Intelligent security method, system and device and storage medium
By employing a distributed architecture that combines initial screening at the edge with multi-agent collaboration in the cloud, the problems of high network bandwidth consumption and response latency in traditional security systems are solved, enabling faster security decision generation and real-time response.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHONGKE YUNGU TECH
- Filing Date
- 2025-12-31
- Publication Date
- 2026-04-10
AI Technical Summary
Traditional security systems suffer from high network bandwidth consumption and response latency due to centralized processing of massive amounts of raw data on servers, making it difficult to meet real-time security needs.
It adopts a distributed architecture that coordinates cloud, edge, and device, with the edge device performing preliminary data screening and processing, the cloud device performing in-depth analysis and decision generation, and multiple agents being used for data fusion and decision-making.
Significantly reduces network bandwidth usage, shortens decision generation time, improves response speed, and meets real-time security needs.
Smart Images

Figure CN121842238A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of security technology, specifically to an intelligent security method, system, device, and storage medium. Background Technology
[0002] Intelligent security refers to the use of modern information technologies such as the Internet of Things and cloud computing to achieve more automated, intelligent, and networked security management and prevention.
[0003] Traditional security systems typically employ a model where front-end sensors collect data and a back-end central server processes it centrally. In this model, sensors collect massive amounts of raw data, which is then uploaded entirely to the central server. This not only consumes significant network bandwidth but also results in high response latency due to centralized server processing, making it difficult to meet real-time security requirements. Summary of the Invention
[0004] The purpose of this application is to provide an intelligent security method, system, device, and storage medium.
[0005] To achieve the above objectives, the first aspect of this application provides an intelligent security method, which is applied to an intelligent security system, including an edge terminal and a cloud terminal. The method includes: Acquire various types of raw environmental data based on the edge; For each type of raw environmental data, the target environmental data is obtained by filtering the raw environmental data at the edge. The target environmental data is environmental data related to security events. Multiple intelligent agents deployed in the cloud are used to fuse and analyze data from all types of target environments and generate corresponding security decisions.
[0006] In this embodiment, the intelligent agent includes an event review intelligent agent and a rule linkage intelligent agent. Multiple intelligent agents deployed in the cloud perform fusion analysis on all types of target environment data and generate corresponding security decisions. This includes: using the event review intelligent agent to perform fusion analysis on all types of target environment data to obtain the event type of the security event; and using the rule linkage intelligent agent to match the event type based on a preset event processing rule library and generate the security decision corresponding to the security event based on the matching result.
[0007] In this embodiment of the application, the method further includes: extracting data features of all types of target environment data through an event review agent; calculating the confidence level of the security event based on the data features when the data features of all types of target environment data meet the preset intrusion mode; and performing fusion analysis on all types of target environment data through the event review agent when the confidence level is greater than or equal to a preset threshold to obtain the event type of the security event.
[0008] In this embodiment of the application, the intelligent agent also includes a trajectory drawing intelligent agent, and the method further includes: performing fusion analysis on all types of target environment data through an event review intelligent agent to determine the tracking target corresponding to the security event; extracting the spatiotemporal data of the tracking target from the target environment data through the trajectory drawing intelligent agent, and drawing the activity trajectory of the tracking target based on the spatiotemporal data.
[0009] In this embodiment of the application, the intelligent agent also includes an instruction issuing intelligent agent, and the method further includes: issuing at least one of an alarm instruction, a contingency plan execution instruction, and a work order processing instruction through the instruction issuing intelligent agent based on security decisions.
[0010] In this embodiment of the application, for each type of raw environmental data, target environmental data is obtained by filtering the raw environmental data at the edge, including: for each type of raw environmental data, extracting data features of the raw environmental data through a small model deployed at the edge, and identifying security events based on the data features; and filtering target environmental data related to security events from the raw environmental data.
[0011] In this embodiment of the application, the method further includes: acquiring new raw environmental data based on the edge terminal; and determining that the security decision was successfully executed if the raw environmental data meets the preset security standards.
[0012] A second aspect of this application provides an intelligent security system, which includes an edge terminal and a cloud terminal.
[0013] A third aspect of this application provides an intelligent security device, comprising: a memory configured to store instructions; a processor configured to retrieve instructions from the memory and to implement an intelligent security method when executing the instructions.
[0014] A fourth aspect of this application provides a machine-readable storage medium storing instructions that cause a machine to perform an intelligent security method.
[0015] This solution employs a distributed architecture that integrates cloud, edge, and endpoint collaboration. At the edge, raw environmental data is acquired and initially filtered, effectively reducing the upload of redundant data and significantly lowering network bandwidth consumption. In the cloud, the collaborative advantages of various intelligent agents are fully leveraged to perform deep reasoning, information fusion, and decision generation on the filtered target environmental data. This architecture significantly shortens the overall time from data acquisition to decision generation, reduces response latency, and thus better meets the needs of real-time security.
[0016] Other features and advantages of the embodiments of this application will be described in detail in the following detailed description section. Attached Figure Description
[0017] The accompanying drawings are provided to further illustrate the embodiments of this application and form part of the specification. They are used together with the following detailed description to explain the embodiments of this application, but do not constitute a limitation on the embodiments of this application. In the drawings: Figure 1 A schematic flowchart of an intelligent security method according to an embodiment of this application is shown. Figure 2 The schematic diagram illustrates the operation mechanism of the intelligent security method according to an embodiment of this application; Figure 3 This diagram schematically illustrates the system architecture of an intelligent security method according to an embodiment of this application. Figure 4 A schematic diagram illustrating the structure of an intelligent security device according to an embodiment of this application is shown. Figure 5 The diagram illustrates the internal structure of a computer device according to an embodiment of this application. Detailed Implementation
[0018] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only for illustration and explanation of the embodiments of this application and are not intended to limit the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.
[0019] Figure 1 The illustration shows a flowchart of an intelligent security method according to an embodiment of this application. Figure 1 As shown, this application provides an intelligent security method applied to an intelligent security system, which includes an edge terminal and a cloud terminal. The edge terminal refers to devices and / or nodes deployed at the data source, typically possessing a certain level of computing, storage, and networking capabilities, enabling preliminary data analysis and processing locally; examples include smart cameras and edge computing gateways. The cloud terminal refers to a remote data center composed of servers, possessing powerful computing, storage, and data processing capabilities.
[0020] Intelligent security methods may include the following steps: Step 101: Obtain various types of raw environmental data based on the edge device.
[0021] Raw environmental data refers to data directly collected by various acquisition devices without any processing, such as images, photos, audio, and text. This data reflects the environment in different dimensions, containing both relevant and useful information directly related to the current application, as well as a large amount of redundant or irrelevant information.
[0022] Optionally, based on specific needs such as security and environmental monitoring, appropriate data collection devices can be deployed, such as cameras, microphones, smart glasses, drones, and automated patrol vehicles in key areas. Then, by actively pushing data to the data collection devices or periodically polling them, the edge devices can acquire various types of raw environmental data.
[0023] For example, when constructing a cross-protection network, an intelligent security system can integrate various sensors such as vibration fiber optics, electronic fences, infrared beam detectors, radar, and smart cameras. Among them, vibration fiber optics can be used to sense physical vibrations such as climbing or shearing fences, while smart cameras continuously collect video data, thereby forming a multi-dimensional environmental perception capability.
[0024] Step 102: For each type of raw environmental data, the target environmental data is obtained by filtering the raw environmental data at the edge. The target environmental data is environmental data related to security events.
[0025] Target environmental data refers to environmental data closely related to security incidents. Security incidents broadly refer to various situations that may pose a threat to the safety of people, property, or the environment, such as fires, unauthorized intrusions, leaks, and sabotage.
[0026] In one feasible implementation, corresponding data features are first defined for various types of raw environmental data. For example, image features for image data include object edges, color distribution, and texture, while audio features for audio data include sound frequency and pitch variation. Then, appropriate filtering algorithms are deployed based on the type of data features. For example, for simple numerical comparisons such as whether the temperature exceeds a threshold, a basic conditional judgment algorithm can be used; for image analysis, a lightweight target detection algorithm needs to be deployed. Based on this, the edge processing unit can then process the raw environmental data using the corresponding filtering algorithm according to the preset data features. Specifically, numerical data is directly compared with a set threshold, while image data is determined using a target detection algorithm to determine whether there are targets related to security events. Data that meets the conditions is then marked as target environmental data.
[0027] In another feasible implementation, for each type of raw environmental data, data features of the raw environmental data are extracted by a small model deployed at the edge, and security events are identified based on the data features; target environmental data related to security events are then filtered from the raw environmental data.
[0028] Among them, small models refer to a class of lightweight artificial intelligence models with fewer parameters, lower computational complexity, and smaller size. These models learn from a large number of data samples, automatically extracting complex features and patterns, adapting to data changes in different scenarios, and making reasonable judgments on unseen situations.
[0029] During the training phase, a large number of raw environmental data samples related to security incidents need to be collected and labeled. Then, a small model is trained based on these samples and deployed to the edge.
[0030] During the application phase, after acquiring raw environmental data, the edge endpoint inputs it into a deployed small model for inference. The small model first extracts features, then matches the data features with event feature templates learned during the training phase, and then determines whether a security event has occurred and the type of event based on the similarity between the features. For example, by comparing the similarity between video features and event templates such as intrusion and fire, the corresponding event type can be identified.
[0031] Finally, based on the time point when the security event was triggered, the edge device locates and extracts data segments containing the event from the original environmental data, which are then used as target environmental data and uploaded to the cloud. For example, a 10-second video clip might be used as target environmental data, tagged with event type labels such as "human detection," and then uploaded to the cloud for further analysis.
[0032] This implementation method achieves initial data screening by deploying small models at the edge. Because small models have strong environmental adaptability and can maintain stable operation even in complex and ambiguous real-world scenarios, exhibiting high robustness, this implementation method can complete the data screening task more accurately and reliably.
[0033] Step 103: Multiple intelligent agents deployed in the cloud perform fusion analysis on all types of target environment data and generate corresponding security decisions.
[0034] This solution deploys a large-scale model integrating multiple agents in the cloud. The large-scale model refers to a deep learning model with powerful language understanding and reasoning capabilities. Agents are intelligent entities capable of autonomously perceiving their environment, making decisions, and executing tasks to achieve specific goals. By integrating multiple agents with different functions into a unified large-scale model framework, each agent can be responsible for different sub-tasks and, through mutual cooperation and interaction, jointly complete more complex and comprehensive tasks.
[0035] Optionally, based on the specific needs of the security scenario, multiple intelligent agents with different functions can be designed and deployed to the cloud, while a scheduling center can be set up to coordinate the task allocation and workflow among the intelligent agents.
[0036] Specifically, once the target environment data uploaded from the edge reaches the cloud, the scheduling center creates corresponding tasks for it, breaks down and plans complex tasks, clarifies the execution order of each sub-task, and then assigns them to appropriate intelligent agents. Each intelligent agent, upon receiving the data, independently analyzes it using its own algorithms and models. Finally, the analysis results from all intelligent agents are synthesized to generate corresponding security decisions, such as generating and dispatching work orders to relevant personnel or triggering perimeter alarm systems.
[0037] In one feasible implementation, the large model is deployed with an event review agent and a rule linkage agent. Specifically, the event review agent performs fusion analysis on all types of target environment data to obtain the event type of the security event; the rule linkage agent matches the event type based on a preset event processing rule base and generates the corresponding security decision based on the matching result.
[0038] Among them, the event review intelligent agent is an intelligent entity with multi-source data fusion and analysis capabilities, capable of comprehensively processing and analyzing various types of target environment data. The rule-linked intelligent agent is an intelligent entity that generates decisions based on preset rules. It internally stores an event processing rule base, which defines various security event types and corresponding handling measures.
[0039] First, the event review agent preprocesses various target environment data, including data cleaning, format conversion, and normalization, to remove noise, correct errors, and convert data of different formats into a unified structure, making it comparable and analyzable. Then, the event review agent uses specific algorithms and models to extract features from the preprocessed target environment data. For example, it extracts visual features such as object edges, color distribution, and texture from image data, and acoustic features such as frequency and pitch variations from audio data. Next, it employs multi-source information fusion algorithms to perform correlation analysis and comprehensive judgment on the features of different types of data. By considering the mutual influence between features, it more accurately identifies security events and their specific types, such as distinguishing between ordinary personnel activity and illegal intrusion, or determining whether temperature changes are normal equipment operation or a fire hazard.
[0040] Furthermore, the rule-linking intelligent agent receives the event type output by the event review intelligent agent and searches for a match in a pre-set event processing rule base. If multiple matching results exist, the most suitable matching result can be determined automatically based on rule priority or through manual intervention. Finally, the rule-linking intelligent agent generates corresponding security decisions based on the matching results.
[0041] It is important to note that to reduce the impact of false alarms at the edge, this solution can introduce a secondary verification mechanism before the fusion analysis. Specifically, a series of intrusion patterns are predefined, represented by combinations of features. For example, for illegal intrusion events, the pattern can be set as "an unfamiliar person appears in the video within a specific time period, and the magnetic sensors of doors and windows detect that they are open, and the vibration sensors detect abnormal vibrations." In this way, the event verification agent can match the data features of all types of target environmental data extracted with the preset intrusion patterns to check whether all conditions are met. If necessary, image recognition tools can be called or other camera perspectives can be requested to assist in the judgment to improve the accuracy of the results. If all data features meet the preset intrusion patterns, the confidence calculation stage is entered, that is, by using weighted averaging or other suitable fusion methods, different types of data features are combined to calculate the confidence of the security event. If the confidence is lower than a preset threshold, it is judged as a false alarm at the edge. If the confidence is greater than or equal to the preset threshold, the event is judged to have high authenticity, and fusion analysis is continued to determine the specific type of the event, thereby generating the corresponding security decision.
[0042] In another feasible implementation, the large model also deploys a trajectory mapping agent. Specifically, the event verification agent performs fusion analysis on all types of target environment data to determine the tracking target corresponding to the security event; the trajectory mapping agent extracts the spatiotemporal data of the tracking target from the target environment data, and draws the activity trajectory of the tracking target based on the spatiotemporal data.
[0043] Among them, the trajectory drawing agent is an intelligent entity that can draw and track the activity trajectory of a target.
[0044] First, the event verification agent identifies security events (the specific steps are the same as above and will not be repeated here), and further analyzes the tracking targets related to the events. For example, in an intrusion event, personnel appearing in abnormal areas can be identified as tracking targets. Then, the trajectory drawing agent extracts the spatiotemporal data of the tracking target from the target's environmental data. Next, based on the distribution characteristics of the target's spatiotemporal data, a suitable trajectory drawing algorithm is selected to draw its activity trajectory. For example, for simple linearly moving targets, a straight-line trajectory can be formed by connecting the position coordinates of each time point. For complex curved-moving targets, a curve fitting algorithm can be used to generate a smooth trajectory curve.
[0045] This implementation method integrates spatiotemporal data to draw and track the target's activity trajectory across the entire domain, enabling real-time linkage between security events and maps. This effectively improves positioning accuracy and provides a global perspective for situation analysis.
[0046] In another feasible implementation, the large model also deploys an instruction-issuing agent. Specifically, the instruction-issuing agent issues at least one of the following based on security decisions: alarm instructions, contingency plan execution instructions, and work order processing instructions.
[0047] Among them, the instruction-issuing intelligent agent is an intelligent entity specifically responsible for conveying instructions.
[0048] The instruction-issuing agent receives security decisions from the rule-linked agent and determines the type of instruction to be issued based on the decision content, namely, at least one of the following: alarm instruction, contingency plan execution instruction, or work order processing instruction.
[0049] Furthermore, to monitor the execution status and results of security decisions, this application can also make judgments based on new raw environmental data acquired at the edge, such as analyzing whether there are still targets related to the security event in the image data. If the raw environmental data meets the preset security standards, the security decision can be determined to have been successfully executed. This solution can automatically verify whether the event has completed closed-loop processing and ultimately achieve archive management.
[0050] In this embodiment, various types of raw environmental data are first preliminarily screened at the edge, and then multiple intelligent agents deployed in the cloud fuse and process the screened target environmental data to collaboratively generate corresponding security decisions. This architecture employs an edge-based preliminary screening mechanism, effectively removing invalid and redundant information from the raw data and retaining only target environmental data relevant to security events. After screening, only the target environmental data is uploaded to the cloud, significantly reducing data transmission volume compared to the traditional mode of transmitting all raw data. Furthermore, this solution uses multiple intelligent agents deployed in the cloud to collaboratively fuse and analyze all types of target environmental data. This collaborative approach fully leverages the strengths of each agent, improving the efficiency and accuracy of data analysis. Simultaneously, since the data uploaded to the cloud is already edge-screened target environmental data, its volume is relatively small, allowing agents to complete analysis more quickly and generate corresponding security decisions. This significantly shortens the overall time from data collection to decision generation, reduces response latency, and better meets real-time security needs.
[0051] To help understand the implementation process of the intelligent security method obtained by combining this embodiment with the above embodiment one, an example is provided here.
[0052] Reference Figure 2 , Figure 2 A schematic diagram illustrating the operational mechanism of an intelligent security method is provided.
[0053] 1. Task Triggering and Input: The input layer receives various types of raw environmental data (such as video streams, alarm signals, text reports, etc.) from the acquisition devices and transforms them into task instructions that the system can understand.
[0054] 2. Task Planning and Distribution: The core layer acts as a "scheduling center," breaking down and planning complex tasks. Its workflow management module determines the execution order of subtasks, the agent evaluation module selects the most suitable agent from the agent system layer, and then the task management module and agent communication module realize task distribution and collaborative communication.
[0055] 3. Intelligent Analysis and Decision-Making: 1) Memory module: Records key contextual information to ensure the consistency and accuracy of decision-making.
[0056] 2) Planning module: Develop step-by-step execution plans for the assigned sub-tasks.
[0057] 3) Inference engine: Analyzes the current context and understands the core elements of complex requests.
[0058] 4) Tool selection module: Based on the needs, users can independently call appropriate resources in the tool layer (such as API query, search engine, code execution, etc.) to assist in task completion.
[0059] 4. Capability Support and Execution: The basic model layer (large model) provides fundamental language understanding and content generation capabilities to support the reasoning, planning, and tool invocation of the upper layers. Ultimately, decision-making instructions are output through the business application layer (such as the work order center) to drive actual business responses and action execution.
[0060] Reference Figure 3 , Figure 3 A system architecture diagram for an intelligent security method is provided.
[0061] 1. Perception Layer: As the data acquisition source of the system, this layer integrates various front-end acquisition devices, such as cameras, drones, microphones, smoke detectors, unmanned patrol vehicles, AR glasses, etc., and is responsible for acquiring various types of raw environmental data in real time.
[0062] 2. Edge Analysis Layer: Performs preliminary processing and analysis on the raw environmental data collected by the perception layer, mainly including behavior recognition and event analysis.
[0063] 3. Cloud-based decision-making layer: Responsible for aggregating and deeply analyzing data from the edge, and generating decision instructions through mechanisms such as event verification, false alarm elimination, multi-source data fusion, and rule linkage.
[0064] 4. Execution Layer: Based on the instructions issued by the cloud-based decision-making layer, it executes specific operations, including linking devices, sending messages, dispatching work orders, scheduling work orders, handling on-site, and closing work orders.
[0065] 5. Monitoring layer: Responsible for monitoring and evaluating the operation of the entire system, including result detection and data archiving.
[0066] The specific process is as follows: 1. Sensing and Detection When intrusion occurs (such as climbing, touching fences, or entering restricted areas), front-end data collection devices deployed along the perimeter will detect it in real time. For example, vibrating fiber optic cables can detect physical vibrations such as climbing or cutting fences; smart cameras use video analytics to collect behavioral data in real time, such as area intrusion, boundary crossing, or loitering.
[0067] 2. Preliminary processing of the edge ends To reduce cloud load, edge computing-enabled data acquisition devices or nodes perform preliminary analysis and filtering of raw environmental data, uploading only target environmental data relevant to suspicious security events to the cloud via wired or wireless networks. This significantly reduces false alarms (e.g., filtering out disturbances from swaying leaves or small animals). Data transmission typically employs encryption and redundant network designs to ensure secure, reliable, and low-latency transmission.
[0068] 3. Cloud-based decision-making A large model integrating multiple agents is deployed in the cloud, with a scheduling center. This multi-agent collaborative mechanism enables efficient event processing and false alarm control. Specifically, when target environment data uploaded from the edge reaches the cloud, the scheduling center creates corresponding tasks, breaks down and plans complex tasks, clarifies the execution order of sub-tasks, and assigns them to appropriate agents for processing.
[0069] The following uses a perimeter intrusion incident as an example to explain in detail the functions and collaboration process of each agent: (1) Event review agent: By fusing and analyzing various types of raw environmental data (such as structured video information and sensor time-series data), the validity of events can be verified, significantly reducing the false alarm rate. For example, target behavior can be analyzed by combining camera video (such as distinguishing between climbing and animal interference), and consistency comparison can be performed with vibration fiber optic data in the time dimension.
[0070] Iterative reasoning can be performed using the ReAct pattern: 1) Observation: Acquire all types of target environment data; 2) Reasoning: Determine whether the data characteristics of all types of target environmental data meet the preset intrusion mode; 3) Action: If necessary, invoke image recognition tools or request additional camera views; 4) Feedback: If the confidence level is lower than the preset threshold, it will be marked as a "false alarm" and the process will be terminated; 5) Output: Generate verification conclusions, such as "True intrusion, confidence level 92%" or "False alarm, cause: leaf shaking".
[0071] In addition, the event review agent will perform integrated analysis of all types of target environment data to determine the tracking target corresponding to the security event, so that the subsequent trajectory drawing agent can draw the activity trajectory.
[0072] In addition, the event review agent will perform integrated analysis on all types of target environment data to obtain the event type of security event, so that the subsequent rule-linked agent can generate security decisions.
[0073] (2) Trajectory drawing agent Responsible for spatial data parsing and context enhancement.
[0074] When the edge device reports target environment data, the intelligent agent immediately associates the geographical location of the event (such as coordinates, regional attributes), surrounding defense equipment (cameras, radar range), and terrain information (such as blind spots, high-risk sections).
[0075] Once the target is identified, the trajectory drawing AI extracts the spatiotemporal data of the target from the target's environmental data to draw the target's activity trajectory.
[0076] In addition, the event review agent can also provide spatial decision support for other agents. For example, it can recommend the optimal camera angle to the event review agent, or output contextual information such as "the intrusion point is located in the northwest blind spot" to the rule linkage agent.
[0077] (3) Rule-linked intelligent agents Security decisions are generated based on a pre-defined event handling rule base (such as "if both vibration of the fiber optic cable and intrusion into the video area are triggered simultaneously, the alarm will be escalated"). Specifically, a Plan & Solve mode can be used to pre-plan response paths; for example, a level 1 alarm can directly trigger a work order, while a level 2 alarm requires review.
[0078] In addition, after receiving contextual information from the trajectory drawing agent, the rule-linking agent can dynamically adjust the application of rules (e.g., automatically escalating nighttime blind spot events to high risk). If there are no rule conflicts, the agent is triggered to execute the task. If there are rule conflicts, a reflection mode is activated, requesting the event review agent to reassess, or transferring the matter to manual intervention for adjustment.
[0079] (4) Instructions are issued to the intelligent agent It receives security decisions generated by rule-based intelligent agents and issues corresponding instructions, including alarm notifications, contingency plan execution, and work order dispatch. For example, it generates dynamic work orders (such as "dispatch security personnel to area A3"); it coordinates with external systems such as access control, lighting, and drones to execute contingency plans; or it transfers instructions to human resources or equipment control-related intelligent agents through task handover mode.
[0080] 4. Incident Handling: Once a genuine intrusion is confirmed, the system immediately activates a comprehensive alarm and coordinated response mechanism.
[0081] Multi-channel alarm notification: The system will issue warnings on-site via sound and light alarms, and at the same time quickly deliver alarm information (including location, video screenshots, and type) to relevant security personnel via SMS, APP push, voice broadcast, etc.
[0082] Automated contingency plan linkage: The system can automatically execute preset linkage plans, such as: activating on-site lighting and sirens for deterrence; linking with the access control system to lock relevant passages; making remote announcements through the broadcast system; and even dispatching patrol cars or drones to the scene.
[0083] Work order processing: After receiving a work order, security personnel will go to the site to handle it and report the results back to the system via mobile terminal.
[0084] 5. Closed-loop and archiving The system will review the results based on the newly collected raw environmental data at the edge. If the data meets the preset security standards (such as confirming that the intrusion event has been eliminated through methods such as monitoring with associated cameras and full-domain face comparison), the security decision will be deemed to have been successfully executed, and the event handling loop will be completed.
[0085] The system records the entire process of the incident, including alarm time, location, review video, personnel involved, and results, forming a complete electronic file for future reference, auditing, and optimization of contingency plans.
[0086] The aforementioned solution employs a dual mechanism of "preliminary edge filtering + multimodal intelligent verification in the cloud," effectively identifying and eliminating various environmental interferences. This architecture avoids data surges while achieving real-time edge response and automated decision-making and dispatching by cloud-based intelligent agents, significantly shortening the average incident handling time and reducing reliance on manual intervention. Furthermore, through multi-agent collaboration, the system integrates discrete security processes such as perception, alarm, verification, dispatching, handling, and verification into a seamless automated workflow, thereby greatly improving the overall intelligence level of security management.
[0087] Figure 1 This is a flowchart illustrating an intelligent security method in one embodiment. It should be understood that, although... Figure 1 The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise explicitly stated herein, there is no strict order in which these steps are executed, and they can be performed in other orders. Figure 1At least some of the steps in the process may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least some of the sub-steps or stages of other steps.
[0088] This application provides an intelligent security system, which includes an edge terminal and a cloud terminal.
[0089] In one embodiment, such as Figure 4 As shown, an intelligent security device 400 is provided, including a raw environmental data acquisition module, a target environmental data filtering module, and a security decision generation module, wherein: The raw environment data acquisition module 401 is used to acquire various types of raw environment data based on the edge terminal.
[0090] The target environment data filtering module 402 is used to filter the raw environment data for each type of raw environment data through the edge terminal to obtain target environment data, which is environmental data related to security events.
[0091] The security decision generation module 403 is used to perform fusion analysis on all types of target environment data through multiple intelligent agents deployed in the cloud, and generate corresponding security decisions.
[0092] The intelligent security device includes a processor and a memory. The aforementioned raw environmental data acquisition module, target environmental data filtering module, and security decision generation module are all stored as program units in the memory. The processor executes the aforementioned program modules stored in the memory to implement the corresponding functions.
[0093] The processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured, and intelligent security methods can be implemented by adjusting kernel parameters.
[0094] The memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0095] This application provides a storage medium on which a program is stored, which, when executed by a processor, implements the above-described intelligent security method.
[0096] This application provides a processor for running a program, wherein the program executes the above-described intelligent security method during runtime.
[0097] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 5 As shown in the figure, the computer device includes a processor A01, a network interface A02, a display screen A04, an input device A05, and a memory (not shown) connected via a system bus. The processor A01 provides computing and control capabilities. The memory includes internal memory A03 and a non-volatile storage medium A06. The non-volatile storage medium A06 stores an operating system B01 and a computer program B02. The internal memory A03 provides an environment for the operation of the operating system B01 and the computer program B02 stored in the non-volatile storage medium A06. The network interface A02 is used for communication with external terminals via a network connection. When the computer program is executed by the processor A01, it implements an intelligent security method. The display screen A04 can be an LCD screen or an e-ink display screen. The input device A05 can be a touch layer covering the display screen, buttons, a trackball, or a touchpad mounted on the computer device casing, or an external keyboard, touchpad, or mouse.
[0098] Those skilled in the art will understand that Figure 5 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0099] This application provides a computer (electronic) device, which includes a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it implements the steps of any of the above-mentioned intelligent security methods.
[0100] This application also provides a computer program product that, when executed on a data processing device, is suitable for executing a program that initializes intelligent security method steps.
[0101] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0102] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0103] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0104] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0105] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0106] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0107] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0108] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0109] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. An intelligent security method, characterized in that, The intelligent security method is applied to an intelligent security system, which includes an edge terminal and a cloud terminal. The method includes: Multiple types of raw environmental data are acquired based on the edge endpoint; For each type of raw environmental data, the target environmental data is obtained by filtering the raw environmental data through the edge terminal. The target environmental data is environmental data related to security events. Multiple intelligent agents deployed in the cloud perform fusion analysis on all types of target environment data and generate corresponding security decisions.
2. The intelligent security method according to claim 1, characterized in that, The intelligent agents include event review intelligent agents and rule linkage intelligent agents. Multiple intelligent agents deployed in the cloud perform fusion analysis on all types of target environment data and generate corresponding security decisions, including: The event type of the security event is obtained by fusing and analyzing all types of target environment data through the event verification intelligent agent. The rule-linked intelligent agent matches the event types based on a preset event processing rule base, and generates security decisions corresponding to the security events based on the matching results.
3. The intelligent security method according to claim 2, characterized in that, The method further includes: The event verification agent extracts data features from all types of target environment data. When the data characteristics of all types of target environment data meet the preset intrusion mode, the confidence level of the security event is calculated based on the data characteristics; When the confidence level is greater than or equal to a preset threshold, the event verification agent performs fusion analysis on all types of target environment data to obtain the event type of the security event.
4. The intelligent security method according to claim 2, characterized in that, The intelligent agent also includes a trajectory drawing intelligent agent, and the method further includes: The event verification agent performs fusion analysis on all types of target environment data to determine the tracking target corresponding to the security event; The trajectory drawing agent extracts the spatiotemporal data of the tracked target from the target environment data and draws the activity trajectory of the tracked target based on the spatiotemporal data.
5. The intelligent security method according to claim 2, characterized in that, The intelligent agent also includes an instruction-issuing intelligent agent, and the method further includes: The intelligent agent, based on the security decision, issues at least one of the following commands: an alarm command, a contingency plan execution command, and a work order processing command.
6. The intelligent security method according to claim 1, characterized in that, For each type of raw environmental data, the target environmental data is obtained by filtering the raw environmental data through the edge terminal, including: For each type of raw environmental data, data features are extracted from the raw environmental data using a small model deployed at the edge, and the security event is identified based on the data features. Filter the target environmental data related to the security incident from the original environmental data.
7. The intelligent security method according to claim 1, characterized in that, The method further includes: New raw environmental data is obtained based on the edge endpoint; If the original environmental data meets the preset security standards, the security decision is deemed to have been successfully executed.
8. An intelligent security system, characterized in that, The system includes an edge device and a cloud device.
9. An intelligent security device, characterized in that, include: The memory is configured to store instructions; A processor is configured to retrieve the instructions from the memory and, when executing the instructions, to implement the intelligent security method according to any one of claims 1 to 7.
10. A machine-readable storage medium storing instructions thereon, characterized in that, When executed by a processor, the instruction causes the processor to be configured to perform the intelligent security method according to any one of claims 1 to 7.