Multi-agent large model security event cognition early warning system
By using a multi-agent cluster and a large model to collaboratively process multi-source security data, and combining edge computing and dual-mode communication, the problem of low data fusion and insufficient deep cognitive ability in existing systems has been solved, achieving efficient and accurate security event identification and real-time early warning.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHONGQING ZHONGXIN SECURITY SERVICE CO LTD
- Filing Date
- 2025-12-25
- Publication Date
- 2026-05-12
AI Technical Summary
Existing security early warning systems mostly use a single intelligent module to process multi-source security data, resulting in low data fusion and a lack of deep understanding of complex scenarios, making it impossible to effectively identify new types of security events outside the rules.
By employing a multi-agent cluster and a large model to collaboratively process multi-source data, and combining edge computing and dual-mode communication, the system leverages the deep cognitive capabilities of the large model to perform event identification and risk assessment, thereby enabling multi-channel early warning output.
It improves the utilization rate of data fusion, ensures the real-time and accuracy of data processing, reduces the false alarm and missed alarm rates, shortens the response time from early warning to handling, and provides efficient security support in complex scenarios.
Smart Images

Figure CN122024401A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a multi-agent large-model security event cognition and early warning system, which is located in the field of interdisciplinary technology of artificial intelligence and security technology. Specifically, it relates to a security event cognition and early warning system based on multi-agent collaboration and large-model cognitive capabilities, and is applicable to various complex security scenarios such as parks, transportation hubs, and large venues. Background Technology
[0002] Current security early warning systems have gradually shifted from traditional manual monitoring to intelligent monitoring. Mainstream products typically integrate video surveillance, infrared detection, and personnel identification hardware, combined with simple algorithm models to achieve basic anomaly detection functions. These systems use preset rules (such as area intrusion or excessive crowd density) to judge the collected security data, issuing an early warning signal when a preset threshold is triggered. They are widely used in shopping malls and factories. Some high-end systems have also introduced deep learning algorithms to improve the accuracy of target recognition, enabling preliminary identification of specific dangerous items and abnormal behaviors.
[0003] The following problems still exist with existing technologies:
[0004] 1. Existing systems mostly use a single intelligent module to process multi-source security data, which cannot achieve data classification, processing and collaborative analysis, resulting in low integration of multiple types of data such as video, audio and sensor data;
[0005] 2. The early warning logic of existing systems mostly relies on fixed rules or simple models, lacking a deep understanding of complex scenarios and unable to effectively identify new security events outside the rules. Summary of the Invention
[0006] The purpose of this invention is to provide a multi-agent large-model security event cognitive early warning system. By collaboratively processing multi-source data through multiple agents and combining the deep cognitive capabilities of the large model, it can achieve accurate identification and real-time early warning of security events, thereby solving the problems mentioned in the background art.
[0007] To solve the above-mentioned technical problems, the present invention is achieved through the following technical solution:
[0008] This invention is a multi-agent large-model security event cognition and early warning system, including a multi-agent cluster, a large-model core processing module, a data interaction module, and an early warning output module;
[0009] The multi-agent cluster and the large model core processing module communicate bidirectionally through the data interaction module, and the output of the large model core processing module is connected to the early warning output module.
[0010] The multi-agent cluster is configured to collect multi-source security data and perform preliminary preprocessing; the large model core processing module is configured to perform event recognition and risk assessment on the preprocessed security data; and the early warning output module is configured to generate and output early warning information based on the assessment results.
[0011] The multi-agent cluster includes a data-sensing agent, a data-transmitting agent, and a data-filtering agent.
[0012] The core processing module of the large model includes an event cognition engine, a risk assessment engine, and a model optimization unit.
[0013] The early warning output module includes a tiered early warning submodule and a multi-channel push submodule.
[0014] Furthermore, the data sensing agent is configured to collect video data, audio data, environmental sensing data, and personnel identity data; the data transmission agent is configured to transmit the collected data using an encrypted transmission protocol; and the data filtering agent is configured to remove redundant data and abnormal interference data.
[0015] Furthermore, the event recognition engine is configured to identify security event types and key features based on a pre-trained large model, the risk assessment engine is configured to calculate the risk level by combining historical event data with real-time scene parameters, and the model optimization unit is configured to update model parameters based on early warning feedback results.
[0016] Furthermore, the event cognition engine includes a feature extraction submodule and a semantic understanding submodule. The feature extraction submodule is configured to use deep learning algorithms to extract visual features, audio features, and text features from multi-source data. The semantic understanding submodule is configured to parse the semantic information of abnormal behavior descriptions and dangerous goods identification.
[0017] Furthermore, the graded early warning submodule is configured to divide early warning information into three levels: Level 1 Emergency, Level 2 Important, and Level 3 Attention. The multi-channel push submodule is configured to simultaneously push early warning information through security terminals, mobile apps, SMS messages, and audible and visual alarms.
[0018] Furthermore, it also includes a human-computer interaction module, which is connected to the core processing module of the large model and is configured to receive human intervention commands and correct and confirm the warning results.
[0019] Furthermore, the risk assessment engine adopts a weighted scoring algorithm, and the weight parameters include the urgency of the event, the scope of impact, the probability of occurrence, and the historical difficulty of handling it. The weight of each parameter can be dynamically adjusted according to the type of security scenario.
[0020] Furthermore, the data-sensing intelligent agent includes a high-definition camera, a microphone, an infrared sensor, a metal detector, and a facial recognition terminal. Each sensing device performs preliminary local data processing through an edge computing unit.
[0021] Furthermore, the data interaction module supports dual-mode communication of 5G and WiFi 6, and is set to automatically switch to local caching mode when the network is interrupted, and synchronize the data to the large model core processing module after the network is restored.
[0022] Furthermore, the edge computing unit is configured to perform real-time target detection on video data, and only transmit video segments containing abnormal targets to the large model core processing module, thereby reducing the amount of data transmission.
[0023] The present invention has the following beneficial effects:
[0024] (1) This invention uses the division of labor and cooperation of multiple intelligent agents to classify and collect different types of data such as video, audio and environmental sensing, and process them in a special way, effectively breaking down data silos, improving the data fusion and utilization rate, and solving the problem of single data processing in existing systems.
[0025] (2) The present invention performs local preliminary screening of data through edge computing units, transmits only valid data to the core processing module, and combines dual-mode communication and caching mechanisms to reduce data transmission pressure, ensure the real-time performance of data processing, and alleviate the problem of long data processing links in existing systems.
[0026] (3) The event cognition engine of the core processing module of the large model of the present invention combines feature extraction and semantic understanding technology, which can identify new security events outside the preset rules, realize in-depth cognition of security events, and solve the defect that the event recognition of the existing system is limited to fixed rules.
[0027] (4) The risk assessment engine of this invention combines multi-dimensional parameters to dynamically calculate the risk level. The graded early warning mechanism can push early warning information in a targeted manner, reduce interference from invalid early warnings, reduce false alarms and missed alarms, and improve the accuracy of early warnings.
[0028] (5) The present invention combines multi-channel early warning push with human-computer interaction module to ensure that security personnel can quickly receive and confirm early warning information and take disposal measures, shorten the disposal cycle from early warning to response, and solve the problem of untimely disposal caused by the lag in early warning in the existing system.
[0029] (6) Through the collaborative division of labor among multiple agents and the deep cognitive capabilities of large models, this invention enables efficient processing of security data from collection to early warning, improves the accuracy of security event identification and the real-time nature of early warning, and provides reliable technical support for security work in complex scenarios.
[0030] (7) Through the collaborative division of labor among multiple agents and the deep cognitive ability of large models, this invention enables efficient processing of security data from collection to early warning, improves the accuracy of security event identification and the real-time nature of early warning, and provides reliable technical support for security work in complex scenarios.
[0031] Of course, any product implementing this invention does not necessarily need to achieve all of the advantages described above at the same time. Attached Figure Description
[0032] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0033] Figure 1 This is a diagram of the overall architecture of the present invention. Detailed Implementation
[0034] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0035] Please see Figure 1 As shown, the present invention is a multi-agent large model security event cognition and early warning system, including a multi-agent cluster, a large model core processing module, a data interaction module and an early warning output module;
[0036] The multi-agent cluster and the large model core processing module communicate bidirectionally through the data interaction module. The output of the large model core processing module is connected to the early warning output module. The data interaction module supports dual-mode communication of 5G and WiFi 6. It is set to automatically switch to local caching mode when the network is interrupted and synchronize the data to the large model core processing module after the network is restored. The edge computing unit is set to perform real-time target detection on video data and only transmit video clips containing abnormal targets to the large model core processing module to reduce the amount of data transmission.
[0037] The multi-agent cluster is set to collect multi-source security data and perform preliminary preprocessing. The core processing module of the large model is set to perform event recognition and risk assessment on the preprocessed security data. The early warning output module is set to generate and output early warning information based on the assessment results.
[0038] The multi-agent cluster includes a data sensing agent, a data transmission agent, and a data filtering agent. The data sensing agent is configured to collect video data, audio data, environmental sensor data, and personnel identity data. The data transmission agent is configured to transmit the collected data using an encrypted transmission protocol. The data filtering agent is configured to remove redundant data and abnormal interference data. The data sensing agent includes a high-definition camera, a microphone, an infrared sensor, a metal detector, and a face recognition terminal. Each sensing device performs preliminary local data processing through an edge computing unit.
[0039] The core processing module of the large model includes an event recognition engine, a risk assessment engine, and a model optimization unit. The event recognition engine is designed to identify security event types and key features based on a pre-trained large model. The risk assessment engine is designed to calculate the risk level by combining historical event data with real-time scene parameters. The model optimization unit is designed to update model parameters based on early warning feedback results. The event recognition engine includes a feature extraction submodule and a semantic understanding submodule. The feature extraction submodule is designed to extract visual, audio, and text features from multi-source data using deep learning algorithms. The semantic understanding submodule is designed to parse the semantic information of abnormal behavior descriptions and dangerous goods identification. The risk assessment engine uses a weighted scoring algorithm. The weight parameters include the urgency of the event, the scope of impact, the probability of occurrence, and the historical difficulty of handling it. The weights of each parameter can be dynamically adjusted according to the type of security scenario.
[0040] The early warning output module includes a tiered early warning submodule and a multi-channel push submodule. The tiered early warning submodule is configured to classify early warning information into three levels: Level 1 Emergency, Level 2 Important, and Level 3 Attention. The multi-channel push submodule is configured to simultaneously push early warning information through security terminals, mobile apps, SMS, and audible and visual alarms.
[0041] It also includes a human-computer interaction module, which is connected to the core processing module of the large model and is set to receive human intervention instructions and correct and confirm the warning results.
[0042] It should be noted that through the division of labor and collaboration of a multi-agent cluster, different types of data such as video, audio, and environmental sensing are collected and processed in a classified and specialized manner, effectively breaking down data silos, improving data fusion and utilization, and solving the problem of single data processing in existing systems. Edge computing units perform preliminary local screening of data, transmitting only valid data to the core processing module. Combined with dual-mode communication and caching mechanisms, this reduces data transmission pressure, ensures real-time data processing, and alleviates the problem of long data processing links in existing systems. The event recognition engine of the large model's core processing module, combining feature extraction and semantic understanding technologies, can identify new types of security events outside of preset rules, achieving deep understanding of security events and overcoming the limitation of existing systems' event recognition being restricted to fixed rules. The risk assessment engine dynamically calculates risk levels based on multi-dimensional parameters, and the tiered early warning mechanism can push targeted alerts. This system improves early warning accuracy by reducing invalid warning interference, lowering false alarm and missed alarm rates, and combining multi-channel early warning push with a human-computer interaction module. This ensures security personnel can quickly receive and confirm early warning information and take appropriate measures, shortening the response cycle from warning to action. It solves the problem of untimely response caused by delayed early warnings in existing systems. Through the collaborative division of labor among multiple intelligent agents and the deep cognitive capabilities of a large model, this system achieves efficient processing of security data from collection to early warning, improving the accuracy of security event identification and the real-time nature of early warnings. This provides reliable technical support for security work in complex scenarios.
[0043] The first stage is data collection and preprocessing: Data sensing agents collect corresponding types of security data according to their division of labor, such as high-definition cameras collecting video data, infrared sensors collecting environmental data, and facial recognition terminals collecting personnel identity data. The data collected by each sensing device is first transmitted to the local edge computing unit, where the data filtering agent removes redundant data such as blurry videos and invalid sensor signals, retaining only the data containing potential abnormal information. The data transmission agent uses an encryption protocol to transmit the preprocessed data to the core processing module of the large model via a 5G or WiFi 6 network. When the network is interrupted, it automatically switches to local caching mode and completes data synchronization after the network is restored.
[0044] The second stage is event recognition and risk assessment: The event recognition engine of the core processing module of the large model performs in-depth processing on the received data. The feature extraction submodule uses convolutional neural networks to extract target features from videos and Mel-frequency cepstral coefficients to extract audio features. The semantic understanding submodule analyzes semantic information such as personnel dialogue and abnormal sounds, and combines the knowledge reserves of the pre-trained large model to identify the type and key features of security events. The parameter weighting module of the risk assessment engine calculates a comprehensive score by combining dynamic weight parameters such as the urgency of the event and the scope of its impact. The level determination module divides the event into three warning levels based on the score. If there is a manual intervention instruction, the human-computer interaction module synchronizes the instruction to the risk assessment engine to correct the warning result.
[0045] The third stage is early warning output and model optimization: The early warning output module pushes early warning information to the corresponding security personnel through multiple channels according to the early warning level, including the event type, location, risk level, and on-site data; the security personnel provide feedback on the handling results through the human-computer interaction module, and the model optimization unit collects the early warning results and handling feedback data, and updates the parameters of the large model using incremental training to improve the accuracy of subsequent event cognition and risk assessment; all data is stored in the data storage module to provide data support for historical event tracing and model optimization.
[0046] The present invention also provides the following embodiments for further detailed description:
[0047] Example 1
[0048] For security scenarios in industrial parks, multiple functional areas including production workshops, warehouses, office areas, and hazardous materials storage areas were selected. The security focus was on unauthorized entry by personnel, unauthorized handling of hazardous materials, fire hazards, and abnormal equipment operation.
[0049] The system is deployed in this scenario as follows: In terms of data perception intelligence, infrared sensors and vibration sensors are deployed around the perimeter of the hazardous materials storage area; facial recognition terminals and metal detectors are installed at the warehouse entrance; high-definition cameras and temperature sensors are deployed in the production workshop; and microphones are installed in the office corridor. Edge computing nodes are divided according to functional areas, with one edge computing server deployed in each area to achieve real-time filtering of temperature data and personnel entry and exit data for that area. The core server is deployed in the park's security control center, equipped with a large model core processing module finely adjusted by industrial scenario data, and presets core early warning rules for unauthorized personnel staying in the hazardous materials storage area and workshop temperatures exceeding 60°C.
[0050] In actual operation, when the temperature sensor in the production workshop detects a temperature of 62℃, the edge computing node initially judges it as abnormal data and transmits it to the core processing module of the large model through encrypted data transmission agent. The event recognition engine extracts the temperature data features and combines them with the equipment operation images captured by cameras in the same area to identify the abnormal situation of blocked heat dissipation vents. The risk assessment engine, combined with the parameters that there are 20 workers in the workshop and the distance to the hazardous materials storage area is 300 meters, calculates the risk level as Level 2 Important. The early warning output module immediately pushes the early warning information to the workshop security post terminal and the security personnel's mobile APP, and at the same time triggers the audible and visual alarms in the workshop. The human-machine interaction module allows security personnel to issue an instruction to stop equipment operation after confirming the early warning. The model optimization unit records the results of this event processing and updates the correlation identification parameters between temperature anomalies and equipment failures.
[0051] Example 2
[0052] For security scenarios at large transportation hubs, such as high-speed rail stations with complex areas including waiting halls, ticket gates, parking lots, and transfer passages, the security focus is on the risk of stampedes due to overcrowding, carrying dangerous items, suspected terrorist acts, and missing persons.
[0053] The system is deployed in this scenario as follows: In terms of data perception intelligence, high-definition cameras are arranged at 5-meter intervals on the ceiling of the waiting hall to achieve coverage without blind spots; facial recognition terminals and ID card verification equipment are integrated at the ticket gates; crowd density sensors are installed in the transfer channels; and license plate recognition and infrared cameras are deployed in the parking lot. Edge computing nodes are divided by floor, with two edge computing servers deployed on each floor to process video data and sensor data respectively. The core server is deployed in the transportation hub security command center, equipped with a large model core processing module that integrates passenger flow analysis algorithms, and optimizes risk assessment parameters by combining historical security event data of the transportation hub.
[0054] In actual operation, when the crowd density sensor in a certain area of the waiting hall detects that there are 8 people per square meter, the edge computing node synchronously transmits the real-time video clips and passenger flow data of that area to the core processing module of the large model. The event recognition engine identifies abnormal behavior such as slow crowd movement and signs of pushing through video analysis, while the semantic understanding submodule simultaneously analyzes the cries for help collected by the on-site microphone. The risk assessment engine, combined with the parameters that the area has a capacity limit of 5 people per square meter and is 100 meters away from the nearest security post, calculates the risk level as Level 1 Emergency. The early warning output module immediately pushes the early warning information to the command center's large screen, and at the same time sends an emergency warning with location to the mobile apps of 3 security personnel around the area. It also links the waiting hall's broadcast system to play evacuation notices. The human-computer interaction module allows command center personnel to view the on-site scene in real time and issue evacuation instructions. The entire early warning response process takes no more than 3 seconds.
[0055] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.
Claims
1. A multi-agent large-scale model security event cognitive early warning system, characterized in that, It includes a multi-agent cluster, a large model core processing module, a data interaction module, and an early warning output module; The multi-agent cluster and the large model core processing module communicate bidirectionally through the data interaction module, and the output of the large model core processing module is connected to the early warning output module. The multi-agent cluster is configured to collect multi-source security data and perform preliminary preprocessing; the large model core processing module is configured to perform event recognition and risk assessment on the preprocessed security data; and the early warning output module is configured to generate and output early warning information based on the assessment results. The multi-agent cluster includes a data-sensing agent, a data-transmitting agent, and a data-filtering agent. The core processing module of the large model includes an event cognition engine, a risk assessment engine, and a model optimization unit. The early warning output module includes a tiered early warning submodule and a multi-channel push submodule.
2. The multi-agent large-scale model security event cognitive early warning system according to claim 1, characterized in that, The data sensing agent is configured to collect video data, audio data, environmental sensor data, and personnel identity data. The data transmission agent is configured to transmit the collected data using an encrypted transmission protocol. The data filtering agent is configured to remove redundant data and abnormal interference data.
3. The multi-agent large-scale model security event cognitive early warning system according to claim 1, characterized in that, The event recognition engine is configured to identify security event types and key features based on a pre-trained large model; the risk assessment engine is configured to calculate risk levels by combining historical event data with real-time scene parameters; and the model optimization unit is configured to update model parameters based on early warning feedback results.
4. The multi-agent large-scale model security event cognitive early warning system according to claim 3, characterized in that, The event cognition engine includes a feature extraction submodule and a semantic understanding submodule. The feature extraction submodule is configured to use deep learning algorithms to extract visual features, audio features and text features from multi-source data. The semantic understanding submodule is configured to parse the semantic information of abnormal behavior descriptions and dangerous goods identification.
5. The multi-agent large-scale model security event cognitive early warning system according to claim 1, characterized in that, The graded early warning submodule is configured to classify early warning information into three levels: Level 1 Emergency, Level 2 Important, and Level 3 Attention. The multi-channel push submodule is configured to simultaneously push early warning information through security terminals, mobile apps, SMS, and audible and visual alarms.
6. The multi-agent large-scale model security event cognitive early warning system according to claim 1, characterized in that, It also includes a human-computer interaction module, which is connected to the core processing module of the large model and is configured to receive human intervention instructions and correct and confirm the warning results.
7. The multi-agent large-scale model security event cognitive early warning system according to claim 3, characterized in that, The risk assessment engine uses a weighted scoring algorithm. The weight parameters include the urgency of the event, the scope of impact, the probability of occurrence, and the historical difficulty of handling it. The weight of each parameter can be dynamically adjusted according to the type of security scenario.
8. The multi-agent large-scale model security event cognitive early warning system according to claim 2, characterized in that, The data sensing intelligent agent includes a high-definition camera, a microphone, an infrared sensor, a metal detector, and a facial recognition terminal. Each sensing device performs preliminary local data processing through an edge computing unit.
9. The multi-agent large-scale model security event cognitive early warning system according to claim 1, characterized in that, The data interaction module supports dual-mode communication of 5G and WiFi 6, and is set to automatically switch to local caching mode when the network is interrupted, and synchronize the data to the core processing module of the large model after the network is restored.
10. A multi-agent large-scale model security event cognitive early warning system according to claim 8, characterized in that, The edge computing unit is configured to perform real-time target detection on video data, and only transmit video clips containing abnormal targets to the large model core processing module to reduce the amount of data transmission.