An enterprise security and energy-saving optimization decision method and system based on multi-agent cooperation
By using a link state determination function and a partial order comparison mechanism for state vectors, combined with conflict classification and security weight arbitration, the problem of autonomous decision-making in multi-agent collaborative systems under network interruption is solved. This achieves a unified strategy of prioritizing security and system stability, and improves the robustness and consistency of enterprise security and energy-saving optimization.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHEJIANG MAI XIN TECH CO LTD
- Filing Date
- 2026-05-07
- Publication Date
- 2026-07-31
AI Technical Summary
Traditional multi-agent collaborative enterprise security and energy-saving optimization decision-making methods suffer from several drawbacks, including decreased system responsiveness due to network outages or high latency, inconsistent states among multiple nodes, control conflicts, a lack of unified coordination mechanisms between security and energy-saving strategies, data silos, and a lack of autonomous decision-making capabilities in scenarios involving edge node computing power bottlenecks and communication interruptions.
The system achieves dynamic switching between cloud-edge collaboration and edge autonomy by using a link state determination function. It adopts a state vector partial order comparison and bifurcation detection mechanism, combined with a conflict classification and security weight arbitration mechanism, to unify the security-first strategy. Finally, it achieves long-term system optimization through a strategy evolution model.
It improves the robustness and state convergence speed of the system, reduces the probability of state conflict propagation in distributed systems, ensures the consistency of the safety-first strategy and the stability of the system, and realizes autonomous decision-making and global consistency in communication interruption scenarios.
Smart Images

Figure CN122496508A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of multi-agent collaboration technology, specifically to a method and system for enterprise security and energy-saving optimization decision-making based on multi-agent collaboration. Background Technology
[0002] As enterprise parks expand, security and energy management systems are increasingly characterized by multi-source heterogeneity and distributed deployment. Traditional cloud-based centralized decision-making methods suffer from problems such as significantly reduced system responsiveness and inconsistent states of multiple nodes in the event of network interruption or high latency, which can easily lead to control conflicts, lack of unified coordination mechanisms between security and energy-saving strategies, and lack of effective consistency verification and conflict resolution mechanisms after communication is restored. There is a lack of overall technical solutions for the coordinated optimization of security and energy saving.
[0003] Existing enterprise security and energy-saving optimization decision-making methods and systems based on multi-agent collaboration adopt a discrete architecture, with security, energy, and access control systems operating independently. This results in the inability to integrate multi-source heterogeneous data, forming serious data silos, making them susceptible to environmental interference. Anomaly identification and handling are passive and delayed. Energy management relies on human experience and lacks real-time analysis and precise waste point location capabilities. It does not solve the problem of multi-agent collaboration failure in scenarios with edge node computing power bottlenecks and communication interruptions. It lacks distributed consistency protocols and network outage self-governance mechanisms, resulting in subsystems being unable to make autonomous decisions when links are abnormal, and state fork conflicts cannot be resolved after recovery. There is a lack of cross-system linkage response mechanisms for security and energy saving, which limits its practicality. Summary of the Invention
[0004] This invention provides a method and system for enterprise security and energy-saving optimization decision-making based on multi-agent collaboration. It achieves dynamic switching between cloud-edge collaboration and edge autonomy through a link state determination function, improving system robustness. It effectively reduces the probability of distributed system state conflict propagation through a state vector partial order comparison and fork detection mechanism. It achieves a unified security-first strategy through conflict classification and security weight arbitration mechanism. It improves system state convergence speed and stability through total order consistency verification. It achieves long-term system optimization capabilities through a policy evolution model, thus solving the problems of strong communication dependencies, poor consistency, and difficulty in handling conflicts in existing technologies.
[0005] This invention provides the following technical solution: a decision-making method for enterprise security and energy conservation based on multi-agent collaboration, comprising:
[0006] Collect multi-source sensing data and perform spatiotemporal alignment and standardization processing; monitor heartbeat latency and packet loss between edge nodes and the cloud; construct a link status determination function based on heartbeat round-trip latency and number of consecutive packet losses; and select cloud-collaborative or edge autonomous channels based on the determination results.
[0007] In edge processing mode, perform local preprocessing on the data, read the local policy cache and verify its timeliness and security level, and output the caching policy or the most conservative policy.
[0008] Select the control mode based on the security status and energy consumption status, drive the strategy execution and synchronously update the multi-dimensional state vector clock and execution log;
[0009] During edge operation, continuous valid heartbeats are counted, and when recovery conditions are met, the state vector clock increment and logs are extracted, encapsulated, and reported.
[0010] The cloud receives data uploaded by each edge node and compares their status, and constructs a conflict classification function based on the device scope and command semantics;
[0011] Conflicts between different devices or regions are merged; conflicts of the same device are determined according to the safety priority rule; mergeable conflicts are overlaid; and non-mergeable conflicts are arbitrated based on the safety weight function and a global policy is generated.
[0012] Perform a consistency check on the processed strategy.
[0013] Preferably, multi-source sensing data is collected and subjected to spatiotemporal alignment and standardization processing to monitor heartbeat latency and packet loss between edge nodes and the cloud, specifically:
[0014] Acquire smart cameras, smart water and electricity meters, photovoltaic sensors, biometric access control systems, infrared detectors, and environmental sensors deployed in the park;
[0015] Based on the unified network time protocol and three-dimensional spatial coordinate system, video stream frame sequences, instantaneous energy consumption values, passage records, security trigger signals, and environmental parameters are collected synchronously.
[0016] Establish a spatiotemporal correlation index, generate the original multimodal dataset, aggregate multi-source heterogeneous sensing data from the park, and eliminate data silos and semantic gaps by aligning with a unified spatiotemporal coordinate system, providing a consistent data base for subsequent intelligent agent collaboration.
[0017] Standardization encapsulation is performed on the original multimodal dataset to unify data with different dimensions and protocol formats into structured standard values;
[0018] Simultaneously, a preliminary data quality screening is performed. Based on historical statistical characteristics, it is determined whether there are abnormal jumps in the current sampled values, and the duration of missing data is detected. Standardized packaged data values and quality qualified marks are generated after dimension normalization. The original data is standardized and packaged and subjected to preliminary quality screening to remove abnormal jumps and excessively long missing samples. The data credibility is marked to ensure that the data entering the decision-making process is true and reliable.
[0019] If the quality pass mark is output as 1, the data quality is considered to be passable.
[0020] If the quality pass mark output is 0, the data quality is considered unqualified.
[0021] Edge nodes periodically send heartbeat detection messages to the coordinated scheduling agent;
[0022] Real-time monitoring of round-trip latency and the number of consecutive packet losses;
[0023] The communication link status is divided according to the dual threshold judgment rule, and the standardized data flow is determined to either the cloud collaborative channel or the edge autonomous preprocessing channel. The health of the communication link between the edge node and the central hub is monitored in real time. The link status is determined based on the dual indicators of latency and packet loss, and the data flow is determined to either the edge autonomous channel or the cloud collaborative channel.
[0024] If the communication link status flag is output as 1, the communication link is determined to be abnormal.
[0025] Then, the standardized dataset will be output to the edge preprocessing channel;
[0026] If the communication link status flag output is 0, the communication link is considered to be normal.
[0027] Then, the standardized dataset will be uploaded to the cloud to coordinate and schedule the intelligent agent.
[0028] Preferably, in edge processing mode, local preprocessing is performed on the data, and the local policy cache is read and its timeliness and security level are verified, specifically as follows:
[0029] Edge nodes receive and collect multi-source sensing data and perform spatiotemporal alignment and standardization processing to monitor the heartbeat latency and packet loss between edge nodes and the cloud, outputting a standardized dataset.
[0030] Deploy a lightweight AI inference engine to perform object detection and behavior recognition on video data, generate object confidence vectors, and filter invalid images;
[0031] Perform sliding window verification on instantaneous energy consumption values to generate abnormal fluctuation markers;
[0032] Perform local preliminary judgment on security anomaly signals and generate security anomaly confidence level;
[0033] Simultaneously monitor the current available computing power resource ratio of edge nodes, determine the feasibility of local preprocessing, complete data dimensionality reduction and anomaly screening at the edge, and monitor computing power margin to ensure that preprocessing does not exceed the carrying capacity of edge nodes;
[0034] If the edge preprocessing feasibility flag is output as 1, then the edge computing power is determined to be sufficient, and local lightweight preprocessing is performed.
[0035] If the edge preprocessing feasibility mark output is 0, it is determined that the edge computing power is insufficient, and only data pass-through and simplified anomaly marking are performed, without uploading complex features;
[0036] Read the decision image sequence from the local policy cache, arranged in reverse order of version timestamp;
[0037] Extract the latest valid decision image ranked first, calculate the time interval between its version timestamp and the current system time, and determine whether the image has expired based on the policy validity threshold. Quantitatively evaluate the freshness of the caching policy to prevent edge autonomy from executing based on outdated policies and reduce the risk of decision failure.
[0038] If the timeliness compliance mark is 1, then the mirror image is deemed to be timeliness compliant;
[0039] If the timeliness qualification mark is 0, the image is determined to be expired;
[0040] Extract the security level tag of the latest decision image and verify whether it belongs to the system's predefined set of valid security levels;
[0041] By combining the timeliness qualification mark and the security level validity mark, the overall availability of the caching strategy is determined through joint product operation, and the caching strategy or the most conservative default strategy is selected to be executed accordingly. By combining the dual constraints of timeliness and security level, the credibility of the caching strategy is determined, and the implementation of fine-grained hierarchical autonomy or downgraded conservative strategy is decided to strengthen the security bottom line.
[0042] If the security level validity mark is 1, then the security level mark is considered valid;
[0043] If the security level validity flag is 0, then the security level flag is deemed invalid.
[0044] If the timeliness qualification mark is 1 and the security level validity mark is 1, then the overall availability mark of the cache policy is 1, and the cache policy is determined to be available. At this time, the final selected execution policy set is the complete policy set corresponding to the latest valid decision image in the cache area. The control mode is selected according to the security status and energy consumption status to execute hierarchical autonomy.
[0045] If the timeliness qualification mark is 0 or the security level validity mark is 0, the overall availability mark of the caching policy will be 0, and the caching policy will be determined to be unavailable. In this case, the final selected execution policy set is the most conservative default policy set, and the most conservative default policy will be executed directly. The control mode will be selected according to the security status and energy consumption status.
[0046] Preferably, the control mode is selected based on the security status and energy consumption status, specifically as follows:
[0047] The local security agent at the edge node outputs the current security status level based on multi-source fusion features;
[0048] Energy intelligence agent outputs regional energy consumption status;
[0049] The coordinated dispatching intelligent agent extracts the corresponding device control list from the cache policy based on the security situation level, selects the autonomous policy execution mode, and divides the autonomous mode according to the security situation level. In case of emergency and abnormality, security takes precedence over everything, while in normal times, energy saving optimization is also taken into account to ensure that the security bottom line is not breached.
[0050] If the security situation level is emergency or abnormal, the security priority autonomous mode is triggered, and the selected autonomous strategy execution mode output is the security priority autonomous mode.
[0051] If the security status level is normal, then the energy-saving adaptation autonomous mode is triggered, and the selected autonomous strategy execution mode output is the energy-saving adaptation mode under security constraints.
[0052] Based on the selected autonomous strategy execution mode, the edge node sends the corresponding set of strategy instructions to each execution terminal, and synchronously increments the clock value in the corresponding dimension of the local state vector clock.
[0053] The policy execution events are appended to the autonomous execution log, the autonomous policy is executed hierarchically according to the selected mode, the state vector clock is updated synchronously and the execution log is recorded, providing traceable time-series evidence for subsequent conflict resolution;
[0054] If the selected autonomous strategy execution mode output is the security-first autonomous mode, then the set of autonomous strategy instructions actually executed by the edge node is the union of the security-first strategy subset and the non-critical equipment forced shutdown strategy subset, and the security-first strategy is executed and the non-critical equipment is shut down.
[0055] If the selected autonomous strategy execution mode output is the energy-saving adaptation mode under security constraints, then the set of autonomous strategy instructions actually executed by the edge node is the intersection of the device control list in the cache strategy and the set of security bottom line constraints, and the energy-saving adaptation instructions are executed under the security bottom line constraints.
[0056] If the agent actually issues a policy instruction, the indicator function outputs 1, and the corresponding dimension clock value increments by 1.
[0057] If the agent does not actually issue a policy instruction, the indicator function outputs 0, and the corresponding dimension clock value remains unchanged;
[0058] Real-time monitoring of the cumulative duration of network outages and the local computing power utilization rate of edge nodes;
[0059] The sustainability of the current autonomous strategy is evaluated based on the dual threshold judgment rule to determine whether to trigger the downgraded autonomous mode. The duration of network outage and computing power margin are evaluated in real time. If the limit is exceeded, the system will downgrade to the most conservative mode to prevent edge nodes from losing security control due to resource exhaustion or strategy aging.
[0060] If the degradation trigger flag is 1, it is determined that the network outage duration exceeds the limit or the computing power is overloaded, triggering the degradation autonomous mode. At this time, the final output of the autonomous mode is the degradation autonomous mode, and it returns the collection of multi-source sensing data and performs spatiotemporal alignment and standardization processing, continuously monitoring the heartbeat latency and packet loss between edge nodes and the cloud to monitor network recovery.
[0061] If the downgrade trigger flag is 0, it is determined that the network outage duration and computing power are within the tolerance range, and the current autonomous strategy is maintained. At this time, the final autonomous mode output is the selected autonomous strategy execution mode, and the collected multi-source sensing data is returned and spatiotemporally aligned and standardized. The heartbeat latency and packet loss between edge nodes and the cloud are monitored to continuously monitor network recovery.
[0062] Preferably, continuous valid heartbeats are counted during edge operation, specifically as follows:
[0063] During the period of network outage autonomy, edge nodes listen for heartbeat detection messages issued by the linkage scheduling agent and perform validity verification on each heartbeat packet received within the monitoring window.
[0064] The system counts the cumulative number of consecutive valid heartbeats and determines whether the communication link has truly been restored based on the recovery confirmation threshold. It continuously counts valid heartbeats and strictly determines whether the link has truly been restored based on the threshold to prevent false recovery misjudgments caused by network jitter.
[0065] If the communication recovery confirmation flag is 1, then the communication link is determined to have been truly restored.
[0066] If the communication recovery confirmation flag is 0, the heartbeat recovery is determined to be unstable, and edge autonomy continues to be executed;
[0067] Extract the state vector clock values maintained by the local security agent, energy agent, and linkage scheduling agent at the edge node;
[0068] Calculate the clock increments for each dimension during the network outage and verify their monotony and non-negativity and dimensional completeness to ensure that the state vector clock is complete and usable. Verify the completeness and monotonicity of the three-dimensional state vector clock to ensure that all autonomous operations are completely recorded and there are no logical conflicts during the network outage.
[0069] If the state vector clock integrity flag is 1, then the state vector clock is determined to be monotonic and complete.
[0070] If the state vector clock integrity flag is 0, it is determined that there is an abnormal jump or a missing state vector clock.
[0071] Extract the incremental subset of autonomous execution logs generated during the network outage;
[0072] Encapsulate the local state vector clock value, incremental log, recovery confirmation flag, and integrity flag into a reporting data packet;
[0073] Based on the joint judgment result, decide whether to initiate state synchronization with the linkage scheduling agent, extract the network outage incremental log and encapsulate and report it to avoid full transmission redundancy, and realize the efficient transition from the edge policy mirror network outage autonomous mechanism to the network outage recovery state vector clock arbitration.
[0074] If the communication recovery confirmation flag is 1 and the state vector clock integrity flag is 1, then the reporting conditions are met. At this time, the dataset actually reported to the linkage scheduling agent is the encapsulated data packet to be reported. The local state vector clock value and the incremental autonomous execution log are reported to the linkage scheduling agent. The cloud receives the data uploaded by each edge node and performs state comparison to start the network outage recovery state vector clock arbitration.
[0075] If the communication recovery confirmation flag is 0 or the state vector clock integrity flag is 0, it is determined that the reporting conditions are not met. In this case, the dataset actually reported to the linkage scheduling agent is an empty set, and edge autonomy continues to be executed without reporting incomplete states.
[0076] Preferably, the cloud receives data uploaded by each edge node and performs status comparisons, specifically as follows:
[0077] The coordinated scheduling agent gathers the local state vector clocks reported by each edge node and the last consistent global state snapshot before the network outage, and defines the partial order relationship between the state vectors.
[0078] The incomparability between state vectors is detected by comparing all-dimensional components, the existence of state bifurcation is determined, the global state vectors are aggregated and a partial order comparison framework is established, and the state bifurcation point during the network outage is located by detecting the incomparability of vector clocks.
[0079] If a state fork exists, it is marked as 1, then a state fork is determined to exist;
[0080] If a state fork exists, it is marked as 0; otherwise, it is determined that no state fork exists.
[0081] Using the last consistent global state snapshot before the network outage as the bifurcation reference, calculate the dimensional deviation of the state vector of each edge node relative to the reference.
[0082] Extract the index of the first event that caused the state deviation from the autonomous logs of each node, quantify the degree of version difference, quantify the version deviation of each node based on the consistent state before the network outage, accurately locate the first autonomous event that caused the fork, and provide a time-series anchor point for conflict tracing;
[0083] If the total version deviation of a node is greater than 0, it is determined that the node has deviated from its state during the network outage.
[0084] If the total version deviation of a node is equal to 0, then the node is determined not to have deviated from its state.
[0085] Extract conflicting instruction pairs that point to overlapping points from the incremental autonomous logs of each edge node, and parse the device identifier, physical region identifier and control semantics corresponding to each instruction;
[0086] Based on the spatial overlap of equipment and area and the semantic mutual exclusion of instructions, the conflict type is determined, the spatial scope and semantic mutual exclusion of instructions are analyzed, and the forked state is transformed into a conflict type that can be merged or requires arbitration, providing a classification basis for subsequent resolution strategies.
[0087] If the mergeable flag of the instruction pair is 1, the instruction pair is determined to be a mergeable conflict. At this time, the conflict type determination result of the instruction pair is output as the mergeable conflict type identifier. Conflicts between different devices or regions are merged. Conflicts between the same device are determined according to the security priority rule to perform incremental merging.
[0088] If the mergeable flag of the instruction pair is 0, then the unmergeable conflict flag of the instruction pair is further determined:
[0089] If the non-mergeable conflict flag of the instruction pair is 1, the instruction pair is determined to be a non-mergeable conflict. At this time, the conflict type determination result of the instruction pair is the non-mergeable conflict type identifier. For conflicts in different devices or regions, merge processing is performed. For conflicts in the same device, the execution strategy is determined according to the security priority rule to perform priority arbitration.
[0090] If the non-mergeable conflict flag of an instruction pair is 0, then the instruction pair is considered compatible and no conflict occurs.
[0091] Preferably, conflicts between different devices or areas are merged, and conflicts between the same device are handled according to a safety priority rule to determine the execution strategy, specifically:
[0092] The coordinated scheduling intelligent agent obtains the set of mergeable conflict instruction pairs by receiving data uploaded from each edge node in the cloud and comparing and judging their status. It then extracts the energy consumption adjustment amount and security deployment range change amount involved in each conflict pair.
[0093] Accumulation and union operations are performed based on region identifiers to generate a unified global correction strategy subset. Mergeable conflicts are incrementally superimposed based on region and device type, and each node is independently adjusted to a unified global correction strategy to eliminate spatially isolated conflicts.
[0094] The coordinated scheduling agent obtains the set of non-mergeable conflicting instruction pairs that receive data uploaded by each edge node from the cloud and performs state comparison and judgment. It then extracts the clock dimension value of the state vector corresponding to the security policy and energy-saving policy in each conflicting pair.
[0095] Based on the safety criticality weight of conflicting devices, safety priority arbitration is performed, and a structured conflict report is generated. For conflicts that cannot be merged, safety priority arbitration is performed. Regardless of the clock dimension, the safety policy overrides the energy-saving policy, and a structured conflict report with the associated version number is generated.
[0096] If the security priority arbitration trigger flag is 1, the security priority arbitration condition is determined to be triggered, and the security policy overrides the energy-saving policy. At this time, the set of execution policy instructions finally determined by the security priority arbitration for the non-mergeable conflict pair is output as the security policy instruction set of the conflict pair.
[0097] If the security priority arbitration trigger flag is 0, the security policy will still be executed according to the preset security priority rules, overriding the energy-saving policy. At this time, the set of execution policy instructions finally determined by the security priority arbitration for the non-mergeable conflict pair will be output as the security policy instruction set of the conflict pair, and a structured conflict report will be generated simultaneously.
[0098] The coordinated scheduling agent gathers the global correction strategy subset after merging conflict resolution and the strategy subset after non-merging conflict arbitration, and calculates the set of conflicts to be processed.
[0099] Based on the empty set determination rules, check whether all conflicts have been resolved and whether all conflicts have been included in the merging or arbitration process. If they have not been resolved, return to re-identification; if they have been resolved, proceed to the global consistency confirmation stage.
[0100] If the conflict resolution completeness flag is 1, it is determined that all conflicts have been resolved or merged, and the consistency of the processed strategy is checked.
[0101] If the conflict resolution completeness is marked as 0, it is determined that there are still unresolved conflicts. The system then returns to the cloud to receive data uploaded by each edge node and performs a status comparison to re-identify the fork point.
[0102] Preferably, the processed strategy is subjected to consistency verification, specifically as follows:
[0103] The coordinated scheduling intelligent agent aggregates and merges conflicts between different devices or regions. For conflicts of the same device, it determines the global correction strategy set output by the execution strategy according to the safety priority rule, as well as the state vector clock transmitted back by each edge node.
[0104] Verify whether the global state vector clock forms a total order relationship, and determine whether global consistency has been achieved by combining the conflict resolution completeness flag. Verify the total order of the global state vector and the conflict resolution completeness to ensure that there is no branching of the global state after network outage recovery, providing a consistent premise for command issuance.
[0105] If global consistency is achieved and the flag is 0, it is determined that there are still incomparable state vectors or unresolved conflicts. The system then returns to the cloud to receive data uploaded by each edge node and performs state comparison to re-identify the fork point.
[0106] If the global consistency achievement is marked as 1, it is determined that the global state vector clock has formed a total sequence and all conflicts have been resolved;
[0107] Then, the coordinated scheduling agent decomposes the global correction strategy set into device-level control instructions according to region and device type;
[0108] By sending commands to the execution terminal through the edge gateway, cross-system linkage execution is achieved. The global correction policy is mapped to specific device instructions and sent out in a coordinated manner, enabling cross-system collaborative execution of security and energy.
[0109] If the device's executable flag is 1, the device is determined to be online, and the corresponding instruction is sent to the device for execution.
[0110] If the device's executable flag is 0, the device is determined to be offline, the device is marked as an abnormal pending state, and the abnormal record is appended to the pending queue.
[0111] Collect the actual energy consumption changes, security incident handling results, and execution quality scores of each edge node after the implementation of the correction strategy;
[0112] By combining the manual review markers of the conflict report, it is determined whether the autonomous case meets the policy evolution conditions. Cases that meet the conditions are included in the policy evolution library to drive the model update of each agent. The execution effect is collected and quantitatively evaluated. High-quality autonomous cases are included in the evolution library to drive model iteration and achieve closed-loop optimization of the entire process of network outage-recovery.
[0113] If the policy evolution condition judgment mark is 1, then the autonomous case is determined to meet the evolution condition, the case is included in the policy evolution library, and incremental updates of the security risk model and energy consumption prediction model are performed.
[0114] If the policy evolution condition is marked as 0, it is determined that the evolution condition is not met, and only the execution log is recorded without including it in the policy evolution library. The system returns to the normal multi-agent collaborative decision-making process.
[0115] The present invention also discloses a system for implementing an enterprise security and energy-saving optimization decision-making method based on multi-agent collaboration, wherein: it includes:
[0116] Data acquisition and network monitoring module: Collects multi-source data, encapsulates it in a standardized manner according to a unified spatiotemporal coordinate system, and synchronously monitors the heartbeat latency and packet loss count between edge nodes and the central hub to determine the status of the communication link;
[0117] Edge preprocessing and cache management module: Deploys a lightweight AI engine on edge nodes to perform video target detection, energy consumption sliding window verification and initial judgment of security anomalies, while maintaining a policy cache area and determining the availability of cache policies based on timeliness and security level;
[0118] Network outage self-governance and status monitoring module: During communication interruption, the module executes security priority or energy-saving adaptive self-governance strategies according to the security status level, updates the local state vector clock and records logs, and continuously monitors the network outage duration and computing power usage. If the limits are exceeded, the module triggers degraded self-governance.
[0119] Conflict identification and arbitration module: aggregates the state vectors of each edge node, locates the state bifurcation point through partial order comparison, classifies conflicts into mergeable or non-mergeable types, performs incremental superposition on mergeable conflicts, and performs safety priority arbitration on non-mergeable conflicts.
[0120] Global Synchronization and Policy Evolution Module: Verifies the total order of the global state vector and the completeness of conflict resolution, decomposes the correction policy into device-level instructions and issues them across systems, collects feedback on execution results, and incorporates high-quality autonomous cases into the policy evolution library to drive model iterative updates.
[0121] The present invention has the following beneficial effects:
[0122] 1. This enterprise security and energy-saving optimization decision-making method and system based on multi-agent collaboration utilizes various sensors deployed within the park to collect video, energy consumption, access control, and environmental parameters in real time. After alignment with a unified spatiotemporal coordinate system, standardized encapsulation is completed. The health of the communication link between edge nodes and the central hub is monitored simultaneously. When the link is abnormal, the edge node immediately activates the autonomous mechanism, performs local analysis on multi-source data through a lightweight preprocessing engine, and determines the availability of the strategy based on the timeliness of the caching strategy and the security level label. During network outages, the edge node performs hierarchical autonomy based on the local security status level. In emergency situations, priority is given to ensuring the full operation of security equipment and shutting down non-critical loads. In normal situations, energy-saving adaptation is performed within the security baseline. Each round of strategy adjustment triggers the increment of the local state vector clock and the recording of the autonomous log. At the same time, the network outage duration and computing power utilization rate are continuously monitored. If the limits are exceeded, the system is downgraded to the most conservative mode to ensure that the security baseline is not breached during the autonomy period. Through the autonomous decision-making capability of the edge side, the basic operation of park security and energy management is maintained in the scenario of communication interruption, avoiding security loss of control or energy waste due to network failure, and achieving uninterrupted policy implementation during network outages.
[0123] 2. This enterprise security and energy-saving optimization decision-making method and system based on multi-agent collaboration, after the communication link is restored, the edge nodes report the local state vector clock and the autonomous execution log accumulated during the network outage to the linkage scheduling agent. The central system gathers the state vectors of each node and compares them with the global snapshot before the network outage in a partial order to locate the state bifurcation point and identify the conflict type. For mergeable conflicts that affect different areas or devices, the energy consumption adjustment amount is accumulated by area and the security deployment range change is merged to form a unified global correction strategy. For non-mergeable conflicts that affect the same device and have contradictory instructions, security priority arbitration is performed according to the security criticality weight and preset rules to cover the energy-saving strategy with the security strategy. A structured conflict report with the associated strategy version number is generated synchronously. After all conflicts are resolved, the system enters the global synchronization stage. If they are not resolved, the system returns to re-identify the bifurcation point. Through the state vector clock and partial order comparison mechanism, the system accurately locates the differences caused by the independent decisions of each node during the network outage and resolves the conflicts with the principle of security priority to ensure the consistency and reliability of the global strategy after recovery.
[0124] 3. This enterprise security and energy-saving optimization decision-making method and system based on multi-agent collaboration verifies the total order relationship and conflict resolution completeness of the global state vector clock by linking and scheduling agents. After confirming consistency, the correction strategy is decomposed into device-level control commands, which are then sent to terminals such as access control, cameras, power distribution, and air conditioning through edge gateways to execute cross-system linkage. Energy consumption changes, security handling results, and node quality scores are collected after execution. Combined with the manual review results of conflict reports, it is determined whether autonomous cases meet the policy evolution conditions. Cases that meet the conditions are included in the policy evolution library, driving incremental updates of the security risk identification model and energy consumption prediction model, continuously optimizing the autonomous and collaborative decision-making capabilities during network outages, and finally returning to the conventional multi-agent collaborative decision-making process. Through execution feedback and model iteration, the experience of autonomous operation during network outages is transformed into the driving force for system evolution, continuously improving the intelligent level of park security and energy collaborative management, and achieving closed-loop optimization throughout the entire process. Attached Figure Description
[0125] Figure 1 This is a flowchart of the enterprise security and energy-saving optimization decision-making method based on multi-agent collaboration of the present invention;
[0126] Figure 2 This is a system block diagram illustrating the enterprise security and energy-saving optimization decision-making method based on multi-agent collaboration of the present invention.
[0127] Figure 3 The flowchart of the edge strategy mirroring network disconnection autonomous mechanism as described in claims 2-5 of this invention is shown below.
[0128] Figure 4 This is a flowchart of the state vector clock arbitration process for network outage recovery as described in claims 6-8 of this invention.
[0129] Figure 5 This is a schematic diagram of the hydraulic pipe fitting testing error compensation system based on intelligent sensors according to the present invention. Detailed Implementation
[0130] Example 1: A multi-agent collaborative enterprise security and energy-saving optimization decision-making method is applied to industrial park energy control systems, security control systems, or smart park management platforms. It controls and executes decisions on physical devices within the park through an industrial control gateway. (See reference...) Figure 1 ,include:
[0131] Collect multi-source sensing data and perform spatiotemporal alignment and standardization processing; monitor heartbeat latency and packet loss between edge nodes and the cloud; construct a link status determination function based on heartbeat round-trip latency and number of consecutive packet losses; and select cloud-collaborative or edge autonomous channels based on the determination results.
[0132] In edge processing mode, perform local preprocessing on the data, read the local policy cache and verify its timeliness and security level, and output the caching policy or the most conservative policy.
[0133] Select the control mode based on the security status and energy consumption status, drive the strategy execution and synchronously update the multi-dimensional state vector clock and execution log;
[0134] During edge operation, continuous valid heartbeats are counted, and when recovery conditions are met, the state vector clock increment and logs are extracted, encapsulated, and reported.
[0135] The cloud receives data uploaded by each edge node and compares their status, and constructs a conflict classification function based on the device scope and command semantics;
[0136] Conflicts between different devices or regions are merged; conflicts of the same device are determined according to the safety priority rule; mergeable conflicts are overlaid; and non-mergeable conflicts are arbitrated based on the safety weight function and a global policy is generated.
[0137] Perform a consistency check on the processed strategy.
[0138] Example 2 is an improvement upon Example 1. (See attached document for details.) Figure 3 This enterprise security and energy-saving optimization decision-making method based on multi-agent collaboration collects multi-source sensing data and performs spatiotemporal alignment and standardization processing to monitor heartbeat latency and packet loss between edge nodes and the cloud. Specifically:
[0139] Acquire smart cameras, smart water and electricity meters, photovoltaic sensors, biometric access control systems, infrared detectors, and environmental sensors deployed in the park;
[0140] Based on the unified network time protocol and three-dimensional spatial coordinate system, video stream frame sequences, instantaneous energy consumption values, passage records, security trigger signals, and environmental parameters are collected synchronously.
[0141] Establish a spatiotemporal correlation index to generate the original multimodal dataset. It aggregates multi-source heterogeneous sensing data from the park, aligns them using a unified spatiotemporal coordinate system, eliminates data silos and semantic gaps, and provides a consistent data foundation for subsequent intelligent agent collaboration across the entire domain.
[0142] ;
[0143] In the formula, The original multimodal dataset, This represents the total number of sensor nodes. For the first The three-dimensional spatial coordinate vector of each node. Represents the set of real numbers. It is an absolute timestamp after unified time synchronization. For the first The node The raw sampled values of the sensor. A set of sensor types, These correspond to five categories: video, energy consumption, access control, infrared, and environment.
[0144] For the original multimodal dataset Perform standardized encapsulation to unify data with different dimensions and protocol formats into structured standard values;
[0145] Simultaneously, a preliminary data quality screening is performed, determining whether there are abnormal jumps in the current sampled values based on historical statistical characteristics, detecting the duration of missing data, and generating standardized packaged data values after dimensional normalization. and quality certification mark The raw data is standardized, packaged, and initially screened for quality, removing anomalous jumps and excessively long missing samples, and the data credibility is marked to ensure that the data entering the decision-making process is authentic and reliable.
[0146] ;
[0147] ;
[0148] In the formula, These are the standard encapsulated data values after dimensional normalization. , The first The historical maximum and minimum calibration values of this type of sensor For the first Node number Quality acceptance criteria for class data This is an indicator function; it outputs 1 if the logical condition within the parentheses is true, and 0 otherwise. For the first Node number The moving average of historical sampled values from the same period of the sensor. This represents the corresponding historical moving standard deviation. This is the tolerance coefficient for abnormal jumps. The time interval between the current sampling time and the most recent valid sampling time. This is the maximum allowable data loss tolerance time for the system.
[0149] The first requirement for determining quality conformity marks If the inequality is true, then determine the first... Node number If no abnormal jump occurs in the data type, the corresponding indicator function outputs 1. If the inequality does not hold, that is... , it is determined that an abnormal jump has occurred, and the output of the corresponding indication function is 0;
[0150] For the second determination requirement of the quality qualified mark , if this inequality holds, it is determined that the data missing duration is not exceeded, and the output of the corresponding indication function is 1. If this inequality does not hold, that is , it is determined that the data missing duration is exceeded, and the output of the corresponding indication function is 0;
[0151] Quality qualified mark It is determined by the product of the above two indication functions. If both are 1, the quality qualified mark The output is 1. If any one is 0, the quality qualified mark The output is 0;
[0152] If the quality qualified mark The output is 1, it is determined that the data quality is qualified;
[0153] If the quality qualified mark The output is 0, it is determined that the data quality is unqualified;
[0154] The edge node periodically sends a heartbeat detection message to the联动调度智能体;
[0155] Real-time monitor the round-trip delay and the number of consecutive packet losses;
[0156] According to the double-threshold determination rule, divide the communication link status, and accordingly determine the standardized data flow to the cloud collaboration channel or the edge autonomous preprocessing channel. Real-time monitor the communication link health of the edge node and the central hub. According to the double indicators of delay and packet loss, determine the link status and decide the data flow to the edge autonomous channel or the cloud collaboration channel:
[0157] ;
[0158] ;
[0159] In the formula, is the communication link status flag, is the round-trip delay of the most recent heartbeat detection message, is the preset heartbeat delay abnormal threshold, is the cumulative packet loss number of consecutive heartbeat detections without response, is the consecutive packet loss threshold for triggering link anomaly determination, is the logical or operator, is the logical and operator, is the data set entering the edge preprocessing channel, is the data set uploaded to the cloud联动调度智能体;
[0160] If the communication link status flag If the output is 1, the communication link is determined to be abnormal;
[0161] Then, the standardized dataset is output to the edge preprocessing channel, denoted as... ;
[0162] If the communication link status flag If the output is 0, the communication link is considered to be normal.
[0163] Then, the standardized dataset is uploaded to the cloud to coordinate and schedule the intelligent agent, denoted as... .
[0164] This embodiment also provides that, in edge processing mode, local preprocessing is performed on the data, and the local policy cache is read and its timeliness and security level are verified, specifically:
[0165] Edge nodes receive and collect multi-source sensing data and perform spatiotemporal alignment and standardization processing to monitor the heartbeat latency and packet loss between edge nodes and the cloud, outputting a standardized dataset.
[0166] Deploy a lightweight AI inference engine to perform object detection and behavior recognition on video data, generate object confidence vectors, and filter invalid images;
[0167] Perform sliding window verification on instantaneous energy consumption values to generate abnormal fluctuation markers;
[0168] Perform local preliminary judgment on security anomaly signals and generate security anomaly confidence level;
[0169] Simultaneously monitor the current available computing power resource ratio of edge nodes to determine the feasibility of local preprocessing, complete data dimensionality reduction and initial anomaly screening at the edge, and monitor computing power margin to ensure that preprocessing does not exceed the carrying capacity of edge nodes:
[0170] ;
[0171] ;
[0172] ;
[0173] In the formula, This is the feature dataset after edge preprocessing. For the first The three-dimensional spatial coordinate vector of each node. Represents the set of real numbers. It is an absolute timestamp after unified time synchronization; For the first Target detection confidence vector of a node video stream. For the first Marking abnormal fluctuations in node energy consumption data using a sliding window. For the first Local initial confidence level of node security signals. This represents the current available computing power ratio of the edge nodes. This represents the current amount of idle computing resources at the edge node. This represents the total computing power resources of the edge nodes. To determine the threshold for sufficient computing power, Mark the edge preprocessing as feasible. This is an indicator function; it outputs 1 if the logical condition within the parentheses is true, and 0 otherwise.
[0174] Mark if edge preprocessing is feasible. If the output is 1, it is determined that the edge computing power is sufficient, and local lightweight preprocessing is performed. This means that under the condition of sufficient computing power, the edge node deploys a lightweight AI inference engine with model compression, performs target detection and behavior recognition on the video stream and filters invalid images, performs sliding window verification and abnormal fluctuation marking on the instantaneous energy consumption value, performs local preliminary judgment on security abnormal signals, generates feature datasets and reduces cloud transmission pressure.
[0175] Mark if edge preprocessing is feasible. If the output is 0, it is determined that the edge computing power is insufficient. Only data pass-through and simplified anomaly marking are performed. Complex features are not uploaded. Performing data pass-through and simplified anomaly marking means that when the edge node computing power is insufficient (the available computing power ratio is lower than the threshold), complex AI inference is abandoned. Only standardized data is directly passed through or the most basic over-limit anomaly marking is performed. Complex features such as target detection confidence vector are not uploaded to ensure that the edge node does not crash due to overload.
[0176] Read the decision image sequence from the local policy cache, arranged in reverse order of version timestamp;
[0177] Extract the latest valid decision image ranked first, calculate the time interval between its version timestamp and the current system time, and determine whether the image has expired based on the policy validity threshold. Quantitatively evaluate the freshness of the caching policy to prevent edge autonomy from executing outdated policies and reduce the risk of decision failure.
[0178] ;
[0179] ;
[0180] In the formula, This is the current system's absolute timestamp. The timestamp of the latest decision image version, ranked first in the cache, is superscripted. Indicates the first position in the sort order. This represents the interval between the timestamp of the mirror version and the current time. This is the threshold for the validity period of the strategy. This is a mark indicating that the product meets the timeliness requirement. For indicator functions;
[0181] If the timeliness is qualified mark If the value is 1, the timeliness of the mirror image is deemed acceptable.
[0182] If the timeliness is qualified mark If the value is 0, the image is considered expired;
[0183] Extract the security level tag of the latest decision image and verify whether it belongs to the system's predefined set of valid security levels;
[0184] By combining timeliness compliance markers and security level validity markers, the overall availability of the caching strategy is determined through joint multiplication operations. Based on this, either the caching strategy or the most conservative default strategy is selected for execution. The credibility of the caching strategy is determined by considering both timeliness and security level constraints, ultimately deciding whether to implement a fine-grained, tiered, autonomous, or downgraded conservative strategy to solidify the security baseline.
[0185] ;
[0186] ;
[0187] ;
[0188] In the formula, The security level label for the latest decision image ranked first in the cache. A predefined set of valid security level tags for the system. For marking the validity of security levels, The availability flag for caching strategies is jointly determined by timeliness and security. This is the complete policy set corresponding to the latest valid decision image in the cache. This is the most conservative default policy set, which includes maintaining minimum power supply for security, maintaining the last valid access control permissions, and shutting down non-critical equipment. The final set of execution strategies;
[0189] If the security level validity label If the value is 1, the security level label is considered valid;
[0190] If the security level validity label If the value is 0, the security level marker is deemed invalid.
[0191] If the timeliness is qualified mark A value of 1 and a security level validity marker If the value is 1, then the caching strategy incorporates the availability flag. If the output is 1, the caching strategy is deemed available, and the final set of execution strategies is selected. The complete policy set corresponding to the latest valid decision image in the cache. The system selects the control mode based on the security status and energy consumption status to implement hierarchical autonomy.
[0192] If the timeliness is qualified mark Mark 0 or security level validity If the value is 0, the caching strategy will be based on the overall availability flag. If the output is 0, the caching strategy is deemed unavailable, and the final set of execution strategies is selected. The most conservative default policy set It directly executes the most conservative default policy and selects the control mode according to the security status and energy consumption status. Executing the most conservative default policy refers to the security bottom line policy triggered when the cached policy image expires or the security level mark fails. Specifically, it includes: maintaining the minimum power supply for security (ensuring basic power for monitoring and access control), maintaining the last valid access control permission status, and shutting down all non-critical equipment to prevent security from going out of control due to policy failure.
[0193] This embodiment also provides that the control mode is selected according to the security status and energy consumption status, specifically:
[0194] The local security agent at the edge node outputs the current security status level based on multi-source fusion features;
[0195] Energy intelligence agent outputs regional energy consumption status;
[0196] The coordinated dispatching agent extracts the corresponding device control list from the cache policy based on the security situation level, selects the autonomous policy execution mode, and divides the autonomous mode according to the security situation level. In case of emergency or abnormality, security takes precedence over everything, while in normal times, energy-saving optimization is also taken into account to ensure that the security bottom line is not breached.
[0197] ;
[0198] In the formula, For the first The current security status level output by the local security agent at each edge node. This is a set of security situation levels, where 1 corresponds to emergency, 2 to abnormal, and 3 to normal. For the selected autonomous strategy implementation mode, In a safety-first self-governance mode, minimum energy consumption is guaranteed in abnormal areas, video and access control systems operate at full capacity, and all non-critical lighting and air conditioning are shut down. For the energy-saving adaptation mode under security constraints, the energy-saving control instructions in the caching strategy are executed within the security baseline;
[0199] If the security situation level is emergency or abnormal, i.e., the first The current security status level output by the local security agent at each edge node. If the value is 1 or 2, the security-first autonomous mode is triggered, and the selected autonomous strategy execution mode is adopted. The output is a security-first autonomous mode. ;
[0200] If the security status level is normal, i.e., the first level... The current security status level output by the local security agent at each edge node. If the value is 3, it indicates that the energy-saving adaptation autonomous mode has been triggered, and the selected autonomous strategy execution mode will be used. The output is the energy-saving adaptation mode under safety constraints. ;
[0201] Based on the selected autonomous strategy execution mode, the edge node sends the corresponding set of strategy instructions to each execution terminal, and synchronously increments the clock value in the corresponding dimension of the local state vector clock.
[0202] The policy execution events are appended to the autonomous execution log, and the autonomous policy is executed hierarchically according to the selected mode. The state vector clock is updated synchronously and the execution log is recorded to provide traceable temporal evidence for subsequent conflict resolution.
[0203] ;
[0204] ;
[0205] ;
[0206] In the formula, For the first The set of autonomous strategy instructions actually executed by each edge node. This is a subset of the safety-first strategy, including instructions to ensure minimum power supply in abnormal areas and maintain full functionality of video and access control systems. This is a subset of the mandatory shutdown strategy for non-critical equipment. This is the device control list in the caching strategy. Define an inviolable security power supply and access control boundary as a set of security baseline constraints. The union operator. The intersection operator. The symbol for the empty set. For the first The edge node 3D state vector clock at The value at time, For the first time after the strategy is executed dimensional state vector clock value, For the set of clock dimension indices of the state vector, Corresponding to the security dimension, Corresponding to the energy dimension, Corresponding to the scheduling dimension, This is an indicator function; it outputs 1 if the logical condition within the parentheses is true, and 0 otherwise. For the first The node A subset of policy instructions actually issued by the intelligent agent. For the first A collection of autonomous execution logs for each edge node. For the assignment update symbol, This is the absolute timestamp of the strategy execution moment. The complete state vector clock after policy execution;
[0207] If the selected autonomous strategy execution mode The output is a security-first autonomous mode. Then the first The set of autonomous strategy instructions actually executed by each edge node For a subset of security-first strategies Subset of mandatory shutdown strategies for non-critical equipment The union of these, implementing a safety-first strategy and shutting down non-critical equipment. Implementing a safety-first strategy refers to the autonomous mode triggered when the security situation level is emergency or abnormal. Specifically, this includes: implementing minimum energy consumption supply in abnormal areas (only ensuring power for security equipment), maintaining full functionality of video and access control systems, and forcibly shutting down all non-critical lighting and air conditioning. Any energy-saving optimization operations are prohibited. Non-critical equipment refers to auxiliary equipment that does not affect the basic security operation, including but not limited to: lighting systems, air conditioning systems, non-production socket power supplies, and landscape power supplies in non-security areas. These can be forcibly shut down in the safety-first or degraded autonomous mode to save power.
[0208] If the selected autonomous strategy execution mode The output is the energy-saving adaptation mode under safety constraints. Then the first The set of autonomous strategy instructions actually executed by each edge node Device control list in the caching strategy With safety bottom line constraint set The intersection of these elements, under the constraint of the safety baseline, executes the energy-saving adaptation command, meaning that when the security status level is normal, the energy-saving adaptation command is executed within the set of safety baseline constraints. Within the scope, execute energy-saving control instructions in the caching strategy, such as intelligent adjustment of power load, shutdown of idle equipment, optimization of photovoltaic output, and staggered operation of equipment.
[0209] If the first The intelligent agent actually issued policy instructions, that is... If the indicator function outputs 1, the corresponding dimension clock value increments by 1.
[0210] If the first The agent-like entity did not actually issue policy instructions, that is If the indicator function outputs 0, the clock value for the corresponding dimension remains unchanged;
[0211] Real-time monitoring of the cumulative duration of network outages and the local computing power utilization rate of edge nodes;
[0212] The sustainability of the current autonomous strategy is assessed based on a dual-threshold judgment rule to determine whether to trigger a downgraded autonomous mode. The duration of network outage and computing power margin are evaluated in real time. If the limits are exceeded, the system will downgrade to the most conservative mode to prevent edge nodes from losing control of security due to resource exhaustion or strategy aging.
[0213] ;
[0214] ;
[0215] ;
[0216] ;
[0217] In the formula, This is the current system's absolute timestamp. This is the timestamp of the moment when the communication link anomaly was determined, i.e., the starting point of the network outage countdown. The duration of continuous internet outages, This represents the current available computing power ratio of the edge nodes. This refers to the local computing power utilization rate of edge nodes. This represents the maximum tolerance threshold for network outages. This is the upper limit threshold for computing power security. For logical OR operator, For the downgrade trigger flag, For the final implementation of the autonomous model, In the downgraded autonomous mode, only security sensing and minimum power supply are retained, and all energy-saving related calculations and controls are suspended.
[0218] If the downgrade trigger flag If the value is 1, it indicates that the network outage duration has exceeded the limit or the computing power is overloaded, triggering a degraded autonomous mode. In this case, the final autonomous mode executed is... The output is in degraded autonomous mode. It also returns collected multi-source sensing data and performs spatiotemporal alignment and standardization processing, monitors the heartbeat latency and packet loss between edge nodes and the cloud, and continuously monitors network recovery.
[0219] If the downgrade trigger flag If the value is 0, it is determined that both the network outage duration and computing power are within the tolerable range, and the current autonomous strategy is maintained. In this case, the final autonomous mode executed is... The output is the selected autonomous strategy execution mode. It also returns collected multi-source sensing data and performs spatiotemporal alignment and standardization processing, monitors the heartbeat latency and packet loss between edge nodes and the cloud, and continuously monitors network recovery.
[0220] This embodiment also provides the ability to count continuous valid heartbeats during edge operation, specifically:
[0221] During the period of network outage autonomy, edge nodes listen for heartbeat detection messages issued by the linkage scheduling agent and perform validity verification on each heartbeat packet received within the monitoring window.
[0222] The system counts the cumulative number of consecutive valid heartbeats and determines whether the communication link has truly recovered based on a recovery confirmation threshold. It strictly determines whether the link has truly recovered by continuously counting valid heartbeats and adhering to the threshold, preventing false recovery errors caused by network jitter.
[0223] ;
[0224] ;
[0225] In the formula, For self-time The cumulative count of valid heartbeat packets continuously received by the edge node within the monitoring window period. To monitor the total number of heartbeat messages received within the monitoring window period, For the first The validity flag for each heartbeat packet: a value of 1 indicates that the heartbeat packet passed verification, and a value of 0 indicates that the verification failed or there was no response after a timeout. This is an indicator function; it outputs 1 if the logical condition within the parentheses is true, and 0 otherwise. A confirmation flag for communication recovery. The preset recovery confirmation threshold represents the minimum number of consecutive valid heartbeats required to determine if communication has been restored.
[0226] If the communication recovery confirmation flag is displayed If the value is 1, it is determined that the communication link has been truly restored;
[0227] If the communication recovery confirmation flag is displayed If the value is 0, the heartbeat recovery is considered unstable, and marginal autonomy continues.
[0228] Extract the state vector clock values maintained by the local security agent, energy agent, and linkage scheduling agent at the edge node;
[0229] Calculate the clock increment for each dimension during the network outage and verify its monotony, non-negativity, and dimensional completeness to ensure the state vector clock is complete and usable. Verify the completeness and monotonicity of the three-dimensional state vector clock to ensure that all autonomous operations are completely recorded and without logical conflicts during the network outage.
[0230] ;
[0231] ;
[0232] ;
[0233] In the formula, For the first The local state vector clock of each edge node consists of three-dimensional clock values. The state vector clock value maintained by the security agent, corresponding to the security dimension. The state vector clock value maintained by the energy agent corresponds to the energy dimension. The state vector clock value maintained by the coordinated scheduling agent corresponds to the scheduling dimension. For the first The increment of the state vector clock during the network outage. This is the current system's absolute timestamp. This is the timestamp at the moment the communication link anomaly was determined, i.e., the start time of the network outage. For state vector clock integrity marking, The multiplication symbol represents a logical AND operation on the three-dimensional verification result. For a set of dimension indexes, Corresponding to the security dimension, Corresponding to the energy dimension, Corresponding scheduling dimension;
[0234] If the state vector clock integrity flag It is 1, meaning it applies to all dimensions. All exist If so, then the state vector clock is determined to be monotonic and complete;
[0235] If the state vector clock integrity flag A value of 0 indicates the existence of any dimension. exist If so, it is determined that the state vector clock has an abnormal jump or is missing;
[0236] Extract the incremental subset of autonomous execution logs generated during the network outage;
[0237] Encapsulate the local state vector clock value, incremental log, recovery confirmation flag, and integrity flag into a reporting data packet;
[0238] Based on the joint judgment result, a decision is made on whether to initiate state synchronization with the coordinated scheduling agent, extract the network outage incremental log, encapsulate and report it to avoid full transmission redundancy, and realize an efficient transition from the edge policy mirror network outage autonomy mechanism to network outage recovery state vector clock arbitration:
[0239] ;
[0240] ;
[0241] ;
[0242] In the formula, For the first The complete set of autonomous execution logs accumulated by each edge node during the network outage. For a single autonomous execution log record, For logging The corresponding strategy execution timestamp, This is the moment before the network outage when the state was successfully synchronized with the coordinated scheduling agent for the last time. This is a subset of the incremental autonomous execution logs generated during the network outage, containing only logs newly generated after the network outage. For the encapsulated data packets to be reported, The complete local state vector clock at the current moment. The dataset actually reported to the coordinated scheduling agent. The symbol for an empty set indicates that no data is reported.
[0243] If the communication recovery confirmation flag is displayed The state vector clock integrity flag is 1. If the value is 1, the reporting condition is determined to be met. In this case, the dataset actually reported to the linkage scheduling agent is... Encapsulated data packets to be reported The local state vector clock value and incremental autonomous execution log are reported to the linkage scheduling agent. The cloud receives the data uploaded by each edge node and performs state comparison to start the network disconnection recovery state vector clock arbitration.
[0244] If the communication recovery confirmation flag is displayed For 0 or state vector clock integrity flag If the value is 0, the reporting conditions are not met. In this case, the dataset actually reported to the coordinated scheduling agent is not considered to be true. If the set is empty, edge autonomy continues to be implemented, and incomplete states are not reported. Executing edge autonomy means that when the heartbeat recovery is unstable (the number of consecutive valid heartbeat packets has not reached the recovery confirmation threshold), the edge node continues to make autonomous decisions and executes according to the local caching strategy or the most conservative default strategy, without reporting incomplete states to the linkage scheduling agent, and maintaining independent operation during the network outage period.
[0245] Example 3 is an improvement upon Example 2. (See attached document for details.) Figure 4 In this embodiment, the cloud receives data uploaded by each edge node and performs a status comparison, specifically as follows:
[0246] The coordinated scheduling agent gathers the local state vector clocks reported by each edge node and the last consistent global state snapshot before the network outage, and defines the partial order relationship between the state vectors.
[0247] By comparing all components, incomparability between state vectors is detected to determine if state bifurcation exists. Global state vectors are aggregated and a partial-order comparison framework is established. State bifurcation points during network outages are located by detecting incomparability of vector clocks.
[0248] ;
[0249] ;
[0250] ;
[0251] ;
[0252] In the formula, For the set of global state vectors, For the first Local state vector clocks reported by each edge node This is the last consistent global state snapshot before the network outage. This represents the total number of edge nodes. The partial order relation symbol represents the happens-before relationship between state vectors. It is if and only if the symbol is true. It is a universal quantifier, meaning "for all". For the set of clock dimension indices of the state vector, Corresponding to the security dimension, Corresponding to the energy dimension, Corresponding to the scheduling dimension, The notation for concurrent incomparability indicates that the order of two state vectors cannot be determined by a partial order comparison. For logical NOT symbol, For logic and symbols, A flag exists indicating a state fork. It is an existential quantifier, indicating existence. For the set of edge node indices, This indicates that the node indices are not equal. This is an indicator function; it outputs 1 if the logical condition within the parentheses is true, and 0 otherwise.
[0253] If a state fork exists, a marker is present. It is 1, that is If so, then a state fork exists;
[0254] If a state fork exists, a marker is present. =0, that is, for all All If so, then it is determined that there is no state fork;
[0255] Using the last consistent global state snapshot before the network outage as the bifurcation reference, calculate the dimensional deviation of the state vector of each edge node relative to the reference.
[0256] Extract the index of the first event in the autonomous logs of each node that caused the state deviation, quantify the degree of version difference, and quantify the version deviation of each node based on the consistent state before the network outage, so as to accurately locate the first autonomous event that caused the fork and provide a time-series anchor for conflict tracing:
[0257] ;
[0258] ;
[0259] ;
[0260] ;
[0261] In the formula, The reference state vector for state bifurcation. For the first The node The deviation of the state vector clock from the bifurcation reference. The first fork criterion Dimensional clock value, For the first Total version deviation of each node The summation symbol indicates that the deviations in the three dimensions are accumulated. For the first The index of the first autonomous event that causes a state deviation in a given node. It is a set of positive integers. For the first The node The execution timestamp of the autonomous log. This refers to the state fork moment, which is the last synchronization moment before the network outage. This is a minimum value function that returns the smallest positive integer that satisfies the given condition.
[0262] If the first Total version deviation of each node If it is greater than 0, then determine the first... One node experienced a state deviation during the network outage;
[0263] If the first Total version deviation of each node If the value is 0, then determine the first... No node has deviated from its state.
[0264] Extract conflicting instruction pairs that point to overlapping points from the incremental autonomous logs of each edge node, and parse the device identifier, physical region identifier and control semantics corresponding to each instruction;
[0265] Based on the spatial overlap between devices and regions and the semantic mutual exclusion of instructions, the conflict type is determined, the spatial scope and semantic mutual exclusion of instructions are analyzed, and the forked state is transformed into a conflict type that can be merged or requires arbitration, providing a classification basis for subsequent resolution strategies:
[0266] ;
[0267] ;
[0268] ;
[0269] ;
[0270] In the formula, For the first A set of device instructions extracted from incremental logs by each edge node. For the first The device identifier corresponding to each instruction. For the first The physical region identifier corresponding to each instruction. For the first The control semantics encoding of the instruction For the first The total number of entries in the incremental log of each node. Represents the cardinality of a set For instruction pairs Mergeable tags, For instruction pairs Unmergeable conflict markers This is a function to determine the mutual exclusion of instruction semantics. A value of 1 indicates that the control objectives of the two instructions conflict, and a value of 0 indicates that they do not conflict. For instruction pairs The result of the conflict type determination, This is an identifier for mergeable conflict types. This is an identifier for a non-mergeable conflict type, requiring priority arbitration.
[0271] If the instruction is correct Mergeable tags It is 1, that is Then determine the instruction to For mergeable conflicts, the instruction pair Conflict type determination result The output is a mergeable conflict type identifier. For conflicts between different devices or regions, merge processing is performed; for conflicts within the same device, the execution strategy is determined according to the safety priority rule to perform incremental merging.
[0272] If the instruction is correct Mergeable tags It is 0, that is Then further determine the instruction's effect. Unmergeable conflict marker :
[0273] If the instruction is correct Unmergeable conflict marker It is 1, that is Then determine the instruction to For non-mergeable conflicts, in this case, the instruction pair Conflict type determination result The output is a non-mergeable conflict type identifier. For conflicts between different devices or regions, merge the processing; for conflicts of the same device, determine the execution strategy according to the security priority rule and execute priority arbitration.
[0274] If the instruction is correct Unmergeable conflict marker It is 0, that is Then determine the instruction to The instructions are compatible and do not cause conflicts.
[0275] This embodiment also provides a method for merging conflicts between different devices or regions, and for determining the execution strategy for conflicts within the same device according to a security priority rule, specifically:
[0276] The coordinated scheduling intelligent agent obtains the set of mergeable conflict instruction pairs by receiving data uploaded from each edge node in the cloud and comparing and judging their status. It then extracts the energy consumption adjustment amount and security deployment range change amount involved in each conflict pair.
[0277] Accumulation and union operations are performed based on region identifiers to generate a unified global correction strategy subset. Mergeable conflicts are incrementally superimposed based on region and device type, and the independent adjustments of each node are aggregated to a unified global correction strategy to eliminate spatially isolated conflicts.
[0278] ;
[0279] ;
[0280] ;
[0281] ;
[0282] In the formula, For a set of mergeable conflicting instruction pairs, For conflicting instruction pairs index, The cloud receives data uploaded from each edge node, performs status comparisons, and outputs conflict type determination results. This is an identifier for mergeable conflict types. For the region The cumulative energy consumption adjustment, For the conflict In the region Energy consumption adjustment amount, The summation symbol indicates that the energy consumption adjustments for all conflict pairs within the same region are accumulated. For the region The cumulative number of changes in the security deployment area. For the conflict In the region Collection of security deployment range changes, The set union operator represents merging the sets of security changes for all conflicting pairs within the same region. This is a subset of global correction strategies that can be merged after conflict resolution. A set of region identifiers that can be merged in conflict;
[0283] The coordinated scheduling agent obtains the set of non-mergeable conflicting instruction pairs that receive data uploaded by each edge node from the cloud and performs state comparison and judgment. It then extracts the clock dimension value of the state vector corresponding to the security policy and energy-saving policy in each conflicting pair.
[0284] Based on the safety criticality weights of conflicting devices, safety-priority arbitration is performed, and a structured conflict report is generated. For conflicts that cannot be merged, safety-priority arbitration is performed. Regardless of clock dimension priority, the safety policy overrides the energy-saving policy, and a structured conflict report with the associated version number is generated.
[0285] ;
[0286] ;
[0287] ;
[0288] ;
[0289] In the formula, For a set of non-mergeable conflicting instruction pairs, This is an identifier for non-mergeable conflict types. Triggering a flag for priority arbitration, For the conflict The clock dimension value of the state vector corresponding to the security policy in the middle. For the conflict The clock dimension value of the state vector corresponding to the energy-saving strategy. For conflict equipment Safety criticality weight To pre-set the safety criticality weight threshold, For logical OR operator, For the conflict Security policy instruction set, For structured conflict reporting, The global state vector clock is the clock at the arbitration moment. For the associated policy version number, For non-mergeable conflict pairs The final set of execution policy instructions determined after security-priority arbitration, in cases of irreconcilable conflicts (such as conflicting instructions issued by security and energy-saving policies to the same device), will always execute the security policy over the energy-saving policy, regardless of whether the clock dimension value of the security policy is higher than that of the energy-saving policy. Always equal to the security policy instruction set That is, the set of control commands ultimately issued to the conflicting device;
[0290] If the security priority arbitration triggers the flag. It is 1, that is If the security priority arbitration condition is triggered, the security policy will override the energy-saving policy. In this case, the non-mergeable conflict pair... The final set of execution strategy instructions determined after security-priority arbitration. Output is conflict pair Security policy instruction set The implementation of security policy over power-saving policy means that for non-mergeable conflicts (where the same device receives contradictory instructions from both security and power-saving policies), the security policy instruction set will be prioritized according to the pre-defined security priority arbitration rules, regardless of the state vector clock dimension value. To ensure the final implementation, the equipment will be kept in full operation, sacrificing the corresponding energy consumption optimization benefits;
[0291] If the security priority arbitration triggers the flag. It is 0, that is If the preset security priority rule applies, the security policy will still override the energy-saving policy. In this case, conflicting pairs cannot be merged. The final set of execution strategy instructions determined after security-priority arbitration. Output is conflict pair Security policy instruction set Simultaneously generate structured conflict reports ;
[0292] The coordinated scheduling agent gathers the global correction strategy subset after merging conflict resolution and the strategy subset after non-merging conflict arbitration, and calculates the set of conflicts to be processed.
[0293] Based on the empty set determination rules, verify whether all conflicts have been resolved, and whether all conflicts have been included in the merging or arbitration process. If not resolved, return to re-identification; otherwise, proceed to the global consistency confirmation stage.
[0294] ;
[0295] ;
[0296] ;
[0297] In the formula, For a global set of correction strategies, The union operator. For the set of conflicts to be processed, This refers to the set of all conflicts that are received from the cloud by each edge node and whose status is compared and identified. The set difference operator removes merged and arbitrated conflicts from the total conflict set. Completeness markers for conflict resolution The symbol for the empty set is , which represents a set that contains no elements. This is an indicator function; it outputs 1 if the logical condition within the parentheses is true, and 0 otherwise.
[0298] If the conflict resolution completeness mark It is 1, that is If all conflicts have been resolved or merged, then the consistency of the processed strategy is checked.
[0299] If the conflict resolution completeness mark It is 0, that is If the conflict is not resolved, the system will return to the cloud to receive data uploaded by each edge node and perform a status comparison to re-identify the fork point.
[0300] This embodiment also provides a consistency check for the processed strategy, specifically:
[0301] The coordinated scheduling intelligent agent aggregates and merges conflicts between different devices or regions. For conflicts of the same device, it determines the global correction strategy set output by the execution strategy according to the safety priority rule, as well as the state vector clock transmitted back by each edge node.
[0302] Verify whether the global state vector clocks form a total order relationship, and determine whether global consistency has been achieved by combining the conflict resolution completeness flag. Verify the total order of the global state vector and the completeness of conflict resolution to ensure that there are no branches in the global state after network outage recovery, providing a consistent prerequisite for command issuance.
[0303] ;
[0304] In the formula, Achieving global consistency is marked. To perform merge processing on conflicts from different devices or regions, for conflicts on the same device, the conflict resolution completeness flag is determined according to the security priority rule and the output of the execution strategy. It is a non-existent quantifier, indicating that something does not exist. For the set of edge node indices, The node indices are not equal. For the first The state vector clock transmitted back by each edge node The notation for concurrent incomparability indicates that the order of two state vectors cannot be determined by a partial order comparison. For logical AND operator, This is an indicator function; it outputs 1 if the logical condition within the parentheses is true, and 0 otherwise.
[0305] If global consistency is achieved, a flag is set. It is 0, that is If the state vectors are still incomparable or the conflict has not been resolved, the system returns to the cloud to receive the data uploaded by each edge node and performs state comparison to re-identify the bifurcation point.
[0306] If global consistency is achieved, a flag is set. It is 1, that is If so, it is determined that the global state vector clock has formed a total sequence and all conflicts have been resolved;
[0307] Then, the coordinated scheduling agent decomposes the global correction strategy set into device-level control instructions according to region and device type;
[0308] By distributing commands to execution terminals such as access control, cameras, power switches, lighting, and air conditioning through the edge gateway, cross-system coordinated execution is achieved. Global correction policies are mapped to specific device commands and distributed in a coordinated manner, enabling cross-system collaborative execution of security and energy systems.
[0309] ;
[0310] ;
[0311] In the formula, It is a set of device-level control commands. To execute the device identifier, For equipment Control semantic encoding, For the timestamp of the instruction issuance, It is an existential quantifier. For the global correction strategy, the region The strategy tuple, To perform merge processing on conflicts from different devices or regions, for conflicts on the same device, a global set of correction strategies is determined based on the security priority rule to output the execution strategy. For the region The set of execution devices within, This is a mapping function from policy to device instructions. For equipment Executable tags, For equipment Real-time online status For online status indicators, For indicator functions;
[0312] If the device Executable tags It is 1, that is Then determine the device Online, will provide the corresponding instructions Send to device implement;
[0313] If the device Executable tags It is 0, that is Then determine the device If the device is offline, mark it as an abnormal pending state and append the abnormal record to the pending queue.
[0314] Collect the actual energy consumption changes, security incident handling results, and execution quality scores of each edge node after the implementation of the correction strategy;
[0315] Based on the manual review markers of the conflict report, it is determined whether the current autonomous case meets the policy evolution conditions. Cases that meet the conditions are added to the policy evolution library to drive the model updates of each agent. The execution effect is collected and quantitatively evaluated. High-quality autonomous cases are added to the evolution library to drive model iteration, achieving closed-loop optimization of the entire network outage-recovery process.
[0316] ;
[0317] ;
[0318] ;
[0319] ;
[0320] ;
[0321] ;
[0322] In the formula, This represents the actual change in global energy consumption after the strategy is executed. For summation, For the set of region identifiers involved in the strategy, For the region Energy consumption value after execution For the region Baseline energy consumption value before execution The average score for the execution quality of each edge node. This represents the total number of edge nodes. Represents the cardinality of a set. For the first The execution quality score of each edge node. The threshold for strategy evolution quality score. The target energy saving deviation threshold, Mark the conflict report as manually reviewed and approved. For strategy evolution library, The assignment update symbol indicates that the case will be appended to the evolution library. This serves as a sample of the self-governance case. For security intelligent agent risk identification model. For energy consumption prediction models of energy intelligent agents, For the model incremental update operator, For the updated security risk model, For the updated energy consumption prediction model, Used as a marker for determining the conditions for strategy evolution;
[0323] If the strategy evolution condition determination flag is... It is 1, that is If the autonomous case meets the evolutionary conditions, it is determined that the case is included in the strategy evolution library, and incremental updates are performed on the security risk model and energy consumption prediction model. This means using autonomous cases that meet the evolutionary conditions (quality score meets standards, energy consumption deviation meets standards, and manual review passes) as reinforcement learning training samples, and updating the model incrementally using the operators. Risk identification model for security intelligent agents Energy consumption prediction model with energy intelligence Perform parameter fine-tuning and strategy optimization;
[0324] If the strategy evolution condition determination flag is... It is 0, that is If the conditions for evolution are not met, only the execution log will be recorded and the system will not include the policy evolution library. The system will return to the normal multi-agent collaborative decision-making process, which means that when the communication link is normal, the linkage scheduling agent acts as the collaborative hub, coordinating the security agent and the energy agent to execute the standard collaborative working mode: multi-source data fusion, security-energy saving joint decision-making, policy instruction decomposition and distribution, and execution feedback collection, without triggering network outage autonomy and conflict arbitration.
[0325] Example 4: This example also discloses a system for implementing an enterprise security and energy-saving optimization decision-making method based on multi-agent collaboration, see reference. Figure 2 ,include:
[0326] Data acquisition and network monitoring module: Collects multi-source data such as park video, energy consumption, access control, and environment, encapsulates it in a standardized manner according to a unified spatiotemporal coordinate system, and synchronously monitors the heartbeat latency and packet loss count between edge nodes and the central hub to determine the status of communication links;
[0327] Edge preprocessing and cache management module: Deploys a lightweight AI engine on edge nodes to perform video target detection, energy consumption sliding window verification and initial judgment of security anomalies, while maintaining a policy cache area and determining the availability of cache policies based on timeliness and security level;
[0328] Network outage self-governance and status monitoring module: During communication interruption, the module executes security priority or energy-saving adaptive self-governance strategies according to the security status level, updates the local state vector clock and records logs, and continuously monitors the network outage duration and computing power usage. If the limits are exceeded, the module triggers degraded self-governance.
[0329] Conflict identification and arbitration module: aggregates the state vectors of each edge node, locates the state bifurcation point through partial order comparison, classifies conflicts into mergeable or non-mergeable types, performs incremental superposition on mergeable conflicts, and performs safety priority arbitration on non-mergeable conflicts.
[0330] Global Synchronization and Policy Evolution Module: Verifies the total order of the global state vector and the completeness of conflict resolution, decomposes the correction policy into device-level instructions and issues them across systems, collects feedback on execution results, and incorporates high-quality autonomous cases into the policy evolution library to drive model iterative updates.
[0331] Through the modules and methods described above, and by using multi-source heterogeneous data spatiotemporally aligned acquisition and edge lightweight preprocessing technology, standardized fusion and real-time edge analysis of the park's overall perception data are achieved, reducing cloud transmission pressure. Edge policy mirroring and security situation hierarchical autonomous technology enable autonomous protection of the security baseline and adaptive execution of energy-saving strategies during network outages, ensuring security reliability during communication interruptions. State vector clock partial order comparison and conflict resolution arbitration technology ensure the consistency and security verification of global policies after network recovery, eliminating disagreements in independent decision-making among multiple nodes. Execution feedback and policy evolution technology enable continuous iterative optimization of the system's autonomous capabilities, improving the intelligent level of park security and energy collaborative management.
Claims
1. A decision-making method for enterprise security and energy conservation based on multi-agent collaboration, characterized in that: include: Collect multi-source sensing data and perform spatiotemporal alignment and standardization processing. Monitor heartbeat latency and packet loss between edge nodes and the cloud. When latency or packet loss exceeds a threshold, the data is routed to the edge for processing; otherwise, it is uploaded to the cloud. In edge processing mode, local preprocessing is performed on the data, the local policy cache is read and its timeliness and security level are verified. If the conditions are met, the cache policy is called; otherwise, the preset backup policy is executed. The control mode is selected based on the security status and energy consumption status. Safety priority control is executed in abnormal or emergency situations, and energy-saving control subject to safety constraints is executed in normal situations. The execution process and status information are recorded. During edge operation, continuous valid heartbeats are counted. When the recovery threshold is reached, communication is determined to be restored, and the status data and execution records during the network outage are uploaded. The cloud receives data uploaded by each edge node and compares their status. When inconsistencies are found, they are identified as conflicts and classified according to the device range and control type. Conflicts between different devices or areas are merged, and conflicts within the same device are handled according to the safety priority rule to determine the execution strategy. The processed strategy is validated for consistency. When the conditions are met, device control commands are generated and issued for execution. Feedback updates are made based on the execution results.
2. The enterprise security and energy-saving optimization decision-making method based on multi-agent collaboration according to claim 1, characterized in that: Collect multi-source sensing data and perform spatiotemporal alignment and standardization processing to monitor heartbeat latency and packet loss between edge nodes and the cloud. Specifically: Acquire smart cameras, smart water and electricity meters, photovoltaic sensors, biometric access control systems, infrared detectors, and environmental sensors deployed in the park; Based on the unified network time protocol and three-dimensional spatial coordinate system, video stream frame sequences, instantaneous energy consumption values, passage records, security trigger signals, and environmental parameters are collected synchronously. Establish a spatiotemporal correlation index, generate the original multimodal dataset, aggregate multi-source heterogeneous sensing data from the park, and eliminate data silos and semantic gaps by aligning with a unified spatiotemporal coordinate system, providing a consistent data base for subsequent intelligent agent collaboration. Standardization encapsulation is performed on the original multimodal dataset to unify data with different dimensions and protocol formats into structured standard values; Simultaneously, a preliminary data quality screening is performed. Based on historical statistical characteristics, it is determined whether there are abnormal jumps in the current sampled values, and the duration of missing data is detected. Standardized packaged data values and quality qualified marks are generated after dimension normalization. The original data is standardized and packaged and subjected to preliminary quality screening to remove abnormal jumps and excessively long missing samples. The data credibility is marked to ensure that the data entering the decision-making process is true and reliable. If the quality pass mark is output as 1, the data quality is considered to be passable. If the quality pass mark output is 0, the data quality is considered unqualified. Edge nodes periodically send heartbeat detection messages to the coordinated scheduling agent; Real-time monitoring of round-trip latency and the number of consecutive packet losses; The communication link status is divided according to the dual threshold judgment rule, and the standardized data flow is determined to either the cloud collaborative channel or the edge autonomous preprocessing channel. The health of the communication link between the edge node and the central hub is monitored in real time. The link status is determined based on the dual indicators of latency and packet loss, and the data flow is determined to either the edge autonomous channel or the cloud collaborative channel. If the communication link status flag is output as 1, the communication link is determined to be abnormal. Then, the standardized dataset will be output to the edge preprocessing channel; If the communication link status flag output is 0, the communication link is considered to be normal. Then, the standardized dataset will be uploaded to the cloud to coordinate and schedule the intelligent agent.
3. The enterprise security and energy-saving optimization decision-making method based on multi-agent collaboration according to claim 1, characterized in that: In edge processing mode, local preprocessing is performed on the data, reading the local policy cache and verifying its timeliness and security level. Specifically: Edge nodes receive and collect multi-source sensing data and perform spatiotemporal alignment and standardization processing to monitor the heartbeat latency and packet loss between edge nodes and the cloud, outputting a standardized dataset. Deploy a lightweight AI inference engine to perform object detection and behavior recognition on video data, generate object confidence vectors, and filter invalid images; Perform sliding window verification on instantaneous energy consumption values to generate abnormal fluctuation markers; Perform local preliminary judgment on security anomaly signals and generate security anomaly confidence level; Simultaneously monitor the current available computing power resource ratio of edge nodes, determine the feasibility of local preprocessing, complete data dimensionality reduction and anomaly screening at the edge, and monitor computing power margin to ensure that preprocessing does not exceed the carrying capacity of edge nodes; If the edge preprocessing feasibility flag is output as 1, then the edge computing power is determined to be sufficient, and local lightweight preprocessing is performed. If the edge preprocessing feasibility mark output is 0, it is determined that the edge computing power is insufficient, and only data pass-through and simplified anomaly marking are performed, without uploading complex features; Read the decision image sequence from the local policy cache, arranged in reverse order of version timestamp; Extract the latest valid decision image ranked first, calculate the time interval between its version timestamp and the current system time, and determine whether the image has expired based on the policy validity threshold. Quantitatively evaluate the freshness of the caching policy to prevent edge autonomy from executing based on outdated policies and reduce the risk of decision failure. If the timeliness compliance mark is 1, then the mirror image is deemed to be timeliness compliant; If the timeliness qualification mark is 0, the image is determined to be expired; Extract the security level tag of the latest decision image and verify whether it belongs to the system's predefined set of valid security levels; By combining the timeliness qualification mark and the security level validity mark, the overall availability of the caching strategy is determined through joint product operation, and the caching strategy or the most conservative default strategy is selected to be executed accordingly. By combining the dual constraints of timeliness and security level, the credibility of the caching strategy is determined, and the implementation of fine-grained hierarchical autonomy or downgraded conservative strategy is decided to strengthen the security bottom line. If the security level validity mark is 1, then the security level mark is considered valid; If the security level validity flag is 0, then the security level flag is deemed invalid.
4. If the timeliness qualification mark is 1 and the security level validity mark is 1, then the overall availability mark of the cache policy is 1, and the cache policy is determined to be available. At this time, the final selected execution policy set is the complete policy set corresponding to the latest valid decision image in the cache area. The control mode is selected according to the security status and energy consumption status to perform hierarchical autonomy. If the timeliness qualification mark is 0 or the security level validity mark is 0, the overall availability mark of the caching policy will be 0, and the caching policy will be determined to be unavailable. In this case, the final selected execution policy set is the most conservative default policy set, and the most conservative default policy will be executed directly. The control mode will be selected according to the security status and energy consumption status.
5. The enterprise security and energy-saving optimization decision-making method based on multi-agent collaboration according to claim 1, characterized in that: The control mode is selected based on the security status and energy consumption status, specifically: The local security agent at the edge node outputs the current security status level based on multi-source fusion features; Energy intelligence agent outputs regional energy consumption status; The coordinated dispatching intelligent agent extracts the corresponding device control list from the cache policy based on the security situation level, selects the autonomous policy execution mode, and divides the autonomous mode according to the security situation level. In case of emergency and abnormality, security takes precedence over everything, while in normal times, energy saving optimization is also taken into account to ensure that the security bottom line is not breached. If the security situation level is emergency or abnormal, the security priority autonomous mode is triggered, and the selected autonomous strategy execution mode output is the security priority autonomous mode. If the security status level is normal, then the energy-saving adaptation autonomous mode is triggered, and the selected autonomous strategy execution mode output is the energy-saving adaptation mode under security constraints. Based on the selected autonomous strategy execution mode, the edge node sends the corresponding set of strategy instructions to each execution terminal, and synchronously increments the clock value in the corresponding dimension of the local state vector clock. The policy execution events are appended to the autonomous execution log, the autonomous policy is executed hierarchically according to the selected mode, the state vector clock is updated synchronously and the execution log is recorded, providing traceable time-series evidence for subsequent conflict resolution; If the selected autonomous strategy execution mode output is the security-first autonomous mode, then the set of autonomous strategy instructions actually executed by the edge node is the union of the security-first strategy subset and the non-critical equipment forced shutdown strategy subset, and the security-first strategy is executed and the non-critical equipment is shut down. If the selected autonomous strategy execution mode output is the energy-saving adaptation mode under security constraints, then the set of autonomous strategy instructions actually executed by the edge node is the intersection of the device control list in the cache strategy and the set of security bottom line constraints, and the energy-saving adaptation instructions are executed under the security bottom line constraints. If the agent actually issues a policy instruction, the indicator function outputs 1, and the corresponding dimension clock value increments by 1. If the agent does not actually issue a policy instruction, the indicator function outputs 0, and the corresponding dimension clock value remains unchanged; Real-time monitoring of the cumulative duration of network outages and the local computing power utilization rate of edge nodes; The sustainability of the current autonomous strategy is evaluated based on the dual threshold judgment rule to determine whether to trigger the downgraded autonomous mode. The duration of network outage and computing power margin are evaluated in real time. If the limit is exceeded, the system will downgrade to the most conservative mode to prevent edge nodes from losing security control due to resource exhaustion or strategy aging. If the degradation trigger flag is 1, it is determined that the network outage duration exceeds the limit or the computing power is overloaded, triggering the degradation autonomous mode. At this time, the final output of the autonomous mode is the degradation autonomous mode, and it returns the collection of multi-source sensing data and performs spatiotemporal alignment and standardization processing, continuously monitoring the heartbeat latency and packet loss between edge nodes and the cloud to monitor network recovery. If the downgrade trigger flag is 0, it is determined that the network outage duration and computing power are within the tolerance range, and the current autonomous strategy is maintained. At this time, the final autonomous mode output is the selected autonomous strategy execution mode, and the collected multi-source sensing data is returned and spatiotemporally aligned and standardized. The heartbeat latency and packet loss between edge nodes and the cloud are monitored to continuously monitor network recovery.
6. The enterprise security and energy-saving optimization decision-making method based on multi-agent collaboration according to claim 1, characterized in that: During edge operation, continuous valid heartbeats are counted, specifically: During the period of network outage autonomy, edge nodes listen for heartbeat detection messages issued by the linkage scheduling agent and perform validity verification on each heartbeat packet received within the monitoring window. The system counts the cumulative number of consecutive valid heartbeats and determines whether the communication link has truly been restored based on the recovery confirmation threshold. It continuously counts valid heartbeats and strictly determines whether the link has truly been restored based on the threshold to prevent false recovery misjudgments caused by network jitter. If the communication recovery confirmation flag is 1, then the communication link is determined to have been truly restored. If the communication recovery confirmation flag is 0, the heartbeat recovery is determined to be unstable, and edge autonomy continues to be executed; Extract the state vector clock values maintained by the local security agent, energy agent, and linkage scheduling agent at the edge node; Calculate the clock increments for each dimension during the network outage and verify their monotony and non-negativity and dimensional completeness to ensure that the state vector clock is complete and usable. Verify the completeness and monotonicity of the three-dimensional state vector clock to ensure that all autonomous operations are completely recorded and there are no logical conflicts during the network outage. If the state vector clock integrity flag is 1, then the state vector clock is determined to be monotonic and complete. If the state vector clock integrity flag is 0, it is determined that there is an abnormal jump or a missing state vector clock. Extract the incremental subset of autonomous execution logs generated during the network outage; Encapsulate the local state vector clock value, incremental log, recovery confirmation flag, and integrity flag into a reporting data packet; Based on the joint judgment result, decide whether to initiate state synchronization with the linkage scheduling agent, extract the network outage incremental log and encapsulate and report it to avoid full transmission redundancy, and realize the efficient transition from the edge policy mirror network outage autonomous mechanism to the network outage recovery state vector clock arbitration. If the communication recovery confirmation flag is 1 and the state vector clock integrity flag is 1, then the reporting conditions are met. At this time, the dataset actually reported to the linkage scheduling agent is the encapsulated data packet to be reported. The local state vector clock value and the incremental autonomous execution log are reported to the linkage scheduling agent. The cloud receives the data uploaded by each edge node and performs state comparison to start the network outage recovery state vector clock arbitration. If the communication recovery confirmation flag is 0 or the state vector clock integrity flag is 0, it is determined that the reporting conditions are not met. In this case, the dataset actually reported to the linkage scheduling agent is an empty set, and edge autonomy continues to be executed without reporting incomplete states.
7. The enterprise security and energy-saving optimization decision-making method based on multi-agent collaboration according to claim 1, characterized in that: The cloud receives data uploaded by each edge node and performs status comparisons, specifically: The coordinated scheduling agent gathers the local state vector clocks reported by each edge node and the last consistent global state snapshot before the network outage, and defines the partial order relationship between the state vectors. The incomparability between state vectors is detected by comparing all-dimensional components, the existence of state bifurcation is determined, the global state vectors are aggregated and a partial order comparison framework is established, and the state bifurcation point during the network outage is located by detecting the incomparability of vector clocks. If a state fork exists, it is marked as 1, then a state fork is determined to exist; If a state fork exists, it is marked as 0; otherwise, it is determined that no state fork exists. Using the last consistent global state snapshot before the network outage as the bifurcation reference, calculate the dimensional deviation of the state vector of each edge node relative to the reference. Extract the index of the first event that caused the state deviation from the autonomous logs of each node, quantify the degree of version difference, quantify the version deviation of each node based on the consistent state before the network outage, accurately locate the first autonomous event that caused the fork, and provide a time-series anchor point for conflict tracing; If the total version deviation of a node is greater than 0, it is determined that the node has deviated from its state during the network outage. If the total version deviation of a node is equal to 0, then the node is determined not to have deviated from its state. Extract conflicting instruction pairs that point to overlapping points from the incremental autonomous logs of each edge node, and parse the device identifier, physical region identifier and control semantics corresponding to each instruction; Based on the spatial overlap of equipment and area and the semantic mutual exclusion of instructions, the conflict type is determined, the spatial scope and semantic mutual exclusion of instructions are analyzed, and the forked state is transformed into a conflict type that can be merged or requires arbitration, providing a classification basis for subsequent resolution strategies. If the mergeable flag of the instruction pair is 1, the instruction pair is determined to be a mergeable conflict. At this time, the conflict type determination result of the instruction pair is output as the mergeable conflict type identifier. Conflicts between different devices or regions are merged. Conflicts between the same device are determined according to the security priority rule to perform incremental merging. If the mergeable flag of the instruction pair is 0, then the unmergeable conflict flag of the instruction pair is further determined: If the non-mergeable conflict flag of the instruction pair is 1, the instruction pair is determined to be a non-mergeable conflict. At this time, the conflict type determination result of the instruction pair is the non-mergeable conflict type identifier. For conflicts in different devices or regions, merge processing is performed. For conflicts in the same device, the execution strategy is determined according to the security priority rule to perform priority arbitration. If the non-mergeable conflict flag of an instruction pair is 0, then the instruction pair is considered compatible and no conflict occurs.
8. The enterprise security and energy-saving optimization decision-making method based on multi-agent collaboration according to claim 1, characterized in that: Conflicts between different devices or areas are merged, while conflicts within the same device are handled according to a safety priority rule. Specifically: The coordinated scheduling intelligent agent obtains the set of mergeable conflict instruction pairs by receiving data uploaded from each edge node in the cloud and comparing and judging their status. It then extracts the energy consumption adjustment amount and security deployment range change amount involved in each conflict pair. Accumulation and union operations are performed based on region identifiers to generate a unified global correction strategy subset. Mergeable conflicts are incrementally superimposed based on region and device type, and each node is independently adjusted to a unified global correction strategy to eliminate spatially isolated conflicts. The coordinated scheduling agent obtains the set of non-mergeable conflicting instruction pairs that receive data uploaded by each edge node from the cloud and performs state comparison and judgment. It then extracts the clock dimension value of the state vector corresponding to the security policy and energy-saving policy in each conflicting pair. Based on the safety criticality weight of conflicting devices, safety priority arbitration is performed, and a structured conflict report is generated. For conflicts that cannot be merged, safety priority arbitration is performed. Regardless of the clock dimension, the safety policy overrides the energy-saving policy, and a structured conflict report with the associated version number is generated. If the security priority arbitration trigger flag is 1, the security priority arbitration condition is determined to be triggered, and the security policy overrides the energy-saving policy. At this time, the set of execution policy instructions finally determined by the security priority arbitration for the non-mergeable conflict pair is output as the security policy instruction set of the conflict pair. If the security priority arbitration trigger flag is 0, the security policy will still be executed according to the preset security priority rules, overriding the energy-saving policy. At this time, the set of execution policy instructions finally determined by the security priority arbitration for the non-mergeable conflict pair will be output as the security policy instruction set of the conflict pair, and a structured conflict report will be generated simultaneously. The coordinated scheduling agent gathers the global correction strategy subset after merging conflict resolution and the strategy subset after non-merging conflict arbitration, and calculates the set of conflicts to be processed. Based on the empty set determination rules, check whether all conflicts have been resolved and whether all conflicts have been included in the merging or arbitration process. If they have not been resolved, return to re-identification; if they have been resolved, proceed to the global consistency confirmation stage. If the conflict resolution completeness flag is 1, it is determined that all conflicts have been resolved or merged, and the consistency of the processed strategy is checked. If the conflict resolution completeness is marked as 0, it is determined that there are still unresolved conflicts. The system then returns to the cloud to receive data uploaded by each edge node and performs a status comparison to re-identify the fork point.
9. The enterprise security and energy-saving optimization decision-making method based on multi-agent collaboration according to claim 1, characterized in that: The processed strategy undergoes a consistency check, specifically as follows: The coordinated scheduling intelligent agent aggregates and merges conflicts between different devices or regions. For conflicts of the same device, it determines the global correction strategy set output by the execution strategy according to the safety priority rule, as well as the state vector clock transmitted back by each edge node. Verify whether the global state vector clock forms a total order relationship, and determine whether global consistency has been achieved by combining the conflict resolution completeness flag. Verify the total order of the global state vector and the conflict resolution completeness to ensure that there is no branching of the global state after network outage recovery, providing a consistent premise for command issuance. If global consistency is achieved and the flag is 0, it is determined that there are still incomparable state vectors or unresolved conflicts. The system then returns to the cloud to receive data uploaded by each edge node and performs state comparison to re-identify the fork point. If the global consistency achievement is marked as 1, it is determined that the global state vector clock has formed a total sequence and all conflicts have been resolved; Then, the coordinated scheduling agent decomposes the global correction strategy set into device-level control instructions according to region and device type; By sending commands to the execution terminal through the edge gateway, cross-system linkage execution is achieved. The global correction policy is mapped to specific device instructions and sent out in a coordinated manner, enabling cross-system collaborative execution of security and energy. If the device's executable flag is 1, the device is determined to be online, and the corresponding instruction is sent to the device for execution. If the device's executable flag is 0, the device is determined to be offline, the device is marked as an abnormal pending state, and the abnormal record is appended to the pending queue. Collect the actual energy consumption changes, security incident handling results, and execution quality scores of each edge node after the implementation of the correction strategy; By combining the manual review markers of the conflict report, it is determined whether the autonomous case meets the policy evolution conditions. Cases that meet the conditions are included in the policy evolution library to drive the model update of each agent. The execution effect is collected and quantitatively evaluated. High-quality autonomous cases are included in the evolution library to drive model iteration and achieve closed-loop optimization of the entire process of network outage-recovery. If the policy evolution condition judgment mark is 1, then the autonomous case is determined to meet the evolution condition, the case is included in the policy evolution library, and incremental updates of the security risk model and energy consumption prediction model are performed. If the policy evolution condition is marked as 0, it is determined that the evolution condition is not met, and only the execution log is recorded without including it in the policy evolution library. The system returns to the normal multi-agent collaborative decision-making process.
10. A system for implementing the enterprise security and energy-saving optimization decision-making method based on multi-agent collaboration as described in claim 1, characterized in that: include: Data acquisition and network monitoring module: Collects multi-source data, encapsulates it in a standardized manner according to a unified spatiotemporal coordinate system, and synchronously monitors the heartbeat latency and packet loss count between edge nodes and the central hub to determine the status of the communication link; Edge preprocessing and cache management module: Deploys a lightweight AI engine on edge nodes to perform video target detection, energy consumption sliding window verification and initial judgment of security anomalies, while maintaining a policy cache area and determining the availability of cache policies based on timeliness and security level; Network outage self-governance and status monitoring module: During communication interruption, the module executes security priority or energy-saving adaptive self-governance strategies according to the security status level, updates the local state vector clock and records logs, and continuously monitors the network outage duration and computing power usage. If the limits are exceeded, the module triggers degraded self-governance. Conflict identification and arbitration module: aggregates the state vectors of each edge node, locates the state bifurcation point through partial order comparison, classifies conflicts into mergeable or non-mergeable types, performs incremental superposition on mergeable conflicts, and performs safety priority arbitration on non-mergeable conflicts. Global synchronization and strategy evolution module: Verify the total order of the global state vector and the completeness of conflict resolution, decompose the correction strategy into device-level instructions and issue them across systems, collect feedback on execution results, and incorporate high-quality autonomous cases into the strategy evolution library to drive model iterative updates.