Enterprise production safety risk assessment and management system based on big data

By applying big data technology and knowledge graphs, the enterprise production safety risk management system has achieved multi-source data fusion and cross-time series correlation analysis, which solves the passive problem of risk identification and management in existing technologies and realizes the proactive identification and dynamic management of potential risks.

CN122022476APending Publication Date: 2026-05-12SHENZHEN GUANGHONG YINGXIN NETWORK TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN GUANGHONG YINGXIN NETWORK TECH CO LTD
Filing Date
2026-01-29
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing enterprise production safety risk management systems suffer from isolated data and one-sided risk perception, lack the ability to integrate multi-source heterogeneous data and perform cross-time series correlation analysis, are unable to identify multi-dimensional implicit risk patterns, and lack the ability to dynamically analyze the risk evolution process, resulting in safety management being in a passive response mode.

Method used

The enterprise production safety risk assessment and management system based on big data is adopted. The data acquisition module continuously collects heterogeneous data sources, the data preprocessing module performs real-time cleaning and normalization, the risk pattern recognition module performs rolling window scanning and deep pattern mining, and the risk situation inference module builds a risk situation inference model based on knowledge graph, generates a risk situation inference report, and automatically generates closed-loop management instructions based on risk pattern tags and situation inference reports.

Benefits of technology

It achieves deep fusion and cross-time series correlation analysis of multi-source data, can proactively discover potential risk patterns, conduct forward-looking assessments of risk situations, support dynamic simulation and prediction of security situations, and transform into proactive risk management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122022476A_ABST
    Figure CN122022476A_ABST
Patent Text Reader

Abstract

The invention discloses an enterprise production safety risk assessment and management system based on big data, and relates to the technical field of enterprise safety production intelligent management and control, and the system comprises a data collection module, a data preprocessing module, a risk mode recognition module, a risk situation deduction module and a closed-loop management module which are connected in sequence. Multi-source heterogeneous security data is collected and standardized, and a time sequence correlation analysis engine is utilized to perform rolling window scanning and depth pattern mining on a multi-dimensional feature sequence so as to identify a potential composite risk pattern; and performing logic association and situation evolution simulation on the risk events through the knowledge graph model, and predicting a risk development path. The system realizes closed-loop management from data to decision, and can actively discover hidden risks and predict the evolution situation of the hidden risks, thereby improving the initiative and accuracy of enterprise security risk management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of intelligent management and control technology for enterprise safety production, specifically an enterprise production safety risk assessment and management system based on big data. Background Technology

[0002] Currently, enterprise production safety risk management primarily employs alarm technologies based on independent monitoring and static thresholds. Existing solutions utilize sensors and video surveillance deployed across various equipment and environmental areas to collect operational parameters and environmental indicators in real time. Monitoring of personnel operations relies on access control systems and operation recording terminals. These systems typically set fixed alarm thresholds for single data sources, triggering an alarm when monitored data exceeds the threshold.

[0003] Existing technical solutions suffer from data silos and one-sided risk perception. Multi-source heterogeneous data lacks effective integration, leaving security information isolated. Static threshold alarm mechanisms can only respond to explicit changes in a single parameter, failing to identify complex risk patterns composed of implicit correlations across multiple dimensions and time periods. Furthermore, existing systems generally lack the ability to dynamically analyze the risk evolution process. Their functionality is limited to presenting the current abnormal state, unable to simulate and deduce the chain reactions and final outcomes that a single risk point might trigger based on the logical relationships between risk elements. This results in security management remaining in a passive response mode for a long time.

[0004] A technology is needed to achieve deep fusion and cross-temporal correlation analysis of multi-source security data in order to proactively discover potential risk patterns driven by multiple factors. A technology is also needed to simulate and extrapolate the dynamic evolution path of risks based on historical experience and logical rules, in order to support forward-looking assessments of the security situation. Summary of the Invention

[0005] This invention aims to solve at least one of the technical problems existing in the prior art; To this end, the present invention proposes an enterprise production safety risk assessment and management system based on big data, including: The data acquisition module is used to continuously collect security data streams from heterogeneous data sources in the enterprise's production site. These heterogeneous data sources include equipment operation log sensors, environmental status monitoring sensors, video surveillance image streams, and personnel operation behavior recording terminals. The data preprocessing module establishes a dynamic data preprocessing pipeline for real-time cleaning and normalization of the secure data stream, generating a standardized multi-dimensional security feature sequence. The risk pattern recognition module deploys a security risk pattern recognition engine based on time-series correlation analysis, performs rolling window scanning and deep pattern mining on the standardized multi-dimensional security feature sequence, and outputs a set of potential risk events and risk pattern labels. The risk situation simulation module constructs a risk situation simulation model based on a knowledge graph. The risk situation simulation model performs logical association and situation evolution simulation based on the set of potential risk events and the historical accident case library to generate a risk situation simulation report. The closed-loop management module automatically generates a set of closed-loop management instructions, which includes specific risk control measures and resource allocation suggestions, based on the risk pattern labels and the risk situation simulation report.

[0006] Furthermore, the security data stream used for continuously collecting heterogeneous data sources from the enterprise's production site includes: Establish a communication connection with the device operation log sensor to acquire time-series data streams of device vibration, temperature, current and pressure parameters at a predetermined sampling frequency; Establish a communication connection with the environmental condition monitoring sensor to collect environmental parameter data streams in the production area in real time, including the concentration of toxic and harmful gases, dust concentration, temperature and humidity, and noise decibels. Establish an access channel with the video surveillance image stream, acquire real-time video streams covering key production areas and work nodes in units of image frames, and perform structured parsing on the real-time video streams; Establish a data synchronization interface with the personnel operation behavior recording terminal, and receive the behavior log data stream of personnel location coordinates, operation action records and personal protective equipment wearing status reported by the personnel operation behavior recording terminal; The time-series data stream, the environmental parameter data stream, the structured real-time video stream, and the behavior log data stream are timestamped and encapsulated to form the secure data stream with a unified transmission format.

[0007] Furthermore, the establishment of a dynamic data preprocessing pipeline for real-time cleaning and normalization of the secure data stream, generating a standardized multi-dimensional security feature sequence, includes: The time-series data stream in the secure data stream is subjected to missing value imputation and outlier smoothing, and the inherent noise of the equipment is eliminated by the moving average algorithm to generate a clean equipment status signal. The environmental parameter data stream in the security data stream is subjected to dimensional uniformization conversion and threshold rationality verification to eliminate abrupt data points caused by instantaneous sensor failures and generate standardized environmental monitoring signals. For the structured parsed real-time video stream in the security data stream, visual feature vectors of personnel activity areas, equipment operating status areas, and material stacking areas in each frame of the image are extracted to generate a standardized visual feature stream. For the behavior log data stream in the security data stream, discrete operation action records are encoded into continuous operation sequence vectors, and the personnel position coordinates are mapped to a regional grid to generate a standardized behavior feature sequence. The clean equipment status signals, standardized environmental monitoring signals, standardized visual feature streams, and standardized behavioral feature sequences are aligned and spliced ​​according to a unified time series benchmark to form the standardized multi-dimensional safety feature sequence.

[0008] Furthermore, the deployment of a security risk pattern recognition engine based on temporal correlation analysis performs rolling window scanning and deep pattern mining on the standardized multi-dimensional security feature sequences, outputting a set of potential risk events and risk pattern labels, including: Set an adjustable scrolling time window, continuously slide it on the standardized multi-dimensional security feature sequence, and extract feature data fragments within each window; Each of the feature data segments is input into a pre-trained risk pattern classification network, which consists of multiple layers of temporal convolutional kernels and attention mechanism layers, and is used to extract the temporal dependencies between features. The risk pattern classification network outputs the probability distribution of each feature data segment belonging to a predefined risk pattern. The predefined risk patterns include abnormal equipment wear pattern, environmental parameter exceeding the standard pattern, personnel violation operation pattern, and multi-factor coupled risk pattern. When the probability of a risk pattern corresponding to any of the aforementioned feature data segments exceeds a preset confidence threshold, a risk event alarm is triggered, and the start and end times, involved device identifiers, involved environmental areas, and involved personnel information corresponding to the feature data segments are recorded to constitute a risk event instance. All triggered risk event instances within the current rolling window period are aggregated and labeled with the dominant risk patterns identified by the risk pattern classification network to form the potential risk event set and the corresponding risk pattern labels.

[0009] Furthermore, the construction of a knowledge graph-based risk situation simulation model, which logically correlates and simulates the situation evolution based on the set of potential risk events and the historical accident case library, generates a risk situation simulation report, including: The historical accident case database stores structured records of historical risk event chains, final accident consequences, and key causal nodes. Each risk event instance in the set of potential risk events is mapped to a corresponding entity node in the risk situation simulation model. The entity node types include equipment entities, environmental entities, personnel entities, and work activity entities. Based on the risk pattern label, activate the predefined risk propagation path connecting different entity nodes in the risk situation simulation model. The risk propagation path is defined by the accident causation logic rule. Using the set of potential risk events as initial input, the risk situation simulation model simulates the diffusion process of risk along the risk propagation path, and simulates the secondary risk event nodes that will be triggered and the final accident consequence type. The simulation process summarizes all risk event nodes, risk propagation paths, and final accident consequence types, generating a risk situation simulation report that includes the risk evolution chain, key risk nodes, and recommended intervention points.

[0010] Furthermore, the step of triggering a risk event alarm when the probability of a risk pattern corresponding to any of the aforementioned feature data segments exceeds a preset confidence threshold includes: Real-time monitoring of the risk pattern probability stream output by the risk pattern classification network; An independent confidence threshold is set for each of the predefined risk patterns, and the confidence threshold is dynamically adjusted based on the historical false positive rate and false negative rate; When the probability value of a certain predefined risk pattern in the risk pattern probability stream exceeds its corresponding confidence threshold for a duration that reaches a preset minimum duration, it is determined to be a valid alarm. When generating the effective alarm, the time point when the alarm is triggered, the snapshot of the feature vector in the relevant standardized multi-dimensional security feature sequence, and the change curve of the risk pattern probability flow are recorded simultaneously. The effective alerts, the time points, the feature vector snapshots, and the change curves are packaged together as the core content of the risk event instance.

[0011] Furthermore, the process of simulating the diffusion of risk along the risk propagation path in the risk situation simulation model, using the set of potential risk events as initial input, and simulating the secondary risk event nodes to be triggered and the final accident consequence type, includes: Each risk event instance in the set of potential risk events is designated as an active source node in the risk situation simulation model; Based on the entity type of each active source node and the risk pattern label, retrieve all valid risk propagation paths in the knowledge graph that originate from the active source node; According to the weight and confidence of the path, each effective risk propagation path is traversed in turn, the entity node corresponding to the end point of the path is activated as a new secondary risk event node, and the conditions and time delay required for activation are recorded. Check whether newly activated secondary risk event nodes meet the criteria for determining accident consequence nodes. The criteria include node type, severity of risk status, and strength of association with other nodes. If the conditions are met, the accident consequence node is marked as the accident consequence node in this simulation, and the complete propagation chain from the active source node to the accident consequence node is back-recorded. All secondary risk event nodes obtained from the traversal, the deduced accident consequence nodes, and the complete propagation chain are incorporated into the simulation results.

[0012] Furthermore, based on the risk pattern labels and the risk situation simulation report, the automatic generation of a closed-loop management instruction set containing specific risk control measures and resource allocation recommendations includes: Analyze the risk pattern tags to determine the standard response template library corresponding to the current dominant risk pattern; Analyze the risk situation simulation report and extract information on key risk nodes and recommended intervention points; The key risk nodes and recommended intervention points are matched and instantiated with the measures items in the standard response template library to generate detailed risk control measures for specific equipment, specific areas or specific personnel. Based on the complexity and urgency of the risk evolution chain in the aforementioned risk situation simulation report, assess the required types, quantities, and response priorities of emergency resources; Based on the current available resources of the enterprise, the detailed risk control measures are subject to resource binding and scheduling planning to form an executable resource allocation recommendation; The detailed risk control measures are integrated with the resource allocation recommendations, and each is assigned a unique instruction number and execution time window to form a complete instruction in the closed-loop management instruction set.

[0013] Furthermore, the process of matching and instantiating the key risk nodes and recommended intervention point information with the measure items in the standard response template library to generate detailed risk control measures for specific equipment, specific areas, or specific personnel includes: Based on the entity type and risk pattern in the information of key risk nodes and recommended intervention points, a multi-level index search is performed in the standard response template library; A matching abstract measure template was found, which describes general action steps and objectives; Extract the specific device identifiers, specific area coordinates, or specific personnel identity information contained in the information of the key risk nodes and recommended intervention points; Replace the placeholder variables in the abstract measures template with the specific equipment identifier, specific area coordinates, or specific personnel identity information to transform the general steps into specific and operable action descriptions. Based on the risk propagation logic mentioned in the risk situation simulation report, preconditions for execution and the expected blocking effect are added to each action description to form the detailed rules of the risk control measures.

[0014] Furthermore, the system also includes a secure data archiving and model optimization module; The security data archiving and model optimization module is used to: encrypt, compress, and associate the security data streams processed daily, the standardized multi-dimensional security feature sequences, the set of potential risk events, the risk situation simulation reports, and the execution feedback of the closed-loop management instruction set; The security data archiving and model optimization module is used to periodically perform incremental learning and optimization updates on the parameters of the dynamic data preprocessing pipeline, the risk pattern classification network in the security risk pattern recognition engine, and the risk propagation path weights in the risk situation inference model based on newly archived historical data.

[0015] Compared with the prior art, the beneficial effects of the present invention are: A time-series correlation analysis security risk pattern recognition engine is deployed to perform rolling window scanning and deep pattern mining on standardized multi-dimensional security feature sequences. This technical solution can continuously analyze the dynamic correlations of multi-source data such as equipment, environment, video, and personnel behavior over time, extracting complex risk features that transcend single data sources and fixed thresholds. It realizes the transformation from discrete point-based alarms to continuous time-series pattern recognition, and can discover risk precursors composed of multiple seemingly normal parameters changing in a specific order within a specific time window, thus providing early warning before the risk becomes explicit.

[0016] A risk situation simulation model based on a knowledge graph is constructed, logically linking the identified set of potential risk events with a historical accident case database and simulating the situation's evolution. This technical solution provides a computable, structured context for risk events by building a semantic network containing entities such as equipment, environment, behavior, and consequences, along with their causal relationships. The model can perform logical reasoning on the knowledge graph, simulating the propagation and diffusion of the initial risk event along the causal chain, and deducing potential secondary and derivative risks and the final accident situation. This transforms risk analysis from a static assessment of the current state to a multi-path deduction of the dynamic development of the event chain, outputting logically based predictions of future scenarios and directly supporting the formulation of early intervention strategies for key evolutionary nodes. Attached Figure Description

[0017] Figure 1This is a sequence diagram of the enterprise production safety risk assessment and management system based on big data as described in this invention; Figure 2 A flowchart illustrating the workflow of a dynamic data preprocessing pipeline; Figure 3 Analysis chart of the optimization effect of the enterprise production safety risk situation simulation model; Figure 4 Comparison chart of enterprise production safety risk pattern recognition results; Figure 5 A comparison chart showing the effectiveness of implementing closed-loop management instructions for enterprise production safety. Detailed Implementation

[0018] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0019] See Figure 1 The enterprise production safety risk assessment and management system based on big data includes a data acquisition module, a data preprocessing module, a risk pattern recognition module, a risk situation simulation module, and a closed-loop management module. The system continuously collects safety data streams from heterogeneous data sources at the enterprise's production site through the data acquisition module. These heterogeneous data sources include equipment operation log sensors, environmental status monitoring sensors, video surveillance image streams, and personnel operation behavior recording terminals. The safety data streams are sent to the data preprocessing module, which establishes a dynamic data preprocessing pipeline to perform real-time cleaning and normalization of the safety data streams, generating standardized multi-dimensional safety feature sequences. The risk pattern recognition module deploys a safety risk pattern recognition engine based on time-series correlation analysis, performing rolling window scanning and deep pattern mining on the standardized multi-dimensional safety feature sequences, outputting a set of potential risk events and risk pattern labels. The risk situation simulation module constructs a risk situation simulation model based on a knowledge graph, logically associating and simulating situation evolution based on the set of potential risk events and a historical accident case library, generating a risk situation simulation report. Based on risk pattern labels and risk situation simulation reports, the closed-loop management module automatically generates a set of closed-loop management instructions that include specific risk control measures and resource allocation recommendations.

[0020] In one embodiment of the present invention, see [reference] Figure 2In specific implementation, the data acquisition module and data preprocessing module of the enterprise production safety risk assessment and management system based on big data work together in a petrochemical production scenario. The petrochemical production scenario includes reactors, pipelines, and storage tank areas as key production areas. Equipment operation log sensors are installed on the drive motors of the reactors, environmental status monitoring sensors are distributed around the storage tank area, video surveillance image streams cover the reactor operation platform and pipeline valve nodes, and personnel operation behavior recording terminals are worn by on-site inspection personnel. The data acquisition module establishes a communication connection with the equipment operation log sensors and acquires time series data streams of equipment vibration, temperature, current, and pressure parameters at a predetermined sampling frequency of once per second. During the transmission of the time series data stream, data packets may be lost due to network fluctuations, resulting in a missing value sequence.

[0021] Simultaneously, a communication connection is established with environmental condition monitoring sensors to collect real-time environmental parameter data streams, including hydrogen sulfide gas concentration, dust concentration, temperature, humidity, and noise decibels within the production area. The dust concentration readings in the environmental parameter data stream occasionally experience momentary spikes due to deposits on the sensor probes. An access channel is established with video surveillance image streams, acquiring real-time video streams covering the reactor operation platform at 30 frames per second. The real-time video streams are then structured and parsed to extract the bounding box coordinates of personnel and equipment. A data synchronization interface is established with a personnel operation behavior recording terminal to receive a behavior log data stream reported every minute by the terminal, including personnel location coordinates, operation action records, and personal protective equipment wearing status. The operation action records in the behavior log data stream exist in discrete event form, such as "open valve A" or "close pump B." The time-series data stream, the environmental parameter data stream, the structured and parsed real-time video stream, and the behavior log data stream are timestamped and encapsulated. The timestamps of all data sources are uniformly coordinated to UTC and serialized using the Apache Avro format to form a secure data stream with a unified transmission format.

[0022] In some embodiments, the dynamic data preprocessing pipeline established by the data preprocessing module performs real-time cleaning and normalization on the secure data stream. This dynamic data preprocessing pipeline is deployed on the Apache Flink stream processing engine and performs missing value imputation and outlier smoothing on the time-series data stream within the secure data stream. Missing value imputation uses a linear interpolation method to fill gaps caused by lost data packets. Outlier smoothing replaces outliers in the equipment vibration data that exceed three standard deviations using median filtering and eliminates inherent noise from the equipment using a moving average algorithm. The moving average algorithm is defined as follows: in: This indicates the original vibration signal at time point The amplitude value, This indicates the length of the sliding window, and its value is 10 sampling points. This process represents the smoothed amplitude value, generates a clean equipment status signal, and performs dimensional unification and threshold rationality verification on the environmental parameter data stream in the safety data stream. Dimension unification converts the noise decibel value from dB to Pascal-scale sound pressure level. Threshold rationality verification removes abrupt data points caused by sensor malfunctions based on the sensor's physical range; for example, readings of hydrogen sulfide concentration exceeding the upper limit of 2000 ppm are considered invalid and discarded. Standardized environmental monitoring signals are generated. From the structured real-time video stream in the safety data stream, visual feature vectors are extracted from each frame of the image, including areas of personnel activity, equipment operation status, and material stacking. These visual feature vectors are extracted using a pre-trained convolutional neural network model, generating a 512-dimensional floating-point array. The standardized visual feature stream encodes discrete operational actions into continuous operational sequence vectors in the behavior log data stream of the safety data stream. The encoding process uses one-hot encoding to map each operational action into a fixed-length sparse vector, and performs regional gridding mapping on the personnel position coordinates, dividing the entire production area into 1-meter by 1-meter grids, mapping the coordinates to grid index numbers, and generating a standardized behavioral feature sequence. The clean equipment status signals, standardized environmental monitoring signals, standardized visual feature stream, and standardized behavioral feature sequence are aligned and spliced ​​according to a unified time series benchmark. The time series benchmark uses the UTC millisecond timestamp as the key, splicing all feature vectors into a high-dimensional vector within the same time window to form a standardized multi-dimensional safety feature sequence.

[0023] Optionally, in the specific process of processing equipment vibration data using the moving average algorithm, the window length... The window length can be dynamically adjusted according to the type of equipment. For rotating equipment such as centrifugal pumps, the window length can be adjusted accordingly. Setting the sampling points to 20 to better suppress high-frequency mechanical noise, for reciprocating equipment such as compressors, the window length... Five sampling points are set to retain effective impact characteristics. This adjustment is achieved by configuring pipeline parameters and does not affect the continuity of the real-time processing pipeline. It can be understood that missing value interpolation and outlier smoothing are performed sequentially. Linear interpolation fills in missing points first, and median filtering processes outliers to ensure the continuity of equipment status signals in time.

[0024] In some embodiments, when generating standardized environmental monitoring signals, threshold rationality verification not only relies on the static sensor range but also introduces dynamic range checking. Dynamic range checking calculates the rate of change between adjacent sampling points. If the rate of change exceeds a preset threshold, such as 100 ppm per second, the data point is marked as suspicious and undergoes secondary verification. Secondary verification is accomplished by comparing the consistency of readings from multiple sensors in the same area. If they are inconsistent, the abrupt data point is removed. It can be understood that during the extraction of visual feature vectors, the convolutional neural network model adopts the ResNet-50 architecture, the input image resolution is adjusted to 224x224 pixels, and the global average pooling layer before the output layer generates a 512-dimensional feature vector. In the standardized visual feature stream, each frame of image corresponds to a feature vector, and the frame rate is maintained at thirty frames per second, synchronized with the original video stream.

[0025] Optionally, in the encoding operation of the behavior log data stream, the vocabulary of one-hot encoding covers all predefined standard operation actions. The vocabulary is constructed based on the historical operation manual. When an unknown operation action occurs, it is mapped to an all-zero vector and a log record is triggered. The regional gridding mapping uses a Cartesian coordinate system to divide the factory plan into grids. Each grid has a unique number. The personnel location coordinates are obtained through the Global Positioning System or Ultra-Wideband Positioning Technology. The mapping process converts latitude and longitude coordinates into planar coordinates and then calculates the grid number to generate a standardized behavior feature sequence. After the standardized behavior feature sequence is aligned with the equipment status signal, environmental monitoring signal, and visual feature stream in time, the standardized multi-dimensional safety feature sequence formed by splicing them together has a dimension equal to the sum of the dimensions of each signal feature. For example, if the equipment status signal has 4 parameters, the environmental monitoring signal has 4 parameters, the visual feature stream is 512-dimensional, the operation vector in the behavior feature sequence is 50-dimensional, and the location grid number is 1-dimensional, then the total dimension of the spliced ​​feature sequence is 571-dimensional.

[0026] In one embodiment of the present invention, in a specific implementation, the safety risk pattern recognition engine deployed by the risk pattern recognition module operates in a pump unit monitoring scenario in a chemical plant. An adjustable-length rolling time window is set, continuously sliding across a standardized multi-dimensional safety feature sequence. The initial length of the rolling time window is configured as 300 sampling points, corresponding to ten seconds of real-time data. It moves forward with a sliding step size of once per second, capturing feature data segments within each window. Each feature data segment is a 571x300 matrix, where rows correspond to feature dimensions and columns correspond to time series. Each feature data segment is input into a pre-trained risk pattern classification network. The system consists of five temporal convolutional kernels and one multi-head attention mechanism layer, used to extract temporal dependencies between features. The first temporal convolutional kernel has a size of 7, the second temporal convolutional kernel has a size of 5, and the subsequent three temporal convolutional kernels each have a size of 3. Batch normalization and ReLU activation function are applied after each convolutional operation. The multi-head attention mechanism layer has 8 heads. The risk pattern classification network outputs the probability distribution of each feature data segment belonging to a predefined risk pattern. The predefined risk patterns include abnormal wear of pump bearings, dangerous gas leakage at the seal, operator violation of the warning line, and high temperature and vibration coupling risk pattern. The probability distribution is a four-dimensional vector, with each dimension having a value between 0 and 1, and the sum of the four dimensions equals 1.

[0027] In some embodiments, when the probability of a risk pattern corresponding to any feature data segment exceeds a preset confidence threshold, a risk event alarm is triggered, and the start and end times, involved device identifiers, involved environmental areas, and involved personnel information corresponding to the feature data segment are recorded to constitute a risk event instance. All triggered risk event instances within the current rolling window period are aggregated and labeled with the dominant risk pattern identified by the risk pattern classification network. The dominant risk pattern is the risk pattern with the highest median probability distribution, forming a set of potential risk events and corresponding risk pattern labels. The risk pattern probability stream output by the risk pattern classification network is monitored in real time. The probability stream is a continuous four-dimensional vector time series, representing each... An independent confidence threshold is set for each predefined risk mode. The initial confidence threshold for the abnormal wear mode of pump bearings is set to 0.85, the initial confidence threshold for the hazardous gas leakage mode at the seal is set to 0.90, the initial confidence threshold for the mode of operators illegally crossing the warning line is set to 0.80, and the initial confidence threshold for the risk mode of high temperature and vibration coupling is set to 0.75. The confidence threshold is dynamically adjusted based on the historical false alarm rate and false negative rate. The adjustment strategy is based on the ratio of the total number of alarms for each risk mode in the past 24 hours to the number of actual events confirmed by manual verification. If the ratio is higher than the target false alarm rate, the confidence threshold is increased; if the ratio is lower than the target false negative rate, the confidence threshold is decreased.

[0028] Optionally, when the probability value of a predefined risk mode in the risk mode probability flow continuously exceeds its corresponding confidence threshold for a duration that reaches a preset minimum duration, it is determined to be a valid alarm. The preset minimum duration is set to five seconds for the abnormal wear mode of pump bearings, two seconds for the dangerous gas leakage mode at the seal, one second for the mode of operators illegally crossing the warning line, and three seconds for the risk mode of high temperature and vibration coupling. When a valid alarm is generated, the time point of the alarm trigger, the snapshot of the feature vector in the relevant standardized multi-dimensional safety feature sequence, and the change curve of the risk mode probability flow are recorded simultaneously. The feature vector snapshot captures all feature data within a range of 150 sampling points before and after the alarm trigger time. The change curve of the risk mode probability flow records the change of the probability value of the risk mode from 30 seconds before the alarm trigger to 10 seconds after the trigger. The valid alarm, time point, feature vector snapshot, and change curve are packaged as the core content of the risk event instance. The data structure of the risk event instance also includes a unique event identifier generated by the system.

[0029] It is understandable that the computation process of the multi-head attention mechanism layer in the risk pattern classification network involves operations on the query matrix, key matrix, and value matrix, and the calculation of attention weights follows the formula: in: This represents the query matrix generated by linear projection of the output features from the temporal convolutional layer. This represents the key matrix generated by another linear projection of the same features. Represents the transpose of the key matrix. This represents the dimension of the key vector in an attention head, and its value is 64. This represents the calculated attention weight matrix, which is related to the value matrix. Multiply to produce a weighted representation of contextual features.

[0030] In some embodiments, after extracting feature data fragments within each window, the feature data fragments are standardized. Standardization involves subtracting the mean of the feature over all time steps and dividing by the standard deviation to ensure consistent data scale input to the risk pattern classification network. The risk pattern classification network is trained using labeled historical feature data fragments for supervised learning. The loss function is cross-entropy loss, and the optimizer uses the Adam algorithm. Training continues until the accuracy on the validation set no longer improves. The predefined set of risk patterns is predefined and expandable; new risk patterns can be incorporated by modifying the output layer dimensions of the risk pattern classification network and retraining some network layers. Optionally, the confidence threshold is dynamically adjusted automatically in a four-hour cycle, and the adjustment calculation uses the following formula: in: This represents the adjusted new confidence threshold. This represents the old confidence threshold before adjustment. This indicates that the step size factor has been adjusted and set to 0.05. This represents the false alarm rate actually calculated over the past period. The false positive rate represents the target false positive rate set by the system administrator. The adjustment of the false negative rate follows a similar logic but uses a separate formula and target value. It can be understood that when recording feature vector snapshots, the system will create an index for the snapshot data. The index is associated with the unique event identifier of the risk event instance for subsequent tracing and analysis.

[0031] In one embodiment of the present invention, in a specific implementation, the risk situation inference module constructs a knowledge graph-based risk situation inference model to perform logical inference in a scenario involving a flammable liquid storage tank area. The historical accident case library stores structured records of historical risk event chains, final accident consequences, and key causal nodes. The historical risk event chains are stored in the form of a directed graph, where nodes represent events or states and edges represent causal relationships. For example, an event chain of a record is "Pump P-101 bearing high temperature alarm" -> "Pump P-101 mechanical seal failure" -> "Material A leakage" -> "Leaked material A vapor accumulation" -> "Encountering static spark" -> "Fire and explosion". The final accident consequence is marked as "fire and explosion", and the key causal nodes are marked as "Pump P-101 mechanical seal failure" and "Leaked material A vapor accumulation". Each risk event instance in the potential risk event set is mapped to the corresponding entity node in the risk situation inference model. The entity node types include equipment entities, environmental entities, personnel entities, and work activity entities.

[0032] For example, a risk event instance labeled "abnormal wear mode of pump bearing" is mapped to the equipment entity "Pump P-101", and another risk event instance labeled "exceeding environmental parameter limits" (high temperature) is mapped to the environmental entity "Pump Room Area - Ambient Temperature". Based on the risk mode labels, predefined risk propagation paths connecting different entity nodes in the risk situation deduction model are activated. These risk propagation paths are defined by accident causation logic rules. For example, in the knowledge graph, there might be a path from the "abnormal wear" state of equipment entity "Pump P-101" to the equipment entity "Pump..." The propagation path of the "seal failure" state of "P-101" is activated by the rule that "when the bearing vibration value continuously exceeds the standard and the temperature continues to rise for more than 120 seconds". Using a set of potential risk events as the initial input, the risk situation simulation model simulates the diffusion process of risk along the risk propagation path, and simulates the secondary risk event nodes that will be triggered and the final accident consequence type. It summarizes all risk event nodes, risk propagation paths and final accident consequence types passed through in the simulation process, and generates a risk situation simulation report that includes the risk evolution chain, key risk nodes and recommended intervention points.

[0033] In some embodiments, each risk event instance in the potential risk event set is designated as an active source node in the risk situation deduction model. Active source nodes are marked as "activated" and assigned initial weights. Based on the entity type and risk pattern label of each active source node, all valid risk propagation paths originating from active source nodes are retrieved from the knowledge graph. A valid risk propagation path is a path whose current node state satisfies its starting conditions and is not prohibited by logical rules. For example, starting from the "Pump P-101 (Abnormal Wear)" node, three valid risk propagation paths are retrieved: Path 1 points to "Pump P-101 (Seal Failure)", Path 2 points to "Pump P-101 (Shutdown)". Path 3 points to "related pipeline (abnormal vibration)". According to the weight and confidence of the path, each effective risk propagation path is traversed in turn. The weight of the path is determined by the frequency of the path in historical cases and the expert score. The confidence reflects the certainty of the causal relationship of the path. The traversal process is sorted according to the comprehensive score of the path. The entity node corresponding to the end point of the path is activated as a new secondary risk event node, and the conditions and time delay required for activation are recorded. The conditions required for activation refer to other constraints in the path logic other than the starting state, such as "ambient temperature is greater than 40 degrees Celsius". The time delay is based on historical data statistics and represents the typical time interval from the occurrence of the starting event to the occurrence of the ending event.

[0034] Optionally, check whether newly activated secondary risk event nodes meet the criteria for accident consequence nodes. The criteria include node type, risk severity, and correlation strength with other nodes. The node type must be a predefined consequence type, such as "fire," "explosion," "poisoning," or "leakage." The risk severity must reach a preset threshold. Correlation strength refers to the tightness of the connection between the node and the already activated hazard source node in the knowledge graph. If satisfied, the accident consequence node is marked as the accident consequence node in this simulation, and the complete propagation chain from the active source node to the accident consequence node is backtracked and recorded. All traversed secondary risk event nodes, simulated accident consequence nodes, and complete propagation chains are included in the simulation results. The simulation results are stored in a graph structure, where nodes contain event descriptions and states, and edges contain propagation logic and time attributes. It can be understood that the activation probability calculation of the risk propagation path follows a formula: in: This represents the probability that the path is successfully activated in the simulation. Represents the Sigmoid function. This represents the normalized value of the frequency of this path in historical cases. The confidence score given by experts for the causal relationship of this path. This represents the degree of matching between the path triggering conditions and real-time data in the current scenario. , , These are the weight coefficients assigned to the frequency factor, confidence factor, and matching factor, respectively, and satisfying the following conditions: ,when Value exceeds threshold Only when this happens will the path be considered during traversal and may activate secondary nodes.

[0035] In some embodiments, the risk situation simulation model employs a graph traversal algorithm for simulation. It performs a breadth-first search starting from all active source nodes. For each path traversed, the algorithm checks whether the endpoint node is already activated or logically mutually exclusive in the current simulation state. If the endpoint node is not activated and there is no logical mutual exclusion, the algorithm proceeds according to the path activation probability. The system uses random number generation to determine whether to activate a node. The simulation sets the maximum time step, with each time step representing a period of time in reality (e.g., 5 minutes). The time delay of the path is converted into an integer number of time steps. Secondary risk event nodes become new active source nodes at their activated time steps and participate in the subsequent traversal process until the maximum time step is reached or no new nodes can be activated.

[0036] Optionally, the generated risk situation simulation report adopts a combination of structured text and visual graphs. The visual graphs intuitively display the complete risk evolution chain from active source nodes to accident consequence nodes, and highlight key risk nodes and recommended intervention points with different colors. Key risk nodes are selected based on their centrality indicators in multiple propagation paths. Recommended intervention points are nodes calculated in the simulation that, if their status is changed from "dangerous" to "safe", the accident chain development can be blocked or delayed to the greatest extent. The text part of the report details the description of each secondary risk event node in the simulation, the expected occurrence time window, and the corresponding propagation path logic. It is understood that the historical accident case library will be updated regularly. When a new real accident is investigated and analyzed, its structured event chain will be extracted and added to the library to optimize the path weights and confidence in the knowledge graph.

[0037] See Figure 3 This is a chart analyzing the optimization effect of an enterprise production safety risk situation projection model, demonstrating the impact of the number of historical case library updates on the confidence level and projection error rate of risk propagation paths. The chart clearly shows the positive correlation between case library updates and model performance: as the number of case library updates increases, the confidence levels of all three risk propagation paths continuously improve, while the projection error rate decreases simultaneously. This verifies the effectiveness of the patented technology of "incremental learning and model optimization based on newly archived data." Path 1 shows the largest increase in confidence level, indicating that this path appears most frequently in historical cases. Continuous updates to the case library effectively strengthen the causal certainty of this key propagation path, providing a quantitative basis for the dynamic improvement of the knowledge graph. The rate of increase in confidence level and the rate of decrease in error rate both slowed significantly after four updates, indicating that the model performance is close to its optimal state under the current data. This conclusion can guide enterprises to formulate a strategy of regular but not high-frequency case library updates, balancing the cost and effect of model optimization.

[0038] In one embodiment of the present invention, in a specific implementation, the closed-loop management module generates a closed-loop management instruction set in a scenario involving potential risks of flange seal leakage in a chemical storage tank area. It parses risk mode tags, determines the standard response template library corresponding to the current dominant risk mode, which is "hazardous gas leakage at the seal." The standard response template library is a collection stored in a relational database. Each template record contains a risk mode code, applicable entity type, action step description fields, and placeholder variables. The module also parses the risk situation simulation report, extracting key risk nodes and recommended intervention point information. Key risk node information includes "storage tank T-201 outlet flange" and "pump station area - combustible gas concentration." Recommended intervention points are... The pre-defined information is "isolate storage tank T-201 and initiate area ventilation within 10 minutes." Key risk nodes and recommended intervention points are matched and instantiated with measures from the standard response template library to generate detailed risk control measures for specific equipment, areas, or personnel. Based on the complexity and urgency of the risk evolution chain in the risk scenario simulation report, the required emergency resource types, quantities, and response priorities are assessed. Combined with the company's current available resources, the detailed risk control measures are resource-bound and scheduled, forming executable resource allocation recommendations. These recommendations are then integrated with the risk control measures and resource allocation recommendations, each assigned a unique instruction number and execution time window, forming a complete instruction within the closed-loop management instruction set.

[0039] In some embodiments, key risk nodes and recommended intervention point information are matched and instantiated with measure entries in the standard response measure template library to generate detailed risk control measures for specific equipment, specific areas, or specific personnel. Based on the entity type and risk pattern in the key risk nodes and recommended intervention point information, a multi-level index search is performed in the standard response measure template library. The first-level index uses the risk pattern code "M002" (representing the hazardous gas leakage pattern at the seal), and the second-level index uses the entity type "equipment" to find matching abstract measure templates. The abstract measure templates describe general action steps and objectives. For example, an abstract measure template might read "Seal the leak source at [equipment identifier] and use [leak sealing tool type] to execute [specific leak sealing method]". The specific equipment identifier, specific area coordinates, or specific personnel identity information contained in the key risk nodes and recommended intervention point information is extracted. The specific equipment identifier is "storage tank T-201 outlet flange", and the specific area coordinates are "plant area grid coordinates G-07".

[0040] Replace placeholder variables in the abstract measures template with specific equipment identifiers, specific area coordinates, or specific personnel identification information. This transforms general steps into concrete, actionable descriptions. The resulting action description is: "Seal the leak source at the outlet flange of storage tank T-201 and perform a pressurized leak sealing operation using non-metallic spiral wound gaskets." Combining this with the risk propagation logic mentioned in the risk situation simulation report, add preconditions and expected containment effects to each action description, forming detailed risk control measures. The precondition added to the above action description is "Confirm the leak point pressure is below 0.5 MPa," and the expected containment effect is "Reduce the flammable gas concentration to below 20% of the lower explosive limit." Optionally, based on the complexity and urgency of the risk evolution chain in the risk situation simulation report, assess the required emergency resource types, quantities, and response priorities. The assessment process is based on a resource demand assessment matrix, with a resource urgency coefficient... The calculation formula is: in: The urgency coefficient represents the resource demand, with a value range of (0,1). Represents the natural constant. The complexity score, representing the risk evolution chain, is calculated by weighting the total number of nodes and paths involved in the simulation report. The normalized time urgency factor is calculated by dividing the difference (in minutes) between the projected time of the accident's consequences and the current time by the baseline time constant. (Set to 60 minutes) The result is... and These are the weighting coefficients for the complexity factor and the time urgency factor, respectively, set to 0.6 and 0.4. The urgency coefficient... Combined with the basic resource requirements table, determine the final resource quantity and priority. See Table 1.

[0041] Table 1: Emergency Resource Demand Assessment Table Based on the current available resources of the enterprise, the risk control measures are bound to resources and a scheduling plan is made to form an executable resource allocation suggestion. The current available resources of the enterprise are obtained from the real-time interface of the enterprise asset management system. The scheduling plan is as follows: dispatch chemical leak sealing team B, 2 portable detectors, 1 ventilator, and 200 meters of warning tape from the emergency warehouse located on the east side of the factory area; dispatch 1 spare ventilator and 5 spare gaskets from the maintenance workshop located on the west side of the factory area; and assign specific transportation routes and responsible persons to all resources.

[0042] In some embodiments, when generating detailed risk control measures, if a key risk node matches multiple abstract measure templates, multiple detailed measures are generated and arranged in logical order. For example, for the key environmental entity node "pump room area - combustible gas concentration", two templates are matched: "start the forced ventilation system at [area coordinates]" and "set up a warning isolation zone around [area coordinates]". After instantiation, two ordered action descriptions are generated. The abstract measure template library supports version management. When the safety procedures are updated, the administrator releases a new version of the template, and the closed-loop management module automatically uses the latest version of the template for instantiation. It can be understood that the generation of resource configuration suggestions needs to consider resource conflicts. The system maintains a global resource scheduling view. When the same resource is requested by multiple concurrent instructions, arbitration is performed based on the priority of the instructions and the time window.

[0043] Optionally, the process of integrating risk control measures with resource allocation recommendations involves merging all action descriptions, preconditions, expected effects, resource lists, and scheduling details into a structured JSON document, assigning it a unique instruction number such as "CMD-20230715-001". The execution time window is calculated based on the time required for resource scheduling and the estimated time for the action, for example, "Start time: immediately; latest completion time: 15 minutes after the current time". This constitutes a complete instruction in the closed-loop management instruction set. The instruction set is simultaneously sent to the mobile inspection terminal, the central control room screen, and the duty manager's workstation via the enterprise message bus. It can be understood that each issued instruction is associated with its corresponding risk mode label and risk situation simulation report in the database through an event ID, which is used for subsequent instruction execution feedback and effect tracking.

[0044] See Figure 4 This is a comparison chart of enterprise production safety risk pattern recognition results. It quantitatively analyzes four risk patterns from two dimensions: the number of events and the confidence score. Multi-factor coupled risks have the highest number of events and the highest confidence score, indicating that this type of risk is the most frequent and easily identifiable high-risk pattern in current production scenarios and should be the top priority for enterprise safety management. The high confidence score (0.95) of multi-factor coupled risks verifies the effectiveness of the "temporal correlation analysis + risk pattern classification network" technology in the patent, demonstrating the algorithm's strong ability to identify complex multi-factor risks. Conversely, the low confidence score (0.78) of personnel violations reflects the greater difficulty in accurately identifying this type of risk due to its high degree of randomness, making it a key area for algorithm optimization. The high number of events and high confidence score of multi-factor coupled risks suggest that enterprises need to focus on the cross-propagation and coupling effects of risks, such as secondary risks caused by the combined effects of equipment malfunctions and environmental exceedances, in order to develop more targeted prevention and intervention measures.

[0045] In one embodiment of the present invention, in a specific implementation, the safety data archiving and model optimization module in the enterprise production safety risk assessment and management system based on big data performs its functions within the daily operation and maintenance cycle of a large chemical plant. The system includes a safety data archiving and model optimization module, which is used to encrypt, compress, and associate the daily processed safety data stream, standardized multi-dimensional safety feature sequences, potential risk event sets, risk situation simulation reports, and closed-loop management instruction set execution feedback. The daily processing completion time is set to 00:00 AM, and the system automatically triggers the archiving operation. The encryption and compression uses the AES-256 algorithm to encrypt the data and the Zstandard algorithm to compress it to save storage space. The association storage is achieved through the collaboration of a relational database and an object storage system. The database records metadata and indexes, and the object storage system stores the encrypted and compressed data blocks. The metadata includes data date, data type, data size, data hash value, and the association relationship between each data entity. For example, a potential risk event instance is associated with its source standardized multi-dimensional safety feature sequence fragment, generated risk situation simulation report, and triggered closed-loop management instruction set through a unique event identifier.

[0046] In some embodiments, the security data archiving and model optimization module is used to periodically perform incremental learning and optimization updates on the parameters of the dynamic data preprocessing pipeline, the risk pattern classification network in the security risk pattern recognition engine, and the risk propagation path weights in the risk situation inference model based on newly archived historical data. The periodic update cycle is set to every Sunday. Before the incremental learning process starts, the system extracts a subset of newly archived historical data from the associated storage over the past week as training samples to optimize and update the parameters of the dynamic data preprocessing pipeline. The parameter optimization of the dynamic data preprocessing pipeline mainly targets the window length of the moving average algorithm and the threshold for outlier detection. By analyzing the statistical characteristics of the standardized multi-dimensional security feature sequences over the past week, the sliding window length for different equipment types is adaptively adjusted. For pump equipment where vibration patterns drift, the window length parameter... Based on the formula: in: This represents the optimized new window length (unit: number of sampling points, dimensionless). This represents the original window length before optimization (dimensionless). This represents the adjustment coefficient and is set to 0.05. This represents the average peak frequency of the device's vibration signal over the past week (in Hertz). The fractional term in the formula represents the average peak frequency (in Hertz) of the historical baseline data of the device under normal operating conditions. The relative rate of change is a dimensionless value, ensuring dimensional consistency on both sides of the equation.

[0047] Optionally, incremental learning and optimization updates are performed on the risk pattern classification network in the security risk pattern recognition engine. The incremental learning process uses newly archived sets of potential risk events with confirmation labels and their associated standardized multi-dimensional security feature sequences as training data. The training process does not reset the original weights of the network, but fine-tunes them based on the original weights. During fine-tuning, the first three temporal convolutional layers of the network are frozen, and backpropagation training is performed only on the subsequent network layers (including the last two temporal convolutional layers, the attention mechanism layer, and the fully connected output layer). The loss function adopts cross-entropy loss, and the optimizer adopts stochastic gradient descent with momentum. The training rounds of each incremental learning are limited to five rounds to prevent overfitting to the new data. Incremental learning and optimization updates are performed on the risk propagation path weights in the risk situation simulation model. The update of the path weights is based on the newly archived risk situation simulation reports and their corresponding actual accidents or near misses. When a risk propagation path is activated in the simulation report and the subsequent closed-loop management instruction set execution feedback confirms or refutes the simulation, the weight of the path is adjusted.

[0048] It is understandable that during the encryption compression and associated storage process, a globally unique traceability chain identifier is generated for each set of related data. This identifier links all related secure data stream fragments, feature sequences, risk events, inference reports, and instruction feedback together, facilitating future auditing and retrospective analysis. The encryption key is dynamically provided by the enterprise key management system. Each data block has a different encryption key, and the key itself is also stored in encryption. After regular incremental learning and optimization updates, the system will create new versions of dynamic data preprocessing pipeline configuration files, risk pattern classification network model files, and risk situation inference model knowledge graph snapshots. Old versions of the files are archived and saved, and the system automatically loads and uses the new versions of the files in the next work cycle.

[0049] In some embodiments, the newly archived subset of historical data undergoes a balancing sampling process before being used for incremental learning. This balancing sampling process is applied to the training data of the risk pattern classification network. Since real risk events belong to a minority class, the system downsamples the normal feature sequence data that has not been identified as risk events in the past week, so that the number of normal feature sequence data that is not identified as risk events reaches a preset ratio, such as one to one. The update of the risk propagation path weights follows the Bayesian update rule. Each path has a prior weight. When new evidence (i.e., inference reports and actual feedback) appears, the prior weights are updated according to the degree of support or opposition of the evidence to generate posterior weights. For example, if the prior weight of a path is 0.7, and new evidence strongly supports the validity of the path, the posterior weight may be updated to 0.8.

[0050] Optionally, the security data archiving and model optimization module calculates and stores the Message Digest Algorithm Version 5 (SDA5) hash value for each data block during archiving. The SDA5 hash value is used for subsequent data integrity verification. The associated database table structure includes "Original Data Table," "Feature Sequence Table," "Risk Event Table," "Inference Report Table," "Instruction Feedback Table," and "Data Association Mapping Table." The Data Association Mapping Table records the relationships between all data entities through foreign key relationships. The incremental learning and optimization update process is recorded in detail in the system log. The log content includes the update time, updated components, time range of the data used, comparison of parameters or weights before and after the update, and the final status of the update task (success or failure). It can be understood that the execution feedback of the closed-loop management instruction set is submitted by the on-site operator through a mobile terminal application. The feedback content includes the instruction execution status (completed, in progress, canceled), execution result description, on-site photos or readings. This feedback information is associated with the corresponding instruction number during archiving, becoming an important monitoring signal in incremental learning.

[0051] See Figure 5 This chart compares the effectiveness of closed-loop management instructions for enterprise production safety. It quantitatively evaluates five typical risk control measures across two dimensions: instruction completion rate and risk control effectiveness. Mandatory PPE wearing is optimal in both indicators, demonstrating that such standardized, rigidly binding measures are easy to implement and have clear effects, making them the most reliable foundational means of enterprise safety management. Conversely, low performance in personnel retraining reflects the difficulty and slow effectiveness of measures relying on subjective personnel changes. A significant positive correlation exists between instruction completion rate and risk control effectiveness, validating the design logic of the "closed-loop management instruction set" in the patent: the more thorough the implementation of measures, the more significant the risk control effect. This conclusion can guide enterprises to prioritize measures with low implementation costs and clear effects. In emergency scenarios, this chart can be used to quickly select the optimal measure: for example, prioritizing mandatory PPE wearing and equipment shutdown for maintenance in high-risk areas to reduce risk as quickly as possible; while personnel retraining should be used as a medium- to long-term optimization method, rather than an emergency response measure.

[0052] The above embodiments are only used to illustrate the technical methods of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical methods of the present invention without departing from the spirit and scope of the technical methods of the present invention.

Claims

1. A big data-based enterprise production safety risk assessment and management system, characterized in that, The system includes: The data acquisition module is used to continuously collect security data streams from heterogeneous data sources in the enterprise's production site. These heterogeneous data sources include equipment operation log sensors, environmental status monitoring sensors, video surveillance image streams, and personnel operation behavior recording terminals. The data preprocessing module establishes a dynamic data preprocessing pipeline for real-time cleaning and normalization of the secure data stream, generating a standardized multi-dimensional security feature sequence. The risk pattern recognition module deploys a security risk pattern recognition engine based on time-series correlation analysis, performs rolling window scanning and deep pattern mining on the standardized multi-dimensional security feature sequence, and outputs a set of potential risk events and risk pattern labels. The risk situation simulation module constructs a risk situation simulation model based on a knowledge graph. The risk situation simulation model performs logical association and situation evolution simulation based on the set of potential risk events and the historical accident case library to generate a risk situation simulation report. The closed-loop management module automatically generates a set of closed-loop management instructions, which includes specific risk control measures and resource allocation suggestions, based on the risk pattern labels and the risk situation simulation report.

2. The enterprise production safety risk assessment and management system based on big data according to claim 1, characterized in that, The secure data stream used for continuously collecting heterogeneous data sources from the enterprise's production site includes: Establish a communication connection with the device operation log sensor to acquire time-series data streams of device vibration, temperature, current and pressure parameters at a predetermined sampling frequency; Establish a communication connection with the environmental condition monitoring sensor to collect environmental parameter data streams in the production area in real time, including the concentration of toxic and harmful gases, dust concentration, temperature and humidity, and noise decibels. Establish an access channel with the video surveillance image stream, acquire real-time video streams covering key production areas and work nodes in units of image frames, and perform structured parsing on the real-time video streams; Establish a data synchronization interface with the personnel operation behavior recording terminal, and receive the behavior log data stream of personnel location coordinates, operation action records and personal protective equipment wearing status reported by the personnel operation behavior recording terminal; The time-series data stream, the environmental parameter data stream, the structured real-time video stream, and the behavior log data stream are timestamped and encapsulated to form the secure data stream with a unified transmission format.

3. The enterprise production safety risk assessment and management system based on big data according to claim 1, characterized in that, The establishment of a dynamic data preprocessing pipeline for real-time cleaning and normalization of the secure data stream, generating standardized multi-dimensional security feature sequences, includes: The time-series data stream in the secure data stream is subjected to missing value imputation and outlier smoothing, and the inherent noise of the equipment is eliminated by the moving average algorithm to generate a clean equipment status signal. The environmental parameter data stream in the security data stream is subjected to dimensional uniformization conversion and threshold rationality verification to eliminate abrupt data points caused by instantaneous sensor failures and generate standardized environmental monitoring signals. For the structured parsed real-time video stream in the security data stream, visual feature vectors of personnel activity areas, equipment operating status areas, and material stacking areas in each frame of the image are extracted to generate a standardized visual feature stream. For the behavior log data stream in the security data stream, discrete operation action records are encoded into continuous operation sequence vectors, and the personnel position coordinates are mapped to a regional grid to generate a standardized behavior feature sequence. The clean equipment status signals, standardized environmental monitoring signals, standardized visual feature streams, and standardized behavioral feature sequences are aligned and spliced ​​according to a unified time series benchmark to form the standardized multi-dimensional safety feature sequence.

4. The enterprise production safety risk assessment and management system based on big data according to claim 1, characterized in that, The deployment of a security risk pattern recognition engine based on time-series correlation analysis performs rolling window scanning and deep pattern mining on the standardized multi-dimensional security feature sequences, outputting a set of potential risk events and risk pattern labels, including: Set an adjustable scrolling time window, continuously slide it on the standardized multi-dimensional security feature sequence, and extract feature data fragments within each window; Each of the feature data segments is input into a pre-trained risk pattern classification network, which consists of multiple layers of temporal convolutional kernels and attention mechanism layers, and is used to extract the temporal dependencies between features. The risk pattern classification network outputs the probability distribution of each feature data segment belonging to a predefined risk pattern. The predefined risk patterns include abnormal equipment wear pattern, environmental parameter exceeding the standard pattern, personnel violation operation pattern, and multi-factor coupled risk pattern. When the probability of a risk pattern corresponding to any of the aforementioned feature data segments exceeds a preset confidence threshold, a risk event alarm is triggered, and the start and end times, involved device identifiers, involved environmental areas, and involved personnel information corresponding to the feature data segments are recorded to constitute a risk event instance. All triggered risk event instances within the current rolling window period are aggregated and labeled with the dominant risk patterns identified by the risk pattern classification network to form the potential risk event set and the corresponding risk pattern labels.

5. The enterprise production safety risk assessment and management system based on big data according to claim 1, characterized in that, The aforementioned risk situation simulation model, based on a knowledge graph, is constructed. This model logically correlates and simulates the evolution of the situation with the set of potential risk events and a historical accident case database, generating a risk situation simulation report, including: The historical accident case database stores structured records of historical risk event chains, final accident consequences, and key causal nodes. Each risk event instance in the set of potential risk events is mapped to a corresponding entity node in the risk situation simulation model. The entity node types include equipment entities, environmental entities, personnel entities, and work activity entities. Based on the risk pattern label, activate the predefined risk propagation path connecting different entity nodes in the risk situation simulation model. The risk propagation path is defined by the accident causation logic rule. Using the set of potential risk events as initial input, the risk situation simulation model simulates the diffusion process of risk along the risk propagation path, and simulates the secondary risk event nodes that will be triggered and the final accident consequence type. The simulation process summarizes all risk event nodes, risk propagation paths, and final accident consequence types, generating a risk situation simulation report that includes the risk evolution chain, key risk nodes, and recommended intervention points.

6. The enterprise production safety risk assessment and management system based on big data according to claim 4, characterized in that, When the probability of a risk pattern corresponding to any of the aforementioned feature data segments exceeds a preset confidence threshold, a risk event alarm is triggered, including: Real-time monitoring of the risk pattern probability stream output by the risk pattern classification network; An independent confidence threshold is set for each of the predefined risk patterns, and the confidence threshold is dynamically adjusted based on the historical false positive rate and false negative rate; When the probability value of a certain predefined risk pattern in the risk pattern probability stream exceeds its corresponding confidence threshold for a duration that reaches a preset minimum duration, it is determined to be a valid alarm. When generating the effective alarm, the time point when the alarm is triggered, the snapshot of the feature vector in the relevant standardized multi-dimensional security feature sequence, and the change curve of the risk pattern probability flow are recorded simultaneously. The effective alerts, the time points, the feature vector snapshots, and the change curves are packaged together as the core content of the risk event instance.

7. The enterprise production safety risk assessment and management system based on big data according to claim 5, characterized in that, The process of simulating the diffusion of risk along the risk propagation path in the risk situation simulation model, using the set of potential risk events as initial input, and simulating the secondary risk event nodes to be triggered and the final accident consequence type, includes: Each risk event instance in the set of potential risk events is designated as an active source node in the risk situation simulation model; Based on the entity type of each active source node and the risk pattern label, retrieve all valid risk propagation paths in the knowledge graph that originate from the active source node; According to the weight and confidence of the path, each effective risk propagation path is traversed in turn, the entity node corresponding to the end point of the path is activated as a new secondary risk event node, and the conditions and time delay required for activation are recorded. Check whether newly activated secondary risk event nodes meet the criteria for determining accident consequence nodes. The criteria include node type, severity of risk status, and strength of association with other nodes. If the conditions are met, the accident consequence node is marked as the accident consequence node in this simulation, and the complete propagation chain from the active source node to the accident consequence node is back-recorded. All secondary risk event nodes obtained from the traversal, the deduced accident consequence nodes, and the complete propagation chain are incorporated into the simulation results.

8. The enterprise production safety risk assessment and management system based on big data according to claim 1, characterized in that, Based on the risk model labels and the risk situation simulation report, a closed-loop management instruction set is automatically generated, containing specific risk control measures and resource allocation recommendations, including: Analyze the risk pattern tags to determine the standard response template library corresponding to the current dominant risk pattern; Analyze the risk situation simulation report and extract information on key risk nodes and recommended intervention points; The key risk nodes and recommended intervention points are matched and instantiated with the measures items in the standard response template library to generate detailed risk control measures for specific equipment, specific areas or specific personnel. Based on the complexity and urgency of the risk evolution chain in the aforementioned risk situation simulation report, assess the required types, quantities, and response priorities of emergency resources; Based on the current available resources of the enterprise, the detailed risk control measures are subject to resource binding and scheduling planning to form an executable resource allocation recommendation; The detailed risk control measures are integrated with the resource allocation recommendations, and each is assigned a unique instruction number and execution time window to form a complete instruction in the closed-loop management instruction set.

9. The enterprise production safety risk assessment and management system based on big data according to claim 8, characterized in that, The process of matching and instantiating the key risk nodes and recommended intervention points with the measure items in the standard response template library to generate detailed risk control measures for specific equipment, specific areas, or specific personnel includes: Based on the entity type and risk pattern in the information of key risk nodes and recommended intervention points, a multi-level index search is performed in the standard response template library; A matching abstract measure template was found, which describes general action steps and objectives; Extract the specific device identifiers, specific area coordinates, or specific personnel identity information contained in the information of the key risk nodes and recommended intervention points; Replace the placeholder variables in the abstract measures template with the specific equipment identifier, specific area coordinates, or specific personnel identity information to transform the general steps into specific and operable action descriptions. Based on the risk propagation logic mentioned in the risk situation simulation report, preconditions for execution and the expected blocking effect are added to each action description to form the detailed rules of the risk control measures.

10. The enterprise production safety risk assessment and management system based on big data according to claim 1, characterized in that, The system also includes a secure data archiving and model optimization module; The security data archiving and model optimization module is used to: encrypt, compress, and associate the security data streams processed daily, the standardized multi-dimensional security feature sequences, the set of potential risk events, the risk situation simulation reports, and the execution feedback of the closed-loop management instruction set; The security data archiving and model optimization module is used to periodically perform incremental learning and optimization updates on the parameters of the dynamic data preprocessing pipeline, the risk pattern classification network in the security risk pattern recognition engine, and the risk propagation path weights in the risk situation inference model based on newly archived historical data.