Campus behavior risk intelligent analysis method and system fusing multi-dimensional data
By collecting dual-domain information from the campus physical environment and business systems, an individual's all-time and all-space behavioral trajectory chain is generated and dynamically classified and extrapolated. This solves the problem of insufficient multi-dimensional views in traditional campus behavior analysis and realizes the intelligent improvement of accurate risk identification and management of campus behavior.
Patent Information
- Application Number
- CN202610650490.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-12
- Publication Date
- 2026-07-03
AI Technical Summary
Traditional campus behavior analysis lacks the collaborative use of information from both physical perception endpoints and business transaction systems, making it difficult to form a panoramic view of individual behavior that covers all time and space and multiple dimensions. It is also unable to dynamically depict the patterns of individual behavior, resulting in a lag in the identification of potential risks in complex campus situations and limited accuracy.
Collect dual-domain information covering the perception endpoints and the transaction system, generate adjustable elements, form an individual's all-time and all-space behavior trajectory chain, introduce a dynamic classification mechanism for initial classification and cluster merging, combine it with the normal behavior spectrum for inference, use a large language model for behavior discrimination, and construct a personalized judgment strategy.
It enables comprehensive and granular characterization and risk prediction of individual behavior on campus, improves the accuracy and foresight of risk identification, has self-learning and self-adaptive capabilities, can quickly respond to special or emerging behavioral patterns, reduce the misjudgment rate and improve the level of intelligent management.
Smart Images

Figure CN122335003A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of campus management technology, specifically to a method and system for intelligent analysis of campus behavioral risks that integrates multi-dimensional data. Background Technology
[0002] In the field of campus safety management and order maintenance, with the continuous advancement of information technology construction, the deployment of various sensing devices and business systems has accumulated massive amounts of environmental and transaction data. However, traditional campus behavior analysis lacks the collaborative utilization of information from both physical sensing terminals and business transaction systems, making it difficult to form a panoramic view of individual behavior covering all time and space and multiple dimensions. Furthermore, it cannot dynamically depict the behavioral patterns of individuals across different times, spaces, activity types, and states, and it lacks a continuous self-learning and updating mechanism for behavioral patterns, resulting in delayed and limited accuracy in identifying potential risks in complex and ever-changing campus situations.
[0003] Given the high requirements of campus security for real-time perception, dynamic classification, continuous calibration, and intelligent inference, there is an urgent need for an intelligent analysis method and system that can integrate multi-dimensional data, realize all-time and all-space behavioral trajectory modeling, and have self-learning classification and personalized judgment capabilities, so as to ensure the accuracy, foresight, and scalability of campus behavioral risk identification. Summary of the Invention
[0004] The purpose of this invention is to provide a method and system for intelligent analysis of campus behavioral risks that integrates multi-dimensional data, so as to solve the problems in the background technology.
[0005] To achieve the above objectives, the present invention provides the following technical solution: a campus behavior risk intelligent analysis method integrating multi-dimensional data, the analysis method comprising the following steps:
[0006] S1: Collect dual-domain information covering the sensing edge and the transaction system, and generate adjustable elements;
[0007] S2: Based on dual-domain information and adjustable elements, extract patterns from normal behavior records within a set historical reference span to form a normal behavior spectrum at the individual level. Embed the normal behavior spectrum into a four-dimensional fusion framework to generate an individual's all-time-space behavior trajectory chain.
[0008] S3: Introduce a dynamic classification mechanism on the individual's all-time and all-space behavior trajectory chain, map the real-time collected state information into the difference weight of individual behavior, combine it with the normal behavior spectrum for initial classification, and merge the clusters to form several behavior pattern regions.
[0009] S4: After each round of classification, the confirmed normal behavior data will be included in the calculation of the normal behavior spectrum and the distribution characteristics of each dimension will be refitted.
[0010] S5: Input real-time multi-source information and normal behavior spectrum into a large language model optimized for campus scenarios, and conduct inference according to behavior discrimination criteria;
[0011] S6: For a certain behavioral pattern area, if there is no reusable judgment strategy, construct a regional behavioral feature sequence and input it into a preset behavioral risk analysis model to derive a personalized judgment strategy adapted to the area.
[0012] Preferably, step S3: Introducing a dynamic categorization mechanism into the individual's all-time and all-space behavioral trajectory chain, mapping the real-time collected state information to the differential weights of individual behaviors, including the following steps:
[0013] Calculate the degree of deviation between the real-time value of each dimension feature and the corresponding stable interval or distribution range in the normal behavior spectrum, and convert the degree of deviation into the difference weight value of that dimension;
[0014] As the overlap between the real-time residence area and the habitual activity area decreases, the difference weight of that area dimension increases:
[0015] Determine the normal baseline range or proportion for each dimension, obtain the performance of real-time collected values in that dimension, compare the deviation between the two, convert the deviation into numerical weights according to preset grading rules, the larger the deviation, the higher the weight, and the weights of all dimensions are combined to form differential weights.
[0016] Preferably, step S3: Initial classification is performed based on the normal behavior spectrum, and clusters are merged to form several behavioral pattern regions, including the following steps:
[0017] Compare the difference weights with the similarity of the difference weights of various cluster centers that have been formed in history;
[0018] If the tolerance matching condition is not met with any of the existing cluster centers, a new cluster is created and its difference weight is used as the initial cluster center;
[0019] Calculate the dispersion of all members within a cluster in terms of the difference weights in each dimension. If the dispersion is lower than the consistency threshold, the cluster features are considered consistent.
[0020] The difference between different clusters is statistically analyzed, and the difference between the center of each cluster in each dimension is compared. If the difference is lower than the difference threshold, they are merged to form several behavioral pattern regions.
[0021] Preferably, the merging process is as follows:
[0022] Select a cluster center as the center of the merged cluster, merge the members of the other cluster into the merged cluster, and update the center of the merged cluster to the average result of the difference weights of all members of the cluster;
[0023] The process is repeated until the difference between any two clusters is no less than the difference threshold, forming several behavioral pattern regions.
[0024] Preferably, step S4: After each round of classification, the confirmed normal behavior data is included in the calculation of the normal behavior spectrum, and the distribution characteristics of each dimension are refitted, including the following steps:
[0025] After completing the classification and cluster merging, output the set of normal behavior data confirmed by this classification;
[0026] The normal behavior data set is merged with the normal behavior samples within the original historical reference span to form an expanded sample set;
[0027] Based on the historical reference span setting in the adjustable elements, the time range of the expanded sample set is adjusted;
[0028] For the distribution of habitual activity areas, the proportion of dwell time in each area was recalculated; for the time intervals of daily routines, high-frequency time periods were re-identified; for the frequency and amount of consumption, stable intervals were recalculated; for the density of social interaction, the average frequency of interaction was recalculated, and the fitting process was as follows:
[0029] Traverse all records in the new sample set, extract corresponding feature values by dimension, perform frequency statistics or proportion calculation, and update the baseline range or distribution description of the dimension in the normal behavior spectrum based on the statistical results.
[0030] During the refitting process, if a certain dimension is detected to exhibit a continuous gradual change, the weights of that dimension will be flexibly adjusted.
[0031] The preferred logic for determining continuous gradual change is as follows:
[0032] Compare the direction and magnitude of the shift in the distribution characteristics of this dimension between the current period and the previous period. If the shift in the same direction occurs consecutively multiple times, and the magnitude of the shift increases, it is determined to be a continuous gradual change, and the weight of this dimension is flexibly adjusted.
[0033] In the difference weight calculation stage, the influence coefficient of this dimension in the difference weight calculation is increased, and flexibly adjusted as follows:
[0034] Based on the original weight calculation rules, a gradual response factor is added to this dimension. When a continuous gradual change is detected, the value of the gradual response factor is increased by a preset step size.
[0035] Preferably, step S5: Input real-time multi-source information and the normal behavior spectrum into the large language model optimized for campus scenarios, and perform inference according to behavior discrimination criteria, including the following steps:
[0036] It receives multi-source information, including normative behavior profiles and real-time push notifications, and inputs it into a large language model optimized for campus scenarios. The behavior discrimination criteria include:
[0037] Iterate through all perception and transaction identification records of the specified individual and check whether there is any valid consumption record, access control verification record or classroom attendance record. If no such record is detected within the time range, the individual is determined to be in a state of being out of contact.
[0038] The actual behavioral trajectory of an individual is compared with the distribution of habitual activity areas and the time interval of daily routine nodes in the normal behavior spectrum. First, the real-time spatial location and the time of occurrence are located. If the location is a zero-occurrence area in the distribution of normal activity areas and the time point is outside the normal daily routine node interval, it is marked as a deviation event. When deviation events occur multiple times and their spatiotemporal characteristics meet a specific abnormal pattern, they are judged as trajectory abnormalities.
[0039] Real-time statistics on an individual's spending amount, social interaction density, and time spent alone are obtained and compared with the median or benchmark value of the corresponding dimension in the normal behavior spectrum. The median spending amount for the current period is calculated. If the median spending amount for the individual recently decreases by more than the normal median by a first threshold, the first condition is met. Secondly, the median social interaction density for the current period is calculated. If the median decreases by more than the normal median by a second threshold, the second condition is met. The statistical value of time spent alone for the current period is calculated. If the increase in time spent alone for the current period exceeds the normal median by a third threshold, the third condition is met. A psychological risk is determined if and only if all three conditions are met simultaneously within the same period.
[0040] Preferably, step S6: For a certain behavioral pattern area, if there is no reusable judgment strategy, then construct a regional behavioral feature sequence and input it into a preset behavioral risk analysis model to derive a personalized judgment strategy adapted to the area, including the following steps:
[0041] Extract historical behavioral data of all individuals in the region, including past normal behavior patterns, cluster features generated during the classification process, key event records from real-time multi-source information, and risk assessment results derived from the deduction;
[0042] Extract regional scale characteristics, including the number of individuals within the region, the spatial scope involved, the time span, and the degree of consistency in behavioral patterns;
[0043] The two types of information are organized into a regional behavioral feature sequence, and the behavioral events within the region are arranged in chronological order. Each behavioral event is then appended with its own individual identifier, spatial location, timestamp, event type, and difference weight value to form a structured sequence.
[0044] The structured sequence input is a pre-set behavioral risk analysis model, and the risk analysis model outputs a personalized assessment strategy for the region.
[0045] Preferably, step S2: Based on dual-domain information and adjustable elements, extract patterns from normal behavior records within a set historical reference span, including the distribution of habitual activity areas, the interval between work and rest nodes, the stable interval of consumption frequency and amount, and the density of social interaction.
[0046] This application also provides a campus behavior risk intelligent analysis system that integrates multi-dimensional data, including:
[0047] The acquisition module collects dual-domain information covering the sensing edge and the transaction system, and generates adjustable elements. Based on the dual-domain information and adjustable elements, it extracts patterns from normal behavior records within a set historical reference span to form a normal behavior spectrum at the individual level. The normal behavior spectrum is embedded into the four-dimensional fusion framework to generate an individual's all-time-space behavior trajectory chain. The individual's all-time-space behavior trajectory chain is sent to the classification module, and the normal behavior spectrum is sent to the derivation module and the classification module.
[0048] Classification Module: A dynamic classification mechanism is introduced on the individual's all-time and all-space behavior trajectory chain. The real-time collected state information is mapped to the difference weight of individual behavior. The initial classification is performed in combination with the normal behavior spectrum. Clusters are merged to form several behavior pattern regions. After each round of classification, the confirmed normal behavior data is included in the normal behavior spectrum calculation. The distribution characteristics of each dimension are refitted and the behavior pattern regions are sent to the derivation module.
[0049] Inference Module: Input real-time multi-source information and normal behavior spectrum into a large language model optimized for campus scenarios, and perform inference according to behavior discrimination criteria. For a certain behavior pattern area, if there is no reusable judgment strategy, construct a regional behavior feature sequence and input it into a preset behavior risk analysis model to derive a personalized judgment strategy adapted to the area.
[0050] The technical effects and advantages provided by the present invention in the above technical solution are as follows:
[0051] 1. This application introduces a dynamic categorization mechanism on the trajectory chain and combines it with differential weight mapping. This method enables rapid initial categorization and cluster merging of real-time state information, automatically dividing it into several behavioral pattern regions. This allows for efficient extraction of structured patterns from massive behavioral data, significantly improving the real-time performance of analysis and reasoning. After each round of categorization, confirmed normal behaviors are continuously fed back to the normal behavior spectrum and the distribution characteristics are refitted, giving the model self-learning and adaptive capabilities. The benchmark can be continuously optimized during use, reducing the false positive rate and maintaining sensitivity to behavioral changes. Furthermore, by inputting real-time multi-source information and the dynamically updated normal behavior spectrum into a large language model optimized for campus scenarios, and using behavioral discrimination criteria for deduction, the semantic understanding and reasoning advantages of the large model can be fully utilized to achieve in-depth analysis and interpretable output of potential risks in complex campus situations.
[0052] 2. This application, by constructing a regional behavioral characteristic sequence and invoking a pre-set risk analysis model, can derive personalized judgment strategies. This ensures targeted responses to special or emerging behavioral patterns while avoiding the generalization problem caused by applying uniform rules to all scenarios. This closed-loop iteration and personalized strategy generation mechanism enables the system to maintain universality while possessing flexible scalability. It can effectively identify and warn of potential safety and order risks on campus, improve the level of intelligent management and the foresight and accuracy of emergency response, and ultimately achieve a leap from passive response to proactive prediction and intelligent decision-making in campus safety prevention and control.
[0053] 3. This application achieves comprehensive and fine-grained characterization and risk prediction of individual behavior on campus through collaborative collection and dynamic modeling of multi-source information, yielding significant technical results. First, the solution relies on dual-domain information collection covering both the sensory endpoints and the transaction system, along with adjustable element generation, breaking the limitations of traditional single data sources. This allows behavioral analysis to simultaneously consider physical environment perception and business system transaction data, improving data integrity and contextual accuracy. Second, by extracting normal behavioral patterns within a historical reference span and forming a normal behavioral spectrum at the individual level, and then embedding it into a four-dimensional fusion framework to generate a full-time-space behavioral trajectory chain, it can accurately capture individual behavioral patterns across different times, spaces, activities, and states, providing a highly reliable benchmark for subsequent anomaly detection. Attached Figure Description
[0054] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.
[0055] Figure 1 This is a timing diagram of the analytical method of this invention. Detailed Implementation
[0056] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0057] Example: This example provides an intelligent analysis method for campus behavioral risks that integrates multi-dimensional data. Please refer to [link / reference]. Figure 1 As shown, the analysis method includes the following steps:
[0058] S1: Collect dual-domain information covering both the sensing edge and the transaction system. The sensing edge information includes video structured capture events (such as personnel appearance characteristics and movement direction), intelligent identification terminal records (such as access control verification logs and consumption terminal verification data), and public facility operation status (such as monitoring online status and access control response performance).
[0059] The information in the transaction system covers personnel identity and permission configuration (such as student / faculty / staff categories, list of accessible areas) and daily behavior records (such as the time of entering and leaving the school gate, classroom roll call results, and details of catering and supermarket consumption).
[0060] Information collection follows a pace of once per minute to ensure timeliness and generates adjustable elements, including historical reference span (default is 30 days of normal behavior samples, which can be scaled up or down according to data accumulation) and baseline dimension set (initially including four types of features: activity area, work and rest pattern, consumption pattern, and social intensity, which can be added or removed according to data abundance and scenario requirements).
[0061] S2: Based on dual-domain information and adjustable elements, an individual's normal behavior spectrum is established as a comparison benchmark. Patterns are extracted from normal behavior records within a set historical reference span to form an individual-level normal behavior spectrum, including the distribution of habitual activity areas (such as the proportion of time spent in classrooms, dormitories, and canteens), daily routine intervals (such as the time zones for regular entry and exit from the school gate and return to the dormitory), stable intervals of consumption frequency and amount, and social interaction density (such as the frequency of co-occurrence of access control linkage and classrooms). The normal behavior spectrum is embedded into a four-dimensional fusion framework of people-event-location-time to generate an individual's full-time and space-time behavior trajectory chain, realizing the traceable connection of behaviors across scenarios and time periods.
[0062] S3: Based on the individual's all-time and all-space behavioral trajectory chain, a dynamic classification mechanism is introduced to map the real-time collected state information into the difference weight of individual behavior, and perform initial classification in combination with the normal behavior spectrum; then, the consistency of features within the cluster and the degree of difference between clusters are statistically analyzed, and the clusters are merged to form several behavioral pattern regions. Regions with the same pattern can share the same judgment strategy.
[0063] S4: After each round of classification, the confirmed normal behavior data are included in the calculation of the normal behavior spectrum, and the distribution characteristics of each dimension are refitted; when a certain dimension shows a continuous gradual change (such as gradually delaying the return to bed), the weight of that dimension is flexibly adjusted so that the normal behavior spectrum and the classification results always fit the current normal living status of the group.
[0064] S5: Input real-time multi-source information and normal behavior spectrum into a large language model optimized for campus scenarios, and perform inference according to behavior discrimination criteria:
[0065] ①Loss of contact determination: No contact or transaction traces for 24 consecutive hours (no consumption, no access control, no attendance);
[0066] ② Abnormal trajectory identification, behavior significantly deviates from the normal behavior spectrum (such as appearing in the teaching area late at night from 23:00 to 5:00, or entering non-resident areas multiple times in a short period of time);
[0067] ③ Psychological risk assessment: the consumption amount decreases by more than 50% compared to the median of the spectrum, the social interaction density decreases by more than 60%, and the time spent alone increases by more than 30%, and all three conditions are met simultaneously.
[0068] S6: For a certain behavioral pattern area, if there is no directly applicable judgment strategy for this behavior, extract the historical behavioral data of individuals in the area and the area scale characteristics, construct the area behavioral feature sequence, and input it into the preset behavioral risk analysis model to derive a personalized judgment strategy (including risk triggering conditions, attention indicator weights, and response priorities) that is suitable for the area.
[0069] This embodiment also provides a campus behavior risk intelligent analysis system that integrates multi-dimensional data, including:
[0070] The acquisition module collects dual-domain information covering the sensing edge and the transaction system, and generates adjustable elements. Based on the dual-domain information and adjustable elements, it extracts patterns from normal behavior records within a set historical reference span to form a normal behavior spectrum at the individual level. The normal behavior spectrum is embedded into the four-dimensional fusion framework to generate an individual's all-time-space behavior trajectory chain. The individual's all-time-space behavior trajectory chain is sent to the classification module, and the normal behavior spectrum is sent to the derivation module and the classification module.
[0071] Classification Module: A dynamic classification mechanism is introduced on the individual's all-time and all-space behavior trajectory chain. The real-time collected state information is mapped to the difference weight of individual behavior. The initial classification is performed in combination with the normal behavior spectrum. Clusters are merged to form several behavior pattern regions. After each round of classification, the confirmed normal behavior data is included in the normal behavior spectrum calculation. The distribution characteristics of each dimension are refitted and the behavior pattern regions are sent to the derivation module.
[0072] Inference Module: Input real-time multi-source information and normal behavior spectrum into a large language model optimized for campus scenarios, and perform inference according to behavior discrimination criteria. For a certain behavior pattern area, if there is no reusable judgment strategy, construct a regional behavior feature sequence and input it into a preset behavior risk analysis model to derive a personalized judgment strategy adapted to the area.
[0073] This embodiment also provides a detailed description of each step of the analysis method of this application, as follows:
[0074] In step S1, dual-domain information collection operations are performed on the sensing endpoints and the transaction system to obtain basic data to support subsequent behavior modeling and risk analysis. The sensing endpoint information originates from various front-end data collection devices and intelligent identification terminals deployed in the campus physical environment, including the following three categories:
[0075] Video structured capture events are output by video analysis equipment after target detection and attribute parsing of the monitoring screen. For example, the appearance characteristics of people (such as clothing color, body shape, type of items carried) and movement orientation (movement direction angle, path trend) are used to depict the intuitive behavior of individuals in space.
[0076] Intelligent identification terminal records, generated by access control verification devices, payment terminals, etc., such as access control verification logs (including verification time, location, verification result, device number) and payment terminal verification data (including transaction time, terminal location, transaction amount, verification method), are used to reflect an individual's activity trajectory and interaction behavior at key nodes;
[0077] The operational status of public facilities is collected by the facility operation status monitoring system, such as monitoring online status (equipment online time, offline time, fault type) and access control response performance (average response time, rejection rate, false recognition rate). This data is used to characterize the availability and data quality of sensing and control facilities, and to provide a basis for subsequent data validity verification.
[0078] The transaction system information comes from the campus business management platform and includes the following data:
[0079] Personnel identity and permission configuration is maintained by the personnel management system and permission management platform. It includes personnel categories (such as specific classification labels for students, faculty and staff, visitors, etc.) and a list of accessible areas (clearly defining the physical area range and time constraints that an individual is authorized to enter), which are used to define the basic identity attributes and behavioral boundaries of an individual.
[0080] Daily activity logs are generated by aggregating logs from various business systems, such as the time of entering and leaving the school gate (time stamp accurate to the second, direction of entry and exit), class attendance results (course name, attendance time, attendance status), and details of catering and supermarket consumption (merchant number, consumption item, payment time, amount, payment method). These logs are used to record the regular activity patterns and resource usage behaviors of individuals in teaching, living and other scenarios.
[0081] Based on the preprocessed dual-domain information, two types of adjustable elements are further generated as configurable parameters for subsequent behavioral pattern extraction and model construction.
[0082] The first category is the historical reference span, which is defined as the time range of historical samples used to extract normal behavior patterns. The default value is 30 days of normal behavior samples. Here, normal behavior samples refer to the effective data set after preliminary screening to exclude obvious abnormal events (such as invalid records caused by equipment failure or error logs caused by human error). This span can be dynamically adjusted according to the data accumulation. For example, when the amount of data is sufficient and the complexity of the scenario increases, it can be extended to 60 days to cover the periodic characteristics of behavior over a longer period. Conversely, if the data is sparse, it can be shortened to 15 days to ensure the representativeness of the samples.
[0083] The second category is the baseline dimension set, which defines the core feature categories used to characterize routine behavior. Initially, it includes four features: activity area (the physical spatial location where an individual frequently appears), daily routine (the statistical distribution of the start and end times of daily activities), consumption pattern (the concentration trend of consumption frequency, amount range, and preferred merchant types), and social intensity (the proportion and frequency of time spent in the same space with others). This set can be added or removed according to data abundance and scenario requirements. For example, in scenarios requiring focused monitoring of group interaction risks, dimensions such as group gathering duration and cross-group interaction frequency can be added. Conversely, in scenarios focusing on abnormal individual solitude, the weight of dimensions such as the distribution of solitude areas and the deviation of solitude duration can be strengthened. The generation of adjustable elements provides a flexible parameter configuration basis for subsequent steps, enabling the system to adapt to the analytical needs of different campus sizes and management priorities at different times.
[0084] In step S2, based on the dual-domain information and the generated adjustable elements, a normal behavior spectrum at the individual level is established as a benchmark for subsequent behavior comparison, and an individual full-time-space behavior trajectory chain that can be traced back across scenarios and time periods is generated accordingly.
[0085] Based on the historical reference span setting in the adjustable elements, normal behavior samples within the corresponding time range are extracted from the valid behavior records that have completed preprocessing. Here, normal behavior samples refer to the set of continuous valid records after preprocessing and removal of significant abnormal events.
[0086] For a sample set of an individual, four types of patterns are extracted sequentially to construct a spectrum of normal behaviors.
[0087] Distribution of habitual activity areas: Traverse all location records of the individual within the sample period, including spatial coordinates in video structured capture events and verification locations recorded by intelligent recognition terminals, count the number of times the individual appears in each physical area and the cumulative dwell time, and then calculate the proportion of dwell time in each area to the total effective dwell time of the sample, forming a distribution result such as 45% dwell time in the classroom, 30% in the dormitory, 15% in the canteen, and 10% in other areas, to characterize the individual's activity center of gravity in typical environments.
[0088] Daily Routine Intervals: Frequency statistics and clustering are performed on the time stamp data such as the individual's entry and exit times at the school gate and return time to the dormitory to identify the time intervals with the highest frequency. For example, in most cases, the morning entry time is concentrated between 07:40 and 08:10, the afternoon departure time is concentrated between 17:20 and 17:50, and the evening return time to the dormitory is concentrated between 22:30 and 23:10. Based on this, regular daily routine intervals are determined to characterize the stable rhythm of behavior on the time axis.
[0089] Stable range of consumption frequency and amount: Count the number of consumption records and corresponding amounts of the individual in the sample period, aggregate them by day to obtain the daily consumption frequency and amount, and then calculate the statistical distribution range of these daily values. For example, if the daily consumption frequency is stable between 2 and 4 times and the amount of a single consumption is mostly between 8 yuan and 25 yuan, this can be used as the normal boundary of consumption behavior.
[0090] Social interaction density: Based on access control linkage records and classroom co-occurrence data, when the timestamp difference between two records is within a set short-term proximity range (e.g., within 300 seconds) and the spatial location matches the same area, it is determined as an interaction event. The number of interaction events between the individual and other people within the sample period is counted, and the average interaction frequency per unit time is calculated to form a density level description, such as appearing in access control scenarios with different people 3 to 5 times a day and co-occurring in classrooms 1 to 2 times a day, to reflect the normal intensity of their social behavior.
[0091] The above four categories of patterns, after being organized, form a spectrum of normal behaviors at the individual level. This spectrum is stored as a comparison benchmark in the behavior modeling end for subsequent real-time behavior deviation assessment. Subsequently, the spectrum of normal behaviors is embedded into a four-dimensional fusion framework of people, events, locations, and time. This framework uses personnel identification as the main index, event type as a behavior category code (such as entering and leaving school, classroom attendance, consumption, and area stay), location as a unique physical space code, and time as a timestamp accurate to the minute. By mapping each valid behavior record of an individual within the sample period to these four dimensions and arranging them in chronological order, a continuous chain of individual full-time and spacetime behavior trajectories is generated.
[0092] For example, on [Date], a student completes entry verification at the South Gate access control at 07:45 (Event Type: Entry, Location: South Gate, Time: 07:45), enters classroom 302 of the teaching building at 08:02 (Event Type: Area Stay, Location: Classroom 302, Time: 08:02), consumes at the First Canteen at 12:10 (Event Type: Consumption, Location: First Canteen, Time: 12:10), and completes dormitory return verification at the dormitory building access control at 22:40 (Event Type: Return to Dormitory, Location: Dormitory Area Access Control, Time: 22:40). The above records, strung together by time, constitute a segment of the student's behavioral trajectory for that day. Accumulating the trajectory segments of all dates within the sample period forms a complete spatiotemporal behavioral trajectory chain.
[0093] In step S3, based on the individual spatiotemporal behavior trajectory chain generated in the previous steps, a dynamic categorization mechanism is introduced to realize the categorization and processing of real-time collected status information and the division of behavior pattern regions.
[0094] Real-time status information is acquired by the acquisition terminal at a predetermined pace. This information includes the current location of personnel, event type, location, and timestamp. After being transmitted to the classification terminal, this information is compared item by item with the individual's corresponding normal behavior spectrum. The comparison process is achieved by mapping these differences to weights specific to the individual's behavior.
[0095] For each feature dimension (such as activity area, daily routine, consumption frequency and amount, and social interaction density), the deviation between its real-time value and the corresponding stable interval or distribution range in the normal behavior spectrum is calculated, and the deviation is converted into a difference weight value for that dimension. When the overlap ratio between the real-time residence area and the habitual activity area decreases, the difference weight of that dimension increases. The calculation logic for the difference weight is as follows:
[0096] Determine the normal baseline range or proportion for each dimension, then obtain the specific performance of the real-time collected values in that dimension, compare the deviation between the two, and convert the deviation into numerical weights according to preset grading rules. The larger the deviation, the higher the weight. The weights of all dimensions are combined to form the difference weights for this real-time state.
[0097] In one embodiment disclosed in this application, the baseline occupancy rate is set at 45% for classrooms, 30% for dormitories, 15% for canteens, and 10% for other areas. Real-time occupancy rates are collected for classrooms (30%), dormitories (40%), canteens (20%), and other areas (10%). The deviation of the occupancy rate for each area is calculated: the classroom deviation is 15 percentage points (45% minus 30%), the dormitory deviation is 10 percentage points (30% minus 40%), the canteen deviation is 5 percentage points (15% minus 20%), and the deviation for other areas is 0 percentage points.
[0098] The preset grading rule is that every 5 percentage points of deviation corresponds to a Level 1 weight, with a weight value of 1 for Level 1, 2 for Level 2, 3 for Level 3, 4 for Level 4, and 5 for Level 5. Deviations less than 5 percentage points are counted as the same level. A classroom deviation of 15 percentage points corresponds to a Level 3 weight of 3, a dormitory deviation of 10 percentage points corresponds to a Level 2 weight of 2, a canteen deviation of 5 percentage points corresponds to a Level 1 weight of 1, and other areas deviations of 0 percentage points correspond to a weight of 0. Therefore, the difference weight vector for the activity area dimension is: Classroom 3, Dormitory 2, Canteen 1, and Other Areas 0. This vector, combined with the weights obtained from other dimensions in the same way, constitutes the difference weight vector for this real-time state.
[0099] After obtaining the difference weights, the classification end performs initial classification by combining the normal behavior spectrum:
[0100] The difference weights are compared with the similarity of the difference weights of various types of cluster centers that have been formed in the past. The similarity can be judged by comparing the weight differences in each dimension and accumulating them. If the tolerance matching condition is not met with any of the existing cluster centers, a new cluster is created and its difference weight is used as the initial cluster center.
[0101] After the initial classification, the next step is cluster statistics and merging. The consistency of features within each cluster is statistically analyzed:
[0102] Calculate the dispersion of all members within a cluster across all dimensions' weights. If the dispersion is below a consistency threshold, the cluster is considered to have consistent characteristics. Then, perform a difference statistics analysis between different clusters: compare the differences between the center centers of each pair of clusters across all dimensions' weights. If the differences are below a difference threshold, it indicates that the two clusters are similar in behavior and can be merged. The merging process is as follows:
[0103] One cluster center is selected as the center of the merged cluster. Members of the other cluster are merged into this new cluster, and the center of the merged cluster is updated to the average of the difference weights of all members in that new cluster. This process is repeated until the difference between any two clusters is no less than the difference threshold. Through the above processing, several behavioral pattern regions are finally formed. Individuals or states in each region have high similarity in behavioral characteristics, so the same judgment strategy can be shared in subsequent analyses, thereby reducing strategy maintenance costs and improving applicability.
[0104] In one embodiment of this application, let the existing cluster center vector A be classroom 3, dormitory 2, canteen 1, and other areas 0, and the new difference weight vector B be classroom 4, dormitory 2, canteen 1, and other areas 0. The weight differences are compared dimension by dimension, and the differences are 1, 0, 0, and 0 respectively. The cumulative difference is 1. The tolerance matching condition is set to the cumulative difference being less than or equal to 2. Then B and A are matched and B is assigned to cluster A. If cluster A contains member vectors A1 (classroom 3, dormitory 2, canteen 1, other areas 0), A2 (classroom 4, dormitory 2, canteen 1, other areas 0), and A3 (classroom 2, dormitory 2, canteen 1, other areas 0), calculate the dispersion of each dimension. The average value of the classroom dimension is (3+4+2) / 3, which equals 3. The variance is calculated by dividing the sum of the squares of the differences between each member and the average value by the number of members, which equals [(3-3)²+(4-3)²+(2-3)²] / 3, which is (0+1+1) / 3, which equals 0.67. The variance of the dormitory dimension is 0, the variance of the canteen dimension is 0, and the variance of the other areas dimension is 0. The consistency threshold is set to a maximum variance less than or equal to 1, then the cluster features are consistent.
[0105] Compare the central vectors of cluster A (Classroom 3, Dormitory 2, Canteen 1, Other Areas 0) with those of cluster C (Classroom 3, Dormitory 3, Canteen 1, Other Areas 0). The differences in each dimension are 0, 1, 0, 0, and the cumulative difference is 1. The difference threshold is set to allow merging if the cumulative difference is less than 2. Then, the members of cluster C are merged into cluster A, and the central vector of cluster A is updated to the arithmetic mean of the corresponding dimensions of the two cluster member vectors. If the merged member vectors are Classroom 3, Dormitory 3, Canteen 1, Other Areas 0, then the new central vectors are (3+3+4+2+3) / 5 (3 for Classroom), (2+2+2+2+3) / 5 (2.2 for Dormitory), and (1 for Canteen), Other Areas 0. Repeat the comparison until the difference between any two clusters is not lower than the difference threshold. This forms several behavioral pattern regions, making the individuals or states in the regions highly similar in behavioral characteristics.
[0106] In step S4, after each round of classification, the data identified as normal behavior during the classification process are included in the normal behavior spectrum, and the distribution characteristics of each dimension are refitted to maintain the timeliness and representativeness of the normal behavior spectrum.
[0107] After completing the classification and cluster merging, the classification end will output the set of normal behavior data confirmed by this classification. This type of data consists of real-time status records that have not reached the abnormal threshold in the difference weight calculation, or the cluster to which it belongs has been determined to be in normal mode after consistency verification.
[0108] After receiving the set, the modeling end merges it with the normal behavior samples within the original historical reference span to form a new expanded sample set. Based on the setting of the historical reference span in the adjustable elements, the time range of the samples is adjusted accordingly to ensure that the samples include both the original period and the newly added normal data.
[0109] For each dimension of the normal behavior spectrum, refit its distribution characteristics:
[0110] For the distribution of habitual activity areas, the percentage of time spent in each area was recalculated; for the time spent between work and rest periods, high-frequency time periods were re-identified; for the frequency and amount of consumption, stable intervals were recalculated; for the density of social interaction, the average frequency of interaction was recalculated. The fitting processing logic is as follows:
[0111] Traverse all records in the new sample set, extract corresponding feature values by dimension, perform frequency statistics or proportion calculations, and update the baseline range or distribution description of the dimension in the normal behavior spectrum based on the statistical results.
[0112] During the refitting process, if a persistent gradual change is detected in a certain dimension, a flexible adjustment is performed on the weights of that dimension. The logic for determining persistent gradual changes is as follows:
[0113] By comparing the direction and magnitude of the shift in the distribution characteristics of this dimension between the current period and the previous period, if the shift in the same direction occurs consecutively multiple times, and the magnitude of the shift steadily increases, it is determined to be a continuous gradual change. The modeling end flexibly adjusts the weights of this dimension:
[0114] In the differential weighting calculation stage, the influence coefficient of this dimension in the calculation of differential weights is increased, making it easier to reflect this type of gradual change in subsequent real-time state comparisons. This avoids the normal behavior spectrum failing to reflect the current normal living conditions of the group due to lag. The flexible adjustment is as follows:
[0115] Based on the original weight calculation rules, a gradual response factor is added to this dimension. When a continuous gradual change is detected, the value of this factor is increased by a preset step size, so that the weight of this dimension accounts for a larger proportion in the deviation calculation, thereby affecting the classification and subsequent inference results.
[0116] In one embodiment disclosed in this application, the normal high-frequency school entry time period of the N-2th cycle is set to 07:40–08:10, the N-1th cycle to 07:50–08:20, and the Nth cycle to 08:00–08:30. The offset direction is always delayed, and the offset magnitude is 10 minutes and 10 minutes respectively, which is determined to be a continuous gradual change. The initial value of the gradual change response factor is 1.0, and the preset step size is 0.2. After the gradual change is detected, the factor increases to 1.2. In the difference weight calculation, the deviation of this dimension is multiplied by 1.2, which enhances its influence in classification and inference. Therefore, the normal behavior spectrum is more in line with the current delayed work and rest status of the group.
[0117] In step S5, the analysis end receives the normal behavior spectrum from the modeling end and the multi-source information pushed in real time by the collection end, and inputs both into the large language model optimized for campus scenarios. The model then performs inferences based on predetermined behavior discrimination criteria to identify possible situations such as loss of contact, abnormal trajectory, and psychological risks. The real-time multi-source information includes data from the perception terminal and transaction system within the current moment and recent retrospective periods, such as video structured capture events, records from intelligent recognition terminals, the operation status of public facilities, personnel identity and permission configurations, and daily behavior logs. The data has been cleaned and standardized according to the collection rhythm and preprocessing rules of S1. The large language model optimized for campus scenarios incorporates typical campus behavior patterns, spatiotemporal constraint rules, and risk case corpora during training and fine-tuning, enabling it to perform logical inferences and comprehensive judgments on each discrimination criterion based on an understanding of the context of multi-source information.
[0118] The behavioral judgment criteria consist of three parts, and the execution logic is as follows:
[0119] ① Disconnection Detection: The system iterates through all perception and transaction records of a specified individual within the past 24 hours, checking for any valid consumption records, access control verification records, or class attendance records. If no such records are detected within the specified timeframe, the individual is determined to be disconnected. For example, if a student has no consumption terminal verification data, access control verification logs, or roll call results from 08:00 the previous day to 08:00 currently, this meets the disconnection detection criteria.
[0120] ② Trajectory Anomaly Detection: This involves comparing an individual's recent actual behavioral trajectory with their usual activity area distribution and sleep / rest intervals within the normal behavioral spectrum. First, the individual's real-time spatial location and time of occurrence are determined. If this location is a zero-occurrence area in the normal activity area distribution, and the time point is outside the normal sleep / rest interval, it is marked as a deviation event. When deviation events occur multiple times within a short period, and their spatiotemporal characteristics meet specific abnormal patterns (e.g., appearing in the teaching area between 11:00 PM and 5:00 AM, or entering a non-resident area three or more times within a week), it is determined to be a trajectory anomaly. For example, if a student is detected by structured video capture around 1:00 AM for three consecutive days in a classroom in the laboratory building, but this time period is not included in their normal sleep / rest interval and the laboratory building is not among the top areas in their usual activity area distribution, then the trajectory anomaly detection criteria are met.
[0121] ③ Psychological Risk Assessment: Real-time statistical values of an individual's spending amount, social interaction density, and time spent alone are obtained and compared with the median or benchmark value of the corresponding dimension in the normal behavior spectrum. The median spending amount for the current period is calculated. If the individual's recent median spending amount decreases by more than 50% compared to the normal median, the first condition is met. Secondly, the median social interaction density for the current period is calculated. If it decreases by more than 60% compared to the normal median, the second condition is met. The statistical value of time spent alone for the current period is calculated. If it increases by more than 30% compared to the normal time spent alone, the third condition is met. A psychological risk is determined only if all three conditions are met simultaneously within the same period. For example, if a student's normal median spending amount is 20 yuan per day, and it decreases to below 8 yuan in the current period; the normal daily average number of social interactions is 4 times, and it decreases to below 1 time in the current period; the normal daily average time spent alone is 2 hours, and it increases to more than 3 hours in the current period, then the student meets the psychological risk assessment criteria.
[0122] In step S6, for the behavioral pattern regions derived from the deduction, it is checked whether there are any directly reusable assessment strategies. Assessment strategies include elements such as risk triggering conditions, weights of key indicators, and response priorities. If the characteristics of a behavioral pattern region completely match the applicable conditions of a strategy in the existing strategy library, then that strategy is directly reused; if no matching strategy exists, the personalized strategy generation process begins. The processing logic for personalized strategy generation is as follows:
[0123] Historical behavioral data of all individuals within the region is extracted. This data includes past routine behavior patterns, cluster features generated during the classification process, key event records from real-time multi-source information, and risk assessment results derived from inference. Regional scale characteristics are also extracted, including the number of individuals within the region, the spatial extent involved, the time span, and the degree of consistency in behavioral patterns.
[0124] The two types of information mentioned above are organized into a regional behavioral feature sequence. The construction method is to arrange representative behavioral events in the region in chronological order, and add the individual identifier, spatial location, timestamp, event type and difference weight value to each event to form a structured sequence that can be analyzed by the model.
[0125] The sequence is input into a pre-defined behavioral risk analysis model. During the training phase, this model learns risk evolution patterns and effective intervention elements for regions of different sizes and characteristics. Based on the input sequence, it can infer applicable risk triggering conditions, weight allocation of key indicators, and response priority ranking for that region. The model output is a personalized assessment strategy for that region. The analysis end stores this strategy in a strategy library and establishes a correlation between the strategy and the corresponding behavioral pattern region, allowing for direct retrieval in subsequent simulations of similar situations, thereby improving the efficiency and relevance of the assessment.
[0126] Specifically, the steps for constructing a behavioral risk analysis model are as follows:
[0127] The training samples consist of several historically established behavioral pattern regions and their corresponding processing results. Each sample includes a behavioral feature sequence for that region, along with manually labeled or back-derived effective risk triggering conditions, weighted indicators, and response priority rankings derived from existing assessment strategies. The construction method for the behavioral feature sequence is consistent with step S6, i.e., representative behavioral events within the region are arranged chronologically, and each event is accompanied by its associated individual identifier, spatial location, timestamp, event type, and difference weight value. The samples should cover different regional scale characteristics, including the range of variation in the number of individuals within the region, the breadth of the spatial scope involved, the length of the time span, and the distribution range of the consistency of behavioral patterns, to ensure that the model has cross-scenario adaptability.
[0128] The input is a structured sequence of regional behavioral features. Each event field in the sequence is transformed according to a unified encoding rule, enabling the model to parse individual identifiers, spatial location codes, timestamp values, event type codes, and differential weight values. The output consists of three parts: risk triggering conditions, composed of several logical expressions, each associated with a specific dimension feature and a threshold; weight allocation of attention indicators, representing the influence coefficients of each dimension feature in subsequent extrapolation; and response priority ranking, a numerical level indicator used to indicate the urgency of intervention.
[0129] Employing a model structure suitable for sequence data processing and capable of learning causal relationships and pattern induction, the training phase incorporates risk evolution pattern corpus and effective intervention element annotations within a campus setting. This enables the model to capture the mapping patterns between behavioral events and risk outcomes across regions of different sizes and characteristics. The training logic involves feeding the sample input sequence into the model for forward computation, outputting predicted risk triggering conditions, weights of key indicators, and response priorities. This is compared with the sample annotation results, and the deviation is calculated according to a preset loss function. The model parameters are then adjusted through backpropagation, iterating until the loss converges or the set number of training epochs is reached. During training, samples are stratified and sampled according to regional size characteristics to prevent the model from being biased towards specific size regions.
[0130] Inference tests are conducted using a validation sample set that was not used in training. The model output is compared with the labeled results in terms of risk trigger condition hit rate, the degree of consistency between the weight of the key indicators and the actual risk contribution, and the consistency between the response priority and the treatment effect. If the indicators meet the preset qualified threshold, the model parameters are fixed as the inference version; if they do not meet the standards, the training sample coverage or model structure is adjusted and the model is retrained.
[0131] The fixed inference model is deployed on the analysis platform, and an interface is established with the policy library. This allows the model to receive regional behavioral feature sequences and return personalized judgment strategies when invoked in step S6. A model version management mechanism is established simultaneously during deployment to facilitate incremental training and version iteration based on new samples, ensuring the model's ability to judge newly emerging behavioral pattern regions and its adaptability remain consistent.
[0132] In one embodiment disclosed in this application, taking a certain area as an example, the number of individuals in the area is 12, the space involved is the 3rd to 5th floors of the laboratory building, the time span is the past 7 days, and the consistency degree of behavioral patterns is 0.85; the historical behavioral data includes individual A staying in room 402 of the laboratory building at 22:40 on day N-2, with a difference weight of 3, and individual B staying in room 408 of the laboratory building at 23:15 on day N-1, with a difference weight of 4. Real-time multi-source information records show that 3 people appeared together in room 405 of the laboratory building at 00:05 on day N, and it can be inferred that... The risk assessment result is trajectory anomaly; the above events are arranged in chronological order, with the following for event 1: individual identifier A, spatial location: Room 402, Experimental Building, timestamp: N-2 day 22:40, event type: regional residence, and difference weight value: 3; individual identifier B, spatial location: Room 408, Experimental Building, timestamp: N-1 day 23:15, event type: regional residence, and difference weight value: 4; and individual identifier group, spatial location: Room 405, Experimental Building, timestamp: N day 00:05, event type: co-occurrence, and difference weight value: 4, forming a structured sequence.
[0133] The sequence is input into a pre-defined behavioral risk analysis model. During the training phase, this model has learned the risk evolution patterns and effective intervention elements of regions with different scales and characteristics. Based on the input sequence, it can infer the risk triggering conditions, the weight allocation of key indicators, and the priority ranking of responses applicable to that region. The model output is the personalized assessment strategy for that region.
[0134] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0135] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to any specific implementation. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.
Claims
1. A method for intelligent analysis of campus behavioral risk by fusing multi-dimensional data, characterized in that: The analytical method includes the following steps: S1: Collect dual-domain information covering the sensing edge and the transaction system, and generate adjustable elements; S2: Based on dual-domain information and adjustable elements, extract patterns from normal behavior records within a set historical reference span to form a normal behavior spectrum at the individual level. Embed the normal behavior spectrum into a four-dimensional fusion framework to generate an individual's all-time-space behavior trajectory chain. S3: Introduce a dynamic classification mechanism on the individual's all-time and all-space behavior trajectory chain, map the real-time collected state information into the difference weight of individual behavior, combine it with the normal behavior spectrum for initial classification, and merge the clusters to form several behavior pattern regions. S4: After each round of classification, the confirmed normal behavior data will be included in the calculation of the normal behavior spectrum and the distribution characteristics of each dimension will be refitted. S5: Input real-time multi-source information and normal behavior spectrum into a large language model optimized for campus scenarios, and conduct inference according to behavior discrimination criteria; S6: For a certain behavioral pattern area, if there is no reusable judgment strategy, construct a regional behavioral feature sequence and input it into a preset behavioral risk analysis model to derive a personalized judgment strategy adapted to the area. 2.The method of claim 1, wherein the method further comprises: determining a risk score for each of the plurality of students based on the plurality of multi-dimensional data; and determining a risk score for each of the plurality of students based on the plurality of multi-dimensional data. Step S3: Introduce a dynamic categorization mechanism on the individual's all-time and all-space behavioral trajectory chain, mapping the real-time collected state information to the differential weights of individual behaviors, including the following steps: Calculate the degree of deviation between the real-time value of each dimension feature and the corresponding stable interval or distribution range in the normal behavior spectrum, and convert the degree of deviation into the difference weight value of that dimension; As the overlap between the real-time residence area and the habitual activity area decreases, the difference weight of that area dimension increases: Determine the normal baseline range or proportion for each dimension, obtain the performance of real-time collected values in that dimension, compare the deviation between the two, convert the deviation into numerical weights according to preset grading rules, the larger the deviation, the higher the weight, and the weights of all dimensions are combined to form differential weights.
3. The method of claim 2, wherein the method further comprises: Step S3: Initial classification is performed based on the normal behavior spectrum, and clusters are merged to form several behavioral pattern regions, including the following steps: Compare the difference weights with the similarity of the difference weights of various cluster centers that have been formed in history; If the tolerance matching condition is not met with any of the existing cluster centers, a new cluster is created and its difference weight is used as the initial cluster center; Calculate the dispersion of all members within a cluster in terms of the difference weights in each dimension. If the dispersion is lower than the consistency threshold, the cluster features are considered consistent. The difference between different clusters is statistically analyzed, and the difference between the center of each cluster in each dimension is compared. If the difference is lower than the difference threshold, they are merged to form several behavioral pattern regions.
4. The method of claim 3, wherein the method further comprises: The merging process is as follows: Select a cluster center as the center of the merged cluster, merge the members of the other cluster into the merged cluster, and update the center of the merged cluster to the average result of the difference weights of all members of the cluster; The process is repeated until the difference between any two clusters is no less than the difference threshold, forming several behavioral pattern regions.
5. The method of claim 1, wherein the method further comprises: Step S4: After each round of classification, the confirmed normal behavior data are included in the calculation of the normal behavior spectrum, and the distribution characteristics of each dimension are refitted, including the following steps: After completing the classification and cluster merging, output the set of normal behavior data confirmed by this classification; The normal behavior data set is merged with the normal behavior samples within the original historical reference span to form an expanded sample set; Based on the historical reference span setting in the adjustable elements, the time range of the expanded sample set is adjusted; For the distribution of habitual activity areas, the proportion of dwell time in each area was recalculated; for the time intervals of daily routines, high-frequency time periods were re-identified; for the frequency and amount of consumption, stable intervals were recalculated; for the density of social interaction, the average frequency of interaction was recalculated, and the fitting process was as follows: Traverse all records in the new sample set, extract corresponding feature values by dimension, perform frequency statistics or proportion calculation, and update the baseline range or distribution description of the dimension in the normal behavior spectrum based on the statistical results. During the refitting process, if a certain dimension is detected to exhibit a continuous gradual change, the weights of that dimension will be flexibly adjusted.
6. The method of claim 5, wherein the method further comprises: The logic for determining a continuous gradual change is as follows: Compare the direction and magnitude of the shift in the distribution characteristics of this dimension between the current period and the previous period. If the shift in the same direction occurs consecutively multiple times, and the magnitude of the shift increases, it is determined to be a continuous gradual change, and the weight of this dimension is flexibly adjusted. In the difference weight calculation stage, the influence coefficient of this dimension in the difference weight calculation is increased, and flexibly adjusted as follows: Based on the original weight calculation rules, a gradual response factor is added to this dimension. When a continuous gradual change is detected, the value of the gradual response factor is increased by a preset step size.
7. The method of claim 1, wherein the method further comprises: Step S5: Input real-time multi-source information and the normal behavior spectrum into the large language model optimized for campus scenarios, and perform inference according to the behavior discrimination criteria, including the following steps: It receives multi-source information, including normative behavior profiles and real-time push notifications, and inputs it into a large language model optimized for campus scenarios. The behavior discrimination criteria include: Iterate through all perception and transaction identification records of the specified individual and check whether there is any valid consumption record, access control verification record or classroom attendance record. If no such record is detected within the time range, the individual is determined to be in a state of being out of contact. The actual behavioral trajectory of an individual is compared with the distribution of habitual activity areas and the time interval of daily routine nodes in the normal behavior spectrum. First, the real-time spatial location and the time of occurrence are located. If the location is a zero-occurrence area in the distribution of normal activity areas and the time point is outside the normal daily routine node interval, it is marked as a deviation event. When deviation events occur multiple times and their spatiotemporal characteristics meet a specific abnormal pattern, they are judged as trajectory abnormalities. Real-time statistics on an individual's spending amount, social interaction density, and time spent alone are obtained and compared with the median or benchmark value of the corresponding dimension in the normal behavior spectrum. The median spending amount for the current period is calculated. If the median spending amount for the individual recently decreases by more than the normal median by a first threshold, the first condition is met. Secondly, the median social interaction density for the current period is calculated. If the median decreases by more than the normal median by a second threshold, the second condition is met. The statistical value of time spent alone for the current period is calculated. If the increase in time spent alone for the current period exceeds the normal median by a third threshold, the third condition is met. A psychological risk is determined if and only if all three conditions are met simultaneously within the same period.
8. The method of claim 1, wherein the method further comprises: Step S6: For a specific behavioral pattern area, if there is no reusable assessment strategy, construct a regional behavioral feature sequence and input it into a preset behavioral risk analysis model to derive a personalized assessment strategy adapted to the area, including the following steps: Extract historical behavioral data of all individuals in the region, including past normal behavior patterns, cluster features generated during the classification process, key event records from real-time multi-source information, and risk assessment results derived from the deduction; Extract regional scale characteristics, including the number of individuals within the region, the spatial scope involved, the time span, and the degree of consistency in behavioral patterns; The two types of information are organized into a regional behavioral feature sequence, and the behavioral events within the region are arranged in chronological order. Each behavioral event is then appended with its own individual identifier, spatial location, timestamp, event type, and difference weight value to form a structured sequence. The structured sequence input is a pre-set behavioral risk analysis model, and the risk analysis model outputs a personalized assessment strategy for the region.
9. The method of claim 1, wherein the method further comprises: Step S2: Based on dual-domain information and adjustable elements, extract patterns from normal behavior records within the set historical reference span, including the distribution of habitual activity areas, the interval between work and rest nodes, the stable interval of consumption frequency and amount, and the density of social interaction.
10. A campus behavioral risk intelligence analysis system for fusing multi-dimensional data, for implementing the analysis method of any one of claims 1-9, characterized in that: include: The acquisition module collects dual-domain information covering the sensing edge and the transaction system, and generates adjustable elements. Based on the dual-domain information and adjustable elements, it extracts patterns from normal behavior records within a set historical reference span to form a normal behavior spectrum at the individual level. The normal behavior spectrum is embedded into the four-dimensional fusion framework to generate an individual's all-time-space behavior trajectory chain. The individual's all-time-space behavior trajectory chain is sent to the classification module, and the normal behavior spectrum is sent to the derivation module and the classification module. Classification Module: A dynamic classification mechanism is introduced on the individual's all-time and all-space behavior trajectory chain. The real-time collected state information is mapped to the difference weight of individual behavior. The initial classification is performed in combination with the normal behavior spectrum. Clusters are merged to form several behavior pattern regions. After each round of classification, the confirmed normal behavior data is included in the normal behavior spectrum calculation. The distribution characteristics of each dimension are refitted and the behavior pattern regions are sent to the derivation module. Inference Module: Input real-time multi-source information and normal behavior spectrum into a large language model optimized for campus scenarios, and perform inference according to behavior discrimination criteria. For a certain behavior pattern area, if there is no reusable judgment strategy, construct a regional behavior feature sequence and input it into a preset behavior risk analysis model to derive a personalized judgment strategy adapted to the area.