An agent cooperative alarm data processing and port security report generation method and system
Patent Information
- Application Number
- CN202610893541.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-18
- Publication Date
- 2026-09-29
AI Technical Summary
[0009]本发明解决现有技术难以满足现代港口对高可靠、高效率、智能化安防运维需求的问题,提供一种智能体协同的报警数据处理及港口安防报告生成方法及系统
[0027]本发明提供一种报警数据验证分析及周期性港口安防报告生成的方法及系统,现有港口安防多类感知设备产生的报警数据来源分散、格式异构,缺乏统一汇聚与标准化处理机制,导致数据杂乱无章,易出现大量重复报警、缺失数据及异常数据,增加人工核验难度,造成误报率高、漏报风险大的问题,本发明采集港口报警数据,对报警数据进行预处理,所述预处理包括:数据格式标准化、数据清洗和数据存储,对报警数据的格式进行统一,并对数据进一步进行清洗,清洗掉重复和异常的数据,明显降低人工核验难度,减少误报率和漏报风险。单一传感器报警信息可信度低,现有技术缺乏多源数据交叉验证与智能研判能力,无法通过时空关联、多模态数据比对实现报警真伪精准判定,导致安防值班人员疲于应对无效报警,真实安全隐患响应滞后,另外,各安防子系统独立运行,未形成协同分析架构,缺乏对报警事件的时间连续性、空间邻近性及区域联动性分析能力,难以识别复杂场景下的连锁安防风险,无法实现风险的精准分级与高效处置,本发明构建智能体集群,所述时空关联智能体通过时空关联分析输出关联结果;多源验证智能体基于关联结果,调取对应采集的数据进行比对验证;风险研判智能体基于报警真伪结果对报警进行风险等级划分和事件标注;所述投票智能体对时空关联智能体、多源验证智能体和风险研判智能体的结果进行加权,输出报警真伪结果,解决现有技术的上述问题。港口安防报告依赖人工统计汇总,存在生成周期长、数据口径不统一、内容规范性差等问题,且无法按日/周/月等预设周期自动生成,难以全面、及时呈现安防态势,无法为管理决策与风险复盘提供有效支撑,本发明所述报告生成智能体内置标个智能体输出的数据,按照预设的报告周期自动生成港口安防报告,解决上述现有技术的问题。现有报警数据、分析过程与报告结果缺乏结构化归档与追溯机制,导致安防事件的历史关联分析、责任追溯及系统优化缺乏数据基础,难以实现港口安防水平的持续提升,本发明将生成的港口安防报告进行归档并推送给相关的人员,可随时根据归档的数据追溯历史安防事件,实现港口安防水平的持续提升。
Smart Images

Figure FT_1
Abstract
Description
Technical Field
[0001] This invention belongs to the field of port security monitoring technology, specifically relating to a method and system for intelligent agent collaborative alarm data processing and port security report generation. Background Technology
[0002] With the continuous advancement of smart port construction, port security systems have widely deployed various sensing devices, including video surveillance, perimeter intrusion detection, infrared alarms, radar detection, and AIS ship identification, generating massive amounts of alarm data. Existing port security systems suffer from the following technical problems:
[0003] 1. Existing port security alarm data generated by various sensing devices is scattered and heterogeneous in format, lacking a unified aggregation and standardized processing mechanism. This results in disorganized data, prone to numerous false alarms, missed alarms, duplicate alarms, missing data, and abnormal data, increasing the difficulty of manual verification and leading to low efficiency and delayed response. For example, the invention patent CN121637159A, "Multi-source Alarm Information Collaborative Verification Method and System Based on Cross-modal Causal Attention," establishes a deep correlation between sensor and video data through a cross-modal bidirectional causal attention mechanism; it uses prior information about the building space to constrain attention calculation, improving verification efficiency; and it standardizes multi-source data and extracts modal feature vectors to output a risk score. However, this patent does not involve multi-modal large-scale model applications, lacks port-specific analysis dimensions, does not provide four-dimensional statistics on "region-cause-quantity-false alarm rate," and lacks port compliance adaptation design.
[0004] 2. The lack of intelligent judgment mechanism for alarm events, the low reliability of alarms from single sensors, and the lack of cross-verification and intelligent judgment capabilities of multi-source data in existing technologies make it impossible to determine the authenticity of alarms through spatiotemporal correlation and cross-verification of multimodal data. This results in security personnel being overwhelmed by invalid alarms and a delayed response to real security risks.
[0005] 3. The lack of a multi-agent collaborative analysis architecture means that each security subsystem operates independently, failing to form a comprehensive analytical capability encompassing regional linkage, temporal correlation, and spatial topology. It lacks the ability to analyze the temporal continuity, spatial proximity, and regional linkage of alarm events, making it difficult to identify cascading security risks in complex scenarios and hindering accurate risk classification and efficient handling. For example, invention patent CN114582965A, a port intelligent security alarm system and method, integrates port radar, video, and AIS (Automatic Identification System) data for alarm monitoring; it achieves alarm location and hierarchical push based on port area division; and it constructs an alarm event database to support historical data tracing. However, this patent does not employ a multimodal large model for image verification, and its analysis dimensions only cover "region-alarm type." It does not involve specific analysis of false alarm rates or the automated generation of periodic reports, and lacks an agent collaborative verification mechanism.
[0006] 4. Port security reports rely heavily on manual statistics and compilation, resulting in long generation cycles, inconsistent data standards, and non-standard content. They cannot be automatically generated on a daily / weekly / monthly basis, making it difficult to comprehensively and timely present the security situation and provide effective support for management decisions and risk reviews.
[0007] 5. The lack of structured archiving and traceability mechanisms for alarm data, analysis processes, and report results leads to a lack of data foundation for historical correlation analysis of security incidents, accountability tracing, and system optimization, making it difficult to achieve continuous improvement in port security levels.
[0008] In summary, existing technologies are insufficient to meet the demands of modern ports for highly reliable, efficient, and intelligent security operations and maintenance. Summary of the Invention
[0009] This invention addresses the problem that existing technologies cannot meet the high reliability, high efficiency, and intelligent security operation and maintenance requirements of modern ports, and provides a method and system for intelligent agent collaborative alarm data processing and port security report generation.
[0010] The technical solution claimed by this invention is as follows:
[0011] A method for processing alarm data and generating port security reports in a collaborative manner using intelligent agents includes the following steps:
[0012] S1: Multi-source alarm data acquisition and preprocessing: Acquire port alarm data, preprocess the alarm data, and add port-specific area and alarm cause classification tags to the obtained data; the alarm data includes: video surveillance, sensor, AIS ship identification and access control system data; the preprocessing includes: data format standardization, data cleaning and data storage;
[0013] S2: Agent Cluster Initialization and Task Scheduling: Construct an agent cluster and initialize and schedule tasks for each agent in the cluster to process and verify the alarm data obtained in S1; the agent cluster includes a data access agent, a spatiotemporal correlation agent, a multi-source verification agent, a risk assessment agent, a voting agent, a report generation agent, and a task scheduling agent.
[0014] S3: Collaborative Alarm Data Verification and Authenticity Determination by Intelligent Agents: The spatiotemporal correlation intelligent agent outputs correlation results through spatiotemporal correlation analysis; the multi-source verification intelligent agent retrieves the corresponding data collected in S1 for comparison and verification based on the correlation results; the risk assessment intelligent agent classifies the alarms into risk levels and labels events based on the alarm authenticity results; the voting intelligent agent weights the results of the spatiotemporal correlation intelligent agent, the multi-source verification intelligent agent, and the risk assessment intelligent agent, outputs the alarm authenticity results, and classifies and records real alarms and false alarms; the multi-source verification intelligent agent integrates a multimodal large model;
[0015] S4: Automatic generation of periodic port security reports: The report generation agent has a built-in standardized report template. Based on the data output by each agent in the agent cluster, it conducts in-depth investigation of the root causes of high-frequency alarms and high false alarms, extracts compliance indicators, provides core content for the report, and automatically generates port security reports according to the preset reporting cycle.
[0016] S5: Archive the generated port security report and push it to relevant personnel.
[0017] Preferably, the alarm data is collected in real time from various security devices in the port via the device SDK and IoT gateway; the collected content includes: alarm ID, device ID, device type, alarm type, occurrence time, location coordinates, event description, and raw data fragments; the alarm types include: intrusion, boundary crossing, and access control anomaly; the location coordinates include: latitude and longitude, and area code; the raw data fragments include: video frames and sensor waveforms.
[0018] Preferably, the data format standardization is based on a preset data dictionary, which unifies heterogeneous data into JSON format; the data cleaning uses a rule engine and machine learning algorithm to clean the data obtained from the data standardization process: removing duplicate alarms of the same device, location, and type within 1 minute; automatically completing alarms with missing location coordinates by associating them with the device ledger using the device ID; filtering out abnormal data that exceeds the port's geographical boundaries, has incorrect time format, or has a data field missing rate exceeding 50%; the data storage stores the cleaned standardized data in a time-series database, supporting fast retrieval by time, region, and device type.
[0019] Preferably, the data access agent is responsible for device connection management, data acquisition, and format verification, and adopts a multi-threaded concurrent processing mechanism to support simultaneous access of 1000+ devices; the spatiotemporal correlation agent analyzes the temporal continuity and spatial proximity of alarm events based on a spatiotemporal indexing algorithm; the multi-source verification agent integrates image recognition and sensor data fusion algorithms to achieve multimodal data cross-verification; the risk assessment agent uses a rule base + random forest model to determine risk levels and generate handling suggestions; the voting agent uses a "weighted voting mechanism" to output alarm authenticity results; the report generation agent has built-in standardized report templates, supports automatic rendering in PDF / Word format, and integrates data visualization components; the task scheduling agent is based on a distributed task scheduling framework and dynamically allocates tasks according to alarm priority and regional load; the task scheduling agent allocates tasks according to the following rules: the task scheduling agent assigns alarm events in the same region to the same group of agents; alarms in critical regions trigger parallel processing of the agent cluster, while alarms in ordinary regions are processed in queue order.
[0020] Preferably, the spatiotemporal correlation analysis includes: time window analysis and spatial proximity analysis; the time window analysis extracts alarm data in the same area within 10 minutes before and after the alarm occurrence time to determine whether there are consecutively triggered time-series correlation events; the spatial proximity analysis calculates the distance between the alarm location and surrounding devices to determine whether there are spatial correlation events triggered by multiple devices; the correlation results include: "isolated event / time-series correlation event / spatial correlation event" labels and correlation confidence.
[0021] Preferably, the comparison and verification includes: video verification, sensor data verification, and AIS / GPS data verification; the video verification involves retrieving video clips 30 seconds before and after the alarm time for intrusion and boundary crossing alarms, using the YOLOv8 algorithm to identify the presence of a target, and outputting the target detection confidence level; the sensor data verification involves comparing the heat source signal intensity of infrared sensors at the same location for infrared alarms, and verifying the target trajectory and speed of radar echoes for radar alarms; the AIS / GPS data verification involves associating AIS ship dynamic data for ship-related alarms to determine whether the ship is within the alarm area; the risk levels include: major risk, significant risk, general risk, and low risk; the event labeling includes: responsible area, responsible person, handling suggestions, and estimated handling time.
[0022] Preferably, the alarm authenticity result output in S3 is fed back to the multimodal large model for optimization.
[0023] Preferably, the port security report automatically compiles the following core indicators: Basic statistics: total number of alarms, actual number of alarms, suspected number of alarms, false alarms, actual alarm rate, false alarm rate, and closed-loop handling rate; Distribution statistics: alarm distribution in each area, proportion of each type of alarm, and number of alarms at each risk level; Trend statistics: weekly / monthly change in total alarms, trend of high-incidence alarm types, and trend of actual alarm rate; Handling statistics: response time of each shift, number of events handled beyond the time limit, and rectification completion rate.
[0024] Preferably, the agent cluster further includes a backup agent and an upgrade agent; the report template supports user-defined modifications, and the modifications are automatically synchronized to the report generation agent.
[0025] This invention also provides an intelligent agent collaborative alarm data processing and port security report generation system. The system includes, in sequence, a data acquisition and preprocessing module, an intelligent agent cluster initialization and task scheduling module, an alarm data verification and authenticity determination module, a port security report automatic generation module, and a report archiving and push module. The data acquisition and preprocessing module acquires port alarm data and preprocesses it. The intelligent agent cluster initialization and task scheduling module constructs an intelligent agent cluster and initializes and schedules tasks for each agent in the cluster, realizing alarm data processing and content verification. The alarm data verification and authenticity determination module verifies and determines the authenticity of the alarm data. The port security report automatic generation module periodically generates port security reports automatically. The report archiving and push module archives the generated port security reports and pushes them to relevant personnel.
[0026] The beneficial effects of this invention are as follows:
[0027] This invention provides a method and system for alarm data verification and analysis, and the generation of periodic port security reports. Existing port security alarm data generated by various sensing devices is scattered in origin and heterogeneous in format, lacking a unified aggregation and standardized processing mechanism. This results in disorganized data, prone to numerous duplicate alarms, missing data, and abnormal data, increasing the difficulty of manual verification and causing high false alarm rates and a high risk of missed alarms. This invention collects port alarm data and preprocesses it, including data format standardization, data cleaning, and data storage. The alarm data format is standardized, and the data is further cleaned to remove duplicate and abnormal data, significantly reducing the difficulty of manual verification and decreasing the risk of false alarms and missed alarms. The reliability of alarm information from a single sensor is low. Existing technologies lack the ability to cross-verify and intelligently analyze multi-source data, making it impossible to accurately determine the authenticity of alarms through spatiotemporal correlation and multimodal data comparison. This leads to security personnel being overwhelmed by invalid alarms and delayed responses to real security risks. Furthermore, the independent operation of each security subsystem lacks a collaborative analysis architecture and the ability to analyze the temporal continuity, spatial proximity, and regional linkage of alarm events. This makes it difficult to identify cascading security risks in complex scenarios and achieve accurate risk classification and efficient handling. This invention constructs an intelligent agent cluster. The spatiotemporal correlation intelligent agent outputs correlation results through spatiotemporal correlation analysis; the multi-source verification intelligent agent retrieves corresponding collected data for comparison and verification based on the correlation results; the risk assessment intelligent agent classifies alarms by risk level and labels events based on the alarm authenticity results; and the voting intelligent agent weights the results of the spatiotemporal correlation intelligent agent, the multi-source verification intelligent agent, and the risk assessment intelligent agent to output the alarm authenticity result, thus solving the above-mentioned problems of existing technologies. Port security reports currently rely on manual statistical compilation, resulting in problems such as long generation cycles, inconsistent data definitions, and poor content standardization. Furthermore, they cannot be automatically generated on preset daily / weekly / monthly schedules, making it difficult to comprehensively and promptly present the security situation and providing effective support for management decisions and risk reviews. The report generation intelligence agent described in this invention incorporates data output by a set number of intelligence agents and automatically generates port security reports according to a preset reporting cycle, solving the aforementioned problems of existing technologies. Existing alarm data, analysis processes, and report results lack structured archiving and traceability mechanisms, leading to a lack of data foundation for historical correlation analysis of security incidents, responsibility tracing, and system optimization, hindering the continuous improvement of port security levels. This invention archives the generated port security reports and pushes them to relevant personnel, allowing for the tracing of historical security incidents at any time based on the archived data, thus achieving continuous improvement in port security levels.
[0028] This invention achieves intelligent and standardized port security data processing and report generation through a closed-loop architecture of "standardized access to multi-source data - collaborative verification by multiple intelligent agents - risk classification and assessment - automated report generation - full-process data archiving". Attached Figure Description
[0029] Figure 1 This is a flowchart illustrating the method for processing alarm data and generating port security reports in collaboration with intelligent agents in this embodiment of the invention. Detailed Implementation
[0030] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions will be further described clearly and completely below with reference to the accompanying drawings.
[0031] This invention provides a method for processing alarm data and generating port security reports in a collaborative manner using intelligent agents, such as... Figure 1 As shown, the specific steps include the following:
[0032] S1: Multi-source alarm data acquisition and preprocessing: Acquire port alarm data, preprocess the alarm data, and add port-specific area and alarm cause classification tags to the obtained data; the alarm data includes: video surveillance, sensor, AIS ship identification and access control system data; the alarm data supports visualization display. The preprocessing includes: data format standardization, data cleaning, and data storage. In a specific embodiment of the present invention, the data acquisition is achieved by accessing alarm data from various security devices in the port in real time through the device SDK and IoT gateway (MQTT / HTTP protocol). When data acquisition is interrupted, local caching is initiated, and data is automatically retransmitted after the connection is restored. The acquired content includes: alarm ID, device ID, device type, alarm type (intrusion / boundary crossing / access control anomaly, etc.), occurrence time (accurate to milliseconds), location coordinates (latitude and longitude / area number), event description, and raw data fragments (video frames / sensor waveforms). The data format standardization is based on a preset data dictionary, which uniformly parses heterogeneous data into JSON format, as shown in the following example: { "alarm_id": "ALM20240520001","device_id":"CAM0035","device_type": "video_surveillance", "alarm_type": "intrusion","occur_time":"2024-05-20 03:12:45.678", "location": {"longitude": 121.856, "latitude": 31.235, "area_code": "A01-Frontline Work Area"}, "description": "Personnel detected entering restricted area", "raw_data": "video_frame_20240520031245.jpg"}.
[0033] The data cleaning process employs a rule engine and machine learning algorithms. This includes deduplication, completion, and anomaly removal. Deduplication removes duplicate alarms from the same device, location, and type within one minute. Completion automatically fills in missing location coordinates for alarms by associating them with the device ledger using the device ID. Anomaly removal filters out abnormal data that exceeds port geographical boundaries, has incorrect time format, or has a data field missing rate exceeding 50%. The data storage process stores the cleaned, standardized data in a time-series database, supporting rapid retrieval by time, region, and device type.
[0034] S2: Agent Cluster Initialization and Task Scheduling: Construct an agent cluster and initialize and schedule tasks for each agent in the cluster to process and verify the alarm data obtained in S1; the agent cluster includes a data access agent, a spatiotemporal correlation agent, a multi-source verification agent, a risk assessment agent, a voting agent, a backup agent, a report generation agent, an upgrade agent, and a task scheduling agent; each agent interacts with data and collaborates on tasks through a preset communication protocol (RESTful API + message queue); in a specific embodiment of the present invention, this step includes:
[0035] Intelligent Agent Cluster Construction: The functions and technical characteristics of each intelligent agent are as follows: The data access intelligent agent is responsible for device connection management, data acquisition and format verification, and adopts a multi-threaded concurrent processing mechanism to support 1000+ devices to access simultaneously; The spatiotemporal correlation intelligent agent is based on the spatiotemporal indexing algorithm (R-tree + time window) to analyze the temporal continuity and spatial proximity of alarm events; The multi-source verification intelligent agent integrates image recognition (YOLOv8) and sensor data fusion (Kalman filtering) algorithms to achieve multimodal data cross-verification; The risk assessment agent, based on a rule base and random forest model, determines risk levels and generates handling suggestions. The report generation agent has built-in standardized report templates, supports automatic rendering in PDF / Word formats, and integrates data visualization components. The task scheduling agent, based on a distributed task scheduling framework, dynamically allocates tasks according to alarm priority and regional load. The backup agent is used when other agents fail. The upgrade agent updates parameters online incrementally based on false alarm samples, continuously optimizing verification adaptability under complex operating conditions and reducing the rate of repeated false alarms. When an agent fails, the task scheduling agent automatically assigns tasks to the backup agent to ensure uninterrupted flow. The agent cluster adopts a "message queue + publish-subscribe" model, with each agent using RabbitMQ to achieve message transmission, ensuring the real-time performance and reliability of task scheduling, and supporting dynamic expansion and failover of agents.
[0036] Agent initialization: When the method starts, the task scheduling agent automatically loads each agent instance, initializes communication connections and task queues, and detects the running status of each agent.
[0037] The task allocation rules of the task scheduling agent are as follows:
[0038] Allocation by region: Alarm events in the same region are assigned to the same group of agents to ensure the consistency of event correlation analysis within the region;
[0039] Assigned by type: The intelligent agent cluster also includes video + infrared verification intelligent agents, and intrusion alarms are prioritized to be scheduled by video + infrared verification intelligent agents;
[0040] Allocation is based on priority: alarms in critical areas (such as hazardous chemical storage areas) are triggered by the intelligent agent cluster for parallel processing, while alarms in ordinary areas are processed in queue order.
[0041] S3: Collaborative Alarm Data Verification and Authenticity Determination by Intelligent Agents: The spatiotemporal correlation intelligent agent outputs correlation results through spatiotemporal correlation analysis; the multi-source verification intelligent agent retrieves the corresponding data collected in S1 for comparison and verification based on the correlation results; the risk assessment intelligent agent classifies alarms into risk levels and labels events based on the alarm authenticity results; the voting intelligent agent weights the results of the spatiotemporal correlation intelligent agent, the multi-source verification intelligent agent, and the risk assessment intelligent agent, outputs alarm authenticity results, and classifies and records real alarms and false alarms; the multi-source verification intelligent agent integrates a multimodal large model, which incorporates port prior knowledge, extracts visual and semantic features of alarm images, outputs authenticity confidence, and accurately distinguishes between real and false alarms. Real threats and false alarms; additionally, the real alarm and false alarm data recorded in the classification are sent to the analysis module for further analysis; in a specific embodiment of the present invention, after receiving standardized alarm data, the spatiotemporal correlation agent performs the following operations: Time window analysis: extract alarm data in the same area within 10 minutes before and after the alarm occurrence time, and determine whether there are continuously triggered time-series correlation events; Spatial proximity analysis: calculate the distance between the alarm location and surrounding devices (threshold set to 50 meters), and determine whether there are spatial correlation events triggered by multiple devices; Output spatiotemporal correlation results (correlation results): generate "isolated event / time-series correlation event / spatial correlation event" labels and correlation confidence scores (0-100 points).
[0042] The comparison and verification specifically involves: The multi-source verification agent, based on spatiotemporal correlation results, retrieves corresponding verification data for comparison: Video verification: For intrusion and boundary crossing alarms, video clips 30 seconds before and after the alarm time are retrieved, and the YOLOv8 algorithm is used to identify the presence of a target (personnel / vehicle / ship), outputting the target detection confidence level; Sensor data verification: For infrared alarms, the heat source signal intensity of infrared sensors at the same location is compared (threshold set at 36℃); For radar alarms, the target trajectory and speed of the radar echo are verified; AIS / GPS data verification: For ship-related alarms, AIS ship dynamic data is correlated to determine whether the ship is within the alarm area.
[0043] The risk assessment intelligence agent is graded based on the following indicators: Core indicators (weight 0.5): Alarm type (major types such as intrusion / hazardous chemical leakage score 100 points, general types such as access control anomalies score 40 points); Auxiliary indicators (weight 0.3): Impact range (single device impact score 20 points, multi-area linkage score 100 points); Historical indicators (weight 0.2): Frequency of similar events and accident consequences in the past 3 months (no accidents score 30 points, minor accidents score 60 points, serious accidents score 100 points); Based on the total score of the indicators, it is divided into 4 levels: Major risk (≥90 points): such as intrusion into hazardous chemical storage areas, ship collisions with docks, etc., requiring immediate activation of emergency plans; Significant risk (70-89 points): such as unauthorized personnel entering the work area, critical equipment failures, etc. For example, alarms and other malfunctions require on-site handling within 15 minutes; general risks (40-69 points): such as abnormal access control in ordinary areas, low battery alarms of equipment, etc., require closed-loop management within 2 hours; low risks (<40 points): such as false alarms caused by environmental interference, minor anomalies in non-core areas, etc., are only recorded for filing; the risk assessment intelligent agent automatically generates event labeling information, including: responsible area (based on location coordinates and port zoning ledger), responsible person for handling (assigned to the corresponding security team according to the area), handling suggestions (based on the rule base to match the optimal handling solution for similar events), and estimated handling time.
[0044] The voting agent uses a "weighted voting mechanism" to output the alarm authenticity results: spatiotemporal correlation agent (weight 0.2), multi-source verification agent (weight 0.6), and risk assessment agent (weight 0.2).
[0045] Voting rules: Each agent outputs a "true / suspected / false positive" conclusion and a confidence score, which are then weighted and summed.
[0046] A total score of ≥80 points is considered a "real alarm" and triggers a real-time alarm push.
[0047] 40 points ≤ Total score < 80 points: judged as "suspected alarm", and sent to manual review;
[0048] Total score < 40 points: judged as "false alarm", only stored in the database, and no alarm is triggered.
[0049] The above steps perform a four-dimensional linkage analysis of the data, conducting statistical analysis from four dimensions: overall area, cause, quantity, and false alarm rate, clearly presenting the security situation.
[0050] S4: Automatic Generation of Periodic Port Security Reports: The report generation agent has a built-in standardized report template. Based on the data output by each agent in the agent cluster, it thoroughly investigates the root causes of high-frequency alarms and high false alarms, extracts compliance indicators that conform to the "Port Facility Security Rules," and provides core content for the report. Port security reports are automatically generated according to a preset reporting cycle. In a specific embodiment of this invention, users can preset the reporting cycle (daily / weekly / monthly report). If the user does not preset, the default cycle is: daily report (data from the previous day is generated at 00:30 each day), weekly report (data from the previous day is generated every Monday at 01:00). The system generates data for the previous week (02:00 on the 1st of each month) and monthly reports (data for the previous month is generated on the 1st of each month). Before generating the port security report, the intelligent agent will automatically perform the following statistics: Basic statistics: total number of alarms, actual number of alarms, suspected number of alarms, false alarms, actual alarm rate, false alarm rate, and closed-loop handling rate; Distribution statistics: alarm distribution in each area, percentage of alarms of each type, and number of alarms at each risk level; Trend statistics: weekly / monthly change in total alarms, trend of high-incidence alarm types, and trend of actual alarm rate; Handling statistics: response time of each team, number of overdue handling events, and rectification completion rate.
[0051] The port security report has the following content structure: The report generation AI automatically fills in the content according to a preset template, with the following structure: Cover: Report name, period, generation time, port name; Table of contents: Automatically generated table of contents with jumpable links; Overview summary: Overview of core indicators, summary of security situation in this period (AI automatically generates natural language description); Data statistics: Basic statistics and distribution statistics are presented in tabular form; Hotspot analysis: High alarm areas are displayed through heat maps, and high-incidence alarm types are displayed through bar charts; Trend analysis: Alarm trends are displayed through line charts, and AI analyzes the reasons for the trends (e.g., "Intrusion alarms in area A01 increased this week, presumably related to insufficient night patrol frequency"); Rectification suggestions: Based on risk distribution and trends, targeted suggestions are automatically generated (e.g., "Strengthen nighttime infrared equipment inspections in hazardous chemical area B03"); Attachments: Original data tables, chart source files, details of key incident handling; The port security report supports PDF (default) and Word formats, uses a template engine for rendering to ensure standardized formatting, and charts are automatically inserted into corresponding chapters.
[0052] S5: Archive the generated port security report and push it to relevant personnel; in a specific embodiment of the present invention, the push channels include: port security management platform (Web terminal), mobile terminal of the person in charge (APP / WeChat official account / SMS), and corporate email; the push rules are: daily reports are pushed to the security team leader, weekly reports are pushed to the department manager, and monthly reports are pushed to the port management.
[0053] The content pushed is subject to access control: report viewing permissions are assigned based on role permissions, and sensitive data (such as alarm details for hazardous chemical areas) is only visible to authorized personnel;
[0054] The archived content includes: raw alarm data, standardized dataset, agent analysis log, alarm judgment results, risk classification records, and generated report files;
[0055] The report is stored as follows: structured data is stored in a relational database, unstructured data (videos, report files) is stored in a distributed file system, archived data is retained for one year, and it supports retrieval and export by time, region, and alarm type.
[0056] The report's backup mechanism employs a dual backup system of "local + cloud" to prevent data loss.
[0057] The report-generating intelligent agent includes a report management module and an access control module, allowing only authorized personnel to view reports.
[0058] The parameters of the risk assessment model and multi-source verification algorithm are periodically (monthly) iteratively optimized based on historical data to improve the accuracy of judgment.
[0059] This invention also provides a system for intelligent agent collaborative alarm data processing and port security report generation. The system includes, in sequence, a data acquisition and preprocessing module, an intelligent agent cluster initialization and task scheduling module, an alarm data verification and authenticity determination module, a port security report automatic generation module, and a report archiving and push module. The data acquisition and preprocessing module collects port alarm data and preprocesses it. The intelligent agent cluster initialization and task scheduling module constructs an intelligent agent cluster and initializes and schedules tasks for each agent in the cluster, realizing alarm data processing and content verification. The alarm data verification and authenticity determination module verifies and determines the authenticity of alarm data. The port security report automatic generation module periodically generates port security reports. The report archiving and push module archives the generated port security reports and pushes them to relevant personnel. The report archiving and push module includes a report archiving module and a push service module. The system also includes an alarm visualization module, a report management module, and an access control module; the data acquisition and preprocessing module is connected to the alarm visualization module, which visualizes the alarm data collected by the data acquisition and preprocessing module; the port security report automatic generation module is connected to the report management module and the access control module, which manages the generated reports and controls access to the generated reports, ensuring that only authorized users can view the generated reports.
[0060] In the above system, the report template can be customized by users (such as adding indicators or adjusting the order of chapters). After modification, it will be automatically synchronized to the report generation agent without the need to restart the system.
[0061] The system is constructed with a three-tier architecture: "Data Layer - Intelligent Agent Collaboration Layer - Application Layer". The functions and relationships of each layer are as follows: Data Layer: Includes a cluster of port security sensing equipment (video surveillance, perimeter intrusion detection, infrared beam detectors, radar detection, access control systems, AIS ship identification systems, GPS positioning devices, etc.), a data caching module, and a standardized database, responsible for raw data collection, temporary storage, and structured management; Intelligent Agent Collaboration Layer: The core is a multi-agent cluster, including data access agents, spatiotemporal correlation agents, multi-source verification agents, risk assessment agents, report generation agents, and task scheduling agents. Each agent achieves data interaction and task collaboration through a preset communication protocol (RESTful API + message queue); Application Layer: Includes an alarm visualization module, a report management module, an access control module, and a push service module, responsible for result display, report distribution, and system operation and maintenance.
[0062] It should be noted that the specific embodiments described above enable those skilled in the art to more fully understand the present invention, but do not limit the present invention in any way. Therefore, although the present invention has been described in detail with reference to the accompanying drawings and embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the present invention. In short, all technical solutions and improvements that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the present invention patent.
Claims
1. A method for intelligent agent collaborative alarm data processing and port security report generation, characterized in that, Includes the following steps: S1: Multi-source alarm data acquisition and preprocessing: Acquire port alarm data, preprocess the alarm data, and add port-specific area and alarm cause classification tags to the obtained data; The alarm data includes: video surveillance, sensor data, AIS ship identification and access control system data; the preprocessing includes: data format standardization, data cleaning and data storage. S2: Agent Cluster Initialization and Task Scheduling: Construct an agent cluster and initialize and schedule tasks for each agent in the cluster to process and verify the alarm data obtained in S1; the agent cluster includes a data access agent, a spatiotemporal correlation agent, a multi-source verification agent, a risk assessment agent, a voting agent, a report generation agent, and a task scheduling agent. S3: Collaborative Alarm Data Verification and Authenticity Determination by Intelligent Agents: The spatiotemporal correlation intelligent agent outputs correlation results through spatiotemporal correlation analysis; the multi-source verification intelligent agent retrieves the corresponding data collected in S1 for comparison and verification based on the correlation results; the risk assessment intelligent agent classifies the alarms into risk levels and labels events based on the alarm authenticity results; the voting intelligent agent weights the results of the spatiotemporal correlation intelligent agent, the multi-source verification intelligent agent, and the risk assessment intelligent agent, outputs the alarm authenticity results, and classifies and records real alarms and false alarms; the multi-source verification intelligent agent integrates a multimodal large model; S4: Automatic generation of periodic port security reports: The report generation agent has a built-in standardized report template. Based on the data output by each agent in the agent cluster, it conducts in-depth investigation of the root causes of high-frequency alarms and high false alarms, extracts compliance indicators, provides core content for the report, and automatically generates port security reports according to the preset reporting cycle. S5: Archive the generated port security report and push it to relevant personnel.
2. The method for processing alarm data and generating port security reports based on intelligent agent collaboration as described in claim 1, characterized in that, The alarm data is collected in real time by accessing various security devices in the port through the device SDK and IoT gateway. The collected content includes: alarm ID, device ID, device type, alarm type, occurrence time, location coordinates, event description, and raw data fragments. The alarm types include: intrusion, boundary crossing, and access control anomaly. The location coordinates include: latitude and longitude, and area code. The raw data fragments include: video frames and sensor waveforms.
3. The method for processing alarm data and generating port security reports based on intelligent agent collaboration as described in claim 2, characterized in that, The data format standardization is based on a preset data dictionary, which unifies heterogeneous data into JSON format. The data cleaning uses a rule engine and machine learning algorithm to clean the data obtained from the data standardization process: removing duplicate alarms of the same device, location, and type within 1 minute; automatically completing alarms with missing location coordinates by associating them with the device ledger using the device ID; filtering out abnormal data that exceeds the port's geographical boundaries, has incorrect time format, or has a data field missing rate exceeding 50%; and storing the cleaned standardized data in a time-series database, supporting fast retrieval by time, region, and device type.
4. The method for processing alarm data and generating port security reports based on intelligent agent collaboration as described in any one of claims 1-3, characterized in that, The data access agent is responsible for device connection management, data acquisition, and format verification, employing a multi-threaded concurrent processing mechanism to support simultaneous access from 1000+ devices. The spatiotemporal correlation agent analyzes the temporal continuity and spatial proximity of alarm events based on a spatiotemporal indexing algorithm. The multi-source verification agent integrates image recognition and sensor data fusion algorithms to achieve cross-validation of multimodal data. The risk assessment agent uses a rule base and random forest model to determine risk levels and generate handling suggestions. The voting agent uses a weighted voting mechanism to output alarm authenticity results. The report generation agent has built-in standardized report templates, supports automatic rendering in PDF / Word formats, and integrates data visualization components. The task scheduling agent is based on a distributed task scheduling framework and dynamically allocates tasks according to alarm priority and regional load. The task scheduling agent allocates tasks according to the following rules: alarm events in the same region are assigned to the same group of agents; alarms in critical regions trigger parallel processing by the agent cluster, while alarms in ordinary regions are processed in queue order.
5. The method for processing alarm data and generating port security reports based on intelligent agent collaboration as described in claim 4, characterized in that, The spatiotemporal correlation analysis includes: time window analysis and spatial proximity analysis; the time window analysis extracts alarm data in the same area within 10 minutes before and after the alarm occurrence time to determine whether there are consecutively triggered time-series correlation events; the spatial proximity analysis calculates the distance between the alarm location and surrounding devices to determine whether there are spatial correlation events triggered by multiple devices; the correlation results include: "isolated event / time-series correlation event / spatial correlation event" labels and correlation confidence.
6. The method for processing alarm data and generating port security reports based on intelligent agent collaboration as described in claim 5, characterized in that, The comparison and verification include: video verification, sensor data verification, and AIS / GPS data verification; the video verification involves retrieving video clips 30 seconds before and after the alarm time for intrusion and boundary crossing alarms, using the YOLOv8 algorithm to identify the presence of a target, and outputting the target detection confidence score; the sensor data verification involves comparing the heat source signal intensity of infrared sensors at the same location for infrared alarms, and verifying the target trajectory and speed of radar echoes for radar alarms; the AIS / GPS data verification involves associating AIS ship dynamic data for ship-related alarms to determine whether the ship is within the alarm area; the risk levels include: major risk, significant risk, general risk, and low risk; the event labeling includes: responsible area, responsible person for handling, handling suggestions, and estimated handling time.
7. The method for processing alarm data and generating port security reports based on intelligent agent collaboration as described in claim 6, characterized in that, The alarm authenticity results output in S3 will be fed back to the multimodal large model for optimization.
8. The method for processing alarm data and generating port security reports based on intelligent agent collaboration as described in claim 7, characterized in that, The port security report automatically compiles the following core indicators: Basic statistics: total number of alarms, actual number of alarms, suspected number of alarms, false alarms, actual alarm rate, false alarm rate, and closed-loop handling rate; Distribution statistics: alarm distribution in each area, percentage of each type of alarm, and number of alarms at each risk level; Trend statistics: weekly / monthly change in total alarms, trend of high-incidence alarm types, and trend of actual alarm rate; Handling statistics: response time for each shift, number of incidents handled beyond the time limit, and rectification completion rate.
9. The method for processing alarm data and generating port security reports based on intelligent agent collaboration as described in claim 8, characterized in that, The agent cluster also includes backup agents and upgrade agents; the report template supports user customization and modification, and the modifications are automatically synchronized to the report generation agent.
10. A system for intelligent agent-based collaborative alarm data processing and port security report generation, characterized in that, The system comprises, in sequence, a data acquisition and preprocessing module, an agent cluster initialization and task scheduling module, an alarm data verification and authenticity determination module, a port security report automatic generation module, and a report archiving and push module. The data acquisition and preprocessing module acquires port alarm data and preprocesses it. The agent cluster initialization and task scheduling module constructs an agent cluster and initializes and schedules tasks for each agent within the cluster, enabling alarm data processing and content verification. The alarm data verification and authenticity determination module verifies and determines the authenticity of alarm data. The port security report automatic generation module periodically generates port security reports. The report archiving and push module archives the generated port security reports and pushes them to relevant personnel.
Citation Information
Patent Citations
Low-switching-loss power device structure and manufacturing method thereof
CN114582965A
Multi-source alarm information collaborative verification method and system based on cross-modal causal attention
CN121637159A