An adaptive intelligent behavior management method for heterogeneous terminals

By employing an adaptive intelligent behavior control method based on multimodal data acquisition and virtual synchronous collaboration, the challenges of inconsistent control and privacy protection for heterogeneous terminal devices have been resolved. This method achieves efficient, accurate, and low-latency unified control across devices, extending coverage to devices that cannot install client software, thus meeting the needs of user experience and privacy protection.

CN122120378APending Publication Date: 2026-05-29HANZHONG BIG FRUIT TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HANZHONG BIG FRUIT TECHNOLOGY CO LTD
Filing Date
2026-02-27
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing technologies face several challenges when dealing with heterogeneous terminal devices, including inconsistent control effects due to device performance heterogeneity, the ease with which a single data channel can be bypassed, inconsistent control across devices, the inability to install control clients on some devices, and the difficulty in balancing privacy protection and control effectiveness.

Method used

An adaptive intelligent behavior control method based on the physical performance status of the terminal is adopted. Through multimodal data collection, performance perception and dynamic policy adaptation, multimodal behavior intent recognition and virtual synchronization collaboration, cross-device collaborative and consistent control is achieved.

Benefits of technology

It achieves adaptive management and control across devices on heterogeneous terminals, significantly improving the ability to prevent bypass, increasing the recognition accuracy, reducing latency, and expanding the coverage to non-standard devices. It also maintains user experience while ensuring privacy protection, with a theoretical expected accuracy of over 98%.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
  • Figure FT_3
    Figure FT_3
Patent Text Reader

Abstract

The application discloses a kind of self-adapting intelligent behavior management and control methods for heterogeneous terminal, electronic equipment and storage medium, belong to the technical field of intelligent terminal management and control.The method comprises: real-time acquisition of multi-modal operation data on terminal equipment side;Dynamic adaptation behavior analysis strategy based on terminal real-time performance state;According to the adaptive strategy, real-time analysis is carried out on data to identify user behavior intention category;Trigger control action based on the identification result;Wherein, through the virtual synchronization mechanism maintained by the cloud global state pool, the cross-device state freezing mark is actively broadcast to all associated terminals, and the control strategy is forced to be synchronized and executed, to realize cross-device consistency control.The application solves the technical problems of inconsistent control effect in heterogeneous terminal environment, single-channel bypassing and cross-device state asynchronization through the cooperation of performance perception dynamic adaptation, multi-modal fusion identification and virtual synchronization mechanism, significantly improves the accuracy, robustness and consistency of behavior control, and guarantees user privacy security through localization desensitization processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of intelligent terminal management technology, specifically to an adaptive intelligent behavior management method for heterogeneous terminals, which is particularly suitable for scenarios such as parental control, enterprise device management, and educational institution device supervision. Background Technology

[0002] With the widespread adoption of smart devices, a large number of heterogeneous devices exist in homes, schools, and businesses, including smartphones, tablets, smart TVs, and personal computers. These devices differ significantly in performance, operating systems, and network environments, posing a significant challenge to unified behavior management.

[0003] Problems with existing technology Question 1: Inconsistent control effects due to heterogeneous equipment performance Existing device management solutions typically employ a uniform analysis strategy, failing to consider the performance differences between various devices. For example, an analysis algorithm that runs smoothly on a high-performance mobile phone may cause lag or even crashes on a low-performance smart TV. This "one-size-fits-all" approach cannot guarantee both effective control and a superior user experience.

[0004] Question 2: Single data channel is easily bypassed. Existing solutions typically rely on a single data channel for behavior identification, such as network traffic analysis or application process monitoring. This approach has significant loopholes: users can easily bypass controls by disabling VPNs, using encrypted DNS, or casting their screens.

[0005] Question 3: Inconsistent management across devices The existing solution lacks a cross-device state synchronization mechanism. When a user is frozen for violating regulations on one device, they can immediately switch to another device to continue using the device, rendering the control ineffective. This "whack-a-mole" approach to control cannot truly solve the problem.

[0006] Question 4: The management client cannot be installed on some devices. Smart TVs, game consoles, and other devices typically do not support the installation of third-party applications, making them a blind spot for regulation. Existing solutions are unable to effectively manage these devices.

[0007] Question 5: It is difficult to balance privacy protection and effective regulation. To achieve accurate behavior recognition, existing solutions typically require collecting large amounts of raw data (such as screenshots and complete data packets), which contains a significant amount of personal privacy information. How to achieve effective control while protecting privacy is a pressing issue that needs to be addressed.

[0008] Limitations of existing technical solutions Currently available equipment management solutions mainly include: 1. Application-layer-based control solution: Implemented by installing a control app on the device. Limitations: Cannot control devices without the app installed; easily uninstalled or disabled; 2. Network layer-based control scheme: Traffic analysis is performed through routers or gateways. Limitations: Cannot identify encrypted traffic; cannot obtain device-side behavioral data; 3. Operating System-Based Control Solution: Utilizing parental control functions provided by the operating system. Limitations: Limited functionality; inconsistent functionality across different operating systems; inability to work across devices.

[0009] These solutions all have obvious limitations and cannot meet the comprehensive requirements of control effectiveness, user experience, and privacy protection in practical applications.

[0010] Analysis of existing solutions in related technical fields In the relevant technical field, the following types of potentially related technical solutions exist: 1. Model adaptation solution based on business containers These solutions are primarily used in server environments, selecting different recognition models based on the type of business container. For example, different traffic recognition models are invoked for different business containers (such as payment containers and social containers).

[0011] limitation: - The adaptation is based on business requirements, not on the physical performance of the terminal. - Suitable for server environments (with ample resources), not suitable for mobile devices (with limited resources). - Unable to cope with the problems of large fluctuations in computing power and limited battery life on mobile terminals - The granularity is at the server / container level, rather than at the endpoint user behavior level. 2. Multimodal Fusion Solution for Payment Scenarios These solutions are primarily used for payment security, employing a combination of voice, text, image, and touch trajectory data for identity verification and error correction.

[0012] limitation: - Limited to the specific scenario of payment security - User proactive cooperation, no bypass requirements - No fault tolerance mechanism (failure of a single channel means failure). - Not suitable for continuous behavior monitoring and control scenarios - Subsequent actions are limited to auditing and alerting, with no adaptive policy adaptation or cross-platform synchronous execution. 3. Traffic interception scheme for edge gateways This type of solution uses an edge gateway to perform initial identification of traffic, allowing normal traffic to pass and blocking abnormal traffic, in order to reduce the latency from the gateway to the cloud server.

[0013] limitation: - Only implements the simple logic of "local exception blocking and cloud log storage". - No cross-device collaboration mechanism - If device A violates the rules, only device A will be blocked; devices B and C will not be affected. - Users can easily bypass controls by switching devices. - Lack of a virtual synchronization mechanism that causes "one violation, global freeze". 4. Intent recognition scheme for operation and maintenance commands These solutions utilize behavioral intent recognition models to identify abnormal commands from operations and maintenance personnel and determine risk control strategies (blocking, alarming).

[0014] limitation: - The identified object is the instructions (text / command stream) from operations and maintenance personnel. - Single data source, processing only text data - Unable to recognize complex behavioral sequences across applications and modalities. - Not applicable to full-modal behavior recognition for heterogeneous end users 5. Tiered processing scheme for the back-end approval system These solutions employ a three-tiered review architecture, including "rapid review," "full-modal review (in-depth analysis)," and "adaptive feedback," to improve the efficiency of the review process.

[0015] limitation: - The purpose of the tiered system is to improve the efficiency of the review process (fast, accurate, and stable), rather than to adapt to the physical performance of the terminal. - The triggering factor is the complexity of the content, not the terminal's battery power, computing power, or thermal power consumption. - Runs on a cloud-based or backend review system (with ample server resources), rather than on the client-side (where resources are limited). - No cross-device collaboration mechanism - This is fundamentally different from terminal-side control scenarios. The essential difference between this invention and the prior art The essential difference between this invention and the aforementioned prior art lies in: 1. Fundamental differences in adaptation dimensions Existing technologies adapt based on "business containers" or "content complexity," while this invention adapts based on "terminal physical performance status" (computing power, battery level, thermal power consumption). This is because the performance of mobile terminals fluctuates greatly (when the battery level drops from 100% to 20%, the computing power may decrease by more than 50%), and real-time adaptation is necessary to ensure system availability. Without performance adaptation, low-performance devices will experience lag or even crash, becoming completely unusable.

[0016] 2. Fundamentally different application scenarios Existing technologies are limited to specific scenarios (payment security, content moderation, operation and maintenance monitoring), while this invention is positioned for general behavior control (parental control, enterprise management, school supervision). General behavior control scenarios require: - Enhanced anti-bypass capabilities (the controlled end may actively counter this). - Cross-device collaboration capability (the controlled end may switch devices). - Continuous behavioral monitoring (rather than one-time verification or auditing) - Multimodal data fusion (to handle extreme environments such as encrypted traffic) 3. Fundamental differences in the depth of collaboration Existing technologies only achieve simple data synchronization or interception, while this invention implements a "virtual synchronization mechanism" (one violation, global freeze). Specifically, it is manifested in: - Cloud-based global state pool maintains cross-device freeze flags - Active broadcast mechanism (long-connection push / device wake-up) - Status linkage between related devices (if A violates a rule, synchronization of B / C is restricted) - Forced execution without secondary verification This virtual synchronization mechanism is a vacuum in existing technology; no patent mentions how to enable related devices (such as TVs and mobile phones) to share a logical state and enforce control policies.

[0017] 4. Fundamentally different architectural positioning Existing technologies are mostly single-point algorithm solutions (such as a specific recognition algorithm or a specific synchronization algorithm). This invention is an end-to-end complete architecture solution, covering: - Data Acquisition (Multimodal Data) - Feature extraction (local anonymization processing) - Intent recognition (behavioral sequences across applications and modalities) - Policy adaptation (dynamic selection based on terminal performance) - Control and management execution (terminal side and control and management node side) - State synchronization (virtual synchronization mechanism) This systematic innovation enables the present invention to ensure effective control while also taking into account user experience and privacy protection.

[0018] 5. Fundamental differences in the scope of recognition Existing intent recognition technologies are limited to a single command stream or a single data source, while this invention identifies "cross-application, cross-modal behavioral sequences." For example: - The controlled device first opens the game app (process channel). - Then turn off the VPN (traffic channel abnormality). - The game screen displays the game footage (screen channel). - Device landscape mode (sensor channel) This invention can integrate this cross-application, cross-modal information to accurately identify the true intent of the controlled device, which is something that existing technologies cannot do.

[0019] Differences and Refinements Summary In summary, the essential difference between this invention and the prior art lies in: 1) Upgraded Adaptation Dimension: The adaptation was upgraded from "business / content adaptation" to "terminal physical performance adaptation," resolving usability issues caused by mobile terminal performance fluctuations. 2) Architectural Upgrade: The architecture has been upgraded from a "single-point algorithm" to an "end-to-end system architecture," providing a complete solution from data acquisition to control and execution. 3) Enhanced Collaboration: Moving beyond "simple synchronization" to "forced collaboration based on virtual synchronization logic," achieving cross-device consistency management. This multi-dimensional upgrade and combination is not a simple patchwork of existing technologies, but a systematic innovation targeting the specific challenge of "intelligent management and control of heterogeneous terminals". This invention deeply couples three technical dimensions: "terminal performance perception", "multimodal fusion recognition" and "virtual synchronization mechanism", generating a synergistic effect of "1+1+1>3", comprehensively solving five major problems: heterogeneous device performance, easy bypassing of single channels, inconsistency across devices, inability to manage some devices, and difficulty in balancing privacy protection and management effectiveness. Summary of the Invention

[0020] Terminology Explanation For ease of understanding, the meanings of relevant terms in this article are as follows: Heterogeneous terminals: refer to various smart devices that differ in computing power, memory, operating system, network connectivity, etc., such as smartphones, tablets, smart TVs, personal computers and Internet of Things devices; Multimodal data: The 'multimodal data' refers to data from two or more different forms or sources that are preferentially used to achieve more accurate and robust behavior recognition. In specific simplified implementation scenarios or for specific behavior types, the system can also operate based on a single data modality; Behavioral intent category: refers to the category to which the user behavior belongs, identified through the fusion analysis of the multimodal data, such as work, study, entertainment, or specific restricted behaviors (such as games, videos). Control node: refers to the logical entity that performs control functions such as traffic analysis and policy execution. Its physical form can be a proxy module, home gateway, edge server or cloud microservice deployed locally on the terminal. Virtual synchronization: refers to a mechanism that uses a global logical state (such as a freeze flag) maintained in the cloud and actively broadcasts it to all associated physical terminals to force consistency of management state across devices; Global state pool: refers to a database that is centrally stored and maintained on a cloud server, containing the logical control status of all associated terminals of the same user, and serves as the sole source of facts for cross-device state synchronization; Graceful degradation: refers to a fault-tolerant mechanism in which the system automatically switches to a low-resource-consumption mode when the terminal device is in an extremely resource-constrained state (such as power depletion or network interruption), maintaining operation while ensuring core control functions and emergency communication capabilities.

[0021] This invention recognizes that the reason why existing technologies cannot solve the five major problems described in the background technology is that they are all isolated, single-point solutions. For example, business container adaptation (related patents) only solves server-side resource scheduling and does not care about terminal performance; multimodal payment verification (related patents) only solves single-time authentication and has no need for continuous management and anti-bypass; edge gateway interception (related patents) only achieves single-device blocking and has no cross-device collaboration.

[0022] Technological Evolution and Systemic Conception of the Invention This invention relates to a systematic innovation in the field of intelligent terminal behavior control. The applicant's previous series of applications have gradually built up the fundamental technological capabilities in this field: Application number CN202610105087.1 mainly solves the problem of content recognition and classification under encrypted traffic; Application number CN202610105510.8 mainly constructs a terminal control relationship model based on incentive and trust assessment; Application number CN202610217869.4 mainly implements the security management of multi-role devices.

[0023] However, in complex scenarios where multiple managed devices have heterogeneous performance and require real-time collaboration, achieving global consistency and bypass-resistant collaborative governance across terminals becomes a core challenge not yet covered by the aforementioned technical systems. Specifically, existing solutions lack the ability to dynamically adapt to fluctuations in terminal physical performance and have failed to establish a mandatory state synchronization network across multiple managed devices.

[0024] To address these challenges, this invention proposes an end-to-end architectural innovation based on the aforementioned technologies. This innovation aims to systematically solve the challenges by deeply integrating three dimensions: terminal performance perception and dynamic adaptation, multimodal behavior sequence recognition, and virtual synchronous collaboration.

[0025] Purpose of the invention In the field of online behavior governance for minors, the applicant's prior art has successfully constructed a technical system encompassing content recognition, single-device guidance, and role-based security management. However, with the increasing diversification of devices in home and educational environments (such as the coexistence of mobile phones, tablets, TVs, and IoT devices), a more complex system-level challenge has emerged: how to achieve real-time, accurate, consistent, and user-friendly collaborative behavior governance across a network of terminals with varying performance, form factors, and operating systems (i.e., "heterogeneous terminals"). The purpose of this invention is to provide a systematic architectural solution for this new scenario and challenge of "heterogeneous terminal collaborative governance," building upon the aforementioned existing technological achievements. This solution aims to integrate and elevate preceding technologies, achieving a technological leap from "single-point intelligent control" to "network intelligent collaboration." Technical Solution Overview

[0026] To achieve the leap from single-point control to network collaboration, this invention provides an adaptive intelligent behavior control method for heterogeneous terminals. Please refer to the appendix. Figure 1 The flowchart shown mainly includes the following steps: S110: Multimodal data acquisition. On the terminal device side, multimodal operational data reflecting user behavioral intentions is acquired in real time. The data includes, but is not limited to, at least one of: network traffic data, screen image data, application process information, sensor data, and system logs, and preferably a combination of two or more modal data to achieve accurate identification of complex behavioral sequences; S120: Performance Awareness and Dynamic Policy Adaptation. Based on an assessment of the terminal device's real-time computing power, memory, power consumption, and network connectivity, a device capability score is generated, and the execution path of the behavior analysis strategy is dynamically redirected accordingly. This step dynamically decides whether the analysis task is executed locally or in the cloud based on the terminal's real-time physical resource status, to achieve the optimal balance between analysis accuracy and resource consumption. S130: Behavioral intent recognition based on multimodal fusion. According to the strategy adapted in S120, the data collected in S110 is analyzed in real time to identify the user's behavioral intent category. This recognition not only targets the instantaneous state of a single application but also covers the logical correlation analysis of cross-application and cross-modal behavioral sequences. Example scenario: The system detects that a user first performs the behavior of "searching for game strategies in a browser," and then establishes an "encrypted network tunnel." Even if the traffic within the tunnel cannot be decrypted, by associating this behavioral sequence, the system can logically determine that the user's intent is "attempting to circumvent control," thereby achieving the identification of complex circumvention strategies. S140: Control action triggered. Based on the behavioral intent category identified in S130, the corresponding control action is triggered on the terminal device side and / or the associated control node (such as cloud server, home gateway); S150: Cross-device collaboration based on virtual synchronization. Through a global state pool maintained in the cloud and virtual synchronization logic, information representing the control status (such as freeze flags) is proactively and in real time broadcast to all associated terminal devices of the user, forcing these devices to synchronously execute consistent control policies, thereby achieving cross-device collaborative consistency. Synergistic Explanation of Technical Solutions

[0027] The technological advancement of this invention does not stem from improvements to a single step, but rather from the organic integration and deep synergy of three technical dimensions represented by S120, S130, and S150, thereby empowering the entire system to address the aforementioned new challenges: Performance adaptation provides a universal foundation for high-precision recognition (Dimension 1): Step S120 (dynamic adaptation) ensures that the algorithm, which may involve complex calculations in step S130 (multimodal behavior sequence recognition), can run stably on all devices, from high-end mobile phones to low-performance TVs, in the most suitable way according to the terminal performance. This solves the core deployment problem caused by uneven computing power of heterogeneous terminals, enabling advanced recognition capabilities to be fully covered; Behavioral sequence recognition provides high-confidence decision signals for collaborative management (Dimension 2): Step S130 (multimodal fusion and sequence analysis) can generate accurate intent determination that is resistant to interference and bypass. This provides a reliable and accurate trigger source for step S150 (virtual synchronization), ensuring that cross-device collaborative actions are based on high-confidence judgments and effectively avoiding user experience damage caused by mismanagement. Virtual synchronization integrates and amplifies single-point capabilities into a network-level effect (Dimension 3): Step S150 (virtual synchronization), acting as the system's "coordination hub," integrates and transforms the "precise identification" and "stable operation" capabilities achieved on a single device in steps S120 and S130 into instantaneous and consistent network-level control actions. This allows any violation judgment at a single point to instantly translate into a unified constraint on all user devices, fundamentally solving the problem of device switching bypass. In summary, this invention constructs a self-reinforcing technical closed loop through the aforementioned three-dimensional collaborative design. By introducing system-level dimensions such as resource adaptation (dimension one) and network virtual synchronization (dimension three), this invention enhances and integrates existing identification (dimension two) and control capabilities, achieving a dimensional upgrade of the technical architecture and ultimately forming a complete solution specifically designed to address the complex scenario of "heterogeneous terminal collaborative governance." Beneficial effects

[0028] The following section, combining theoretical deduction and industry benchmarks, elucidates the beneficial effects of the technical solution of this invention. It should be noted that the performance data and comparative effects cited in this section are intended to qualitatively and quantitatively illustrate its expected advantages over existing technologies, based on the technical principles, algorithm logic, and publicly available industry information of this invention. The data referred to are theoretical deduction values, simulation expected values, or early module test values, and their calculations all follow common knowledge in the relevant technical field, mathematical principles, and the following benchmarks: Public technical standards, such as 3GPP, IEEE, and RFC series standards, are used to extrapolate parameters such as network latency and bandwidth.

[0029] Academic research achievements: such as the performance of public datasets like UNSW-NB15 and ImageNet, and benchmark models like MobileNetV3.

[0030] Hardware platform specifications: such as the publicly available computing power parameters of mobile chips like Qualcomm Snapdragon and MediaTek Dimensity.

[0031] Market analysis data: such as equipment market reports published by institutions like IDC and Gartner.

[0032] Those skilled in the art, in conjunction with the above description, can understand the attainability and feasibility of the technical effects of the present invention.

[0033] Compared with the prior art, the technical solution provided by the present invention can bring the following significant and interrelated beneficial effects: (1) Achieving adaptive management and control across heterogeneous terminals, ensuring user experience and system stability. Through dynamic resource adaptation in dimension (1), the system can intelligently allocate computing tasks based on the real-time performance of the device. Theoretical analysis shows (based on publicly available computing power parameters of mainstream mobile chips and typical algorithm complexity models): On low-performance devices, by offloading complex analysis tasks to the cloud, the stuttering threshold of local CPU utilization exceeding 80% can be avoided. Based on the theoretical deduction of the performance model, the stuttering rate is expected to be reduced by more than 95%, while maintaining the recognition accuracy. This ensures the wide applicability and user acceptability of the management and control scheme on various devices.

[0034] (2) Significantly improve the anti-bypass capability and robustness of behavior recognition. Through multimodal fusion and behavior sequence recognition in dimension (II), the system no longer relies on a single signal channel. Based on public datasets (such as UNSW-NB15 and ImageNet) and typical circumvention behavior models, it is shown that when a single channel (such as traffic) fails due to VPN encryption, the system can automatically increase the decision weight of other channels (such as screens and sensors), thereby increasing the theoretically expected anti-bypass success rate from about 50% in the single-channel solution to over 98%. The recognition accuracy is also improved synchronously through the weighted fusion model.

[0035] (3) Achieving real-time cross-device collaboration and eliminating control time lag and blind spots: Through the virtual synchronization logic in dimension (3), control status can cover all related devices in a very short time. Latency analysis based on typical network conditions (RFC standard) shows that by adopting a hybrid mechanism of "long connection push + LAN broadcast", the theoretical expected latency of status synchronization can be as low as about 53ms, which is more than an order of magnitude lower than the traditional cloud polling scheme (about 900ms). This makes it almost impossible for users to use the time difference of device switching to circumvent control, and the theoretical expected success rate of cross-device control can reach 98%.

[0036] (4) Expanding the scope of control to non-standard devices to achieve comprehensive management. Combining non-intrusive technologies such as traffic mirroring and protocol interaction, this invention can effectively control devices without dedicated clients (such as smart TVs and game consoles). Based on theoretical deductions from industry market analysis data (such as IDC reports), this capability can increase device coverage from approximately 60% for App-only solutions to 100%, completely eliminating control blind spots caused by device type limitations.

[0037] (5) Implementing privacy protection design principles while maintaining efficient management: In the data collection and processing stages, this invention implements "default privacy design". For example, screen image data is converted into desensitized feature vectors locally, and only about 1KB of abstract feature information is uploaded. According to the principles of image processing and information theory, this approach can reduce the amount of data uploaded per instance by more than 99.95% compared to transmitting the original image, while maintaining high recognition accuracy. Moreover, the technical process complies with the requirements of China's Personal Information Protection Law and other laws and regulations, as well as international standards such as the EU GDPR for de-identification and privacy protection.

[0038] (6) Synergistic effect analysis of technical features The core advantage of this invention lies in the system-level gain resulting from the deep synergy of its multiple technical features, which is far more than a simple summation of the effects of a single feature. This is specifically reflected in the following two key aspects: (1) Delayed Synergistic Effect of Identification and Collaboration By combining efficient local identification (corresponding to step S130) with a lightweight virtual synchronization mechanism (corresponding to step S150), this invention achieves forced cross-device collaboration while keeping the total system latency at an extremely low level. Theoretical analysis shows that the traditional solution relying on cloud analysis and polling synchronization has an expected total latency of about 900 milliseconds; if only local identification capability is available, the latency can be as low as about 45 milliseconds, but cross-device collaboration cannot be achieved. The solution of this invention controls the total latency to about 53 milliseconds through the collaborative design of "local identification (about 45 milliseconds) + local area network virtual synchronization (about 8 milliseconds)". This means that this invention achieves a qualitative change from "single-point control" to "full-network collaboration" without introducing almost any additional latency, completely eliminating the possibility of users bypassing the device switching time difference (usually several seconds); (2) Synergistic Effect of Multimodal Recognition and Performance Adaptation: This invention, through a performance adaptation strategy (corresponding to step S120), enables multimodal fusion recognition capabilities (corresponding to step S130) to flexibly adapt to various heterogeneous terminals, thereby unifying recognition accuracy and device coverage. The expected performance on different devices is compared as follows: - On high-performance devices such as flagship smartphones, the expected accuracy of a single traffic recognition scheme is about 78%, and that of a single screen recognition scheme is about 85%. However, this invention can improve the expected accuracy to about 92% through local full-modal fusion. - On mid-performance devices such as entry-level tablets, a single traffic recognition solution achieves an accuracy of approximately 75%, while a single screen recognition solution may cause device lag due to computational load. This invention, through an adaptive strategy of "local traffic analysis + cloud-assisted analysis," can maintain the expected accuracy at approximately 90% while avoiding lag. - On devices such as smart TVs where client applications cannot be directly installed, a single solution typically cannot directly collect valid data. This invention, through non-intrusive control technologies such as traffic mirroring mentioned in Effect 4 above, can still achieve the expected identification accuracy of approximately 89%.

[0039] In summary, the adaptive mechanism of this invention ensures the availability and stability of advanced recognition capabilities across terminals with varying performance and form factors, solving the fundamental problem that a single technical solution cannot balance performance, accuracy, and coverage in complex heterogeneous environments. The aforementioned synergistic effects further demonstrate the technical value of this invention as a complete system architecture. Attached Figure Description

[0040] Figure 1 The overall flowchart of an adaptive intelligent behavior control method for heterogeneous terminals provided by the present invention shows the main process of the entire lifecycle from multimodal data acquisition (S110), performance perception and dynamic policy adaptation (S120), behavior intent recognition (S130), control action triggering (S140) to cross-device collaboration based on virtual synchronization (S150). Figure 2 is Figure 1 The schematic diagram of the sub-process of equipment capability assessment and dynamic strategy adaptation in step S120 shows the anti-vibration processing through smoothing filtering and hysteresis comparison, and the decision logic of dynamically selecting strategy A (local full function), strategy B (end-cloud collaboration) or strategy C (cloud-led) based on the scoring judgment result. Figure 3 is Figure 1 The middle step S130 is a schematic diagram of the behavior intent recognition process based on multimodal fusion, which focuses on multi-channel data acquisition (S110), local feature extraction and desensitization, weighted fusion calculation in the fusion decision engine, and the weight adaptive adjustment mechanism based on confidence feedback. Figure 4 is Figure 1 The middle step S150 is a schematic diagram of the cross-device collaborative management process based on virtual synchronization, which shows the complete closed-loop logic from single-point violation triggering (S32), cloud generation of freeze mark and broadcast (S33), forced execution by associated devices (S34), to offline consensus mechanism (S35) and automatic policy release (S36). Figure 5 is a schematic diagram of the non-intrusive control process for a local area network environment in this invention, showing the technical solution through control node deployment (S41), traffic mirroring configuration (S42), network behavior analysis (S43), non-intrusive action execution (S44), and status synchronization reporting (S45). Figure 6 is a schematic diagram of the privacy protection processing flow for screen image data in this invention, which reflects the security mechanism from controllable collection and localized processing (S51), privacy stripping and feature extraction (S52), irreversibility protection (S53) to compliant uploading and cloud analysis (S54), ensuring that the original data does not leave the source. Figure 7 is a detailed flowchart of the adaptive strategy decision-making process with anti-oscillation mechanism in this invention. It shows that after the comprehensive scoring of the input device capabilities, the scoring is determined after smoothing filtering and hysteresis comparison, and the logic of triggering strategy redirection in a loop based on monitoring feedback is performed. Figure 8 illustrates the architecture and consistency guarantee mechanism of the cloud-based global state pool. Among them, the version logic clock (Vector Clock) is a core logical component used to track the causal relationship of state changes and determine whether the state increment submitted after the offline device recovers is valid. It works in conjunction with conflict resolution strategies (such as the strictest policy taking precedence) to ensure the eventual consistency of cross-device management in a distributed asynchronous environment. Detailed Implementation

[0041] Modular design description The behavior control framework described in this invention employs a modular design approach. The core of this approach lies in decomposing the complex end-to-end control system into subsystems (modules) with standardized interfaces and relatively independent functions, and flexibly adapting to diverse needs through different combinations of modules. Specifically, this invention constructs the following four decoupled technical layers, each embodying the modular characteristics of being "configurable" and "replaceable": Data Acquisition Layer: As an input module, it can selectively enable one or more data source modules such as network traffic, screen images, application processes, and sensors; Adaptive Analysis Layer: As a processing module, it can dynamically select different strategy algorithm modules such as local analysis, cloud analysis, or hybrid analysis based on the real-time performance of the device; Control and execution layer: As an output module, it can be adapted to actuator modules such as client control, gateway control or hybrid control, depending on the target device type; State synchronization layer: As a collaborative module, communication protocol modules such as long connection push, periodic pull or hybrid synchronization can be selected according to the network environment quality.

[0042] This modular architecture brings significant technical advantages and practical value to the present invention: First, it significantly improves the system's adaptability and deployment flexibility across different scenarios. Drawing on common practices in software engineering, modular layering allows for deployment by enabling or combining only certain modules (e.g., enabling only lightweight data sources and cloud analytics modules on low-performance devices) based on terminal computing power constraints, network conditions, or management granularity requirements, without altering the core logic. This achieves a smooth adaptation from full-featured management to simplified management, significantly shortening the adaptation cycle for different heterogeneous devices. Secondly, it effectively reduces the overall costs of R&D, deployment, and maintenance. Modular design combines system variability with component standardization, allowing modules within each layer (such as different identification algorithms and synchronization protocols) to be developed, tested, and optimized independently, and reused across different projects or product lines. When upgrades are needed for new device types (such as new IoT devices) or new circumvention methods, only specific modules need to be updated or replaced (such as adding a new sensor acquisition module or analysis strategy), without reconstructing the entire system. This significantly reduces iteration costs and technical risks. Finally, it provides the technological foundation for achieving "mass customization." Based on the modular framework of this invention, customized management and control solutions can be quickly assembled for different scenarios such as homes, enterprises, and schools, or for different combinations of devices such as mobile phones, tablets, and televisions. This allows for efficient coverage of fragmented market demands with a unified architecture and meets personalized governance needs at near-standardized costs.

[0043] In summary, the modular design of this invention is not a simple functional division, but a systematic architectural innovation. Through hierarchical decoupling, interface standardization, and module configurability, it endows the technical solution with excellent flexibility, scalability, and economy, fundamentally enhancing its practicality and viability in addressing the complex governance challenges of heterogeneous terminals.

[0044] Example 1: Adaptation of Performance-Aware Dynamic Analysis Strategies This embodiment uses a typical heterogeneous home environment, including high-performance mobile terminals, mid-performance portable terminals, and low-performance fixed terminals, as an example to demonstrate how the present invention, through a dynamic adaptation analysis strategy, can ensure effective control while also considering the user experience of various devices. The terminals exemplarily include flagship smartphones, entry-level tablets, and smart TVs.

[0045] (1) Multimodal data acquisition and equipment capability assessment The system silently collects multimodal operational data such as network traffic and application processes in the background of various terminals. Simultaneously, it evaluates the performance status of each terminal in real time and generates a device capability score (in this embodiment, an exemplary quantification range of 0-100 points is used, with higher scores indicating stronger overall performance): - Flagship phone: Equipped with a high-performance processor, large-capacity memory, ample battery, and suitable for high-speed mobile network environments. Device capability score: 95 points (high-performance level); - Entry-level tablet: Features a mid-performance processor, medium-capacity memory, medium battery life, and operates in a Wi-Fi environment. Device performance score: 60 (mid-performance level); - Smart TV: Features a basic processor, limited memory, continuous power supply, and operates in a Wi-Fi environment. Device capability score: 45 (low performance level).

[0046] (2) Analyze the dynamic redirection and execution of task execution paths Based on the above scores, the system dynamically redirects the analysis task of each terminal to a different execution path (corresponding to main process step S120): - For flagship phones (score 95): Employs a "local full-function analysis" strategy. All feature extraction and machine learning model inference are completed locally on the device, achieving real-time behavior recognition with extremely low latency (theoretically expected <100ms). - For entry-level tablets (score 60): A hybrid strategy of "local simplification + cloud assistance" is adopted. Lightweight feature extraction is performed locally on the device, while complex model inference tasks are offloaded to the cloud server for collaborative processing, maintaining recognition accuracy while balancing resource consumption (theoretically expected latency <500ms). - For smart TVs (score 45): A "cloud-led analytics" strategy is adopted. The terminal is only responsible for data collection and uploading, while all analysis tasks are completed in the cloud, minimizing the terminal load (theoretically expected latency <1000ms).

[0047] (3) Dynamic strategy optimization based on recognition quality The adaptation logic of this invention is not only based on static performance, but also incorporates recognition quality feedback for dynamic optimization. For example, when the confidence level of the local model on a high-performance terminal for a specific behavior (such as a new game) falls below a preset threshold, the system will automatically trigger "cloud-based collaborative verification," sending the anonymized data to the cloud for high-precision analysis and feeding back the results to enhance the local model. This mechanism ensures that even on high-performance devices, cloud computing power compensation can be used to cope with unknown scenarios, continuously guaranteeing high recognition accuracy.

[0048] (4) Dynamic adjustment as equipment status changes The adaptation strategy is dynamically adjusted according to the real-time status of the terminal. For example: When the flagship phone's battery level drops to a low level (such as below 20%), its performance score decreases accordingly, and the system automatically downgrades its strategy from "local full-function analysis" to "local simplification + cloud assistance" mode. When a mid-performance tablet is connected to a power source and in an idle state, its available computing power increases, and the system can upgrade its strategy to "local full-function analysis" mode. This process demonstrates the system's ability to dynamically redirect and analyze task execution paths based on real-time status.

[0049] To further optimize and address the user-perceived lag caused by frequent redirection (switching) of execution paths due to inconsistent control effects caused by heterogeneous device performance in the background technology, this embodiment introduces an anti-vibration design in the scoring and policy mapping logic. Its core includes: - Hysteresis Comparison Mechanism: Different rise and fall thresholds are set for strategy switching, forming a hysteresis interval. Strategy change is only triggered when the score consistently and stably exceeds the threshold, thus effectively filtering out instantaneous fluctuations; - Smoothing filtering mechanism: The original performance indicators are smoothed within a time window (such as by using moving average or exponential smoothing algorithms) to reflect the steady-state performance trend of the equipment.

[0050] Furthermore, to address extreme resource-constrained scenarios such as device battery depletion, overheating, or persistent network outages, this embodiment's adaptation mechanism includes a graceful degradation design. When the system detects that the device is in such an extreme state, it will automatically trigger a degradation process: First, suspend or significantly simplify non-core analysis tasks (such as high-precision screen recognition and real-time cloud synchronization) to free up system resources and reduce power consumption. Secondly, the analysis tasks are redirected (switched) to a backup control path that relies solely on a local lightweight rule base to maintain the most basic ability to intercept violations. Simultaneously, the availability of emergency communication functions (such as emergency calls and SMS) is always ensured, unaffected by any degradation strategies. This mechanism ensures the system's survivability and basic functionality under extreme conditions, demonstrating the robustness and human-centered design of the solution.

[0051] Through the above mechanism, the system can accurately adapt to long-term performance changes while avoiding frequent policy switching caused by short-term fluctuations, thus ensuring the smoothness of the control process and the stability of the user experience.

[0052] Technical effect Through the above dynamic adaptation, this embodiment achieves the following: - All devices are available: The three terminals with different performance levels can run the management and control functions stably without any lag or crashes; - Consistent recognition accuracy: Through policy adaptation, all terminals can maintain a high accuracy rate in behavior recognition (for example, theoretically expected to reach over 90%). -Optimal resource efficiency: Significantly saves local computing and power resources on low-performance terminals, and fully utilizes the computing power of high-performance terminals to achieve the lowest latency.

[0053] Summary of Implementation Examples This embodiment focuses on demonstrating the specific implementation of the "performance awareness and dynamic redirection of execution paths" dimension in the technical solution of this invention (corresponding to step S120 in the claims). It illustrates how the "adaptive analysis layer" in the modular architecture configures different processing modules (local / cloud analysis strategies) according to the input (device capabilities). This adaptive mechanism is a key foundation for ensuring that the subsequent "multimodal behavior sequence recognition" capability can be implemented on all heterogeneous terminals.

[0054] Example 2: Multimodal Data Fusion and Behavior Sequence Recognition Application Scenario Description This embodiment uses a typical scenario where a controlled user attempts to bypass network traffic monitoring by disabling VPN, screen mirroring, or switching applications as an example to demonstrate how the present invention can accurately identify the user's true behavioral intent through multimodal data fusion and cross-application behavior sequence analysis.

[0055] It should be noted that the multimodal operation data described in this invention can be implemented by including at least one. Although it is preferable to enable multiple channels simultaneously for optimal results on high-performance devices, in resource-constrained or privacy-sensitive scenarios, implementations that enable only the network traffic channel or only the screen image channel also fall within the scope of protection of this invention. For example, in an enterprise environment, for privacy protection reasons, only the network traffic channel and the application process channel can be enabled without collecting screen image data; in a home environment, the data channels enabled can be flexibly selected according to the privacy preferences of parents.

[0056] Step 1: Multi-channel data acquisition Preferably, the system collects data from multiple data sources simultaneously: Network traffic tunnel: Capture packet metadata via VPN Service or local network card; Screen content channel: Optionally, capture screen images at a preset frequency (e.g., every 5 seconds); Application process channel: Real-time monitoring of foreground application package name and status; Sensor channel: Optionally, the monitoring device uses attitude (such as landscape or portrait orientation, acceleration).

[0057] In another implementation, depending on device performance and privacy requirements, only some data channels (such as only network traffic channels and application process channels) can be enabled, while omitting screen content channels and sensor channels, as long as the purpose of behavior recognition can be achieved.

[0058] Step 2: Feature Extraction and Local Desensitization Feature extraction is performed on the data from each channel. It is important to emphasize that feature extraction for privacy-sensitive data (such as screen images) is performed locally on the terminal; only abstract feature labels are uploaded. Traffic characteristics: IAT distribution, CUMUL pattern, entropy value, TLS fingerprint, etc.; Screen features: Preferably, OCR is performed locally to extract text content, or image classification labels (such as game, video, and learning categories) are extracted using a lightweight CNN model, without uploading the original screenshot; Process characteristics: application package name, usage duration, switching frequency, etc.; Sensor characteristics: optionally, landscape / portrait mode, stationary / moving mode, etc.

[0059] In another implementation, the feature extraction process can be simplified based on the device's computing power constraints. For example, only traffic features and process features can be extracted, while screen features and sensor features can be omitted.

[0060] Step 3: Multimodal fusion decision Taking the example of a controlled user disabling the VPN in an attempt to bypass monitoring, the status of each system channel is as follows: Traffic channel: No valid data (encrypted traffic cannot be parsed because the VPN is closed); Screen Channel: Game screen features detected (such as the interface of a well-known MOBA game); Process Channel: Detects the running of the game application process (e.g., package name com.tencent.tmgp.sgame). Sensor channel: Detected that the device is in landscape orientation (a typical game feature).

[0061] The fusion decision engine determined that, despite the failure of the traffic channel, the system determined that the user was playing a game based on the evidence chain from the screen, process, and sensor channels, with a comprehensive confidence level of 95%.

[0062] The fusion decision-making mechanism includes a weight adaptive adjustment function. The system periodically monitors the recognition accuracy or confidence feedback of each data channel. If the reliability of a certain channel (e.g., due to network encryption causing traffic feature failure) continues to decline, the system will automatically reduce the decision weight of that channel and correspondingly increase the weight of other high-reliability channels. This closed-loop feedback mechanism gives the system strong adaptability. Even in extreme cases of single or multiple channel failures, it can still maintain high overall recognition accuracy and robustness by dynamically adjusting the weight allocation. This weight adaptive adjustment function is precisely to address the challenge of 'single data channels being easily bypassed' mentioned in the background technology. When a channel (e.g., traffic) fails due to being closed or encrypted, the system automatically shifts the decision focus to other effective channels (e.g., screens, sensors) by dynamically adjusting the weights, thereby continuously maintaining high robustness in recognition capabilities without relying on any single channel.

[0063] Step 4: Trigger control actions Based on the above determination, control measures will be triggered immediately: A pop-up message appears: "Game activity detected; today's limit has been exceeded." Force quit the game application; Update the global state pool and synchronize the freeze flag to all associated devices.

[0064] Step 5: Cross-application behavior sequence recognition case study This invention can not only identify the instantaneous state of a single application, but also determine the user's deeper intent through logical correlation analysis of cross-application and cross-modal behavior sequences. The following are three typical examples: Case 1: Identifying Control Avoidance Intent Based on "Search + Tunneling" Behavior Behavioral sequence: 10:00 - Open your browser and search for "game strategy" (related keywords are identified through screen content channel OCR, and / or the search request is detected through network traffic channel audit). 10:01 - Open the VPN application and establish an encrypted tunnel (the process channel detects that the VPN has started, and the traffic channel detects that the tunnel handshake has been established). 10:02 - Traffic characteristics show a large amount of encrypted data transmission (traffic channel); 10:03 - Device switched to landscape mode (sensor channel).

[0065] Integrated Decision Making: Individually, each action is not against the rules (searching, VPN, and data transfer are all normal behaviors). However, the sequence of actions, "searching for game guides → establishing an encrypted tunnel → landscape mode," is closely related in time and is highly suspected to be game-related behavior. The system determined that the user's intent was "to attempt to circumvent access controls to the game," with a comprehensive confidence level of 85%. Control actions: A pop-up message "Suspected circumvention of control behavior detected" appears, the VPN connection is disconnected, and the violation is recorded.

[0066] Case 2: Identifying Covert Viewing Intent Based on "Screen Casting + Mute" Behavior Behavioral sequence: 10:00 - Mobile data usage suddenly decreased (data channel); 10:01 - Screen mirroring protocol (DLNA / Miracast) activation detected (process channel). 10:02 - Set phone volume to mute (sensor channel); 10:03 - The screen mirroring control interface (screen channel) is displayed on the mobile phone screen.

[0067] Integrated Decision Making: Users cast videos to their TVs via screen mirroring and silence their phones to avoid being detected. The system determines that the user's intent is "to secretly watch videos," with a comprehensive confidence level of 90%. Control actions: Automatically identify the TV's IP address and implement non-intrusive control over the TV (such as DNS redirection), while freezing permissions on the mobile device.

[0068] Case 3: Disguised Intent Recognition Based on "Application Switching + Background Running" Behavioral sequence: 10:00 - Open a learning app (process channel); 10:01 - Minimize learning apps to the background (process channel); 10:02 - Open game apps (process channel); 10:03 - The game screen is displayed (screen channel); 10:04 - Traffic characteristics display game traffic pattern (traffic channel).

[0069] Integrated Decision Making: Users open the learning app as a disguise; they are actually running a game. The system determines that the user's intent is "to pretend to learn the actual game," with a comprehensive confidence level of 95%. Control actions: Forcefully exit the game app, close the learning app (to prevent further spoofing), and pop up a message "Spoofing behavior detected, violation recorded".

[0070] Technical effect Through the aforementioned cross-application behavior sequence recognition mechanism, this invention can identify more complex evasion behaviors: - Significantly improved anti-bypass capability: Theoretical analysis shows that the success rate of anti-bypass is significantly improved compared to the solution that only identifies a single application state; - Enhanced robustness across multiple channels: Even if a single channel (such as traffic) fails, the system can still accurately identify violations through fusion analysis of other channels (such as screens and sensors), ensuring effective control.

[0071] Example 3: Cross-device consistency management based on virtual synchronization Application scenarios This embodiment uses a home scenario as an example to demonstrate how, when a controlled user triggers a violation on a terminal (such as a mobile phone) and is subsequently controlled, the present invention uses a virtual synchronization mechanism to prevent the user from circumventing control by switching to another associated terminal (such as a tablet computer).

[0072] Specific implementation steps

[0073] This embodiment is a detailed elaboration of the main process step S150 (cross-device collaboration based on virtual synchronization). Steps S31 to S36 described below correspond to their specific implementation logic: Step S31: Establishment and Maintenance of a Global State Pool in the Cloud: Establish and maintain a global state pool on the cloud server to centrally manage the logical control status of all associated terminal devices of the same user. This state pool records the identifier, real-time status, and potentially effective global control policies (such as freeze flags) of each device, on a user-by-user basis. This centralized state management provides a single source of facts for cross-device collaboration; Step S32: Single-point violation triggering and status synchronization: When a high-performance terminal (such as a mobile phone) identifies a violation (such as game timeout) through local analysis, it performs two key actions: 1) Triggers a control action locally (such as executing a restriction policy corresponding to the control status); 2) Immediately reports the violation event and the triggered control policy (such as "setting a global control status flag with a preset validity period") to the cloud global status pool. The cloud status pool is then updated, setting a global freeze flag for the user and recording its effective time range; Step S33: Proactive Broadcasting and Forced Synchronization of Control Policies: After the cloud state pool is updated, the freeze flag and policy are proactively "pushed" in real time to all online associated terminals of the user through a low-latency communication channel (such as a long connection). Upon receiving the instruction, these terminals immediately enforce the same control policy locally (such as entering restricted mode) without secondary verification. This is the core of "virtual synchronization": the control state is defined as a logical whole in the cloud and forcibly synchronized to all physical terminals; Step S34: Failure of Device Switching Bypass: When a user attempts to use another terminal (such as a tablet) that has received the synchronization command, the local agent on that terminal will verify the local status before the user's operation, detect a valid freeze flag, and directly intercept the attempted illegal operation (such as starting a game) and provide a unified prompt. At this point, the path to bypass via device switching is completely blocked. Step S35: Offline consensus, conflict resolution, and graceful degradation (enhancing robustness) To address complex situations such as network outages and extremely limited device resources, and to ensure the continuity and reliability of control strategies, this embodiment designs a multi-layered enhancement mechanism (its underlying architecture and data flow are shown in Figure 8): (1) Offline decision-making and prediction mechanism: After each synchronization with the cloud, each terminal will cache a "state fingerprint" with a timestamp locally. When the network is disconnected, the terminal will autonomously deduce the current state based on the local clock and the cached state logic (such as the start and end time of the freeze) to ensure that the control policy can continue to be effective during offline period and prevent the synchronization from being bypassed by disconnecting the network; (2) Conflict Resolution and Consistency Guarantee Mechanism: To ensure the eventual consistency of state across devices in a distributed asynchronous environment, this embodiment designs a conflict resolution mechanism based on vector clocks to track the causal relationship of state changes. When the cloud state pool detects a conflict in state updates from different devices based on the vector clock (i.e., the causal order of events cannot be determined), the system will execute preset security-side conflict resolution rules, such as automatically adjudicating based on the principle of "the strictest control strategy takes precedence". This mechanism ensures the atomicity and integrity of state updates, guaranteeing that the logic of "one violation, global freeze" can be reliably executed under any network conditions; (3) Graceful Degradation and Critical Function Guarantee Mechanism: To address extreme resource-constrained scenarios such as device power depletion, excessively high temperatures, or continuous network outages, this embodiment also includes a system-level graceful degradation design. When such extreme states are detected, the system automatically triggers a multi-level response: - Control downgrade: Suspend or significantly simplify resource-intensive analysis tasks (such as real-time screen content recognition) and switch to a "safety net" control state that relies on a local lightweight rule base; - Resource Guarantee: Prioritize the allocation of computing and communication resources to critical functions that ensure basic equipment operation and user safety (such as emergency calls and SMS sending and receiving) to ensure their absolute availability; - State Preservation and Recovery: The system maintains the effective control state from the last synchronization with the cloud (i.e., the "last known compliance state") and continues to perform offline simulations based on this. Once device resources or network connectivity are restored, the system will automatically and seamlessly revert to full synchronization and analysis mode.

[0074] Through the synergy of the above mechanisms, the virtual synchronization mechanism of this invention can not only maintain consistency under normal network fluctuations, but also ensure that in extremely harsh environments, while maintaining core control functions, the system can absolutely guarantee the smooth operation of critical channels such as emergency communications, thereby enabling the 'one violation, global freeze' strategy to be executed safely and reliably under any foreseeable real-world conditions.

[0075] Step S36: Automatic Policy Unfreezing and State Restoration: When the global freeze flag expires, the cloud state pool automatically clears the flag and broadcasts a "unfreeze" command. All online devices are restored immediately, while offline devices synchronize to the latest state the next time they connect to the network, or are automatically unfrozen based on offline deduction logic. No manual intervention is required throughout the entire lifecycle.

[0076] Technical effect This embodiment demonstrates how the "virtual synchronization mechanism" of the present invention achieves consistency management across devices: - Eliminate blind spots in control: It achieves the effect of "one violation, global restriction", making it theoretically impossible to circumvent control by switching devices; - Ensure real-time performance: Based on the proactive push synchronization mechanism, the state synchronization latency is extremely low (theoretically expected to be within seconds), and users can hardly take advantage of the time difference; - Enhanced robustness: Through offline state simulation, the continuity and correctness of the control strategy are ensured in scenarios with unstable or interrupted networks, making the system's anti-bypass capability more complete; This mechanism ensures the continuity of control policies during network outages. If the terminal's local clock is abnormally tampered with, the system will correct the state by verifying the cloud timestamp the next time it successfully synchronizes with the cloud, and can record such 'clock anomaly' events as potential evasion attempts.

[0077] Summary of Implementation Examples This embodiment focuses on demonstrating the specific implementation of the "virtual synchronous collaboration" dimension in the technical solution of this invention (corresponding to main process step S150). It embodies the core role of the "state synchronization layer" in the modular architecture. By establishing a cloud-based global state pool as a single source of fact and adopting a strategy combining active broadcasting and offline consensus, this invention upgrades traditional, independent single-device management to a mandatory, consistent networked collaborative management, which is a key innovation in solving the challenge of inconsistent cross-device management.

[0078] Example 4: Non-intrusive control of non-standard equipment This embodiment assumes a management scenario where the home administrator has obtained the appropriate authorization (e.g., through a parental control protocol). This embodiment targets terminal devices (such as smart TVs, game consoles, and certain IoT devices) where installing a dedicated management client is impossible or inconvenient, demonstrating how the present invention achieves non-intrusive and effective management through network-side collaborative analysis, thereby expanding the solution's coverage. It should be noted that the core of this embodiment lies in achieving 'non-intrusive' management through network-side nodes. In a simplified deployment scenario with only network traffic monitoring capabilities, the system can primarily or even entirely rely on the analysis of device network traffic time-series data to achieve behavior recognition and basic management functions. Furthermore, the multimodal data fusion described in Embodiment 2 can provide higher recognition accuracy and robustness for this type of analysis. Specific implementation steps

[0079] This embodiment demonstrates the collaborative implementation of control action triggering (S140) and virtual synchronization collaboration (S150) in the main process on non-standard devices: Step S41: Deploy a network-side management node on a critical path (such as a home router or enterprise edge gateway) in a home or enterprise LAN. Deploy or enable a management node (also called a management gateway). This node, as one of the "management execution layer" modules in the architecture of this invention, is responsible for monitoring and analyzing the network traffic of the specified device. Step S42: Configure traffic monitoring policies. By configuring policies on the control node, network traffic of target devices (such as smart TVs) can be mirrored or monitored in a bypass manner. This is a non-intrusive method that can obtain network behavior data without installing any software on the target device, which complies with the principle of minimizing privacy and solves the problem of coverage for non-standard devices. Step S43: Network Behavior Analysis and Intent Recognition: The control node performs real-time analysis on the traffic obtained from the mirroring, extracting features such as traffic timing and protocol fingerprints. By comparing these features with the behavior model library, the type of network activity currently being performed by the device is identified (e.g., accessing online video services, updating games, or browsing web pages). Step S44: Non-intrusive control action execution: When a violation is identified (such as accessing a video stream during a prohibited period), the control node intervenes at the network layer. For example, this can be achieved by dynamically generating DNS resolution rules (resolving a specific domain name to an invalid address) or configuring a temporary access control list (ACL) to block the target device from connecting to the violating service. The intervention action precisely targets the violating traffic without affecting other normal network functions of the device. To avoid the problems of frequent device reconnection, abrupt user perception, and easy bypassing caused by the traditional direct network disconnection (DROP) method, the control action can adopt silent guidance technology, the specific implementation of which includes: (1) TCP connection persistence and flow control simulation: By simulating the TCP zero-window mechanism, the sender pauses data transmission but maintains the connection establishment state, making the terminal appear as 'loading' instead of 'disconnected'; (2) Protocol layer response injection: hijack the HTTP response and inject standard error status codes (such as 429, 503) or redirect to the prompt page provided by the control node, causing the client application to terminate the current connection or display prompt information according to the protocol specifications; This fine-grained control at the protocol layer not only achieves effective blocking, but also greatly enhances the concealment of control and user experience, and reduces the risk of being bypassed. Step S45: Synchronize with the state of the core system: The control node reports the identified violations and the actions taken to the global state pool in the cloud. This will trigger the same virtual synchronization logic as in Example 3: that is, the user's violation record is updated to the global state, and all associated devices under the user's name (including mobile phones and tablets with the client installed) will be synchronously executed with the corresponding control policies (such as global freezing), thereby achieving unified governance across heterogeneous devices.

[0080] Technical effect This embodiment demonstrates how the present invention solves the problem of controlling non-standard devices by extending the network architecture: - Expanded control boundaries: Effective behavior recognition and intervention can be implemented on a wide range of devices such as smart TVs and game consoles without relying on the cooperation of the device side, significantly improving the device coverage of the overall solution; - Maintain consistent control: Violations identified through network-side control nodes will also trigger a global virtual synchronization mechanism, ensuring that users' behavior rules and consequences are consistent regardless of the device they use; - Practice privacy design: By using network traffic analysis instead of screen content capture, the system achieves its control objectives while minimizing access to users' internal privacy data, in accordance with the principle of data minimization.

[0081] Summary of Implementation Examples: This embodiment demonstrates the flexibility and scalability of the invention's architecture. By introducing a network-side management node as an optional module of the "management execution layer," the invention constructs a dual-track mechanism combining "deep terminal-side management" and "non-intrusive network-side management." This not only solves the challenge of "some devices being unable to install management clients" in the background technology, but also demonstrates that the invention, as a systemic architecture, can integrate multiple technical paths (terminal proxy, gateway mirroring, protocol intervention) to achieve a unified governance goal. Its innovation lies in this systemic architecture design that is collaborative between the terminal and the network and flexibly adaptable, rather than an improvement on any single specific technology.

[0082] Example 5: Localized Data Processing Based on Privacy-First Design Application scenarios This embodiment addresses scenarios requiring analysis of user terminal screen content for accurate behavior recognition while strictly protecting user privacy. It demonstrates how this invention, through a combination of "localized feature extraction" and "data anonymization," achieves control objectives while fundamentally eliminating the risk of privacy data leakage.

[0083] Specific implementation steps This embodiment is a concrete demonstration of the "privacy-preserving design principle" that runs throughout this invention and the collaboration between the "data acquisition layer" and the "adaptive analysis layer" in the modular architecture: Step S51: Controlled data acquisition and real-time localized processing The system collects screen information according to a preset strategy (such as event-triggered or low-frequency periodic sampling). The key design feature is that the collected raw data (such as image frames) does not leave the terminal device; it is processed immediately in the device's local memory. This physically isolates the channel for the transmission of raw privacy data, strictly adhering to the principle of data minimization. This achieves compliance from the source. Step S52: Feature extraction and desensitization for privacy stripping Locally, the system performs feature extraction on the raw data. At the heart of this process is "privacy stripping": Content understanding and abstraction: Identify the categories of screen content (such as "game interface", "video stream", "document browsing") through a lightweight model and abstract them into category labels; Active filtering of sensitive information: During the feature extraction process, the system actively removes or masks visual features that are directly related to personal identity and communication content by using preset sensitive pattern recognition (such as detection of face regions and continuous text input boxes), and retains only non-sensitive feature elements necessary for judging behavioral intentions (such as interface layout features, application identification features, color statistical features, etc.). Generating irreversible abstract feature vectors: This design ensures that even if all feature vectors are theoretically obtained, it is impossible to reconstruct any original screen pixel array containing user personal information through reverse calculation. Ultimately, the original pixel data is transformed into a low-dimensional, digital feature vector (e.g., a 128-dimensional floating-point array). This vector has a "one-way mapping" relationship with the original image, mathematically and engineeringally ensuring the technical irrecoverability of the original privacy information. This constitutes a technical response to the legal requirement to "take necessary measures to protect personal information security." Step S53: Irreversible Protection of Enhanced Privacy To further enhance privacy protection and ensure irreversibility, this embodiment introduces privacy-enhancing techniques (such as Local Sensitive Hash (LSH)) to process the aforementioned feature vectors, converting them into a shorter hash value. This technique ensures that similar behaviors generate similar hash values ​​to maintain recognition capability, but also, based on the one-way nature of hash functions, ensures that reverse engineering to restore the original features or even the screen image is computationally infeasible. Through this two-stage processing of "feature extraction → hashing," the uploaded data is merely a thoroughly desensitized "digital fingerprint" representing the behavioral pattern. This fingerprint is mathematically one-way and cannot restore the original image or text, thus satisfying the requirements of data minimization and privacy compliance from a technical perspective. This technically satisfies the data processing principle of "clear purpose and minimum necessity," and embeds default privacy protection settings through technical means.

[0084] Step S54: Compliant Data Upload and Cloud Analysis Only the completely anonymized "digital fingerprint" generated in step S53 (a very small data size, approximately 1KB, and containing no personally identifiable information) is uploaded to the cloud analysis system. The cloud server performs behavioral intent matching and determination solely based on these abstract features that do not contain personal information, ensuring that the cloud does not access any original user privacy information from the data flow perspective. The cloud only outputs behavioral intent categories and does not store any intermediate data that can be associated with individuals.

[0085] Technical effect Compared to existing solutions that require uploading raw or simply encrypted screen data to the cloud for analysis, this embodiment achieves multiple privacy protection effects through the above steps: - Data localization: Raw sensitive data does not leave the device, controlling risks at the source; - Feature abstraction: Converting specific visual content into abstract features that cannot be used to deduce the original content, thereby achieving privacy separation; - Minimizes transmission: Uploaded data volume is reduced by more than 99% compared to transmitting the original image, greatly reducing the impact of leakage; - Intrinsic compliance: The entire process design incorporates the principles of "default privacy design" and "data minimization". Its technical means (such as irreversible feature extraction) constitute a technical response to the core requirements of privacy regulations, rather than relying solely on process statements.

[0086] Summary of Implementation Examples This embodiment systematically demonstrates how the present invention transforms privacy protection from an external compliance requirement into a core feature inherent in the technical architecture. It does not simply add encryption or anonymization steps after data collection, but rather eliminates the possibility of privacy leakage during the design phase of the technical solution through a deep integration of "local real-time processing - privacy stripping and extraction - irreversible transformation." This responds to the legal requirements that data processing activities must adhere to the principles of legality, legitimacy, and necessity, and that necessary measures must be taken to ensure security. It also reflects a writing strategy that avoids privacy infringement risks through technical design. This design is the key cornerstone for the legal and compliant implementation of the present invention in sensitive behavior control scenarios, and together with the control effectiveness demonstrated in embodiments 1, 2, 3, and 4, constitutes a complete technical solution loop.

Claims

1. An adaptive intelligent behavior control method for heterogeneous terminals, characterized in that, The method includes: collecting multimodal operational data reflecting user behavioral intentions in real time on the terminal device side; dynamically adapting a behavioral analysis strategy based on the real-time performance status of the terminal device to balance analysis accuracy and resource consumption; performing real-time analysis on the multimodal operational data according to the adapted behavioral analysis strategy to identify the user's behavioral intention category; triggering corresponding control actions on the terminal device side and / or its associated control nodes based on the identified behavioral intention category; wherein the triggering logic of the control actions is achieved by actively broadcasting cross-device state freeze flags to multiple associated terminal devices through a virtual synchronization mechanism maintained by a cloud-based global state pool, forcing multiple associated terminal devices to synchronously execute the control strategy according to preset rules, thereby achieving consistent cross-device control.

2. The method according to claim 1, characterized in that, The multimodal operation data includes at least one of the following: network traffic data, screen image data, application process information, sensor data, and system logs; wherein, when the multimodal operation data includes screen image data, feature extraction or desensitization processing is performed locally immediately after acquisition to generate a feature vector that does not contain personal sensitive information in the original pixels, and the feature vector is only used for subsequent analysis or uploading.

3. The method according to claim 1, characterized in that, The dynamic adaptation behavior analysis strategy based on the real-time performance status of the terminal device includes: real-time evaluation of at least one of the terminal device's computing power, memory, power consumption, and network connection status to generate a device capability score; when the device capability score is higher than a preset threshold and the local model confidence meets the requirements, dynamically selecting one of several locally preset analysis models of different complexities for local analysis; when the device capability score is lower than the preset threshold or the local model confidence is insufficient, deciding to send the anonymized data to a related node with stronger computing power for analysis to ensure the continuity and accuracy of behavior recognition.

4. The method according to claim 1, characterized in that, The virtual synchronization mechanism maintained through a cloud-based global state pool specifically includes: maintaining a global state pool associated with user accounts in the cloud, wherein the global state pool stores cross-device state freeze flags containing violation types, validity periods, and affected device ranges; when any associated terminal device identifies a violation and triggers control, the freeze flags in the global state pool are immediately updated; the global state pool actively broadcasts the updated freeze flags to all other associated terminal devices through long-connection push, periodic retrieval, or device online instant query mechanisms; after receiving the freeze flags, other associated terminal devices enforce the corresponding control policies without secondary verification until the validity period expires or an authorization release instruction is received.

5. The method according to claim 1, characterized in that, The control node includes at least one of the following: a cloud server, a proxy device on the same local area network as the terminal device, or a routing device that provides network access for the terminal device; wherein, when the control node is a local area network proxy device or a routing device, the method further includes obtaining behavioral data of the controlled device without a control client installed through traffic mirroring or protocol interaction to achieve non-intrusive control.

6. The method according to claim 3, characterized in that, The dynamic selection or decision-making process includes an anti-oscillation mechanism; the anti-oscillation mechanism avoids frequent switching of analysis strategies due to instantaneous fluctuations in performance indicators by setting a hysteresis interval or performing smoothing filtering on the equipment capability score.

7. The method according to claim 4, characterized in that, When the network connection between the terminal device and the cloud global state pool is interrupted, the terminal device autonomously infers and executes the current control state based on the last known state and timestamp cached locally. Once the network connection is restored, if the local simulation state is inconsistent with the state in the cloud global state pool, the final execution strategy will be determined according to the preset conflict resolution rules. The conflict resolution rules include at least one of the following: based on the cloud state, based on a stricter control strategy, or based on state merging using a vector clock.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method as described in any one of claims 1 to 7.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1 to 7.