Active perception protection monitoring system based on multi-source fusion all-in-one machine

By using hardware-level synchronization and self-supervised learning of the multi-source fusion all-in-one machine, combined with risk-level adaptive protection, the passive protection and rigidity problems of existing security systems are solved, and efficient, adaptive active protection and operation and maintenance optimization are achieved.

CN122435753APending Publication Date: 2026-07-21EAST (BEIJING) ENERGY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610311105.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-03-14
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing security systems suffer from problems such as passive protection, delayed early warning, inability to identify unknown anomalies, poor scenario generalization ability, and rigid protection. They cannot achieve pre-event early warning and in-event handling, and have high operation and maintenance costs.

Method used

The system adopts a multi-source fusion all-in-one machine, which integrates hardware-level trusted perception synchronization, lightweight cross-source spatiotemporal fusion, self-supervised baseline-based intelligent early warning, risk-level adaptive closed-loop protection, and full-link trusted security and traceability evidence storage units. It realizes hardware-level synchronization, self-supervised learning, dynamic risk level classification and adaptive protection strategies, and builds a protection closed loop.

Benefits of technology

It achieves 24-hour unmanned automatic anomaly identification and early warning, reduces false alarm rate, improves scenario generalization ability, adaptive protection strategy, builds protection closed loop, and improves system reliability and operation and maintenance efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122435753A_ABST
    Figure CN122435753A_ABST
Patent Text Reader

Abstract

The application discloses an active perception protection monitoring system based on a multi-source fusion all-in-one machine, belongs to the technical field of safety monitoring, and comprises a multi-source fusion all-in-one machine, further comprising a hardware-level trusted perception synchronization unit, a lightweight cross-source space-time fusion unit, a self-supervised baseline intelligent early warning unit, a risk grading self-adaptive closed-loop protection unit and a full-link trusted security and traceability storage unit integrated in the multi-source fusion all-in-one machine; all core processing links are integrated in the multi-source fusion all-in-one machine to complete locally, so that the time delay problem caused by cloud transmission is eliminated; meanwhile, through self-supervised baseline intelligent early warning, 24-hour unmanned automatic abnormal identification and early warning are realized, manual screen monitoring is not needed, the core logic of the security system is upgraded from post-backtracking to pre-warning, in-process disposal and full-process active protection of post-compliance traceability, and the problems of passive protection, early warning lag and inability to perceive in the event of the prior art are effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of security monitoring technology, specifically, it relates to an active sensing and protection monitoring system based on a multi-source fusion integrated machine. Background Technology

[0002] With the digital and intelligent upgrade of the security industry, security monitoring systems have been widely used in many scenarios such as industrial parks, power substations, warehousing and logistics, border and coastal defense, and data centers. Among them, integrated machines, with their high integration, flexible deployment, and strong field adaptability, are gradually replacing the traditional multi-device, stacked security architecture and becoming the core hardware carrier for edge security scenarios. Currently, mainstream security monitoring systems are mainly divided into two categories: one is a localized security system based on a local hard disk recorder, whose core functions are mainly video recording and storage, post-event playback, and fixed threshold alarms; the other is a networked security system based on a cloud SaaS platform, which relies on cloud computing power to achieve AI intelligent analysis and centralized management. However, in actual use, existing security monitoring solutions have certain shortcomings and may not be able to meet the proactive security needs in complex scenarios.

[0003] Most existing security systems (including cloud-based SaaS platform solutions) still rely on passive protection logic such as video recording and playback or fixed threshold alarms. The detection of abnormal events depends heavily on security personnel manually monitoring the screens, which is extremely inefficient and prone to missed detections. Even solutions with intelligent analysis functions can only trigger alarms after an abnormal event occurs, and may not be able to achieve pre-event warnings or real-time handling. Often, they cannot effectively detect the event at the time of occurrence and can only conduct post-event retrospective analysis after the loss has occurred, completely losing the proactive protection value of the security system.

[0004] Existing security solutions with AI-powered intelligent analysis generally employ supervised learning algorithms, which require a large number of labeled anomaly samples for training. They can only identify predefined anomaly types and are completely unable to identify novel intrusion behaviors or unknown anomalies, potentially leading to a high risk of missed detections. Furthermore, the models can only adapt to the fixed scenarios during training. When the scenario environment, equipment installation location, and operating conditions change, the model's recognition accuracy drops sharply, and the false alarm rate soars. This necessitates on-site re-collection and re-labeling of samples for training, resulting in extremely poor scenario generalization capabilities, high maintenance costs, and an inability to effectively guarantee the reliability of core analytical data.

[0005] The existing security systems have a serial and fragmented architecture for sensing, monitoring, and protection. After an alarm is triggered, most systems can only provide audible and visual alerts. The protection strategy is a rigid mode with fixed threshold triggers, which cannot be adaptively adjusted according to the actual risk level of the anomaly, the type of scenario, and business needs. In actual operation, two extreme problems may occur: one is the overprotection problem where minor anomalies trigger access control lockouts and equipment shutdowns, affecting normal production and operation; the other is the underprotection problem where high-risk anomalies only trigger audible and visual alarms, which may not be able to effectively avoid security risks. Summary of the Invention

[0006] To address the aforementioned problems and technical deficiencies, this application adopts the following technical solution: an active perception and protection monitoring system based on a multi-source fusion integrated machine, comprising a multi-source fusion integrated machine, wherein the multi-source fusion integrated machine is provided with an expansion interface compatible with multiple protocols, the expansion interface connecting to multi-source heterogeneous security perception terminals and protection execution terminals, and the system further comprising a hardware-level trusted perception synchronization unit, a lightweight cross-source spatiotemporal fusion unit, a self-supervised baseline-based intelligent early warning unit, a risk-level adaptive closed-loop protection unit, and a full-link trusted security and traceability evidence storage unit integrated within the multi-source fusion integrated machine; The input end of the hardware-level trusted perception synchronization unit is connected to each security perception terminal through an expansion interface, and the output end is connected to the input end of the lightweight cross-source spatiotemporal fusion unit. It is used to add nanosecond-level hardware synchronization timestamps to the raw perception data collected from each channel and complete spatial coordinate registration. After multi-dimensional trusted verification, it outputs lightweight perception features with dynamic trusted weights. The output of the lightweight cross-source spatiotemporal fusion unit is connected to the input of the self-supervised baseline-type intelligent early warning unit. It is used to dynamically allocate fusion weights based on the credibility weights of the input perception features and the protection priority of the current scene, to complete cross-source spatiotemporal deep fusion, and to construct a baseline of multi-source data association relationship in normal scenes through self-supervised learning, and output real-time fusion features and corresponding baseline deviation data. The output of the self-supervised baseline-type intelligent early warning unit is connected to the input of the risk classification adaptive closed-loop protection unit and the input of the full-link trusted security and traceability and evidence storage unit, respectively. It is used to classify the abnormal risk level based on the received baseline deviation and combined with multi-dimensional quantitative parameters, trigger the corresponding level of proactive early warning and output risk data synchronously. The command output end of the risk-level adaptive closed-loop protection unit is connected to each protection execution terminal through an extended interface. The data feedback end is connected to the optimization input end of the lightweight cross-source spatiotemporal fusion unit and the self-supervised baseline intelligent early warning unit. It is used to adaptively match the graded protection strategy based on real-time risk data and scene type and issue it for execution. After completing the closed-loop verification of the protection effect, it outputs the optimized data to the corresponding unit to complete the model iteration. The end-to-end trusted security and traceability evidence storage unit is bidirectionally connected to the other four units. It is used to isolate the system's core programs and data through a hardware-level trusted execution environment, monitor the operating status of the multi-source fusion all-in-one machine in real time, and complete the tamper-proof evidence storage and traceability management of key data across the entire chain.

[0007] Preferably, the multi-dimensional trust verification of the hardware-level trustworthy perception synchronization unit includes three levels of verification executed sequentially: Level 1 compliance verification, used to filter invalid data that exceeds the sensor's range or has abnormal format; Level 2 continuity verification, used to identify abnormal data caused by data drift and noise interference; Level 3 cross-source verification, used to verify the rationality of single-source data based on the correlation patterns of multi-source data in the same space and time, and finally assign a dynamic trustworthiness weight of 0-1 to each set of valid data.

[0008] Furthermore, when the lightweight cross-source spatiotemporal fusion unit dynamically allocates fusion weights, it assigns higher fusion weights to perception features with high credibility and high scene protection priority, automatically reduces the fusion weights of low credibility features, and performs deep fusion calculations only on cross-source features with high correlation.

[0009] Preferably, when the lightweight cross-source spatiotemporal fusion unit constructs the baseline of multi-source data association in a normal scene, it only needs unlabeled normal scene perception data to complete the baseline construction through self-supervised learning. At the same time, it incrementally updates the baseline based on the daily added normal scene data to adapt to normal changes in the scene.

[0010] Furthermore, when the self-supervised baseline-based intelligent early warning unit classifies abnormal risk levels, the multi-dimensional quantitative parameters used include: the deviation of the fused features from the normal baseline, the duration of the abnormal state, the range of the protection area involved in the abnormality, and the protection priority of the current scenario.

[0011] Preferably, the self-supervised baseline-based intelligent early warning unit can identify undefined unknown anomalies. Regardless of whether there are historical labeled samples for the anomaly type, as long as the deviation between the real-time fused features and the baseline of the correlation between the normal scene and the anomaly exceeds a set threshold, it can be identified as an anomaly and trigger an early warning of the corresponding level.

[0012] Preferably, the risk-level adaptive closed-loop protection unit is pre-set with a graded protection strategy library that corresponds one-to-one with risk level and scenario type. The strategy library includes protection strategies corresponding to four risk levels: low, medium, high, and extremely high. Low-risk strategies only trigger early warning prompts, medium-risk strategies trigger local linkage protection, high-risk strategies trigger global linkage protection, and extremely high-risk strategies trigger emergency isolation and alarm protection. Furthermore, when the risk-level adaptive closed-loop protection unit completes the closed-loop verification of the protection effect, it collects scene data after the protection is executed in real time through the security sensing terminal to verify the risk elimination effect. If the risk level does not decrease after protection, the protection strategy is automatically upgraded and re-executed. At the same time, the full process data of this protection is used as optimization data and fed back to the corresponding unit to complete the iterative optimization of the fusion baseline and risk-level model.

[0013] Furthermore, the hardware-level trusted execution environment of the end-to-end trusted security and traceability evidence storage unit is isolated from the embedded operating system of the multi-source fusion all-in-one machine. The core fusion algorithm, early warning model, and protection strategy library of the system are all deployed within the trusted execution environment. At the same time, the trusted execution environment monitors the all-in-one machine in real time for illegal login, program tampering, and permission change behaviors. When an anomaly is detected, it immediately triggers network disconnection isolation and core function lockout protection.

[0014] Furthermore, all core functions of the system support fully offline operation. In the absence of network access, local sensing data collection, fusion computing, intelligent early warning, protection execution, and data storage functions can all operate normally, and relevant data will be automatically synchronized after the network is restored.

[0015] Compared to existing technologies, the beneficial effects of this application are as follows: (1) This application integrates all core processing links into the local multi-source fusion all-in-one machine, without relying on the cloud SaaS platform, thus eliminating the latency problem caused by cloud transmission; at the same time, through self-supervised baseline intelligent early warning, it realizes 24-hour unmanned automatic anomaly identification and early warning, without the need for manual screen monitoring, and upgrades the core logic of the security system from post-event retrospective to full-process proactive protection of pre-event early warning, in-event handling, and post-event compliance traceability, effectively solving the core problems of passive protection, delayed early warning, and inability to perceive the incident in the existing technology; (2) This application uses a hardware-level three-level trusted verification mechanism to filter dirty data from the source and assign dynamic trust weights to each group of perceived data, so that the trustworthiness of the core analysis data is effectively guaranteed and the false alarm rate is reduced from the root. At the same time, self-supervised learning is used to construct the baseline of multi-source data association in normal scenarios. Only unlabeled normal scenario data is needed to complete model training and scenario adaptation. There is no need for a large number of abnormal labeled samples, the scenario adaptation cycle is effectively shortened, and the scenario generalization ability is significantly improved. Based on the abnormal identification logic of baseline deviation, there is no need to predefine the abnormal type. It can accurately identify new intrusions and unknown abnormal events that have not been predefined, thereby solving the core pain points of poor scenario generalization ability, inability to identify unknown abnormalities, and low data trustworthiness of existing solutions.

[0016] (3) This application completes the quantitative classification of abnormal risk levels based on multi-dimensional parameters, and has a pre-set hierarchical protection strategy library that corresponds one-to-one with risk level and scenario type. It can adaptively match the optimal protection strategy, taking into account both protection effect and business continuity, and effectively solves the problem of protection rigidity caused by fixed threshold triggering. At the same time, it constructs a complete protection closed loop of strategy matching-execution-effect verification-automatic upgrade-model optimization. After protection fails, the protection strategy can be automatically upgraded to complete the supplementary protection. It can also optimize the fusion baseline and early warning model through protection effect data to realize the self-iterative optimization of the system and greatly improve the overall reliability of the system. Attached Figure Description

[0017] In the attached diagram: Figure 1 This is a system diagram from an embodiment of this application. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of this application, but not all embodiments. Generally, the components of the embodiments of this application described and shown in the accompanying drawings can be arranged and designed in various different configurations.

[0019] Example 1: The multi-source fusion all-in-one machine in this embodiment uses domestically produced industrial-grade edge computing hardware. All core functional units are integrated into this all-in-one machine, and it can run independently without relying on a cloud server. The specific configuration is as follows: Main control and computing unit: It adopts Rockchip RK35888 64-bit processor with 6 TOPS computing power NPU and is equipped with a domestic embedded Linux operating system to meet the real-time operation requirements of lightweight algorithms at the edge. Hardware-level timing module: Built-in Beidou-3 timing chip, with a time synchronization accuracy of ±50ns, providing nanosecond-level hardware synchronization timestamps for all sensing data; Trusted Security Unit: Built-in national cryptographic level 2 security chip, supporting hardware-level isolated trusted execution environment technology features; Multi-protocol expansion interface: Configured with 8 PoE gigabit RJ45 network ports, 4 RS485 serial ports, and 8 DI / DO switch interfaces, compatible with mainstream security protocols such as ONVIF, GB28181, and Modbus-RTU / TCP, and can be directly connected to various heterogeneous security sensing terminals and protection execution terminals; Storage unit: 8GB LPDDR4 memory, 128GB industrial-grade SSD, supports up to 4TB SATA hard drive expansion, used for sensor data storage, algorithm model operation and end-to-end data storage; Power supply unit: DC12V / 5A industrial-grade wide voltage power supply, supporting DC9-36V input, suitable for complex power supply environments in outdoor industrial sites.

[0020] like Figure 1 As shown, the active sensing and protection monitoring system based on a multi-source fusion integrated machine includes: The hardware-level trusted awareness synchronization unit serves as the system's data source entry point. The specific implementation process is as follows: Hardware-level spatiotemporal synchronization processing: When the all-in-one machine collects raw data from each sensing terminal through the expansion interface, the Beidou time synchronization module adds an immutable nanosecond-level timestamp to each channel and each frame of raw data, which is bound to the hardware clock. At the same time, based on the installation spatial coordinates of each sensing terminal, spatial registration is performed on sensing data with different fields of view and different detection ranges to establish a unified perimeter spatial coordinate system, ensuring accurate matching of spatiotemporal data and solving the problems of time sequence misalignment and spatial mismatch of heterogeneous data.

[0021] Multi-dimensional three-level trust verification and trust weight calculation: For the original data that has completed spatiotemporal synchronization, three-level trust verification is performed sequentially, and the dynamic trust weight W of each group of valid data is calculated using a formula, with a value range of [0,1]. The calculation formula is as follows:

[0022] in, Level 1 compliance verification coefficient: when the data format and measurement range conform to the sensor specifications. =1, Invalid data due to exceeding the measurement range or abnormal format. =0, filter directly; The second-level continuity check coefficient is used to identify data drift and noise interference. The calculation formula is as follows:

[0023] in This is the current sampled value. This is the average of the sensor's normal data over the past 7 days. To correspond to the standard deviation, when hour, =0, which is considered abnormal data.

[0024] The three-level cross-source cross-validation coefficients are used to verify the rationality of the correlation patterns of multi-source data in the same space-time, and to verify the synchronous triggering of correlated sensors. =1, when there is no associated trigger. =0.3, for example, if a single IPC experiences screen anomalies while the park is closed at night, but the radar and vibration sensors do not trigger synchronously, then the data of that IPC is... =0.3, the credibility is greatly reduced; Lightweight feature output: For valid data that has been verified, feature extraction is performed through a lightweight convolutional neural network at the edge, and the perceptual features with dynamic confidence weights W are output to the lightweight cross-source spatiotemporal fusion unit. Only feature data is transmitted instead of the full amount of original data, reducing computing power consumption.

[0025] The lightweight cross-source spatiotemporal fusion unit is the core fusion foundation of the system. The specific implementation process is as follows: Dynamic fusion weight adaptive allocation: based on the confidence weight W of input-aware features and the protection priority of the current scene. Dynamic fusion weights are assigned to the features of each sensing source. The calculation formula is:

[0026] in, For the first The credibility weight of each sensing source comes from the output of the hardware-level trusted sensing synchronization unit; For the first The protection priority coefficient of each sensing source in the current scenario ranges from [0,1]. In this embodiment, the perimeter radar and vibration fiber optic cable are prioritized in a nighttime park-closed scenario. =0.9, office area IPC =0.3; In weekday work scenarios, access control controllers and entrance / exit IPCs =0.9, perimeter vibration fiber =0.4; To ensure the total number of connected sensing sources, normalization is performed. It achieves high-weight fusion of high-confidence and high-priority features, automatically reduces the weight of low-confidence features, and performs deep fusion calculation only on cross-source features with high correlation, balancing edge computing power and fusion accuracy.

[0027] Baseline Construction of Multi-Source Data Associations in Normal Scenarios: A baseline for normal scenarios is constructed through self-supervised learning. Training can be completed with only 7-14 days of unlabeled normal scenario perception data, without any anomaly labeled samples. The core of model learning is the inherent association patterns of multi-source data in normal scenarios (such as the steady-state associations of no vibration at the perimeter, no moving targets on the radar, and locked access control at night when the park is closed), rather than the fixed thresholds of a single sensor. At the same time, the model is incrementally updated daily based on newly added normal scenario data to adapt to normal data shifts caused by seasonal changes and equipment aging, thereby enhancing the scene generalization ability.

[0028] Cross-source spatiotemporal deep fusion is achieved based on dynamic weights, and real-time fused feature vectors are output. Simultaneously calculate the deviation between real-time fused features and the normal baseline. The deviation is output to the self-supervised baseline-based intelligent early warning unit. The lightweight Mahalanobis distance is used for calculation, and the formula is as follows:

[0029] in, The feature mean vector of the normal baseline. The covariance matrix of the fused features under normal scenarios is obtained through self-supervised learning pre-training.

[0030] The self-supervised baseline-based intelligent early warning unit is the core of the system's intelligent decision-making process. The specific implementation process is as follows: Multi-dimensional risk level quantification: based on baseline deviation from received data A risk quantification score is calculated by combining four dimensions of quantitative parameters. (Value range [0, 100]), the formula is:

[0031] in, To normalize the deviation, , The deviation threshold; weight =0.35 This is the normalized value for the duration of the anomaly. , The duration of the anomaly. =30s, weight =0.25; This is the normalized value for the range of impact of the anomaly. , The number of defense zones involved in the anomaly Total number of defense zones, weight =0.2; This is a normalized value for scene protection priority. , The highest priority coefficient for the anomaly affecting the defense zone, weighted by... =0.2; Based on the R value, there are four risk levels: R∈[0,25) is low risk, [25,50) is medium risk, [50,75) is high risk, and [75,100] is extremely high risk.

[0032] Proactive graded early warning triggering: According to the risk level, the corresponding early warning is triggered. Low risk is only marked by a pop-up window on the all-in-one machine and continuously tracked; medium risk and above are simultaneously pushed to the park security manager through multiple channels such as client push, SMS and voice call. The risk level, abnormal location and related video are simultaneously output to the risk graded adaptive closed-loop protection unit. No manual intervention is required throughout the process and the early warning response latency is ≤180ms.

[0033] Adaptive identification of unknown anomalies: Regardless of whether the anomaly type is predefined or whether there are historical labeled samples, as long as the deviation of the fused features is measured in real time... Exceeding the threshold =3 indicates an anomaly and triggers a corresponding warning.

[0034] Risk-based adaptive closed-loop protection unit, which is the core of the system's execution, is implemented as follows: Tiered protection strategy library preset: A pre-built protection strategy library that corresponds one-to-one with risk level and scenario type. The strategy library configuration in this embodiment is as follows: Low-risk strategy: Only trigger warning prompts, do not execute mandatory protective actions, and avoid over-protection; Medium-risk strategy: Triggering abnormal zones triggers LED supplementary lights, activates sound and light alarms, and uses smart loudspeakers to drive away occupants, without locking access control. High-risk strategies: Triggering an anomaly will lock all doors in the affected area, trigger a full-area audible and visual alarm, activate the one-button alarm device in the security room, and send an alert to the security manager; Extremely high-risk strategies: triggering full perimeter access control lockout, unnecessary power cut-off, police one-click alarm, and locking and storing all video recording data as evidence.

[0035] Adaptive policy matching and execution: Receives real-time risk data and scenario types, automatically matches corresponding protection policies, and directly sends instructions to the protection execution terminal through the all-in-one machine's extended interface, with an execution latency of ≤100ms and no need for cloud relay; at the same time, policy matching can adapt to the scenario.

[0036] Closed-loop verification and iterative optimization of protection effectiveness: After the protection command is issued, the scene data after the protection is executed is collected in real time through the security sensing terminal to verify the risk elimination effect; if the risk level does not decrease after protection, the protection strategy is automatically upgraded and re-executed; after the protection is completed, the full process data of this protection is used as optimization data and fed back to the lightweight cross-source spatiotemporal fusion unit and the self-supervised baseline-type intelligent early warning unit to complete the incremental optimization of the fusion baseline and risk classification model, forming a complete closed-loop link.

[0037] The end-to-end trusted security and traceability evidence storage unit is the underlying security guarantee of the system. The specific implementation process is as follows: Hardware-level Trusted Execution Environment (TEE) protection: The system's core fusion algorithm, early warning model, protection strategy library, and hash encryption key are all deployed within the TEE, completely isolated from the embedded operating system. External programs cannot access, tamper with, or reverse engineer the core data within the TEE. At the same time, the TEE monitors the all-in-one machine in real time for illegal logins, program tampering, permission changes, and network attacks. When an anomaly is detected, it immediately triggers network isolation, locks core functions, and encrypts and protects local data to prevent the system from being maliciously attacked and rendered ineffective.

[0038] End-to-end tamper-proof evidence storage and traceability: All key data across the entire system chain, including original sensing data, credibility weights, fusion features, early warning records, risk level assessment criteria, protection command issuance records, protection effect verification data, and system operation logs, are hash-encrypted using the national cryptographic SM3 algorithm and chain-stored after being bound to hardware timestamps, making them tamper-proof and undeletable. In post-event traceability, the entire process data of abnormal events can be fully traced back, making up for the shortcomings of existing methods that only record video for traceability.

[0039] Offline operation guarantee: All core functions of the system support complete offline operation. In the absence of network, local sensing data collection, fusion computing, intelligent early warning, protection execution, and data storage functions can all operate normally. After the network is restored, relevant data will be automatically synchronized. The entire process of protection and monitoring can be completed independently without relying on the cloud SaaS platform.

[0040] In practical use, the steps include: Initialization and baseline construction phase: After the all-in-one machine is powered on, it completes the docking and hardware time synchronization of various sensing terminals and execution terminals, collects unlabeled sensing data of the park's normal operation for 7 days, and completes the construction of the baseline of normal scene correlation through self-supervised learning, thus completing system initialization.

[0041] During routine monitoring: The system continuously collects multi-source sensing data 24 hours a day, completes hardware-level spatiotemporal synchronization and three-level trust verification, outputs lightweight features with trust weights, performs cross-source fusion calculations in real time, compares with normal baselines to determine if there are any anomalies, and the computing power usage is ≤35% under normal operation, meeting the long-term stable operation requirements of the edge.

[0042] Anomaly identification and early warning protection phase: When abnormal behavior such as personnel crossing the perimeter occurs at night, vibration fiber optics, radar, IPC, and thermal imager simultaneously collect abnormal data. After three levels of verification, high-confidence features are output. After fusion calculation, the deviation D=4.2, exceeding the threshold of 3. The system calculates a risk score R=78, which is judged as extremely high risk. An early warning is immediately pushed to the security manager, and at the same time, extremely high risk protection strategies are issued, such as locking the perimeter access control, triggering the sound and light alarm, linking with the public security one-click alarm, and locking all video recording data.

[0043] Closed-loop verification and optimization phase: After the protection command is executed, the system verifies the protection effect in real time through the sensing terminal. After confirming that the abnormal personnel have been driven away and the risk has been eliminated, the protection process ends. At the same time, the entire process data of this abnormal event is fed back to the fusion unit and the early warning unit to complete the incremental optimization of the model and further reduce the subsequent false alarm rate.

[0044] Offline operation phase: When the park network is interrupted, the system automatically switches to offline operation mode. All core functions operate normally. There is no data loss or functional failure within 72 hours of network outage. After the network is restored, the evidence storage data and event records during the network outage period are automatically synchronized.

[0045] The above embodiments only illustrate preferred embodiments of this application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of this application's patent. It should be noted that those skilled in the art can make various modifications, improvements, and substitutions without departing from the concept of this application, and these all fall within the protection scope of this application.

Claims

1. An active sensing and protection monitoring system based on a multi-source fusion integrated machine, comprising a multi-source fusion integrated machine, wherein the multi-source fusion integrated machine is provided with an expansion interface compatible with multiple protocols, the expansion interface connecting to multi-source heterogeneous security sensing terminals and protection execution terminals, characterized in that, The system also includes a hardware-level trusted perception synchronization unit, a lightweight cross-source spatiotemporal fusion unit, a self-supervised baseline-type intelligent early warning unit, a risk-level adaptive closed-loop protection unit, and a full-link trusted security and traceability evidence storage unit integrated into the multi-source fusion all-in-one machine. The input end of the hardware-level trusted perception synchronization unit is connected to each security perception terminal through an expansion interface, and the output end is connected to the input end of the lightweight cross-source spatiotemporal fusion unit. It is used to add nanosecond-level hardware synchronization timestamps to the raw perception data collected from each channel and complete spatial coordinate registration. After multi-dimensional trusted verification, it outputs lightweight perception features with dynamic trusted weights. The output of the lightweight cross-source spatiotemporal fusion unit is connected to the input of the self-supervised baseline-type intelligent early warning unit. It is used to dynamically allocate fusion weights based on the credibility weights of the input perception features and the protection priority of the current scene, to complete cross-source spatiotemporal deep fusion, and to construct a baseline of multi-source data association relationship in normal scenes through self-supervised learning, and output real-time fusion features and corresponding baseline deviation data. The output of the self-supervised baseline-type intelligent early warning unit is connected to the input of the risk classification adaptive closed-loop protection unit and the input of the full-link trusted security and traceability and evidence storage unit, respectively. It is used to classify the abnormal risk level based on the received baseline deviation and combined with multi-dimensional quantitative parameters, trigger the corresponding level of proactive early warning and output risk data synchronously. The command output end of the risk-level adaptive closed-loop protection unit is connected to each protection execution terminal through an extended interface. The data feedback end is connected to the optimization input end of the lightweight cross-source spatiotemporal fusion unit and the self-supervised baseline intelligent early warning unit. It is used to adaptively match the graded protection strategy based on real-time risk data and scene type and issue it for execution. After completing the closed-loop verification of the protection effect, it outputs the optimized data to the corresponding unit to complete the model iteration. The end-to-end trusted security and traceability evidence storage unit is bidirectionally connected to the other four units. It is used to isolate the system's core programs and data through a hardware-level trusted execution environment, monitor the operating status of the multi-source fusion all-in-one machine in real time, and complete the tamper-proof evidence storage and traceability management of key data across the entire chain.

2. The active sensing and protection monitoring system based on a multi-source fusion integrated machine according to claim 1, characterized in that, The hardware-level trusted sensing synchronization unit's multi-dimensional trusted verification includes three levels of verification executed sequentially: Level 1 compliance verification, used to filter invalid data that exceeds the sensor's range or has abnormal format; Secondary continuity check is used to identify abnormal data caused by data drift and noise interference; The three-level cross-source cross-validation is used to verify the rationality of single-source data based on the correlation patterns of multi-source data in the same space and time, and finally assigns a dynamic credibility weight of 0-1 to each group of valid data.

3. The active sensing and protection monitoring system based on a multi-source fusion integrated machine according to claim 1, characterized in that, When the lightweight cross-source spatiotemporal fusion unit dynamically allocates fusion weights, it assigns higher fusion weights to perception features with high credibility and high scene protection priority, automatically reduces the fusion weights of low credibility features, and performs deep fusion calculations only on cross-source features with high correlation.

4. The active sensing and protection monitoring system based on a multi-source fusion integrated machine according to claim 1, characterized in that, When constructing the baseline of multi-source data association in a normal scene, the lightweight cross-source spatiotemporal fusion unit only needs unlabeled normal scene perception data to complete the baseline construction through self-supervised learning. At the same time, the baseline is incrementally updated based on the daily added normal scene data to adapt to normal changes in the scene.

5. The active sensing and protection monitoring system based on a multi-source fusion integrated machine according to claim 1, characterized in that, When classifying abnormal risk levels, the self-supervised baseline-based intelligent early warning unit uses multi-dimensional quantitative parameters, including: the deviation of the fused features from the normal baseline, the duration of the abnormal state, the range of the protection area involved in the abnormality, and the protection priority of the current scenario.

6. The active sensing and protection monitoring system based on a multi-source fusion integrated machine according to claim 1, characterized in that, The self-supervised baseline-based intelligent early warning unit can identify undefined unknown anomalies. Regardless of whether there are historical labeled samples for the anomaly type, as long as the deviation between the real-time fused features and the baseline of the correlation between the normal scene and the anomaly exceeds the set threshold, it can be identified as an anomaly and trigger an early warning of the corresponding level.

7. The active sensing and protection monitoring system based on a multi-source fusion integrated machine according to claim 1, characterized in that, The risk-level adaptive closed-loop protection unit is pre-set with a graded protection strategy library that corresponds one-to-one with risk level and scenario type. The strategy library includes protection strategies corresponding to four risk levels: low, medium, high, and extremely high. Low-risk strategies only trigger early warning prompts, medium-risk strategies trigger local linkage protection, high-risk strategies trigger global linkage protection, and extremely high-risk strategies trigger emergency isolation and alarm protection.

8. The active sensing and protection monitoring system based on a multi-source fusion integrated machine according to claim 1, characterized in that, When the risk-level adaptive closed-loop protection unit completes the closed-loop verification of the protection effect, it collects scene data after the protection is executed in real time through the security sensing terminal to verify the risk elimination effect. If the risk level does not decrease after protection, the protection strategy is automatically upgraded and re-executed. At the same time, the entire process data of this protection is used as optimization data and fed back to the corresponding unit to complete the iterative optimization of the fusion baseline and risk-level model.

9. The active sensing and protection monitoring system of the multi-source fusion integrated machine according to claim 1, characterized in that, The hardware-level trusted execution environment of the end-to-end trusted security and traceability evidence storage unit is isolated from the embedded operating system of the multi-source fusion all-in-one machine. The core fusion algorithm, early warning model and protection strategy library of the system are all deployed in the trusted execution environment. At the same time, the trusted execution environment monitors the all-in-one machine in real time for illegal login, program tampering and permission change behavior. When an anomaly is detected, it immediately triggers network disconnection isolation and core function lockout protection.

10. The active sensing and protection monitoring system of the multi-source fusion integrated machine according to claim 1, characterized in that, All core functions of the system support fully offline operation. In the absence of network access, local sensing data collection, fusion computing, intelligent early warning, protection execution, and data storage functions can all operate normally, and relevant data will be automatically synchronized after the network is restored.