Intelligent identification and joint disposal method and system for complex emergency accidents of commercial complex
By dividing large commercial complexes into operational continuity units, collecting various operational indicators to generate state vectors, establishing collaborative boundaries and permitted boundaries, and combining mechanism consistency and stable operation verification, the complex accident chain is locked and a joint response action package is generated. This solves the problem of identifying and coordinating the response to complex emergency accidents in large commercial complexes, and achieves early identification and precise response.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHAOTONG LIANGFENGTAI INFORMATION TECH CO LTD
- Filing Date
- 2026-05-06
- Publication Date
- 2026-07-24
AI Technical Summary
Existing technologies struggle to identify and handle complex emergency incidents in large commercial complexes, especially those that disrupt operational continuity and cause resource conflicts between multiple units due to events such as elevator malfunctions and gas anomalies, lacking effective cross-verification and coordinated response mechanisms.
By dividing commercial complexes into operational continuity units, collecting various operational indicators to generate state vectors, establishing collaborative boundaries and permission boundaries, combining mechanism consistency and stable operation verification, locking in complex accident chains, generating joint disposal action packages, and updating rules in a closed loop.
It enables early identification and precise handling of complex emergency incidents, reduces the risk of misjudgment and resource conflicts, and improves the robustness and adaptability of the system.
Smart Images

Figure CN122453576A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of emergency response technology, specifically to a method and system for intelligent identification and joint handling of complex emergency incidents in commercial complexes. Background Technology
[0002] Large commercial complexes typically encompass multiple functional areas, including retail, dining, cinemas, entertainment, transportation hubs, and equipment rooms. They are characterized by complex spatial structures, numerous vertical transportation routes, high population density, and rapidly changing operational status. When incidents occur within a commercial complex, such as elevator malfunctions, gas outages, localized congestion, security alarms, restricted broadcasting, or blocked passageways, they often involve not only single safety issues but also simultaneous disruptions to business continuity, such as queue buildup, transaction interruptions, personnel relocation, and secondary congestion. In such scenarios, the on-site situation includes not only safety factors such as fire safety, equipment safety, and access control, but also operational factors such as customer flow, transactions, and occupancy behavior. Traditional single-source monitoring or fixed contingency plans are insufficient to fully reflect the formation and propagation of an incident.
[0003] One type of existing technology mainly focuses on risk monitoring, early warning classification, and hazard management in commercial areas or large commercial complexes. For example, patent document CN112163732A proposes a method for constructing a risk early warning system and classifying early warning levels for typical commercial areas. By establishing a risk indicator system, calculating indicator weights, and performing fuzzy comprehensive evaluation, the target area is mapped to the current risk warning level. Another example is patent document CN111008781A, which proposes a resource dispatching method applied to the field of fire protection. By collecting basic information on alarm situations, implementing alarm classification, matching structured contingency plans, and initiating dispatching schemes, an emergency closed loop from alarm identification to resource dispatching is formed. By combining remote monitoring, passenger flow monitoring, gas leak alarms, electrical fire monitoring, and facility inspection in the fire risk management of large commercial complexes, existing technologies can establish basic perception and graded response conditions for commercial complexes. However, they still have certain limitations. For example, their monitoring objects are mostly centered on fire risk, alarm level, equipment risk, or facility status. Operational signals such as changes in passenger flow, transaction fluctuations, abnormal member stays, and changes in vertical transportation capacity are usually not included in a unified judgment framework. Therefore, it is not conducive to identifying the complex accident process that gradually evolves from equipment abnormalities to operational instability.
[0004] Another type of existing technology focuses on dynamic evacuation navigation and path planning. For example, patent document CN109472411A proposes an adaptive emergency evacuation navigation system for large commercial complexes, which periodically updates evacuation paths through fire monitoring, personnel positioning, infrared situation assessment, and dynamic path planning. Related research schemes also express indoor fire scenarios through an integrated spatiotemporal model of entities, states, and actions, and serve evacuation strategy reasoning. Existing technologies can improve evacuation guidance in single fire scenarios through dynamic path replanning, but they still have certain limitations. For example, their starting point is usually a confirmed accident or hazard distribution, and they pay insufficient attention to signs of business continuity disruption before accident confirmation. They also rarely deal with the chain propagation problem when elevator malfunctions, transaction disruptions, queues at alternative routes, and personnel migration overlap. Therefore, they are difficult to adapt to the needs of early identification and joint handling of complex emergency accidents in commercial complexes.
[0005] In addition, existing technologies also include emergency decision-making and monitoring solutions based on knowledge graphs, rule-based reasoning, case-based reasoning, and operational anomaly analysis. For example, patent document CN116681305A proposes an emergency decision-making method for sudden events based on knowledge graphs. It constructs a knowledge graph using historical event data and retrieves response and safeguard measures based on keywords to form an emergency decision-making plan. Patent document US20160371613A1 uses historical sales frequency data to compare with current POS data to detect retail sales anomalies. Patent document US20190213607A1 further associates POS transaction data with the physical location of shelves to reconstruct customer dwell areas and distribution. These solutions typically generate handling suggestions or management prompts through event classification, rule matching, knowledge retrieval, case similarity calculation, or operational anomaly analysis, and have certain application value in single alarm situations, single accident types, general emergencies, or retail operation monitoring scenarios. Existing technologies can improve the efficiency of solution generation or the ability to detect operational anomalies through knowledge organization, rule reasoning, and operational data analysis, but they still have certain limitations. For example, there is a lack of cross-verification mechanisms between security perception data and operational data such as customer flow, transactions, and member stay; there is a lack of reverse verification to determine whether accident candidates truly lead to a break in business continuity; there is a lack of constraints on the propagation direction and node transfer conditions between multiple units; and there is insufficient consideration of resource conflicts, action degradation, and rule rollback under conditions of multiple concurrent accidents. Therefore, it is difficult to form a closed-loop handling mechanism that fits the actual operating characteristics of commercial complexes.
[0006] Therefore, there is an urgent need for an intelligent identification and joint handling method and system for complex emergency incidents in commercial complexes. This system would unify the internal security status, access status, and operational status of the commercial complex into a calculable expression of operational continuity, establish a cross-verification relationship between security perception anomalies and operational continuity disruptions, and combine propagation direction, node transfer conditions, recovery benefits, and handling and recovery records to complete the chain locking, joint handling, and rule closed-loop update of complex incidents. This would provide a more favorable technical implementation path for the identification and coordinated handling of complex emergency incidents in commercial complexes. Summary of the Invention
[0007] The purpose of this invention is to overcome the shortcomings of the prior art and propose an intelligent identification and joint handling method and system for complex emergency incidents in commercial complexes, so as to solve the above-mentioned problems.
[0008] The objective of this invention is achieved through the following technical solution: a method for intelligent identification and joint handling of complex emergency incidents in commercial complexes, comprising the following steps: S1, dividing the commercial complex into business continuity units according to region, floor, and business type, and collecting data on the rate of change in the number of people entering and leaving, the distribution of dwell time, the rate of change in queue length, the transaction initiation rate, the transaction completion rate, the refund and cancellation rate, the abnormality of member dwell time, the vertical transportation throughput rate, the security perception status, and the availability of emergency facilities for each business continuity unit; S2, generating collaborative edges for each business continuity unit based on historical normal operating data, activity plans, and business type attributes. The collaborative boundary defines at least the upper limit of traffic phase difference, the upper limit of transaction deviation, and the upper limit of recovery time. Based on the collaborative boundary, an operational continuity state vector is generated. A continuity break signature is determined when the traffic phase difference, transaction deviation, queuing pressure index, vertical traffic congestion index, abnormal member dwell time index, and recovery delay factor exceed the collaborative boundary. S3: When any of the following occurs—an abnormal security perception state or the establishment of a continuity break signature—an incident candidate is generated. A contradiction check is performed on the incident candidate, including at least a mechanism consistency check and a stable operation check. The mechanism consistency check is used to determine the incident candidate. The system checks whether a continuity break signature consistent with the mechanism of an accident candidate appears in the corresponding area within a predetermined time window. Stable operation verification determines whether there is evidence of stable operation corresponding to transaction synchronization, traffic recovery, and maintenance of traffic capacity in the area corresponding to the accident candidate. If the mechanism consistency verification passes and stable operation evidence does not exist, the accident candidate that passes the contradiction verification is identified. S4: For the accident candidate that passes the contradiction verification, the composite accident chain is locked according to the propagation direction of the continuity break signature and node transfer conditions. S5: For each composite accident chain, a handling action package containing safety actions, traffic diversion actions, and operational intervention actions is generated. Based on the recovery benefits corresponding to each disposal action package, a joint disposal plan is determined to restore the target business continuity unit to within the permitted boundary; S6, after the joint disposal is completed, the evolution of the business continuity status before, during and after the disposal is extracted to form a disposal recovery record. Based on the disposal recovery record, the impact of candidate rules on recovery time, false alarm escalation rate and resource conflicts in similar scenarios is verified. The rule is only implemented when the recovery time is shortened, the false alarm escalation rate is reduced and no new resource conflicts are introduced. If the aforementioned conditions are not met, the rule is frozen. If any of the following situations occur after implementation: recovery time deteriorates or false alarm freezing fails, the rule is rolled back.
[0009] The operational continuity state vector consists of the rate of change in the number of people entering and leaving, the distribution of dwell time, the rate of change in queue length, the transaction initiation rate, the transaction completion rate, the refund and cancellation rate, the abnormality of member dwell time, the vertical traffic throughput, the security perception status, and the availability of emergency facilities. The continuity break signature consists of the flow phase difference, the transaction deviation, the queue pressure index, the vertical traffic congestion index, the abnormality of member dwell time, and the recovery delay factor.
[0010] The permission boundary is determined based on the coordination boundary and is used to characterize the boundary state where the target business continuity unit recovers to the point where the flow phase difference, transaction deviation magnitude, and recovery time do not exceed the corresponding upper limit, and the queuing pressure index and vertical traffic congestion index fall back to the predetermined stabilization range.
[0011] Evidence of stable operation is generated from the transaction synchronization status, traffic recovery status, and traffic capacity maintenance status of the area corresponding to the accident candidate, and is only considered to exist when the transaction synchronization status, traffic recovery status, and traffic capacity maintenance status are all valid.
[0012] The complex accident chain includes at least the initial disturbance event, the propagation event, the business continuity disruption event, and the secondary risk event. The node transfer conditions include at least the decline in vertical transportation availability, the queuing pressure of alternative channels exceeding the coordination boundary, the decline in transaction completion rate, and the increase in local density and the decrease in speed distribution.
[0013] Recovery benefits are determined based on the speed at which queuing pressure decreases, the slope of transaction recovery, the magnitude of the decrease in false alarm escalation rate, and the time for secondary congestion to be resolved. The action package with the best recovery benefits is selected as the joint handling plan.
[0014] Candidate rules undergo manual review before being implemented. This manual review is used to confirm that the node transfer conditions, action package selection conditions, freeze thresholds, and recovery records corresponding to the candidate rules are consistent with the records.
[0015] A smart identification and joint response system for complex emergency incidents in commercial complexes includes an operational continuity modeling module, a continuity rupture signature extraction module, a dual-gate trigger judgment module, a complex incident chain locking module, a joint response module, and a rule closed-loop update module. The operational continuity modeling module establishes operational continuity units based on region, floor, and business type, and generates operational continuity state vectors. The continuity rupture signature extraction module extracts continuity rupture signatures based on collaborative boundaries. The dual-gate trigger judgment module generates incident candidates and performs mechanism consistency verification and stable operation verification. The complex incident chain locking module locks the complex incident chain according to the propagation direction of the continuity rupture signature and node transfer conditions. The joint response module determines a joint response plan based on recovery benefits and restores the target operational continuity unit to within the permitted boundaries. The rule closed-loop update module executes the online, frozen, and rolledback of candidate rules based on the response and recovery records.
[0016] The dual-gate trigger judgment module includes an accident candidate gate and a contradiction verification gate. The accident candidate gate is used to generate accident candidates when any of the following situations occur: abnormal security perception status or continuity break signature is established. The contradiction verification gate is used to perform mechanism consistency verification and stable operation verification on the accident candidates.
[0017] The rule closed-loop update module is used to extract the evolution of the operational continuity status before, during and after the disposal to form a disposal recovery record, and to determine the online status, frozen status and rollback status of the candidate rule based on the changes in recovery time, false alarm escalation rate and resource conflict in similar scenarios.
[0018] The beneficial effects of this invention are: This invention uses operational continuity units as the internal state organization objects of commercial complexes, and constructs an operational continuity state vector by combining the rate of change in the number of people entering and exiting, the distribution of dwell time, the rate of change in queue length, the transaction initiation rate, the transaction completion rate, the refund and cancellation rate, the abnormality of member dwell time, the vertical transportation throughput rate, the security perception status, and the availability of emergency facilities. Simultaneously, it determines the collaborative boundaries and permitted boundaries between adjacent units. Compared to existing technologies that treat security alarms, passenger flow statistics, and operational indicators in isolation, this invention unifies the security status, passage status, and operational status of the same spatial unit within the same continuous expression framework. This provides a consistent basis for identifying whether operational order has been disrupted, and is beneficial for detecting abnormal evolution trends before an incident becomes fully apparent.
[0019] The continuity disruption signature is determined by combining traffic phase difference, transaction deviation, queuing pressure index, vertical traffic congestion index, member dwell anomaly index, and recovery delay factor. Compared to existing technologies that easily misjudge short-term passenger flow fluctuations, local queuing congestion, or transaction pulses as accident events, this invention uses the synergistic mismatch relationship between multiple sources of operational continuity characteristics to identify disruption features. This elevates the judgment criteria from single-point anomalies to multi-dimensional state-coupled anomalies, helping to improve the targeting of early identification of complex emergency incidents and providing a more stable pre-input for subsequent accident chain locking.
[0020] After generating incident candidates, a mechanism consistency check and a stable operation check are further implemented to form a dual-trigger structure. Compared to existing technologies that directly trigger a high-level response upon the occurrence of a security anomaly or presume incident spread based solely on a single abnormality in operational indicators, this invention requires, on the one hand, that the candidate and the business continuity disruption signature be consistent in their formation mechanism; and on the other hand, it requires reverse verification of stable operation evidence to distinguish between scenarios of normal operation but occasional disturbances and scenarios of genuine, ongoing incidents. This structure reduces the risk of false escalation and false linkage, and provides a more suitable identification path for events that are highly concealed but have already caused damage to business continuity.
[0021] After identifying candidate incidents, a complex incident chain is locked based on the propagation direction coefficient and node transfer conditions. Compared to existing technologies where the chain-like inference boundary is too wide and parallel anomalies are easily mistaken for causal diffusion, this invention requires an interpretable progression relationship between upstream and downstream units in terms of passenger flow migration, channel capacity, operational disruption, and facility status changes. The incident chain is only allowed to continue extending when the node progression conditions are met. This makes the generation process of the complex incident chain closer to the actual propagation path within the commercial complex, which is conducive to concentrating coordinated response resources on key nodes that are more likely to experience interconnected instability.
[0022] This invention combines safety actions, traffic control actions, and operational intervention actions into a joint response action package, and evaluates and selects candidate action packages based on recovery benefits. Compared to existing technologies that only issue fixed safety actions according to pre-planned procedures or take lockdown measures solely from a security perspective, this invention incorporates personnel safety, traffic restoration, and business continuity restoration into the same response evaluation framework. It selects action packages based on their comprehensive effects on restoring the target unit's permitted boundaries, mitigating congestion transmission, and inhibiting the spread of operational disruptions. This approach can provide more favorable conditions for the target unit to quickly return to a controllable operational state while meeting emergency response requirements, and reduces unnecessary disruptions to commercial operations caused by single response strategies.
[0023] Based on the handling and recovery records, candidate rules are manually reviewed before being put online, frozen, or rolled back. Compared to existing technologies that mainly rely on the number of hits, experience thresholds, or statically preset long-term retention rules, this invention links the rule lifecycle with the actual recovery results after handling, conflict situations, and consequences of accidental triggering. This ensures that rules are not only responsible for the identification results but also for whether handling promotes continuous recovery. Through this closed-loop mechanism, rules that are incompatible with the scenario or cause side effects can be continuously eliminated, while a set of rules that better matches the actual operating state of the commercial complex can be gradually retained, thereby helping to maintain the long-term stability and maintainability of the system.
[0024] Furthermore, this invention establishes degradation, freezing, recovery, and retrospective writing mechanisms to address issues such as limited data sources, execution resource conflicts, link freezes, state recovery, and replay-based supplementary judgments. Compared to existing technologies that are prone to system shutdowns, erroneous chain expansion, or inability to verify historical judgments under conditions of partial data loss or multiple concurrent incidents, this invention can automatically narrow the scope of judgment and handling based on data availability and action executability. It freezes the chain-like progression when conditions are insufficient and performs supplementary judgments and retrospective writing after conditions are restored. This enables the maintenance of basic judgment capabilities and record integrity under concurrent conditions in complex commercial complexes, contributing to improved robustness, traceability, and adaptability to edge scenarios during project implementation. Attached Figure Description
[0025] Figure 1 The process of this invention Figure 1 ; Figure 2 The process of this invention Figure 2 ; Figure 3 The process of this invention Figure 3 . Detailed Implementation
[0026] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0027] Example 1 like Figure 1 As shown, this embodiment uses a four-story commercial space comprising a cinema area, a dining area, and an atrium area of a commercial complex as the implementation target. The commercial complex is equipped with video passenger flow acquisition devices, anonymous trajectory aggregation devices, cashier transaction data acquisition terminals, member attendance identification terminals, elevator and escalator operation monitoring terminals, fire and broadcast status acquisition terminals, and emergency facility status acquisition terminals on each floor. Each terminal is connected to a central decision-making server via a floor edge gateway. The central decision-making server communicates with broadcast controllers, elevator control equipment, evacuation route access control, security dispatch terminals, and rule review terminals. The original sampling period for video passenger flow is set to 2 seconds, and the original sampling period for elevator control and fire status is set to 1 second. Cashier transaction data and member attendance records are uploaded via event triggering. The central decision-making server aligns all data sources with a uniform operating cycle of 30 seconds and uses the most recent 5 minutes as the current incident judgment window.
[0028] In this implementation, operational continuity units are first divided according to area, floor, and business type. Each operational continuity unit is bound to an actual operating area, a floor identifier, a business type label, a vertical transportation association group, at least one set of alternative passages, and a set of emergency facilities corresponding to that area. Taking the waiting area of a four-story cinema as an example, the waiting area of the four-story cinema and its two directly associated passenger elevators, one set of escalators, and one spare staircase are defined as an operational continuity unit; this unit is also associated with the waiting area's cashier, ticket gate, member service desk, and broadcasting area. If the same area corresponds to different vertical transportation paths and the failure of each path will cause different propagation directions, multiple operational continuity units are established in that area to ensure that the vertical transportation throughput, queue length change rate, and transaction completion rate can correspond to the same propagation chain.
[0029] After the business continuity unit is established, the system generates a collaboration boundary for each business continuity unit. The collaboration boundary is established using normal operating data from nearly 30 similar business days for that unit. Similar business days refer to business days with consistent business types, consistent activity status, and no equipment failures or security incidents. Boundary versions are established for weekday off-peak, weekday evening peak, weekend peak, and special event days, and the upper limits of phase difference, transaction deviation, recovery time, queuing pressure, vertical traffic congestion, and abnormal member dwell time are written into the corresponding versions. The collaboration boundary for the waiting area of the four-story cinema in the evening exit scenario can be set as follows: the expected phase difference from the change in passenger flow to the change in transaction initiation is 90 seconds, the upper limit of phase difference is 120 seconds, the upper limit of transaction deviation is 0.35, the upper limit of queuing pressure is 1.10, the upper limit of vertical traffic congestion is 0.40, the upper limit of abnormal member dwell time is 0.30, and the upper limit of recovery time is 6 minutes. The above values are written as the default values for the evening session boundary version of this unit, and can be recalibrated according to the same standard when there are long-term structural changes in passenger flow.
[0030] The permissible boundary is determined based on the collaborative boundary and used as a stabilization criterion after the joint response ends. In this embodiment, the permissible boundary does not reintroduce an independent criterion, but requires the business continuity unit to simultaneously meet the following conditions for three consecutive operating cycles: the flow phase difference does not exceed the upper limit of the corresponding collaborative boundary, the transaction deviation does not exceed the upper limit of the corresponding collaborative boundary, the queuing pressure index does not exceed 1.00, the vertical traffic congestion index does not exceed 0.20, and the cumulative recovery time since the incident candidate generation time does not exceed the upper limit of the recovery time corresponding to the boundary version. The aforementioned queuing pressure index and vertical traffic congestion index together constitute the predetermined stabilization range of the business continuity unit. If any of these conditions is breached again within three consecutive operating cycles, the system keeps the incident chain in an unresolved state and does not consider the business continuity unit to have recovered to within the permissible boundary.
[0031] Within each 30-second operating cycle, the system generates an operational continuity state vector for each operational continuity unit. This state vector includes at least the rate of change in the number of people entering and leaving, the distribution of dwell time, the rate of change in queue length, the transaction initiation rate, the transaction completion rate, the refund and cancellation rate, the abnormality of member dwell time, the vertical transportation throughput rate, the security perception status, and the availability of emergency facilities. The following metrics are used to determine the change rate of the number of people entering and exiting: the relative change between the number of people entering in the current period and the moving average number of people entering in the previous 5 minutes; the dwell time distribution is obtained by statistically analyzing the time difference between the entry and exit of the same object in the anonymous trajectory; the queue length change rate is obtained by summarizing the queue identification results of elevator halls, escalator entrances, cash registers, and ticket gates; the transaction initiation rate is obtained by dividing the number of new orders created in the current period by the period duration; the transaction completion rate is obtained by dividing the number of successfully paid orders in the current period by the period duration; the refund and cancellation rate is calculated from the refund, cancellation, and abnormal ticket refund records in the most recent hour; the member dwell time anomaly is determined by the degree of deviation of the member's dwell time in the unit from the upper limit of the historical quartile of the unit; the vertical traffic throughput rate is determined by the number of people actually passing through elevators, escalators, and backup staircases per unit time; the security perception status is synthesized from the highest level of smoke detectors, temperature detectors, access control anomalies, equipment failures, and manual alarms; and the emergency facility availability is obtained by weighting the availability status of broadcasts, fire exits, emergency lighting, and backup evacuation doors. If a source data source is missing one running cycle, the stable value of the previous cycle will be used and the data integrity will be marked as "restricted". If two consecutive running cycles are missing, the boundary update corresponding to the source data source will be frozen, and only the incident verification function will be retained. No new rule update conclusions will be generated based on this.
[0032] Instead of using a single threshold, the extraction of continuity-breaking signatures calculates flow phase difference, transaction deviation, queuing pressure index, vertical traffic congestion index, member dwell anomaly index, and recovery delay factor separately, and projects them onto the same judgment criterion. Flow phase difference describes the time misalignment between a surge in passenger flow and the response to transaction initiation or completion. In this embodiment, the difference between the peak passenger flow entry rate and the peak transaction initiation rate within the most recent 5 minutes is taken as the observed phase difference, denoted as [missing information]. Take the expected phase difference in the boundary version corresponding to the operating continuity unit as... Take the upper limit of the phase difference in this boundary version as Then the first The flow phase difference for each operating cycle is determined by the following formula: when A value greater than 1 indicates that the time misalignment between the arrival of customers and the initiation of transactions has exceeded the normal coordination boundary of the business continuity unit.
[0033] Transaction deviation is used to characterize the degree of imbalance between changes in customer flow and changes in transaction completion. Let the first... Passenger flow change rate per operating cycle The transaction completion rate changed to Both are normalized based on the previous 5-minute moving average, and the trading divergence is determined by the following formula: When customer traffic increases rapidly while the transaction completion rate decreases simultaneously, or when customer traffic decreases rapidly while the refund and cancellation rate increases simultaneously, It will increase rapidly. To avoid false triggering due to short-term fluctuations, this implementation method requires... A trading divergence is considered valid only if it is greater than 0.35 for two consecutive operating cycles.
[0034] The queuing pressure index is determined by the ratio of the current number of people in the queue to the number of people that the associated alternative channel can handle within 5 minutes. If the alternative channel can handle 35 people within 5 minutes and the current number of people in the queue is 43, then the queuing pressure index is 1.23. The vertical traffic congestion index is determined by "1 minus the ratio of the current vertical traffic throughput to the normal boundary throughput." When the normal vertical traffic throughput is 0.92 people / s at the end of the evening session, and the current throughput drops to 0.28 people / s, then the vertical traffic congestion index is 0.70. The abnormal member dwell time index is determined by the percentage of members exceeding the upper quartile of the historical data. The recovery delay factor is determined by the ratio of the duration of continuous boundary crossing of the core indicator to the upper limit of the recovery time. Based on the above six components, the system generates a continuity break signature strength value: in, Queuing pressure index This is a vertical traffic congestion index. The abnormal member dwell time index To restore the delay factor. All weights are non-negative and sum to 1, with higher weights assigned to the flow phase difference, transaction divergence, and queuing pressure index, which directly reflect the direction of operational continuity breakdown. Under the default engineering values, when... and , , When at least two of the three components have broken through the corresponding collaborative boundary, the system determines that the continuity break signature is valid.
[0035] Incident candidates are generated from the incident candidate gate. The incident candidate gate has two entry paths: First, when an anomaly occurs in the security sensing status, such as equipment failure, smoke detector malfunction, access control anomaly, or broadcast failure, an incident candidate is directly generated based on this anomaly. Second, when a continuity break signature is established but the security sensing status has not reached the alarm threshold, an incident candidate is generated in reverse based on the continuity break signature, and the candidate type is marked as a candidate to be verified. After generating incident candidates, the system immediately performs mechanism consistency verification and stable operation verification. Mechanism consistency verification is not generalized to arbitrary matching, but rather calls the corresponding mechanism template for the candidate incident type. Taking elevator malfunction candidates as an example, the template requires at least two of the following three phenomena to occur: "decreased vertical traffic throughput, increased queuing pressure in alternative channels, and imbalance between transaction completion rate and passenger flow changes," and the temporal order must satisfy the basic order of "vertical traffic changes precede queuing changes, and queuing changes precede transaction deviations." Stable operation verification consists of transaction synchronization status, traffic recovery status, and capacity maintenance status: transaction synchronization status is used to determine whether the transaction initiation rate and transaction completion rate are still maintained within the normal coordination boundary; traffic recovery status is used to determine whether the queue length change rate and dwell time distribution have declined for two consecutive operating cycles; capacity maintenance status is used to determine whether the combined throughput of elevators, escalators, and backup staircases is not lower than the minimum guaranteed throughput.
[0036] In this embodiment, the mechanism consistency matching degree is denoted as It is determined by the ratio of the number of key phenomena observed in the candidate accident type template to the total number of phenomena in the template; the penalty value for stable operation evidence is recorded as... The value is set to 1 when all three states—transaction synchronization, traffic recovery, and traffic capacity maintenance—are met; 0.5 when only two are met; and 0 in all other cases. The comprehensive judgment value is determined by the following formula: when and At that time, the system determines that the accident candidate passes the contradiction check; when When the emergency candidate is switched to active verification mode, a rapid verification of the status of elevator controls, broadcasts, smoke detectors, and passageways in the corresponding area is triggered; when At that time, the accident candidate will be frozen as a suspected false alarm record and will not enter the subsequent accident chain locking process.
[0037] After contradiction verification, the system locks the composite accident chain according to the propagation direction and node transfer conditions of the continuity break signature. The composite accident chain contains at least four types of nodes: initial disturbance event, propagation event, business continuity damage event, and secondary risk event. For the crowd migration scenario caused by elevator failure, the initial disturbance event is defined as "the available capacity of the elevator group decreases by more than 40% for 60 seconds"; the propagation event is defined as "the queuing pressure index of the adjacent escalator or backup stairwell is greater than 1.10 for two consecutive operating cycles"; the business continuity damage event is defined as "the transaction completion rate decreases and the refund and cancellation rate is higher than the boundary limit, or the 95th quantile of the dwell time distribution increases for two consecutive operating cycles"; the secondary risk event is defined as "the local density increases and the speed distribution decreases", which in this embodiment corresponds to a local density higher than 2.8 people / m² and a speed distribution 20th quantile value lower than 0.35 m / s for 60 seconds. If only the initial disturbance event and propagation event are met at present, the incident chain is locked only to the propagation stage and will not enter the secondary risk stage prematurely. Once the transaction completion rate decreases and the refund and cancellation rate increases simultaneously, the system will add a node indicating business continuity impairment. Secondary risk nodes will only be added after the conditions of local density increase and speed distribution decrease are met. For gas anomaly scenarios in catering areas, "gas monitoring anomaly or smoke exhaust failure" is taken as the initial disturbance event, "personnel reverse movement and broadcast occupancy anomaly" is taken as the propagation event, and "transaction interruption and partial cancellation anomaly" is taken as the business continuity impairment event.
[0038] After a complex incident chain is locked, the system generates multiple response action packages for that chain. Each response action package includes safety actions, traffic control actions, and operational intervention actions. Taking the incident chain in the four-story cinema waiting area as an example, the first response action package includes: disabling the malfunctioning elevator, opening the access control of the backup staircase, implementing traffic diversion broadcasts in the adjacent broadcast zones on the fourth and third floors, setting up one-way traffic flow at the escalator entrance, suspending order taking at the two cash registers adjacent to the escalator entrance, and freezing the member activity check-in entrance in the waiting area; the second response action package includes: keeping the escalator running, implementing only broadcast traffic diversion and security guidance, and maintaining cash register operations; the third response action package includes: implementing short-term lockdown of the waiting area and directly switching customer flow to the backup staircase. The system first reads the real-time resource status and constructs the demand relationship between actions and resources. Resources include at least elevators, fire exits, broadcast systems, and security personnel. When an action package requires the use of a malfunctioning elevator or a congested passage, the system determines that the action package cannot be executed; if multiple action packages are executable, the system selects the one that restores revenue.
[0039] In this embodiment, the processing action package The recovery benefit is determined by the following formula: in, This is the normalized value of the queuing pressure fall rate relative to the boundary stabilization rate. The normalized value of the trading recovery slope. This is the normalized value of the decrease in the false alarm upgrade rate. This is a normalized value for the improvement in secondary congestion relief time. All four components are calculated from pre-implementation simulation results, historical records of similar implementations, or baseline data from the contingency plan database, and range from 0 to 1. The system only operates when the action package is executable and... In the best-case scenario, this action package will be issued as a joint handling solution; if multiple action packages... If the actions are the same, the action package that consumes fewer critical resources will be selected first; if there is no automatic alternative, the conflicting actions will be marked as pending manual decision-making.
[0040] After the joint response action package is issued, the central decision-making server continues to calculate the operational continuity state vector and continuity break signature in each subsequent operating cycle, and records the evolution of operational continuity state before, during, and after the response, forming a response recovery record. The response recovery record includes at least the incident chain type, the establishment time of each node, the continuity break signature strength value for each operating cycle, the action package identifier, resource occupancy, the time required to recover to the permitted boundary, the results of suspected false alarm freezes, and whether new resource conflicts have occurred. If new resource conflicts occur during the joint response, such as the broadcast system being occupied by a high-priority incident on another floor, the broadcast action in the current action package is downgraded to security personnel making announcements and an alternative action is recorded; if the backup stairwell access control fails to open, the system maintains broadcasts and security guidance, and marks the accessibility maintenance status as not restored, without declaring the permitted boundary restored.
[0041] The rule-based closed-loop update is performed based on the handling and recovery records. The system groups the handling and recovery records of similar incident chains into the same comparison group according to incident chain type, floor relationship, business type, and action package type. When the comparison group accumulates 20 handling and recovery records, the system generates candidate rules based on the median recovery time, false alarm escalation rate, and new resource conflict occurrence rate. Candidate rules can be new node transfer conditions, continuity break signature component combination methods, handling action package priority adjustment methods, or freeze thresholds. In this implementation, false alarm freeze failure is used to characterize the situation where an incident candidate has been frozen according to the suspected false alarm path, but within 5 minutes after freezing, manual verification confirms the incident facts, or the supplementary judgment result during the freezing period simultaneously satisfies the establishment of the initial disturbance event and the establishment of the continuity break signature, thus causing the incident candidate to need to be unfrozen and transferred to the formal incident chain processing. The system will only send a candidate rule to the manual review queue if it simultaneously meets three conditions relative to the current official rule group: a median recovery time decrease of more than 8%, a false alarm escalation rate decrease of more than 10%, and no increase in the occurrence rate of new resource conflicts. Reviewers in the queue will then compare the candidate rule's source scenario, applicable floor, applicable business type, and whether it conflicts with existing rules before deciding whether to implement it. If, after implementation, any of the following occurs in three consecutive similar events: median recovery time worsens, false alarm freeze fails, or resource conflicts increase, the rule will automatically revert to the previous official version.
[0042] Work process example The fourth-floor cinema waiting area entered the evening screening exit phase at 20:35, and the system had already loaded the evening screening coordination boundary version for this operational continuity unit. At 20:35:30, two elevators in a group stopped, and one repeatedly opened and closed its doors. The central decision server read that the actual throughput of the elevator group decreased from 0.92 people / s to 0.28 people / s, corresponding to a vertical traffic congestion index of 0.70. Within the same operating cycle, the number of people queuing at the escalator entrance was 43, and the number of people that could be processed in 5 minutes was 35, with a queuing pressure index of 1.23. The observed phase difference between the peak passenger flow and the peak transaction initiation was 215 seconds. Substituting these values into the aforementioned formula yielded... The passenger flow change rate is 0.48, and the transaction completion rate change is -0.21. Substituting these values into the aforementioned formula yields... At this point, the member dwell anomaly index is set to 0.18, and the recovery delay factor is set to 0.50. Therefore, the continuity breakdown signature strength value is... The score is approximately 0.90, satisfying the criteria for a continuity breakdown signature. Since the candidate accident type is elevator malfunction, three of the three key phenomena required by the template have been met, indicating a good mechanism consistency match. Set to 1; at this moment, the transaction synchronization state, traffic recovery state, and traffic capacity maintenance state are all not established, resulting in a penalty value for evidence of stable operation. Take 0, therefore If the value is greater than 0.55, the system generates accident candidates that pass the contradiction check.
[0043] After the candidate incident passed the contradiction verification, the system immediately wrote "elevator group malfunction" into the initial disturbance event node and "escalator entrance queuing pressure continues to exceed the limit" into the propagation event node, and continued to monitor the operational continuity damage node and secondary risk node. From 20:36:00 to 20:36:30, the transaction completion rate continued to decline, and the refund cancellation rate exceeded the upper limit of the unit's evening session boundary, so the system wrote the operational continuity damage node; at this time, the local density had not yet reached 2.8 people / m², so the system did not add a secondary risk node. Subsequently, the system generated three handling action packages for this incident chain. After reading the resource status, it was found that the third handling action package required occupying the fire escape that was locked in another incident chain on the same floor, so it was determined that it was not executable; the first and second handling action packages were executable. Among them, the first handling action package was estimated to have a higher queuing pressure reduction speed and secondary congestion relief capability based on the contingency plan library and historical similar records. Therefore, its recovery benefit was higher than that of the second handling action package. The system selected the first handling action package and issued it. After execution, the system continues to update the state vector every 30 seconds. When the flow phase difference, transaction deviation, queuing pressure index, and vertical traffic congestion index all return to the permissible boundary within three consecutive operating cycles, the system marks the business continuity unit as recovered and forms a complete disposal recovery record.
[0044] In this implementation, the business continuity state vector unifies the operational status of customer flow, transactions, members, vertical transportation, and emergency facilities into the same business continuity unit, thus providing a basis for comparing security incidents and changes in business operations within the same period. The continuity disruption signature jointly describes the degree of disruption of business continuity through traffic phase difference, transaction deviation, queuing pressure index, vertical transportation congestion index, member dwell anomaly index, and recovery delay factor, thereby avoiding misjudging short-term business fluctuations as incidents. The incident candidate gate and contradiction verification gate jointly ensure that the establishment of an incident has both an abnormal source and a mechanism consistency and stable operation counter-evidence judgment, which can block false alarms and discover security blind spots. The composite incident chain locking expands single-point anomalies into chain objects with propagation direction and transfer conditions, so that subsequent handling action packages are generated around the actual propagation direction. The joint handling action package aims to restore to the permitted boundary, rather than simply executing a fixed plan. The final write-back of the handling recovery record serves as the basis for rule updates, so that the rule launch, freezing, and rollback are all subject to the joint constraints of recovery time, false alarm escalation rate, and resource conflicts.
[0045] Example 2 like Figure 1 and Figure 2As shown, this embodiment focuses on the local evacuation conflict chain caused by gas anomalies in the catering area. It emphasizes the generation criteria for stable operation evidence, the method for determining the propagation direction, and the rules for the advancement and freezing of complex accident chains among multiple operational continuity units. In this embodiment, the operational continuity unit, operational continuity state vector, collaborative boundary, permitted boundary, and continuity rupture signature are still generated in the aforementioned manner, but the monitoring focus is narrowed to four interconnected operational continuity units: the open kitchen on the west side of the second-floor catering area, the outdoor waiting area on the second floor, the atrium bridge on the second floor, and the evacuation exit in the atrium on the first floor. The open kitchen on the west side of the second-floor catering area corresponds to the first operational continuity unit, the outdoor waiting area on the second floor corresponds to the second operational continuity unit, the atrium bridge on the second floor corresponds to the third operational continuity unit, and the atrium evacuation exit on the first floor corresponds to the fourth operational continuity unit. The preset propagation delay between the first business continuity unit and the second business continuity unit is set to 30 s to 90 s, the preset propagation delay between the second business continuity unit and the third business continuity unit is set to 45 s to 120 s, and the preset propagation delay between the third business continuity unit and the fourth business continuity unit is set to 60 s to 150 s.
[0046] The evidence for stable operation of the catering area is no longer judged solely by "whether normalcy has been restored," but rather by a combination of three results: transaction synchronization status, traffic recovery status, and capacity maintenance status. Transaction synchronization status is determined by the deviation between order initiation volume, payment completion volume, and order cancellation volume; traffic recovery status is determined by whether the queuing pressure index, dwell time distribution, and reverse movement ratio have returned to within the boundaries; and capacity maintenance status is determined by the combined throughput of connecting bridges, escalators, backup staircases, and first-floor evacuation exits. For the continuous operation unit of the catering area, the upper limit of allowable transaction synchronization deviation is set at 0.18, the upper limit of safe queuing pressure is set at 1.00, the queuing buffer margin is set at 0.20, and the minimum guaranteed throughput rate is set at 0.65 people / s, under the default engineering settings. For ease of standardized judgment, the strength of evidence for stable operation is denoted as... It is calculated using the following formula: In the formula, For the first Order initiation change rate within each operating cycle To pay the rate of change, This is the upper limit of the transaction synchronization deviation for the corresponding business continuity unit. This represents the current queuing pressure index. To ensure safe queuing pressure limit, To provide a buffer for queuing, This represents the current synthesis success rate. To ensure the minimum pass rate. When A result greater than 1 is counted as 1, and a result less than 0 is counted as 0. Only when... Furthermore, the system only recognizes the existence of evidence of stable operation when the transaction synchronization status, traffic recovery status, and throughput maintenance status are all established for two consecutive operating cycles; when When the system marks the corresponding accident candidate as pending review; when In such cases, evidence of stable business operations is not considered valid.
[0047] In this embodiment, the propagation direction is determined jointly based on the pedestrian migration trend between adjacent business continuity units, the load change of alternative channels, and temporal consistency. The pedestrian migration trend is obtained through anonymous trajectory crossing records at the boundaries of adjacent business continuity units; the load change of alternative channels is obtained through the difference in queuing pressure indices of each business continuity unit; and temporal consistency is obtained through the time difference between upstream and downstream business continuity units reaching their queuing peaks or reverse movement peaks. Let the first... In each operating cycle, the upstream business continuity unit Downstream business continuity units The proportion of migrant workers is Its value is taken from the period starting from Leave and enter within 60 seconds The number of people accounted for from The proportion of the total number of people leaving; let the load transfer amount be... Its value is Compared to The normalized value of the upper limit of queuing pressure. Timing consistency is denoted as... It is calculated using the following formula: In the formula, This refers to the moment when the upstream continuous operation unit reaches the queuing peak or the reverse movement peak. This refers to the moment when downstream business continuity units reach their corresponding peak. This is the median of the preset propagation delay for this unit pair. To allow for a maximum allowable delay deviation, the scenario is as follows: for the spread from the open kitchen on the west side of the second-floor dining area to the outdoor waiting area on the second floor, Take 60 seconds. Take 45 seconds. The closer the timing is to the preset propagation delay, the better. The closer it is to 1.
[0048] After obtaining the proportion of people migration, load transfer volume, and timing consistency, the system calculates the propagation direction coefficient. : when Furthermore, if any of the following phenomena occurs in the corresponding downstream business continuity unit: increased transaction divergence, increased queuing pressure index, or increased reverse movement ratio, the system determines that the propagation direction has changed. point to If two downstream operating continuity units simultaneously meet the above conditions for the same upstream operating continuity unit, then the upstream operating continuity unit shall be selected first. The larger direction is designated as the primary propagation direction, while the remaining directions are recorded as secondary propagation directions but do not immediately advance the main chain nodes. If all downstream directions... If all values are less than 0.45, the system determines that there is no stable propagation direction, and the composite accident chain only retains the initial disturbance node.
[0049] The progression of nodes in a complex accident chain no longer depends on a single condition hit, but is jointly determined by the initial disturbance intensity, the propagation direction coefficient, the degree of damage to business continuity, and the degree of accumulation of secondary risks. Let the initial disturbance intensity be... It is determined based on the hit ratio among abnormal gas monitoring, smoke exhaust failure, and abnormal local temperature rise; let the intensity of the propagation direction be... It takes the coefficient of the current main propagation direction. Let the intensity of the business continuity impairment be... It is determined by normalization based on the proportion of transaction interruptions, the degree of exceeding the cancellation rate limit, and the degree of exceeding the limit of the 95th percentile of dwell time; let the intensity of secondary risk be... The node advancement coefficient is determined by normalizing the degree of increase in local density, the degree of decrease in velocity distribution, and the proportion of reverse movement. Calculate using the following formula: when When this happens, the system will advance the complex accident chain to the next node; when When the system maintains the current node and triggers supplementary verification, it neither advances nor freezes; when At this time, the system freezes the current candidate incident chain and writes the reason for the freeze into the handling and recovery record. Because... The negative term is used in the formula, so as long as the evidence of stable operation is strong, the node advancement coefficient will decrease significantly, thereby preventing the escalation of errors caused by false alarms from local sensors.
[0050] This implementation also sets up a reverse triggering path for situations where business continuity breaks first but a valid alarm has not yet been generated on the security side. For the first business continuity unit and the second business continuity unit, if the continuity break signature has been established, and Meanwhile, the main propagation direction coefficient If at least two of the following conditions are met simultaneously: the transaction interruption rate is greater than 0.30, the reverse movement rate is greater than 0.18, and the broadcast occupancy time increases by more than 0.25 minutes compared to the average of the previous 5 minutes, then a candidate incident gate will directly generate a candidate incident to be verified. The verification objects for this candidate incident are fixed as the gas detector status, exhaust fan operation status, local thermal imaging of the catering area, broadcast system occupancy record, and bridge access status. If, after verification, any fact of abnormal gas monitoring or exhaust failure is confirmed within 90 seconds, the candidate incident to be verified will be transferred to the formal candidate incident and continue to be processed according to the aforementioned node advancement rules; if no security fact is confirmed within 90 seconds and If the value recovers to above 0.85, the candidate for the pending verification accident will be automatically frozen.
[0051] In the dining area scenario, the complex incident chain is organized according to at least the following four types of nodes. The first type is the initial disturbance event, which is defined as at least one of the following: abnormal gas monitoring, smoke exhaust failure, abnormal local temperature rise, or manual reporting. The second type is the propagation event, which is defined as at least one of the following: an increase in the proportion of reverse movement in the second-floor outdoor waiting area, an increase in queuing pressure on the second-floor atrium connecting bridge, an abnormal duration of broadcast occupancy, or a sudden increase in traffic flow at the first-floor atrium evacuation exit entrance. The third type is the business continuity disruption event, which is defined as at least one of the following: a decrease in transaction completion rate, an increase in order cancellation rate, an increase in the 95th percentile of dwell time, or a cashier shutdown. The fourth type is the secondary risk event, which is defined as at least one of the following: an increase in local density and a decrease in velocity distribution, wherein in this embodiment, the local density exceeds 2.6 people / m² and the 20th percentile of velocity distribution is below 0.40 m / s, or a short-term backflow at the evacuation exit, or manual reporting of congestion by security personnel. When any node is written into the complex incident chain, it must include the business continuity unit identifier, the establishment time, the corresponding main propagation direction, and the key quantity that triggered the node.
[0052] Work process example The first example corresponds to the frozen branch of "security anomaly but stable operation evidence established". At 18:12:00, the open kitchen on the west side of the second-floor dining area experienced a short-term high value from the gas detector, thus triggering a gas anomaly candidate in the security sensing status. The system read that the order initiation change rate was 0.06, the payment completion change rate was 0.02, the queuing pressure index was 0.94, and the synthesis pass rate was 0.78 people / s within the same operating cycle. Substituting these values into the aforementioned formula for the strength of stable operation evidence yields... The value is greater than 0.90. Meanwhile, no significant reverse movement was observed in the second-floor outdoor waiting area or the second-floor atrium connecting bridge; the main propagation direction coefficient was below 0.30, and the node propagation coefficient was below 0.45. Therefore, the system records this candidate event in the suspected false alarm log, but does not record it in the propagation event node, nor does it trigger local evacuation actions; it only retains a short-term check of the gas detectors and exhaust fans.
[0053] The second example corresponds to the main chain progression branch of "Gas Anomaly in the Catering Area Causing Localized Evacuation Conflict". At 19:18:00, the open kitchen on the west side of the second-floor catering area experienced a smoke exhaust failure accompanied by continuous gas detector anomalies, and the system wrote the first operational continuity unit into the initial disturbance event. At 19:18:30, the second-floor outdoor waiting area showed significant reverse movement, the order initiation change rate was -0.32, the payment completion change rate was -0.58, the queuing pressure index rose to 1.18, and the synthesis pass rate dropped to 0.49 people / s. Calculations showed... The rate decreased to 0.34; the proportion of people leaving the first business continuity unit and entering the second business continuity unit within 60 seconds during the same period reached 0.52, the load transfer between the second and first business continuity units reached 0.27, and the timing consistency reached 0.81. Therefore, the main propagation direction coefficient... Greater than 0.60. Due to the simultaneous increase in the initial disturbance intensity, propagation direction intensity, and operational continuity impairment intensity, while the evidence of stable operation is low, the node advancement coefficient exceeds 0.70, and the system will advance the complex incident chain to the propagation event node and the operational continuity impairment node.
[0054] From 19:19:00 to 19:19:30, the queuing pressure index of the second-floor atrium bridge continued to rise, and the flow rate at the first-floor atrium evacuation exit increased rapidly within 60 seconds. The third and fourth operational continuity units successively met the main propagation direction determination conditions, and the system wrote the main propagation direction as "first operational continuity unit to second operational continuity unit", "second operational continuity unit to third operational continuity unit", and "third operational continuity unit to fourth operational continuity unit". At this time, the local density of the third operational continuity unit reached 2.7 people / m², the 20th percentile of the velocity distribution dropped to 0.38 m / s, the secondary risk intensity increased, and the node advancement coefficient exceeded 0.70 again. The system advanced the complex accident chain to the secondary risk event node and output priority actions to the joint response module: switch the zoned broadcast of the catering area and the atrium bridge, suspend order taking at the adjacent cashier points of the first operational continuity unit, restrict the flow of customers into the adjacent area, open the first-floor backup evacuation exit, and dispatch security personnel to perform one-way flow guidance on the second-floor atrium bridge.
[0055] In another operational branch, if the smoke exhaust failure at 19:18:00 has not yet been identified by the security side, and the first and second operational continuity units have consecutively met the "continuity break signature established" condition for two operating cycles, If the main propagation direction coefficient is greater than 0.60 and both the transaction interruption ratio and the reverse movement ratio exceed the limit, then the incident candidate will become a pending verification incident candidate, and the status of the smoke exhaust fan, thermal imaging, and broadcast occupancy records will be retrieved immediately. If the smoke exhaust fan is confirmed to be stopped before 19:19:00, the pending verification incident candidate will be converted into a formal incident candidate, and the initial disturbance event will be directly added; if no security facts are confirmed and after 19:19:00... If the value recovers to above 0.85, the candidate for the pending verification accident will be automatically frozen and the complex accident chain will not be further advanced.
[0056] This implementation method defines both stable operation evidence and propagation direction as quantifiable objects, making the contradiction verification gate and complex accident chain locking module more than just experience-based judgments. Strength of stable operation evidence By converging the transaction synchronization state, traffic recovery state, and capacity maintenance state under the same judgment criterion, as long as these three states cannot be consecutively true, candidate incidents will not be erroneously frozen due to short-term local stability. Conversely, as long as these three states are consecutively true, the negative term in the node advancement coefficient will inhibit chain upgrades, thereby preventing false alarms from single-point sensors in the catering area. (Propagation direction coefficient) By using the proportion of people migration, load transfer volume, and timing consistency, the spread of anomalies from one business continuity unit to another is described, avoiding the misinterpretation of multi-directional short-term fluctuations as main chain expansions. Node advancement coefficient. Furthermore, the initial disturbance, propagation, disruption of business continuity, and secondary risks are unified under the same advancement rule, and stable operational evidence is used as a reverse constraint. This ensures that the complex incident chain can proceed sequentially when real risks occur, and can also stop or freeze when business continuity has been restored or the propagation direction is invalid. The reverse triggering path ensures that if business continuity breaks first, it will not be missed due to security delays, thereby achieving early identification and stable termination of local evacuation conflict chains in the catering area.
[0057] Example 3 like Figures 1 to 3As shown, this embodiment focuses on the handling of anomalies, boundaries, and degradation when multiple incidents occur concurrently, key data sources are restricted, and key resource conflicts overlap. It emphasizes the anomaly triggering criteria, degradation action chains, recovery conditions, and retrospective writing rules. In this embodiment, the definitions of operational continuity unit, operational continuity state vector, collaborative boundary, permission boundary, continuity break signature, stable operation evidence, propagation direction coefficient, and node advancement coefficient are all retained. However, four boundary control chains are added during the joint handling phase: data availability determination, resource executability determination, degradation execution determination, and recovery eligibility determination. For ease of explanation, this embodiment uses the concurrent occurrence of a "crowd migration chain in the fourth-floor cinema waiting area" and a "partial evacuation conflict chain in the second-floor catering area" as a scenario: the fourth-floor cinema waiting area requires broadcast guidance and backup staircase diversion, while the second-floor catering area requires broadcast flow control and first-floor evacuation exit guidance. At this time, the broadcast system only supports high-priority broadcasts for two zones simultaneously, a backup evacuation exit on the first floor is occupied by temporary goods, and the fourth-floor video passenger flow acquisition equipment experiences continuous frame drops in the early stages of the incident.
[0058] In this boundary scenario, the system first determines the availability of key data sources. Key data sources include at least video passenger flow data, anonymous trajectory aggregation, cashier transaction records, member dwell time, vertical transportation operation status, broadcast status, and emergency facility status. Since different data sources have varying impacts on accident determination, this implementation uses a weighted availability coefficient. Description of the Data completeness for each running cycle: In the formula, , , , , , and These represent the availability status of each data source within the current runtime cycle: 1 for fully available, 0 for delays exceeding one runtime cycle or consecutive missing data, and 0.5 for unstable but still usable data. The weights sum to 1, with passenger flow, trajectory, and vertical transportation-related data having a higher weighting because they directly determine the direction of population migration chains and evacuation conflict chains. The system executes in full data mode; if The system enters restricted data mode, allowing only a portion of the reference values from the previous stable window to be used; if The system enters a frozen data mode, stops generating new candidate rules based on the current cycle, and restricts the write range of newly added nodes in the composite accident chain.
[0059] For handling action packages, the system not only checks for conflicts, but also considers the remaining execution capacity after a conflict. Let's say a handling action package... In the The availability rates of the four resource categories—elevators, fire exits, public address systems, and security personnel—for each operating cycle are as follows: , , and The resource executability coefficient is calculated as follows: 1 for complete satisfaction, 0 to 1 for partial satisfaction based on the ratio of schedulable resources to required resources, and 0 for non-satisfaction. Calculate using the following formula: If an action package itself does not require a certain type of resource, the corresponding component is counted as 1. Taking a broadcast system as an example, when a concurrency incident results in only one high-priority broadcast partition being immediately available, and the action package requires two partitions to broadcast together... Take 0.5; if the first-floor spare evacuation exit is occupied, only half of the passage's capacity will be maintained for passage operations. Set the value to 0.5. After generating the action package, the system first calculates... Then decide whether to allow the action package to enter the formal execution queue.
[0060] After data availability and resource executability are quantified, the system calculates the degradation execution coefficient. This is used to determine whether the current incident chain should continue in its entirety, whether to downgrade to a safety-first mode, or whether to enter a freeze mode: In the formula, This indicates the action package that currently offers the highest recovery benefit and is still executable. Indicates the first The resource conflict intensity for each operating cycle is taken as the normalized ratio of conflicting resource demand to the total available conflicting resources. When, the system maintains full execution mode; when When this happens, the system enters a security priority downgrade mode; when When this happens, the system enters freeze mode. In security-priority downgrade mode, the system retains only security actions and minimum necessary passage and evacuation actions, suspends further expansion of operational intervention actions, does not write new secondary risk nodes, and only retains confirmed nodes and highly reliable propagation directions; in freeze mode, the system stops promoting new propagation nodes and nodes that impair operational continuity, stops generating candidate rules, and only retains hard security actions such as manual review, broadcast preemption, backup channel unlocking, and security scheduling.
[0061] The traceability write during the abnormal period cannot be omitted due to downgrading. This implementation method writes a traceability integrity coefficient for each processing cycle. Its completeness is determined by five categories of fields: whether the source of the anomaly is written, whether the reason for the freeze is written, whether the alternative action is written, whether the recovery conditions are written, and whether the result of manual takeover is written. In the formula, This indicates whether the exception source field has been completely written. Indicates whether the reason for freezing or downgrading has been written. Indicates whether alternative and failure actions are written. Indicates whether the recovery conditions and recovery time have been written. Indicates whether the manual takeover decision has been written. A value of 1 indicates a complete write, 0.5 indicates a partial write, and 0 indicates no write. If... Even if the accident chain is superficially restored, the system will not allow the current handling cycle to enter the candidate rule generation stage. Instead, it will mark the cycle as "incomplete record, archiveable only, not learnable".
[0062] The recovery criteria use a recovery eligibility coefficient. Unified control. The system will only allow a return from degraded or frozen mode to full execution mode after three requirements are met: permission boundary stabilization, data source recovery, and complete traceability records. The recovery eligibility coefficient is determined by the following formula: In the formula, This indicates the degree of boundary stabilization, and is measured as the proportion of key indicators that the current business continuity unit has recovered to within the permissible boundary out of all key indicators. If... If this condition is met for three consecutive operating cycles, the system will be unfrozen and write access will be restored to nodes with impaired operational continuity and nodes with secondary risks. The system remains in observation mode, only allowing recalculation of continuity-breaking signatures and stable operation evidence, without resuming rule learning; if The system maintains the original freeze level unchanged.
[0063] Under the security-first degradation mode, the execution boundaries of each module are as follows: The business continuity modeling module continues to update the business continuity state vector, but uses the reference value of the previous stable window for missing data and marks the data integrity as "restricted"; the continuity break signature extraction module continues to calculate the flow phase difference, transaction deviation degree, and queuing pressure index, but does not refresh the boundaries for the member residence anomaly index and recovery delay factor; the dual-door trigger judgment module only allows the maintenance of existing incident candidates based on confirmed security facts and continuity break signatures, and does not generate new candidates to be verified; the composite incident chain locking module only retains the confirmed main propagation direction and does not accept new secondary propagation directions to be incorporated into the main chain; the joint handling module only executes security actions and minimum necessary passage actions, such as preempting broadcasts, opening backup staircases, restricting local passenger flow, and security manual guidance; the rule closed-loop update module stops writing candidate rules and only records the recovery and conflict facts of the current cycle. In freeze mode, all automatic extension actions except for manual review, emergency broadcasting, evacuation door control, and security dispatch are stopped; at the same time, the currently used boundary version, action package version, and propagation direction version are frozen until the recovery qualification coefficient conditions are met.
[0064] For the downgrading of resource conflicts, this implementation method adopts the order of "life safety first, passage guarantee second, and operation restoration last." If the broadcast system capacity is insufficient, the broadcast action corresponding to the gas abnormality in the catering area takes priority over the operation notice broadcast in the cinema waiting area, the latter being downgraded to verbal guidance from security personnel; if the first-floor spare evacuation exit is occupied, the evacuation exit is cleared first and the evacuation chain in the catering area is maintained, and the "directly guide to the first-floor spare evacuation exit" in the cinema-side action package is replaced by "guide the diversion combination of the third-floor connecting bridge and the fourth-floor spare staircase"; if there are insufficient security personnel, the second-floor atrium connecting bridge and the first-floor evacuation exit are guaranteed first, and then the non-essential order maintenance in the fourth-floor waiting area is postponed. Once any alternative action is adopted, it must be recorded in the handling and restoration record along with the action being replaced, and the reason for the substitution, the time of the substitution, and the percentage of remaining capacity after the substitution must be noted.
[0065] After the data source is restored, the system does not directly overwrite all judgments made during the freeze period with the current period. Instead, it performs a replay-based supplementary judgment. The replay-based supplementary judgment uses the cached data from the most recent 10 minutes as input to recalculate propagation nodes, business continuity-impaired nodes, and secondary risk nodes that were not written during the freeze period. However, it only applies to nodes corresponding to those within the replay period. It has recovered to above 0.80. A supplementary judgment result can only be incorporated into the formal handling and recovery record if the score is not lower than 0.80 and the manual review result does not conflict with the automatic judgment. If the replay of the supplementary judgment conflicts with the manual takeover record during the freeze period, the manual takeover record shall prevail, and a mark of "automatic supplementary judgment not adopted" shall be written in the handling and recovery record.
[0066] Work process example The following is a set of boundary scenario operation procedures to illustrate the anomaly, degradation, and recovery rules of this implementation method. At 20:41:00, the crowd migration chain in the waiting area of the fourth-floor cinema and the partial evacuation conflict chain in the second-floor catering area are both in progress. At this time, the fourth-floor video passenger flow acquisition equipment has only uploaded a portion of frames for two consecutive operating cycles, and the video passenger flow is in an available state. The value is set to 0.5; Anonymous trajectory aggregation, cashier transaction data, vertical traffic, and broadcast status are all normal. There is a one-cycle delay in member retention, and member retention is currently available. Take 0.5 and the rest 1, then substitute them into the data availability coefficient formula to get... The value was approximately 0.79, causing the system to enter restricted data mode. Simultaneously, only one high-priority partition remained available for immediate use by the broadcast system, and the first-floor backup evacuation exits could only be partially used due to cargo occupation, resulting in the optimal action package being unavailable on the cinema side. Take 0.5, Take 0.5, for the food and beverage area action pack. Take 1, The value is set to 0.8. Since the resource feasibility coefficient of the action package in the catering area is higher and the conflict resource intensity has exceeded 0.60, the system prioritizes ensuring the broadcasting and evacuation exit clearing in the catering area, downgrades the action package on the cinema side to "security diversion + backup staircase diversion", and suspends its operational intervention actions.
[0067] From 20:41:30 to 20:42:00, the resource feasibility coefficient of the optimal action package on the cinema side dropped to 0.58, and the conflict intensity increased to 0.72. Substituting these values into the downgrade execution coefficient formula yields... If the coefficient is greater than 0.65, the system enters a frozen mode for the complex accident chain on the cinema side. After freezing, the system will no longer write new propagation directions or expand new nodes that are damaged in business continuity. It will only retain the confirmed crowd migration chain nodes and continue to execute the opening of backup staircases and manual traffic guidance by security personnel. On the catering area side, due to the successful broadcast control and the completion of evacuation exit clearance, its resource feasibility coefficient has recovered to 0.82, and the downgraded execution coefficient has decreased to 0.33. Therefore, it still maintains the complete execution mode. During this process, the system simultaneously writes the freezing reason "insufficient broadcast resources + partial unavailability of evacuation exits + limited video traffic" and writes the alternative actions "changing the business reminder broadcast to security announcements" and "changing the first-floor backup evacuation exit traffic flow to the third-floor connecting bridge for diversion".
[0068] After 20:43:00, the fourth-floor video passenger flow collection equipment returned to normal, cargo clearance was completed, and the broadcast system released the second highest priority zone for the current operating cycle. Restored to 1, Restored to 1, The value has been restored to 1. At this point, three of the following indicators—traffic phase difference, transaction deviation, queuing pressure index, and vertical traffic congestion index—have returned to within the permissible boundaries, indicating a degree of boundary stabilization. The accuracy rate reached 0.80; the reasons for the freeze in this cycle, the alternative actions, the results of manual security dispatch, and the recovery time have all been recorded, and the traceability completeness coefficient is [value missing]. Reaching 1. After substituting into the formula for the restoration eligibility coefficient, If the value exceeds 0.85, and this level is maintained for three consecutive operating cycles, the system will unfreeze, reopen automatic writing of nodes with impaired operational continuity and secondary risk nodes on the cinema side, and perform replay and supplementary judgment on the 10 minutes of data cached during the freeze period. If the replay and supplementary judgment finds that the conditions for writing secondary risk nodes were not actually met during the freeze period, only nodes confirmed before the freeze will be retained in the official record, and the supplementary judgment result will be marked as "no new nodes added"; if the conditions are met but a higher level of handling has been taken by manual review, only a retrospective description of "manual priority handling during the freeze period" will be written, and the automatic supplementary judgment result will not overwrite the manual record.
[0069] This implementation rewrites the "whether the accident chain can continue to advance automatically" decision from an empirical judgment into an executable boundary control mechanism. Data availability coefficient. The resource feasibility coefficient determines whether the current cycle has sufficient observational basis. Determines whether the optimal action package can still be implemented, and degrades the execution coefficient. This unifies data gaps and resource conflicts under a single anomaly assessment criterion, enabling the system to promptly reduce its automation scope and retain only hard safety actions when critical observations are insufficient or critical resources are unavailable. (Traceability integrity coefficient) This further restricts incomplete records from entering the rule learning path, preventing incomplete logs from polluting the rule closed-loop update in abnormal scenarios. (Recovery eligibility coefficient) Boundary stabilization, data recovery, and complete record integrity are all taken as prerequisites for recovery. This ensures that the system does not immediately unleash all automatic judgments once resources recover, but only lifts the freeze and downgrade after continuous, stable, and traceable recovery conditions are met.
[0070] The above description is merely a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the forms disclosed herein and should not be construed as excluding other embodiments. It can be used in various other combinations, modifications, and environments, and can be modified within the scope of the concept described herein by means of the above teachings or the technology or knowledge in related fields.
Claims
1. A method for intelligent identification and joint handling of complex emergency incidents in commercial complexes, characterized in that, The process includes the following steps: S1, dividing the commercial complex into business continuity units according to region, floor, and business type, and collecting data on the rate of change in the number of people entering and leaving, the distribution of dwell time, the rate of change in queue length, the transaction initiation rate, the transaction completion rate, the refund and cancellation rate, the abnormality of member dwell time, the vertical transportation throughput, the security perception status, and the availability of emergency facilities for each business continuity unit; S2, generating a collaborative boundary for each business continuity unit based on historical normal operating data, activity plans, and business type attributes. This collaborative boundary at least limits the upper limit of traffic phase difference, the upper limit of transaction deviation, and the upper limit of recovery time, and is based on... A continuity state vector is generated at the collaborative boundary. When the flow phase difference, transaction deviation, queuing pressure index, vertical traffic congestion index, member dwell anomaly index, and recovery delay factor exceed the collaborative boundary, a continuity break signature is determined. S3: When any of the following occurs: security perception state anomaly or continuity break signature is established, an incident candidate is generated, and a contradiction check is performed on the incident candidate. The contradiction check includes at least a mechanism consistency check and a stable operation check. The mechanism consistency check is used to determine whether a continuity break signature conforming to the mechanism of the incident candidate appears in the area corresponding to the incident candidate within a predetermined time window. The stable operation check is used to determine whether there is stable operation evidence corresponding to transaction synchronization, flow recovery, and traffic capacity maintenance in the area corresponding to the incident candidate. When the mechanism consistency check passes and stable operation evidence does not exist, the incident candidate that passes the contradiction check is determined. S4: For the incident candidate that passes the contradiction check, a composite incident chain is locked according to the propagation direction of the continuity break signature and node transfer conditions. S5: For each composite incident chain, a handling action package containing security actions, traffic diversion actions, and operational intervention actions is generated, and actions are taken according to each handling action package. S6. Determine the joint disposal plan based on the recovery benefits to restore the target business continuity unit to within the permitted boundary; after the joint disposal is completed, extract the evolution of the business continuity status before, during and after the disposal to form a disposal recovery record. Based on the disposal recovery record, verify the impact of candidate rules on recovery time, false alarm escalation rate and resource conflicts in similar scenarios, and only execute the rule online when the recovery time is shortened, the false alarm escalation rate is reduced and no new resource conflicts are introduced. If the aforementioned conditions are not met, execute the rule freeze. If any of the following situations occurs after the rule is online: recovery time deteriorates or false alarm freeze fails, execute the rule rollback.
2. The intelligent identification and joint handling method for complex emergency incidents in commercial complexes according to claim 1, characterized in that, The operational continuity state vector consists of the rate of change in the number of people entering and leaving, the distribution of dwell time, the rate of change in queue length, the transaction initiation rate, the transaction completion rate, the refund and cancellation rate, the abnormality of member dwell time, the vertical traffic throughput, the security perception status, and the availability of emergency facilities. The continuity break signature consists of the flow phase difference, the transaction deviation, the queue pressure index, the vertical traffic congestion index, the abnormality of member dwell time, and the recovery delay factor.
3. The intelligent identification and joint handling method for complex emergency incidents in commercial complexes according to claim 1, characterized in that, The permission boundary is determined based on the coordination boundary and is used to characterize the boundary state where the target business continuity unit recovers to the point where the flow phase difference, transaction deviation magnitude, and recovery time do not exceed the corresponding upper limit, and the queuing pressure index and vertical traffic congestion index fall back to the predetermined stabilization range.
4. The intelligent identification and joint handling method for complex emergency incidents in commercial complexes according to claim 1, characterized in that, The evidence of stable operation is generated from the transaction synchronization status, traffic recovery status, and traffic capacity maintenance status of the area corresponding to the accident candidate, and the existence of the evidence of stable operation is determined only when the transaction synchronization status, the traffic recovery status, and the traffic capacity maintenance status are all valid.
5. The intelligent identification and joint handling method for complex emergency incidents in commercial complexes according to claim 1, characterized in that, The complex accident chain includes at least an initial disturbance event, a propagation event, an event that disrupts business continuity, and a secondary risk event. The node transfer conditions include at least a decrease in vertical transportation availability, queuing pressure on alternative channels exceeding the coordination boundary, a decrease in transaction completion rate, and an increase in local density and a decrease in speed distribution.
6. The intelligent identification and joint handling method for complex emergency incidents in commercial complexes according to claim 1, characterized in that, The recovery benefits are determined based on the queuing pressure reduction rate, the transaction recovery slope, the decrease in the false alarm escalation rate, and the time for secondary congestion to be resolved, and the action package with the optimal recovery benefits is selected as the joint handling scheme.
7. The intelligent identification and joint handling method for complex emergency incidents in commercial complexes according to claim 1, characterized in that, The candidate rules are also subject to manual review before being implemented. The manual review is used to confirm that the node transfer conditions, action package selection conditions, and freeze thresholds corresponding to the candidate rules are consistent with the action recovery records.
8. A smart identification and joint response system for complex emergency incidents in commercial complexes, characterized in that, The system includes a business continuity modeling module, a continuity failure signature extraction module, a dual-gate trigger judgment module, a complex incident chain locking module, a joint handling module, and a rule closed-loop update module. The business continuity modeling module establishes business continuity units based on region, floor, and business type, and generates business continuity state vectors. The continuity failure signature extraction module extracts continuity failure signatures based on collaborative boundaries. The dual-gate trigger judgment module generates incident candidates and performs mechanism consistency verification and stable operation verification. The complex incident chain locking module locks complex incident chains based on the propagation direction of the continuity failure signature and node transfer conditions. The joint handling module determines a joint handling plan based on recovery benefits and restores the target business continuity unit to within the permitted boundaries. The rule closed-loop update module executes the online, frozen, and rolledback of candidate rules based on the handling and recovery records.
9. The intelligent identification and joint handling system for complex emergency incidents in commercial complexes according to claim 8, characterized in that, The dual-gate trigger judgment module includes an accident candidate gate and a contradiction verification gate. The accident candidate gate is used to generate accident candidates when any of the following situations occur: abnormal security perception status or continuous break signature is established. The contradiction verification gate is used to perform mechanism consistency verification and stable operation verification on the accident candidates.
10. The intelligent identification and joint handling system for complex emergency incidents in commercial complexes according to claim 8, characterized in that, The rule closed-loop update module is used to extract the evolution of the operational continuity status before, during and after the disposal to form a disposal recovery record, and to determine the online status, frozen status and rollback status of the candidate rule based on the changes in recovery time, false alarm escalation rate and resource conflict in similar scenarios.