A knowledge graph-based urban large-scale event security deployment method

By constructing a security knowledge graph with limited attributes and a three-domain write-back StarE model, the problem of continuous iterative updating of cross-domain linkage relationships in the security deployment of large-scale urban events was solved, achieving dynamic consistency and synergy between deployment results and on-site status.

CN122334828APending Publication Date: 2026-07-03SICHUAN WEILONG SECURITY GRP CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SICHUAN WEILONG SECURITY GRP CO LTD
Filing Date
2026-04-07
Publication Date
2026-07-03

AI Technical Summary

Technical Problem

Existing technologies are ill-suited for adapting to the continuous changes and dynamic adjustments of multi-source information in security deployments for large-scale urban events. They lack the ability to continuously iterate and update the cross-domain linkage relationships between event areas, passageways, and police forces, resulting in a disconnect between deployment results and the actual situation on site.

Method used

Based on the security basic dataset, a security knowledge graph with limited attributes is constructed. Through joint processing using the three-domain write-back StarE model, a joint situational representation and deployment hypothesis relationship of the three domains are generated, realizing cross-domain correlation propagation and deployment write-back iteration, forming a continuous update mechanism.

Benefits of technology

It improved the integrity and relevance of security data organization, enhanced the overall coordination and dynamic adjustment capabilities of security deployment plans for large-scale urban events, and ensured the consistency between deployment results and on-site conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122334828A_ABST
    Figure CN122334828A_ABST
Patent Text Reader

Abstract

This invention discloses a knowledge graph-based method for security deployment in large-scale urban events, comprising the following steps: collecting security data for large-scale urban events, extracting and constructing a basic security dataset; based on the basic security dataset, constructing graph entities, graph relationships, and limited attribute slots to generate a limited attribute security knowledge graph; constructing a three-domain write-back StarE model; based on the limited attribute security knowledge graph, generating a combined slot representation and jointly mapping it with graph relationships to generate a composite limited relationship representation; based on the graph entities and composite limited relationship representation, generating a three-domain joint situational awareness representation; based on the three-domain joint situational awareness representation, constructing deployment hypothesis nodes and deployment hypothesis relationships to generate a deployment write-back knowledge graph; and iteratively updating the deployment write-back knowledge graph to generate a security deployment plan for large-scale urban events. This invention improves the expressive and dynamic generation capabilities of security deployment associations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of public safety and security prevention and control, and in particular to a method for security deployment of large-scale urban events based on knowledge graphs. Background Technology

[0002] Security deployment for large-scale urban events involves the coordinated organization of multiple stakeholders, including event areas, access routes, police forces, time periods, risk events, and traffic conditions. This constitutes a complex decision-making problem in public safety assurance. Current technologies typically rely on human experience to develop deployment plans, or analyze local risks using video surveillance, rule statistics, or single graph models, combined with static contingency plans for police deployment. While these methods can support event security management to some extent, they primarily rely on decentralized data processing and single-result output, making them ill-suited to the continuously changing multi-source information and frequent dynamic adjustments to deployment relationships required at large-scale events.

[0003] Furthermore, existing technologies typically process activity area information, passageway information, police force information, and risk information separately, lacking a unified organizational method oriented towards relationships. This makes it difficult to synchronously express the constraints, dependencies, and temporal relationships between different objects. Even when knowledge graphs or graph reasoning methods are introduced, they are mostly focused on risk identification, target association analysis, or static relationship completion, failing to form a relationship expression mechanism that can directly support deployment generation for security deployment tasks. For cross-domain linkage relationships between activity areas, passageways, and police forces, existing methods generally lack continuous iterative update capabilities, leading to a disconnect between deployment results and on-site conditions, making it difficult to support dynamic security deployment in complex scenarios.

[0004] Therefore, how to provide a knowledge graph-based security deployment method for large-scale urban events is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0005] One objective of this invention is to propose a knowledge graph-based method for security deployment in large-scale urban events. This invention constructs a knowledge graph with defined attributes based on a basic security dataset, and then builds a three-domain write-back StarE model based on this knowledge graph. Through a defined slot encoding layer, a composite relationship generation layer, a three-domain coupling propagation layer, a deployment hypothesis generation layer, and a write-back iteration layer, it jointly processes graph relationships, defined attribute slots, event area node data, channel node data, and police force node data to generate a three-domain joint situational awareness representation, deployment hypothesis nodes, deployment hypothesis relationships, and a security deployment plan for large-scale urban events. This invention can complete defined attribute slot attachment, cross-domain association propagation, and deployment write-back iteration.

[0006] A method for security deployment of large-scale urban events based on knowledge graphs according to an embodiment of the present invention includes the following steps: Collect security data for large-scale urban events, and extract and construct a basic security dataset; Based on the security basic dataset, we construct graph entities, graph relations and limited attribute slots, and attach the limited attribute slots to the graph relations to generate a limited attribute security knowledge graph; A three-domain write-back StarE model is constructed, including a limited slot encoding layer, a composite relationship generation layer, a three-domain coupling propagation layer, a deployment hypothesis generation layer, and a write-back iteration layer; Based on the security knowledge graph with limited attributes, the limited attribute slots are input into the limited slot encoding layer for slot-by-slot encoding to generate a combined slot representation. In the composite relation generation layer, the graph relations and the combined slot representation are jointly mapped to generate a composite limited relation representation. Input the graph entities into the three-domain coupled propagation layer, and perform cross-domain association propagation between the graph entities based on the composite constraint relationship representation to generate a three-domain joint situational representation. The three-domain joint situational representation is input into the deployment hypothesis generation layer to construct deployment hypothesis nodes and establish deployment hypothesis relationships between deployment hypothesis nodes and graph entities. The deployment hypothesis nodes and deployment hypothesis relationships are then written back to the limited attribute security knowledge graph to generate the deployment write-back knowledge graph. The knowledge graph of deployment is input into the write-back iteration layer to update and generate a security deployment plan for large-scale urban events.

[0007] Optionally, the extraction and construction of the security basic dataset includes: Collect security data for large-scale urban events, including event area data, passage data, police force data, time period data, risk event data, and traffic status data. Organize the data according to a unified recording format, which includes node identifiers, relationship identifiers, time identifiers, status identifiers, location identifiers, and resource identifiers. Based on the activity area data, extract the activity area node data and the area association data; Based on the channel data, extract the channel node data and channel connection data; Based on police force data, extract police force node data, resource information, personnel information, and police force configuration data; Based on time period data, extract time period information; based on risk event data, extract risk information and risk correlation data; based on traffic status data, extract traffic information. Spatial information is extracted based on activity area data and channel data; The data formats of activity area node data, channel node data, police force node data, time period information, risk information, passage information, spatial information, resource information, personnel information, regional association data, channel connection data, police force configuration data, and risk association data are processed in a unified manner. The data that has undergone unified format processing is collected into node datasets, attribute datasets, and relation datasets to construct a basic security dataset.

[0008] Optionally, the generation of the limited attribute security knowledge graph includes: Based on the security basic dataset, activity area node data, passage node data, and police force node data are written into the knowledge graph node table to construct graph entities; Regional association data, channel connection data, police force configuration data, and risk association data are written into the knowledge graph relationship table to construct the graph relationship; Based on time period information, risk information, access information, spatial information, resource information, and personnel information, relationship limiting fields are extracted respectively, and limiting attribute slots are constructed according to the time period limiting field, risk limiting field, access limiting field, spatial limiting field, resource limiting field, and personnel limiting field. The limiting attribute slots are then attached to the graph relationship. For each graph relationship, after the attribute slots are attached, the content inside the graph relationship is sorted according to a fixed field order; Establish a graph relation index, and simultaneously establish the connection relationship between graph relations and graph entities; The graph relationships and graph entities, after being hooked to the specified attribute slots and indexed, are jointly written into the knowledge graph storage structure to generate a specified attribute security knowledge graph.

[0009] Optionally, the construction of the three-domain write-back StarE model includes: The original structures based on the StarE model include entity embedding structure, relation embedding structure, constraint combination structure, and graph propagation structure; Initialize the entity embedding structure based on the graph entity, initialize the relationship embedding structure based on the graph relationship, and initialize the constraint combination structure based on the constraint attribute slot; Based on the constraint combination structure of the original StarE model, a constraint slot encoding layer is constructed to replace the single constraint input method in the constraint combination structure with the constraint attribute slot input method. Based on the relation embedding structure and the constraint combination structure, a composite relation generation layer is constructed, which retains the independent input connections of the graph relations and constructs the encoding results output by the constraint slot encoding layer as parallel constraint input connections; Based on the graph propagation structure, a three-domain coupled propagation layer is constructed. The unified propagation connection method in the graph propagation structure is decomposed into the activity area node data input end, the channel node data input end, the police force node data input end, and the composite constraint relationship representation input end. Cross-domain propagation connection is established, and the output of the composite relationship generation layer is connected to the cross-domain propagation connection. Based on the output of the three-domain coupled propagation layer, a deployment hypothesis generation layer is constructed, and a deployment hypothesis node construction structure and a deployment hypothesis relationship construction structure are constructed. Based on a security knowledge graph with limited attributes, a write-back iteration layer is constructed, and graph input structure, slot recoding structure, relation reconstruction structure, propagation recalculation structure, relation update structure and stability determination structure are set. A three-domain write-back StarE model is constructed based on a limited slot coding layer, a composite relationship generation layer, a three-domain coupled propagation layer, a deployment hypothesis generation layer, and a write-back iteration layer.

[0010] Optionally, the generation of the composite constraint relation representation includes: Based on the security knowledge graph of limited attributes, each limited field is read from the limited attribute slot and sequentially connected to the limited slot encoding layer; Within the defined slot encoding layer, each defined field is independently encoded and represented as a slot. Based on the representation of each slot, they are arranged in a fixed order to generate a combined slot representation; The composite relation generation layer accepts both graph relations and combined slot representations. According to the connection order of the graph relationship and the combined slot representation, joint mapping processing is performed, combined encoding is performed, and a composite constraint relationship representation is generated.

[0011] Optionally, the generation of the three-domain joint situational representation includes: Connect the activity area node data to the activity area node data input terminal, connect the channel node data to the channel node data input terminal, connect the police force node data to the police force node data input terminal, and connect the composite constraint relationship representation to the composite constraint relationship representation input terminal. Within the three-domain coupled propagation layer, internal propagation of the active region node data is performed based on the active region node data to generate the active region propagation result. Based on the channel node data, perform internal propagation of the channel node data to generate the channel propagation result; Based on the police force node data, internal propagation of the police force node data is performed to generate police force propagation results; Based on the composite constraint relationship representation, cross-domain correlation propagation from region to channel is performed between the propagation results of the activity area and the propagation results of the channel; cross-domain correlation propagation from channel to police force is performed between the propagation results of the channel and the propagation results of the police force; and cross-domain correlation propagation from region to police force is performed between the propagation results of the activity area and the propagation results of the police force, thereby generating cross-domain propagation results. Based on the propagation results from the activity area, channels, police force, and cross-domain propagation, joint mapping processing is performed to generate a joint situational awareness representation across the three domains.

[0012] Optionally, the generation of the deployment write-back knowledge graph includes: The three-domain joint situational representation is input into the deployment hypothesis generation layer to construct deployment hypothesis nodes, including deployment hypothesis node identifier, activity area node identifier, passage node identifier, police force node identifier, and time period limitation field; Based on the deployment assumption nodes, deployment assumption relationships are established between deployment assumption nodes and activity area node data, between deployment assumption nodes and channel node data, and between deployment assumption nodes and police force node data. Based on the three-domain joint situational awareness, the deployment hypothesis relationships are screened, and the deployment hypothesis relationships that form a complete association with the activity area node data, channel node data, and police force node data are identified as write-back relationships. The deployment hypothesis nodes are written into the limited attribute security knowledge graph as new graph entities, and the write-back relationship is written into the limited attribute security knowledge graph as a new graph relationship. When a graph entity corresponding to a deployment hypothesis node identifier already exists in the limited attribute security knowledge graph, the graph entity is updated; when a graph relationship corresponding to a relationship identifier already exists in the limited attribute security knowledge graph, the graph relationship is updated. Based on the security knowledge graph with defined attributes after writing and updating, a defense write-back knowledge graph is generated.

[0013] Optionally, the generated urban large-scale event security deployment plan includes: The knowledge graph of deployment is input into the graph input structure in the write-back iteration layer, and the graph relationships, limited attribute slots, activity area node data, channel node data, police force node data and deployment hypothesis relationship set are read. Input the graph relationship and the limited attribute slots into the slot re-encoding structure, re-execute the limited attribute slot encoding, and obtain the combined slot representation corresponding to the current round; The graph relationship and the combined slot representation corresponding to the current round are used to reconstruct the structure of the input relationship, and the composite constraint relationship generation is performed again to obtain the composite constraint relationship representation corresponding to the current round. The activity area node data, channel node data, police force node data, and the composite constraint relationship corresponding to the current round are input into the propagation recalculation structure, and cross-domain correlation propagation is re-executed to obtain the three-domain joint situation representation corresponding to the current round. Input the three-domain joint situational representation corresponding to the current round into the relation update structure, re-execute the deployment hypothesis relation update, obtain the deployment hypothesis relation set corresponding to the current round, and write it into the deployment writeback knowledge graph; Input the set of deployment assumptions corresponding to the current round into the stability determination structure to determine the change in the set of deployment assumptions; When the change in the set of deployment assumptions is lower than a preset threshold, the deployment assumptions are determined to have reached a stable state. Based on the set of deployment assumptions that have reached a stable state, the corresponding activity area node identifiers, passage node identifiers, police force node identifiers, and time period limitation fields are extracted to generate a security deployment plan for large-scale urban events.

[0014] The beneficial effects of this invention are: First, this invention constructs a security knowledge graph with defined attributes based on a basic security dataset, and attaches the defined attribute slots to the graph relationships. It integrates time period information, risk information, passage information, spatial information, resource information, and personnel information into the graph relationship expression process. Compared with the existing technology that processes activity areas, passages, police force, and risk events separately, this invention can express the constraint relationships and temporal relationships between activity area node data, passage node data, and police force node data under the same relational structure, thereby improving the integrity and relevance of security data organization and providing a stable data foundation for the subsequent generation of composite defined relation representations.

[0015] Secondly, this invention, based on the constrained slot encoding layer, composite relationship generation layer, and three-domain coupling propagation layer in the three-domain write-back StarE model, jointly processes activity area node data, channel node data, and police force node data, and performs cross-domain correlation propagation based on composite constrained relationship representation. This enables the formation of a three-domain joint situational awareness representation among activity area node data, channel node data, and police force node data. Compared to existing technologies that primarily rely on single risk analysis or static relationship completion, this invention can simultaneously characterize the linkage relationships between activity areas, channels, and police forces, enhancing the ability to depict cross-domain correlations during security deployment and improving the overall synergy in the generation of security deployment plans for large-scale urban events.

[0016] Furthermore, this invention, through a deployment hypothesis generation layer and a write-back iteration layer, writes deployment hypothesis nodes and relationships back to a defined attribute security knowledge graph. Based on this knowledge graph, it re-executes defined attribute slot encoding, composite defined relation generation, cross-domain association propagation, and deployment hypothesis relationship updates until the relationships reach a stable state. Compared to existing technologies that output deployment results only once, this invention establishes a continuous update mechanism based on the deployment write-back knowledge graph, thereby improving the consistency between the security deployment plan for large-scale urban events and the actual event conditions, and enhancing the dynamic adjustment and closed-loop generation capabilities of the deployment results. Attached Figure Description

[0017] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is an overall flowchart of a knowledge graph-based security deployment method for large-scale urban events proposed in this invention. Figure 2 This is a schematic diagram illustrating the construction structure of the attribute-based security knowledge graph in this invention; Figure 3 This is a schematic diagram of the structure and deployment write-back iteration process of the three-domain write-back StarE model in this invention. Detailed Implementation

[0018] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.

[0019] refer to Figures 1-3 A knowledge graph-based security deployment method for large-scale urban events includes the following steps: Security data for large-scale urban events is collected, including event area data, access route data, police force data, time period data, risk event data, and traffic status data. Based on the event area data, event area node data and regional correlation data are extracted; based on the access route data, access route node data and access route connection data are extracted; based on the police force data, police force node data, resource information, personnel information, and police force configuration data are extracted; based on the time period data, time period information is extracted; based on the risk event data, risk information and risk correlation data are extracted; based on the traffic status data, traffic information is extracted; and based on the event area data and access route data, spatial information is extracted. These data, along with the event area node data, access route node data, police force node data, time period information, risk information, traffic information, spatial information, resource information, personnel information, regional correlation data, access route connection data, police force configuration data, and risk correlation data, are then used to construct a basic security dataset. Based on the security basic dataset, the activity area node data, passage node data, and police force node data are constructed into graph entities, the area association data, passage connection data, police force configuration data, and risk association data are constructed into graph relationships, and the time period information, risk information, passage information, spatial information, resource information, and personnel information are constructed into limited attribute slots. The limited attribute slots are then attached to the graph relationships to generate a limited attribute security knowledge graph. Based on the security knowledge graph with limited attributes, a three-domain write-back StarE model is constructed. The three-domain write-back StarE model includes a limited slot encoding layer, a composite relationship generation layer, a three-domain coupling propagation layer, a deployment hypothesis generation layer, and a write-back iteration layer. Based on the security knowledge graph with limited attributes, the limited attribute slots are input into the limited slot encoding layer for slot-by-slot encoding to generate a combined slot representation. In the composite relation generation layer, the graph relations and the combined slot representation are jointly mapped to generate a composite limited relation representation. The activity area node data, channel node data, and police force node data are input into the three-domain coupled propagation layer. Based on the composite constraint relationship representation, cross-domain correlation propagation is performed between the activity area node data, channel node data, and police force node data to generate a three-domain joint situational representation. Based on the three-domain joint situational representation, the three-domain joint situational representation is input into the deployment hypothesis generation layer to construct deployment hypothesis nodes, and establish deployment hypothesis relationships between deployment hypothesis nodes and activity area node data, channel node data, and police force node data. The deployment hypothesis nodes and deployment hypothesis relationships are written back to the limited attribute security knowledge graph to generate the deployment write-back knowledge graph. Based on the knowledge graph of deployment writeback, the knowledge graph of deployment writeback is input into the writeback iteration layer, and the limited attribute slot encoding, composite limited relation generation, cross-domain association propagation and deployment hypothesis relation update are re-executed until the deployment hypothesis relation reaches a stable state, thereby generating a security deployment plan for large-scale urban events.

[0020] In this embodiment, extracting and constructing the security basic dataset includes: The data collected includes security information for large-scale urban events, encompassing event area data, access route data, police force data, time period data, risk event data, and traffic status data. This data is organized according to a unified recording format, which includes node identifiers, relationship identifiers, time identifiers, status identifiers, location identifiers, and resource identifiers. Specifically, event area data records event area node identifiers, event area type, event area location, event area capacity, event area boundaries, and adjacent relationships. Access route data records access route node identifiers, access route type, access route location, access route direction, access route capacity, and access route endpoints. Police force data records police force node identifiers, police force unit type, number of police officers, police force deployment locations, police force equipment configuration, and police force duty status. Time period data records time identifiers, event phase markers, start time, and end time. Risk event data records risk event identifiers, risk event type, risk event location, risk event occurrence time, and risk event level. Traffic status data records traffic status identifiers, access route node identifiers, event area node identifiers, crowd density, traffic speed, and congestion status. Based on the activity area data, activity area node data and area association data are extracted. The activity area node data consists of activity area node identifier, activity area type, activity area location, and activity area capacity. The area association data is obtained by mapping the activity area location, activity area boundary, and activity area adjacency relationship in the activity area data. The area association data adopts a structured record format of relationship identifier, source activity area node identifier, target activity area node identifier, and association category. Based on the channel data, channel node data and channel connection data are extracted. The channel node data consists of channel node identifier, channel type, channel location, channel direction, and channel throughput. The channel connection data is obtained by mapping the channel location, channel direction, and channel endpoints from the channel data. The channel connection data adopts a structured record format with relation identifier, source channel node identifier, target channel node identifier, and connection category. Based on police force data, police force node data, resource information, personnel information, and police force configuration data are extracted. Police force node data consists of police force node identifiers, police force unit categories, and police force station locations. Resource information is mapped from police force equipment configuration in the police force data, using a structured record format of resource identifier, police force node identifier, resource category, and resource quantity. Personnel information is mapped from the number of police officers, police force unit categories, and police duty status in the police force data, using a structured record format of police force node identifier, personnel category, personnel quantity, and duty status. Police force configuration data is mapped from police force station locations, activity area locations, and passageway locations, using a structured record format of relationship identifier, police force node identifier, activity area node identifier, passageway node identifier, and configuration category. Based on time period data, time period information is extracted; based on risk event data, risk information and risk-related data are extracted; based on traffic status data, traffic information is extracted. Specifically, time period information uses a structured record format with time identifier, activity phase marker, start time, and end time; risk information uses a structured record format with risk event identifier, risk event type, risk event location, risk event occurrence time, and risk event level; risk-related data is obtained by mapping risk event location, activity area location, and channel location, and uses a structured record format with relationship identifier, risk event identifier, activity area node identifier, channel node identifier, and association category; and traffic information uses a structured record format with traffic status identifier, channel node identifier, activity area node identifier, pedestrian density, traffic speed, and congestion status. Based on activity area data and channel data, spatial information is extracted. The spatial information is obtained by mapping the location of the activity area, the boundary of the activity area, the location of the channel, the direction of the channel, and the endpoints of the channel. The spatial information adopts a structured record format of location identifier, activity area node identifier, channel node identifier, spatial distance, spatial orientation, and connectivity status. For activity area node data, channel node data, police force node data, time period information, risk information, passage information, spatial information, resource information, personnel information, area association data, channel connection data, police force configuration data, and risk association data, perform unified data format processing. Node identifiers are unified to node primary key format, relationship identifiers are unified to relationship primary key format, time identifiers are unified to time series format, status identifiers are unified to status enumeration format, location identifiers are unified to coordinate index format, and resource identifiers are unified to resource classification code format. Missing fields are filled with null values, duplicate records are deduplicated, and conflicting records are checked for consistency. The activity area node data, channel node data, police force node data, time period information, risk information, passage information, spatial information, resource information, personnel information, regional association data, channel connection data, police force configuration data, and risk association data, which have been processed in a unified data format, are collected according to node datasets, attribute datasets, and relationship datasets to construct a basic security dataset.

[0021] In this embodiment, generating a security knowledge graph with defined attributes includes: Based on the security basic dataset, the activity area node data, channel node data, and police force node data are written into the knowledge graph node table according to the field contents corresponding to node identifier, node category, node location, and node status, respectively, to construct graph entities. Among them, the activity area node data corresponds to the activity area graph entity, the channel node data corresponds to the channel graph entity, and the police force node data corresponds to the police force graph entity. Based on the security basic dataset, regional association data, channel connection data, police force configuration data, and risk association data are written into the knowledge graph relationship table according to the fields corresponding to the relationship identifier, source node identifier, target node identifier, and relationship category, respectively, to construct the graph relationship. Among them, regional association data is used to construct the graph relationship between entities in the activity area graph, channel connection data is used to construct the graph relationship between entities in the channel graph, police force configuration data is used to construct the graph relationship between police force graph entities and entities in the activity area graph and channel graph, and risk association data is used to construct the graph relationship between nodes corresponding to risk events and entities in the activity area graph and channel graph. Based on time period information, risk information, access information, spatial information, resource information, and personnel information, relationship limiting fields are extracted respectively, and limiting attribute slots are constructed according to time period limiting fields, risk limiting fields, access limiting fields, spatial limiting fields, resource limiting fields, and personnel limiting fields. Among them, time period information is mapped to time period limiting fields, risk information is mapped to risk limiting fields, access information is mapped to access limiting fields, spatial information is mapped to spatial limiting fields, resource information is mapped to resource limiting fields, and personnel information is mapped to personnel limiting fields. The limited attribute slots are attached to the graph relationship in a fixed order: time period limited field, risk limited field, access limited field, space limited field, resource limited field, and personnel limited field. The limited attribute slots are attached inside the graph relationship record, not inside the graph entity record. For each graph relationship, after the limited attribute slots are attached, the internal content of the graph relationship is sorted according to a fixed field order: relationship identifier, source node identifier, target node identifier, relationship category, time period limited field, risk limited field, access limited field, space limited field, resource limited field, and personnel limited field. A graph relationship index is established based on the relationship identifier. The connection relationship between the graph relationship and the graph entity is established based on the source node identifier and the target node identifier. The time period restriction field, risk restriction field, access restriction field, space restriction field, resource restriction field, and personnel restriction field in the graph relationship are read in a fixed field order. The time period restriction field, risk restriction field, access restriction field, space restriction field, resource restriction field, and personnel restriction field are used as internal restriction content of the graph relationship in the graph relationship reading process. The graph relationships, after being hooked to the specified attribute slots and indexed, are jointly written into the knowledge graph storage structure with the graph entities to generate a security knowledge graph with specified attributes. The time period restriction field, risk restriction field, access restriction field, space restriction field, resource restriction field, and personnel restriction field in the graph relationship serve as the direct input content for the subsequent composite relationship generation layer.

[0022] In this embodiment, constructing the three-domain write-back StarE model includes: Based on the original structure of the StarE model, the StarE model adopts a hyper-relational knowledge graph encoding structure. The StarE model includes an entity embedding structure, a relation embedding structure, a constraint combination structure, and a graph propagation structure. The entity embedding structure corresponds to the embedding construction content of graph entities, the relation embedding structure corresponds to the embedding construction content of graph relations, the constraint combination structure corresponds to the constraint encoding and combination content in graph relations, and the graph propagation structure corresponds to the message propagation connection content between graph entities and graph relations. Initialize the entity embedding structure based on the graph entity, initialize the relationship embedding structure based on the graph relationship, and initialize the constraint combination structure based on the constraint attribute slot; Based on the constraint combination structure of the original StarE model, a constraint slot coding layer is constructed. The single constraint input method in the constraint combination structure is replaced with the constraint attribute slot input method. The time period constraint field, risk constraint field, access constraint field, space constraint field, resource constraint field, and personnel constraint field are respectively connected to the constraint slot coding layer. Within the constraint slot coding layer, a sub-slot coding structure is constructed according to the time period constraint field coding channel, risk constraint field coding channel, access constraint field coding channel, space constraint field coding channel, resource constraint field coding channel, and personnel constraint field coding channel. The output of each constraint field coding channel is connected to the input of the composite relationship generation layer. Based on the relation embedding structure and the constraint combination structure, a composite relation generation layer is constructed. In the composite relation generation layer, the independent input connections of the graph relations are retained. The encoding results of each constraint field output by the constraint slot encoding layer are constructed as parallel constraint input connections. In the composite relation generation layer, according to the connection structure of graph relation input end, time period constraint field input end, risk constraint field input end, access constraint field input end, space constraint field input end, resource constraint field input end, and personnel constraint field input end, the graph relations and the encoding results of each constraint field are combined and processed. The output end of the composite relation generation layer is connected to the input end of the three-domain coupling propagation layer. Within the limited slot coding layer, the output results of the time-limited field coding channel, risk-limited field coding channel, access-limited field coding channel, space-limited field coding channel, resource-limited field coding channel, and personnel-limited field coding channel are respectively connected to the time-limited field input terminal, risk-limited field input terminal, access-limited field input terminal, space-limited field input terminal, resource-limited field input terminal, and personnel-limited field input terminal of the composite relationship generation layer. Within the composite relationship generation layer, the graph relationship input terminal is synchronously connected to each limited field input terminal. Based on the graph propagation structure, a three-domain coupled propagation layer is constructed. The unified propagation connection method in the graph propagation structure is decomposed into the input end of activity area node data, channel node data, police force node data, and composite constraint relation representation. Within the three-domain coupled propagation layer, cross-domain propagation connections are established between activity area node data and channel node data, between channel node data and police force node data, and between activity area node data and police force node data. The output of the composite relation generation layer is used as the composite constraint relation representation and connected to each cross-domain propagation connection. The output of the three-domain coupled propagation layer is connected to the input end of the deployment hypothesis generation layer. Based on the output of the three-domain coupled propagation layer, a deployment hypothesis generation layer is constructed. Within the deployment hypothesis generation layer, a deployment hypothesis node construction structure and a deployment hypothesis relationship construction structure are constructed. The output of the three-domain coupled propagation layer is connected to the input of the deployment hypothesis node construction structure, the output of the deployment hypothesis node construction structure is connected to the input of the deployment hypothesis relationship construction structure, and the output of the deployment hypothesis relationship construction structure is connected to the input of the write-back iteration layer. Based on a security knowledge graph with limited attributes, a write-back iteration layer is constructed. Within the write-back iteration layer, a graph input structure, a slot recoding structure, a relation reconstruction structure, a propagation recalculation structure, a relation update structure, and a stability determination structure are set. The graph input structure is configured to receive the deployment write-back knowledge graph. The slot recoding structure is connected to the limited slot encoding layer, the relation reconstruction structure is connected to the composite relation generation layer, the propagation recalculation structure is connected to the three-domain coupled propagation layer, the relation update structure is connected to the deployment hypothesis generation layer, and the stability determination structure is connected to the output of the relation update structure. Based on the limited slot coding layer, composite relationship generation layer, three-domain coupling propagation layer, deployment hypothesis generation layer, and writeback iteration layer, the three-domain writeback StarE model is constructed by assembling the layers in the following order: from the limited slot coding layer to the composite relationship generation layer, from the composite relationship generation layer to the three-domain coupling propagation layer, from the three-domain coupling propagation layer to the deployment hypothesis generation layer, from the deployment hypothesis generation layer to the writeback iteration layer, and from the writeback iteration layer to the limited slot coding layer. The training data for the three-domain write-back StarE model comes from historical security data of large-scale events, including historical event area data, historical passage data, historical police force data, historical time period data, historical risk event data, historical passage status data, and historical deployment result data. The model training input data is generated according to the construction method of the security basic dataset and the construction method of the limited attribute security knowledge graph. Among them, the historical deployment result data serves as the supervision label for deployment hypothesis nodes and deployment hypothesis relationships. During training, the graph relationships and limited attribute slots are input into the limited slot encoding layer and the composite relationship generation layer. The activity area node data, channel node data, and police force node data are input into the three-domain coupled propagation layer. The deployment hypothesis generation layer outputs deployment hypothesis nodes and deployment hypothesis relationships. Then, the deployment hypothesis nodes and deployment hypothesis relationships are written back to the limited attribute security knowledge graph. The limited slot encoding, composite relationship generation, cross-domain propagation, and deployment hypothesis relationship update are re-executed through the write-back iteration layer. The loss function is constructed using a public supervised learning training method, including composite relation loss, three-domain propagation loss, and deployment relation loss. The composite relation loss is used to constrain the output of the composite relation generation layer, the three-domain propagation loss is used to constrain the output of the three-domain coupled propagation layer, and the deployment relation loss is used to constrain the output of the deployment hypothesis generation layer. The composite relation loss, three-domain propagation loss, and deployment relation loss are weighted and summed to obtain the total loss value, and the parameters of the limited slot coding layer, composite relation generation layer, three-domain coupled propagation layer, and deployment hypothesis generation layer are updated based on the total loss value. The model training uses the publicly available backpropagation method for parameter updates, and the Adam optimization algorithm is used during the parameter update process. When the change in the deployment hypothesis relationship is lower than the preset threshold in two consecutive write-back iterations, the write-back iteration layer is determined to have reached a stable state. When the total loss value on the validation data converges, the training of the three-domain write-back StarE model is completed.

[0023] In this embodiment, generating a composite constraint relation representation includes: Based on the security knowledge graph with defined attributes, the time-limited field, risk-limited field, access-limited field, space-limited field, resource-limited field, and personnel-limited field are read from the defined attribute slots respectively, and connected to the defined slot encoding layer in a fixed field order of time-limited field, risk-limited field, access-limited field, space-limited field, resource-limited field, and personnel-limited field. Specifically, the time-limited field is connected to the time-limited field encoding channel, the risk-limited field is connected to the risk-limited field encoding channel, the access-limited field is connected to the access-limited field encoding channel, the space-limited field is connected to the space-limited field encoding channel, the resource-limited field is connected to the resource-limited field encoding channel, and the personnel-limited field is connected to the personnel-limited field encoding channel. Within the defined slot coding layer, independent coding processes are performed on the time-limited field, risk-limited field, access-limited field, space-limited field, resource-limited field, and personnel-limited field. The time-limited field is encoded as a time-limited slot representation, the risk-limited field is encoded as a risk-limited slot representation, the access-limited field is encoded as a access-limited slot representation, the space-limited field is encoded as a space-limited slot representation, the resource-limited field is encoded as a resource-limited slot representation, and the personnel-limited field is encoded as a personnel-limited slot representation. Each slot representation adopts a unified dimensional coding format. Based on the time slot representation, risk slot representation, access slot representation, space slot representation, resource slot representation, and personnel slot representation, the slots are arranged in a fixed order to generate a combined slot representation, and the combined slot representation is output to the composite relationship generation layer. When there is a missing field in the limited attribute slot, a preset empty slot mark is written into the corresponding encoding channel, and the preset empty slot mark is encoded into a placeholder representation with the same dimension as the other slot representations. The placeholder representation is then written into the corresponding position in the slot representation. In the composite relationship generation layer, the graph relationship is connected to the graph relationship input terminal, and the combined slot representation is connected to the time-limited field input terminal, risk-limited field input terminal, access-limited field input terminal, space-limited field input terminal, resource-limited field input terminal, and personnel-limited field input terminal respectively in the corresponding order of time slot representation, risk slot representation, access-limited field representation, space-limited field input terminal, resource-limited field input terminal, and personnel-limited field input terminal; In the composite relationship generation layer, joint mapping processing is performed according to the connection order of the graph relationship and the combined slot representation. The relationship category content in the graph relationship is combined and encoded with the time slot representation, risk slot representation, access slot representation, space slot representation, resource slot representation, and personnel slot representation in the slot representation to generate a composite limited relationship representation. The composite limited relationship representation adopts a unified dimension output format and is output to the three-domain coupling propagation layer.

[0024] In this embodiment, generating a three-domain joint situational awareness representation includes: Connect the activity area node data to the activity area node data input terminal, connect the channel node data to the channel node data input terminal, connect the police force node data to the police force node data input terminal, and connect the composite constraint relationship representation to the composite constraint relationship representation input terminal. Within the three-domain coupled propagation layer, the internal propagation of the active region node data is performed based on the active region node data to generate the active region propagation result. The internal propagation of the active region node data unfolds along the graph relationship corresponding to the region association data. Within the three-domain coupled propagation layer, internal propagation of channel node data is performed based on channel node data to generate channel propagation results. The internal propagation of channel node data unfolds along the graph relationship corresponding to the channel connection data. Within the three-domain coupled propagation layer, internal propagation of police node data is performed based on police node data to generate police propagation results. The internal propagation of police node data unfolds along the graph relationship corresponding to the police configuration data. Based on the composite constraint relation representation, cross-domain association propagation from region to channel is performed between the propagation results of the activity area and the propagation results of the channel; cross-domain association propagation from channel to police force is performed between the propagation results of the channel and the propagation results of the police force; and cross-domain association propagation from region to police force is performed between the propagation results of the activity area and the propagation results of the police force, generating cross-domain propagation results. The composite constraint relation representation serves as the association constraint input content for each cross-domain association propagation. Based on the propagation results of the activity area, the channel, the police force, and the cross-domain propagation, joint mapping processing is performed at the output of the three-domain coupled propagation layer to generate a three-domain joint situational representation. The three-domain joint situational representation adopts a unified dimension output format and includes the correlation results between the activity area node data, the channel node data, and the police force node data. The three-domain joint situational representation is then output to the deployment hypothesis generation layer.

[0025] In this embodiment, generating the deployment write-back knowledge graph includes: The three-domain joint situational awareness representation is input into the deployment hypothesis generation layer. Within the deployment hypothesis generation layer, the correlation results between the activity area node data, channel node data, and police force node data in the three-domain joint situational awareness representation are extracted. Based on the correlation results, deployment hypothesis nodes are constructed. The deployment hypothesis nodes include a deployment hypothesis node identifier, an activity area node identifier, a channel node identifier, a police force node identifier, and a time period limitation field. The deployment hypothesis node identifier is used to mark the current deployment hypothesis node. The activity area node identifier, channel node identifier, and police force node identifier are used to mark the activity area node data, channel node data, and police force node data corresponding to the current deployment hypothesis node, respectively. The time period limitation field is used to mark the deployment time content corresponding to the current deployment hypothesis node. Specifically, the deployment hypothesis identifier is constructed by reading the correlation results between the activity area node data, channel node data, and police force node data in the three-domain joint situational awareness representation one by one, extracting the activity area node identifier, channel node identifier, police force node identifier, and time period limitation field, and combining them according to a fixed field order to generate the deployment hypothesis node identifier. Based on the deployment hypothesis nodes, deployment hypothesis relationships are established between deployment hypothesis nodes and activity area node data, between deployment hypothesis nodes and channel node data, and between deployment hypothesis nodes and police force node data. Each deployment hypothesis relationship includes a relationship identifier, a source node identifier, a target node identifier, and a relationship category. Based on the three-domain joint situational awareness, the deployment hypothesis relationships are screened. Deployment hypothesis relationships that form a complete association with the activity area node data, channel node data, and police force node data are identified as write-back relationships. Deployment hypothesis relationships that do not form a complete association are removed from the deployment hypothesis relationships. The deployment hypothesis node is written into the limited attribute security knowledge graph as a new graph entity, and the write-back relationship is written into the limited attribute security knowledge graph as a new graph relationship. The time period limitation field is attached to the write-back relationship. When a graph entity corresponding to the deployment hypothesis node identifier already exists in the limited attribute security knowledge graph, the activity area node identifier, channel node identifier, police force node identifier, and time period limitation field in the existing graph entity are updated. When a graph relationship corresponding to the relationship identifier already exists in the limited attribute security knowledge graph, the source node identifier, target node identifier, relationship category, and time period limitation field in the existing graph relationship are updated. Based on the security knowledge graph with defined attributes after writing and updating, a defense write-back knowledge graph is generated.

[0026] In this embodiment, generating a security deployment plan for large-scale urban events includes: The knowledge graph of deployment writeback is input into the graph input structure in the writeback iteration layer, and the graph relationships, limited attribute slots, activity area node data, channel node data, police force node data and deployment hypothesis relationship set in the knowledge graph of deployment writeback are read; Input the graph relationship and the limited attribute slots into the slot recoding structure, and re-execute the limited attribute slot encoding through the limited slot encoding layer to obtain the combined slot representation corresponding to the current round; The graph relationship and the combined slot representation corresponding to the current round are used to reconstruct the structure of the input relationship, and the composite constraint relationship generation is re-executed through the composite relationship generation layer to obtain the composite constraint relationship representation corresponding to the current round. The composite constraint relationship representation corresponding to the current round is input into the propagation recalculation structure, which is composed of activity area node data, channel node data, police force node data, and the current round. Cross-domain correlation propagation is then re-executed through the three-domain coupled propagation layer to obtain the three-domain joint situation representation corresponding to the current round. The three-domain joint situational representation corresponding to the current round is input into the relation update structure, and the deployment hypothesis relation update is re-executed through the deployment hypothesis generation layer to obtain the deployment hypothesis relation set corresponding to the current round. The deployment hypothesis relation set corresponding to the current round is then written into the deployment writeback knowledge graph. Input the set of deployment assumptions corresponding to the current round into the stability determination structure, and compare the set of deployment assumptions corresponding to the current round with the set of deployment assumptions corresponding to the previous round to determine the change in the set of deployment assumptions. When the change in the set of deployment assumptions is lower than the preset threshold, the deployment assumptions are determined to have reached a stable state. When the change in the set of deployment assumptions is not lower than the preset threshold and the current round is less than the preset maximum number of iterations, the deployment write-back knowledge graph written after the deployment assumptions set corresponding to the current round is re-input into the graph input structure, and the limited attribute slot encoding, composite limited relation generation, cross-domain association propagation and deployment assumption relation update are continued. Based on the set of deployment assumptions that have reached a stable state, the corresponding activity area node identifiers, passage node identifiers, police force node identifiers, and time period limitation fields are extracted. These are then aggregated according to their correspondence to form deployment association results. Based on these results, the activity area node data corresponding to the activity area node identifier is determined as the deployment area, the passage node data corresponding to the passage node identifier is determined as the deployment passage, the police force node data corresponding to the police force node identifier is determined as the deployment police force, and the time period limitation field is determined as the deployment time period. These fields are then organized in a fixed order according to deployment area, deployment passage, deployment police force, and deployment time period to generate a security deployment plan for large-scale urban events.

[0027] Example 1: To verify the feasibility of this invention in practice, it was applied to a security deployment task for a large-scale urban event. This event included multiple functional areas: a main event area, a buffer event area, a performance area, an entry area, and an evacuation area. Multiple personnel passageways, security checkpoints, emergency exits, and police patrol routes existed on-site. Personnel flow during the event exhibited phased changes, with significant differences in traffic conditions during the entry, event, and departure phases. Security work required simultaneous consideration of the relationships between event area node data, passageway node data, police force node data, time period information, risk information, traffic information, spatial information, resource information, and personnel information, and timely adjustments to the deployment based on changes in the event's status. Existing methods, manual experience-based deployment, are prone to uneven coverage between event areas and passageways; static rule-based deployment methods struggle to reflect changes in traffic conditions in a timely manner; and using ordinary knowledge graph reasoning methods easily overlooks the influence of limited attribute slots on graph relationships, resulting in a lag between deployment results and on-site changes.

[0028] In this embodiment, the collected security data for large-scale urban events includes 18 event areas, 42 passageways, 36 police units, 9 types of risk event records, 216 time period records, and 864 traffic status records. Event area node data, passageway node data, police unit node data, regional association data, passageway connection data, police unit configuration data, and risk association data are extracted to construct a basic security dataset. Subsequently, the event area node data, passageway node data, and police unit node data are constructed as graph entities; the regional association data, passageway connection data, police unit configuration data, and risk association data are constructed as graph relationships; and time period information, risk information, traffic information, spatial information, resource information, and personnel information are constructed as defined attribute slots and attached to the graph relationships to obtain a defined attribute security knowledge graph.

[0029] In the model application process, the limited attribute slots are input into the limited slot encoding layer. Time-limited, risk-limited, access-limited, spatial, resource-limited, and personnel-limited fields are encoded separately to obtain a combined slot representation. In the composite relationship generation layer, the graph relationships are jointly mapped to the combined slot representation to obtain a composite limited relationship representation. Activity area node data, channel node data, and police force node data are then input together with the composite limited relationship representation into the three-domain coupling propagation layer. Cross-domain association propagation is performed between activity area node data and channel node data, between channel node data and police force node data, and between activity area node data and police force node data to obtain a three-domain joint situational awareness representation. Based on the three-domain joint situational awareness representation, deployment hypothesis nodes are constructed in the deployment hypothesis generation layer, and deployment hypothesis relationships are established between these nodes and graph entities. Subsequently, the deployment hypothesis nodes and their relationships are written back to the limited attribute security knowledge graph, forming a deployment write-back knowledge graph. After the write-back iteration layer reads the deployment write-back knowledge graph, it re-executes the limited attribute slot encoding, composite limited relation generation, cross-domain association propagation, and deployment hypothesis relation update. When the change in the deployment hypothesis relation set is lower than the preset threshold for two consecutive rounds, the final security deployment plan for large-scale urban events is output.

[0030] To ensure comparability in the verification process, three methods were compared under the same set of security baseline datasets and the same set of on-site constraints. Method 1 is a traditional deployment method based on rule statistics, which statically allocates resources according to the activity area capacity, passageway capacity, and number of police officers. Method 2 is a deployment method based on static knowledge graph reasoning, which uses graph entities and graph relationships for one-time reasoning without introducing limited attribute slot attachment or deployment write-back iteration. Method 3 is the method of this invention, which uses a limited attribute security knowledge graph and a three-domain write-back StarE model to generate deployment schemes. To reflect the actual application effect, the deployment coverage rate, passageway congestion identification accuracy, police officer configuration matching rate, number of cross-domain conflicts, scheme generation time, deployment relationship stability error, event response lag time, and scheme adjustment range after iteration were statistically analyzed. The results are shown in the table below.

[0031] Table 1. Comparison of Comprehensive Performance of Security Deployment Methods for Large-Scale Urban Events

[0032] As can be seen from Table 1, the traditional deployment method based on rule statistics is relatively weak in terms of deployment coverage of activity areas, police force matching rate, and number of cross-domain conflicts. The main reason is that this method only makes static deployments based on the capacity of the activity area and the number of police officers, without incorporating the dynamic relationship between the activity area, channels, and police officers into a unified expression process. As a result, although the deployment of the activity area can meet the basic coverage requirements, the configuration relationship between police officers and channels is prone to deviation after changes in channel congestion and the occurrence of risk events. Therefore, the event response lag time reaches 6.5 minutes, the number of mismatches in key areas reaches 9, and the number of missed warnings of channel overload reaches 7.

[0033] The deployment method based on static knowledge graph reasoning outperforms traditional methods in most metrics, indicating that unifying the organization of activity area node data, channel node data, police force node data, and graph relationships can improve the original static manual allocation problem. This method increases the activity area deployment coverage to 88.9%, reduces the number of cross-domain conflicts to 10, and shortens the plan generation time to 11.6 minutes. However, this method does not attach limiting attribute slots to graph relationships, nor does it form a deployment write-back knowledge graph iterative update process. Therefore, when facing scenarios with continuously changing time period information, traffic information, and risk information, the limiting conditions in the graph relationships cannot directly participate in the generation of composite relationships, resulting in a deployment relationship stability error of 6.1%. The number of police force units still needs to be adjusted twice, requiring 8 groups, indicating that there is still a certain deviation between the deployment results and on-site changes.

[0034] The method of this invention exhibits more stable results across various indicators. The deployment coverage rate of the activity area reaches 92.7%, an improvement of 3.8 percentage points compared to deployment methods based on static knowledge graph reasoning. The police force allocation matching rate improves by 3.9 percentage points, the number of cross-domain conflicts decreases from 10 to 5, the scheme generation time is shortened from 11.6 minutes to 8.7 minutes, the deployment relationship stability error decreases from 6.1% to 3.9%, and the event response lag time decreases from 5.2 minutes to 4.3 minutes. These results demonstrate that this invention does not simply improve a single local indicator, but rather achieves synergistic improvements in three aspects: association expression, cross-domain propagation, and iterative updates. After the defined attribute slots are attached to the graph relationships, time period information, risk information, passage information, spatial information, resource information, and personnel information can directly participate in the generation of composite defined relationship representations. Therefore, the relationship status of the same activity area and the same passage under different deployment time periods can be distinguished more finely. The three-domain coupled propagation layer processes activity area node data, channel node data, and police force node data within a unified propagation framework. This reduces the bias caused by independent calculations of activity area deployment and channel deployment, resulting in a significant decrease in the number of cross-domain conflicts and mismatches in key areas. After the deployment hypothesis nodes and deployment hypothesis relationships are written back to the constrained attribute security knowledge graph, the write-back iteration layer can continue to update the deployment relationships. Therefore, the number of police force units for secondary adjustments is reduced from 8 to 5, indicating a higher degree of fit between the final plan and the actual situation, and a lower workload for subsequent manual corrections.

[0035] The above are merely preferred embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. A knowledge graph-based city large-scale event security deployment method, characterized in that, Includes the following steps: Collect security data for large-scale urban events, and extract and construct a basic security dataset; Based on the security basic dataset, we construct graph entities, graph relations and limited attribute slots, and attach the limited attribute slots to the graph relations to generate a limited attribute security knowledge graph; A three-domain write-back StarE model is constructed, including a limited slot encoding layer, a composite relationship generation layer, a three-domain coupling propagation layer, a deployment hypothesis generation layer, and a write-back iteration layer; Based on the security knowledge graph with limited attributes, the limited attribute slots are input into the limited slot encoding layer for slot-by-slot encoding to generate a combined slot representation. In the composite relation generation layer, the graph relations and the combined slot representation are jointly mapped to generate a composite limited relation representation. Input the graph entities into the three-domain coupled propagation layer, and perform cross-domain association propagation between the graph entities based on the composite constraint relationship representation to generate a three-domain joint situational representation. The three-domain joint situational representation is input into the deployment hypothesis generation layer to construct deployment hypothesis nodes and establish deployment hypothesis relationships between deployment hypothesis nodes and graph entities. The deployment hypothesis nodes and deployment hypothesis relationships are then written back to the limited attribute security knowledge graph to generate a deployment write-back knowledge graph. The knowledge graph of deployment is input into the write-back iteration layer to update and generate a security deployment plan for large-scale urban events. 2.The knowledge graph-based city large-scale event security deployment method according to claim 1, characterized in that, The extraction and construction of the security basic dataset includes: Collect security data for large-scale urban events, including event area data, passage data, police force data, time period data, risk event data, and traffic status data. Organize the data according to a unified recording format, which includes node identifiers, relationship identifiers, time identifiers, status identifiers, location identifiers, and resource identifiers. Based on the activity area data, extract the activity area node data and the area association data; Based on the channel data, extract the channel node data and channel connection data; Based on police force data, extract police force node data, resource information, personnel information, and police force configuration data; Based on time period data, extract time period information; based on risk event data, extract risk information and risk correlation data; based on traffic status data, extract traffic information. Spatial information is extracted based on activity area data and channel data; The data formats of activity area node data, channel node data, police force node data, time period information, risk information, passage information, spatial information, resource information, personnel information, regional association data, channel connection data, police force configuration data, and risk association data are processed in a unified manner. The data that has undergone unified format processing is collected into node datasets, attribute datasets, and relation datasets to construct a basic security dataset.

3. The method for security deployment of large-scale urban events based on knowledge graphs according to claim 1, characterized in that, The generation of the limited attribute security knowledge graph includes: Based on the security basic dataset, activity area node data, passage node data, and police force node data are written into the knowledge graph node table to construct graph entities; Regional association data, channel connection data, police force configuration data, and risk association data are written into the knowledge graph relationship table to construct the graph relationship; Based on time period information, risk information, access information, spatial information, resource information, and personnel information, relationship limiting fields are extracted respectively, and limiting attribute slots are constructed according to the time period limiting field, risk limiting field, access limiting field, spatial limiting field, resource limiting field, and personnel limiting field. The limiting attribute slots are then attached to the graph relationship. For each graph relationship, after the attribute slots are attached, the content inside the graph relationship is sorted according to a fixed field order; Establish a graph relation index, and simultaneously establish the connection relationship between graph relations and graph entities; The graph relationships and graph entities, after being hooked to the specified attribute slots and indexed, are jointly written into the knowledge graph storage structure to generate a specified attribute security knowledge graph.

4. The method for security deployment of large-scale urban events based on knowledge graphs according to claim 1, characterized in that, The construction of the three-domain write-back StarE model includes: The original structures based on the StarE model include entity embedding structure, relation embedding structure, constraint combination structure, and graph propagation structure; Initialize the entity embedding structure based on the graph entity, initialize the relationship embedding structure based on the graph relationship, and initialize the constraint combination structure based on the constraint attribute slot; Based on the constraint combination structure of the original StarE model, a constraint slot encoding layer is constructed to replace the single constraint input method in the constraint combination structure with the constraint attribute slot input method. Based on the relation embedding structure and the constraint combination structure, a composite relation generation layer is constructed, which retains the independent input connections of the graph relations and constructs the encoding results output by the constraint slot encoding layer as parallel constraint input connections; Based on the graph propagation structure, a three-domain coupled propagation layer is constructed. The unified propagation connection method in the graph propagation structure is decomposed into the activity area node data input end, the channel node data input end, the police force node data input end, and the composite constraint relationship representation input end. Cross-domain propagation connection is established, and the output of the composite relationship generation layer is connected to the cross-domain propagation connection. Based on the output of the three-domain coupled propagation layer, a deployment hypothesis generation layer is constructed, and a deployment hypothesis node construction structure and a deployment hypothesis relationship construction structure are constructed. Based on a security knowledge graph with limited attributes, a write-back iteration layer is constructed, and graph input structure, slot recoding structure, relation reconstruction structure, propagation recalculation structure, relation update structure and stability determination structure are set. A three-domain write-back StarE model is constructed based on a limited slot coding layer, a composite relationship generation layer, a three-domain coupled propagation layer, a deployment hypothesis generation layer, and a write-back iteration layer.

5. A method for security deployment of large-scale urban events based on knowledge graphs according to claim 1, characterized in that, The generation of composite constraint relation representations includes: Based on the security knowledge graph of limited attributes, each limited field is read from the limited attribute slot and sequentially connected to the limited slot encoding layer; Within the defined slot encoding layer, each defined field is independently encoded and represented as a slot. Based on the representation of each slot, they are arranged in a fixed order to generate a combined slot representation; The composite relation generation layer accepts both graph relations and combined slot representations. According to the connection order of the graph relationship and the combined slot representation, joint mapping processing is performed, combined encoding is performed, and a composite constraint relationship representation is generated.

6. The method for security deployment of large-scale urban events based on knowledge graphs according to claim 1, characterized in that, The generated three-domain joint situational representation includes: Connect the activity area node data to the activity area node data input terminal, connect the channel node data to the channel node data input terminal, connect the police force node data to the police force node data input terminal, and connect the composite constraint relationship representation to the composite constraint relationship representation input terminal. Within the three-domain coupled propagation layer, internal propagation of the active region node data is performed based on the active region node data to generate the active region propagation result. Based on the channel node data, perform internal propagation of the channel node data to generate the channel propagation result; Based on the police force node data, internal propagation of the police force node data is performed to generate police force propagation results; Based on the composite constraint relationship representation, cross-domain correlation propagation from region to channel is performed between the propagation results of the activity area and the propagation results of the channel; cross-domain correlation propagation from channel to police force is performed between the propagation results of the channel and the propagation results of the police force; and cross-domain correlation propagation from region to police force is performed between the propagation results of the activity area and the propagation results of the police force, thereby generating cross-domain propagation results. Based on the propagation results from the activity area, channels, police force, and cross-domain propagation, joint mapping processing is performed to generate a joint situational awareness representation across the three domains.

7. A method for security deployment of large-scale urban events based on knowledge graphs according to claim 1, characterized in that, The generated deployment writeback knowledge graph includes: The three-domain joint situational representation is input into the deployment hypothesis generation layer to construct deployment hypothesis nodes, including deployment hypothesis node identifier, activity area node identifier, passage node identifier, police force node identifier, and time period limitation field; Based on the deployment assumption nodes, deployment assumption relationships are established between deployment assumption nodes and activity area node data, between deployment assumption nodes and channel node data, and between deployment assumption nodes and police force node data. Based on the three-domain joint situational awareness, the deployment hypothesis relationships are screened, and the deployment hypothesis relationships that form a complete association with the activity area node data, channel node data, and police force node data are identified as write-back relationships. The deployment hypothesis nodes are written into the limited attribute security knowledge graph as new graph entities, and the write-back relationship is written into the limited attribute security knowledge graph as a new graph relationship. When a graph entity corresponding to a deployment hypothesis node identifier already exists in the limited attribute security knowledge graph, the graph entity is updated; when a graph relationship corresponding to a relationship identifier already exists in the limited attribute security knowledge graph, the graph relationship is updated. Based on the security knowledge graph with defined attributes after writing and updating, a defense write-back knowledge graph is generated.

8. A method for security deployment of large-scale urban events based on knowledge graphs according to claim 1, characterized in that, The generated security deployment plan for large-scale urban events includes: The knowledge graph of deployment is input into the graph input structure in the write-back iteration layer, and the graph relationships, limited attribute slots, activity area node data, channel node data, police force node data and deployment hypothesis relationship set are read. Input the graph relationship and the limited attribute slots into the slot re-encoding structure, re-execute the limited attribute slot encoding, and obtain the combined slot representation corresponding to the current round; The graph relationship and the combined slot representation corresponding to the current round are used to reconstruct the structure of the input relationship, and the composite constraint relationship generation is performed again to obtain the composite constraint relationship representation corresponding to the current round. The activity area node data, channel node data, police force node data, and the composite constraint relationship corresponding to the current round are input into the propagation recalculation structure, and cross-domain correlation propagation is re-executed to obtain the three-domain joint situation representation corresponding to the current round. Input the three-domain joint situational representation corresponding to the current round into the relation update structure, re-execute the deployment hypothesis relation update, obtain the deployment hypothesis relation set corresponding to the current round, and write it into the deployment writeback knowledge graph; Input the set of deployment assumptions corresponding to the current round into the stability determination structure to determine the change in the set of deployment assumptions; When the change in the set of deployment assumptions is lower than a preset threshold, the deployment assumptions are determined to have reached a stable state. Based on the set of deployment assumptions that have reached a stable state, the corresponding activity area node identifiers, passage node identifiers, police force node identifiers, and time period limitation fields are extracted to generate a security deployment plan for large-scale urban events.