A security risk early warning method and system based on monitoring intelligent analysis

CN122531176APending Publication Date: 2026-08-07ZHEJIANG CHANGCHUN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZHEJIANG CHANGCHUN TECH CO LTD
Filing Date
2026-05-27
Publication Date
2026-08-07

Smart Images

  • Figure CN122531176A_ABST
    Figure CN122531176A_ABST
Patent Text Reader

Abstract

The application provides a security risk early warning method and system based on monitoring intelligent analysis, acquires security sensing data and performs preprocessing, decomposes the security sensing data through a decomposition algorithm, acquires a space-time base mode, estimates a dominant periodic component of the space-time base mode according to an estimation algorithm, screens the dominant periodic component, acquires a screened base mode, acquires a periodic sequence parameter of the screened base mode, judges a risk precursor through the periodic sequence parameter, acquires a risk precursor result, analyzes the periodic sequence parameter according to a phase change theory, acquires an early warning index, and acquires graded early warning information in combination with the risk precursor result; the monitoring intelligent analysis security risk early warning scheme of adaptive base mode extraction, risk precursor judgment, early warning index construction, and graded cooperative response is used to solve the problem of one-sided risk judgment in the existing security risk early warning technology, so as to improve the accuracy of security risk early warning.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security technology, and more specifically, to a security risk early warning method and system based on intelligent monitoring analysis. Background Technology

[0002] With the deep integration of smart cities and the industrial internet, security monitoring scenarios are becoming increasingly complex and their coverage is continuously expanding, placing increasingly stringent demands on the early detection, accuracy, and coordination of security risk warnings. However, the security risk warning process is characterized by high coupling of multi-source data, dynamic changes in scenario operation patterns, and strong concealment of risk precursors, requiring comprehensive data analysis, feature extraction, and accurate judgment throughout the entire process. Currently, existing security risk warning solutions focus on integrating multi-source security data, extracting core operational patterns of scenarios, accurately identifying risk precursors, and achieving tiered responses. However, existing technologies have many shortcomings in key aspects of the entire process, making it difficult to meet the needs of actual scenarios. On the one hand, existing technologies have shortcomings in data processing, often only performing simple analysis on single-dimensional data, failing to achieve deep integration and spatiotemporal alignment of multi-source security data, and unable to adaptively identify core operational patterns of scenarios. This easily leads to missed detections of basic models or misjudgments due to noise, resulting in a lack of reliable data and feature support for subsequent risk analysis. On the other hand, the logic for judging risk precursors is one-sided. Existing technologies mostly rely on single abnormal indicators for judgment, without combining collaborative judgment mechanisms, making it difficult to distinguish between accidental interference and real risk precursors, resulting in high false positive and false negative rates. At the same time, in the construction of early warning indicators and the graded response stage, there is a lack of a multi-dimensional early warning indicator system that can comprehensively reflect fluctuation characteristics, recovery capabilities, and disturbance sensitivity, leading to a misallocation of response resources. This results in either over-response, increasing operation and maintenance costs, or under-response, missing the opportunity for risk prevention and control.

[0003] Therefore, there is an urgent need for a monitoring and intelligent analysis security risk early warning solution that integrates adaptive fundamental model extraction, risk precursor determination, early warning indicator construction, and hierarchical collaborative response to address the one-sided nature of existing risk assessment technologies and improve the accuracy of security risk early warning. Summary of the Invention

[0004] In view of the aforementioned problems, and in conjunction with the first aspect of the present invention, embodiments of the present invention provide a security risk early warning method based on intelligent monitoring analysis, the method comprising: Acquire security sensor data and preprocess it; decompose the security sensor data based on the decomposition algorithm to obtain the spatiotemporal fundamental model. The dominant periodic components of the spatiotemporal fundamental mode are estimated based on the estimation algorithm, and the dominant periodic components are screened to obtain the screened fundamental mode; Obtain the periodic sequence parameter of the screening basic model, and make a risk precursor judgment based on the periodic sequence parameter to obtain the risk precursor result; Based on phase transition theory, periodic sequence parameters are analyzed to obtain early warning indicators, and combined with risk precursor results, graded early warning information is obtained.

[0005] Furthermore, embodiments of the present invention also provide a security risk early warning system based on intelligent monitoring analysis, comprising: The acquisition module is used to acquire security sensor data and acquire the periodic sequence parameter of the filtering fundamental model; The decomposition module decomposes security sensor data based on a decomposition algorithm to obtain a spatiotemporal fundamental model. The estimation module estimates the dominant periodic components of the spatiotemporal fundamental mode based on an estimation algorithm. A filtering module is used to filter the dominant periodic components and obtain the filtering fundamental model; The judgment module performs risk precursor judgment based on the periodic sequence parameter and obtains the risk precursor result; The analysis module analyzes the periodic sequence parameters based on phase transition theory, obtains early warning indicators, and combines them with risk precursor results to obtain graded early warning information. Attached Figure Description

[0006] Figure 1 This is a flowchart of the steps of a security risk early warning method based on intelligent monitoring analysis according to the present invention; Figure 2 This is a flowchart of the steps for obtaining early warning results of risks in a security risk warning method based on intelligent monitoring analysis according to the present invention. Figure 3 This is a schematic diagram of a security risk early warning system based on intelligent monitoring analysis according to the present invention. Detailed Implementation

[0007] The present invention will be further described in detail below through specific embodiments. The following embodiments are merely descriptive and not limiting, and should not be used to limit the scope of protection of the present invention.

[0008] like Figure 1 As shown, a security risk early warning method based on intelligent monitoring analysis includes the following steps: Step S1: Acquire security sensor data and preprocess it. Decompose the security sensor data based on the decomposition algorithm to obtain the spatiotemporal fundamental model.

[0009] In this embodiment, step S1 includes: Step S1-1: Acquire video surveillance data, personnel access control data, environmental sensor data, and equipment operation data to form security sensor data.

[0010] Specifically, the video surveillance data captures in real time the spatial movement trajectories, gathering states, and abnormal behaviors of personnel and vehicles, such as climbing over walls, loitering, and violent conflicts, providing visual evidence and real-time early warning for security risks. This data is crucial for perceiving external dynamic risks in security scenarios. The personnel access control data records the time and identity information of personnel entering and exiting key areas, such as computer rooms, power distribution rooms, and finance offices. This accurately identifies risks related to unauthorized access, such as unauthorized personnel entering confidential areas or unauthorized entry and exit by former employees. Furthermore, combining this with time-based data helps determine the rationality of personnel movement, making it key data for ensuring the security of internal personnel management. The environmental sensing data is essential for environmental safety. Abnormalities in environmental parameters such as temperature, humidity, and light can easily trigger secondary security risks such as equipment malfunctions, fires, and material damage. Monitoring these parameters... Data can provide early warnings of environmental hazards, preventing larger security incidents caused by environmental issues, and is crucial for preventing security risks at their source. The equipment operation data is fundamental to the stable operation of the security system. The operational status of security equipment such as cameras, access control systems, and alarm devices, as well as key facilities like computer room air conditioning and power distribution equipment, determines the effectiveness of the security system. If equipment malfunctions, such as abnormal camera frame rates, delayed access control responses, or air conditioning shutdowns, security warnings will fail. Monitoring equipment operation data allows for timely detection and repair of equipment faults, ensuring the continuous and stable operation of the security system. Therefore, selecting video surveillance data, personnel access control data, environmental sensor data, and equipment operation data as security sensor data comprehensively covers the most risk-prone key aspects of security scenarios, and the data exhibits strong correlation, collaboratively supporting accurate risk identification and early warning.

[0011] In some possible implementations, taking a security scenario in an industrial park as an example, multiple high-definition cameras deployed at the entrances and exits of the industrial park, main roads, and workshop entrances collect video surveillance data; multiple access control card readers in various workshops, office buildings, and computer rooms collect personnel access control data; multiple environmental sensors distributed in workshops, computer rooms, and power distribution rooms collect temperature and humidity data; and an equipment management system collects operational data from cameras, access control devices, and computer room air conditioners. These four types of data are then integrated into the security sensing data for the industrial park.

[0012] Step S1-2 involves preprocessing the security sensor data by cleaning, standardizing, and spatiotemporally aligning it.

[0013] Specifically, because security data is prone to problems such as noise, missing values, inconsistent formats, and spatiotemporal asynchrony during the collection process, preprocessing operations are needed to improve data quality. Cleaning operations can be used to remove outliers, such as extreme abnormal readings from environmental sensors, and to fill in missing values. Interpolation between adjacent time points can be used to remove duplicate data, such as duplicate access control records. Simultaneously, standardization operations can be used to convert data from different dimensions to the same magnitude, such as normalizing temperature data to the [0,1] interval and standardizing access control response time to values ​​with a mean of 0 and a variance of 1, avoiding the impact of magnitude differences on subsequent analysis. Finally, spatiotemporal alignment operations are used to ensure that all data remain consistent in both time and space dimensions, such as using unified timestamps and a planar coordinate system.

[0014] In some possible embodiments, the security sensor data of the aforementioned industrial park is continued. During the cleaning operation, an abnormal temperature value of -50℃ caused by a faulty environmental sensor is removed, and the missing value is filled with the average temperature over the preceding and following 10 minutes. Two access control records generated by repeated employee card swipes are deleted. Next, the temperature data is normalized to the [0,1] range through standardization operations, such as normalizing the temperature range of 20℃-30℃ to [0,1], with 20℃ corresponding to 0 and 30℃ corresponding to 1. The access control response time (0.5s-2s) is standardized to a value with a mean of 0 and a variance of 1. Finally, the timestamps of all data are unified to the hour every minute through spatiotemporal alignment operations, such as 14:00, 14:01, etc. The installation locations of cameras, access control systems, and sensors are converted to the park's planar coordinates, such as the gate camera corresponding to coordinates (10,20) and the workshop access control system corresponding to coordinates (50,30), ensuring that the video data from the gate camera, the entry and exit data from the workshop access control system, and the temperature data from the server room can be correlated at the same time.

[0015] Steps S1-3: The preprocessed security sensor data is constructed into a two-dimensional tensor of time and space. The two-dimensional tensor is decomposed based on the improved PARAFAC2 decomposition algorithm to obtain the spatiotemporal fundamental model, which includes the temporal spatiotemporal fundamental model and the spatial spatiotemporal fundamental model.

[0016] The improved PARAFAC2 decomposition algorithm introduces a non-convex rank proximity norm constraint mechanism to constrain the potential factors in the decomposition process, and replaces the alternating least squares method in the PARAFAC2 decomposition algorithm with the symmetric Gauss-Seidel alternating direction multiplier method.

[0017] Specifically, the preprocessed security sensor data is first used to construct a two-dimensional temporal and spatial tensor X∈R. (T×S)Where T is the length of the time dimension, i.e., the number of timestamps, and S is the length of the spatial dimension, i.e., the number of spatial coordinate points, the tensor element X(t,s) represents the comprehensive feature value of security data at time t and spatial location s, such as the fusion value of personnel density, access control activity, and environmental comfort; at the same time, the time factor matrix A∈R is initialized. (T×R) and spatial factor matrix B∈R (S×R) Where R is the initially preset maximum possible rank, the column vectors of A correspond to the initial features of the spatiotemporal fundamental modes at each time, and the column vectors of B correspond to the initial features of the spatiotemporal fundamental modes at each space; furthermore, a non-convex rank proximity norm constraint term Ω(A,B)=λ1||A|| is added during the decomposition process. * +λ2||B|| * , where ||·|| * Let λ1 and λ2 be the nuclear norm and λ2 be the constraint coefficients. This constraint term adaptively obtains the decomposition rank by minimizing the effective rank of the adaptive compression factor matrix of the nuclear norm, thus eliminating redundant noise factors. This avoids the problems of false alarms in the spatiotemporal fundamental models caused by excessively large preset rank or missed detections in the spatiotemporal fundamental models caused by excessively small rank in the traditional PARAFAC2 algorithm. The traditional alternating least squares method is replaced by the symmetric Gaussian-Seidel alternating direction multiplier method. The decomposition optimization is achieved through a cyclic iteration of alternating updating of the time factor matrix, updating of the spatial factor matrix, optimization of the constraint term, and convergence judgment. Specifically, the spatial factor matrix B is fixed first, and the optimization problem min(A,B) is solved by combining the constraint term Ω(A,B). A ||XA×B T || F 2 +Ω(A,B), the ||·|| F Represented by the F-norm, the optimal time factor matrix A is updated; using the updated time factor matrix A, and also considering the constraint terms, the optimization problem min is solved. B ||XA×B T || F 2 +Ω(A,B), update to obtain the optimal spatial factor matrix B; obtain the error value of the current iteration, if the error value is less than the preset convergence threshold, stop the iteration; otherwise, repeat the above steps to continue the iteration; after the iteration converges, each column of the time factor matrix A corresponds to a time spatiotemporal fundamental model, which is used to reflect the intensity change law of the spatiotemporal fundamental model at different timestamps, and each column of the spatial factor matrix B corresponds to a spatial spatiotemporal fundamental model, which is used to reflect the intensity distribution law of the spatiotemporal fundamental model at different spatial locations; through the improved PARAFAC2 decomposition algorithm, both the decomposition accuracy and the convergence speed can be improved, and finally the spatiotemporal fundamental model that can accurately reflect the time law and spatial distribution law of the security scene can be extracted.

[0018] It should be noted that the constraint coefficients λ1 and λ2 can be determined by cross-validation. First, a set of candidate value ranges is preset. Then, combinations of different constraint coefficients within the candidate range are traversed, and the validation data is decomposed for each combination. The reconstruction error and spatiotemporal fundamental model recognition accuracy of the decomposition results under each combination are calculated. Finally, the optimal constraint coefficient is selected from the combination with the smallest reconstruction error and the highest spatiotemporal fundamental model recognition accuracy. λ1 corresponds to the constraint strength of the time factor matrix A, and λ2 corresponds to the constraint strength of the spatial factor matrix B. If the noise interference of the time spatiotemporal fundamental model is more significant, the value of λ1 can be appropriately increased. If the noise interference of the spatial spatiotemporal fundamental model is more significant, the value of λ2 can be appropriately increased.

[0019] Furthermore, the comprehensive feature values ​​of personnel density, access control activity, and environmental comfort can be obtained by weighted summation. First, the above data are converted into feature values ​​of the same magnitude, and then the comprehensive feature value is obtained by weighted summation of each feature value. The weights can be set using the analytic hierarchy process, specifically, the data with the greater impact on security risks has a higher weight.

[0020] In some possible embodiments, the pre-processed security sensor data from the industrial park is used to construct a two-dimensional tensor of time and space. The time dimension consists of 1440 minute-level timestamps for one day, and the spatial dimension consists of 50 key monitoring coordinate points within the park. The tensor element values ​​are comprehensive feature values ​​of personnel density, access control activity, and environmental comfort at the corresponding time and coordinate point. The personnel density is obtained through video surveillance data, the access control activity is obtained through personnel access control data, and the environmental comfort is obtained through environmental sensor data. The improved PARAFAC2 decomposition algorithm is used to decompose the two-dimensional tensor, and finally, three spatiotemporal fundamental models are extracted, including the morning peak time corresponding to 7:00-9:00, the working period corresponding to 9:00-18:00, and the night period corresponding to 18:00-7:00 the next day, as well as two spatiotemporal fundamental models, including the area gate and workshop entrance corresponding to the densely populated area, and the area server room and power distribution room corresponding to the equipment concentration area.

[0021] Step S2: Estimate the dominant periodic components of the spatiotemporal fundamental mode based on the estimation algorithm, filter the dominant periodic components, and obtain the filtered fundamental mode.

[0022] In this embodiment, step S2 includes: Step S2-1: Use a multiple signal classification algorithm to analyze the non-stationary time series corresponding to the time-space fundamental mode in the spatiotemporal fundamental mode, and estimate the dominant periodic component of the spatiotemporal fundamental mode.

[0023] It should be noted that the spatiotemporal fundamental model is a non-stationary time series that reflects the temporal regularity of a scene, such as a sequence of people's movement over time. The multi-signal classification algorithm has the ability to estimate the period of non-stationary signals, and can separate the signal components and noise components from complex time series, and estimate the dominant periodic components corresponding to each spatiotemporal fundamental model, that is, the most core and most stable repetition period of the spatiotemporal fundamental model. Since the distribution pattern of the spatiotemporal fundamental model depends on the periodic changes of the spatiotemporal fundamental model, the dominant periodic components of all spatiotemporal fundamental models can be indirectly obtained through the periodic analysis of the spatiotemporal fundamental model.

[0024] Specifically, the process of obtaining the dominant periodic component based on the multiple signal classification algorithm includes: segmenting and windowing the non-stationary time series corresponding to the spatiotemporal fundamental mode, such as using a Hanning window to suppress spectral leakage; then constructing an autocovariance matrix using the segmented series; using the autocovariance matrix to characterize the correlation of data at different times in the series, providing a basis for subsequent signal-noise separation; performing eigenvalue decomposition on the constructed autocovariance matrix to obtain a series of eigenvalues ​​and corresponding eigenvectors; dividing the eigenvectors into a signal subspace and a noise subspace according to the magnitude of the eigenvalues, where the signal subspace corresponds to larger eigenvalues, representing... The effective signal components in the sequence correspond to smaller eigenvalues ​​in the noise subspace, representing the noise components in the sequence. A MUSIC spatial spectrum function is constructed, which uses frequency as a variable and calculates spatial spectrum values ​​by traversing a preset frequency range. The preset frequency range needs to cover the possible period range of the security scenario, such as minute, hour, or day. The spatial spectrum function will have peaks at signal frequencies, while the spectrum value approaches zero at noise frequencies. The frequencies corresponding to the peaks in the spatial spectrum are extracted, and the frequencies are converted into periods. The period components with the highest peaks and corresponding periods that are physically reasonable are selected as the dominant period components of the spatiotemporal fundamental mode for that time.

[0025] In some possible embodiments, for the three spatiotemporal fundamental models extracted from the aforementioned industrial park, the corresponding non-stationary time series are the morning peak personnel flow sequence, the working hour equipment operation sequence, and the nighttime security status sequence, respectively. A multiple signal classification algorithm is used to analyze these three sequences, estimating the dominant periodic components of each spatiotemporal fundamental model. Specifically, the dominant period of the morning peak time spatiotemporal fundamental model is 1 day, repeating daily from 7:00 to 9:00; the dominant period of the working hour time spatiotemporal fundamental model is 1 day, repeating daily from 9:00 to 18:00; and the dominant period of the nighttime time spatiotemporal fundamental model is 1 day, repeating daily from 18:00 to 7:00 the next day. The corresponding two spatial spatiotemporal fundamental models, depending on the changes in the temporal spatiotemporal fundamental models, both have a dominant periodic component of 1 day.

[0026] Step S2-2: Evaluate the confidence level of all dominant periodic components based on the Bootstrap method and set a confidence level threshold.

[0027] Specifically, the Bootstrap method resamples the spatiotemporal fundamental model data multiple times, typically 1000-10000 times, to construct multiple resampled datasets. It then estimates the stability of each dominant periodic component under different datasets and obtains the confidence level of each dominant periodic component. The higher the confidence level, the more stable the periodic pattern. The confidence level threshold needs to be set in conjunction with the accuracy requirements of the security scenario, taking into account both the retention rate of effective fundamental models and the elimination rate of noisy patterns. Generally, the value range is 0.8-0.95.

[0028] It should be noted that the confidence threshold setting needs to be combined with the accuracy requirements of the security scenario and confirmed in conjunction with the core objectives of the system. If the scenario is of high security level, such as chemical industrial parks or classified computer rooms, noise patterns need to be strictly eliminated to avoid false warnings caused by unstable spatiotemporal fundamental models, and the threshold should be set to a higher value. If the scenario is of ordinary security level, such as ordinary parks or office buildings, the threshold can be appropriately reduced to avoid missing effective spatiotemporal fundamental models. At the same time, it is necessary to balance the retention rate of effective spatiotemporal fundamental models and the elimination rate of noise patterns. The optimal balance point between the two can be found through statistical analysis of historical data. In this embodiment, taking an industrial park as an example, its security level is medium. It is necessary to take into account both the accuracy and comprehensiveness of risk warnings, and combine the Bootstrap resampling results. For example, the confidence of effective fundamental models such as the morning peak time fundamental model and the working period time fundamental model is 0.98, and the confidence of noise patterns such as the nighttime time fundamental model is 0.75. The confidence threshold can be set to 0.8 to effectively retain the spatiotemporal fundamental model while ensuring the noise elimination rate.

[0029] In some possible embodiments, the dominant periodic components of the spatiotemporal fundamental models of the industrial park obtained in step S2-1 are continued, and the original fundamental model data are resampled 5000 times using the Bootstrap method. After each resampling, the dominant periodic components are re-estimated. It was found that the dominant periodic components of the fundamental models of the morning peak time, working hours, densely populated areas, and concentrated equipment areas all appeared stably in 5000 resamplings throughout the day, with a confidence level of 0.98. The periodic fundamental model of the nighttime time fluctuates due to occasional maintenance work at night, with a confidence level of 0.75.

[0030] Step S2-3: Iterate through the confidence scores of all dominant periodic components, obtain confidence scores greater than the confidence score threshold, and use the spatiotemporal fundamental mode corresponding to the confidence score as the screening fundamental mode.

[0031] Specifically, the confidence scores of the dominant periodic components corresponding to all fundamental models are iterated, and fundamental models with confidence scores higher than a set threshold are selected as screening fundamental models. This process eliminates spatiotemporal fundamental models with unstable periodic patterns, such as those affected by accidental factors, and retains spatiotemporal fundamental models that can stably reflect the normal operation patterns of security scenarios.

[0032] In some possible embodiments, the confidence levels of the five spatiotemporal fundamental models of the aforementioned industrial park are iterated. The confidence levels of the fundamental models for the morning peak hours (0.98), working hours (0.97), densely populated areas (0.96), and concentrated equipment areas (0.98) are all greater than the set threshold of 0.8. The confidence level of the fundamental model for the nighttime hours (0.75) is less than the threshold of 0.8. Therefore, the first four fundamental models are used as screening fundamental models, and the fundamental model for the nighttime hours is removed.

[0033] Step S3: Obtain the periodic sequence parameter of the screening basic model, and make a risk precursor judgment based on the periodic sequence parameter to obtain the risk precursor result.

[0034] like Figure 2 As shown, in this embodiment, step S3 includes: Step S3-1: Based on the periodic sequence parameter formula, obtain the periodic sequence parameter of each screening basic mode; The periodic sequence parameter formula is specifically expressed as follows: ; in, This is represented as the periodicity sequence parameter for screening fundamental models. This represents the number of monitoring signals associated with the filter's fundamental model. Represented as the first The monitoring signal associated with the screening baseline model Represented as the first The weight of each monitoring signal, Represented as the imaginary unit, Represented as Time of the first The phase of a monitoring signal associated with the screening fundamental mode.

[0035] Specifically, this step quantifies the periodic order of the selected basic model by constructing a periodic sequence parameter formula, with a value range of [0-1]. The closer the obtained periodic sequence parameter is to 1, the more stable the periodic pattern of the selected basic model is, and vice versa.

[0036] Furthermore, the phase angle can reflect the periodic variation of the signal over time. Specifically, if the multi-source monitoring signals are periodically ordered, their phase angles will exhibit a stable cooperative relationship. When the periodic regularity of the fundamental mode is disrupted, i.e., a risk precursor appears, the cooperative relationship of the phase angles of each signal will be disordered. Therefore, this step quantifies the overall periodic synchronization of the multi-source signals through the weighted aggregation of phase angles, and then judges the orderliness of the fundamental mode.

[0037] Understandably, the imaginary unit, relying on Euler's formula, transforms the one-dimensional phase angle into a vector on the two-dimensional complex plane. The direction of the vector corresponds to the phase angle, and its magnitude is 1, which can simultaneously preserve the angular information and directional coordination of the phase. By weighted summation of complex vectors, the phase relationship of multi-source signals can be fused, and then the order parameter in the [0,1] interval can be obtained by normalizing the magnitude, simplifying the quantization calculation of order.

[0038] It should be noted that the weights of the monitoring signals are set by the correlation between the monitoring signals and the representational features of the selected baseline model, combined with the analytic hierarchy process (AHP). For example, the feature of the baseline model of a densely populated area is the pattern of personnel gathering and flow, while the feature of the baseline model of an equipment-concentrated area is the stability of equipment operation. The correlation between the associated monitoring signals and these features is then determined. Signals representing the feature are core signals with the highest correlation, while those indirectly representing the feature are auxiliary signals with lower correlation. The AHP is then used to assign weights to each monitoring signal to obtain the initial weights, which are then normalized so that the sum of the weights is 1. Finally, historical data is used for calibration to obtain the final weights. For example, the feature of the baseline model of a densely populated area is the pattern of personnel gathering and flow. The three associated video monitoring signals can directly capture personnel density and gathering status, and are therefore core signals with a higher weight. The two access control signals can only reflect the flow trend of personnel entering and leaving the area, and are therefore auxiliary signals with a lower weight. Using the above method, the weights of the three video monitoring signals are 0.25, and the weights of the two access control signals are 0.125.

[0039] In some possible embodiments, taking a densely populated area spatial model as an example, the associated monitoring signals include 3 video monitoring signals (k=1, 2, 3) and 2 access control signals (k=4, 5), then N=5; weights are set according to the degree of signal influence, including the weights of the video monitoring signals w1=w2=w3=0.25; the weights of the access control signals w4=w5=0.125; at t=14:00, the phases of each signal are φ1=0.2π, φ2=0.3π, φ3=0.25π, φ4=0.4π, φ5=0.35π respectively; substituting into the periodic sequence parameter formula 0.25e (j0.2π) +0.25e (j0.3π) +0.25e (j0.25π) +0.125e (j0.4π) +0.125e (j0.35π) After obtaining its modulus length and dividing it by 5, the periodicity parameter is 0.92, indicating that the fundamental modulus has strong periodicity at 14:00.

[0040] Step S3-2: Obtain time translation symmetry and spatial translation symmetry based on the periodic sequence parameter.

[0041] It should be noted that the time translation symmetry refers to the consistency of the changes of the periodic sequence parameter of the fundamental mode after it has been translated in the time dimension by one dominant period, that is, the time stability of the periodic law; the spatial translation symmetry refers to the consistency of the distribution of the periodic sequence parameter of the fundamental mode after it has been translated in the spatial dimension by a certain distance, that is, the spatial stability of the periodic law.

[0042] Specifically, for the target fundamental model, the periodic sequence parameters within its continuous time period are extracted to obtain a time series O(t), where t is a timestamp. The sequence length is ensured to cover at least two dominant periods; for example, if the dominant period is one day, then a sequence of sequence parameters for two days or more is extracted. The dominant period τ of the fundamental model is used as the translation step size; for example, τ = 1 day corresponds to 1440 minute-level timestamps. The original sequence parameter time series O(t) is shifted τ time units in the positive direction along the time axis to obtain the shifted sequence O(t+τ), i.e., the sequence parameter at time t corresponds to the shifted sequence parameter at time t+τ. The Pearson correlation coefficient is used to calculate the correlation between the original sequence O(t) and the shifted sequence O(t+τ). The correlation coefficient ranges from [-1, 1] and is normalized to the interval [0, 1]. The normalization formula is expressed as S... T =(corr+1) / 2, where corr is the Pearson correlation coefficient, and the resulting S... T That is, time translation symmetry, its S T The closer it is to 1, the stronger the consistency of the parameters before and after the translation, and the more stable the time periodic pattern.

[0043] Furthermore, for the target fundamental model, a fixed time t0 is selected, and the periodic sequence parameters of all key monitoring coordinate points in the scene at that time are extracted and arranged according to their coordinate positions to form a spatial distribution matrix O(x,y), where (x,y) are the planar coordinates in the scene, and the matrix element values ​​are the sequence parameters of the corresponding coordinate points. Combining the actual size of the scene and the spatial distribution range of the fundamental model, a reasonable spatial translation distance d is set, such as 5 meters or 10 meters, to ensure that there are still enough overlapping coordinate points after the translation. The original spatial distribution matrix O(x,y) is then... The model is translated a distance *d* in the positive direction of the spatial plane, which can be along the x-axis, y-axis, or diagonal, and must conform to the spatial characteristics of the fundamental model. For example, in a densely populated area, the model is translated along the passageway to obtain the translated spatial matrix O(x+d,y+d). A set of overlapping coordinate points with valid order parameters before and after the translation is selected. The mean correlation between the original order parameter O(x,y) and the translated order parameter O(x+d,y+d) within this set is calculated. This can also be obtained using the Pearson correlation coefficient, and the correlation result is normalized to the [0,1] interval to obtain S. S That is, spatial translational symmetry, the S S The closer it is to 1, the stronger the consistency of the spatial distribution of the parameters before and after the translation, and the more stable the spatial pattern.

[0044] In some possible embodiments, for the time fundamental model of the working period, whose dominant period τ is 1 day, the periodic sequence parameter sequence O(t) at 14:00 is selected, and it is shifted by 1 day to obtain O(t+τ). The maximum value of the autocorrelation function autocorr(O(t),τ) of the two is calculated to obtain the time shift symmetry S. T =0.95, indicating that the time periodicity of the fundamental model is stable. For the spatial fundamental model of densely populated areas, the periodic sequence parameter distribution O(x,y) of each spatial coordinate point at 14:00 is selected, and it is translated 5 meters in space to obtain O(x+5,y+5). The mean value of the spatial correlation between the two, spatial corr(O(x,y)), is calculated to obtain the spatial translation symmetry S. S =0.93, indicating that the spatial distribution of the screening primitive is stable.

[0045] Step S3-3: Based on the time translation symmetry and spatial translation symmetry, set the time malfunction condition and the spatial malfunction condition, and set the malfunction duration threshold.

[0046] Specifically, in order to determine whether there are any abnormalities in the cyclical patterns of the selected basic model, time-related and spatial-related conditions are set, which are defined by setting a threshold for the ratio of the change in symmetry to the original symmetry. In order to avoid the misjudgment of short-term symmetry fluctuations caused by accidental factors as risk precursors, a threshold for the duration of the failure is set to ensure the reliability of the risk precursor judgment.

[0047] It should be noted that the setting of the time translation symmetry threshold, spatial translation symmetry threshold, and duration threshold needs to be calibrated in conjunction with historical risk data, while taking into account both sensitivity and false positive rate. The setting of the time translation symmetry threshold needs to balance the sensitivity and false positive rate of risk identification in the time dimension, while adapting to the inherent characteristics of the fundamental model's time cycle pattern. The time translation symmetry reflects the stability of the fundamental model's time cycle, and its change ratio reflects the degree of disruption to the time pattern. If the threshold is set too low, such as less than 0.1, normal small time fluctuations will be misjudged as disruptions, such as the slight shift of the fundamental model during the morning rush hour caused by individual late arrivals, significantly increasing the false alarm rate. If the threshold is set too high, such as greater than 0.3, early time pattern anomalies will be missed, such as the risk precursor of an early and continuously shifting morning rush hour, reducing the warning sensitivity. At the same time, the time stability of the fundamental model varies in different scenarios. For example, the time fundamental model stability is high during working hours in industrial parks, and the allowable change ratio can be slightly lower. The threshold needs to be determined by combining the maximum proportion of normal fluctuations and the minimum proportion of changes corresponding to risk precursors in historical data, so as to avoid interference from normal fluctuations and capture the potential risks. Early anomalies are identified, therefore, in this embodiment, the time translation symmetry threshold can be set to 0.2. The setting of the spatial translation symmetry threshold needs to adapt to the distribution characteristics of the spatial fundamental mode, taking into account both the accurate identification of spatial anomalies and the ability to resist environmental interference. The spatial translation symmetry reflects the consistency of the spatial distribution of the fundamental mode, and the proportion of its change corresponds to the degree of disruption of spatial regularity. Spatial dimensions are easily affected by accidental environmental interference, such as changes in local spatial parameters caused by temporary storage of materials. If the threshold is too small, such as less than 0.15, such temporary interference will be misjudged as spatial inconsistency; if the threshold is too large... If the threshold is greater than 0.35, local spatial anomalies cannot be identified, such as early signs of abnormal gathering of people in non-dense areas. Furthermore, the distribution range and uniformity of spatial fundamental models differ. For example, in densely populated areas, the spatial fundamental model distribution is concentrated, allowing for a slightly higher percentage of allowable variation. In areas with concentrated equipment, the spatial fundamental model distribution is scattered, requiring a more stringent threshold. The threshold should be set by combining the maximum percentage of normal spatial interference in historical data with the minimum percentage of change in spatial risk precursors to ensure accurate differentiation between effective spatial anomalies and accidental interference. Therefore, in this embodiment, the spatial translational symmetry threshold can be set to 0.25; The setting of the breach duration threshold is to eliminate accidental and transient interference factors and ensure the reliability and stability of risk precursor judgment. In actual security scenarios, there are many transient symmetrical fluctuations, such as transient changes in spatial symmetry caused by personnel temporarily crossing equipment concentration areas, and temporal symmetrical fluctuations caused by momentary failures of access control systems. These fluctuations are not system-level risk precursors, are short in duration, and recover quickly. If no duration threshold is set, these transient fluctuations will be misjudged as risk precursors, leading to frequent false alarms. Therefore, it is necessary to set a threshold based on the risk handling response time of the scenario, such as the 5-minute time required for security personnel to arrive at the scene in an industrial park, and the maximum duration of normal transient fluctuations in historical data. This can both eliminate transient interference and identify risk precursors in a timely manner before they continue to develop. Therefore, in this embodiment, the breach duration threshold can be set to 5 minutes.

[0048] In some possible embodiments, a time-shift symmetry threshold θ is set based on the historical security data of the aforementioned industrial park for calibration. T =0.2, meaning the ratio of the time symmetry change to the original value exceeds 20%, is considered broken. Spatial translation symmetry threshold θ S =0.25, meaning that a change in spatial symmetry exceeding 25% of the original value is considered a breach; considering the response time requirements for risk management in the park, a breach duration threshold τ is set. min =5 minutes, meaning that a symmetry breaking condition is considered valid only if it lasts for more than 5 minutes.

[0049] Steps S3-4: Obtain risk precursor results based on temporal spurious condition, spatial spurious condition, and spurious duration threshold.

[0050] The time symmetry breaking condition is defined as the ratio of the change in time translation symmetry to the time translation symmetry within a unit time being greater than the time translation symmetry threshold, and the spatial symmetry breaking condition is defined as the ratio of the change in spatial translation symmetry to the spatial translation symmetry within a unit time being greater than the spatial translation symmetry threshold.

[0051] It should be noted that, in order to avoid misjudgment caused by single-dimensional or transient symmetry failure and to ensure the accuracy of risk precursor judgment, risk precursor is only determined to exist when the fundamental model simultaneously exhibits temporal translation symmetry failure and spatial translation symmetry failure, and the duration of the failure exceeds a set threshold.

[0052] In this embodiment, step S3-4 includes: Step S3-4-1: When both the time spurious condition and the spatial spurious condition are met and the duration of the spurious condition is greater than or equal to the spurious condition duration threshold, it is determined that there is a risk precursor.

[0053] Specifically, the premise is to meet the requirements of double breaking and duration, because the symmetry breaking in a single dimension may be caused by accidental factors, such as a brief accidental entry by personnel, which does not mean that there is a systemic risk in the system; and a brief double breaking may also be caused by data fluctuations. Only a continuous double breaking means that the periodic pattern of the fundamental model has been severely disrupted, and the system has a precursor to a risk state.

[0054] In some possible embodiments, for the spatial fundamental model of a densely populated area, at 15:00 on a certain workday, an abnormal gathering of people is caused by a sudden equipment failure, and the time translation symmetry change ΔS is calculated. T =0.22, original time symmetry S T =0.95, |ΔS T | / S T =0.23, which is greater than the set threshold of 0.2, satisfying the time inequality condition; the change in spatial translational symmetry ΔS S =0.28, original space symmetry S S =0.93, |ΔS S | / S S =0.30, which is greater than the set threshold of 0.25, thus meeting the space breaking condition; at the same time, the breaking start time was recorded as 15:00, and it was found that it continued until 15:06, with the breaking state lasting for 6 minutes, which is greater than the set threshold of 5 minutes, thus meeting the duration threshold, and it was initially determined that there were early signs of risk.

[0055] Step S3-4-2, otherwise, it is determined that there are no signs of impending risk.

[0056] For example, if the above equipment failure only lasts until 15:03, and the equipment returns to normal at 15:03, the symmetrical failure state disappears, and the failure duration is 3 minutes, which is less than the set threshold of 5 minutes. Therefore, it is determined that there is no risk precursor.

[0057] Step S4: Analyze the periodic sequence parameters based on phase transition theory to obtain early warning indicators, and combine them with risk precursor results to obtain graded early warning information.

[0058] It should be noted that the phase transition theory describes the process and laws by which a system transitions from one stable state to another. It indicates that the state transition of a system is not abrupt, but rather a continuous evolutionary process from a normal stable state to a critical state and then to an abnormal risk state. In this embodiment, if the system is nearing a critical state, it will exhibit three major precursor characteristics, including enhanced order parameter fluctuations, i.e., the fluctuation amplitude of system characteristics is significantly greater than that of the normal state; prolonged relaxation time, i.e., the time for the system to recover to a stable state after being disturbed is greatly increased; and critical slowing and increased disturbance sensitivity, i.e., the system's response to small disturbances is significantly amplified, and small disturbances can trigger large fluctuations.

[0059] In this embodiment, step S4 includes: Step S4-1: Based on phase transition theory, extract early warning indicators from periodic sequence parameters.

[0060] In this embodiment, step S4-1 includes: Step S4-1-1: Set a time window, obtain the baseline variance of the periodic sequence parameter, and simultaneously obtain the rolling window variance of the periodic sequence parameter. The baseline variance of the periodic sequence parameter represents the variance of the periodic sequence parameter when the system is in a normal state. Obtain the sequence parameter fluctuation index based on the ratio of the rolling window variance to the baseline variance.

[0061] Specifically, to ensure complete acquisition of the periodic fluctuations of the sequence parameter, a time window needs to be set, and the setting of the time window needs to be combined with the dominant period of the selected basic model; the benchmark variance represents the variance of the sequence parameter under normal system conditions, which is obtained through historical normal data and serves as a benchmark for judging whether the current fluctuations are abnormal; the rolling window variance is the real-time variance calculated through a sliding time window, reflecting the real-time fluctuation status of the sequence parameter; the ratio of the two is the sequence parameter fluctuation index, and a ratio greater than 1 indicates that the current fluctuation is greater than the normal state, and the larger the ratio, the higher the degree of abnormality.

[0062] It should be noted that the time window setting is based on the dominant period of the selected fundamental model, while also taking into account the dual requirements of fully capturing periodic fluctuations and real-time monitoring of anomalies. In this embodiment, the dominant period of all selected fundamental models is 1 day. If the window length is too short, such as less than 1 hour, it cannot fully cover the fluctuation characteristics of the sequence parameter within a local period, and it is easy to misjudge fluctuation anomalies due to local data fluctuations. If the window length is too long, such as more than 4 hours, it will lead to a delay in the monitoring of abnormal fluctuations, and it will be impossible to capture the changes in the sequence parameter corresponding to the risk precursors in a timely manner. In this embodiment, the dominant period of the fundamental model is used as a reference. With a cycle of 1 day, a window length covering half of the critical time period is prioritized. The core security monitoring period in the industrial park is the working period, from 9:00 to 18:00, a total of 9 hours. Half of the working period is 4.5 hours. Considering both real-time performance and the completeness of fluctuation capture, the window length can be set to 2 hours. This not only allows for the complete acquisition of local periodic fluctuations of sequence parameters within the working period, such as the short-term rhythms of personnel flow and equipment operation, but also ensures the timeliness of anomaly monitoring and avoids early warning delays caused by excessively long windows. Similarly, the sliding step size can be set using the same method described above.

[0063] In some possible embodiments, for the spatial model of densely populated areas, the dominant period is 1 day, the time window length is set to 2 hours, and the sliding step is 10 minutes; historical data of no risk events in the past month are selected to calculate the baseline variance as 0.02; at the time of equipment failure at 15:00, the sequence parameter values ​​of 12 data points between 13:00 and 15:00 are obtained, such as the sequence parameter value corresponding to 13:00 is 0.93, the sequence parameter value corresponding to 13:10 is 0.92, ..., the sequence parameter value corresponding to 15:00 is 0.85, and the variance of the sequence parameter in the current 2 hours is calculated to be 0.05 through the rolling window. The sequence parameter fluctuation index = 0.05 / 0.02 = 2.5, indicating that the current sequence parameter fluctuation is 2.5 times that of the normal state, and there is a significant fluctuation anomaly.

[0064] Step S4-1-2: Set the autocorrelation function based on the time interval, and obtain the relaxation time index based on the autocorrelation function. The time interval represents the time required for the periodic sequence parameter to recover from the deviation state to the stable state.

[0065] Specifically, the autocorrelation function is used to describe the similarity of periodic order parameters at different time intervals. By setting a series of time intervals, i.e. delay times, the autocorrelation values ​​of the order parameters at each delay time are calculated to form the autocorrelation function curve. The relaxation time index is the delay time corresponding to the autocorrelation function decaying from its maximum value to the maximum value 1 / e. The delay time reflects the system's ability to recover stability after being disturbed. The longer the relaxation time, the weaker the recovery ability and the closer it is to the critical state of phase transition.

[0066] It should be noted that the autocorrelation function is specifically expressed as follows: Wherein, τ1 represents the time interval, i.e. the delay time, and μ represents the mean of the periodic sequence parameter series, which is obtained through historical normal data. n is 1440, corresponding to the minute-level data volume of 1 day. When τ1=0, R(0)=1, i.e. the delay time is 0. When τ1 increases, if the sequence parameter series is highly stable, such as the periodic sequence parameter under normal conditions, R(τ1) will slowly decay and will show periodic fluctuations with the periodic pattern; if the sequence stability is weak, such as the sequence parameter approaching the risk state, R(τ1) has no obvious periodicity.

[0067] In some possible embodiments, for the spatial fundamental model of densely populated areas, the time interval is set to 0-30 minutes, and the autocorrelation function value is calculated at each delay time to obtain the autocorrelation function curve. Under normal conditions, the maximum value of the autocorrelation function R(0) = 0.95, and the delay time corresponding to the decay to R(0) / e≈0.35 is 8 minutes, that is, the relaxation time is 8 minutes. At the time of equipment failure at 15:00, the maximum value of the autocorrelation function R(0) = 0.8, and the delay time corresponding to the decay to 0.8 / e≈0.3 is 25 minutes, that is, the relaxation time is 25 minutes, indicating that the system recovery capability has decreased.

[0068] Step S4-1-3: Apply a small virtual disturbance to the system, obtain the change amplitude of the periodic sequence parameter, and obtain the dynamic response function index based on the change amplitude.

[0069] Specifically, the micro-virtual disturbance refers to a small disturbance applied to the periodic parameters without affecting the actual operation of the system, such as simulating a 5% increase in personnel density; the change amplitude is represented by the absolute value of the difference between the parameter after the disturbance and the parameter before the disturbance; the dynamic response function index is the ratio of the change amplitude to the disturbance amplitude, and the larger the ratio, the more sensitive the system is to the disturbance and the closer it is to the critical state of phase transition.

[0070] In some possible embodiments, a small virtual perturbation of 5% is applied to the periodic sequence parameter of the spatial fundamental model of densely populated areas to simulate a 5% increase in population density. Under normal conditions, the change amplitude of the sequence parameter after the perturbation is 0.03, and the dynamic response function index is 0.03 / 0.05=0.6. When the equipment fails at 15:00, the same 5% perturbation is applied, and the change amplitude of the sequence parameter is 0.12, and the dynamic response function index is 0.12 / 0.05=2.4, indicating that the system's sensitivity to perturbation is improved.

[0071] Step S4-1-4: An early warning indicator is formed based on the order parameter fluctuation index, the relaxation time index, and the dynamic response function index.

[0072] Step S4-1: Set indicator thresholds and obtain the degree of abnormality of early warning indicators based on early warning indicators.

[0073] Specifically, threshold values ​​for indicators can be set based on historical risk data and the risk level classification requirements of security scenarios. The value range of early warning indicators can be divided into three levels: slight abnormality, obvious abnormality, and severe abnormality. The degree of abnormality of each indicator can be determined by comparing the real-time early warning indicators with the threshold values.

[0074] In some possible embodiments, thresholds for three types of indicators are set by calibrating with historical data from the industrial park: the order parameter fluctuation indicator includes slight anomalies (1.2-1.5), significant anomalies (1.5-2.0), and severe anomalies (greater than 2.0); the relaxation time indicator includes slight anomalies (12-18 minutes), significant anomalies (18-24 minutes), and severe anomalies (greater than 24 minutes); and the dynamic response function indicator includes slight anomalies (1.0-1.5), significant anomalies (1.5-2.0), and severe anomalies (greater than 2.0).

[0075] Step S4-2: Based on the abnormality of the risk precursor results and early warning indicators, generate graded early warning information, including attention-level early warning, monitoring-level early warning, warning-level early warning and emergency-level early warning.

[0076] Among them, when the risk precursor result is that there are no risk precursors and any early warning indicator shows a slight abnormality, a warning of concern level is generated. When the risk precursor result is that there are no risk precursors and any early warning indicator shows obvious abnormality, a monitoring-level warning is generated. When the risk precursor result indicates the presence of risk precursors, a warning level warning is generated. An emergency warning is generated when the risk precursor result indicates the presence of risk precursors and any early warning indicator shows a serious anomaly.

[0077] For example, taking the working period time model as an example, at 10:30 on a certain working day, due to a brief debugging of individual equipment, the sequence parameter fluctuated, and the obtained sequence parameter fluctuation index was 1.3, which is in the slightly abnormal range of 1.2-1.5, and this index was judged to be slightly abnormal; other indicators were all within the normal range, and the overall early warning index abnormality level was slightly abnormal. Taking the equipment concentration area space model as an example, at a certain moment, due to the increased operating load of some equipment, the obtained delay time was 20 minutes, which is in the obviously abnormal range of 18-24 minutes, and other indicators were slightly abnormal and normal, respectively, and this index was judged to be obviously abnormal. Taking the densely populated area space model as an example, at a certain moment, due to a sudden equipment failure, the crowd gathered and became disorderly. After applying a small virtual disturbance of 5% to the system, the sequence parameter change amplitude was 0.12, and the dynamic response function index was 2.4, which is greater than the serious abnormality threshold of 2.0, and this index was judged to be seriously abnormal; the synchronously calculated sequence parameter fluctuation index was 2.5 and the relaxation time was 25 minutes, both of which exceeded the corresponding serious abnormality threshold, and the overall early warning index abnormality level was seriously abnormal.

[0078] Figure 3 The diagram illustrates a security risk early warning system based on intelligent monitoring analysis, which can realize the ideas of this application, according to some embodiments of this application.

[0079] Specifically, a security risk early warning system based on intelligent monitoring analysis includes: The acquisition module is used to acquire security sensor data and acquire the periodic sequence parameter of the filtering fundamental model; The decomposition module decomposes security sensor data based on a decomposition algorithm to obtain a spatiotemporal fundamental model. The estimation module estimates the dominant periodic components of the spatiotemporal fundamental mode based on an estimation algorithm. A filtering module is used to filter the dominant periodic components and obtain the filtering fundamental model; The judgment module performs risk precursor judgment based on the periodic sequence parameter and obtains the risk precursor result; The analysis module analyzes the periodic sequence parameters based on phase transition theory, obtains early warning indicators, and combines them with risk precursor results to obtain graded early warning information.

[0080] The specific usage and function of this embodiment are explained below: First, security sensor data is acquired and preprocessed. A decomposition algorithm is used to decompose the security sensor data to obtain a spatiotemporal fundamental model. Then, an estimation algorithm is used to estimate the dominant periodic components of the spatiotemporal fundamental model. These dominant periodic components are then filtered to obtain a filtered fundamental model. Next, the periodic sequence parameters of the filtered fundamental model are obtained. Risk precursors are judged using these periodic sequence parameters, and risk precursor results are obtained. Finally, the periodic sequence parameters are analyzed based on phase transition theory to obtain early warning indicators. Combined with the risk precursor results, graded early warning information is obtained. This solution, by proposing a spatiotemporal fundamental model and obtaining a filtered fundamental model, obtains the operating rhythm of different scenarios at different times, thereby solving the problem of risk misjudgment caused by benchmark ambiguity and accurately identifying the time frame. This solution improves the accuracy of risk identification by identifying anomalous clusters in both spatial and temporal dimensions. Simultaneously, it employs a joint judgment logic combining qualitative assessment of risk precursors and quantitative evaluation of early warning indicators. Risk precursors identify whether the system exhibits clear signs of a potential shift towards risk; early warning quantitatively assesses the system's volatility characteristics, resilience, and disturbance sensitivity. This avoids the problem of being unable to quantify risk levels and solves the difficulty in distinguishing between accidental fluctuations and genuine risks. Through this intelligent monitoring and analysis security risk early warning solution—which integrates adaptive model extraction, risk precursor judgment, early warning indicator construction, and hierarchical collaborative response—the solution addresses the limitations of existing risk assessment technologies, thereby enhancing the accuracy of security risk early warning.

[0081] This embodiment provides an electronic device, which may include: at least one processor, at least one network interface, a user interface, a memory, and at least one communication bus.

[0082] The following is a detailed introduction to the various components of the electronic device: The communication bus can be used to enable communication between the various components mentioned above.

[0083] The user interface may include buttons, and optional user interfaces may also include standard wired interfaces and wireless interfaces.

[0084] The network interface may include, but is not limited to, Bluetooth modules, NFC modules, Wi-Fi modules, etc.

[0085] The processor may include one or more processing cores. It connects various parts of the electronic device via various interfaces and lines, executing instructions, programs, code sets, or instruction sets stored in memory, and accessing data stored in memory to perform various functions and process data. Optionally, the processor can be implemented using at least one hardware form of DSP, FPGA, or PLA. The processor can integrate one or more of the following: CPU, GPU, and modem, for example, one or more digital signal processors (DSPs) or one or more field-programmable gate arrays (FPGAs). The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content required for display; and the modem handles wireless communication. It is understood that the modem may also be implemented as a separate chip without being integrated into the processor.

[0086] The memory may include RAM or ROM. Optionally, the memory may include a non-transitory computer-readable medium. The memory may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (e.g., touch function, sound playback function, image playback function, etc.), instructions for implementing the various method embodiments described above, etc.; the data storage area may store data involved in the various method embodiments described above, etc. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor. The memory, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and an evaluation application. The processor may be used to call the evaluation application stored in the memory and execute the method steps mentioned in the foregoing embodiments.

[0087] It should be noted that the above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0088] The above embodiments can be implemented, in whole or in part, through software, hardware (such as circuits), firmware, or any other combination thereof.

[0089] When implemented using software, the above embodiments can be implemented in whole or in part as a computer program product, which includes one or more computer instructions or computer programs; when the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part.

[0090] It is understood that the computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device; the computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via transmission methods such as infrared, wireless, or microwave; the computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.

[0091] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.

[0092] It should be understood that, in the embodiments of the present invention, the order of the above-mentioned process numbers does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0093] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A security risk early warning method based on intelligent monitoring analysis, characterized in that, It includes the following steps: Acquire security sensor data and preprocess it; decompose the security sensor data based on the decomposition algorithm to obtain the spatiotemporal fundamental model. The dominant periodic components of the spatiotemporal fundamental mode are estimated based on the estimation algorithm, and the dominant periodic components are screened to obtain the screened fundamental mode; Obtain the periodic sequence parameter of the screening basic model, and make a risk precursor judgment based on the periodic sequence parameter to obtain the risk precursor result; Based on phase transition theory, periodic sequence parameters are analyzed to obtain early warning indicators, and combined with risk precursor results, graded early warning information is obtained.

2. The security risk early warning method based on intelligent monitoring analysis according to claim 1, characterized in that, Acquire and preprocess security sensor data, decompose the security sensor data based on a decomposition algorithm, and obtain the spatiotemporal fundamental model, including: Security sensor data is composed of video surveillance data, personnel access control data, environmental sensor data, and equipment operation data. The security sensor data undergoes preprocessing operations including cleaning, standardization, and spatiotemporal alignment. The preprocessed security sensor data is constructed into a two-dimensional tensor in time and space. The two-dimensional tensor is decomposed based on the improved PARAFAC2 decomposition algorithm to obtain the spatiotemporal fundamental model, which includes the temporal spatiotemporal fundamental model and the spatial spatiotemporal fundamental model. The improved PARAFAC2 decomposition algorithm introduces a non-convex rank proximity norm constraint mechanism to constrain the potential factors in the decomposition process, and replaces the alternating least squares method in the PARAFAC2 decomposition algorithm with the symmetric Gauss-Seidel alternating direction multiplier method.

3. The security risk early warning method based on intelligent monitoring analysis according to claim 1, characterized in that, The dominant periodic components of the spatiotemporal fundamental modes are estimated based on the estimation algorithm. These dominant periodic components are then filtered to obtain the filtered fundamental modes, including: A multiple signal classification algorithm is used to analyze the non-stationary time series corresponding to the time-space fundamental mode in the spatiotemporal fundamental mode, and to estimate the dominant periodic component of the spatiotemporal fundamental mode; The confidence level of all dominant periodic components is evaluated based on the Bootstrap method, and a confidence level threshold is set. Iterate through the confidence scores of all dominant periodic components, obtain confidence scores greater than the confidence score threshold, and use the spatiotemporal fundamental mode corresponding to the confidence score as the screening fundamental mode.

4. The security risk early warning method based on intelligent monitoring analysis according to claim 1, characterized in that, Obtain the periodic sequence parameter of the screening primitive, perform risk precursor judgment based on the periodic sequence parameter, and obtain the risk precursor result, including: Based on the periodic sequence parameter formula, the periodic sequence parameter of each screening basic model is obtained; The periodic sequence parameter formula is specifically expressed as follows: ; in, This is represented as the periodicity sequence parameter for screening fundamental models. This represents the number of monitoring signals associated with the filter's fundamental model. Represented as the first The monitoring signal associated with the screening baseline model Represented as the first The weight of each monitoring signal, Represented as the imaginary unit, Represented as Time of the first The phase of a monitoring signal associated with the screening baseline; The temporal and spatial translational symmetries are obtained based on the aforementioned periodic sequence parameters. Based on the aforementioned time translation symmetry and spatial translation symmetry, time breaking conditions and spatial breaking conditions are set, and a breaking duration threshold is set. Risk precursor results are obtained based on temporal failure conditions, spatial failure conditions, and failure duration thresholds.

5. A security risk early warning method based on intelligent monitoring analysis according to claim 4, characterized in that, Risk precursor results are obtained based on temporal failure conditions, spatial failure conditions, and failure duration thresholds, including: When both the time spurious condition and the space spurious condition are met, and the duration of the spurious condition is greater than or equal to the spurious condition duration threshold, it is determined that there are early warning signs of risk; otherwise, it is determined that there are no early warning signs of risk. The time symmetry breaking condition is defined as the ratio of the change in time translation symmetry to the time translation symmetry within a unit time being greater than the time translation symmetry threshold, and the spatial symmetry breaking condition is defined as the ratio of the change in spatial translation symmetry to the spatial translation symmetry within a unit time being greater than the spatial translation symmetry threshold.

6. The security risk early warning method based on intelligent monitoring analysis according to claim 1, characterized in that, Based on phase transition theory, periodic sequence parameters are analyzed to obtain early warning indicators. Combined with risk precursor results, graded early warning information is obtained, including: Based on phase transition theory, early warning indicators are extracted from periodic sequence parameters; Set indicator thresholds and obtain the degree of abnormality of early warning indicators based on early warning indicators; Based on the degree of abnormality of risk precursor results and early warning indicators, graded early warning information is generated, including attention-level early warning, monitoring-level early warning, early warning-level early warning and emergency-level early warning. Among them, when the risk precursor result is that there are no risk precursors and any early warning indicator shows a slight abnormality, a warning of concern level is generated. When the risk precursor result is that there are no risk precursors and any early warning indicator shows obvious abnormality, a monitoring-level warning is generated. When the risk precursor result indicates the presence of risk precursors, a warning level warning is generated. An emergency warning is generated when the risk precursor result indicates the presence of risk precursors and any early warning indicator shows a serious anomaly.

7. A security risk early warning method based on intelligent monitoring analysis according to claim 6, characterized in that, Based on phase transition theory, early warning indicators are extracted from periodic sequence parameters, including: Set a time window, obtain the baseline variance of the periodic sequence parameter, and simultaneously obtain the rolling window variance of the periodic sequence parameter. The baseline variance of the periodic sequence parameter is represented as the variance of the periodic sequence parameter when the system is in a normal state. Obtain the sequence parameter fluctuation index based on the ratio of the rolling window variance to the baseline variance. The autocorrelation function is set based on the time interval, and the relaxation time index is obtained based on the autocorrelation function. The time interval represents the time required for the periodic sequence parameter to recover from the deviation state to the stable state. Apply a small virtual disturbance to the system, obtain the change amplitude of the periodic sequence parameter, and obtain the dynamic response function index based on the change amplitude; An early warning indicator is composed of an order parameter fluctuation index, a relaxation time index, and a dynamic response function index.

8. A security risk early warning system based on intelligent monitoring analysis, used to implement the method described in any one of claims 1-7, characterized in that, include: The acquisition module is used to acquire security sensor data and acquire the periodic sequence parameter of the filtering fundamental model; The decomposition module decomposes security sensor data based on a decomposition algorithm to obtain a spatiotemporal fundamental model. The estimation module estimates the dominant periodic components of the spatiotemporal fundamental mode based on an estimation algorithm. A filtering module is used to filter the dominant periodic components and obtain the filtering fundamental model; The judgment module performs risk precursor judgment based on the periodic sequence parameter and obtains the risk precursor result; The analysis module analyzes the periodic sequence parameters based on phase transition theory, obtains early warning indicators, and combines them with risk precursor results to obtain graded early warning information.