Multi-factor fusion risk behavior early warning method and system

By unifying the processing of multi-source abnormal data and managing early warning positions, the problem of distinguishing the qualifications of abnormal signals in the early warning of multi-factor fusion dangerous behavior has been solved, enabling orderly competition and reliable upgrades, and improving the consistency and stability of the early warning system.

CN122050117BActive Publication Date: 2026-07-10LONGYAN UNIV

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
LONGYAN UNIV
Filing Date
2026-04-15
Publication Date
2026-07-10

Smart Images

  • Figure CN122050117B_ABST
    Figure CN122050117B_ABST
Patent Text Reader

Abstract

The application discloses a multi-factor fusion dangerous behavior early warning method and system, and particularly relates to the technical field of dangerous behavior early warning, which comprises the following steps: acquiring multi-source abnormal data for a target object or a target area in the same early warning period, extracting an abnormal time, an abnormal position, an abnormal category and a change direction, and generating an abnormal event set; reading the abnormal event set, and sequentially comparing the abnormal position, the abnormal category and the change direction of each abnormal event according to the abnormal time. The abnormal event is further written into a trigger event, a support event, an exclusion event, an escalation event and a release event, and the entering qualifications of different abnormal signals are distinguished according to the events, so that weak evidence, conflicting evidence and escalation evidence are no longer directly triggered in the same position. Therefore, the application helps to realize the orderly competition, progressive release and credible escalation of multi-theme early warning in the same object or area, and relatively alleviates the problems of early warning sequence disorder and insufficient result credibility.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of dangerous behavior early warning technology, and more specifically, to a dangerous behavior early warning method and system that integrates multiple factors. Background Technology

[0002] In the field of dangerous behavior early warning, the mainstream practice in the industry is to solve the problem of whether abnormal behavior on site can be identified in a timely manner and trigger the corresponding alarm. This usually involves accessing multiple signals such as video surveillance, door magnets, infrared, smoke detectors, positioning, electronic fences and equipment status, and performing threshold judgment, rule matching or multi-condition linkage on various anomalies, and outputting corresponding early warning results when the preset combination conditions are met.

[0003] Taking the complex scenario of personnel accidentally entering restricted areas, staying for a long time, abnormal gathering, and abnormal behavior accompanied by environmental abnormalities in factory areas, industrial parks, or construction areas as an example, the system not only needs to output warning content under the conditions of continuous online multi-source perception, concurrent occurrence of abnormal types, and inconsistent arrival order of different signals, but also must meet the hard constraint that multiple types of abnormalities in the same area can be identified in parallel, the warning results can be upgraded step by step, and the false triggering and spread can be avoided.

[0004] However, under this constraint, the mainstream approach will consistently expose a key flaw: weak evidence will trigger strong alarms first, subsequent stronger evidence will not effectively improve existing warnings, and multiple conflicting alarms will repeatedly pop up for the same object or area in a short period of time. The reason is that the existing solutions usually assume that different abnormal inputs have similar or even the same decision-making qualifications, without distinguishing which abnormal signals can directly enter the warning decision, which can only be used as corroborating evidence, and which must wait for further confirmation. As a result, although the number of warnings increases, it is difficult to guarantee the release order, escalation logic and the credibility of the results.

[0005] The technical problem this application aims to solve is: how to effectively distinguish the early warning qualifications of different abnormal signals in the process of early warning of dangerous behaviors fused by multiple factors, and to achieve orderly competition, progressive release and reliable upgrading of early warnings for multiple themes in the same object or area. Summary of the Invention

[0006] To overcome the aforementioned deficiencies of the prior art, embodiments of the present invention provide a multi-factor fusion-based dangerous behavior early warning method and system. By uniformly writing multi-source abnormal data into abnormal events, and performing early warning qualification division, early warning seat occupancy, and progressive update of topic status around the abnormal events, the method achieves orderly competition, progressive release, and reliable upgrade of different abnormal signals in the same object or region, thereby solving the problems mentioned in the background art.

[0007] To achieve the above objectives, the present invention provides the following technical solution: a multi-factor fusion method for early warning of dangerous behaviors, comprising:

[0008] S1. Obtain multi-source abnormal data for the target object or target area within the same early warning period, extract the abnormal time, abnormal location, abnormal category and change direction, and generate an abnormal event set;

[0009] S2. Read the abnormal event set, compare the abnormal location, abnormal category and change direction of each abnormal event in sequence according to the abnormal time, and write the comparison results as trigger event, support event, exclusion event, escalation event or cancellation event to generate a qualified event set;

[0010] S3. Read the eligibility event set, group it according to the target object identifier or region identifier, and write the first triggering event in each group into the corresponding warning seat as the current topic, and generate the seat result;

[0011] S4. Read the seat results and write the supporting events, exclusion events, escalation events and deactivation events of the same warning seat, perform evidence appending, topic deletion, level updating and end marker writing, and generate status results;

[0012] S5. Read the status results, output the in-process warning, upgraded warning or deactivated warning corresponding to the current topic according to the warning position, and generate the dangerous behavior warning results.

[0013] In a preferred embodiment, S1 includes:

[0014] S1-1. Obtain multi-source abnormal data within the same early warning period, extract the reporting time, source location, abnormal marker, and two consecutive status values ​​of each source data, and generate a source record set;

[0015] S1-2. Read the source record set, convert the reporting time of each source data into the abnormal time, convert the source location into the abnormal location, write the abnormal mark as the abnormal category, and write the direction of change according to the increase, decrease or no change of the state value before and after, and generate a standard record set.

[0016] S1-3. Read the standard record set, merge the standard records with the same abnormal time and overlapping abnormal location into an abnormal event, and write the corresponding abnormal time, abnormal location, abnormal category and change direction into the abnormal event to generate an abnormal event set.

[0017] In a preferred embodiment, S2 includes:

[0018] S2-1. Read the abnormal event set, arrange each abnormal event in ascending order according to the abnormal time, and take each abnormal event as the central event. Extract subsequent abnormal events within the continuous warning period, and write each subsequent abnormal event into the corresponding position chain according to the relationship of the same, adjacent or contained abnormal position to generate a position chain set.

[0019] S2-2. Read the location chain set, and write each abnormal event in each location chain into the same type sub-chain, opposite type sub-chain and extended sub-chain according to the abnormality category. Calculate the time interval, position offset direction and direction continuation result of two adjacent abnormal events in sequence according to the abnormal time, and generate a chain relationship set. The direction continuation result is recorded as continuation if the change direction of two adjacent abnormal events is the same, reversal if the change direction is opposite, and interruption otherwise.

[0020] In a preferred embodiment, S2 further includes:

[0021] S2-3. Read the chain relationship set, perform cross-determination on each chain position, write the first abnormal event in the same sub-chain as a candidate trigger point, write the abnormal events located after the candidate trigger point and whose direction continuation result is continuation into the support sequence, write the abnormal events in the opposite sub-chain whose abnormal time falls between the first and last time of the support sequence into the conflict sequence, write the abnormal events in the extended sub-chain whose abnormal position expands outward along the same position offset direction into the upgrade sequence, and write the abnormal events in the same sub-chain whose direction continuation result is reversed and located after the support sequence into the release sequence, and generate a candidate relationship set.

[0022] In a preferred embodiment, S2 further includes:

[0023] S2-4. Read the candidate relation set, and for each candidate trigger point, count the number of abnormal events in the support sequence, the number of abnormal events in the conflict sequence, the number of abnormal events in the upgrade sequence, and the number of abnormal events in the deactivation sequence. When the number of abnormal events in the support sequence is greater than the number of abnormal events in the conflict sequence, write a gating token to the candidate trigger point. When the number of abnormal events in the upgrade sequence is greater than zero, write an upgrade lock to the candidate trigger point. When the abnormal time of the first abnormal event in the deactivation sequence is later than the abnormal time of the last abnormal event in the support sequence, write an unlock to the candidate trigger point and generate a gating result set.

[0024] S2-5. Read the gating result set, write the candidate trigger points written to the gating token as trigger events, write the abnormal events written to the gating token and located in the support sequence as support events, write the abnormal events not written to the gating token and located in the conflict sequence as exclusion events, write the abnormal events written to the upgrade lock as upgrade events, write the abnormal events written to the unlock lock as unlock events, and merge the trigger events, support events, exclusion events, upgrade events and unlock events to generate a qualification event set.

[0025] In a preferred embodiment, S3 includes:

[0026] S3-1. Read the qualification event set, group each qualification event according to the same target object identifier or the same region identifier, and sort the trigger events, support events, exclusion events, upgrade events and release events in each group in ascending order of the time of the exception, and generate a seat group set;

[0027] S3-2. Read the seat group set, extract the anomaly type, anomaly time and anomaly location of the first triggered event for each group, write the anomaly type as the current topic, write the anomaly time as the placeholder time, write the anomaly location as the topic location, and establish the warning seat corresponding to the group to generate the initial seat set.

[0028] S3-3. Read the initial seat set, write the target object identifier or region identifier, current topic, occupancy time and topic position of each warning seat into the corresponding seat record, and generate the seat result.

[0029] In a preferred embodiment, S4 includes:

[0030] S4-1. Read the seat results and write the supporting events, exclusion events, escalation events and deactivation events of the same warning seat. Sort the supporting events, exclusion events, escalation events and deactivation events in ascending order according to the time of the anomaly, and write each event sequentially into the topic processing sequence of the corresponding warning seat to generate a seat sequence set.

[0031] S4-2. Read the seat sequence set, and execute the event processing of each warning seat's topic processing sequence in sequence according to the abnormal time. When a supporting event is read, write the supporting event into the evidence sequence of the current topic. When an exclusion event is read, write the deletion mark into the current topic. When an escalation event is read, write the abnormal category of the escalation event into the level record of the current topic. When a cancellation event is read, write the abnormal time of the cancellation event into the end mark of the current topic, and generate a seat status set.

[0032] S4-3. Read the seat status set, write the current topic, evidence sequence, deletion mark, level record and end mark of each warning seat into the corresponding seat status record, and generate the status result.

[0033] In a preferred embodiment, S5 includes:

[0034] S5-1. Read the status results, extract the current topic, evidence sequence, deletion mark, level record and end mark according to the warning position, and sort the position status records corresponding to each warning position in ascending order according to the abnormal time, and generate the output queue.

[0035] S5-2. Read the output queue, and sequentially determine the write status of the deletion mark, level record and end mark for each seat status record. Write the current topic with an empty deletion mark and an empty end mark as an in-process warning, write the current topic with an empty deletion mark and an updated level record as an escalation warning, and write the current topic with an empty deletion mark and an already written end mark as a de-escalation warning, and generate a warning type set.

[0036] In a preferred embodiment, S5 further includes:

[0037] S5-3. Read the warning type set, and write the topic content of each current topic, the first abnormal moment in the corresponding evidence sequence, the current level in the level record, and the end moment in the end marker into the corresponding warning type to generate a warning record set;

[0038] S5-4. Read the warning record set, merge the corresponding ongoing warnings, upgraded warnings, or deactivated warnings according to the warning position, and write the merged result as the dangerous behavior warning result.

[0039] A multi-factor integrated early warning system for dangerous behaviors includes:

[0040] The event generation module is used to acquire multi-source abnormal data for a target object or target area within the same early warning period, extract the abnormal time, abnormal location, abnormal category and change direction, and generate an abnormal event set;

[0041] The qualification determination module is used to read the abnormal event set, compare the abnormal location, abnormal category and change direction of each abnormal event in sequence according to the abnormal time, and write the comparison results as trigger event, support event, exclusion event, escalation event or cancellation event to generate a qualification event set;

[0042] The seat creation module is used to read the set of eligibility events, group them according to the target object identifier or region identifier, and write the first triggering event in each group into the corresponding warning seat as the current topic to generate seat results;

[0043] The status update module is used to read the seat results and write supporting events, exclusion events, escalation events and deactivation events for the same warning seat, perform evidence appending, topic deletion, level updating and end marker writing, and generate status results;

[0044] The early warning output module is used to read the status results and output the in-progress warning, upgraded warning, or deactivated warning corresponding to the current topic according to the warning position, and generate warning results for dangerous behavior.

[0045] The technical effects and advantages of this invention are as follows:

[0046] 1. By further classifying abnormal events into triggering events, supporting events, exclusion events, escalation events, and deactivation events, and distinguishing the entry qualifications of different abnormal signals accordingly, weak evidence, conflicting evidence, and escalation evidence no longer directly trigger alarms with the same status. This helps to achieve orderly competition, progressive release, and credible escalation of multi-theme early warnings in the same object or area, and relatively alleviates the problems of chaotic early warning order and insufficient credibility of results.

[0047] 2. By establishing a location chain for abnormal events and dividing it into similar sub-chains, anti-similar sub-chains, and extended sub-chains, and then combining the supporting sequence, conflict sequence, escalation sequence, and resolution sequence to perform cross-judgment, the formation, conflict, expansion, and termination processes of dangerous topics can be continuously identified, thereby relatively improving the ability to characterize the evolution process of dangerous behavior in complex scenarios.

[0048] 3. By writing gating tokens, upgrading locks, and unlocking locks to candidate trigger points, and using the relationship between effective supporting events and effective conflicting events as the basis for release, the triggering, upgrading, and unlocking no longer depend on a single anomaly or a single matching result. This helps to relatively suppress the problem of weak evidence triggering strong alarms in advance and the repeated fluctuations of the same topic.

[0049] 4. By grouping eligible events according to target object identifiers or area identifiers, and having the first triggering event occupy the corresponding warning position to form the current theme, subsequent support, exclusion, escalation and resolution events of the same object or area are continuously processed around the same theme, which helps to relatively reduce the situation of repeated conflicting alarms popping up in a short period of time.

[0050] 5. By performing evidence addition, topic deletion, level update, and end marker writing in a fixed order within the early warning position, the establishment, escalation, and end boundaries of the current topic have continuous status records, thereby relatively improving the coherence of the early warning processing chain and providing traceable evidence for subsequent differentiation between in-process early warnings, upgraded early warnings, and de-escalated early warnings.

[0051] 6. By determining the warning type and merging the results according to the warning position, and determining the final output type based on the priority relationship of deletion markers, end markers and level records, the same topic has a clear release order and result attribution in the output stage, which helps to relatively improve the output stability and result consistency in multi-content warning scenarios. Attached Figure Description

[0052] Figure 1 This is a flowchart of the method steps of the present invention.

[0053] Figure 2 This is a system module diagram of the present invention. Detailed Implementation

[0054] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0055] Refer to the instruction manual appendix Figure 1-2 The multi-factor fusion-based dangerous behavior early warning method of the present invention includes:

[0056] S1. Obtain multi-source abnormal data for the target object or target area within the same early warning period, extract the abnormal time, abnormal location, abnormal category and change direction, and generate an abnormal event set;

[0057] In this implementation, S1 is used to organize abnormal data from different sources, with different field formats, and different reporting rhythms into a unified abnormal event set for subsequent processing, so that subsequent qualification determination, early warning seat establishment, and status updates are all based on a unified data expression. This process first extracts fields from the original abnormal records uploaded from each source, then performs unified conversion on time, location, category, and direction, and finally merges and writes standard records within the same time slice and the same area, thereby eliminating differences in time, location, and abnormal expression between different sources, and providing consistent input for subsequent continuous determination of the positional, category, and change relationships between abnormal events. This process includes the following steps:

[0058] In S1-1, the system receives multi-source abnormal data within the same warning cycle and reads each received raw abnormal data as a source data to be processed sequentially. The multi-source abnormal data includes at least two of the following: video analysis source, access control source, positioning source, environmental sensing source, device status source, or manually triggered source. For each source data, the system first reads its source identifier and reporting time field, and writes the reporting time field as the reporting time. Then, it reads the location field corresponding to the source identifier and writes the camera field of view number, door number, positioning point, sensor installation point, or device installation point as the source location. Finally, it reads the... The original flag of the abnormal state is written as the abnormal flag; for continuously sampled data, the current sampled value and the previous sampled value are read as the two consecutive state values; for state switching data, the current state code and the previous state code are read as the two consecutive state values; if the current source data does not carry the previous state value, the previous state value is retrieved from the previous cached record corresponding to the same source identifier and paired with the current value and written; after completing the above field extraction, the source identifier, reporting time, source location, abnormal flag, and the two consecutive state values ​​are written as the corresponding source record, and all source records generated within the same warning period are sequentially written into the source record set;

[0059] In S1-2, the system reads each source record from the source record set and performs a unified conversion on the reporting time, source location, anomaly marker, and two consecutive state values ​​in each source record. For the reporting time, if the source record carries the event occurrence time, the event occurrence time is directly written as the anomaly time; if the source record does not carry the event occurrence time, the reporting time is written as the anomaly time. If the same source identifier consistently exhibits a fixed late reporting phenomenon in multiple consecutive warning cycles, the stable delay amount is read from the delay record corresponding to that source identifier, and the reporting time is subtracted from this stable delay amount before being written as the anomaly time. For the source location, the system looks up the corresponding location mapping relationship based on the source identifier, uniformly converts the camera field of view number, gate number, positioning point coordinates, equipment installation point number, or sensor installation point number into a region code, and writes this region code as the anomaly location, thus ensuring that subsequent "same location" entries are correct. The determination of "adjacent location", "containment location", and "extension location" are all based on the same location expression. For anomaly markers, the system writes the original marker as the anomaly category according to the correspondence between anomaly markers and anomaly categories. Original markers from different sources are allowed to be mapped to the same anomaly category so as to form similar relationships later. For two consecutive state values, if the two consecutive state values ​​are consecutive values, the current value is compared with the previous value. If the current value is greater than the previous value, it is written as "enhanced"; if the current value is less than the previous value, it is written as "weakened"; if the current value is equal to the previous value, it is written as "maintained". If the two consecutive state values ​​are state codes, the change from no anomaly to anomaly is written as "enhanced", the change from anomaly to no anomaly is written as "weakened", and the unchanged state is written as "maintained". After the conversion is completed, the anomaly time, anomaly location, anomaly category and change direction are written into the corresponding standard record, and all standard records are written into the standard record set.

[0060] In S1-3, the system reads the standard record set and first sorts all standard records in ascending order by the time of the anomaly. Then, standard records with the same anomaly time and overlapping anomaly positions are grouped into the same merge group. The criteria for determining the same anomaly time is falling into the same time slice, where the time slice is the smallest aligned time unit further subdivided within a warning period. The criteria for overlapping anomaly positions is that the corresponding standard records have the same area code. For each merge group, the system extracts the anomaly time, anomaly position, anomaly category, and direction of change for all standard records within the group. The time corresponding to the time slice of the group is written as the anomaly time, and the area code corresponding to the group is written as the anomaly position. When the exception categories of standard records within a group are the same, the exception category is directly written into the exception event; when the exception categories of standard records within a group are different, the first exception category is written as the primary category in the order of appearance, and the remaining exception categories are written as secondary categories; when the change directions of standard records within a group are consistent, the change direction is directly written into the exception event; when the change directions of standard records within a group are inconsistent, the first change direction is written into the exception event, and a direction mixing flag is also written at the same time; after the field merging within the group is completed, the system writes the exception time, exception location, exception category, and change direction into a single exception event, and writes all exception events sequentially into the exception event set;

[0061] Through the above processing, multi-source anomaly data is organized into an anomaly event set with unified field structure, time caliber, location caliber, category caliber, and direction caliber. This allows subsequent steps to directly perform time-series comparison, location chain establishment, category chain division, and qualification event writing around the anomaly events, avoiding interruptions in the subsequent processing chain due to inconsistencies in the caliber of data from different sources. Simultaneously, by performing merged writing based on time slices and region codes, multi-source anomalies within the same time slice and region are no longer split into multiple isolated input items, which helps improve the continuity and stability of subsequent qualification determination. In practical applications: taking a restricted area early warning scenario in a factory area as an example, within a certain early warning period, The video analysis source identifies personnel crossing the warning line, the access control source reports an abnormal door opening, and the positioning source reports that the personnel's location point has entered a restricted area. The system first extracts the reporting time, source location, anomaly marker, and the status values ​​before and after the three types of source data to generate corresponding source records. Then, it converts the camera field of view number, door number, and positioning point coordinates into the same area code, converts the three types of original markers into corresponding anomaly categories, and writes the corresponding status changes as enhancement directions to generate standard records. Subsequently, standard records that fall in the same time slice and have the same area code are grouped into the same merge group, and this merge group is written as an anomaly event, thus obtaining a set of anomaly events that can be directly read for subsequent qualification determination.

[0062] S2. Read the abnormal event set, compare the abnormal location, abnormal category and change direction of each abnormal event in sequence according to the abnormal time, and write the comparison results as trigger event, support event, exclusion event, escalation event or cancellation event to generate a qualified event set;

[0063] In this embodiment, S2 is used to identify which abnormal events can enter the subsequent early warning processing based on the abnormal event set, and write abnormal events with different functions as trigger events, supporting events, exclusion events, escalation events, and deactivation events, thereby providing inputs with clear qualifications and clear functions for the establishment of subsequent early warning positions. This process is not a one-time single-point judgment on abnormal events, but first constructs a position chain around each abnormal event, then divides different sub-chains within the position chain according to the abnormality category, and calculates the inter-chain relationship by combining the abnormal time, abnormal location, and change direction. Then, it determines whether to allow the event and what qualification event to allow it by the cross relationship between candidate trigger points, supporting sequences, conflict sequences, escalation sequences, and deactivation sequences. In order to enable subsequent processing to accurately distinguish which abnormal events belong to the formation evidence of dangerous topics, which abnormal events belong to conflict evidence, and which abnormal events belong to the dangerous expansion or termination evidence, this application completes the position chain establishment, chain relationship calculation, candidate relationship generation, gating result writing, and qualification event generation in S2 in sequence. This implementation process includes the following steps:

[0064] In S2-1, the system reads all abnormal events in the abnormal event set and first sorts them in ascending order by the time of occurrence, so that abnormal events that the same dangerous topic may experience can be processed in the order of their occurrence. Then, each of the sorted abnormal events is treated as a central event, and subsequent abnormal events within consecutive warning periods are read from the warning period of the central event. A consecutive warning period is a sequence of periods extending sequentially from the warning period of the central event, where adjacent periods all contain abnormal events related to the region where the central event is located. The system stops truncating when no abnormal events related to the region of the central event are found in a subsequent warning period. For each truncated subsequent abnormal event, the system reads its abnormal position and determines its positional relationship with the abnormal position of the central event. If the region codes corresponding to the two abnormal positions are similar... If the two region codes are the same, they are considered to be in the same position; if the two region codes share a boundary in the region adjacency list, they are considered to be in adjacent positions; if the region code of the central event is a parent region and covers the region code of the subsequent abnormal event, or the region code of the subsequent abnormal event is a parent region and covers the region code of the central event, they are considered to be in a contained position; the system writes the subsequent abnormal events that satisfy any of the relationships of same position, adjacent position, or contained position into the position chain corresponding to the central event, and takes the central event as the first event of the position chain; after completing the backward truncation and position assignment of all central events, the resulting position chains are written into the position chain set; through this step, each position chain corresponds to an abnormal event sequence that starts from the central event and expands along the same or adjacent position range within a continuous warning period, thereby providing a unified processing object for subsequent chain classification and time sequence relationship calculation;

[0065] In S2-2, the system reads each position chain in the position chain set and reads each abnormal event in that position chain one by one. Before reading, the main category of the first event of the position chain is determined as the base category of that position chain. Then, according to the correspondence between abnormal categories, each abnormal event in the position chain is written into the same type sub-chain, the opposite type sub-chain, and the extended sub-chain respectively. Among them, abnormal events with the same abnormal category as the base category are written into the same type sub-chain; abnormal events with an abnormal category that has an exclusive, canceling, or contradictory relationship with the base category in the category comparison relationship are written into the opposite type sub-chain; abnormal events with an abnormal category that is not exclusive to the base category and whose abnormal position extends outward along the propagation direction of the position chain are written into the extended sub-chain. After completing the sub-chain division, the system reads two adjacent abnormal events in the same position chain in ascending order of abnormal time and calculates the time interval, position offset direction, and direction continuation result between them. Among them, the time interval is determined by the abnormal time of the next abnormal event. The position offset direction is obtained by subtracting the abnormal time of the previous abnormal event. The direction of position offset is written as up, down, left, right, cohesion, or expansion based on the relative positions of the corresponding region codes of the two adjacent abnormal events in the region adjacency list. If the region codes of the two abnormal events are the same, it is recorded as the original position. The direction continuation result is obtained based on the change direction of the two adjacent abnormal events. When the change direction of the two adjacent abnormal events is both increasing or both decreasing, it is recorded as continuation; when one is increasing and the other is decreasing, it is recorded as reversal; otherwise, it is recorded as interruption. After completing the above calculations, the system writes the position chain identifier, adjacent abnormal event identifier, time interval, position offset direction, and direction continuation result into the corresponding chain relationship record, and writes all chain relationship records into the chain relationship set. Through this step, the category relationship, time relationship, spatial offset relationship, and change relationship within the position chain are all written into directly referenceable chain relationship records, providing a clear basis for subsequent cross-judgment.

[0066] In S2-3, the system reads the chain relationship set and performs cross-determination on a per-position chain basis. During execution, it first reads the corresponding sub-chains of the same type and locates the starting abnormal event of consecutive similar segments from the sub-chains of the same type. This starting abnormal event is written as a candidate trigger point. Consecutive similar segments refer to abnormal event segments in the same sub-chain that are arranged consecutively according to their abnormal time and are not interrupted by direction reversal or position interruption. After determining the candidate trigger point, the system continues to read the abnormal events of the sub-chains of the same type located after the candidate trigger point. Abnormal events whose direction continuation result is continuation and whose abnormal time is later than the candidate trigger point are written into the support sequence in the order of their abnormal time. The support sequence is used to characterize the continuous formation process of the dangerous topic corresponding to the candidate trigger point. Subsequently, the system reads each abnormal event in the anti-type sub-chain and writes the anti-type sub-chain abnormal events whose abnormal time falls between the first and last abnormal events in the support sequence into the conflict sequence. This is used to characterize the counter-evidence or cancellation of the formation process of the dangerous topic. Afterward, the system reads the expanded... For each anomalous event in the subchain, those with anomalous locations continuously expanding outward along the same offset direction and whose anomalous time is later than the candidate trigger point are written into the escalation sequence in the order of their anomalous times. This is used to characterize the spatial expansion of the hazard theme. For the deactivation sequence, the system continues to read anomalous events in the same subchain that are located after the support sequence. Anomalous events with a reversed direction and whose anomalous time is later than the last anomalous event in the support sequence are written into the deactivation sequence. This is used to characterize the previously continuously enhanced hazard theme that has undergone a reverse change and entered the termination process. After completing the above processing, the system writes the candidate trigger point, support sequence, conflict sequence, escalation sequence, and deactivation sequence into the same candidate relationship record and writes all candidate relationship records into the candidate relationship set. Through this step, the originally scattered chain relationships are further organized into a multi-sequence relationship structure that unfolds around the candidate trigger point. This allows subsequent gating processing to no longer target a single anomalous event, but to make a unified judgment on the entire process of the formation, conflict, expansion, and termination of the hazard theme.

[0067] In S2-4, the system reads each candidate relation record in the candidate relation set and counts the number of abnormal events in its supporting sequence, conflict sequence, escalation sequence, and de-escalation sequence, respectively. To avoid amplifying local conflicts by simply counting the original numbers, the system first performs alignment processing on the supporting and conflict sequences by time slice. Support sequence abnormal events that are in the same time slice and at the same abnormal position as abnormal events in the conflict sequence are marked as covered supporting events. Then, uncovered supporting sequence abnormal events are counted as valid supporting events, and all abnormal events in the conflict sequence are counted as valid conflict events. Afterward, the number of valid supporting events and valid conflict events are counted separately. When the number of valid supporting events is greater than the number of valid conflict events, the system writes a gating token to the candidate relation record corresponding to the candidate trigger point. The gating token indicates that the candidate trigger point has passed the release judgment and is allowed to generate a trigger event. When the number of abnormal events in the escalation sequence... When the quantity is greater than zero, the system writes an upgrade lock to the candidate relationship record corresponding to the candidate trigger point. The upgrade lock indicates that the dangerous topic corresponding to the candidate trigger point has an outward upgrade relationship and allows the generation of upgrade events. When the deactivation sequence is not empty and the abnormal time of the first abnormal event in the deactivation sequence is later than the abnormal time of the last abnormal event in the support sequence, the system writes a deactivation lock to the candidate relationship record corresponding to the candidate trigger point. The deactivation lock indicates that the dangerous topic corresponding to the candidate trigger point has entered the final stage and allows the generation of deactivation events. After completing the gating processing of all candidate relationship records, the system writes the candidate trigger point, gating token, upgrade lock, and deactivation lock to the gating result record and writes all gating result records to the gating result set. Through this step, the system does not decide whether to allow or not based solely on a single abnormal event, but writes the gating token, upgrade lock, and deactivation lock according to the quantitative and temporal relationships between support, conflict, upgrade, and deactivation, thereby establishing the subsequent qualification generation of dangerous topics on the complete link relationship.

[0068] In S2-5, the system reads each gating result record from the gating result set and generates qualification events one by one according to the candidate trigger points. For candidate trigger points written to the gating token, the system writes the candidate trigger point as a trigger event and writes the abnormal time, abnormal location, abnormal category, and corresponding topic identifier of the candidate trigger point into the trigger event record. For abnormal events that are simultaneously written to the gating token and are located in the support sequence, the system writes them one by one as support events in ascending order of abnormal time, and makes each support event inherit the topic identifier of the corresponding candidate trigger point to ensure that the same dangerous topic can be continuously processed in the same warning position. For abnormal events that are not written to the gating token and are located in the conflict sequence, the system writes them as exclusion events and writes the corresponding candidate trigger point identifier and conflict source identifier into the exclusion event for subsequent deletion or exclusion processing of the current topic. For abnormal events written to the upgrade lock, the system writes each abnormal event in the upgrade sequence as an upgrade event in ascending order of abnormal time and writes them according to their appearance order in the upgrade sequence. The upgrade order field is used to form level records in subsequent steps. For exceptions that are unlocked, the system writes the first exception in the unlock sequence as the unlock event and its exception time as the unlock start time. If there are similar exceptions in the unlock sequence after the first exception event whose change direction no longer increases, the unlock is retained. If a similar exception reappears with a continuation of the direction and an increase in the change direction, the original unlock is deleted and the candidate relationship record is rolled back to before the gating process for recalculation. After the above writing is completed, the system merges the trigger events, support events, exclusion events, upgrade events, and unlock events according to the candidate trigger points, and writes all the merged qualified events into the qualified event set for direct reading when establishing early warning positions in subsequent steps. Through this step, exceptions with different functions are organized into qualified events with consistent fields, clear functions, and shared theme identifiers, so that the subsequent placement, updating, and output of early warning positions can all continue to revolve around the same danger theme.

[0069] Through the above processing, abnormal events are no longer simply raw inputs arranged chronologically, but are further organized into a set of qualified events with location chain structure, sub-chain structure, candidate relationship structure, and gating structure. This allows for the identification of spatial continuity of abnormal events using same, adjacent, and contained relationships; the identification of the formation, conflict, and expansion processes of hazardous topics using similar, opposite, and extended relationships; and the differentiation of which abnormal events should enter subsequent warning processing and with what qualifications using gating tokens, upgrade locks, and unlocking locks. This improves the continuity, stability, and interpretability of qualified event generation. In practical applications, taking a restricted area warning scenario in a factory as an example, the system first reads prohibited abnormal events within a certain area code as the central event in a set of abnormal events. Then, within a continuous warning cycle, it continues to intercept subsequent abnormal events within the same and adjacent area codes, forming corresponding location chains. In this location chain, the system writes prohibited abnormal events into the same sub-chain, representing... Anomalies such as personnel leaving or door status restoration are written into the anti-type subchain. Prohibited anomalies whose location expands continuously from one region code to two adjacent region codes are written into the extended subchain. Then, the first anomaly in the same subchain is written as a candidate trigger point, subsequent enhanced anomalies are written into the support sequence, anti-type anomalies within the same time frame are written into the conflict sequence, outward-expanding anomalies are written into the upgrade sequence, and subsequent anomalies of the same type with reversed direction are written into the deactivation sequence. Next, a gating token is written based on the comparison between the number of valid support events and the number of valid conflict events, and upgrade locks and deactivation locks are written respectively when upgrade and deactivation sequences exist. Finally, the candidate trigger point is written as a trigger event, anomalies in the support sequence are written as support events, anomalies in the conflict sequence are written as exclusion events, anomalies in the upgrade sequence are written as upgrade events, and the first anomaly in the deactivation sequence is written as a deactivation event. This generates a set of qualifying events that can be directly used for establishing subsequent early warning seats.

[0070] S3. Read the eligibility event set, group it according to the target object identifier or region identifier, and write the first triggering event in each group into the corresponding warning seat as the current topic, and generate the seat result;

[0071] In this embodiment, S3 is used to organize the qualified events that have completed the qualification assessment into early warning seats that can continuously carry the same dangerous topic. This allows subsequent status updates and early warning outputs to no longer directly deal with scattered qualified events, but instead to continuously process the current topic in the early warning seats. This process first groups the qualified events according to the target object identifier or region identifier, then determines the triggering event that can occupy the seat first in each group, and writes the anomaly category, anomaly time, and anomaly location corresponding to the triggering event into the early warning seat, ultimately forming a seat result that can be directly called by subsequent steps. To avoid the same qualified event being repeatedly grouped, different topics being mixed into the same processing unit, and subsequent status updates lacking a clear writing object, this application sequentially completes the qualification event grouping, early warning seat establishment, and seat record writing in S3. This implementation process includes the following steps:

[0072] In S3-1, the system reads all qualification events in the qualification event set and extracts the subject identifier, target object identifier, region identifier, abnormal time, abnormal location, and event type for each qualification event in sequence. Qualification events include trigger events, supporting events, exclusion events, escalation events, and deactivation events. When grouping, the system first determines whether the current qualification event carries a target object identifier. If it does, the qualification event is written to the corresponding group based on the same target object identifier. If it does not carry a target object identifier, the qualification event is written to the corresponding group based on the same region identifier. If the same qualification event carries both a target object identifier and a region identifier, the target object identifier is used as the primary group. The system uses the region identifier as an auxiliary field within the group to ensure that the same qualification event enters only one group. After grouping, the system sorts the trigger events, supporting events, exclusion events, upgrade events, and deactivation events within each group in ascending order of their time of exception. When two qualification events have the same time of exception, the trigger event is sorted first, followed by the exclusion event, upgrade event, supporting event, and deactivation event, so that subsequent placeholders and status updates have a fixed processing order. After merging and sorting all groups, each group is written as a seat group set, where each group includes at least a group identifier, a target object identifier or region identifier, a sequence of qualification events within the group, and a corresponding topic identifier.

[0073] In S3-2, the system reads each group in the seat grouping set and sequentially reads the qualified event sequence within each group. First, it locates the first triggering event in this sequence. The first triggering event is the one that is ranked first in the group and has already passed the gating. After determining the first triggering event, the system extracts its anomaly category, anomaly time, and anomaly location, respectively writing the anomaly category as the current topic, the anomaly time as the placeholder time, and the anomaly location as the topic location. Simultaneously, it writes the topic identifier carried by the first triggering event as the current topic identifier, enabling subsequent supporting events, exclusion events, and escalation events written to the same warning seat to be considered as the topic identifier. Events and their resolution can continue to be processed around the same current topic. Subsequently, the system establishes an early warning seat for the group. The early warning seat is a topic placeholder record unit for the corresponding group, which includes at least a seat identifier, a group identifier, a current topic identifier, a current topic, a placeholder time, and a topic position. The seat identifier is formed by combining the group identifier and the current topic identifier to ensure that different groups or different topics correspond to different early warning seats. After the first trigger event is extracted and the early warning seat is established for all groups, each early warning seat is written into the initial seat set. If there is no trigger event in a group, no early warning seat is established for that group, and the group is retained to be regrouped for processing in subsequent early warning cycles.

[0074] In S3-3, the system reads each warning seat from the initial seat set and writes the target object identifier or region identifier, current topic, occupancy time, and topic position of each warning seat into the corresponding seat record. Specifically, if the warning seat is formed by grouping based on target object identifiers, the target object identifier is written as the main seat identifier, and the region identifier is written as the seat's secondary position field. If the warning seat is formed by grouping based on region identifiers, the region identifier is written as the main seat identifier. Simultaneously, the system writes the current topic identifier, seat identifier, and group identifier into the seat record, enabling subsequent steps to accurately write supporting events, exclusion events, escalation events, and deactivation events into the corresponding warning seats based on the seat identifiers, and to distinguish different dangerous topics formed by the same group at different times based on the current topic identifier. After writing all the fields for the initial seats, the system sequentially writes each seat record into the seat result, which serves as the direct input for subsequent status update steps.

[0075] Through the above processing, eligibility events are organized into a set of seats based on target object identifiers or region identifiers, with the first triggering event as the placeholder, and the current topic as the core processing object. This allows subsequent steps to avoid processing each scattered eligibility event independently, instead focusing on adding evidence, deleting topics, updating levels, and writing end markers around the current topic in the warning seat. Simultaneously, by prioritizing grouping by target object identifier and then by region identifier when no target object identifier is available, the system avoids the same eligibility event repeatedly entering multiple groups and ensures that the same hazardous topic has a unique placeholder and a stable writing entry point in subsequent processing. In practical applications: taking a restricted area warning scenario in a factory as an example, the system reads the triggering event, supporting event, escalation event, and deactivation event corresponding to a certain person from the eligibility event set, and reads another... The system categorizes access control anomalies into two groups. For the first group of qualifying events, they are grouped together based on the shared target object identifier. Events within the group are then sorted in ascending order of their anomaly time. The earliest triggering event is selected as the first triggering event. The anomaly category of this triggering event is written as the current topic, its anomaly time as the placeholder time, and its area code as the topic location. A corresponding warning seat is then established. For the second group of qualifying events, they are grouped into another group based on their area identifier, and another warning seat is established using the first triggering event within that group. Finally, the system writes the target object identifier or area identifier, current topic, placeholder time, topic location, seat identifier, and current topic identifier for each warning seat into the seat results, providing stable input for subsequent status updates performed around different warning seats.

[0076] S4. Read the seat results and write the supporting events, exclusion events, escalation events and deactivation events of the same warning seat, perform evidence appending, topic deletion, level updating and end marker writing, and generate status results;

[0077] In this embodiment, S4 is used to continuously write supporting events, exclusion events, escalation events, and deactivation events that subsequently enter the same early warning seat into the current topic, based on the established early warning seat, thereby forming a state result that can be directly used to output early warning results. This process does not process individual eligibility events independently, but rather constructs a topic processing sequence around the current topic in the same early warning seat, and then executes evidence addition, topic deletion, level update, and end writing in a unified order, so that the same dangerous topic has a clear state evolution trajectory in subsequent processing. To avoid problems such as unstable writing order of different eligibility events, unclear boundaries between deletion and end markers, unclear source of level records, and lack of continuous evidence chain for the same topic, this application completes seat sequence generation, seat status update, and state result writing sequentially in S4. This implementation process includes the following steps:

[0078] In S4-1, the system reads each warning seat from the seat results and extracts the seat identifier, current topic identifier, current topic, reservation time, and topic position corresponding to each warning seat. Then, the system searches the qualified event set for supporting events, exclusion events, escalation events, and deactivation events that match both the seat identifier and the current topic identifier. Each found event is then written as a subsequent processing event for the same warning seat. To ensure a stable order for subsequent status updates, the system first sorts the supporting events, exclusion events, escalation events, and deactivation events in ascending order based on the time of the anomaly. When two subsequent processing events have the same time of anomaly, the exclusion event is prioritized, followed by the escalation event, supporting event, and deactivation event. Prioritizing the exclusion event is to prevent conflicts arising at the same time of anomaly. First, the system determines whether the current topic should be retained. Upgrade events take precedence over supporting events to ensure that topic level elevation is completed before adding supporting evidence at the same abnormal time. Removal events are placed last to ensure that the end of the write operation occurs after other state processing occurs at the same abnormal time. After sorting, the system writes the sorted subsequent processing events sequentially into the topic processing sequence corresponding to the warning position, and writes the position identifier, current topic identifier, and topic processing sequence into the corresponding position sequence record. After completing the same processing for all warning positions, a position sequence set is generated. If a warning position does not find supporting events, removal events, upgrade events, or removal events in the current processing round, the system creates an empty topic processing sequence for that warning position and still writes it into the position sequence set to maintain the integrity of the subsequent state output structure.

[0079] In S4-2, the system reads each seat sequence record from the seat sequence set and processes the topic processing sequence of the corresponding warning seat one by one according to the seat identifier. At the start of processing, the current topic written by the warning seat in the seat result is taken as the topic to be updated, and four types of status fields are established for this topic: evidence sequence, deletion flag, level record, and end flag. The evidence sequence is initially empty, the deletion flag is initially empty, the level record is initially set to the base level corresponding to the current topic, and the end flag is initially empty. Subsequently, the system reads each subsequent processing event in the topic processing sequence in sequence according to the abnormal time. When a supporting event is read, it first determines whether the abnormal time, abnormal location, and abnormal category of the supporting event are already present in the current topic. If a record with the same information exists in the evidence sequence, the supporting event will be appended to the evidence sequence if no record exists. If records with the same abnormal time, location, and category exist, they will not be written repeatedly. When an exclusion event is read, the system writes a deletion flag in the status field corresponding to the current topic. The deletion flag indicates that the current topic will no longer be output as a valid warning topic in subsequent outputs. After the deletion flag is written, subsequent supporting events and escalation events following the exclusion event will no longer be written to the current topic, but the cancellation event is still allowed to be used to complete the end boundary. When an escalation event is read, the system reads the escalation order field in the escalation event and writes the level value corresponding to the escalation order field into the level record of the current topic.

[0080] If the current level record is lower than the level corresponding to the upgrade sequence, an update is performed. If the current level record is higher than or equal to the level corresponding to the upgrade sequence, the original level record is kept unchanged, thus preventing subsequent lower-level upgrade events from overwriting the already formed higher level. When a cancellation event is read, the system writes the abnormal moment of the cancellation event into the end marker of the current topic. The end marker is used to indicate that the current topic was once established and has entered the end state, which is different from the deletion marker indicating that the topic is not established. After completing the sequential processing of all subsequent processing events in the topic processing sequence, the system writes the updated current topic, evidence sequence, deletion marker, level record, and end marker into the corresponding seat status record, and performs the same processing on all warning seats to generate a seat status set. Through this step, the system enables the current topic in the same warning seat to continuously evolve along the temporal relationship of support, conflict, upgrade, and end, and makes the deletion marker and end marker correspond to the two different state boundaries of "topic not established" and "topic has ended", respectively.

[0081] In S4-3, the system reads the status records of each seat in the seat status set and writes the seat identifier, current topic identifier, current topic, evidence sequence, deletion flag, level record, and end flag from each seat status record into the corresponding seat status record structure. The evidence sequence stores the set of supporting events retained during the formation and continuation of the current topic; the deletion flag records whether the current topic has been excluded due to event negation; the level record records the highest level reached by the current topic during processing; and the end flag records the time boundary of the current topic's end. During writing, the system first writes the seat identifier and current topic identifier into the primary index field, then writes the current topic, evidence sequence, deletion flag, level record, and end flag into the status content field, thereby... When reading the status results later, the system can directly locate the complete status of the corresponding current topic by seat identifier and current topic identifier. For seat status records with empty evidence sequences, the system still retains the current topic and level records to distinguish the status of "occupied but without additional supporting evidence" later. For seat status records with non-empty deletion markers, the system retains the original writing results of deletion and end markers so that the output stage can decide whether to output them according to priority. For seat status records with non-empty end markers but empty deletion markers, the system retains its current topic, level records, and end markers so that the warning can be lifted later. After completing the above writing, the system will write all seat status records into the status results in sequence, and the status results will serve as the direct input for the subsequent warning output steps.

[0082] Through the above processing, the current topic in the warning position no longer remains in the initial occupying state, but is further organized into a state result containing evidence sequence, deletion flag, level record, and end flag. This allows subsequent output steps to distinguish whether the current topic is valid, escalated, or terminated based on a unified state structure. Simultaneously, by establishing a topic processing sequence first and then processing them sequentially, the writing order of supporting events, exclusion events, escalation events, and deactivation events within the same warning position is ensured to be fixed, avoiding instability in the topic state due to changes in the writing order. Furthermore, by separately writing the deletion flag and the end flag, the two different processing results of "not valid and excluded" and "valid before termination" are clearly distinguished. In practical applications: taking a restricted area warning scenario in a factory as an example, a certain warning position has already been occupied by the first prohibited entry trigger event, and the system continues reading... The system retrieves two supporting events, one escalation event, and one de-escalation event from the warning entry point and sorts them by the time of the anomaly to form a topic processing sequence. During sequential processing, the two supporting events are first appended to the evidence sequence of the current topic. Then, the escalation order carried by the escalation event is written into the level record of the current topic, raising it from the basic level to a higher level. Subsequently, the time of the anomaly of the de-escalation event is written into the end marker, indicating that the prohibited danger topic has ended. If there is an exclusion event in the same sequence, the system first writes a deletion marker, so that the current topic will no longer be a valid warning output in subsequent outputs. Finally, the system writes the current topic of the warning entry point, the appended evidence sequence, the deletion marker, the updated level record, and the end marker into the status result, thus providing direct evidence for subsequent outputs of in-progress warnings, escalated warnings, or de-escalated warnings.

[0083] S5. Read the status results, output the in-process warning, upgraded warning or deactivated warning corresponding to the current topic according to the warning position, and generate the dangerous behavior warning results;

[0084] In this embodiment, S5 is used to determine whether the current topic should be output as an ongoing warning, an upgraded warning, or a deactivated warning based on the status results formed by each warning position in the previous processing stage, and organizes the corresponding content into the final dangerous behavior warning result. This process is not a simple read of the current topic and direct output, but first organizes the position status records according to the warning position, then determines the warning type based on the write status of the deletion mark, level record, and end mark, then writes the start time, current level, and end time of the current topic into the corresponding warning record, and finally merges them according to the warning position to obtain a stable output result. In order to avoid duplicate output of the same current topic, conflict between different warning types, unclear output time boundaries, and lack of a unified structure in the final result, this application completes the output queue generation, warning type determination, warning record writing, and dangerous behavior warning result generation in S5 in sequence. This implementation process includes the following steps:

[0085] In S5-1, the system reads all seat status records from the status results and extracts the current topic, evidence sequence, deletion flag, level record, and end flag for each warning seat. The current topic represents the dangerous topic currently held by the warning seat; the evidence sequence represents the set of supporting events retained during the formation and continuation of the current topic; the deletion flag indicates whether the current topic has been negated by excluded events; the level record indicates the current level reached by the current topic; and the end flag indicates whether the current topic has ended. After extraction, the system further reads the occupancy time from each seat status record and the first abnormal time from the evidence sequence, using the earlier of the two as the seat status. The system records the sorting time; if the evidence sequence is empty, the placeholder time is used directly as the sorting time; subsequently, the system sorts all seat status records in ascending order according to the sorting time; when two seat status records have the same sorting time, the seat status record with the smaller seat identifier is prioritized to ensure a fixed output order; after sorting, the system writes each sorted seat status record into the output queue in sequence, where each output queue item includes at least the warning seat identifier, current topic identifier, current topic, evidence sequence, deletion flag, level record, end flag, and sorting time; through this step, the status results corresponding to different warning seats are organized into an output queue with a unified order, providing stable input for subsequent warning type determination;

[0086] In S5-2, the system reads the status records of each seat in the output queue and sequentially determines the write status of the deletion flag, level record, and end flag according to the output queue order. During the determination, it first checks if the deletion flag is empty. If the deletion flag is not empty, the current topic is determined to be an invalid topic, and no alert type is written to it; the process then proceeds directly to the next seat status record. If the deletion flag is empty, it continues to check if the end flag is empty. When the end flag is empty, it then checks if the level record is higher than the base level written when the current topic was created. If the level record is not higher than the base level, the current topic is written as an in-process alert; if the level record is higher than the base level, the current topic is written as an escalation alert. If the deletion flag is empty... Furthermore, if the end marker is not empty, then regardless of whether the level record is updated, the current topic will be prioritized as cleared from warning, thus ensuring that the same current topic will not continue to be output as an ongoing warning or an upgraded warning if it has already ended. After completing the above determination, the system will write the warning position identifier, the current topic identifier, the current topic, and the corresponding warning type into the warning type record, and write all warning type records into the warning type set. Through this step, the system will use the deletion marker as the first determination condition and the end marker as the priority determination condition above the level record, thus clearly distinguishing the four different state boundaries of "no output", "continue output", "level upgrade output" and "end output", and avoiding the same current topic from falling into multiple output types at the same time.

[0087] In S5-3, the system reads each warning type record from the warning type set and extracts the corresponding topic content, evidence sequence, level record, and end marker for each record. For topic content, the system directly reads the current topic field and writes it to the corresponding warning type. For start time, the system prioritizes reading the first abnormal moment in the evidence sequence; if the evidence sequence is empty, it reads the placeholder moment of the current topic and writes the read time as the start time of the warning record. For the current level, the system reads the current level value from the level record and writes it to the warning record. For end time, if the warning type is "warning lifted," it reads the end marker from the end marker. The system writes the warning information to the warning record at any time. If the warning type is an ongoing warning or an escalating warning, the end time field is left empty. At the same time, the system also writes the warning seat identifier, current topic identifier, and warning type to the corresponding warning record to ensure that subsequent merging can be performed according to the warning seat and current topic. After writing the fields of all warning type records, the system generates a warning record set. Through this step, the topic content, start time, current level, and end time corresponding to different warning types are organized into warning records with a unified field structure, so that the subsequent output of dangerous behavior warning results has clear topic content, time boundaries, and level expression.

[0088] In S5-4, the system reads all warning records from the warning record set and performs merging processing according to the warning position. During merging, all warning records are first grouped according to the warning position identifier, and then warning records corresponding to the same current topic are merged within each warning position according to the current topic identifier. For multiple warning records under the same warning position and the same current topic identifier, the system retains only the one with the highest output priority as the main output record. Among them, the priority of canceling the warning is higher than that of escalating the warning, and the priority of escalating the warning is higher than that of the warning in progress. If there is only one warning record, then that warning record is directly used as the main output record for that warning position. After determining the main output record, the system will... The topic content, start time, current level, end time, and warning type are written as the dangerous behavior warning result corresponding to the warning position. If the same warning position has different current topic identifiers in the current processing round, the main output records corresponding to different current topic identifiers are retained and written into the dangerous behavior warning results in ascending order of start time. After merging all warning positions, the system generates the final dangerous behavior warning result. Through this step, duplicate or conflicting warning records within the same warning position are organized into a unique output result, and different warning types have a fixed priority order, thereby ensuring that the final output result is stable, clear, and can be directly used for subsequent linkage or display.

[0089] Through the above processing, the status results are further organized into dangerous behavior warning results with clear warning types, clear time boundaries, clear current levels, and clear output priority. This allows the subsequent system to directly perform display, push, broadcast, or linkage based on the dangerous behavior warning results. Simultaneously, by using deletion markers, end markers, and level records in a fixed order for judgment, the boundary relationships of the current topic in the output stage are clarified, avoiding situations where the same current topic is simultaneously output as an ongoing warning, an escalating warning, and a deactivated warning. Furthermore, by merging based on the warning position and the current topic identifier, duplicate or conflicting outputs are avoided. In practical applications: taking a restricted area warning scenario in a factory as an example, the system reads the position status record corresponding to a certain warning position... If the deletion marker for the current topic is found to be empty, the level record is higher than the basic level, and the end marker is empty, then the current topic is written as an escalation warning. Furthermore, the prohibited topic content of the current topic, the first abnormal moment in the evidence sequence, and the current level in the level record are written into the corresponding warning record. If the same warning position writes an end marker in a subsequent processing round, the system will prioritize writing the current topic as a de-warning in the next output, and write the end time in the end marker into the corresponding warning record. Finally, the system retains the de-warning as the main output record according to the warning position and writes it as a dangerous behavior warning result, so that the front end or linkage side can directly obtain the warning type, start time, current level, and end time of the dangerous topic.

[0090] Furthermore, it also includes a multi-factor fusion-based early warning system for dangerous behaviors, the system comprising:

[0091] The event generation module is used to acquire multi-source abnormal data for a target object or target area within the same early warning period, extract the abnormal time, abnormal location, abnormal category and change direction, and generate an abnormal event set;

[0092] The qualification determination module is used to read the abnormal event set, compare the abnormal location, abnormal category and change direction of each abnormal event in sequence according to the abnormal time, and write the comparison results as trigger event, support event, exclusion event, escalation event or cancellation event to generate a qualification event set;

[0093] The seat creation module is used to read the set of eligibility events, group them according to the target object identifier or region identifier, and write the first triggering event in each group into the corresponding warning seat as the current topic to generate seat results;

[0094] The status update module is used to read the seat results and write supporting events, exclusion events, escalation events and deactivation events for the same warning seat, perform evidence appending, topic deletion, level updating and end marker writing, and generate status results;

[0095] The early warning output module is used to read the status results and output the in-progress warning, upgraded warning, or deactivated warning corresponding to the current topic according to the warning position, and generate warning results for dangerous behavior.

[0096] Working principle: First, abnormal data from different sources such as video, access control, positioning, environmental sensing, and device status are uniformly organized into abnormal events, and standardized according to the same time, location, category, and direction of change. Then, a location chain is established around these abnormal events according to their time sequence and location relationship, and further distinguishes which events belong to the continuous support of the same hazard theme, which belong to conflict resolution, which indicate the expansion of the hazard range, and which indicate that the hazard is beginning to be resolved, thereby transforming the originally scattered abnormal inputs into qualification events with different functions. Finally, these qualification events are assigned to the corresponding early warning positions according to the target object or region, with the first triggering event occupying the position to form the current theme. Subsequent supporting events, exclusion events, escalation events, and de-escalation events are continuously written into this topic, gradually updating its evidence, level, and termination status. Finally, based on the status results in each warning position, the system determines whether the topic should currently output as an ongoing warning, an escalated warning, or a de-escalated warning, and generates the final dangerous behavior warning result. In other words, this solution does not directly trigger an alarm upon seeing a certain anomaly, but first determines whether the anomaly can form a complete dangerous topic, and then continuously tracks whether the topic is strengthened, denied, escalated, or de-escalated. Therefore, the output warnings are more continuous and more in line with the gradual formation, change, and termination of dangerous behaviors in real-world situations.

[0097] For example, within a restricted area of ​​a factory, if a person is first detected by video crossing the warning line, then the access control system abnormally opens, and location data shows that they continue to move deeper into the restricted area, the system will not treat these data points as three independent alarms. Instead, it will first group them into abnormal events within the same area and time period, and then determine whether these events are consecutive in location, mutually supportive in category, and continuously increasing in direction of change. If so, the earliest abnormality is used as the trigger point, subsequent abnormalities developing in the same direction are used as supporting evidence, and abnormalities that continue to expand the danger zone are used as the basis for escalation. If later, personnel leave, the door status is restored, or the intensity of the abnormality decreases, these are then written as exclusion or cancellation information. In this way, the system's final output is not a simple alarm, but a warning result that continuously reflects status changes such as "someone has entered the restricted area," "danger is expanding," and "danger has been eliminated." On-site managers can then more accurately determine whether the current situation has just occurred, is escalating, or has ended.

[0098] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A multi-factor integrated method for early warning of dangerous behaviors, characterized in that, include: S1. Obtain multi-source abnormal data for the target object or target area within the same early warning period, extract the abnormal time, abnormal location, abnormal category and change direction, and generate an abnormal event set; S2. Read the abnormal event set, compare the abnormal location, abnormal category and change direction of each abnormal event in sequence according to the abnormal time, and write the comparison results as trigger event, support event, exclusion event, escalation event or cancellation event to generate a qualified event set; The execution of S2 includes: S2-1. Read the abnormal event set, arrange each abnormal event in ascending order according to the abnormal time, and take each abnormal event as the central event. Extract subsequent abnormal events within the continuous warning period, and write each subsequent abnormal event into the corresponding position chain according to the relationship of the same, adjacent or contained abnormal position to generate a position chain set. S2-2. Read the location chain set, write each abnormal event in each location chain into the same type sub-chain, opposite type sub-chain and extended sub-chain according to the abnormality category, and calculate the time interval, position offset direction and direction continuation result of two adjacent abnormal events in sequence according to the abnormal time to generate a chain relationship set. Among them, the direction continuation result is the change direction of two adjacent abnormal events. If the change direction is the same, it is recorded as continuation; if the change direction is opposite, it is recorded as reversal; otherwise, it is recorded as interruption. S2-3. Read the chain relationship set, perform cross-determination on each chain position, write the first abnormal event in the same sub-chain as a candidate trigger point, write the abnormal events located after the candidate trigger point and whose direction continuation result is continuation into the support sequence, write the abnormal events in the opposite sub-chain whose abnormal time falls between the first and last time of the support sequence into the conflict sequence, write the abnormal events in the extended sub-chain whose abnormal position expands outward along the same position offset direction into the upgrade sequence, and write the abnormal events in the same sub-chain whose direction continuation result is reversed and located after the support sequence into the release sequence, and generate a candidate relationship set. S2-4. Read the candidate relation set, and for each candidate trigger point, count the number of abnormal events in the support sequence, the number of abnormal events in the conflict sequence, the number of abnormal events in the upgrade sequence, and the number of abnormal events in the deactivation sequence. When the number of abnormal events in the support sequence is greater than the number of abnormal events in the conflict sequence, write a gating token to the candidate trigger point. When the number of abnormal events in the upgrade sequence is greater than zero, write an upgrade lock to the candidate trigger point. When the abnormal time of the first abnormal event in the deactivation sequence is later than the abnormal time of the last abnormal event in the support sequence, write an unlock to the candidate trigger point and generate a gating result set. S2-5. Read the gating result set, write the candidate trigger points written to the gating token as trigger events, write the abnormal events written to the gating token and located in the support sequence as support events, write the abnormal events not written to the gating token and located in the conflict sequence as exclusion events, write the abnormal events written to the upgrade lock as upgrade events, write the abnormal events written to the unlock lock as unlock events, and merge the trigger events, support events, exclusion events, upgrade events and unlock events to generate a qualification event set; S3. Read the eligibility event set, group it according to the target object identifier or region identifier, and write the first triggering event in each group into the corresponding warning seat as the current topic, and generate the seat result; S4. Read the seat results and write the supporting events, exclusion events, escalation events and deactivation events of the same warning seat, perform evidence appending, topic deletion, level updating and end marker writing, and generate status results; S5. Read the status results, output the in-process warning, upgraded warning or deactivated warning corresponding to the current topic according to the warning position, and generate the dangerous behavior warning results.

2. The multi-factor fusion-based early warning method for dangerous behaviors according to claim 1, characterized in that: S1 includes: S1-1. Obtain multi-source abnormal data within the same early warning period, extract the reporting time, source location, abnormal marker, and two consecutive status values ​​of each source data, and generate a source record set; S1-2. Read the source record set, convert the reporting time of each source data into the abnormal time, convert the source location into the abnormal location, write the abnormal mark as the abnormal category, and write the direction of change according to the increase, decrease or no change of the state value before and after, and generate a standard record set. S1-3. Read the standard record set, merge the standard records with the same abnormal time and overlapping abnormal location into an abnormal event, and write the corresponding abnormal time, abnormal location, abnormal category and change direction into the abnormal event to generate an abnormal event set.

3. The multi-factor fusion-based early warning method for dangerous behaviors according to claim 2, characterized in that: S3 includes: S3-1. Read the qualification event set, group each qualification event according to the same target object identifier or the same region identifier, and sort the trigger events, support events, exclusion events, upgrade events and release events in each group in ascending order of the time of the exception, and generate a seat group set; S3-2. Read the seat group set, extract the anomaly type, anomaly time and anomaly location of the first triggered event for each group, write the anomaly type as the current topic, write the anomaly time as the placeholder time, write the anomaly location as the topic location, and establish the warning seat corresponding to the group to generate the initial seat set. S3-3. Read the initial seat set, write the target object identifier or region identifier, current topic, occupancy time and topic position of each warning seat into the corresponding seat record, and generate the seat result.

4. The multi-factor fusion-based early warning method for dangerous behaviors according to claim 3, characterized in that: S4 includes: S4-1. Read the seat results and write the supporting events, exclusion events, escalation events and deactivation events of the same warning seat. Sort the supporting events, exclusion events, escalation events and deactivation events in ascending order according to the time of the anomaly, and write each event sequentially into the topic processing sequence of the corresponding warning seat to generate a seat sequence set. S4-2. Read the seat sequence set, and execute the event processing of each warning seat's topic processing sequence in sequence according to the abnormal time. When a supporting event is read, write the supporting event into the evidence sequence of the current topic. When an exclusion event is read, write the deletion mark into the current topic. When an escalation event is read, write the abnormal category of the escalation event into the level record of the current topic. When a cancellation event is read, write the abnormal time of the cancellation event into the end mark of the current topic, and generate a seat status set. S4-3. Read the seat status set, write the current topic, evidence sequence, deletion mark, level record and end mark of each warning seat into the corresponding seat status record, and generate the status result.

5. The multi-factor fusion-based early warning method for dangerous behaviors according to claim 4, characterized in that: S5 includes: S5-1. Read the status results, extract the current topic, evidence sequence, deletion mark, level record and end mark according to the warning position, and sort the position status records corresponding to each warning position in ascending order according to the abnormal time, and generate the output queue. S5-2. Read the output queue, and sequentially determine the write status of the deletion mark, level record and end mark for each seat status record. Write the current topic with an empty deletion mark and an empty end mark as an in-process warning, write the current topic with an empty deletion mark and an updated level record as an escalation warning, and write the current topic with an empty deletion mark and an already written end mark as a de-escalation warning, and generate a warning type set.

6. The multi-factor fusion-based early warning method for dangerous behaviors according to claim 5, characterized in that: The S5 also includes: S5-3. Read the warning type set, and write the topic content of each current topic, the first abnormal moment in the corresponding evidence sequence, the current level in the level record, and the end moment in the end marker into the corresponding warning type to generate a warning record set; S5-4. Read the warning record set, merge the corresponding ongoing warnings, upgraded warnings, or deactivated warnings according to the warning position, and write the merged result as the dangerous behavior warning result.

7. A multi-factor fusion-based dangerous behavior early warning system, used to implement the multi-factor fusion-based dangerous behavior early warning method according to any one of claims 1-6, characterized in that, include: The event generation module is used to acquire multi-source abnormal data for a target object or target area within the same early warning period, extract the abnormal time, abnormal location, abnormal category and change direction, and generate an abnormal event set; The qualification determination module is used to read the abnormal event set, compare the abnormal location, abnormal category and change direction of each abnormal event in sequence according to the abnormal time, and write the comparison results as trigger event, support event, exclusion event, escalation event or cancellation event to generate a qualification event set; The seat creation module is used to read the set of eligibility events, group them according to the target object identifier or region identifier, and write the first triggering event in each group into the corresponding warning seat as the current topic to generate seat results; The status update module is used to read the seat results and write supporting events, exclusion events, escalation events and deactivation events for the same warning seat, perform evidence appending, topic deletion, level updating and end marker writing, and generate status results; The early warning output module is used to read the status results and output the in-progress warning, upgraded warning, or deactivated warning corresponding to the current topic according to the warning position, and generate warning results for dangerous behavior.