Smart home device security alarm linkage response method and system

CN122290264BActive Publication Date: 2026-08-21FUJIAN FULUOSEN HOME FURNISHING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610757537.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-05-29
Publication Date
2026-08-21
Estimated Expiration
2046-05-29

AI Technical Summary

Technical Problem

[0003]本发明提供了一种智能家居设备安全警报联动响应方法及系统,旨在解决现有智能家居安防系统在面对复杂多变的安全事件时,难以对多源、异构且可能存在干扰或篡改的次生事件进行有效关联分析和综合评估,导致信息碎片化、判断失误,从而影响响应及时性和有效性的技术问题

Benefits of technology

[0072] The smart home device security alarm linkage response method and system disclosed in this application can effectively identify and judge secondary events such as image information being interfered with or altered, localized and purposeful communication interference, and covert environmental interference by acquiring initial security event information, image data visual characteristic information, security protection device communication status information, and environmental sensor minute change data, and by real-time correlation and comprehensive evaluation of these multi-source heterogeneous information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122290264B_ABST
    Figure CN122290264B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of smart home security and protection, and discloses a smart home device security alarm linkage response method and system; the method can effectively identify and judge secondary events such as image information interference or change, local purposeful communication interference and hidden environmental interference by acquiring initial security event information, image data visual characteristic information, security protection device communication state information and environment sensor slight change data, and performing real-time correlation and comprehensive evaluation on the multi-source heterogeneous information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of smart home security, and more specifically, to a method and system for security alarm linkage response of smart home devices. Background Art

[0002] The smart home security system aims to provide comprehensive security protection for the home, and realizes intelligent monitoring and response through various sensors and execution devices. However, in actual applications, when an abnormal event occurs, the alarm of a single device often fails to form an effective disposal loop. Traditional linkage strategies often rely on preset fixed rules, which makes it difficult for the system to cope with various risks when facing complex and changeable scenarios. Especially in some intrusion behaviors, the intruder may take means to interfere with or damage the security devices, making it difficult for the system to accurately judge the truth, thus affecting the timeliness and effectiveness of the response. Summary of the Invention

[0003] The present invention provides a method and system for security alarm linkage response of smart home devices, aiming to solve the technical problem that in the face of complex and changeable security events, the existing smart home security system is difficult to conduct effective correlation analysis and comprehensive evaluation on multi-source, heterogeneous and possibly interfered or tampered secondary events, resulting in fragmented information and misjudgment, thus affecting the timeliness and effectiveness of the response.

[0004] The technical solution of this application is as follows:

[0005] In the first aspect, this application discloses a method for security alarm linkage response of smart home devices, including:

[0006] Obtain the occurrence information of an initial security event;

[0007] Obtain the image data related to the area where the initial security event occurs, and process the image data to obtain the visual characteristic information of the image data;

[0008] According to the visual characteristic information, identify whether there is a large range of low-contrast areas, or over-bright or over-dark areas with specific patterns in the image data, and determine the abnormal situation in the image data as an event where the image information is interfered or changed, and determine the degree of occurrence of the event;

[0009] For the security protection devices related to the area where the initial security event occurs and its adjacent areas, obtain their communication status information;

[0010] When a security protection device is unresponsive or disconnected, and other non-security protection devices are in a normal connected state, analyze the proximity of the area where the unresponsive or disconnected security protection device is located to the area where the initial security event occurred, and judge the communication anomaly of the security protection device as a localized, purposeful communication interference event, and determine the degree of danger of the event.

[0011] It continuously acquires real-time sensing data from multiple environmental sensors, identifies minute changes in the real-time sensing data that have not yet reached the preset alarm threshold but show a slow, continuous change or an abnormal fluctuation trend, and records these minute changes.

[0012] Real-time correlation between initial security events, the extent of occurrence of events, the degree of danger of events, and minor changes in events;

[0013] Based on the chronological order of each event, its proximity to the area where the initial security incident occurred, and the degree of danger it may indicate, a weight is assigned to each event. Information with these weights is then compiled to calculate an assessment value that reflects the current overall security situation.

[0014] Based on the assessment values, the duration of the management alarm is determined; and based on the highest level of danger currently assessed, key information is extracted from all identified and associated anomalies, and the key information is structured and integrated to generate a unified security status report. The security status report includes a preliminary assessment of the current nature of the danger and is sent to the user's mobile terminal and the security service center in an encrypted manner.

[0015] Furthermore, based on the above method, and based on visual characteristic information, it identifies whether there are large-scale low-contrast areas or overly bright or dark areas in the image data, and judges the anomalies identified in the image data as events indicating that the image information has been interfered with or altered, and determines the degree of occurrence of the event, including:

[0016] Continuously collect and record real-time values ​​of brightness, contrast, edge density, and specific frequency components in image data to form a time series;

[0017] Analyze time series data to identify whether there are periodically changing visual characteristics in image data. Periodically changing visual characteristics include brightness, contrast, edge density, or specific frequency components that periodically switch between normal and abnormal ranges within a short period of time.

[0018] When periodically changing visual characteristics are identified, the anomalies identified in the image data are judged as malicious interference events mimicking equipment malfunctions, and the degree of occurrence of the event is determined based on the degree of change of the periodically changing visual characteristics.

[0019] Building upon the above, this application further proposes to continuously acquire real-time sensing data from multiple environmental sensors, identify minute changes in the real-time sensing data that have not yet reached a preset alarm threshold but exhibit slow, continuous changes or abnormal fluctuation trends, and record these minute changes, including:

[0020] Continuously acquire real-time sensing data from multiple environmental sensors;

[0021] The real-time sensing data of each environmental sensor is sampled, and the changes in the real-time sensing data are recorded.

[0022] Calculate the range of numerical fluctuations and rate of change for each environmental sensor within a sliding time window;

[0023] A pre-defined library of environmental background activity patterns is provided, which includes patterns of benign environmental changes.

[0024] The behavior trajectory of real-time sensing data is compared with the patterns in the environmental background activity pattern library;

[0025] When there is a mismatch, analyze the duration, frequency of occurrence, and temporal correlation of the minor changes with the initial security event;

[0026] When minute changes exhibit intermittent, short-lived, and low-intensity characteristics, and repeatedly occur within a certain time window after the initial security incident, they are identified as covert environmental interference patterns and judged as signs of malicious activity by intruders.

[0027] Furthermore, based on the above method, according to the chronological order of each event, its proximity to the area where the initial security incident occurred, and the degree of danger it may indicate, a weight is assigned to each event. Information with these weights is then compiled to calculate an assessment value reflecting the current overall security situation, including:

[0028] Obtain information about the occurrence of an initial security event;

[0029] Track the evolution of initial security incidents, incidents of image information being interfered with or altered, communication interference incidents, and subtle changes to identify their respective abnormal behavior trajectories;

[0030] Compare abnormal behavior trajectories with preset normal equipment failure modes and malicious interference modes;

[0031] Based on the comparison results, identify malicious interference intentions;

[0032] Based on the intent of malicious interference, the weighting of initial security events, events where image information is interfered with or altered, communication interference events, and minor changes in environmental parameters in the numerical calculations of the evaluation is dynamically adjusted.

[0033] Summarize information with dynamically adjusted consideration weights and calculate the evaluation values.

[0034] Based on the above method and the evaluation values, the duration of the management alarm includes:

[0035] When a malicious interference intent is detected, the system enters an intent-locked state, maintains the alert status, and keeps the alert at the highest response level.

[0036] When intent is locked, the evaluation scores for all events identified as malicious intent are forced to remain at the highest level when calculating evaluation values;

[0037] In the intent-locked state, the alarm will be deactivated only when security personnel confirm and rule out the possibility of malicious behavior on-site, or when multiple independent sensors continuously report no abnormalities, and when all identified malicious behavior trajectories have stopped and been judged as good or eliminated.

[0038] As a technical improvement, according to the above method, when a malicious interference intent is identified, an intent-locking state is entered, and the alarm remains active. Furthermore, after maintaining the alarm at the highest response level, the following additional steps are also taken:

[0039] While the intent is locked, continuously monitor the user's response behavior to the alert, including the number of times the alert is viewed, the duration of the view, and the frequency of alert cancellation requests.

[0040] When a downward trend in response behavior is detected, the alarm fatigue assessment process is initiated.

[0041] Based on the alarm fatigue assessment process, analyze the duration, number of devices involved, and level of the current malicious interference event;

[0042] When the analysis results indicate a risk of user alert fatigue, the presentation of alerts will be adjusted. This may include changing the alert from a real-time pop-up to a periodic summary push, or playing a low-volume alert tone through a smart speaker; and sending a report containing a detailed analysis and response recommendations to the user's mobile device.

[0043] As a further improvement, based on the above method, while the intent is locked, the user's response behavior to the alarm is continuously monitored. This response behavior includes the number of alarm views, the duration of views, and the frequency of alarm cancellation requests, including:

[0044] In the intent-locked state, continuously monitor the user's mobile terminal screen on time, application switching records, alarm notification click rate, and alarm information reading progress;

[0045] Continuously monitor user interaction records on the smart home control screen. The interaction records include the activation time of the control screen, the type of operation command, and the time spent on alarm-related interfaces.

[0046] Based on interaction records, the actual attention level of users to the alarm is calculated. The actual attention level reflects the depth of users' understanding of the alarm and their willingness to take action.

[0047] When the actual attention level is lower than a preset alert maintenance threshold, it is determined that the user has deep-seated alarm fatigue.

[0048] To enhance functionality, based on the above method, when the analysis results indicate a risk of user alert fatigue, the presentation of the alert is adjusted. This adjustment includes changing the alert information from a real-time pop-up to a periodic summary push, or playing a low-volume alert tone via a smart speaker, followed by:

[0049] After adjusting the way alarm information is presented, the types of operation commands that users use on the smart home control screen are monitored. These operation command types include security event confirmation commands, security device status query commands, or security service request commands.

[0050] Monitor users' click behavior on alert summary push notifications on their mobile devices, as well as the depth of their reading of the report content;

[0051] If a user does not execute a security event confirmation command, or does not query the status of security devices, or sends a security service request command within a preset time window, and the click behavior of the alarm summary push and the reading depth of the report content are lower than a preset threshold, it is determined that the user has not regained vigilance.

[0052] When it is determined that the user has not regained vigilance and the malicious interference continues or the level escalates, all lighting devices in the smart home environment will be forcibly activated, causing them to operate in a high-brightness flashing mode, while simultaneously playing a preset emergency alarm sound through the smart speaker.

[0053] To improve the solution, based on the above methods, a report containing a detailed analysis and response recommendations will be sent to the user's mobile terminal, including:

[0054] Obtain a security status report;

[0055] Attempt to send a security status report to the user's mobile terminal via the main communication channel;

[0056] When the main communication channel fails to send a security status report or the user's mobile terminal is offline, switch to the auxiliary communication channel to send a simplified version of the security status report or critical alarm information.

[0057] Security status reports are encrypted and stored in a secure local storage unit within the smart home.

[0058] Generate a notification containing access credentials and send it to the user via an auxiliary communication channel;

[0059] Once the user's mobile device returns to online status or the battery is restored, the user will be prompted to download the complete security status report from the smart home's local secure storage unit or resend the complete security status report through the main communication channel.

[0060] Continuously monitor the user's mobile terminal's reception status and the reading status of security status reports;

[0061] When a security status report is not received or read by the user for an extended period of time, the system periodically resends the report through different channels and sends a voice prompt to the user.

[0062] Secondly, this application also discloses a smart home device security alarm linkage response system, including:

[0063] The acquisition end is used to acquire information about the occurrence of an initial security event; acquire image data related to the area where the initial security event occurred, and process the image data to obtain visual characteristic information of the image data;

[0064] The recognition end is used to identify whether there are large areas of low contrast or areas of excessive brightness or darkness in the image data based on visual characteristic information, and to determine whether the abnormalities in the image data are events of interference or alteration of image information, and to determine the degree of occurrence of the event.

[0065] The analysis unit is used to obtain the communication status information of security protection devices related to the area where the initial security incident occurred and its adjacent areas. When a security protection device is unresponsive or in a disconnected state, and other non-security protection devices are in a normal connected state, the unit analyzes the proximity of the area where the unresponsive or disconnected security protection device is located to the area where the initial security incident occurred, and judges the communication anomaly of the security protection device as a localized, purposeful communication interference event, and determines the degree of danger of the event.

[0066] The recording end continuously acquires real-time sensing data from multiple environmental sensors, identifies minute changes in the real-time sensing data that have not yet reached the preset alarm threshold but show a slow, continuous change or an abnormal fluctuation trend, and records these minute changes.

[0067] The correlation endpoint is used to correlate initial security events, the extent of the event, the severity of the event, and minor changes in the event in real time.

[0068] The calculation unit is used to determine the weight of each event based on the order of their occurrence, their proximity to the area where the initial security incident occurred, and the degree of danger they may indicate. It then summarizes the information with the weighted values ​​and calculates an assessment value that reflects the current overall security situation.

[0069] The integration unit manages the duration of alarms based on assessment values; and extracts key information from all identified and associated anomalies based on the highest assessed level of danger, integrates the key information in a structured manner, and generates a unified security status report. The security status report includes a preliminary judgment on the nature of the current danger and is sent to the user's mobile terminal and the security service center in an encrypted manner.

[0070] This technical solution provides a system that implements the above methods. Through the collaborative work of various functional modules, it effectively solves the limitations of traditional systems in handling complex security events and realizes real-time correlation, comprehensive evaluation, and intelligent response of multi-source heterogeneous information.

[0071] Beneficial effects

[0072] The smart home device security alarm linkage response method and system disclosed in this application can effectively identify and judge secondary events such as image information being interfered with or altered, localized and purposeful communication interference, and covert environmental interference by acquiring initial security event information, image data visual characteristic information, security protection device communication status information, and environmental sensor minute change data, and by real-time correlation and comprehensive evaluation of these multi-source heterogeneous information. Attached Figure Description

[0073] Figure 1 This is a flowchart illustrating a smart home device security alarm linkage response method provided in an embodiment of the present invention;

[0074] Figure 2 This is a schematic diagram of the structure of a smart home device security alarm linkage response system provided in an embodiment of the present invention. Detailed Implementation

[0075] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0076] Reference Figure 1 , Figure 1This is a flowchart illustrating a smart home device security alarm linkage response method according to an embodiment of the present invention, including:

[0077] S11, Obtain information about the occurrence of an initial security event;

[0078] S12, acquire image data related to the area where the initial security incident occurred, and process the image data to obtain visual characteristic information of the image data;

[0079] S13, based on the visual characteristic information, identify whether there is a large area of ​​low contrast or a specific pattern of overly bright or dark areas in the image data, and determine the abnormal situation in the image data as an event in which the image information is interfered with or altered, and determine the degree of occurrence of the event.

[0080] S14, Obtain the communication status information of the security protection equipment related to the area where the initial security event occurred and its adjacent areas;

[0081] S15, when the security protection device does not respond or is in a disconnected state, and other non-security protection devices are in a normal connected state, analyze the proximity of the area where the unresponsive or disconnected security protection device is located to the area where the initial security event occurred, and judge the communication anomaly of the security protection device as a localized, purposeful communication interference event, and determine the degree of danger of the event;

[0082] S16, continuously acquire real-time sensing data from multiple environmental sensors, identify minute changes in the real-time sensing data that have not yet reached a preset alarm threshold but show a slow, continuous change or an abnormal fluctuation trend, and record the minute changes.

[0083] S17, perform real-time correlation between the initial security event, the degree of occurrence of the event, the degree of danger of the event, and the minute changes;

[0084] S18. Based on the order of occurrence of each event, its proximity to the area where the initial security event occurred, and the degree of danger it may indicate, determine a consideration weight for each event, and summarize the information with the consideration weight to calculate an assessment value that reflects the current overall security situation.

[0085] S19. Based on the assessment value, manage the duration of the alarm; and based on the currently assessed highest level of danger, extract key information from all identified and associated anomalies, structure and integrate the key information to generate a unified security status report, which includes a preliminary judgment on the current nature of the danger, and send the security status report to the user's mobile terminal and the security service center in an encrypted manner.

[0086] This application effectively addresses the limitations of traditional smart home security systems in complex scenarios by real-time correlation, comprehensive evaluation, and dynamic response to multi-source heterogeneous security events. It significantly improves the system's ability to identify, judge, and handle potential dangers, thereby providing users with more comprehensive, intelligent, and reliable security protection.

[0087] The method proposed in this application is mainly applied to smart home security systems, aiming to improve the system's ability to identify and respond to complex security threats. In this system, an "initial security event" refers to an abnormal situation that is first detected by smart home security devices (such as door magnetic sensors, infrared detectors, smoke sensors, etc.) and triggers an alarm response, such as illegal intrusion or early signs of a fire. "Image data" typically originates from smart cameras or video surveillance equipment, and its "visual characteristic information" includes, but is not limited to, brightness, contrast, color saturation, edge density, and motion vectors. This information is extracted using image processing algorithms to analyze anomalies in the image content. "Security protection devices" refer to devices directly used for security prevention and response, such as smart door locks, alarms, and emergency buttons; while "non-security protection devices" refer to other devices in the smart home that do not directly perform security protection functions, such as smart light bulbs, smart curtains, and smart speakers. "Environmental sensors" include, but are not limited to, temperature sensors, humidity sensors, gas sensors, and sound sensors, used to continuously monitor various physical parameters of the home environment. "Minor changes" refer to abnormal fluctuations or slow, continuous trends in these sensor data when they do not reach traditional alarm thresholds; these changes may indicate potential threats.

[0088] In practice, the system first acquires information about an initial security event. For example, when a smart door magnetic sensor detects that a door or window has been opened without authorization, an initial security event is generated. This information may include the event type, the time of occurrence, and the area where the event occurred.

[0089] Subsequently, the system acquires image data related to the area where the initial security incident occurred. For example, if the initial security incident occurred in the living room, the system activates the smart camera in the living room and acquires the real-time video stream or image frames it captures. The acquired image data is transmitted to the processing module for processing to obtain visual characteristic information of the image data. Image processing may include operations such as grayscale conversion, edge detection, and feature point extraction to quantify the image's brightness, contrast, texture, motion, and other visual characteristics.

[0090] Next, the system will identify whether there are large areas of low contrast or areas of excessive brightness or darkness in the image data based on the visual characteristic information. For example, by analyzing the histogram distribution of the image, it can determine whether there are large areas of concentrated or dispersed brightness, thereby identifying areas of excessive brightness or darkness; by calculating local contrast, low contrast areas can be identified. When these anomalies are identified, the system will classify the anomalies in the image data as events indicating that the image information has been interfered with or altered, and determine the degree of occurrence of the event. For example, if a large area of ​​solid color or a blurred area appears in the image, it may indicate that the camera has been obstructed or sprayed; if the image brightness increases or decreases abnormally, it may indicate strong light or that the light source has been blocked. The degree of occurrence of the event can be quantified based on parameters such as the area, duration, and magnitude of change of the abnormal area.

[0091] Simultaneously, the system will acquire communication status information of security devices related to the area where the initial security incident occurred and its adjacent areas. For example, if the initial security incident occurred in the living room, the system will check the network connection status of security devices such as smart door locks and alarms in the living room and adjacent bedrooms. Communication status information may include whether the device is online, signal strength, data transmission rate, etc.

[0092] When the security device is unresponsive or disconnected, and other non-security devices are normally connected, the system analyzes the proximity of the unresponsive or disconnected security device to the area where the initial security event occurred. For example, if the smart door lock in the living room is offline, while the smart light bulb and smart speaker are online, this may indicate that the door lock's communication is experiencing localized interference. The system will classify the communication anomaly of the security device as a localized, purposeful communication interference event and determine the severity of the event. The severity can be assessed based on factors such as the importance of the affected device, its offline time, and its correlation with the initial event.

[0093] In addition, the system continuously acquires real-time sensing data from multiple environmental sensors. For example, temperature sensors, humidity sensors, and gas sensors continuously send real-time data to the system. The system identifies and records minute changes in the real-time sensing data that have not yet reached a preset alarm threshold but exhibit slow, continuous changes or abnormal fluctuation trends. For example, if the indoor temperature rises slowly over a short period of time but does not reach the fire alarm threshold, or if the concentration of a certain gas in the air shows slight but continuous fluctuations, these may be identified as minute changes.

[0094] Subsequently, the system will correlate the initial security event, the occurrence of the event, the degree of danger of the event, and the minor changes in real time. For example, if the initial security event is that a door or window is illegally opened, while the living room camera footage is interfered with, the living room smart door lock is offline, and the indoor temperature rises slightly, the system will correlate these events to form a more comprehensive security situation view.

[0095] Based on this correlation information, the system assigns a weight to each event according to its chronological order, proximity to the area where the initial security incident occurred, and the degree of danger it may indicate. For example, events closer to the initial security incident in time and location, and those indicating a higher degree of danger, will have a greater weight. The system then aggregates the information with these weights to calculate an assessment value reflecting the overall current security situation. This assessment value can be a comprehensive score used to quantify the security risks of the current environment.

[0096] Finally, the system manages the duration of the alert based on the assessed values. For example, if the assessed value is high, the alert may last longer or be presented in a more urgent manner. Simultaneously, based on the currently assessed highest level of danger, the system extracts key information from all identified and associated anomalies, structurally integrates this key information, and generates a unified security status report. This security status report includes a preliminary assessment of the current nature of the danger, such as "suspected intrusion accompanied by device interference." This report is sent to the user's mobile terminal and the security service center in an encrypted manner to ensure the security and timeliness of the information.

[0097] The smart home device security alarm linkage response method of this application significantly improves the ability of smart home security systems to cope with complex situations through multi-dimensional and multi-level event correlation and comprehensive evaluation. Traditional systems often rely on a single event to trigger an alarm, making it difficult to identify and respond to complex security situations accompanied by device interference or environmental camouflage. For example, when an intruder attempts to conceal their presence by interfering with cameras, blocking communication of some security devices, and creating minor environmental changes, traditional systems may be unable to make an accurate judgment due to fragmented information.

[0098] This application acquires initial security event information, image visual characteristics, security device communication status information, and minute changes in environmental sensor data in real time. By deeply correlating and comprehensively evaluating this heterogeneous information, it can identify potential patterns that are difficult for traditional systems to detect. For example, if, after an initial security event, there is simultaneous camera image interference, local security device communication anomalies, and minute but continuous fluctuations in environmental parameters, this application can link these seemingly independent events together, classifying them as an intrusion behavior accompanied by system interference, thereby calculating a higher assessment value and level of danger.

[0099] Furthermore, this application can dynamically manage alarm duration based on assessment values ​​and generate a unified security status report containing a preliminary assessment of the nature of the hazard, which is then sent to the user's mobile terminal and the security service center in an encrypted manner. This not only provides more comprehensive and accurate information but also offers users and security service centers more timely and effective decision-making support, thereby significantly improving the overall response efficiency and security of the smart home security system. Compared to existing technologies, this application demonstrates significant innovation and practicality in the identification, assessment, and response to complex security events.

[0100] This application further proposes, based on the aforementioned visual characteristic information, to identify whether the image data contains a large area of ​​low contrast, or a specific pattern of overly bright or overly dark areas, and to determine the abnormalities identified in the image data as events indicating that the image information has been interfered with or altered, and to determine the degree of occurrence of the events, including:

[0101] The image data brightness, contrast, edge density, and specific frequency components are continuously collected and recorded in real time to form a time series.

[0102] Analyze the time series data to identify whether the image data has periodically changing visual characteristics. The periodically changing visual characteristics include brightness, contrast, edge density, or specific frequency components periodically switching between normal and abnormal ranges within a short period of time.

[0103] When the periodically changing visual characteristics are identified, the abnormal situation identified in the image data is judged as a malicious interference event mimicking equipment failure, and the degree of occurrence of the event is determined according to the degree of change of the periodically changing visual characteristics.

[0104] Specifically, continuously collecting and recording real-time values ​​of image data brightness, contrast, edge density, and specific frequency components to form a time series involves using image sensors built into smart home devices or connected cameras to uninterruptedly acquire video streams or continuous image frames at a preset sampling frequency. For each frame, its global average brightness, local contrast distribution, edge density, and specific spatial frequency components obtained through Fourier transform are extracted. These real-time values ​​are continuously stored and organized to construct a sequence of data reflecting the changes in image visual characteristics over time. The purpose is to provide foundational data for subsequent dynamic pattern analysis, enabling the detection of non-transient, time-regular anomalies.

[0105] Among them, analyzing time series data and identifying whether the image data has periodic changes in visual characteristics, such as brightness, contrast, edge density, or specific frequency components periodically switching between normal and abnormal ranges within a short period of time, can be understood as performing pattern recognition on the time series data formed above.

[0106] In practical applications, when periodically changing visual characteristics are identified, anomalies in image data are judged as malicious interference events mimicking equipment malfunctions. The severity of the event is determined based on the degree of change in the periodically changing visual characteristics. This means that once the aforementioned periodically changing visual pattern is detected, the system categorizes it as a high-level event. This judgment is based on a deep understanding of malicious behavior patterns; intruders may attempt to mislead users into believing there is equipment malfunction by simulating camera flickering, image distortion, or intermittent blackouts, thereby lowering their guard. The severity of the event can be quantitatively assessed based on the frequency, amplitude, duration of the periodic changes, and the types of visual characteristics involved (e.g., whether it is a single characteristic change or multiple characteristics changing simultaneously). For example, the greater the amplitude, the higher the frequency, and the longer the duration, the higher the severity of the event, indicating stronger and more purposeful interference. The purpose is to accurately classify and quantify the risk of detected malicious interference, providing a precise basis for subsequent alarm responses.

[0107] This application's solution, by continuously acquiring multi-dimensional visual characteristics of image data and constructing a time series, can capture dynamic change patterns that traditional methods may overlook. Through the above technical solution, this application can significantly improve the accuracy and judgment capability of smart home security systems in identifying anomalies in image information.

[0108] This application further proposes the following steps for continuously acquiring real-time sensing data from multiple environmental sensors, identifying minute changes in the real-time sensing data that have not yet reached a preset alarm threshold but exhibit slow, continuous changes or abnormal fluctuation trends, and recording these minute changes:

[0109] Continuously acquire real-time sensing data from the multiple environmental sensors;

[0110] The real-time sensing data of each of the environmental sensors is sampled, and the changes in the values ​​of the real-time sensing data are recorded.

[0111] Calculate the range of numerical fluctuations and rate of change for each of the environmental sensors within a sliding time window;

[0112] A pre-defined environmental background activity pattern library is provided, which includes benign environmental change patterns.

[0113] The behavior trajectory of the real-time sensing data is compared with the patterns in the environmental background activity pattern library;

[0114] When a mismatch occurs, analyze the duration, frequency of occurrence, and temporal correlation of the minute changes with the initial security event;

[0115] When the minute changes exhibit intermittent, short-lived, and low-intensity characteristics, and repeatedly occur within a certain time window after the initial security event, they are identified as a covert environmental interference pattern and judged as signs of malicious activity by the intruder.

[0116] Specifically, continuously acquiring real-time sensing data from multiple environmental sensors means that the system uninterruptedly receives data streams from various environmental sensors, such as temperature sensors, humidity sensors, light sensors, and air quality sensors. These data streams are sampled in real time, and their values ​​are recorded as they change over time, forming detailed data records.

[0117] Specifically, the calculation of the numerical fluctuation range and rate of change of each environmental sensor within a sliding time window aims to capture the dynamic characteristics of the data over a short period of time, such as the maximum temperature difference within five minutes or the average rise and fall per second. These calculated fluctuation ranges and rates of change constitute the "behavioral trajectory" of the real-time sensing data.

[0118] In practical applications, a pre-set environmental background activity pattern library is crucial to this solution. This library, through long-term monitoring and learning, stores various benign and normal environmental change patterns in the smart home environment, such as natural variations in daylight intensity, seasonal temperature fluctuations, or localized temperature and humidity changes caused by daily user activities (such as cooking and bathing). These patterns are modeled as specific data behavior trajectories. When the behavior trajectory of real-time sensed data does not match any benign pattern in the environmental background activity pattern library, the system further analyzes the characteristics of these subtle changes.

[0119] Specifically, the analysis will cover the duration of these changes (whether they occur instantaneously or over a period of time), their frequency of occurrence (whether they occur sporadically or repeatedly), and their temporal correlation with the initial security event (whether they occur shortly after or simultaneously with the initial security event).

[0120] Furthermore, when these minute changes exhibit intermittent, short-lived, and low-intensity characteristics, and repeatedly occur within a certain time window after the initial security incident, the system identifies them as a "covert environmental interference pattern." This pattern typically does not directly trigger high-threshold alarms, but its specific behavioral patterns strongly suggest unnatural or benign external intervention, and are therefore judged as signs of malicious activity by intruders.

[0121] The proposed solution, by introducing a database of environmental background activity patterns and combining it with refined analysis of subtle change behavior trajectories, can effectively address the limitations of traditional methods in distinguishing between benign environmental changes and covert malicious interference.

[0122] Based on the chronological order of events, their proximity to the area where the initial security incident occurred, and the degree of danger they may indicate, a weight is assigned to each event. Information incorporating these weights is then compiled to calculate an assessment value reflecting the current overall security situation. Specifically, this includes:

[0123] Obtain information about the occurrence of an initial security event;

[0124] The evolution of the initial security event, the event in which the image information was interfered with or altered, the communication interference event, and the minute changes is tracked to form their respective abnormal behavior trajectories;

[0125] Compare the abnormal behavior trajectory with preset normal equipment failure modes and malicious interference modes;

[0126] Based on the comparison results, identify malicious interference intentions;

[0127] Based on the malicious interference intent, the weighting of the initial security event, the event of interference or alteration of image information, the communication interference event, and the event of minor changes in environmental parameters in the evaluation numerical calculation is dynamically adjusted.

[0128] The evaluation value is calculated by summarizing the information with dynamically adjusted weightings.

[0129] Specifically, acquiring information about the occurrence of an initial security event refers to the system receiving any preliminary alarm or anomaly report that may indicate a security risk, such as the triggering of door and window sensors or the activation of a smoke alarm. Tracking the evolution of initial security events, events involving interference or alteration of image information, communication interference events, and subtle changes to form their respective abnormal behavior trajectories can be understood as the system continuously recording and analyzing data from the occurrence to the development of these events, including timestamps, locations, involved devices, duration, and intensity changes, thereby constructing a dynamic behavioral pattern for each abnormal event.

[0130] In practical applications, comparing abnormal behavior trajectories with preset normal device failure modes and malicious interference modes involves matching the tracked abnormal behavior trajectories with a known pattern library stored internally by the system. This pattern library can include various normal device failure modes, such as sensor battery depletion, temporary network interruption, and sudden changes in ambient light, as well as various malicious interference modes, such as signal jamming, camera obstruction, and injection of spoofed sensor data. The comparison process can employ machine learning algorithms, such as support vector machines, neural networks, or decision trees, to extract and classify the features of the behavior trajectories. Furthermore, identifying malicious interference intent based on the comparison results means that when an abnormal behavior trajectory highly matches a malicious interference pattern, the system determines that there is an intent to maliciously attack or intrude. For example, if a camera image continuously exhibits periodic, regular areas of excessive brightness or darkness, and matches a known jammer pattern, it can be identified as malicious interference.

[0131] Therefore, based on the stated malicious interference intent, the system dynamically adjusts the weighting of initial security events, events involving interference or alteration of image information, communication interference events, and minor changes in environmental parameters in the overall security assessment. This means that once a malicious interference intent is identified, the system immediately increases the weight of events related to that intent in the overall security assessment. For example, if communication interference is identified as malicious, the weighting of communication anomaly events will significantly increase, giving them a greater impact on the final assessment value and reflecting a higher level of security. Finally, the assessment value is calculated by summarizing the information with the dynamically adjusted weightings. This means combining the current state information of all events (including initial security events, image anomalies, communication anomalies, and minor changes) with their dynamically adjusted weightings, and using a preset algorithm (e.g., a weighted summation model) to calculate a comprehensive assessment value that more accurately reflects the overall security status of the current smart home environment.

[0132] The solution proposed in this application addresses the limitation of traditional methods in effectively distinguishing between normal malfunctions and malicious behavior when assessing security status by introducing tracking of abnormal behavior trajectories, pattern comparison, and identification of malicious interference intentions.

[0133] Specifically, the methods for managing alarm duration based on the aforementioned assessment values ​​include:

[0134] When the malicious interference intent is identified, the system enters an intent-locked state, maintains the activation of the alarm, and keeps the alarm at the highest response level.

[0135] In the intent-locked state, when calculating the evaluation value, the evaluation scores of all events identified as malicious intent are forced to remain at the highest level;

[0136] In the intent-locked state, the alarm will be deactivated only when security personnel confirm and rule out the possibility on-site, or when multiple independent sensors continuously report no abnormalities, and when all identified malicious behavior trajectories have stopped and been determined to be benign or eliminated.

[0137] "Intent Lockout State" refers to a special operating mode that a smart home security system enters after identifying malicious intent to interfere. In this mode, the system assumes a persistent and purposeful intent and takes a series of enhanced measures to counter it. Maintaining the alarm's active state and keeping it at the highest response level means that once in intent lockout state, the alarm will not automatically downgrade or deactivate due to a temporary drop in individual indicators, but will continue to operate at the most urgent settings, for example, responding through high-decibel alarm sounds, high-brightness flashing lights, and immediate notification of the security service center. In intent lockout state, when the system calculates the overall security assessment value, the assessment scores for all events identified as having malicious intent will be forcibly set to the highest level. This is designed to prevent malicious actors from lowering the system's vigilance by briefly stopping or changing their attack patterns, thereby ensuring that the overall assessment value accurately reflects a persistent intent.

[0138] Furthermore, the conditions for clearing the alarm are strictly limited, and it can only be cleared when one of the following three conditions is met: first, security personnel confirm and explicitly rule out the possibility of misconduct on-site; second, multiple independently operating sensors continuously report no abnormalities, forming a consistent security judgment; and third, all identified malicious behavior trajectories have ceased and have been judged by the system as benign events or completely eliminated. These strict clearing conditions are designed to minimize the risk of prematurely clearing the alarm due to misjudgment or malicious deception.

[0139] This application's solution, by introducing an "intent-locked state" and its accompanying alarm management strategy, effectively addresses the limitation that alarms may prematurely downgrade or deactivate due to real-time fluctuations in assessment values ​​after malicious interference intent has been identified. Through the aforementioned technical solution, this application can significantly improve the robustness and reliability of smart home security alarm systems.

[0140] The above-mentioned process of entering an intent-locked state upon identifying malicious interference intent, maintaining the alert's active state, and keeping the alert at the highest response level also includes:

[0141] While the intent is locked, the user's response behavior to the alarm is continuously monitored, including the number of times the alarm is viewed, the viewing duration, and the frequency of alarm cancellation requests.

[0142] When a downward trend in the response behavior is detected, the alarm fatigue assessment process is initiated.

[0143] Based on the alarm fatigue assessment process, analyze the duration, number of devices involved, and level of the current malicious interference event;

[0144] When the analysis results indicate a risk of user alert fatigue, the presentation of the alert is adjusted. The presentation method includes changing the alert from a real-time pop-up to a periodic summary push, or playing a low-volume alert tone through a smart speaker; and sending a report containing the current detailed analysis and response suggestions to the user's mobile terminal.

[0145] Specifically, while the system is in an intent-locked state, it continuously monitors user interactions related to alerts. These responses can be understood as a reflection of the user's level of attention to the alert and their willingness to take action. For example, the system records the number of times the user views alert notifications, the duration of each viewing, and the frequency with which the user attempts to send an alert cancellation request. This data is used to quantify the user's reaction to persistent alerts.

[0146] Specifically, when a downward trend in the detected response behavior is observed—for example, a decrease in the number of alert views, a shortening of the viewing duration, or an increase in the frequency of alert cancellation requests—it indicates that the user may be experiencing alert fatigue. In this case, the system will automatically initiate an alert fatigue assessment process.

[0147] In practical applications, the alarm fatigue assessment process comprehensively analyzes multiple factors, including the duration of the current malicious interference event, the number of affected smart home devices, and the system's assessment level. These factors are used together to determine the degree of risk users face from alarm fatigue.

[0148] As a preferred implementation, when the analysis results clearly indicate a risk of user alert fatigue, the system will take measures to adjust the presentation of alerts. For example, the originally real-time, forced pop-up alert notifications can be changed to periodically pushing summary information to the user's mobile device, or a low-volume alert tone can be played through a smart speaker to avoid excessively disturbing the user. Simultaneously, to ensure that users still receive critical security information, the system will also send a report to the user's mobile device containing a detailed analysis and response recommendations to help the user understand the situation and take appropriate action.

[0149] This application's solution introduces a continuous monitoring mechanism for user alarm response behavior, enabling timely detection of potential alarm fatigue. When the system detects a decline in user attention to alarms, it initiates an alarm fatigue assessment process. This process quantifies the risk of user alarm fatigue by incorporating factors such as the duration, scope, and severity of malicious interference events. This dynamic assessment allows the system to avoid indiscriminately maintaining high-intensity alarms, instead intelligently adjusting the alarm presentation based on the user's actual state.

[0150] This application further proposes, under the aforementioned intent-locked state, continuous monitoring of the user's response behavior to the alarm, wherein the response behavior includes the number of alarm views, the viewing duration, and the frequency of alarm cancellation requests, including:

[0151] In the intent-locked state, the screen-on time of the user's mobile terminal, application switching records, alarm notification click rate, and alarm information reading progress are continuously monitored.

[0152] Continuously monitor user interaction records on the smart home control screen, including the activation time of the control screen, the type of operation command, and the dwell time on alarm-related interfaces;

[0153] Based on the interaction records, the actual attention level of the user to the alarm is calculated. The actual attention level reflects the user's depth of understanding of the alarm and willingness to take action.

[0154] When the actual attention level is lower than a preset alert maintenance threshold, it is determined that the user has deep-seated alarm fatigue.

[0155] Specifically, in the intent-locked state, the system is configured to continuously monitor the user's specific interactive behaviors on different smart devices. For the user's mobile terminal, the screen-on time is recorded to assess whether the user is actively viewing the device; application switching records are analyzed to determine whether the user quickly switches to other applications after the alarm notification pops up, thus reflecting their level of attention to the alarm; alarm notification click-through rate is statistically analyzed to measure the user's willingness to respond to the alarm immediately; and alarm information reading progress is determined by analyzing the user's scrolling and dwelling behavior on the alarm details page or report to assess the user's depth of understanding of the alarm content.

[0156] Among them, the activation time of the smart home control screen is continuously monitored to understand when the user interacts with the control screen; the type of operation command is recorded, such as whether the user has executed the security event confirmation command, the security device status query command, or the security service request command, which helps to determine the user's intention to act; the time spent on alarm-related interfaces is statistically analyzed to reflect the duration of the user's attention to alarm information.

[0157] In practical applications, based on the collected interaction records from mobile terminals and the central control screen, the system is designed to calculate a user's actual attention level to the alarm. This value is a comprehensive indicator, derived through weighted analysis or machine learning model processing of data from multiple dimensions, including screen-on time, application switching records, alarm notification click-through rate, alarm information reading progress, central control screen activation time, operation command type, and dwell time on alarm-related interfaces. This actual attention level is understood as reflecting the user's depth of understanding of the alarm and their willingness to act; that is, the user not only saw the alarm but also understood its meaning and had a tendency to take action.

[0158] When the actual attention level falls below a preset alert maintenance threshold, the system determines that the user is experiencing deep-seated alarm fatigue. This alert maintenance threshold is a configurable parameter designed to distinguish between general user distraction and genuine alarm fatigue. Deep-seated alarm fatigue means that the user has become significantly desensitized or weary of continuous alarm messages, and their potential alertness has drastically decreased, requiring more proactive intervention from the system.

[0159] The solution proposed in this application continuously monitors the multi-dimensional and granular interactive behaviors of users on mobile terminals and smart home control screens, and calculates the actual attention value reflecting the user's depth of understanding and willingness to act based on these interaction records, thereby solving the limitation of insufficient accuracy in alarm fatigue judgment in the above-mentioned basic solutions.

[0160] This application further proposes a method that, after adjusting the presentation of alarm information, continuously monitors user interaction behavior to determine whether the user has regained alertness, and if the user has not regained alertness and the alertness persists or escalates, forcibly activates all lighting devices in the smart home environment to operate in a high-brightness flashing mode, while simultaneously playing a preset emergency alarm sound through a smart speaker.

[0161] Specifically, after adjusting the presentation of the alarm information, the system will continuously monitor the types of operation commands given by users on the smart home control screen. These command types can include security incident confirmation commands, security device status query commands, or security service request commands. Simultaneously, the system will also monitor users' clicking behavior on alarm summary push notifications on their mobile terminals, as well as the depth of their reading of the report content. Specifically, a security incident confirmation command refers to a user's active confirmation that they have acknowledged and addressed a security incident; a security device status query command refers to a user's query of the current working status of a specific security device (such as a camera, door sensor, etc.); and a security service request command refers to a user's command to send a request for assistance or on-site support to the security service center. Clicking behavior on alarm summary push notifications and the depth of reading of the report content reflect the user's level of attention and understanding of the alarm information.

[0162] If a user fails to execute the security event confirmation command, query the security device status, or send the security service request command within a preset time window, and both the click on the alarm summary push and the reading depth of the report content are below a preset threshold, the system will determine that the user has not regained alertness. The preset time window can be flexibly configured according to the urgency of the security event and user habits; for example, it can be set to 5 minutes, 10 minutes, or longer. The preset threshold can be set based on historical data or expert experience to quantify the minimum level of user attention to the alarm.

[0163] When the system determines that the user has not regained alertness and that malicious interference continues or escalates in intensity, it will forcibly activate all lighting devices in the smart home environment, causing them to operate in a high-brightness flashing mode, and simultaneously play a preset emergency alarm tone through the smart speaker. "Continuous malicious interference" means that the system, through continuous monitoring and analysis, confirms that previously identified malicious interference (such as image interference, communication interference, or minor environmental changes) has not stopped or has been eliminated. "Elevated intensity" means that the overall security assessment value calculated based on evaluation values ​​continues to rise, or that new and more serious anomalies are identified and associated. Forcibly activating all lighting devices and causing them to flash at high brightness, along with playing the emergency alarm tone, aims to overcome the user's alarm fatigue through strong visual and auditory stimulation, forcing them to focus on the serious security situation they face.

[0164] This application's solution, based on user alert fatigue risk management, further introduces a monitoring mechanism for the actual recovery of user alertness. Through the above technical solution, this application can effectively solve the problem that even after adjusting the alert presentation method, security incidents may still be overlooked due to the user's failure to regain alertness after alert fatigue has occurred.

[0165] This application further proposes steps for sending a report containing a detailed current analysis and response recommendations to the user's mobile terminal, including:

[0166] Obtain a security status report;

[0167] An attempt was made to send the security status report to the user's mobile terminal via the main communication channel;

[0168] When the main communication channel fails to send the security status report or the user's mobile terminal is offline, the system switches to the auxiliary communication channel to send a simplified version of the security status report or key alarm information.

[0169] The security status report is encrypted and stored in a local secure storage unit within the smart home.

[0170] Generate a notification containing access credentials and send it to the user through the auxiliary communication channel;

[0171] When the user's mobile terminal returns to online status or its battery is restored, the user is prompted to download the complete security status report from the smart home local secure storage unit or resend the complete security status report through the main communication channel;

[0172] Continuously monitor the receiving status of the user's mobile terminal and the reading status of the security status report;

[0173] If the security status report is not received or read by the user for an extended period of time, the system will periodically resend the security status report through different channels and send a voice prompt to the user.

[0174] Specifically, obtaining a safety status report refers to the process by which the system extracts key information from all identified and associated anomalies based on the currently assessed highest level of danger, and then structurally integrates this key information to generate a report that includes a preliminary assessment of the current nature of the hazard. This report aims to provide users with comprehensive and detailed analysis and response recommendations.

[0175] The attempt to send the security status report to the user's mobile terminal via the main communication channel can be understood as the system prioritizing the use of the stable, high-speed network connection established between the smart home system and the user's mobile terminal, such as via Wi-Fi or cellular data networks, for data transmission. This main communication channel typically has high bandwidth and low latency, making it suitable for transmitting complete security status reports containing detailed information.

[0176] In practical applications, when the primary communication channel fails to send a security status report—for example, due to network interruption, weak signal, or the user's mobile terminal being temporarily unable to access the network, or the user's mobile terminal being offline (e.g., powered off, in airplane mode, or without a network connection)—the system automatically switches to the secondary communication channel. The secondary communication channel can be SMS service, email, low-power wide area network (LPWAN), or local broadcast notifications from a smart home gateway. The secondary communication channel sends a simplified version of the security status report or critical alert information, aiming to ensure that the most critical danger information and initial response recommendations are delivered to the user in a timely manner, even under conditions of limited communication.

[0177] Furthermore, encrypting and storing security reports in a local secure storage unit within the smart home means that after the report is generated, the system saves it in encrypted form in a dedicated storage module within the smart home system. This local secure storage unit typically has a high level of security protection, effectively preventing unauthorized access and data tampering, ensuring the integrity and confidentiality of the report.

[0178] Furthermore, generating a notification containing access credentials and sending it to the user via a secondary communication channel means that once the full report is stored locally, the system generates a lightweight notification containing the credentials or instructions required for the user to access the locally stored report. This notification, sent via the secondary communication channel, aims to inform the user that a new security report is available and guide the user to access or download the full report when conditions permit.

[0179] Therefore, when the user's mobile device returns to online status or its battery is restored, the system will proactively prompt the user to download the complete security status report from the smart home's local secure storage unit, or resend the complete security status report through the main communication channel. This mechanism ensures that even if the initial transmission fails, the user can obtain complete and detailed security information when conditions are restored.

[0180] As a preferred implementation, the system continuously monitors the user's mobile terminal's reception status and the reading status of security reports. The reception status can be determined through the confirmation mechanism of the communication protocol, while the reading status can be analyzed through behavioral data such as receipts from smart home applications on the user's mobile terminal, screen-on time, application dwell time, or scrolling progress.

[0181] Specifically, if a security status report is not received or read by the user for an extended period, the system will determine that the user may have missed the alert or failed to fully understand its importance. In this case, the system will periodically resend the security status report through different channels, such as the main channel, auxiliary channels, or even by playing a preset voice prompt through a smart speaker, to remind the user to pay attention in multiple ways and ensure that the critical information is ultimately received and understood by the user.

[0182] This application's solution effectively addresses the problems of low delivery rates, information loss, or users not responding promptly that may arise with traditional single-channel report sending by constructing a multi-channel, multi-level report sending and confirmation mechanism. Through the above technical solution, this application can significantly improve the reliability of smart home security alarm response and user experience.

[0183] refer to Figure 2 , Figure 2 This is a schematic diagram of a smart home device security alarm linkage response system provided in an embodiment of the present invention, comprising:

[0184] The acquisition end is used to acquire information about the occurrence of an initial security event; acquire image data related to the area where the initial security event occurred, and process the image data to obtain visual characteristic information of the image data;

[0185] The recognition end is used to identify, based on the visual characteristic information, whether there is a large area of ​​low contrast or a specific pattern of overly bright or dark areas in the image data, and to determine the abnormality in the image data as an event in which the image information is interfered with or altered, and to determine the degree of occurrence of the event.

[0186] The analysis unit is used to acquire communication status information of security protection devices related to the area where the initial security incident occurred and its adjacent areas; when the security protection device is unresponsive or in a disconnected state, and other non-security protection devices are in a normal connected state, the analysis unit analyzes the proximity of the area where the unresponsive or disconnected security protection device is located to the area where the initial security incident occurred, and judges the communication anomaly of the security protection device as a localized, purposeful communication interference event, and determines the degree of danger of the event;

[0187] The recording end continuously acquires real-time sensing data from multiple environmental sensors, identifies minute changes in the real-time sensing data that have not yet reached a preset alarm threshold but exhibit slow, continuous changes or abnormal fluctuation trends, and records these minute changes.

[0188] The correlation terminal is used to correlate the initial security event, the occurrence of the event, the degree of danger of the event, and the minor changes in real time.

[0189] The calculation unit is used to determine a consideration weight for each event based on the order of occurrence of each event, its proximity to the area where the initial security event occurred, and the degree of danger it may indicate, and to summarize the information with the consideration weight to calculate an assessment value that reflects the current overall security status.

[0190] The integration unit manages the duration of alarms based on the assessment values; and extracts key information from all identified and associated anomalies based on the highest assessed risk level, integrates the key information in a structured manner, generates a unified security status report, which includes a preliminary assessment of the current risk nature, and sends the security status report to the user's mobile terminal and the security service center in an encrypted manner.

[0191] This application modularizes the functional aspects of the smart home device security alarm linkage response method, clarifying the responsibilities of each functional unit. This enables more efficient and stable real-time correlation, comprehensive assessment, and dynamic response to multi-source heterogeneous security events. This modular design helps the system improve its ability to identify, judge, and handle potential dangers in complex and ever-changing scenarios, providing users with comprehensive, intelligent, and reliable security. Through the collaborative work of various functional units, the system overcomes the limitations of traditional security systems in terms of information fragmentation and judgment errors, ensuring the integrity, accuracy, and timeliness of security information and responses.

[0192] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for security alarm linkage response of smart home devices, characterized in that, include: Obtain information about the occurrence of an initial security event; Acquire image data related to the area where the initial security incident occurred, and process the image data to obtain visual characteristic information of the image data; Based on the visual characteristic information, identify whether there are large areas of low contrast in the image data, or identify large areas of excessively bright or dark areas with concentrated or dispersed brightness by analyzing the image histogram distribution, and judge the abnormalities in the image data as events where the image information is interfered with or altered, and determine the degree of occurrence of the event. For security protection devices related to the area where the initial security event occurred and its adjacent areas, obtain their communication status information; When the security protection device is unresponsive or disconnected, and other non-security protection devices are in a normal connected state, the proximity of the area where the unresponsive or disconnected security protection device is located to the area where the initial security event occurred is analyzed, and the communication anomaly of the security protection device is judged as a localized, purposeful communication interference event, and the degree of danger of the event is determined. Continuously acquire real-time sensing data from multiple environmental sensors, identify minute changes in the real-time sensing data that have not yet reached a preset alarm threshold but exhibit slow, continuous changes or abnormal fluctuation trends, and record the minute changes. The initial security event, the extent of the event's occurrence, the degree of danger of the event, and the minute changes are correlated in real time. Based on the chronological order of each event, its proximity to the area where the initial security event occurred, and the degree of danger it indicates, a weight is assigned to each event, and information with the weight is summarized to calculate an assessment value that reflects the current overall security situation. The duration of the management alert is determined based on the assessed values. Based on the highest level of danger currently assessed, key information is extracted from all identified and associated anomalies. This key information is then structured and integrated to generate a unified security status report. The security status report includes a preliminary assessment of the current nature of the danger and is sent to the user's mobile terminal and the security service center in an encrypted manner.

2. The smart home device security alarm linkage response method according to claim 1, characterized in that, The step of identifying whether there are large-scale low-contrast areas in the image data based on the visual characteristic information, or large areas of concentrated or dispersed brightness that are too bright or too dark, identified by analyzing the image histogram distribution, and judging the anomalies identified in the image data as events of image information being interfered with or altered, and determining the degree of occurrence of the event, includes: The image data is continuously collected and recorded in real time, including the brightness, contrast, edge density, and spatial frequency components obtained through Fourier transform, forming a time series. Analyze the time series data to identify whether there are periodically changing visual characteristics in the image data. The periodically changing visual characteristics include brightness, contrast, edge density, or spatial frequency components obtained by Fourier transform that periodically switch between normal and abnormal ranges in a short period of time. When the periodically changing visual characteristics are identified, the anomalies identified in the image data are judged as malicious interference events mimicking equipment malfunctions, and the degree of occurrence of the event is determined based on the degree of change of the periodically changing visual characteristics.

3. The smart home device security alarm linkage response method according to claim 1, characterized in that, The system continuously acquires real-time sensing data from multiple environmental sensors, identifies minute changes in the real-time sensing data that have not yet reached a preset alarm threshold but exhibit slow, continuous changes or abnormal fluctuation trends, and records these minute changes, including: Continuously acquire real-time sensing data from the multiple environmental sensors; The real-time sensing data of each of the environmental sensors is sampled, and the changes in the values ​​of the real-time sensing data are recorded. Calculate the range of numerical fluctuations and rate of change for each of the environmental sensors within a sliding time window; A pre-defined environmental background activity pattern library is provided, which includes benign environmental change patterns. The behavior trajectory of the real-time sensing data is compared with the patterns in the environmental background activity pattern library; When a mismatch occurs, analyze the duration, frequency of occurrence, and temporal correlation of the minute changes with the initial security event; When the minute changes exhibit intermittent, short-lived, and low-intensity characteristics, and repeatedly occur within a certain time window after the initial security event, they are identified as a covert environmental interference pattern and judged as signs of malicious activity by the intruder.

4. The smart home device security alarm linkage response method according to claim 1, characterized in that, The process involves determining a weighting for each event based on its chronological order, proximity to the area where the initial security incident occurred, and the degree of danger it foreshadows. Information incorporating these weightings is then aggregated to calculate an assessment value reflecting the current overall security situation. This includes: Obtain information about the occurrence of an initial security event; The evolution of the initial security event, the event in which the image information was interfered with or altered, the communication interference event, and the minute changes is tracked to form their respective abnormal behavior trajectories; Compare the abnormal behavior trajectory with preset normal equipment failure modes and malicious interference modes; Based on the comparison results, identify malicious interference intentions; Based on the malicious interference intent, the weighting of the initial security event, the event of interference or alteration of image information, the communication interference event, and the event of minor changes in environmental parameters in the evaluation numerical calculation is dynamically adjusted. The evaluation value is calculated by summarizing the information with dynamically adjusted weighting of the considerations.

5. The smart home device security alarm linkage response method according to claim 4, characterized in that, The process of managing the duration of the alarm based on the assessed value includes: When the malicious interference intent is identified, the system enters an intent-locked state, maintains the activation of the alarm, and keeps the alarm at the highest response level. In the intent-locked state, when calculating the evaluation value, the evaluation scores of all events identified as malicious intent are forced to remain at the highest level; In the intent-locked state, the alarm will be deactivated only when security personnel confirm and rule out the possibility on-site, or when multiple independent sensors continuously report no abnormalities, and when all identified malicious behavior trajectories have stopped and been determined to be benign or eliminated.

6. The smart home device security alarm linkage response method according to claim 5, characterized in that, The step of entering an intent-locking state upon identifying the malicious interference intent, maintaining the alarm's active state, and keeping the alarm at the highest response level, further includes: While the intent is locked, the system continuously monitors the user's response to the alert, including the number of times the alert is viewed, the duration of the view, and the frequency of alert cancellation requests. When a downward trend in the response behavior is detected, the alarm fatigue assessment process is initiated. Based on the alarm fatigue assessment process, analyze the duration, number of devices involved, and level of the current malicious interference event; When the analysis results indicate a risk of user alert fatigue, the presentation of the alert is adjusted. The presentation method includes changing the alert from a real-time pop-up to a periodic summary push, or playing a low-volume alert tone through a smart speaker; and sending a report containing the current detailed analysis and response suggestions to the user's mobile terminal.

7. A smart home device security alarm linkage response method according to claim 6, characterized in that, In the intent-locked state, the system continuously monitors the user's response behavior to the alarm, including the number of alarm views, the viewing duration, and the frequency of alarm cancellation requests, including: In the intent-locked state, the screen-on time of the user's mobile terminal, application switching records, alarm notification click rate, and alarm information reading progress are continuously monitored. Continuously monitor user interaction records on the smart home control screen, including the activation time of the control screen, the type of operation command, and the dwell time on alarm-related interfaces; Based on the interaction records, the actual attention level of the user to the alarm is calculated. The actual attention level reflects the user's depth of understanding of the alarm and willingness to take action. When the actual attention level is lower than a preset alert maintenance threshold, it is determined that the user has deep-seated alarm fatigue.

8. A smart home device security alarm linkage response method according to claim 6, characterized in that, When the analysis results indicate a risk of user alert fatigue, the presentation method of the alert is adjusted. This adjustment includes changing the alert information from a real-time pop-up to a periodic summary push, or playing a low-volume alert tone via a smart speaker, followed by: After adjusting the presentation method of the alarm information, monitor the types of operation commands that users use on the smart home control screen. The types of operation commands include security event confirmation commands, security device status query commands, or security service request commands. Monitor users' click behavior on alert summary push notifications on their mobile devices, as well as the depth of their reading of the report content; If a user does not execute the security event confirmation command, or does not query the security device status, or does not send the security service request command within a preset time window, and the click behavior of the alarm summary push and the reading depth of the report content are lower than a preset threshold, it is determined that the user has not regained vigilance. When it is determined that the user has not regained vigilance and the malicious interference continues or the level escalates, all lighting devices in the smart home environment will be forcibly activated, causing them to operate in a high-brightness flashing mode, while simultaneously playing a preset emergency alarm sound through the smart speaker.

9. A smart home device security alarm linkage response method according to claim 6, characterized in that, The process of sending a report containing a detailed analysis and response recommendations to the user's mobile terminal includes: Obtain a security status report; An attempt was made to send the security status report to the user's mobile terminal via the main communication channel; When the main communication channel fails to send the security status report or the user's mobile terminal is offline, the system switches to the auxiliary communication channel to send a simplified version of the security status report or key alarm information. The security status report is encrypted and stored in a local secure storage unit within the smart home. Generate a notification containing access credentials and send it to the user through the auxiliary communication channel; When the user's mobile terminal returns to online status or the battery is restored, the user is prompted to download the complete security status report from the smart home local security storage unit or resend the complete security status report through the main communication channel; Continuously monitor the receiving status of the user's mobile terminal and the reading status of the security status report; If the security status report is not received or read by the user for an extended period of time, the system will periodically resend the security status report through different channels and send a voice prompt to the user.

10. A method for security alarm linkage response of a smart home device, characterized in that, include: The acquisition end is used to obtain information about the occurrence of an initial security event; Acquire image data related to the area where the initial security incident occurred, and process the image data to obtain visual characteristic information of the image data; The recognition end is used to identify, based on the visual characteristic information, whether there is a large area of ​​low contrast in the image data, or a large area of ​​excessively bright or dark areas with concentrated or dispersed brightness identified by analyzing the image histogram distribution, and to determine the abnormal situation in the image data as an event in which the image information is interfered with or altered, and to determine the degree of occurrence of the event. The analysis unit is used to acquire communication status information of security protection devices related to the area where the initial security incident occurred and its adjacent areas; when the security protection device is unresponsive or in a disconnected state, and other non-security protection devices are in a normal connected state, the analysis unit analyzes the proximity of the area where the unresponsive or disconnected security protection device is located to the area where the initial security incident occurred, and judges the communication anomaly of the security protection device as a localized, purposeful communication interference event, and determines the degree of danger of the event; The recording end is used to continuously acquire real-time sensing data from multiple environmental sensors, identify minute changes in the real-time sensing data that have not yet reached a preset alarm threshold but show a slow, continuous change or an abnormal fluctuation trend, and record the minute changes. The correlation terminal is used to correlate the initial security event, the occurrence of the event, the degree of danger of the event, and the minor changes in real time. The calculation unit is used to determine a consideration weight for each event based on the order of occurrence of each event, its proximity to the area where the initial security event occurred, and the degree of danger it indicates, and to summarize the information with the consideration weight to calculate an assessment value that reflects the current overall security status. The integration unit is used to manage the duration of alarms based on the evaluation values. Based on the highest level of danger currently assessed, key information is extracted from all identified and associated anomalies. This key information is then structured and integrated to generate a unified security status report. The security status report includes a preliminary assessment of the current nature of the danger and is sent to the user's mobile terminal and the security service center in an encrypted manner.

Citation Information

Patent Citations

  • Intelligent security software monitoring method and system

    CN117423197A

  • Ai-based real-time fire prediction and response optimization system and method

    KR102882828B1