Safe shutdown method and device, computer equipment and storage medium
By combining target recognition and safety output channel status for cross-verification in industrial safety scenarios where the visual inspection link is unstable, a safety control signal is generated, which solves the problem of accidental shutdown or inconsistent shutdown caused by the instability of the visual inspection link and achieves a balance between safety and stability in complex industrial environments.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHENZHEN BAYTEST TECH CO LTD
- Filing Date
- 2025-12-30
- Publication Date
- 2026-05-01
AI Technical Summary
Existing technologies struggle to balance security and stability in industrial security scenarios where visual inspection links are unstable, leading to issues such as accidental shutdowns or inconsistent shutdowns.
By acquiring detection data from the target monitoring area, target identification processing is performed. Intrusion determination is made by combining category information and confidence information. The output status and heartbeat status information of the security output channel are acquired, cross-validation processing is performed, and a security control signal is generated to trigger a security shutdown.
When the visual inspection link is unstable, it can make reliable safety decisions based on multi-source criteria, avoid accidental or missed shutdowns, improve the stability and consistency of safety shutdown control, and is suitable for complex industrial environments.
Smart Images

Figure CN121963367A_ABST
Abstract
Description
Safe shutdown methods, devices, computer equipment and storage media Technical Field
[0001] This invention relates to the field of industrial safety, and more particularly to a safe shutdown method, apparatus, computer equipment, and storage medium. Background Technology
[0002] In the current field of industrial safety protection, to prevent personnel or foreign objects from entering hazardous work areas, safety sensing devices are typically used to monitor the target monitoring area in real time. Upon detecting personnel intrusion or equipment malfunction, the external working equipment is controlled to enter a shutdown or safe state. Common safety monitoring methods include intrusion detection schemes based on safety light curtains, laser scanners, vision sensors, 3D sensors, or TOF cameras (time-of-flight cameras). These schemes identify and determine the status of targets within the monitoring area and output corresponding safety control signals.
[0003] With the development of 3D vision sensing technology and intelligent recognition algorithms, some existing technologies have begun to use methods based on depth images, point cloud data, or target recognition models to detect targets within a monitored area and determine whether there is any intrusion based on the target's category or the recognition result. This type of approach can provide relatively rich environmental information, which is beneficial for improving detection capabilities in complex scenarios, and therefore it has been applied in some industrial security protection scenarios.
[0004] However, in real-world industrial applications, intrusion detection systems based on Time-of-Flight (TOF) cameras typically operate under complex electromagnetic and optical conditions, making them susceptible to various factors such as electromagnetic interference, power fluctuations, strong light exposure, occlusion changes, and sensor aging. Under these interference conditions, visual inspection systems may experience issues such as image data loss, discontinuities between frames, incomplete target outlines, or abnormal fluctuations in recognition confidence, leading to significant differences in the recognition results for the same target across different detection cycles.
[0005] Furthermore, since visual inspection results are typically used directly in security decisions as high-level semantic criteria, transient anomalies or unstable recognition in the inspection link can easily lead to frequent changes in intrusion judgments within a short period, resulting in erroneous shutdowns or inconsistent shutdown responses of external equipment, affecting production continuity and system reliability. Current technologies typically mitigate the instability of the visual inspection link by adjusting recognition thresholds, extending the judgment cycle, or adding data smoothing processing. However, these methods either rely on empirical parameter configurations or sacrifice response speed, failing to address the lack of effective correlation verification between abnormal visual inspection results and secure shutdown decisions at the system level. A balance between security and stability remains difficult to achieve.
[0006] Therefore, how to achieve a balance between security and stability in scenarios where the visual inspection link is unstable has become a technical problem that urgently needs to be solved in this field. Summary of the Invention
[0007] Therefore, it is necessary to provide a safe shutdown method, device, computer equipment, and storage medium to address the above-mentioned technical problems, which has the advantage of achieving a balance between security and stability even in scenarios where the visual inspection link is unstable.
[0008] A safe shutdown method includes: acquiring detection data of a target monitoring area and performing target identification processing based on the detection data to obtain a target object identification result, the identification result including target object category information and confidence information; performing intrusion determination processing based on the category information and the confidence information to obtain intrusion determination information; acquiring output status information and heartbeat status information of at least two safe output channels and performing channel health determination processing based on the output status information and the heartbeat status information to obtain channel abnormality information corresponding to each safe output channel; performing cross-validation processing based on the intrusion determination information and the channel abnormality information to obtain danger determination results corresponding to at least two safe output channels; generating a safety control signal based on the danger determination results, and controlling at least one of the safe output channels to output a shutdown signal based on the safety control signal to trigger a safe shutdown.
[0009] Optionally, the recognition result includes a first recognition result and a second recognition result. The step of performing target recognition processing based on the detection data to obtain the recognition result of the target object includes: inputting the detection data into a preset first detection model to obtain a first detection result; inputting the detection data into a preset second detection model to obtain a second detection result; inputting the first detection result into a preset first classification network to obtain the first recognition result; and inputting the second detection result into a preset second classification network to obtain the second recognition result.
[0010] Optionally, the intrusion determination processing based on the category information and the confidence information to obtain intrusion determination information includes: when the first category information in the first identification result indicates that the target object is a person, and the first confidence information is not less than a preset confidence threshold, determining that the intrusion determination information indicates that the target object meets the person intrusion condition; when the second category information in the second identification result indicates that the target object is a person, and the second confidence information is not less than the preset confidence threshold, determining that the intrusion determination information indicates that the target object meets the person intrusion condition; when the first category information in the first identification result does not indicate that the target object is a person, and / or the first confidence information is less than the preset confidence threshold, and the second category information in the second identification result does not indicate that the target object is a person, and / or the second confidence information is less than the preset confidence threshold, determining that the intrusion determination information does not meet the person intrusion condition.
[0011] Optionally, acquiring the heartbeat status information of at least two safety output channels includes: acquiring the heartbeat signal output by each safety output channel within a preset detection time window; determining the heartbeat count information and / or heartbeat frequency information corresponding to each safety output channel based on the heartbeat signal; and generating corresponding heartbeat status information based on the heartbeat count information and / or the heartbeat frequency information.
[0012] Optionally, the step of performing channel health determination processing based on the output status information and the heartbeat status information to obtain channel abnormality information corresponding to each safe output channel includes: determining that the channel abnormality information corresponding to the safe output channel is abnormal when the output status information of any safe output channel indicates that the safe output channel is in an abnormal output state; determining that the channel abnormality information corresponding to the safe output channel is abnormal when the heartbeat status information of any safe output channel indicates that the safe output channel does not meet the preset heartbeat condition; and determining that the channel abnormality information corresponding to the safe output channel is normal when the output status information indicates that the safe output channel is not in an abnormal output state and the heartbeat status information indicates that the safe output channel meets the preset heartbeat condition.
[0013] Optionally, the step of performing cross-validation processing based on the intrusion determination information and the channel anomaly information to obtain the danger determination results corresponding to at least two safe output channels includes: when the intrusion determination information indicates that the conditions for human intrusion are met, determining that the danger determination results corresponding to the at least two safe output channels all indicate danger; when the channel anomaly information corresponding to any safe output channel indicates anomaly, determining that the danger determination result corresponding to that safe output channel indicates danger; when the intrusion determination information does not indicate that the conditions for human intrusion are met, and the channel anomaly information corresponding to the at least two safe output channels all indicates normal, determining that the danger determination results corresponding to the at least two safe output channels all indicate non-danger.
[0014] Optionally, controlling at least one of the security output channels to output a shutdown signal based on the security control signal includes: setting the security control signal to a shutdown hold state when the danger determination result indicates danger; controlling at least one security output channel to continuously output a shutdown signal when the security control signal is in the shutdown hold state; and releasing the shutdown hold state when the intrusion determination information indicates that the conditions for human intrusion are not met in multiple consecutive detection cycles, and the channel abnormality information corresponding to all security output channels indicates normality.
[0015] A safety shutdown device includes: an acquisition module for acquiring detection data of a target monitoring area and performing target identification processing based on the detection data to obtain a target object identification result, the identification result including target object category information and confidence information; an intrusion determination module for performing intrusion determination processing based on the category information and the confidence information to obtain intrusion determination information; a channel determination module for acquiring output status information and heartbeat status information of at least two safety output channels and performing channel health determination processing based on the output status information and the heartbeat status information to obtain channel abnormality information corresponding to each safety output channel; a cross-validation module for performing cross-validation processing based on the intrusion determination information and the channel abnormality information to obtain danger determination results corresponding to at least two safety output channels; and a safety shutdown module for generating a safety control signal based on the danger determination results and controlling at least one of the safety output channels to output a shutdown signal based on the safety control signal to trigger a safety shutdown.
[0016] A computer device includes a memory, a processor, and computer-readable instructions stored in the memory and executable on the processor, wherein the processor implements the above-described safe shutdown method when executing the computer-readable instructions.
[0017] A readable storage medium having computer-readable instructions stored thereon, which, when executed by a processor, implement the above-described safe shutdown method.
[0018] The aforementioned safety shutdown method, apparatus, computer equipment, and storage medium acquire detection data of the target monitoring area and perform target identification processing based on the detection data to obtain the target object identification result, the identification result including the target object's category information and confidence level information; perform intrusion determination processing based on the category information and the confidence level information to obtain intrusion determination information; acquire output status information and heartbeat status information of at least two security output channels, and perform channel health determination processing based on the output status information and the heartbeat status information to obtain channel abnormality information corresponding to each security output channel; perform cross-validation processing based on the intrusion determination information and the channel abnormality information to obtain danger determination results corresponding to at least two security output channels; generate a safety control signal based on the danger determination results, and control at least one of the security output channels to output a shutdown signal based on the safety control signal to trigger a safety shutdown. By cross-validating the intrusion determination information obtained from target recognition with the operational status of at least two security output channels, reliable security decisions can still be made based on multi-source criteria even in the event of transient interference, fluctuations in recognition results, or single-point anomalies in the visual detection link. This avoids false or missed shutdowns caused by anomalies in a single detection link. Simultaneously, by comprehensively judging the output status and heartbeat status of the security output channels and triggering a security shutdown when a danger determination is established, the stability, consistency, and overall system security reliability of the security shutdown control can be improved while ensuring real-time response. This makes it suitable for security protection scenarios in complex industrial environments. Attached Figure Description
[0019] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0020] Figure 1 is a flowchart illustrating a safe shutdown method according to an embodiment of the present invention; Figure 2 is a flowchart illustrating a second safe shutdown method according to an embodiment of the present invention; Figure 3 is a flowchart illustrating a third safe shutdown method according to an embodiment of the present invention; Figure 4 is a structural schematic diagram of a safe shutdown device according to an embodiment of the present invention; Figure 5 is a schematic diagram of a computer device according to an embodiment of the present invention. Detailed Implementation
[0021] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0022] In one embodiment, as shown in FIG1, a safe shutdown method is provided, including the following steps: 101. Acquire detection data of the target monitoring area, and perform target recognition processing based on the detection data to obtain the recognition result of the target object.
[0023] In this embodiment of the invention, acquiring detection data of the target monitoring area refers to continuously sensing the workspace with potential safety risks to obtain information reflecting the state of the target within that space. This safe shutdown method can be applied to automated production lines, robot work areas, the vicinity of stamping equipment, or other industrial scenarios requiring protection against accidental personnel intrusion. The target monitoring area is typically pre-defined based on the equipment's operating range and safety protection requirements, used to define the spatial range requiring focused monitoring. This area can be a fixed area or dynamically adjusted as the equipment's status changes.
[0024] Detection data reflects the actual situation within the target monitoring area and can include image data, depth data, point cloud data, or ranging information collected by visual sensors, 3D sensors, or TOF cameras (also known as time-of-flight cameras or stereo security sensors). Analyzing this type of detection data can determine whether a target object exists within the monitoring area. Target recognition processing based on detection data involves parsing and reasoning about the collected data to identify the existence and attributes of the target object. This process can be achieved through model reasoning, feature matching, or classification, thereby outputting the target object's identification result.
[0025] The target object primarily represents an entity that enters the target monitoring area and may pose a security risk, such as a person. The identification result describes the identification status of the target object and includes its category information and confidence level. Category information characterizes the type of target object, distinguishing between human and non-human targets; confidence level information reflects the reliability of the current identification result, quantifying the target identification process's confidence in the judgment outcome. By simultaneously acquiring category and confidence level information, a more stable basis can be provided for subsequent security judgments when detection data is affected by changes in lighting, occlusion interference, or transient anomalies.
[0026] In one possible implementation, target recognition processing can analyze the same detection data based on different recognition models and output corresponding category information and confidence information respectively. In subsequent processing, the reliability of target recognition in complex industrial environments can be improved by comprehensively judging the multi-path recognition results.
[0027] 102. Intrusion determination is performed based on category information and confidence information to obtain intrusion determination information.
[0028] In this embodiment of the invention, after obtaining the identification result of the target object, it is further determined whether there is an intrusion situation within the target monitoring area that requires triggering security protection. The intrusion determination process is not based solely on whether the target is identified as a person, but comprehensively considers the target object's category information and corresponding confidence information to avoid making direct security decisions when the identification result is unstable or lacks credibility. In this way, security can be guaranteed while reducing misjudgments caused by identification fluctuations.
[0029] Intrusion determination information is used to characterize whether the conditions for human intrusion are met within the current detection period. When the category information indicates that the target object is a person, and the corresponding confidence information reaches a preset confidence level, it can be considered that there is a risk of human intrusion within the target monitoring area, thus generating intrusion determination information characterizing the intrusion as established. Conversely, when the category information does not indicate that the target object is a person, or the confidence information is lower than the preset confidence level, it can be considered that the current identification result is insufficient to support the human intrusion judgment, and the intrusion determination information is correspondingly characterized as not meeting the conditions for human intrusion.
[0030] By incorporating confidence information into the intrusion detection process, fluctuations in recognition results caused by changes in lighting, electromagnetic interference, or short-term occlusion in industrial environments can be effectively addressed. For example, even if the model identifies a person or group with incomplete target outlines or low confidence, it can avoid directly triggering an intrusion detection process, thereby reducing the probability of erroneous system shutdown.
[0031] In one possible implementation, when there are multiple target recognition results, intrusion determination can be made based on the category information and confidence information corresponding to each recognition result. As long as any intrusion determination result indicates that the human intrusion condition is met, it can be considered that there is a risk of human intrusion within the current detection period, thereby improving the sensitivity to real intrusion behavior and the reliability of security protection.
[0032] 103. Obtain the output status information and heartbeat status information of at least two safe output channels, and perform channel health judgment processing based on the output status information and heartbeat status information to obtain the channel abnormal information corresponding to each safe output channel.
[0033] In this embodiment of the invention, the safety output channel is used to output a shutdown control signal to an external device. It is typically configured in a dual-channel or multi-channel configuration to meet the redundancy and fail-safe requirements in industrial safety protection. By acquiring the output status information of each safety output channel, it is possible to reflect whether the corresponding channel is in the expected on or off state. The aforementioned safety output channel can be implemented using an OSSD (Safety Signal Switching Device). An OSSD is a commonly used safety output interface in industrial safety protection. It can provide safety enable or safety disable signals to an external controller or actuator in a dual-channel output manner. Furthermore, the periodic heartbeat variation facilitates monitoring for output jamming, short circuits, or failures, thereby meeting the redundancy and fail-safe requirements of TOF cameras.
[0034] Heartbeat status information reflects the dynamic operation of the safety output channel, typically manifested as a periodically changing signal indicating whether the channel is continuously functioning normally. By monitoring the heartbeat signal, it's possible to determine if the safety output channel is stuck, malfunctioning, or experiencing abnormal stagnation, thus overcoming the difficulty of timely detection of channel faults by relying solely on static output status information. Output status information and heartbeat status information reflect the operational status of the safety output channel from different dimensions, complementing each other.
[0035] Channel health assessment based on output status and heartbeat status information involves comprehensively analyzing the static output status and dynamic heartbeat status of each safety output channel to determine if any abnormalities exist. When the output status information indicates that the channel is not outputting as expected, or the heartbeat status information indicates that the channel is not meeting normal heartbeat conditions, an abnormality can be determined for that safety output channel, and corresponding channel abnormality information will be generated. Conversely, when both the output status and heartbeat status information are within the normal range, the corresponding safety output channel can be determined to be in a healthy state.
[0036] By introducing channel health assessment processing, the risk of failure in the security output channel itself can be detected in advance before personnel intrusion occurs or the visual detection link malfunctions. This avoids the inability to effectively output a shutdown signal due to channel abnormalities when a safety shutdown needs to be triggered, thereby improving the overall reliability of security protection.
[0037] In one possible implementation, the heartbeat status information can be obtained by statistically analyzing the signal changes of the safety output channel within a preset time window, and then combined with the output status information for joint determination, so as to adapt to the requirements of the safety output channel's operational stability in different industrial environments.
[0038] 104. Based on the intrusion determination information and the channel anomaly information, perform cross-validation to obtain the danger determination results corresponding to at least two secure output channels.
[0039] In this embodiment of the invention, intrusion determination information reflects whether there is a risk of personnel entering the target monitoring area, and channel anomaly information reflects whether the output channel used to perform security control is in a reliable working state. By cross-validating the two types of information, security decisions can be avoided by relying on a single criterion.
[0040] In cross-validation, when the intrusion determination information indicates that the conditions for human intrusion are met, even if the security output channel itself does not detect any anomalies, it can be considered that there is a dangerous state that requires triggering security protection, thereby generating a danger determination result characterizing the danger. This method ensures that the security shutdown logic has sufficient sensitivity when real personnel enter the dangerous area, avoiding ignoring intrusion risks due to a normal channel status.
[0041] On the other hand, when channel anomaly information indicates an abnormality in any security output channel, even if the intrusion determination information does not indicate personnel intrusion, it can be considered that the current security protection link has a potential failure risk, thereby generating a corresponding danger determination result. By incorporating channel anomalies into the danger determination, security protection can be triggered in advance when security output capabilities are impaired, avoiding the inability to reliably execute shutdown control when subsequent shutdown is required.
[0042] When the intrusion detection information indicates that the conditions for personnel intrusion are not met, and the channel anomaly information corresponding to at least two security output channels indicates that they are in a normal state, it can be considered that there is no dangerous situation that requires triggering a safety shutdown, and the danger detection result is correspondingly characterized as a non-dangerous state. Through the above cross-validation method, the collaborative judgment of personnel intrusion risk and the reliability of security output channels can be achieved in complex industrial environments, improving the consistency and reliability of security decisions.
[0043] In one possible implementation, the hazard determination results can be generated separately for each safety output channel, providing a more refined basis for subsequent safety control to adapt to the application needs of different devices or safety strategies.
[0044] 105. Generate a safety control signal based on the hazard determination result, and control at least one safety output channel to output a shutdown signal based on the safety control signal to trigger a safety shutdown.
[0045] In this embodiment of the invention, the safety control signal is used to explicitly indicate the need to enter a safety protection state and serves as the direct basis for subsequent safety shutdown actions. In this way, abstract hazard assessment results can be transformed into control signal forms that can be recognized and responded to by the execution unit.
[0046] After generating the safety control signal, at least one safety output channel is controlled to output a shutdown signal to trigger a safety shutdown.
[0047] Each safety output channel can correspond to the same area in the target monitoring area, or the target monitoring area can be divided into multiple sub-areas, with each safety output channel corresponding to one sub-area. If any safety output channel outputs a shutdown signal, all external devices corresponding to the sub-areas will trigger a safety shutdown.
[0048] Alternatively, multiple safety output channels can simultaneously output shutdown signals, ensuring that external devices stop operating promptly upon detecting a dangerous condition, thus meeting the redundancy and fail-safe requirements in industrial safety protection. Even if one safety output channel has a potential anomaly, the remaining channels can still achieve safety control of the equipment by shutting down their outputs, preventing single-point failures from causing safety function malfunctions. Specific configurations can be made according to actual needs.
[0049] By immediately triggering the shutdown of the safety output channel upon confirmation of a hazard, the response path from risk identification to equipment shutdown can be shortened, improving the timeliness of safe shutdown. Simultaneously, since the generation of safety control signals is based on the cross-validation results of intrusion detection information and channel anomaly information, unnecessary shutdown actions caused by transient identification fluctuations or single channel anomalies can be avoided, thus achieving a balance between safety and production continuity.
[0050] In one possible implementation, the safety control signal can be maintained after entering the shutdown state until no risk of personnel intrusion is detected in multiple consecutive detection cycles and all safety output channels return to normal, at which point the shutdown control is released to prevent frequent switching of the safety shutdown state in complex interference environments.
[0051] In this embodiment of the invention, detection data of the target monitoring area is acquired, and target recognition processing is performed based on the detection data to obtain the target object recognition result, which includes the target object's category information and confidence information. Intrusion determination processing is performed based on the category information and the confidence information to obtain intrusion determination information. Output status information and heartbeat status information of at least two security output channels are acquired, and channel health determination processing is performed based on the output status information and the heartbeat status information to obtain channel anomaly information corresponding to each security output channel. Cross-validation processing is performed based on the intrusion determination information and the channel anomaly information to obtain danger determination results corresponding to at least two security output channels. A security control signal is generated based on the danger determination results, and the security control signal controls at least one of the security output channels to output a shutdown signal to trigger a security shutdown. By cross-validating the intrusion determination information obtained from target recognition with the operating status of at least two security output channels, reliable security decisions can still be made based on multi-source criteria even in the event of transient interference, fluctuations in recognition results, or single-point anomalies in the visual detection link, thereby avoiding false shutdowns or missed shutdowns caused by a single detection link anomaly. Meanwhile, by comprehensively judging the output status and heartbeat status of the safety output channel, and triggering a safety shutdown when the danger judgment is established, the stability, consistency and overall safety and reliability of the safety shutdown control can be improved while ensuring real-time response. It is suitable for safety protection scenarios in complex industrial environments.
[0052] Optionally, the recognition result includes a first recognition result and a second recognition result. In the step of performing target recognition processing based on detection data to obtain the recognition result of the target object, the detection data can also be input into a preset first detection model to obtain a first detection result; the detection data can be input into a preset second detection model to obtain a second detection result; the first detection result can be input into a preset first classification network to obtain a first recognition result; and the second detection result can be input into a preset second classification network to obtain a second recognition result.
[0053] In this embodiment of the invention, the same detection data can be input into a first detection model and a second detection model respectively. The first detection model outputs a first detection result, and the second detection model outputs a second detection result. The two detection models can adopt different network structures, feature extraction methods, or training data configurations, so that the two models exhibit different error characteristics when facing disturbances such as strong light, occlusion, electromagnetic interference, or data loss, thereby reducing the probability that the same interference factor will affect the two recognition results simultaneously.
[0054] After obtaining the two detection results, the first detection result is further input into the first classification network to obtain the first recognition result, and the second detection result is further input into the second classification network to obtain the second recognition result. The classification network is used to perform semantic parsing on the detection results, outputting the category information and confidence information of the target object, so that each recognition result can independently characterize whether the target object is a person and the credibility of the judgment. By adopting a combination of a two-way detection model and a two-way classification network, a dual-link redundant structure from detection to classification can be formed. This allows for triggering an intrusion judgment in subsequent intrusion judgment processing based on whether either recognition result meets the conditions, and also allows for consistency constraints on the two recognition results when needed to improve the stability of the judgment result.
[0055] For example, within a certain detection cycle, if the first identification result loses confidence due to glare from lighting and cannot reliably represent a person's intrusion, the second identification result may still maintain high confidence and correctly identify the person. This allows subsequent intrusion detection to trigger security protection in a timely manner, avoiding the risk of missed detections due to the instability of a single path identification. Conversely, if there is no person intrusion but a short-term occlusion causes a false detection on one path, the other identification link can provide complementary information, providing a more reliable basis for subsequent cross-validation and security decisions.
[0056] In one possible implementation, the two detection models can be optimized for different distance ranges, different human postures, or different occlusion conditions. The classification network can also adopt different threshold strategies or confidence calibration methods to adapt to the requirements of personnel intrusion detection accuracy and real-time performance in different industrial scenarios.
[0057] Optionally, in the step of performing intrusion determination processing based on category information and confidence information to obtain intrusion determination information, it can be further determined that the intrusion determination information representation meets the human intrusion condition when the first category information in the first identification result represents the target object as a person and the first confidence information is not less than a preset confidence threshold; when the second category information in the second identification result represents the target object as a person and the second confidence information is not less than a preset confidence threshold, it can be determined that the intrusion determination information representation meets the human intrusion condition; when the first category information in the first identification result does not represent the target object as a person, and / or the first confidence information is less than a preset confidence threshold, and the second category information in the second identification result does not represent the target object as a person, and / or the second confidence information is less than a preset confidence threshold, it can be determined that the intrusion determination information representation does not meet the human intrusion condition.
[0058] In this embodiment of the invention, when the first category information given by the first identification result indicates that the target object is a person, and the first confidence information reaches a preset confidence threshold, it can be directly determined that the person intrusion condition is met, and the intrusion judgment information indicates that the intrusion is established. Similarly, when the second category information given by the second identification result indicates that the target object is a person, and the second confidence information reaches a preset confidence threshold, it can also be determined that the person intrusion condition is met, and the intrusion judgment information indicating that the intrusion is established is output. By triggering the intrusion establishment by having any identification result meet the intrusion criterion, the risk of missed detection due to decreased confidence caused by frame loss in a single path, strong light glare, or obstruction can be reduced, which is more in line with the requirements of conservative judgment in security protection.
[0059] When neither of the two recognition results is sufficient to support a person intrusion judgment, the intrusion judgment information representation does not meet the person intrusion condition. The situation where the two recognition results are insufficient to support an intrusion judgment can manifest in several combinations, such as the first category information not representing a person or the first confidence information being below a preset threshold, while the second category information also not representing a person or the second confidence information is below a preset threshold. This judgment method considers both category information and confidence information simultaneously, which can avoid misjudgment when the confidence is low due to relying solely on the person category, and also avoid judgment bias caused by ignoring category semantics based solely on the confidence value.
[0060] For example, when reflective objects or strong direct sunlight are present in the monitored area, one identification link might briefly misidentify a non-human target as a human. However, if the confidence level is insufficient to reach a preset threshold, the intrusion determination will not be directly triggered. If another identification link simultaneously fails to consistently output a human category or its confidence level is also low, the intrusion determination information will remain that the human intrusion condition is not met, thus reducing the probability of false shutdown. Conversely, when a person actually enters the dangerous area and one of the identification links consistently outputs a human category with sufficient confidence, the intrusion can be triggered promptly, avoiding missed shutdowns.
[0061] In one possible implementation, the pre-set confidence threshold can be configured based on on-site lighting conditions, installation angle, or work cycle, or it can be determined during the equipment commissioning phase through statistical analysis of normal and intrusion samples, so as to balance security sensitivity and false alarm suppression capability.
[0062] Optionally, in the step of acquiring the heartbeat status information of at least two safety output channels, the heartbeat signal output by each safety output channel within a preset detection time window can also be acquired; based on the heartbeat signal, the heartbeat count information and / or heartbeat frequency information corresponding to each safety output channel can be determined; and based on the heartbeat count information and / or heartbeat frequency information, the corresponding heartbeat status information can be generated.
[0063] In this embodiment of the invention, the heartbeat signal is used to characterize the periodic changes (e.g., square wave, sine wave, etc.) of the safety output channel during operation. This signal can be used to determine whether the channel is continuously in a controllable and predictable operating state. In implementation, the heartbeat signals output by each safety output channel can be collected within a preset detection time window, and the number of changes in the heartbeat signals within this time window can be counted to obtain the corresponding heartbeat count information. The heartbeat count information reflects whether the heartbeats occur as expected within the time window, and is suitable for detecting problems such as missing, stalled, or abnormal heartbeat changes.
[0064] In addition to counting statistics, heartbeat frequency information can be further determined based on the periodic changes in the heartbeat signal. Heartbeat frequency information characterizes the rate of change of the heartbeat signal per unit time. By comparing it with preset frequency conditions, it can be determined whether the heartbeat is within a reasonable range. For example, when the heartbeat frequency is significantly lower than expected, it may indicate channel jamming, output limitation, or monitoring link abnormality; when the heartbeat frequency is significantly higher than expected, it may indicate jitter interference, abnormal oscillation, or sampling misjudgment. Based on heartbeat count information and heartbeat frequency information, heartbeat status information can be generated to characterize whether the heartbeat of the corresponding safe output channel is normal within the current detection time window.
[0065] For example, the preset detection time window can be set to cover a range of several heartbeat cycles. If the count of heartbeats reaches the expected number and the heartbeat frequency falls within the preset range within the time window, the heartbeat status information is characterized as normal; if the heartbeat count is insufficient or the heartbeat frequency does not meet the preset conditions, the heartbeat status information is characterized as abnormal, thus providing a basis for subsequent channel health determination.
[0066] Understandably, in this field, a heartbeat signal can be understood as a periodic signal generated by a safety output channel during operation at a preset rhythm, used to characterize that the channel is continuously controllable, not jammed, and has dynamic response capabilities; this signal can manifest as a periodic level flip, a periodic pulse train, or complementary signals alternating at a fixed beat. Heartbeat count information can be understood as the number of valid heartbeat edges or pulses detected within a preset detection time window, used to reflect whether the heartbeat occurs as expected and whether there are any missing, stalled, or abnormally sparse heartbeats; heartbeat frequency information can be understood as the rate of change of the heartbeat signal per unit time or the reciprocal of the corresponding period, used to reflect whether the heartbeat beat is within a reasonable range and whether there are any abnormally slow, fast, or jittery distortions. Heartbeat status can be understood as a state-based criterion obtained based on heartbeat count information and / or heartbeat frequency information, used to characterize whether the channel heartbeat meets preset conditions, typically divided into normal and abnormal states. Abnormal states can further include types such as missing heartbeats, heartbeat frequency deviations, or unstable heartbeats.
[0067] In one possible implementation, the length of the preset detection time window can be configured according to the response time requirements of the external device, or it can be adaptively adjusted according to the nominal period of the heartbeat signal, so as to balance the fault detection speed and the ability to suppress false judgments under different operating cycles.
[0068] Optionally, in the step of performing channel health determination processing based on output status information and heartbeat status information to obtain channel abnormality information corresponding to each safe output channel, it can also be further determined that the channel abnormality information corresponding to the safe output channel is abnormal when the output status information of any safe output channel indicates that the safe output channel is in an abnormal output state; when the heartbeat status information of any safe output channel indicates that the safe output channel does not meet the preset heartbeat conditions, it can be determined that the channel abnormality information corresponding to the safe output channel is abnormal; when the output status information indicates that the safe output channel is not in an abnormal output state and the heartbeat status information indicates that the safe output channel meets the preset heartbeat conditions, it can be determined that the channel abnormality information corresponding to the safe output channel is normal.
[0069] In this embodiment of the invention, channel health determination can comprehensively assess the operational reliability of a safe output channel by simultaneously utilizing output status information and heartbeat status information, thereby generating channel anomaly information. Output status information reflects whether the channel's output at the current moment or within the current detection cycle meets expectations, such as whether it can enter the on or off state as required by control. Heartbeat status information reflects whether the channel maintains periodic changes over time, thereby indicating whether the channel is at risk of jamming, stagnation, or loss of dynamic response. These two types of information provide criteria from the perspectives of static output consistency and dynamic operational continuity, respectively; their combined use can improve the coverage of channel faults.
[0070] When the output status information of any safety output channel indicates that the channel is in an abnormal output state, it can be directly determined that the channel is abnormal, and the corresponding channel abnormality information is set to an abnormal state. An abnormal output state can be understood as a situation where the channel output is inconsistent with the expected state, the output cannot be switched, the output remains at an unreasonable level for a long time, or the output feedback shows obvious abnormalities. By prioritizing the response to abnormal output states, failure risks directly related to shutdown execution can be captured in a timely manner, avoiding the channel's inability to operate effectively when shutdown is required.
[0071] When the heartbeat status information of any safety output channel indicates that the channel does not meet the preset heartbeat conditions, it can also be determined that the channel is abnormal, and the corresponding channel abnormality information will be set to an abnormal state. Heartbeat condition failure usually refers to situations such as missing heartbeats, heartbeat frequency deviating from the preset range, or unstable heartbeat waveforms. These types of abnormalities often reflect potential channel jamming, drive failure, or monitoring link anomalies. Even if the output status appears normal for a short period, unpredictable failures may occur in subsequent control.
[0072] When the output status information representing the channel is not in an abnormal output state, and the heartbeat status information representing the channel meets the preset heartbeat conditions, the corresponding safe output channel can be determined to be in a healthy state, and the abnormal channel information can be set to a normal state. By simultaneously satisfying both static output consistency and dynamic heartbeat continuity conditions, channel health determination can more comprehensively confirm that the channel has reliable shutdown execution capabilities, thereby providing a reliable basis for subsequent hazard assessment and safety control.
[0073] For example, when external electromagnetic interference causes momentary jitter in the feedback sampling, the output status information may show a short-term abnormal indication. The channel health judgment can mark the channel as abnormal, thereby prompting subsequent safety decisions to adopt a conservative strategy. When the channel drive circuit ages and the heartbeat frequency gradually deviates from the preset range, even if the output status can still be maintained, the heartbeat status information can still reflect potential risks in advance, so that the abnormal channel information can be promptly converted into an abnormal state.
[0074] In one possible implementation, the channel anomaly information can not only distinguish between normal and abnormal, but also carry an anomaly source identifier to distinguish between output status anomalies and heartbeat anomalies, so as to provide a clearer reference basis in subsequent maintenance diagnosis or fault location.
[0075] Optionally, in the step of performing cross-validation processing based on intrusion determination information and channel anomaly information to obtain danger determination results corresponding to at least two safe output channels, it can be further determined that when the intrusion determination information characterizes the conditions for human intrusion, the danger determination results corresponding to at least two safe output channels all characterize danger; when the channel anomaly information corresponding to any safe output channel characterizes anomaly, the danger determination result corresponding to that safe output channel is determined to characterize danger; when the intrusion determination information characterizes the conditions for human intrusion, and the channel anomaly information corresponding to at least two safe output channels all characterizes normal, the danger determination results corresponding to at least two safe output channels all characterize non-danger.
[0076] In this embodiment of the invention, cross-validation processing can jointly analyze intrusion determination information and channel anomaly information to form a hazard assessment result for the secure output channel, thereby integrating personnel intrusion risk and shutdown execution link reliability into security decision-making. Intrusion determination information reflects the risk of personnel entry into the target monitoring area, while channel anomaly information reflects whether the secure output channel currently possesses reliable shutdown execution capabilities. Cross-validation, by cross-verifying the two types of information, ensures that hazard assessment no longer relies on a single source, thus improving the stability and consistency of secure shutdown decisions in complex interference environments.
[0077] When the intrusion determination information meets the conditions for human intrusion, the danger determination results corresponding to at least two safe output channels can be directly determined as dangerous. This process reflects the conservative principle of security protection, that is, once human intrusion is established, the dangerous state needs to cover all output channels, so as to ensure that external devices can be shut down in time and avoid incomplete shutdown or inconsistent response due to a certain channel not being triggered.
[0078] When any channel anomaly information corresponding to a security output channel indicates an anomaly, the hazard assessment result corresponding to that channel can be determined as a dangerous state. By mapping channel anomalies to dangerous states, potential failure risks in the shutdown execution link can be identified in advance, even if no personnel intrusion has been detected in the target monitoring area. This allows the security control logic to remain conservative and avoids unreliable shutdown due to channel anomalies when a real intrusion occurs later.
[0079] When the intrusion determination information does not meet the conditions for personnel intrusion, and the channel anomaly information corresponding to at least two security output channels is normal, the danger determination results corresponding to at least two security output channels can be determined as non-dangerous. This process can maintain normal operation when no personnel have intruded and the security output links are healthy, reducing unnecessary downtime and providing a stable state foundation for subsequent security control.
[0080] For example, when personnel actually enter a dangerous area, even if a certain channel experiences a short-term abnormality in status feedback due to external interference, the hazard assessment can still cover at least two channels to ensure that the shutdown action is executed reliably. When personnel have not intruded but a certain channel is missing a heartbeat, the hazard assessment can first mark the corresponding channel as dangerous, thereby indicating that there is a hidden danger in the execution link and prompting the safety control to enter a conservative state.
[0081] In one possible implementation, the hazard assessment results can be further used to generate differentiated diagnostic information, such as indicating whether the hazard originates from personnel intrusion or channel anomaly, so as to provide a clearer direction for on-site maintenance without affecting the safe shutdown strategy.
[0082] Optionally, in the step of generating a safety control signal based on the hazard determination result, when the hazard determination result indicates a hazard, the safety control signal can be set to a shutdown holding state; when the safety control signal is in the shutdown holding state, at least one safety output channel is controlled to continuously output a shutdown signal; when the intrusion determination information indicates that the conditions for human intrusion are not met in multiple consecutive detection cycles, and the channel abnormality information corresponding to all safety output channels indicates that they are normal, the shutdown holding state is released.
[0083] In this embodiment of the invention, the safety control signal can employ a shutdown-hold mechanism to improve the stability of safe shutdown under complex interference environments and prevent repeated start-ups and shutdowns of external devices caused by frequent switching of dangerous states within a short period. When the danger assessment result indicates danger, the safety control signal can be set to a shutdown-hold state, changing the safety control from an instantaneous trigger to a maintainable safety lock state. The shutdown-hold state is used to indicate that the safe shutdown has taken effect and needs to be continuously maintained, thereby forming a clear and stable shutdown command for external devices.
[0084] When the safety control signal is in the off-hold state, at least one safety output channel can be controlled to continuously output the off signal, keeping the external device in a safe shutdown state until the release condition is met. Continuous output avoids the instantaneous cancellation of the off signal due to short-term jitter in the detection link, sampling errors, or external interference, thus preventing the external device from mistakenly resuming operation before the danger has truly passed.
[0085] When releasing the shutdown holding state, a security confirmation condition based on continuous detection cycles can be introduced to ensure sufficient reliability in risk clearance. The shutdown holding state is only released if, within multiple consecutive detection cycles, the intrusion determination information consistently indicates that the intrusion conditions are not met, and all channel anomaly information corresponding to the secure output channels indicates normal operation. By simultaneously constraining the release condition to both the disappearance of the intrusion risk and the restoration of the output channel's health, the shutdown can be avoided based solely on the results of a single detection cycle, thereby reducing the risk of false recovery caused by frame drops, confidence fluctuations, or short-term channel state anomalies.
[0086] For example, if strong light causes a sudden drop in the confidence level of person recognition within a detection cycle, the intrusion determination may temporarily change to not meeting the intrusion conditions. Without a shutdown hold mechanism, external devices may experience a brief resumption of operation. Adopting a shutdown hold mechanism, requiring the release conditions to be met for multiple consecutive detection cycles before resuming operation, can significantly reduce the impact of such transient fluctuations on security control. Similarly, if a security output channel's heartbeat signal is briefly lost and then returns to normal, immediately resuming the shutdown may still pose a potential instability risk. Continuous periodic confirmation can improve the reliability of the release action.
[0087] In one possible implementation, the number of continuous detection cycles can be configured based on the on-site safety level, the inertial characteristics of external equipment, or the response time requirements. Alternatively, it can be determined after verification during the equipment commissioning phase in conjunction with typical interference conditions, in order to achieve a more reasonable balance between safety and production continuity.
[0088] As shown in Figure 2, this embodiment of the invention also provides a flowchart of a second safe shutdown method. Figure 2 shows two parallel recognition links and the final safe output link from left to right. The "3D data acquisition" on the left indicates that the front-end sensor collects spatial information in each detection cycle, outputting raw detection data such as depth, point cloud, or ranging, which serves as a unified input source for subsequent recognition. The "Tianying Quantization Model" and "Tiantu Quantization Model" represent two independent target detection models. Quantization is used to reduce computational load and improve inference speed, making the model more suitable for real-time operation at the edge.
[0089] The following "custom operators" represent dedicated data processing units inserted before or during model inference. These units perform preprocessing or feature transformations required for engineering purposes, such as noise suppression, outlier removal, distortion correction, region filtering, or tensor format conversion, making subsequent inference inputs more stable and outputs more usable. "Tianying Model Inference Acceleration BPU0" and "Tiantu Model Inference Acceleration BPU1" indicate that the two links are executed by different inference acceleration units. BPU0 and BPU1 operate independently, reducing the impact of single-point failures or interference on overall recognition and facilitating parallel processing to improve throughput and real-time performance.
[0090] "Detection Results from the Tianying Model" and "Detection Results from the Tiantu Model" represent the candidate target information output by the two detection models, typically including target location or region, target bounding box set, key structural information, etc., and are intermediate results of the detection stage. The "Classification Network" following each link represents semantic parsing and fine-classification of the detection stage results, outputting the target category and corresponding confidence score, used to determine whether the target belongs to a person and the degree of credibility. "Detection and Classification Results" represent the comprehensive recognition result after fusing the detection output and classification output, facilitating direct use by subsequent security logic, such as simultaneously carrying category, confidence score, and spatial location information.
[0091] The "detection and classification results" from the two links are merged into "security detection cross-validation." This module represents the merging and consistency constraints of the results from the two independent identification links. Its core function is to use the credibility of human intrusion determination and identification as security criterion input, enabling the risk of human intrusion to be transmitted to the security output side in a more robust manner. On the security output side, "OSSD1.A output" and "OSSD1.B output" represent the final control outputs of the two security output channels, used to perform shutdown or enable actions on external devices. The dual-channel design is used to meet the redundancy and fail-safe requirements in industrial security. The "cross-checking" between the two outputs represents the mutual monitoring and consistency constraints between the channels, used to detect abnormalities, jams, or heartbeat failures in any output, and to maintain or trigger shutdown strategies when an abnormality is detected, thereby preventing the failure of a single channel from causing the security function to fail.
[0092] The lines and arrows in the diagram indicate the direction of data and criterion transmission: the collected data enters two parallel model links, the detection results are obtained through custom operators and inference acceleration, the classification network forms the recognition results that can be used for security determination, and finally enters the cross-validation module to generate a security output. The reliable execution of the shutdown action is ensured through dual-channel output and channel mutual verification.
[0093] As shown in Figure 3, this embodiment of the invention also provides a flowchart of a third safe shutdown method. As can be seen from Figure 3, Figure 3 shows the judgment and output logic of dual-channel safe output under cross-validation control. The upper part forms a judgment closed loop around the Eagle model corresponding to channel A, and the lower part forms a symmetrical judgment closed loop around the Rabbit model corresponding to channel B. The two parts have the same structure, only the channel roles are interchanged, which is used to realize the safety control of mutual monitoring and mutual backup between the two channels.
[0094] In the decision chain of Channel A, the "Skyhawk Classification Network" on the left outputs the "Target Category," used to determine whether the target is a person; the "Skyhawk Model" on the left outputs the "Target Score," used to characterize the confidence level of person recognition. The "Person" branch corresponds to the category judgment branch; when the target category meets the person condition, it proceeds to the next step of the logic. The "Greater than Threshold" branch corresponds to the score judgment branch; when the target score reaches a preset threshold, it proceeds to the next step of the logic. When the category meets the person condition and the score reaches the threshold, it enters the "Person Intrusion" stage, used to characterize the person intrusion condition being met, and this conclusion is sent to the shutdown control chain on the right.
[0095] In parallel with the character intrusion detection, the Channel A link also includes monitoring the operational status of Channel B. "OSSD_B Output OFF" determines whether Channel B is currently in a shutdown output state; "OSSD_B Output Heartbeat" determines whether Channel B's output maintains a preset heartbeat pattern. "OSSD_A Output ON" represents the allowed output state of Channel A before shutdown is triggered, and forms a cyclical check relationship with the heartbeat detection of Channel B, thus continuously monitoring whether Channel B's heartbeat is normal while Channel A maintains allowed output. When Channel B's output is detected to be in a shutdown state, or Channel B's heartbeat does not meet the preset conditions, the detection link will pass this abnormal state to the shutdown control path on the right, causing Channel A to enter a shutdown output state.
[0096] The "OSSD_A Output OFF" on the right indicates that channel A is driven to output a shutdown signal, used to trigger external devices to stop or enter a safe state. This shutdown output is triggered not only when a person intrusion is confirmed, but also when the other end channel is abnormal, thus making the security control conservative. The "Yes / No" branches that appear in multiple places in the diagram are used to express the path selection when the conditions are met and not met, making the decision link a combination of loop detection and immediate shutdown logic.
[0097] The lower part constructs the same logical structure centered on channel B. The "TianTu Classification Network," "TianTu Model," "Target Category," "Target Score," "Person," "Greater than Threshold," and "Person Intrusion" constitute the person intrusion judgment chain. When the judgment is successful, "OSSD_B Output OFF" is triggered. Simultaneously, "OSSD_A Output OFF" and "OSSD_A Output Heartbeat" constitute the monitoring of the operating status of channel A. While maintaining "OSSD_B Output ON," channel B continuously checks for anomalies in channel A. Once it detects that channel A is in a deactivated state or the heartbeat condition is not met, channel B is triggered to enter deactivated output mode.
[0098] Through a symmetrical, mutually monitoring structure, the dual channels can both jointly shut down based on intrusion detection, and can also promptly shut down the other channel if either channel experiences abnormal output or heartbeat anomalies, thereby improving the consistency and reliability of the safety shutdown action. In one possible implementation, the source of the target category determination can be replaced with any classifier capable of outputting the person category, the target score can be replaced with any scoring index capable of quantifying the recognition reliability, and the threshold can also be configured according to the installation distance, lighting conditions, or on-site false alarm tolerance.
[0099] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0100] In one embodiment, a safe shutdown device is provided, which corresponds one-to-one with the safe shutdown method in the above embodiments. As shown in FIG4, the safe shutdown device includes an acquisition module 401, an intrusion determination module 402, a channel determination module 403, a cross-validation module 404, and a safe shutdown module 405. The functional modules are described in detail below: Acquisition module 401 is used to acquire detection data of the target monitoring area and perform target recognition processing based on the detection data to obtain the target object recognition result, which includes the target object's category information and confidence information; Intrusion determination module 402 is used to perform intrusion determination processing based on the category information and the confidence information to obtain intrusion determination information; Channel determination module 403 is used to acquire the output status information and heartbeat status information of at least two secure output channels and perform channel health determination processing based on the output status information and the heartbeat status information to obtain channel abnormality information corresponding to each secure output channel; Cross-validation module 404 is used to perform cross-validation processing based on the intrusion determination information and the channel abnormality information to obtain the danger determination result corresponding to at least two secure output channels; Safety shutdown module 405 is used to generate a safety control signal based on the danger determination result and control at least one of the secure output channels to output a shutdown signal based on the safety control signal to trigger a safety shutdown.
[0101] Optionally, the acquisition module 401 is further configured to: input the detection data into a preset first detection model to obtain a first detection result; input the detection data into a preset second detection model to obtain a second detection result; input the first detection result into a preset first classification network to obtain a first recognition result; and input the second detection result into a preset second classification network to obtain a second recognition result.
[0102] Optionally, the intrusion determination module 402 is further configured to: determine that the intrusion determination information characterization meets the human intrusion condition when the first category information in the first identification result characterizes the target object as a person and the first confidence information is not less than a preset confidence threshold; determine that the intrusion determination information characterization meets the human intrusion condition when the second category information in the second identification result characterizes the target object as a person and the second confidence information is not less than a preset confidence threshold; and determine that the intrusion determination information characterization does not meet the human intrusion condition when the first category information in the first identification result does not characterize the target object as a person, and / or the first confidence information is less than the preset confidence threshold, and the second category information in the second identification result does not characterize the target object as a person, and / or the second confidence information is less than the preset confidence threshold.
[0103] Optionally, the channel determination module 403 is further configured to: acquire the heartbeat signal output by each of the safety output channels within a preset detection time window; determine the heartbeat count information and / or heartbeat frequency information corresponding to each of the safety output channels based on the heartbeat signal; and generate corresponding heartbeat status information based on the heartbeat count information and / or the heartbeat frequency information.
[0104] Optionally, the channel determination module 403 is further configured to: determine that the channel abnormality information representation of the safety output channel is abnormal when the output status information of any safety output channel indicates that the safety output channel is in an abnormal output state; determine that the channel abnormality information representation of the safety output channel is abnormal when the heartbeat status information of any safety output channel indicates that the safety output channel does not meet the preset heartbeat condition; and determine that the channel abnormality information representation of the safety output channel is normal when the output status information indicates that the safety output channel is not in an abnormal output state and the heartbeat status information indicates that the safety output channel meets the preset heartbeat condition.
[0105] Optionally, the cross-validation module 404 is further configured to: determine that the danger judgment results corresponding to the at least two security output channels all indicate danger when the intrusion judgment information characterizes the conditions for human intrusion; determine that the danger judgment result corresponding to the security output channel indicates danger when the channel abnormality information characterizes an abnormality for any security output channel; and determine that the danger judgment results corresponding to the at least two security output channels all indicate non-danger when the intrusion judgment information characterizes the conditions for human intrusion and the channel abnormality information corresponding to the at least two security output channels all indicate normality.
[0106] Optionally, the safety shutdown module 405 is further configured to: set the safety control signal to a shutdown hold state when the danger determination result indicates danger; control at least one safety output channel to continuously output a shutdown signal when the safety control signal is in the shutdown hold state; and release the shutdown hold state when the intrusion determination information indicates that the conditions for human intrusion are not met in multiple consecutive detection cycles, and the channel abnormality information corresponding to all safety output channels indicates that they are normal.
[0107] Each module in the aforementioned safety shutdown device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0108] In one embodiment, a computer device is provided, which may be a terminal device, and its internal structure diagram is shown in Figure 5. The computer device includes a processor, memory, and a network interface connected via a system bus. The processor of the computer device provides computing and control capabilities. The memory of the computer device includes a readable storage medium. The readable storage medium stores computer-readable instructions. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer-readable instructions are executed by the processor, a safe shutdown method is implemented. The readable storage medium provided in this embodiment includes both non-volatile readable storage media and volatile readable storage media.
[0109] In this application embodiment, a computer device is provided, including a memory, a processor, and computer-readable instructions stored in the memory and executable on the processor. When the processor executes the computer-readable instructions, it implements the steps of the safe shutdown method described above.
[0110] In one embodiment of the application, a readable storage medium is provided, which stores computer-readable instructions that, when executed by a processor, implement the steps of the safe shutdown method described above.
[0111] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by instructing related hardware with computer-readable instructions. These computer-readable instructions can be stored in a non-volatile readable storage medium or a volatile readable storage medium. When executed, these computer-readable instructions can include the processes of the embodiments of the methods described above. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0112] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0113] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. A safe shutdown method, characterized in that, The method includes: acquiring detection data of the target monitoring area, and performing target recognition processing based on the detection data to obtain the target object recognition result, wherein the recognition result includes the target object's category information and confidence information; performing intrusion judgment processing based on the category information and the confidence information to obtain intrusion judgment information; acquiring output status information and heartbeat status information of at least two security output channels, and performing channel health judgment processing based on the output status information and the heartbeat status information to obtain channel abnormality information corresponding to each security output channel; performing cross-validation processing based on the intrusion judgment information and the channel abnormality information to obtain danger judgment results corresponding to at least two security output channels; generating a security control signal based on the danger judgment results, and controlling at least one of the security output channels to output a shutdown signal based on the security control signal to trigger a security shutdown.
2. The safe shutdown method as described in claim 1, characterized in that, The recognition result includes a first recognition result and a second recognition result. The step of performing target recognition processing based on the detection data to obtain the recognition result of the target object includes: inputting the detection data into a preset first detection model to obtain a first detection result; inputting the detection data into a preset second detection model to obtain a second detection result; inputting the first detection result into a preset first classification network to obtain the first recognition result; and inputting the second detection result into a preset second classification network to obtain the second recognition result.
3. The safe shutdown method as described in claim 2, characterized in that, The intrusion determination processing based on the category information and the confidence information to obtain intrusion determination information includes: when the first category information in the first identification result indicates that the target object is a person, and the first confidence information is not less than a preset confidence threshold, determining that the intrusion determination information indicates that the target object meets the person intrusion condition; when the second category information in the second identification result indicates that the target object is a person, and the second confidence information is not less than the preset confidence threshold, determining that the intrusion determination information indicates that the target object meets the person intrusion condition; when the first category information in the first identification result does not indicate that the target object is a person, and / or the first confidence information is less than the preset confidence threshold, and the second category information in the second identification result does not indicate that the target object is a person, and / or the second confidence information is less than the preset confidence threshold, determining that the intrusion determination information does not meet the person intrusion condition.
4. The safe shutdown method as described in claim 1, characterized in that, The step of acquiring the heartbeat status information of at least two safety output channels includes: acquiring the heartbeat signal output by each of the safety output channels within a preset detection time window; determining the heartbeat count information and / or heartbeat frequency information corresponding to each of the safety output channels based on the heartbeat signal; and generating corresponding heartbeat status information based on the heartbeat count information and / or the heartbeat frequency information.
5. The safe shutdown method as described in claim 1, characterized in that, The process of performing channel health determination based on the output status information and the heartbeat status information to obtain channel abnormality information corresponding to each safe output channel includes: determining that the channel abnormality information corresponding to the safe output channel is abnormal when the output status information of any safe output channel indicates that the safe output channel is in an abnormal output state; determining that the channel abnormality information corresponding to the safe output channel is abnormal when the heartbeat status information of any safe output channel indicates that the safe output channel does not meet the preset heartbeat condition; and determining that the channel abnormality information corresponding to the safe output channel is normal when the output status information indicates that the safe output channel is not in an abnormal output state and the heartbeat status information indicates that the safe output channel meets the preset heartbeat condition.
6. The safe shutdown method as described in claim 1, characterized in that, The step of performing cross-validation processing based on the intrusion determination information and the channel anomaly information to obtain danger determination results corresponding to at least two safe output channels includes: when the intrusion determination information indicates that the conditions for human intrusion are met, determining that the danger determination results corresponding to the at least two safe output channels all indicate danger; when the channel anomaly information corresponding to any safe output channel indicates anomaly, determining that the danger determination result corresponding to that safe output channel indicates danger; and when the intrusion determination information does not indicate that the conditions for human intrusion are met, and the channel anomaly information corresponding to the at least two safe output channels all indicates normal, determining that the danger determination results corresponding to the at least two safe output channels all indicate non-danger.
7. The safe shutdown method as described in claim 1, characterized in that, The step of controlling at least one of the security output channels to output a shutdown signal based on the security control signal includes: setting the security control signal to a shutdown hold state when the danger determination result indicates danger; controlling at least one security output channel to continuously output a shutdown signal when the security control signal is in the shutdown hold state; and releasing the shutdown hold state when the intrusion determination information indicates that the conditions for human intrusion are not met and the channel abnormality information corresponding to all security output channels indicates normal conditions in multiple consecutive detection cycles.
8. A safety shutdown device, characterized in that, The device includes: an acquisition module for acquiring detection data of a target monitoring area and performing target recognition processing based on the detection data to obtain a target object recognition result, the recognition result including target object category information and confidence information; an intrusion determination module for performing intrusion determination processing based on the category information and the confidence information to obtain intrusion determination information; a channel determination module for acquiring output status information and heartbeat status information of at least two secure output channels and performing channel health determination processing based on the output status information and the heartbeat status information to obtain channel abnormality information corresponding to each secure output channel; a cross-validation module for performing cross-validation processing based on the intrusion determination information and the channel abnormality information to obtain danger determination results corresponding to at least two secure output channels; and a safety shutdown module for generating a safety control signal based on the danger determination results and controlling at least one of the secure output channels to output a shutdown signal based on the safety control signal to trigger a safety shutdown.
9. A computer device comprising a memory, a processor, and computer-readable instructions stored in the memory and running on the processor, characterized in that, When the processor executes the computer-readable instructions, it implements the safe shutdown method as described in any one of claims 1 to 7.
10. A readable storage medium having computer-readable instructions stored thereon, characterized in that, When the computer-readable instructions are executed by the processor, they implement the safe shutdown method as described in any one of claims 1 to 7.