0162] processor;

[0163] Memory used to store processor-executable instructions;

[0164] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.

[0165] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.

[0166] This invention can be a method, apparatus, system, and / or computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for performing various aspects of the invention.

[0167] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A distributed optical fiber vibration event detection method, characterized in that, include: Vibration signals from multiple spatial regions are collected by distributed optical fiber sensing units deployed along a preset path. The vibration signals include time-domain waveforms and spatial location identifiers. The vibration signal is decomposed in the time-frequency domain to extract feature vectors reflecting the vibration mode, and the feature vectors are mapped to corresponding spatial regions according to the spatial location identifiers to form a regional feature set; For multiple spatial regions in the aforementioned regional feature set, a transfer matrix of vibration energy is constructed among these regions. This transfer matrix characterizes the diffusion path and energy distribution ratio of vibration energy from the source region to adjacent regions. Based on this transfer matrix, energy flow source tracing analysis is performed on the feature vectors of different spatial regions to identify cross-regional vibration events with a common energy source. A causal dependency graph of vibration response between regions is established. In the causal dependency graph, nodes represent spatial regions, edges represent vibration transmission relationships between regions, and edge weights represent the temporal sequence of vibration transmission. Linked intrusion events are identified by searching for subgraph structures that satisfy a preset topological pattern in the causal dependency graph. The spatial location and movement trajectory of the intrusion source are determined based on the topological position of the nodes in the subgraph structure. The topological pattern is defined by a region access sequence that characterizes the intrusion behavior. Based on the spatial location and movement trajectory of the linked intrusion event, a regional cascade response command is generated. The regional cascade response command is used to control the protective equipment corresponding to the multiple spatial regions to perform linked protective actions.

2. The method according to claim 1, characterized in that, The vibration signal is decomposed in the time-frequency domain to extract feature vectors reflecting the vibration mode. These feature vectors are then mapped to corresponding spatial regions based on the spatial location identifiers, forming a regional feature set including: The vibration signal is decomposed into a multi-resolution time-frequency domain to obtain a time-frequency distribution matrix characterizing the evolution of different frequency components over time. The time axis of the time-frequency distribution matrix corresponds to the sampling time of the vibration signal, the frequency axis corresponds to the spectral components of the vibration signal, and the matrix element values ​​correspond to the energy amplitude of the frequency component at a certain time. Statistical and morphological features characterizing vibration modes are extracted from the time-frequency distribution matrix. The statistical features include energy distribution statistics of the time-frequency distribution matrix in the time and frequency dimensions, and the morphological features include geometric shape description parameters of energy concentration regions in the time-frequency distribution matrix. The statistical features and the morphological features are combined to form the feature vector. The spatial region corresponding to the vibration signal is determined based on the spatial location identifier, and the feature vector is mapped to the spatial region and stored in the region feature set.

3. The method according to claim 1, characterized in that, Based on the transfer matrix, energy flow source analysis is performed on the feature vectors of different spatial regions to identify cross-regional vibration events with a common energy source, including: Based on the diffusion path and energy distribution ratio represented in the transfer matrix, for the feature vector of each spatial region, the reverse transfer path of the vibration energy received by the spatial region in the transfer matrix is ​​calculated. The reverse transfer path is composed of the node sequence of the spatial region tracing back to the source region along the reverse edge of the transfer matrix, thus obtaining the set of candidate energy source regions corresponding to the spatial region. The intersection operation is performed on the set of candidate energy source regions to identify common source regions that appear simultaneously in multiple spatial regions. Multiple spatial regions with the same common source region are grouped into candidate cross-regional vibration event groups. For the candidate cross-regional vibration event group, the theoretical energy distribution after the feature vector of the common source region is transmitted to each spatial region in the group through the transfer matrix is ​​calculated. The consistency of the theoretical energy distribution with the actual feature vector of each spatial region is checked. When the consistency check passes, the candidate cross-regional vibration event group is confirmed as a cross-regional vibration event with a common energy source.

4. The method according to claim 3, characterized in that, The reverse transmission path of the vibration energy received in this spatial region in the transmission matrix includes: Transpose the transfer matrix to obtain the inverse transfer matrix. The row index of the inverse transfer matrix represents the energy receiving region, the column index represents the energy supply region, and the matrix element values ​​represent the energy distribution ratio from the energy supply region to the energy receiving region. For the target spatial region, extract the row vectors in the inverse transfer matrix with the target spatial region as the row index. The column element values ​​of the row vectors represent the energy contribution of different energy supply regions to the target spatial region. Based on the energy contribution, select energy supply regions whose energy contribution exceeds a preset contribution threshold as first-level source regions. The first-level source region is used as the new target spatial region. The energy contribution calculation steps are repeated to obtain the second-level source region to the Nth-level source region in sequence. When the energy contribution of a certain source region is all lower than the preset contribution threshold or reaches the preset traceability depth limit, the recursion is terminated. The region sequence from the target spatial region to the terminal source region is used as the reverse transmission path, and the terminal source region is included in the energy source candidate region set.

5. The method according to claim 1, characterized in that, Linked intrusion events are identified by searching for subgraph structures that satisfy a preset topological pattern in the causal dependency graph, and the spatial location and movement trajectory of the intrusion source are determined based on the topological location of nodes in the subgraph structure, including: In the causal dependency graph, all node combinations are traversed, and candidate subgraph structures composed of nodes and edges in each node combination are extracted. The candidate subgraph structures are compared with the preset topology pattern for structural isomorphism. It is determined whether the candidate subgraph structure can be decomposed into atomic topology combinations contained in the preset topology pattern and whether the splicing relationship between each atomic topology conforms to the primitive combination rules. When the candidate subgraph structure meets the structural isomorphism comparison condition, the candidate subgraph structure is marked as a matching subgraph structure, and the cross-regional vibration event corresponding to the matching subgraph structure is marked as a linkage intrusion event. Based on the serial splicing order of the atomic topology and the temporal order of the edge weights within each atomic topology, the nodes in the matching subgraph structure are temporally sorted to obtain the temporal access sequence of the nodes. The spatial region corresponding to the earliest node in the temporal access sequence is determined as the spatial location of the intrusion source. The spatial regions corresponding to each node in the temporal access sequence are connected in temporal order to form the movement trajectory of the intrusion source.

6. The method according to claim 5, characterized in that, The preset topology modes include: The topological element library and element combination rules are defined based on the characteristics of intrusion behavior. The topology primitive library contains atomic topology structures that represent basic intrusion actions. Each atomic topology structure consists of a fixed number of nodes and edges with a fixed connection method. The primitive combination rules define the splicing methods and connection conditions of multiple atomic topologies. The splicing methods include serial splicing and parallel splicing, and the connection conditions include the attribute matching requirements of nodes at the splicing interface and the continuity requirements of edge weights. Multiple atomic topological structures are combined according to the primitive combination rules to generate a composite topological pattern.

7. The method according to claim 1, characterized in that, The generation of regional cascaded response commands based on the spatial location and movement trajectory of the linked intrusion event includes: The motion direction vector and motion speed parameter of the intrusion object are calculated based on the temporal access sequence of each spatial region in the motion trajectory. The motion direction vector is obtained by calculating the spatial coordinate difference between temporally adjacent spatial regions, and the motion speed parameter is obtained by calculating the ratio of the spatial distance between temporally adjacent spatial regions to the time interval. All spatial regions in the motion trajectory are marked as response coverage areas, which include historical spatial regions in the motion trajectory where intrusion events have occurred. A temporal position index is calculated for each response coverage area, which represents the temporal order in which the response coverage area was accessed during the intrusion process. Regional response instructions are generated sequentially for each response coverage area according to the order of the time-series position index. Each regional response instruction includes a target area identifier, a response start time, and a response action type. The target area identifier points to the corresponding response coverage area. The response start time is calculated based on the time-series position index of the response coverage area and the current time. The response action type is determined based on the position attribute of the response coverage area in the motion trajectory. All regional response instructions are organized into regional cascaded response instructions according to the order of the response start times.

8. A distributed optical fiber vibration event detection system, used to implement the method as described in any one of claims 1-7, characterized in that, include: The first unit is used to collect vibration signals from multiple spatial regions through distributed optical fiber sensing units deployed along a preset path. The vibration signals include time-domain waveforms and spatial location identifiers. The second unit is used to perform time-frequency domain decomposition on the vibration signal, extract feature vectors reflecting the vibration mode, and map the feature vectors to the corresponding spatial regions according to the spatial location identifiers to form a regional feature set; The third unit is used to construct a transmission matrix of vibration energy among multiple spatial regions in the set of regional features. The transmission matrix represents the diffusion path and energy distribution ratio of vibration energy from the source region to adjacent regions. Based on the transmission matrix, energy flow source analysis is performed on the feature vectors of different spatial regions to identify cross-regional vibration events with a common energy source. The fourth unit is used to establish a causal dependency graph of vibration response between regions. The nodes of the causal dependency graph represent spatial regions, the edges represent the vibration transmission relationship between regions, and the edge weights represent the temporal sequence of vibration transmission. Linked intrusion events are identified by searching for subgraph structures that satisfy a preset topological pattern in the causal dependency graph. The spatial location and movement trajectory of the intrusion source are determined based on the topological position of the nodes in the subgraph structure. The topological pattern is defined by a region access sequence that characterizes the intrusion behavior. The fifth unit is used to generate a regional cascade response command based on the spatial location and movement trajectory of the linked intrusion event. The regional cascade response command is used to control the protective devices corresponding to the multiple spatial regions to perform linked protective actions.

9. An electronic device, characterized in that, include: processor; Memory used to store processor-executable instructions; The processor is configured to invoke instructions stored in the memory to execute the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, they implement the method described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Distributed optical fiber invasion detecting method based on Mel spectrum

    CN110823356A

  • Cross-domain collaborative information tracking and positioning auxiliary method and system

    CN120632789A