Campus security and protection sensing emergency linkage method and system based on image recognition

By introducing impact identifiers and command context index records into the smart campus security system, combined with granular tolerance judgment and delay processing, the problems of data timing misalignment and secondary effects of linkage commands under high load are solved, enabling accurate security decision-making and rapid response.

CN122120306APending Publication Date: 2026-05-29大图人工智能(深圳)有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
大图人工智能(深圳)有限公司
Filing Date
2026-03-23
Publication Date
2026-05-29

Smart Images

  • Figure CN122120306A_ABST
    Figure CN122120306A_ABST
Patent Text Reader

Abstract

The application provides a campus security perception emergency linkage method and system based on image recognition, relates to the technical fields of image recognition and emergency linkage, and has the technical solution points that an event summary containing an influence identifier is received and sent by an edge node, the influence identifier is checked, an instruction context index record is generated and written into a real-time index after the check is passed; after the index is written, granularity tolerance determination is performed according to the frame interval span of the event summary, and the instruction context index record in the real-time index is queried according to the device and time information; when the matching record is queried and the abnormal determination result is within the instruction influence period, the delay processing is performed on the abnormal determination result. The method has the advantages of improving the accuracy and robustness of security decision by introducing the influence identifier and the instruction context index record and combining the granularity tolerance determination and the delay processing mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of image recognition technology and emergency linkage technology. Specifically, it relates to a campus security perception emergency linkage method and system based on image recognition. Background Art

[0002] In the daily operation of a smart campus, a large number of cameras, access control devices, and fire and environmental sensors are usually deployed in the security system to continuously monitor areas such as teaching buildings, dormitories, corridors, playgrounds, etc. Among them, edge computing nodes are generally set near building entrances or key passage areas, responsible for local image preprocessing, target detection, and event extraction; the central platform receives event summaries reported by each edge node, and performs unified correlation analysis, anomaly determination, and linkage control in combination with access control records, sensor status information, etc.

[0003] In scenarios with short-term high-density traffic on campus, such as after evening self-study, during centralized class changes, or when activities end, a large number of human targets will appear simultaneously in the images of multiple cameras, and the access control system will also generate intensive card swiping and access records in a short period of time. At this time, the processing load of the edge computing node increases significantly, and situations such as increased single-frame processing delay, processing queue backlog, local frame rate reduction, and batch summary reporting are likely to occur, resulting in a decrease in the time accuracy of video events, and even problems such as blurred event start and end boundaries and unstable sequential expression of consecutive frames.

[0004] At the same time, the central platform usually needs to align the time and correlate the order of multi-source events from the video side and the access control side to judge risk states such as crowd gathering, abnormal reverse movement, and unauthorized access. However, under high-load conditions, video events may change the original time sequence due to frame rate reduction, batch upload, or node processing delay; access control records may also make the central recorded time inconsistent with the actual occurrence time due to factors such as time synchronization deviation and batch write delay. As a result, time sequence misalignment is likely to occur between video detection events and access control events, leading to distortion of the multi-source data correlation results.

[0005] Based on the above situation, the processing mechanism in the prior art that relies on the order of event occurrence for anomaly determination is likely to misjudge a normal continuous release or high-density traffic process as a suspicious event. For example, in a real normal release process, it may appear as local aggregation first, then dispersion or turning back in the video summary, and the access control record fails to provide accurate time sequence evidence in time, so the central platform may trigger an alarm based on this and further execute linkage measures such as broadcast diversion, access control flow restriction, and security dispatching notification.

[0006] However, such coordinated measures directly impact the behavior of people on-site. Upon receiving diversion prompts or being restricted by turnstiles, people may linger, turn back, or choose a different exit, creating new localized congestion, backflow, or clustering. These secondary phenomena induced by the system's coordinated measures are then collected by cameras and access control equipment and reported to the central platform. The resulting logic further interprets these as evidence of escalating anomalies, leading to escalated alarm levels and expanded intervention scope. This creates a cascading amplification problem: misjudgment triggers intervention, intervention in turn creates abnormal phenomena, and abnormal phenomena further reinforce misjudgment.

[0007] Furthermore, to improve the robustness of multi-source event alignment, existing technologies typically downgrade events with excessively coarse summary granularity, unreliable timing, or alignment failures, or divert related events to a low-priority review queue. While this approach can reduce direct misjudgments to some extent, it also introduces new problems. Specifically, some event summaries containing crucial contextual information or linkage indicators may not enter the real-time pathway in a timely manner, leading to short-term inconsistencies between real-time visualizations, automatic judgment results, and information seen by manually monitored terminals. Lacking complete context, monitoring personnel may easily expand the diversion scope or increase the flow restriction intensity based on localized phenomena, thereby inducing secondary manifestations similar to the original anomaly in more areas, ultimately causing the system to continuously amplify its response range within a short period.

[0008] To address the aforementioned issues, existing technologies urgently need improvement. Summary of the Invention

[0009] The purpose of this application is to provide a campus security perception and emergency linkage method and system based on image recognition, which can effectively solve the problems of high false alarm rate and excessive system intervention caused by high load, data timing misalignment and secondary effects of linkage commands in smart campus security systems, and improve the accuracy and robustness of security decision-making.

[0010] This application provides a campus security sensing and emergency response method based on image recognition, the technical solution of which is as follows: A campus security sensing and emergency response method based on image recognition includes: Receive event digests sent by edge nodes. The event digests contain at least the device number, local sequence number, and impact identifier. The impact identifier is associated with the issued linkage command. Extract impact identifiers from the event summary and validate the impact identifiers; When the impact identifier passes the verification, an instruction context index record is generated based on the device number, local sequence number, and impact identifier, and the instruction context index record is written into the real-time index; After writing the instruction context index record, perform granular tolerance determination based on the frame interval span of the event digest; When it is determined that the frame interval span exceeds the preset tolerance threshold, the event summary is diverted to the review queue, and the instruction context index record is retained in the real-time index; Obtain the anomaly assessment result for the target object; Based on the device information and time information corresponding to the anomaly determination result, query the instruction context index record in the real-time index; When a matching instruction context index record is found, and the exception determination result is within the influence period of the instruction corresponding to the instruction context index record, the exception determination result is processed with a delay.

[0011] The above solution solves the problem of increased false alarm rate caused by time sequence misalignment and summary granularity fluctuation in the existing technology, and avoids vicious cycle and resource consumption during peak periods.

[0012] Furthermore, this application also proposes a step for performing delayed processing on the anomaly determination result, including: Place the anomaly determination result within a preset time delay decision window; Within the delayed decision window, monitor whether any deviation evidence events are obtained. Deviation evidence events include cross-regional synchronization anomalies or local deviation behaviors that are contrary to the expectations of the linkage command. When a deviating evidence event is obtained within the delayed decision window, bypass the delayed processing and execute an exception escalation response; When the delayed decision window ends and no deviation evidence event is obtained, the abnormal judgment result is suppressed.

[0013] By employing the above-mentioned approach, which utilizes delayed decision windows and deviation evidence monitoring, misjudgments of secondary phenomena and unnecessary escalation of anomalies are effectively avoided, thereby improving the accuracy and robustness of decision-making.

[0014] Furthermore, this application also proposes a step for querying the instruction context index record in the real-time index based on the device information and time information corresponding to the anomaly determination result, including: Obtain the event sequence associated with the anomaly determination result. The event sequence includes global time information and the local occurrence order constructed from local sequence numbers. When it is determined that there is a conflict between global time information and local occurrence order, the occurrence interval corresponding to the anomaly judgment result is determined according to the local occurrence order. Using the occurrence interval as a time base, the matching instruction context index record is queried in the real-time index.

[0015] The above solution resolves the conflict between global time information and local occurrence order. By determining the occurrence interval through local occurrence order, the accuracy of anomaly detection results and instruction context index record queries is improved.

[0016] Furthermore, this application also proposes that the step of writing the instruction context index record into the real-time index includes: Using the device number and local sequence number as the primary keys, a write request is initiated in the real-time index; When a target record with the same primary key is detected in the real-time index, the receiving time and status flag of the target record are updated, and the original impact flag in the target record is retained.

[0017] The above approach optimizes the real-time index writing mechanism by updating existing records instead of repeatedly writing them, ensuring data consistency and the persistence of impact identifiers, and avoiding information loss.

[0018] Furthermore, this application also proposes that the method further includes the following steps: When the impact identifier fails the validation and the impact identifier field exists in the event summary, a restricted instruction context index record marked as untrusted is generated. Write restricted instruction context index records into the real-time index; When delayed processing is performed on the anomaly determination result based on the restricted instruction context index record, a blocking prompt is triggered. The blocking prompt is used to request manual confirmation or secondary verification in the background.

[0019] The above scheme adds a mechanism for handling untrusted influence identifiers. By generating restricted instruction context index records and triggering blocking prompts, manual confirmation or secondary verification is introduced, thereby enhancing the security and reliability of the system.

[0020] Furthermore, this application also proposes that the method further includes the following steps: When obtaining the anomaly determination result for the target object, concurrent status information is received from preset independent sensors, including fire environment sensors or access control physical status sensors. When concurrent state information represents a confirmed emergency event of physical damage or environmental mutation, the matching results of the instruction context index record in the real-time index are ignored; Bypass the delay processing and directly execute the corresponding highest-level response action on the anomaly determination result.

[0021] The above approach introduces concurrent state information from independent sensors, enabling the highest-level response to be executed directly without delay when an emergency is confirmed, thus ensuring a rapid response to real emergencies.

[0022] Furthermore, this application also proposes that the method further includes the following steps: After the influence period of the corresponding instruction is recorded in the instruction context index, the summaries of all events that have been entered into the database and belong to the influence period in the review queue are merged. Perform a deviation evidence backtracking verification on the merged event summary; When the back-verification of deviation evidence does not reveal cross-regional synchronization anomalies or local deviation behaviors, the anomaly judgment result will be characterized as a secondary phenomenon caused by the linkage command. The qualitative conclusions of secondary phenomena and the execution records should be archived together.

[0023] By using the above method to backtrack and verify the event summaries in the review queue, we can accurately identify secondary phenomena caused by linkage commands, avoid misjudging them as new anomalies, and thus reduce false alarms and unnecessary interventions.

[0024] Furthermore, this application also proposes that the method further includes the following steps: Obtain the intervention type corresponding to the linkage command and the on-site spatial parameters of the affected area; Based on the intervention type and on-site spatial parameters, calculate the shortest observable response time and the longest tolerable response time corresponding to the linkage command; Read the expected effective start sequence number from the instruction context index record and determine the baseline occurrence time corresponding to the expected effective start sequence number; The time window of the influence period is determined by using the baseline occurrence time plus the shortest observable response time as the starting boundary and the baseline occurrence time plus the longest tolerable response time as the ending boundary. When the time information corresponding to the anomaly determination result falls within the time window, it is confirmed that the anomaly determination result is within the period of influence.

[0025] The above scheme provides a method for accurately determining the time window of the instruction's impact period. By calculating the shortest / longest observable reaction time, it ensures an accurate correlation between the anomaly judgment result and the instruction's impact period, thereby improving the accuracy of the judgment.

[0026] Furthermore, this application also proposes that deviation evidence events, including local deviation behaviors contrary to the expected linkage instructions, be determined in the following way: Obtain the crowd forward vector of the target object corresponding to the anomaly judgment result in two consecutive summary time periods before and after the linkage command takes effect; Based on the crowd's forward vector, calculate the average speed difference and relative growth rate of the crowd in the target area; Compare the average speed difference of the population with the preset absolute speed threshold, and compare the relative growth rate with the preset relative growth threshold; When the average speed difference of the crowd is greater than the absolute speed threshold, or the relative growth rate is greater than the relative growth threshold, it is determined that a behavior opposite to the target direction of the linkage instruction has occurred, and the local deviation behavior is confirmed to be acquired.

[0027] The above scheme provides a method for quantitatively judging local deviation behavior. By analyzing the crowd's forward vector, speed difference, and growth rate, it is possible to objectively and accurately identify behaviors that are contrary to the expectations of the linkage command, as evidence of deviation.

[0028] Furthermore, this application also proposes an image recognition-based campus security sensing and emergency response system for performing the above-mentioned methods, including: The receiving module is used to receive event digests sent by edge nodes. The event digest includes at least the device number, local sequence number, and impact identifier. The impact identifier is associated with the issued linkage command. The extraction module is used to extract impact identifiers from event summaries and to verify these impact identifiers. The generation module is used to generate an instruction context index record based on the device number, local sequence number and influence identifier when the influence identifier passes the verification, and write the instruction context index record into the real-time index; The determination module is used to perform granular tolerance determination based on the frame interval span of the event digest after writing the instruction context index record. The offloading module is used to offload the event summary to the review queue when the span of the determined frame interval exceeds the preset tolerance threshold, and retain the instruction context index record in the real-time index; The acquisition module is used to obtain the anomaly determination results for the target object; The query module is used to query the instruction context index records in the real-time index based on the device information and time information corresponding to the anomaly determination result; The execution module is used to perform delayed processing on the exception determination result when a matching instruction context index record is found and the exception determination result is within the influence period of the instruction corresponding to the instruction context index record.

[0029] The above solution provides a system that can effectively execute the above methods. Through modular design, it realizes the various functions of the methods and improves the overall performance and deployment efficiency of the system.

[0030] As can be seen from the above, the campus security perception and emergency linkage method and system based on image recognition provided in this application receives event summaries containing impact identifiers sent by edge nodes, verifies the impact identifiers, generates instruction context index records after successful verification, and writes them into the real-time index; after writing the index, a granular tolerance judgment is performed based on the frame interval span of the event summary. If the threshold is exceeded, the data is diverted to the review queue but the index is retained; then, the anomaly judgment result is obtained, and the instruction context index records in the real-time index are queried based on the device and time information; when a matching record is found and the anomaly judgment result is within the instruction impact period, the anomaly judgment result is delayed. This method effectively distinguishes between secondary phenomena caused by linkage commands and real abnormal events by introducing impact identifiers and command context index records, combined with granular tolerance judgment and delay processing mechanisms. It avoids false alarm escalation and excessive intervention caused by data timing misalignment and system self-feedback, thereby improving the accuracy and robustness of security decisions. It has the advantage of effectively solving the problems of high false alarm rate and excessive system intervention caused by high load, data timing misalignment and secondary effects of linkage commands in smart campus security systems, and improving the accuracy and robustness of security decisions. Attached Figure Description

[0031] Figure 1 This is a flowchart illustrating a campus security sensing and emergency response method based on image recognition, which is provided for this application.

[0032] Figure 2 This application provides a schematic diagram of the structure of a campus security sensing and emergency response system based on image recognition.

[0033] In the diagram: 1. Receiving module; 2. Extraction module; 3. Generation module; 4. Judgment module; 5. Stream splitting module; 6. Acquisition module; 7. Query module; 8. Execution module. Detailed Implementation

[0034] The technical solutions of this application will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this application, and not all embodiments. The components of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0035] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0036] Reference Figure 1 This application proposes a campus security perception and emergency response method based on image recognition, which includes: S110. Receive an event digest sent by the edge node. The event digest includes at least the device number, local sequence number, and impact identifier. The impact identifier is associated with the issued linkage command. S120. Extract the impact identifier from the event summary and verify the impact identifier; S130. When the impact identifier passes the verification, an instruction context index record is generated based on the device number, local sequence number and impact identifier, and the instruction context index record is written into the real-time index. S140. After writing the instruction context index record, perform granular tolerance determination based on the frame interval span of the event summary. S150. When the span of the frame interval is determined to exceed the preset tolerance threshold, the event summary is diverted to the review queue and the instruction context index record is retained in the real-time index. S160. Obtain the anomaly determination result for the target object; S170. Based on the device information and time information corresponding to the anomaly determination result, query the instruction context index record in the real-time index; S180. When a matching instruction context index record is found and the exception determination result is within the influence period of the instruction corresponding to the instruction context index record, the exception determination result is delayed.

[0037] The working principle of this application method is to establish an information processing priority mechanism that separates interpretive information from observational information, ensuring that, under any circumstances, the contextual information responsible for interpreting the situation on site can be processed and presented as quickly as possible.

[0038] Specifically, when the central platform determines that a certain area, such as Exit A of the teaching building, needs to be broadcast diverted or gate access restricted, it will generate an impact identifier at the same time as issuing this linkage instruction. This impact identifier will be sent along with the instruction to all edge devices in the affected area, such as camera CAM_A01 and access control DOOR_A01.

[0039] Subsequently, as the camera CAM_A01 continues operating, it processes the captured images into event summaries and reports them. During the command's duration, each event summary includes the previously received impact identifier. The event summary contains three key pieces of information: the device ID, which is the camera's name CAM_A01; the local sequence number, an internal counter that records the order in which events occurred (this sequence number is more reliable than a timestamp, which may be inaccurate due to network latency); and the impact identifier.

[0040] Once the central platform receives the event summary, it will immediately initiate a dual-channel processing flow.

[0041] First, upon entering the fast track, a preprocessing step immediately extracts the impact identifier from the digest and verifies it to confirm that it was issued by the central platform itself. The specific implementation of impact identifier verification includes pre-set signature verification or checksum matching. Specifically, when generating the linkage instruction, a preset encryption algorithm is used to sign the impact identifier, generating a signature string, which is then appended to the impact identifier and sent to the edge nodes. After receiving the event digest, the impact identifier and the appended signature string are extracted. The signature string is verified using the corresponding decryption algorithm or public key. If the verification result matches the extracted impact identifier, the impact identifier is deemed to have passed verification, thus ensuring that the impact identifier was indeed issued by the scheduling unit and has not been tampered with during transmission.

[0042] Once the verification is successful, an instruction context index record will be generated immediately based on the device number, local sequence number, and impact identifier. This record describes the observation of camera CAM_A01 at a certain sequence number, which was affected by a certain broadcast diversion instruction. It will also be immediately written into the real-time index database to ensure that security personnel can check it at any time.

[0043] After completing the above operations, the complete content of this event summary enters the regular processing channel. In this channel, the quality of the event summary is evaluated, which involves performing a granular tolerance determination. The process of performing granular tolerance determination based on the frame interval span of the event summary specifically involves extracting the start and end frame numbers recorded in the event summary and calculating the absolute value of the difference between them as the frame interval span. Subsequently, this frame interval span is numerically compared with a preset tolerance threshold. The preset tolerance threshold is a fixed value set based on the typical output granularity of the field equipment and the average frame span under historical normal operating conditions. When the calculated frame interval span is greater than the preset tolerance threshold, the granular stability of the event summary is deemed insufficient, i.e., the frame interval span exceeds the preset tolerance threshold, thereby triggering subsequent traffic splitting operations.

[0044] The key here is that even if the detailed content of the summary is downgraded due to quality issues, the instruction context index record is still safely retained in the real-time index.

[0045] Next, when the anomaly detection module arrives at an anomaly determination result based on various data analyses—for example, detecting an abnormal crowd gathering at Exit A of the teaching building—it will first query the real-time index before triggering an alarm. Using the device information and time information of the anomaly event, it will retrieve the previously written instruction context index record. If it finds that the current abnormal gathering event happens to occur within the impact period of the broadcast diversion instruction, then the event will not be immediately defined as an escalation of danger; instead, a delayed processing will be performed on the anomaly determination result.

[0046] The specific logic for delaying the processing of anomaly determination results is as follows: when an anomaly determination result falls within the influence period of the corresponding instruction in the instruction context index record, the regular alarm or linkage intervention action corresponding to the anomaly determination result is not immediately triggered. Instead, the status of the anomaly determination result is marked as affected and requires interpretation, and a timer of a preset duration is started. During the timer's operation, i.e., within the delay decision window, new observation data from the same area or other related areas are continuously collected to assess whether the anomaly determination result belongs to a normal secondary phenomenon caused by the linkage instruction. If sufficient deviation evidence to overturn the characterization of the secondary phenomenon is not collected before the timer expires, the alarm triggering process for the anomaly determination result is canceled.

[0047] By employing the above processing methods, we can ensure that contextual information explaining the background of an event is always indexed and prioritized immediately, even if detailed data describing the event itself is delayed due to quality issues. This fundamentally breaks the chain reaction of false alarms, preventing security personnel from misinterpreting normal crowd reactions triggered by coordinated commands as new security threats when information is incomplete, thus avoiding incorrect intervention decisions.

[0048] Furthermore, the steps for performing delayed processing on the anomaly determination result include: placing the anomaly determination result within a preset delay decision window; monitoring whether a deviation evidence event is obtained within the delay decision window, where deviation evidence events include cross-regional synchronization anomalies or local deviation behaviors contrary to the expected linkage instructions; when a deviation evidence event is obtained within the delay decision window, bypassing the delay processing and executing an anomaly escalation response; and when the delay decision window ends and no deviation evidence event is obtained, suppressing the anomaly determination result.

[0049] Specifically, delayed processing is a proactive, short decision window with a clearly defined observation target. The duration can be preset, for example, 5 seconds. During this window, two special types of deviation evidence events are specifically monitored. These events are crucial for determining whether the current situation is truly dangerous.

[0050] The first type of deviation evidence is cross-regional synchronous anomalies. For example, a broadcast diversion instruction only targets Exit 1 of Teaching Building A, but during this period, a similar abnormal gathering of people is also detected at Exit 2, which is 100 meters away from Exit 1. Since Exit 2 was not affected by the instruction, this newly emerging anomaly is likely to be an independent and broader real risk.

[0051] The second type of deviation evidence is localized deviation behavior that is contrary to the expected outcome of the linkage instruction. For example, the instruction aims to slow down the flow of people, but in the affected area, it is detected that someone forcibly rushes through the turnstile, or the average movement speed of the crowd increases instead of decreasing. This behavior is clearly contrary to the goal of the instruction and is very likely a real danger signal.

[0052] If any of the aforementioned deviation evidences are detected within the delayed decision window, the delayed processing will be immediately bypassed, and the anomaly escalation response will be executed directly to ensure rapid handling of real dangers. Conversely, if no deviation evidence is found by the end of the delayed decision window, the initial anomaly judgment will remain suppressed and ultimately classified as a normal secondary phenomenon caused by the instruction.

[0053] In one specific implementation, the step of querying the instruction context index record in the real-time index based on the device information and time information corresponding to the anomaly determination result includes: obtaining the event sequence associated with the anomaly determination result, the event sequence containing global time information and the local occurrence order constructed from local sequence numbers; when it is determined that there is a conflict between the global time information and the local occurrence order, determining the occurrence interval corresponding to the anomaly determination result based on the local occurrence order; using the occurrence interval as a time base, querying the matching instruction context index record in the real-time index.

[0054] This step is to address the issue of inaccurate global timestamps caused by frame downsampling or network latency at edge nodes. When processing an abnormal event, information from both the global time and local sequence number is obtained simultaneously. In many cases, the global time information may conflict with the local sequence of events. For example, the camera's local sequence number clearly shows that event A occurred before event B, but due to network latency, the global timestamp of event B is actually earlier than that of event A.

[0055] When such a conflict occurs, the local occurrence order, which better reflects the actual order of events in the physical world, is prioritized. Based on this reliable local order, the actual interval in which the anomalous event occurred is determined. Then, using this calibrated occurrence interval as a time base, the matching instruction context index record is queried from the real-time index. In this way, even when the timelines of various data sources are disordered, anomalous events can be accurately associated with the correct linked instruction context.

[0056] To ensure the stability and consistency of data processing, the steps for writing instruction context index records to the real-time index include: initiating a write request in the real-time index using the device number and local sequence number as the primary key; when a target record with the same primary key is detected in the real-time index, updating the reception time and status flag of the target record, and retaining the original impact flag in the target record.

[0057] At the database operation level, the device number and local sequence number are combined as the unique primary key of a record. This prevents the same event summary from being processed repeatedly due to network retransmissions, thus avoiding duplicate records in the real-time index. When a record with the exact same primary key is detected in the database, a new record is not created; instead, the status information such as the reception time of the existing record is updated. Most importantly, the original impact identifier field in the record is preserved and not overwritten. This strategy ensures that once the critical explanatory context information is recorded, it will not be lost due to subsequent data updates.

[0058] In some special cases, the method further includes the following steps: when the impact identifier fails the verification and the impact identifier field exists in the event summary, a restricted instruction context index record marked as untrusted is generated; the restricted instruction context index record is written into the real-time index; when the abnormal judgment result is processed with a delay based on the restricted instruction context index record, a blocking prompt is triggered, which is used to request manual confirmation or secondary verification in the background.

[0059] Sometimes, although the event summary includes an impact identifier field, this identifier may be corrupted due to data transmission errors or fail security verification. In such cases, a special restricted instruction context index record marked as untrusted is generated and written to the real-time index. The advantage of this is that security personnel can still see the potential connection, but they will be explicitly informed that its credibility is questionable. When subsequent decision-making logic attempts to perform delayed processing based on this untrusted record, a blocking prompt will be triggered, forcing the personnel to manually confirm or initiating a secondary verification process in the background. This ensures that a real threat is not blindly suppressed due to an incorrect or forged identifier.

[0060] To ensure responsiveness to extreme emergencies, the method further includes the following steps: when obtaining an anomaly determination result for a target object, receiving concurrent status information from preset independent sensors, including fire environment sensors or access control physical status sensors; when the concurrent status information indicates a confirmed emergency event of physical damage or environmental change, ignoring the matching results recorded in the instruction context index in the real-time index; bypassing delay processing, and directly executing the corresponding highest-level response action on the anomaly determination result.

[0061] In addition to processing image information from cameras, it also receives status information from other independent sensors in parallel, such as fire smoke sensors, temperature sensors, or access control physical status sensors that can detect whether the door has been forcibly broken. These sensors provide undeniable physical evidence. When the information from these sensors indicates a confirmed emergency, such as a fire or forced entry, all the previously established complex logic regarding impact identification and delayed processing is immediately ignored. It bypasses all intermediate steps and executes the highest level of emergency response for the event. This design ensures that the physical security of the campus can be guaranteed as quickly as possible in the most critical moments.

[0062] To enable the review of historical events and system optimization, the method further includes the following steps: after the influence period of the corresponding instruction recorded in the instruction context index ends, merging all the event summaries that have been stored in the database and belong to the influence period in the review queue; performing deviation evidence backtracking verification on the merged event summaries; when the deviation evidence backtracking verification does not find cross-regional synchronization anomalies or local deviation behaviors, the anomaly judgment result is characterized as a secondary phenomenon caused by the linkage instruction; and the qualitative conclusion of the secondary phenomenon is archived together with the execution record.

[0063] Once the impact period of a linkage command has completely ended, the event summaries of all events diverted to the review queue during this period will be automatically merged. Then, using this more complete data, a backtracking verification of deviation evidence will be performed again. If no cross-regional synchronization anomalies or local deviation behaviors are found in this review, then it can be finally confirmed that the anomalies observed during the impact period were indeed secondary phenomena caused by the linkage command. This conclusion, along with the relevant execution records, will be formally archived. This archived data is very valuable and can be used for manual review or as samples for machine learning to continuously optimize future judgment rules and linkage strategies.

[0064] To make the setting of the impact period more scientific and precise, the method also includes the following steps: obtaining the intervention type corresponding to the linkage command and the on-site spatial parameters of the affected area; calculating the shortest observable response time and the longest tolerable response time corresponding to the linkage command based on the intervention type and on-site spatial parameters; reading the expected effective start sequence number from the command context index record and determining the baseline occurrence time corresponding to the expected effective start sequence number; determining the time window of the impact period by using the baseline occurrence time plus the shortest observable response time as the starting boundary and the baseline occurrence time plus the longest tolerable response time as the ending boundary; and confirming that the anomaly judgment result is within the impact period when the time information corresponding to the anomaly judgment result falls within the time window.

[0065] As a specific implementation method, when a localized gathering of people occurs in the school's playground area at night, a linkage command is issued with the intervention type being a high-frequency flashing light warning. The intervention type corresponding to this linkage command is identified as a strong visual stimulus warning, and the on-site spatial parameters of the affected area are determined to be an unobstructed, open outdoor area with an area meeting the preset playground size standard.

[0066] Based on the intervention type of strong visual stimulus warning and the on-site spatial parameters of the open outdoor venue, the shortest observable reaction time for the crowd to visually perceive the flashing light and make a stopping or turning reaction was calculated to be two seconds. At the same time, considering the large buffer space for crowd evacuation and redistribution in the open venue, the longest tolerable reaction time for the crowd to complete behavioral adjustment was calculated to be forty-five seconds.

[0067] The expected effective start sequence number is read from the instruction context index record. This sequence number corresponds to the instant the playground edge control node receives the light control signal, and the baseline occurrence time corresponding to this expected effective start sequence number is determined to be 21:15:00 that evening. The shortest observable reaction time of 2 seconds plus this baseline occurrence time is used as the starting boundary, i.e., 21:15:02, and the longest tolerable reaction time of 45 seconds plus this baseline occurrence time is used as the ending boundary, i.e., 21:15:45. Thus, the time window of the influence period is determined to be from 21:15:02 to 21:15:45.

[0068] When an abnormal judgment result of a short-term chaotic movement of people in the playground area is obtained, and the time information corresponding to the abnormal judgment result is 21:15:20, since the time information falls within the aforementioned time window, it is confirmed that the abnormal judgment result is within the impact period. Therefore, the abnormal judgment result is delayed to avoid misjudging the normal stress dispersion behavior of the crowd after being stimulated by strong light as an escalation of safety threats.

[0069] To quantify and determine local deviation behaviors contrary to the expected direction of the command, deviation evidence events, including local deviation behaviors contrary to the expected direction of the linkage command, are determined as follows: The crowd movement vector of the target object corresponding to the anomaly determination result is obtained during two consecutive summary periods before and after the linkage command takes effect; based on the crowd movement vector, the average speed difference and relative growth rate of the crowd in the target object's region are calculated; the average speed difference is compared with a preset absolute speed threshold, and the relative growth rate is compared with a preset relative growth threshold; when the average speed difference is greater than the absolute speed threshold, or the relative growth rate is greater than the relative growth threshold, it is determined that behavior contrary to the target direction of the linkage command has occurred, and the local deviation behavior is confirmed.

[0070] Before and after the coordinated command takes effect, crowd movement vector data is continuously acquired over two time periods. By comparing the data from these two periods, the difference in average crowd speed can be calculated—an absolute change—and the relative speed increase rate can also be calculated. These two calculation results are then compared to preset absolute speed thresholds, such as 0.5 meters per second, and relative increase thresholds, such as 30 percentage points. If either value exceeds the threshold, it can be determined that behavior contrary to the command's objective, such as deceleration or diversion, has occurred on-site, confirming evidence of localized deviation behavior.

[0071] Secondly, referring to Figure 2 This application also provides an image recognition-based campus security sensing and emergency response system for performing any one of the steps in the above methods, including: The receiving module 1 is used to receive an event digest sent by the edge node. The event digest includes at least a device number, a local sequence number, and an impact identifier, and the impact identifier is associated with a issued linkage instruction. Extraction module 2 is used to extract the impact identifier from the event summary and to verify the impact identifier; Generation module 3 is used to generate an instruction context index record based on the device number, the local sequence number and the influence identifier when the influence identifier passes the verification, and write the instruction context index record into the real-time index; The determination module 4 is used to perform granular tolerance determination based on the frame interval span of the event summary after writing the instruction context index record; The diversion module 5 is used to divert the event summary to the review queue when it is determined that the frame interval span exceeds the preset tolerance threshold, and to retain the instruction context index record in the real-time index. Module 6 is used to obtain the anomaly determination results for the target object; Query module 7 is used to query the instruction context index record in the real-time index based on the device information and time information corresponding to the anomaly determination result; Execution module 8 is used to perform delayed processing on the exception determination result when a matching instruction context index record is found and the exception determination result is within the influence period of the instruction corresponding to the instruction context index record.

[0072] This method effectively distinguishes between secondary phenomena caused by linkage commands and real abnormal events by introducing impact identifiers and command context index records, combined with granular tolerance judgment and delayed processing mechanisms. It avoids false alarms and excessive intervention caused by data timing misalignment and system self-feedback, thereby improving the accuracy and robustness of security decisions. It effectively addresses the problems of high false alarm rates and excessive system intervention caused by high load, data timing misalignment, and secondary effects of linkage commands in smart campus security systems, thus improving the accuracy and robustness of security decisions. This method effectively solves the problems of high false alarm rates and excessive system intervention caused by high load, data timing misalignment, and secondary effects of linkage commands in smart campus security systems, improving the accuracy and robustness of security decisions. The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A campus security sensing and emergency response method based on image recognition, characterized in that, include: Receive an event digest sent by an edge node, the event digest containing at least a device number, a local sequence number, and an impact identifier, the impact identifier being associated with a issued linkage instruction; Extract the impact identifier from the event summary and verify the impact identifier; When the impact identifier passes the verification, an instruction context index record is generated based on the device number, the local sequence number, and the impact identifier, and the instruction context index record is written into the real-time index; After writing the instruction context index record, a granular tolerance determination is performed based on the frame interval span of the event summary; When it is determined that the span of the frame interval exceeds the preset tolerance threshold, the event summary is diverted to the review queue, and the instruction context index record is retained in the real-time index; Obtain the anomaly assessment result for the target object; Based on the device information and time information corresponding to the anomaly determination result, query the instruction context index record in the real-time index; When a matching instruction context index record is found, and the anomaly determination result is within the influence period of the instruction corresponding to the instruction context index record, a delay processing is performed on the anomaly determination result.

2. The campus security perception and emergency response method based on image recognition according to claim 1, characterized in that, The step of performing delayed processing on the anomaly determination result includes: The anomaly determination result is placed within a preset time delay decision window; Within the delay decision window, it is monitored whether deviation evidence events are obtained. Deviation evidence events include cross-regional synchronization anomalies or local deviation behaviors that are contrary to the expected linkage instructions. When the deviation evidence event is obtained within the delay decision window, the delay processing is bypassed and an abnormal escalation response is executed. When the delayed decision window ends and no deviation evidence event is obtained, the abnormal judgment result is suppressed.

3. The campus security perception and emergency response method based on image recognition according to claim 1, characterized in that, The step of querying the instruction context index record in the real-time index based on the device information and time information corresponding to the anomaly determination result includes: Obtain the event sequence associated with the anomaly determination result, wherein the event sequence includes global time information and a local occurrence order constructed from the local sequence number; When it is determined that there is a conflict between the global time information and the local occurrence order, the occurrence interval corresponding to the anomaly determination result is determined according to the local occurrence order. Using the occurrence interval as a time base, a matching instruction context index record is queried in the real-time index.

4. The campus security perception and emergency response method based on image recognition according to claim 1, characterized in that, The step of writing the instruction context index record into the real-time index includes: Using the device number and the local sequence number as primary keys, initiate a write request in the real-time index; When a target record with the same primary key is detected in the real-time index, the reception time and status flag of the target record are updated, and the original impact flag in the target record is retained.

5. The campus security perception and emergency response method based on image recognition according to claim 1, characterized in that, The method also includes the following steps: When the impact identifier fails the verification and it is determined that the impact identifier field exists in the event summary, a restricted instruction context index record marked as untrusted is generated; Write the restricted instruction context index record into the real-time index; When the exception determination result is processed with a delay based on the restricted instruction context index record, a blocking prompt is triggered, which is used to request manual confirmation or secondary verification in the background.

6. The campus security perception and emergency response method based on image recognition according to claim 1, characterized in that, The method also includes the following steps: When obtaining the anomaly determination result for the target object, concurrent status information is received from a preset independent sensor, which includes a fire environment sensor or an access control physical status sensor. When the concurrent state information represents a confirmed emergency event of physical damage or environmental change, the matching results of the instruction context index record in the real-time index are ignored; Bypass the aforementioned delay processing and directly execute the corresponding highest-level response action on the anomaly determination result.

7. The campus security perception and emergency response method based on image recognition according to claim 2, characterized in that, The method also includes the following steps: After the influence period of the instruction corresponding to the instruction in the instruction context index record ends, the summaries of all events that have been entered into the database and belong to the influence period in the review queue are merged. Perform a deviation evidence backtracking verification on the merged event summary; When the back-verification of the deviation evidence does not reveal any cross-regional synchronization anomalies or local deviation behaviors, the anomaly determination result is characterized as a secondary phenomenon caused by the linkage command. The qualitative conclusions regarding the secondary phenomena, along with the execution records, should be archived together.

8. The campus security perception and emergency response method based on image recognition according to claim 1, characterized in that, The method also includes the following steps: Obtain the intervention type corresponding to the linkage command and the on-site spatial parameters of the affected area; Based on the intervention type and the on-site spatial parameters, calculate the shortest observable response time and the longest tolerable response time corresponding to the linkage command; Read the expected effective start sequence number from the instruction context index record, and determine the baseline occurrence time corresponding to the expected effective start sequence number; The time window of the influence period is determined by taking the baseline occurrence time plus the shortest observable response time as the starting boundary and the baseline occurrence time plus the longest tolerable response time as the ending boundary. When the time information corresponding to the anomaly determination result falls within the time window, it is confirmed that the anomaly determination result is within the period of influence.

9. A campus security sensing and emergency response method based on image recognition according to claim 2, characterized in that, The deviation evidence events, including local deviation behaviors contrary to the expected linkage instructions, are determined in the following ways: Obtain the crowd forward vector of the target object corresponding to the anomaly determination result during two consecutive summary time periods before and after the linkage instruction takes effect; Based on the crowd's forward vector, calculate the average speed difference and relative growth rate of the crowd in the area where the target object is located; The average speed difference of the population is compared with a preset absolute speed threshold, and the relative growth rate is compared with a preset relative growth threshold. When the average speed difference of the crowd is greater than the absolute speed threshold, or the relative growth rate is greater than the relative growth threshold, it is determined that a behavior opposite to the target direction of the linkage command has occurred, and the local deviation behavior is confirmed to have been obtained.

10. A campus security sensing and emergency response system based on image recognition, used to execute the method according to any one of claims 1 to 9, characterized in that, include: The receiving module is used to receive an event digest sent by the edge node. The event digest includes at least the device number, local sequence number, and impact identifier, and the impact identifier is associated with the issued linkage instruction. An extraction module is used to extract the impact identifier from the event summary and to verify the impact identifier; The generation module is used to generate an instruction context index record based on the device number, the local sequence number, and the influence identifier when the influence identifier passes the verification, and write the instruction context index record into the real-time index; The determination module is used to perform granular tolerance determination based on the frame interval span of the event summary after writing the instruction context index record; The traffic splitting module is used to split the event summary to the review queue when it is determined that the frame interval span exceeds the preset tolerance threshold, and to retain the instruction context index record in the real-time index. The acquisition module is used to obtain the anomaly determination results for the target object; The query module is used to query the instruction context index record in the real-time index based on the device information and time information corresponding to the anomaly determination result; The execution module is used to perform delayed processing on the exception determination result when a matching instruction context index record is found and the exception determination result is within the influence period of the instruction corresponding to the instruction context index record.