System and method for providing event-related information

A machine learning model generates textual summaries of surveillance events to enhance situational awareness and decision-making in surveillance systems, addressing inefficiencies in existing systems by providing enriched alarm data.

WO2025213264A1PCT designated stage Publication Date: 2025-10-16GENETEC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CA2025/050517
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-10-31
Filing Date
2025-04-09
Publication Date
2025-10-16

AI Technical Summary

Technical Problem

Surveillance systems face complexity and inefficiency in providing clear, concise, and actionable information to operators due to the large number of devices involved, making it time-consuming to provide situational awareness and informed decision-making.

Method used

A method and system utilizing a machine learning model to generate textual descriptions of events captured in media data, enriching alarm data with scene descriptions before, during, and after alarm triggers, enhancing situational awareness for operators.

Benefits of technology

Enables operators to efficiently gain situational awareness and make informed decisions by providing enriched alarm data summaries, improving response efficiency in surveillance systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CA2025050517_16102025_PF_FP_ABST
    Figure CA2025050517_16102025_PF_FP_ABST
Patent Text Reader

Abstract

A method for providing alarm-related information in a security system comprises obtaining alarm indication(s) associated with alarm(s) triggered at a monitored location, obtaining media data related to the alarm(s), the media data acquired during a period of interest by media device(s) deployed at the monitored location, executing machine learning model (s)to obtain a textual description of event(s) captured in the media data, and outputting the textual description. A method for summarizing data comprises obtaining a data summary request, determining a period of interest associated therewith, identifying events that occurred at the monitored location during the period of interest, obtaining media data related to the events, the media data acquired by the media device(s) during the period of interest, executing machine learning model(s) to obtain, based on the media data, textual descriptions of events, executing the machine learning model(s) to generate summary(ies) based on the textual descriptions, and outputting the summary(ies).
Need to check novelty before this filing date? Find Prior Art

Description

SYSTEM AND METHOD FOR PROVIDING EVENT-RELATED INFORMATIONCross-reference to related applications

[0001] The present application claims the benefit of United States Provisional Patent Application No. 63 / 631 ,709 filed on April 9, 2024, and of United States Provisional Patent Application No. 63 / 714,230 filed on October 31 , 2024, the contents of which are hereby incorporated by reference.Field

[0002] The present disclosure relates generally to physical security and surveillance, and more specifically to providing event-related information in a security system.Background

[0003] A surveillance system is a network of various devices employed to monitor activities and behaviours of persons, vehicles, or the like in a particular area being surveyed. A surveillance system may collect information from a variety of sources, centralize that information, and make the information available to surveillance personnel to aid them in making decisions relating to the safety of persons or other objects within the area being surveilled. A surveillance network may include any suitable number of devices for collecting information, including cameras, microphones, access card readers, and the like, as well as any number of monitors or other interfaces for presenting information to operators of the surveillance system. However, due to the large number of devices involved in the surveillance network, it may prove complex and timeconsuming to provide surveillance personnel with information in a clear, concise, and actionable manner.

[0004] Therefore, there is a need for improvement.Summary

[0005] The following presents a simplified summary of one or more implementations in accordance with aspects of the present disclosure in order to provide a basic understanding of such implementations, without limiting the embodiments presented within the present disclosure.

[0006] The present disclosure relates to methods, systems, devices, and computer-readable media for providing an operator of a security system with an overview of event(s) that occurred at a monitored location during a period of interest (e.g., since the operator’s last login into the security system). For this purpose, a machine learning model is provided with media data acquired at the monitored location during the period of interest, and generates a textualdescription of the event(s) captured in the media data. In one embodiment, the media data comprises images captured before, during, and after the triggering of alarm(s), and scene descriptions from before, during, and after the triggering of the alarm(s) are generated based on the media data. The scene descriptions are then used to enrich the alarm data (e.g., alarm listing and timestamp) generated upon the triggering of the alarm(s). This may in turn augment the operator’s ability to efficiently gain situational awareness and make informed decisions in response to event(s).

[0007] In accordance with a broad aspect, there is provided a method for providing alarm-related information in a security system comprising at least one media device deployed at a monitored location. The method comprises obtaining at least one alarm indication associated with one or more alarms triggered at the monitored location, obtaining media data related to the one or more alarms, the media data acquired by the at least one media device during a period of interest, executing at least one machine learning model to obtain a textual description of at least one event captured in the media data, and outputting the textual description.

[0008] In at least one embodiment in accordance with any previous / other embodiment described herein, obtaining the at least one alarm indication comprises receiving, via a user interface, at least one query for information related to the one or more alarms.

[0009] In at least one embodiment in accordance with any previous / other embodiment described herein, obtaining the at least one alarm indication comprises receiving at least one alarm signal from the security system.

[0010] In at least one embodiment in accordance with any previous / other embodiment described herein, the method further comprises querying at least one database with the at least one alarm indication, the at least one database having a plurality of event occurrence records stored therein, identifying, based on the querying, at least one event occurrence record related to the one or more alarms triggered at the monitored location, and obtaining, from the at least one event occurrence record, alarm data associated with the one or more alarms.

[0011] In at least one embodiment in accordance with any previous / other embodiment described herein, obtaining the alarm data comprises obtaining first alarm data associated with an entirety of the one or more alarms triggered at the monitored location, and filtering the first alarm data to obtain second alarm data associated with a subset of the one or more alarms.

[0012] In at least one embodiment in accordance with any previous / other embodiment described herein, the alarm data comprises at least one of a listing of the one or more alarms and a triggering time of each of the one or more alarms.

[0013] In at least one embodiment in accordance with any previous / other embodiment described herein, the alarm data comprises the media data.

[0014] In at least one embodiment in accordance with any previous / other embodiment described herein, obtaining the media data comprises receiving the media data from the at least one media device.

[0015] In at least one embodiment in accordance with any previous / other embodiment described herein, the at least one machine learning model is a large language model (LLM), the LLM trained to receive visual content, to identify one or more objects within the visual content, and to generate a textual output describing the one or more objects.

[0016] In at least one embodiment in accordance with any previous / other embodiment described herein, the method further comprises identifying, based on the querying, at least one first event that occurred at a triggering time of the one or more alarms.

[0017] In at least one embodiment in accordance with any previous / other embodiment described herein, obtaining the media data comprises obtaining at least one first image depicting the at least one first event, and executing the at least one machine learning model comprises providing the at least one first image to the at least one machine learning model, and obtaining a first textual description of the at least one first event from the at least one machine learning model.

[0018] In at least one embodiment in accordance with any previous / other embodiment described herein, the method further comprises identifying, based on the querying, at least one second event that occurred a first time period before the triggering time of the one or more alarms.

[0019] In at least one embodiment in accordance with any previous / other embodiment described herein, obtaining the media data comprises obtaining at least one second image depicting the at least one second event, and executing the at least one machine learning model comprises providing the at least one second image to the at least one machine learning model, and obtaining a second textual description of the at least one second event from the at least one machine learning model.

[0020] In at least one embodiment in accordance with any previous / other embodiment described herein, the method further comprises identifying, based on the querying, at least one third event that occurred a second time period after the triggering time of the one or more alarms.

[0021] In at least one embodiment in accordance with any previous / other embodiment described herein, obtaining the media data comprises obtaining at least one third image depicting the at least one third event, and executing the at least one machine learning model comprises providing the at least one third image to the at least one machine learning model, and obtaining a third textual description of the at least one third event from the at least one machine learning model.

[0022] In at least one embodiment in accordance with any previous / other embodiment described herein, the method further comprises associating the first textual description and at least one of the second textual description and the third textual description with the alarm data to create an enriched alarm dataset.

[0023] In at least one embodiment in accordance with any previous / other embodiment described herein, the enriched alarm dataset comprises, for each of the one or more alarms, a name of the alarm, a timestamp indicative of a triggering time of the alarm, the first textual description, and the at least one of the second textual description and the third textual description.

[0024] In at least one embodiment in accordance with any previous / other embodiment described herein, the at least one machine learning model is trained to receive textual content and to summarize the textual content, the method further comprising providing at least one of the first textual description, the second textual description, and the third textual description to the at least one machine learning model, obtaining, from the at least one machine learning model, a summary of the at least one of the first textual description, the second textual description, and the third textual description, and outputting the summary.

[0025] In accordance with another broad aspect, there is provided a system for providing alarm- related information in a security system comprising at least one media device deployed at a monitored location. The system comprises a processing unit and a non-transitory computer- readable medium having stored thereon program instructions executable by the processing unit for obtaining at least one alarm indication associated with one or more alarms triggered at the monitored location, obtaining media data related to the one or more alarms, the media data acquired by the at least one media device during a period of interest, executing at least onemachine learning model to obtain a textual description of at least one event captured in the media data, and outputting the textual description.

[0026] In accordance with yet another broad aspect, there is provided a non-transitory computer-readable medium having stored thereon program instructions executable by a processor for obtaining at least one alarm indication associated with one or more alarms triggered at a monitored location, obtaining media data related to the one or more alarms, the media data acquired during a period of interest by at least one media device deployed at the monitored location, executing at least one machine learning model to obtain a textual description of at least one event captured in the media data, and outputting the textual description.

[0027] In accordance with yet another broad aspect, there is provided a method for summarizing data in a security system comprising at least one media device deployed at a monitored location. The method comprises obtaining a data summary request, determining a period of interest associated with the data summary request, identifying a plurality of events that occurred at the monitored location during the period of interest, obtaining media data related to the plurality of events, the media data acquired by the at least one media device during the period of interest, executing at least one machine learning model to obtain, based on the media data, a plurality of textual descriptions of the plurality of events, executing the at least one machine learning model to generate at least one summary based on the plurality of textual descriptions, and outputting the at least one summary.

[0028] In at least one embodiment in accordance with any previous / other embodiment described herein, obtaining the data summary request comprises receiving user input indicative of the period of interest.

[0029] In at least one embodiment in accordance with any previous / other embodiment described herein, determining the period of interest comprises retrieving from memory at least one rule indicative of the period of interest.

[0030] In at least one embodiment in accordance with any previous / other embodiment described herein, identifying the plurality of events comprises obtaining an aggregated dataset indicative of the plurality of events.

[0031] In at least one embodiment in accordance with any previous / other embodiment described herein, the aggregated dataset comprises a time series indicative of a count of the plurality of events.

[0032] In at least one embodiment in accordance with any previous / other embodiment described herein, the method further comprises providing the time series to the at least one machine learning model and obtaining, from the at least one machine learning model a textual description of one or more trends associated with the plurality of events.

[0033] In at least one embodiment in accordance with any previous / other embodiment described herein, identifying the plurality of events comprises obtaining a list of the plurality of events and a timestamp for each event.

[0034] In at least one embodiment in accordance with any previous / other embodiment described herein, the method further comprises grouping the plurality of events into one or more activity clusters, the media data being obtained based on the one or more activity clusters.

[0035] In at least one embodiment in accordance with any previous / other embodiment described herein, obtaining the media data comprises obtaining a video frame for each of the one or more activity clusters.

[0036] In at least one embodiment in accordance with any previous / other embodiment described herein, obtaining the media data comprises retrieving the media data from at least one database.

[0037] In at least one embodiment in accordance with any previous / other embodiment described herein, obtaining the media data comprises receiving the media data from the at least one media device.

[0038] In at least one embodiment in accordance with any previous / other embodiment described herein, obtaining the media data comprises obtaining images depicting at least one first event, at least one second event, and / or at least one third event that respectively occurred during, before, and / or after a triggering time of one or more alarms, and executing the at least one machine learning model to obtain the plurality of textual descriptions of the plurality of events comprises executing a large language model (LLM) to obtain a first description of the at least one first event, a second description of the at least one second event, and / or a third description of the at least one third event.

[0039] In at least one embodiment in accordance with any previous / other embodiment described herein, the at least one media device comprises a plurality of media devices, and the at least one machine learning model is executed to generate the at least one summary comprising a plurality of first summaries, each first summary generated based on the media data acquired by a respective one of the plurality of media devices.

[0040] In at least one embodiment in accordance with any previous / other embodiment described herein, the method further comprises determining a grouping of the plurality of media devices, and executing the at least one machine learning model to combine, based on the grouping, the plurality of first summaries into a second summary.

[0041] In at least one embodiment in accordance with any previous / other embodiment described herein, the grouping comprises a plurality of grouping levels each having at least one subset of the plurality of media devices associated therewith, and the at least one machine learning model is executed to combine, for each of the plurality of grouping levels, the first summaries associated with the at least one subset of devices into a third summary, thereby obtaining a plurality of third summaries, and to iteratively combine the plurality of third summaries into the second summary.

[0042] In at least one embodiment in accordance with any previous / other embodiment described herein, the method further comprises receiving user input indicative of the grouping of the plurality of media devices.

[0043] In at least one embodiment in accordance with any previous / other embodiment described herein, the method further comprises identifying a level of interest associated with each media device, the grouping being determined based on the level of interest.

[0044] In at least one embodiment in accordance with any previous / other embodiment described herein, the level of interest is identified based on topological data indicative of a configuration of the monitored location having the plurality of media devices deployed thereat.

[0045] In at least one embodiment in accordance with any previous / other embodiment described herein, the level of interest associated with each media device is identified based on at least one of an identifier, a type, a configuration, and a geolocation of the media device.

[0046] In at least one embodiment in accordance with any previous / other embodiment described herein, the level of interest associated with each media device is identified based on the media data acquired by the media device.

[0047] In accordance with yet another broad aspect, there is provided a system for summarizing data in a security system comprising at least one media device deployed at a monitored location. The system comprises a processing unit and a non-transitory computer-readable medium having stored thereon program instructions executable by the processing unit for obtaining a data summary request, determining a period of interest associated with the data summary request, identifying a plurality of events that occurred at the monitored location during the period of interest, obtaining media data related to the plurality of events, the media data acquired by the at least one media device during the period of interest, executing at least one machine learning model to obtain, based on the media data, a plurality of textual descriptions of the plurality of events, executing the at least one machine learning model to generate at least one summary based on the plurality of textual descriptions, and outputting the at least one summary.

[0048] In accordance with yet another broad aspect, there is provided a non-transitory computer-readable medium having stored thereon program instructions executable by a processor for obtaining a data summary request, determining a period of interest associated with the data summary request, identifying a plurality of events that occurred at a monitored location during the period of interest, obtaining media data related to the plurality of events, the media data acquired during the period of interest by at least one media device deployed at the monitored location, executing at least one machine learning model to obtain, based on the media data, a plurality of textual descriptions of the plurality of events, executing the at least one machine learning model to generate at least one summary based on the plurality of textual descriptions, and outputting the at least one summary.Brief Description of the Drawings

[0049] For a more complete understanding of the present disclosure, reference is now made to the accompanying drawings. The following brief descriptions of the drawings should not be considered limiting in any fashion.

[0050] Fig. 1 is a block diagram of an example surveillance system, in accordance with one embodiment;

[0051] Fig. 2A is a block diagram of the event information unit of Fig. 1 , in accordance with one embodiment;

[0052] Fig. 2B is a block diagram detailing the event information unit of Fig. 2A, in accordance with one embodiment;

[0053] Fig. 2C is a schematic diagram of a hierarchical grouping ofthe electronic devices of Fig. 1 , in accordance with one embodiment;

[0054] Fig. 2D is an example of a briefing summary generated based on the hierarchical grouping of Fig. 2C, in accordance with one embodiment;

[0055] Fig. 3A and Fig. 3B are examples of a graphical user interface generated by the event information system of Fig. 1 , in accordance with one embodiment;

[0056] Fig. 4A is a flowchart of an example method for providing alarm-related information, in accordance with one embodiment;

[0057] Fig. 4B is a flowchart of an example method for summarizing data, in accordance with one embodiment; and

[0058] Fig. 5 is a block diagram of an example computing device, in accordance with one embodiment.

[0059] It will be noted that throughout the appended drawings that like features are identified by like reference numerals.Detailed Description

[0060] The present disclosure relates to, inter alia, methods, systems, devices, and computer- readable media for providing alarm-related information in a surveillance system. In one embodiment, the systems and methods described herein may be used to assist in surveillance shift handovers, where an operator of a surveillance system (e.g., an area monitoring system) may be provided with information about what happened at a monitored location since their last shift. The system and methods described herein may thus provide the operator with situational awareness so the operator can efficiently prepare for their next shift. It should however be understood that the systems and methods described herein may be used for a variety of applications.

[0061] Fig. 1 illustrates an example surveillance system 100. The system 100 may be an area monitoring system, such as the one described in U.S. Patent No. 10,885,066, the contents of which are hereby incorporated by reference. The system 100 comprises one or more electronic devices 101 disposed at various locations within a geographical area. The one or more electronic devices 101 are used to monitor objects, events, places, and / or people of interest within the geographical area and to generate data accordingly. As a result of such monitoring, the devices 101 may generate media streams, which may include image and / or video data (e.g., meta-data, compressed video data, and / or uncompressed video data) and / or audio data. The media streams may be provided in real-time or non-real-time. Examples of the one or more electronic devices 101 include, but are not limited to, cameras (e.g., digital video cameras, Pan Tilt Zoom or PTZ cameras, etc.) 102i , 1022, ... , 102N, video and / or audio encoders connected to analog device(s) or appliance(s), audio microphones, radars, components of access control systems also referred to herein as “access control devices” (e.g., access card readers), door stations, intercoms, sensors, license plate recognition (LPR) devices, Internet of Things (loT) devices (e.g., automatic lights, air quality monitors, etc.), and the like. It should be understood that any suitable number of devices 101 may apply. When the system 100 comprises several devices 101 , these may be located in close proximity to one another, for instance in the same building or on the same city block, or they may be remote from one another, for instance, located in different parts of the same city or in different cities altogether. Embodiments involving clusters of devices 101 may also be considered, where devices 101 belonging to one of a number of clusters may be geographically proximate to one another while the clusters themselves may be remote from one another.

[0062] Event(s) of interest may be associated with data acquired by the devices 101 (e.g., video feed(s) captured by the cameras 102i, 1022, .... 102N) and stored in one or more data sources (e.g., databases) 108, as “occurrence records” (also referred to herein as “event occurrence records”). As used herein, the term “occurrence record” refers to information indicative of an event stored or provided by a data source and that may be accessed or obtained from the data source. The data source may be or may comprise a database that stores occurrence records. The occurrence record has an occurrence record type (indicative of the nature or type of the occurrence record), and may have at least one time parameter (i.e. a parameter specifying time, such as a timestamp, a time interval, or a period of time) and may have at least one geographical parameter (i.e. a location, such as Global Positioning System (GPS) coordinates, a location range or distance, an area defined by a set of coordinates, or a geographical label such as a room name). The occurrence record may have other metadata and data associated with additionalparameters. The data structure of the occurrence record may depend upon the configuration of the data source and / or database in which the occurrence record is stored. Examples of occurrence records are surveillance video analytics, license plate reads associated with a time and geographical parameter, the identity of a registered criminal with a location of the criminal, 911 call events or computer-aided dispatch (CAD) events with a time parameter, geographical parameter, a narrative and / or a priority value, a gunshot event associated with the picking up of a sound that is identified to be a gunshot having a time parameter, a geographical parameter and the identification of the firearm, a traffic accident event with a time parameter and a location parameter, etc.

[0063] Still referring to Fig. 1 , the electronic devices 101 are communicatively coupled, over a network 104, to an event information unit 106 which is in communication with the one or more data sources 108. The network 104 may comprise any suitable network including, but not limited to, a Personal Area Network (PAN), Local Area Network (LAN), Wireless Local Area Network (WLAN), Metropolitan Area Network (MAN), or Wide Area Network (WAN), or combinations thereof. The event information unit 106 may store or archive data from the devices 101 (e.g., in the memory 114, in one or more of the data sources 108, etc.).

[0064] The event information unit 106 may be a server-based system in communication with one or multiple client devices 110 that may, in some embodiments, also be configured to access the network 104. The event information unit 106 is illustratively configured to obtain data related to event(s) of interest from the devices 101 and may store the data (e.g., in the data source(s) 108, as one or more event occurrence records). As will be discussed further below, the event information unit 106 is also configured to transmit the data (e.g., video feeds) obtained from the devices 101 , along with any additional relevant information that may be retrieved from the data source(s) 108, to the one or more client devices 110 for presentation on a graphical user interface (GUI). The event information unit 106 may be internal or “on-site”, located in close proximity to the client device 110, for instance in the same building, or may be external or “off-site”, located remotely from the client device 110, for instance in a remote data center. The event information unit 106 may be a cloud-based system.

[0065] The event information unit 106 has at least one processor 112, memory 114, and at least one input / output (I / O) interface 116 for communication with the one or more data sources 108, and / or an I / O interface 118 of the client device 110. The one or more data sources 108 may be one or more external database(s), one or more external systems, for example, having one ormore databases, that are accessible via Application Programming Interface (API) calls, and / or one or more local databases that are part of the event information unit 106.

[0066] The processor 112 may be a general-purpose programmable processor. In the example of Fig. 1 , the processor 112 is shown as being unitary, but the processor 112 may also be multicore, or distributed (e.g., a multi-processor).

[0067] The computer readable memory 114 stores program instructions and data used by the processor 112. The computer readable memory 114 may also store locally the data obtained from the electronic devices 101 , acting as a local database. The memory 114 may also store information regarding the data source(s) 108 that are accessible by the event information unit 106, such as the identity of the data source(s) 108, the configuration type of the data source(s) 108, and the like. The computer readable memory 1 14, though shown as unitary for simplicity in the example of Fig. 1 , may comprise multiple memory modules and / or caching. In particular, the memory 114 may comprise several layers of memory such as a hard drive, external drive (e g., SD card storage) or the like and a faster and smaller Random Access Memory (RAM) module. The RAM module may store data and / or program code currently being, recently being or soon to be processed by the processor 112 as well as cache data and / or program code from a hard drive. A hard drive may store program code and be accessed to retrieve such code for execution by the processor 112 and may be accessed by the processor 1 12 to store and access data. The memory 1 14 may have a recycling architecture where older data files are deleted when the memory 114 is full or near being full, or after the older data files have been stored in memory 114 for a certain time.

[0068] The I / O interface(s) 116 is in communication with the processor 112. The I / O interface^) 1 16 may comprise a network interface and may be a wired or wireless interface for establishing a remote connection with, for example, a remote server, an external data source 108, the client device 110, etc. For instance, the I / O interface(s) 1 16 may be an Ethernet port, a WAN port, a TCP port, etc.

[0069] The processor 1 12, the memory 114 and the I / O interface(s) 116 may be linked via bus connections.

[0070] The data source(s) 108 may be one or more remote server(s) comprising one or more databases. A data source 108, and in particular a database, may contain occurrence records and any other relevant information.

[0071] In some examples, the event information unit 106 may have a local database stored, e.g., in memory 114, that contains occurrence records and any other relevant information.

[0072] The client device 110 may be a remote computing device (i.e. , client). One or more client devices 110 may be provided, in close proximity to one another, for instance located in the same office or data center, or remote from one another, for instance located in different offices and data centers dispersed across the same city or in different cities altogether.

[0073] The client device 110 is in communication with the I / O interface(s) 1 16 of the event information unit 106. The client device 110 has a processor 120, a memory 122, I / O interface(s) 1 18 that may be linked via bus connections. The client device 110 may have (or be connect to) any suitable I / O device(s) 124, for example, such as a keyboard, a mouse, a touchscreen, etc. The client device 110 may be a desktop computer, a laptop, a smartphone, a tablet, etc. The client device 110 has (or is connect to) a display 126 (e.g., a screen, a tactile display, etc.). The processor 120, the memory 122 and the I / O interface^) 118 may be similar to the processor 112, the memory 114 and the I / O interface(s) 116, respectively.

[0074] A client application program may be stored in memory of the client device 1 10 that is associated with the event information unit 106, the client application program providing the user with an interface to interact with the event information unit 106.

[0075] In some embodiments, the event information unit 106 may include at least one client device 110, where, for instance, the connection between the event information unit 106 and the client device 110 may be a wired connection. In some embodiments, the functionality of the event information unit 106 and the client device 110 may be implemented on a single computing device.

[0076] The client device 110 may be operated by user(s) to access, view, process, and / or analyze information generated by the event information unit 106. The information may comprise video information, such as the video feed, as well as relevant information obtained from the data source(s) 108. The client device 110 may be configured to launch a web browser or web application that renders a GUI on the display 126. The GUI may be used to display outputs and accept inputs and / or commands from user(s) of the client device 110, as will be described further below.

[0077] The system 100 may comprise a wide variety of different network technologies and protocols. Communication between the electronic devices 101 , event information unit 106, datasource(s) 108, and client device 110 may occur across wired, wireless, or a combination of wired and wireless networks. The system 100 may include any number of networking devices such as routers, modems, gateways, bridges, hubs, switches, and / or repeaters, among other possibilities, communicatively coupled to the electronic devices 101 , event information unit 106, data source(s) 108, client device 110 and / or at any point along network 104.

[0078] For purposes of illustration, reference is made herein to the system 100 being used for security purposes. The system 100 may therefore be referred to herein as a “security system”. However, it should be understood that the system 100 may be used for any other suitable purpose, such as for traffic management and health and safety.

[0079] Referring now to Fig. 2A and Fig. 2B in addition to Fig. 1 , a user (e.g., an operator of the surveillance system 100) may access the event information unit 106 by launching (e.g., via their client device 110) a web application 202 having a briefing module 204 associated therewith. In one embodiment, in response to the user signing into the system 100 (e.g., via their client device 1 10, using an identifier and password for authentication purposes) and launching the web application 202, the briefing module 204 causes a first query (also referred to herein as a request or an alarm indication) 206a for enriched alarm data to be sent to an alarm enrichment unit 208, and a second query (also referred to herein as a request) 206b for a briefing summary to be sent to a summary unit 210. It should however be understood that, in other embodiments, the briefing module 204 may cause a single request to be sent in response to the user signing into the system 100. For example, only one of the alarm enrichment unit 208 and the summary unit 210 may be queried based on the corresponding request 206a or 206b. In the case where both the alarm enrichment unit 208 and the summary unit 210 are queried, the alarm retrieval module 212 may, in some embodiments, be automatically queried by the event information unit 106 at the time an alarm is triggered (i.e. , without being queried by the briefing module 204 in response to the user’s sign in). In this case, the alarm enrichment unit 208 may therefore generate enriched alarm data systematically for all triggered alarms. In response to the user signing into the system 100, the briefing module 204 may then send a single query (e.g., the second query 206b to the summary unit 210) to retrieve both the enriched alarm data and the briefing summary. In other words, the generation of the briefing summary by the summary unit 210 may be automatically triggered by the event information unit 106 at login.

[0080] As used herein, the term “alarm” refers to a signal (e.g., visual and / or audible) that alerts a user to a condition requiring immediate attention. Alarms may be triggered by a component ofthe surveillance system 100 (e.g., by the electronic devices 101) or a third-party system (e.g., a system configured to manage the surveillance system 100), based on certain conditions, which may be defined by the user. For example, alarms may be triggered in response to events detected by the devices 101 , such events including, but not being limited to, motion-based events, video analytics-generated events, glass break events, gas leak events, door opening events, gunshot events, and stolen car events. When an alarm is triggered, a corresponding alarm indication is received at the event information unit 106.

[0081] The alarm enrichment unit 208 is configured to generate enriched alarm data in response to the first query 206a (or systematically for all alarms, as described herein above). For this purpose, an alarm retrieval module 212 retrieves alarm information associated with alarms triggered during a given time period (referred to herein as a “period of interest") and / or for a given geographical area or range (referred to herein as a “range of interest”). The period of interest may vary depending on the application. In one embodiment, the alarm information may be retrieved for all alarms triggered since the user’s last shift (e.g., since the user’s last login into the system 100). The period of interest may encompass a time (also referred to herein as a “triggering time”) at which the alarms are triggered at the monitored location. Other embodiments may apply. The range of interest may also vary depending on the application. For example, the alarm information may be retrieved for all alarms triggered in a given area of the monitored location (e.g., a given area of a building) or triggered by a subset of equipment (e.g., a subset of the devices 101) deployed at the monitored location.

[0082] The alarm information (also referred to herein as “alarm data”) may be retrieved from the data source(s) 108, for instance by querying the data source(s) 108 to obtain the alarm data based on the event occurrence records stored in the data source(s) 108. The retrieved alarm information may comprise details about the triggered alarms, such as a listing of the triggered alarms and a timestamp indicating the time at which each alarm was triggered. The retrieved alarm information may also comprise data acquired by the electronic devices 101 (e.g., images, videos, or other media data captured by the cameras 102i, 102? 102N) during the period of interest, including at the time the alarm was triggered.

[0083] In one embodiment, the alarm retrieval module 212 may be configured to retrieve alarm information associated with all the alarms that were triggered during the period of interest and for the range of interest. The retrieved alarm information may be subsequently filtered, such that a subset of the triggered alarms may be used to generate the enriched alarm data. For example,the filtering process may entail identifying the alarm information that is relevant for a particular user or for a particular application. The filtering process may also entail filtering out (i.e., disregarding) alarm information that was previously considered by the system 100 and / or the user. The alarm information may be filtered in any suitable manner. In one embodiment, the retrieved alarm information may be provided to the user (e.g., output via their client device 110) for filtering. In other embodiments, the alarm retrieval module 212 may be configured to interpret and filterthe alarm information (e.g., based on criteria provided by the user). Other embodiments may apply.

[0084] In some embodiments, the retrieved alarm information is provided to a neighbour frames and events retrieval module 214 which is configured to identify (e.g., based on the event occurrence records stored in the data source(s) 108), for each triggered alarm, the event(s) that occurred within a given timeframe of the alarm triggering time. In one embodiment, the given timeframe starts a predetermined period of time before the alarm was triggered and ends the predetermined period of time after the alarm was triggered. The events that occurred within the predetermined period of time before the alarm was triggered and within the predetermined period of time after the alarm was triggered are referred to herein as “neighbour events”. Any suitable period of time may apply. For example, the predetermined period of time may be defined in terms of seconds or minutes, depending on the application. In one embodiment, events that occurred five (5) minutes before the alarm and five (5) minutes after the alarm was triggered may be considered as neighbour events. Information regarding event(s) having occurred before and / or after the alarm was triggered provides the context of the alarm. In one embodiment, in addition to identifying event(s) that occurred at the time the alarm was triggered, the neighbour frames and events retrieval module 214 is configured to identify event(s) that occurred before the alarm was triggered. In another embodiment, in addition to identifying the event(s) that occurred at the time the alarm was triggered, the neighbour frames and events retrieval module 214 is configured to identify event(s) that occurred after the alarm was triggered. In yet another embodiment, in addition to identifying the event(s) that occurred at the time the alarm was triggered, the neighbour frames and events retrieval module 214 is configured to identify event(s) that occurred both before and after the alarm was triggered.

[0085] Subsequent to identifying the events having occurred within the given timeframe (e.g., before, during, and / or after the triggering of the alarm), the neighbour frames and events retrieval module 214 retrieves (e.g., from the data source(s) 108) data, such as one or more video feeds, associated with (e.g., depicting) the identified events. The data associated with the identifiedevents may have been generated by a single electronic device 101 or multiple electronic devices 101. For instance, video feeds from a single camera 102i, 1022, ... , 1 02N or multiple cameras 102i , 1022, .... 102N may be retrieved. The neighbour frames and events retrieval module 214 may further obtain, based on the retrieved data, a video frame (i.e., one of the multiple still images forming a given video feed) for each event that occurred before, during, and / or after triggering of the alarm. Forthis purpose, the neighbour frames and events retrieval module 214 communicates with a unification search API module 216, which is configured to cause alarms to be triggered from a combination of conditions, and with an event analysis module 218, which is configured to group events to human interpretable actions and trends. The frames are in turn provided to a conversion module 220, which generates an alarm description using a large language model (LLM) module 222.

[0086] Although a single LLM module 222 is illustrated and described herein, it should be understood that multiple LLM modules may apply. In addition, although reference is made herein to the use of LLM module 222, it should be understood that artificial intelligence (Al) or machine learning (ML) model(s) other than LLM may apply. The LLM module 222 may be any suitable type of Al or ML model trained to receive as input images and / or text (whether written or in some other form) and to perform tasks based on the input. In one embodiment, the LLM module 222 is trained to accept visual content (e.g., image data), to identify object(s) within the visual content, and to provide information (e.g., a description in a textual format) about the identified object(s). The LLM module 222 is also trained to accept textual content (e.g., text data) and to provide information about (e.g., a summary of) the received textual content. Training may be performed in any suitable manner. In one embodiment, the LLM module 222 may be trained to provide specific references (discussed further below) such that verification of the summary can be performed by a user. In another embodiment, the LLM module 222 may be trained to not include any value judgment or subjective content (e.g., a person acting suspicious) in the summary. Other embodiments may apply.

[0087] The LLM module 222 may be a general-purpose LLM, such as GPT which is available through Azure OpenAI Service. To this end, the LLM module 222 may comprise an API interface for interfacing with an external LLM service, to transmit thereto prompts (which may include text and other data, such as images) and receive therefrom responses (which may include images) as part of the prompt completion.

[0088] A general-purpose LLM may be used and adapted to the intended purpose by the use of prompt engineering. More specifically, in some examples the prompt may include different messages embodying different roles. For example, there may be a system prompt message which comprises instructions to the LLM regarding how to interpret, summarize, describe and / or report the information that is provided to it, including events, alarm and / or sensor information, and / or images. These instructions may include, but are not limited to, indications of what to look for, what kind of details are important, how much detail to provide, and / or the tone and format of the response. In one example, a system prompt may resemble the following:{ "role": "system", "content": "[system prompt]" }

[0089] where [system prompt] comprises instructions regarding what the job of the LLM is, what kind of data it will be provided, what kind of output it is required to provide, what in particular, if anything, to look out for, what, if anything, to ignore, the tone of the response, the length of the response, the format of the response, and / or the kind of analysis allowed (e.g., exclude any speculation).

[0090] A non-limiting example of a system prompt (referred to herein as an “Alarm Enrichment prompt”) that may be used to generate enriched alarm data is as follows: string systemPromptAct as an Analyst working for a Security Officer inspecting an event happening within an office.The event being analysed is:{{JsonSerializer.Serialize(new { date = TimeZonelnfo. ConvertTime(alarmDate, camerainfo. TimeZone), alarmName, situation = alarmsituation })}}The following events happened around the same time, use them as context to summarize what happened, but do not summarize them:{{{string .Join(neighbourEvents.Select(neighbourEvent ->$"\"{TimeZonelnfo.ConvertTime(neighbourEvent.Eventlnfo.Date, cameralnfo.TimeZone)}\":\"{neighbourEvent.SceneDescription}\""))}}}The following describes the location of the camera:{{camerainfo. Description}}INCLUDE information about the actions taken by peopleINCLUDE That an alarm was raised and the alarm nameEXCLUDE any details about image quality or anything pertaining to image metadata.DO NOT comment security concerns or if the people are aware of the cameraRespond in a professional, formal tone, min . string userPrompt =Summarize what happened.Your reply MUST be short, about one sentence of 40 words, min .

[0091] A non-limiting example of a system prompt (referred to herein as a “Briefing Summary prompt”) that may be used to generate a briefing summary is as follows: string systemPrompt =You are a useful assistant briefing a security officer on what has happened in the previous shift.You have two tasks to perform:Task 1 :Summarise the AlarmsTask 2:You will analyze time series data that tracks the frequency of occurrences within specific intervals, measured in minutes.Your task is to provide a qualitative summary of the patterns in activity observed. Use the location from which the data was collected to add context to your summary.Response Format: Please present your response in the following markdown format:## Alarms:- alarm name (alarm time) : alarm summary## Overview:- Time of Day Category : qualitative summary of the activity trends- Time of Day Category : qualitative summary of the activity trendsGuidelines for Qualitative Summary:- Use clear and formal language that can be understood by a 15-year-old.- Do not use clickbait language- Keep the summary concise, ideally one sentence per time period.- Incorporate the camera location into the summary to provide context.- Avoid speculative language such as "suggesting", "likely", "indicating" and "possibly".- Refrain from using specific numbers from the data. Instead, describe general trends, such as "a noticeable uptick in activity" or "the location experienced minimal activity"Guidelines for Time of Day Categories:- Define time of day categories with descriptive names and their corresponding time ranges (e.g., Early Morning (5 AM - 8 AM), Midday (8 AM - 12 PM), etc ).- Use broad time categories rather than exact timestamps, with no more than four categories to maintain simplicity and clarity.**Note:** The output should not infer or speculate about specific activities or behaviors that may be occurring at the camera location, but rather describe the general patterns of activity. min . string userPrompt =Time series of the number of counts seen per 30 minutes:{{{string .Join(II II trends.Select(trend =>$"\"{TimeZonelnfo.ConvertTime(trend.StartDate, cameralnfo.TimeZone).ToString("yyyy-MM-dd hh:mm tt", Cultureinfo. lnvariantCulture)}\":{trend. Events. Count}"))}}}Camera Location is:{{camerainfo. Description}}List of Alarms:{{{string .Join(II II alarms. Select(alarm =>$"\"{TimeZonelnfo.ConvertTime(alarm.Date, camerainfo. TimeZone) .ToString("yyyy-MM-dd hh:mm tt", Cultureinfo. lnvariantCulture)}\":{JsonSerializer.Serialize(new { name = alarm.AlarmName, description = alarm. Situation })}"))}}}

[0092] It should be understood that the system prompts indicated above are for illustrative purposes only and should not be considered limiting. As such, other system prompts may apply.

[0093] The system prompt may be constructed from template information stored in the memory 1 14. Template information may include different portions of system prompts which the LLM module 222 pieces together based on requirements. These portions, as well as logic elements providing when or how to use them may, be stored as template elements. For instance, in the examples provided above, the Alarm Enrichment prompt may be one template element, and the Briefing Summary prompt may be another template element.

[0094] Additional details and logic elements may be included in template elements. Such additional details may, for example, include, but are not limited to, instructions to include identifier (ID) information of recent badge reads when a camera is related to a badge reader. This can be coupled with logic elements indicating which cameras are related to which badge readers, and, for example, logic providing lists of authorized personnel or a link thereto.

[0095] The LLM module 222 may include logic to piece together template elements based on logic elements in the template elements, optionally in combination with external factors such as time, or current user, or briefing module 204 query. Thus, a template element may include partial or full text of a system prompt, and a template element that is a logical element may define when or how to use that text. In a simple example, a template element comprises the Alarm Enrichment system prompt provided above, and a logical element indicates that this should be used in response to query 206a for enriched alarm data. Likewise, a template element comprises the Briefing Summary system prompt provided above, and a logical element indicates that this should be used in response to query 206b for briefing summary.

[0096] Herein is also provided a system and method to update an alarm enrichment and / or briefing summary system without retraining an Al model. By using template elements for system prompts, the system and method can be updated to account for new information available, such as new video metadata, new video analytics capabilities, or even new sensor types, and to allow the system to act upon them in briefing and alarm enrichment by changing the template elements stored in memory 1 14. Thus, an update method may include a step of accessing memory 114, identifying template elements therein and modifying the template elements, such as by replacing one or more template elements, deleting a template element, or adding a template element. To this end, the system may include an LLM updating module (not shown) to perform this step. The LLM updating module may be prompted by user input or other input. In one embodiment, the LLM updating module may access and display the template elements to a user and receive user input defining the changes. In another embodiment, the LLM updating module may automatically generate new template elements based on input providing available data such as sensor data or analytics data.

[0097] Moreover, the use of template elements for a system prompt also allows the updating of the LLM or Al model used without having to change the rest of the system and method to adapt to it. Specifically, herein is provided a system and method for upgrading the Al model or LLM used. If a new Al model or LLM becomes available, the LLM is provided with new access details.In the case of an LLM-as-a-service, such as Azure OpenAI Service GPT, this involves updating the LLM module 222 API interface to access the new GPT. If needed, e.g., if the new Al model or LLM has new capabilities, the template elements for the system prompt may be updated as well, as described above.

[0098] Still referring to Fig. 2A and Fig. 2B, the conversion module 220 provides the LLM module 222 with the frames from before, during, and / or after triggering of the alarm. The LLM module 222 then extracts from the frames information which is used to generate a first textual description of what is seen in each frame. The generated text is human readable (e.g., sentence-based) and provides a description of the scene depicted in each frame. The descriptions of the scenes from during and at least one of before and after triggering of the alarm are then provided to the conversion module 220, which associates the descriptions with the alarm information to create enriched alarm data (also referred to herein as an “enriched dataset”) which may be used to provide the user with additional context about the triggered alarm. The enriched alarm data may be created for each one of the plurality of cameras 102i , 1022, ... , 102N or for a subset of the cameras 102i, 1022, .... 102N. In one embodiment, an enriched alarm dataset is created for each triggered alarm and comprises a timestamp indicative of a time at which the alarm was triggered, an alarm name or type, and a textual description of the scenes captured by a given camera 102i , 1022 102N during and at least one of before and after triggering of the alarm. The enriched alarm data is then stored (in any suitable data structure) by the conversion module 220 in an enriched alarms database 224.

[0099] The summary unit 210 is configured to generate the briefing summary in response to obtaining a corresponding request (referred to herein as a “data summary request”). The request may be received in any suitable manner (e.g., via a user interface or other suitable input means). In one embodiment, obtaining the request comprises receiving the second query 206b. As used herein, the term “briefing summary” refers to a concise summary of event(s) that occurred (e.g., alarm(s) triggered) during a given period of interest and / or for a given range of interest. While reference is initially made herein to a single briefing summary being generated for (i.e., based on data acquired by) one camera 102i , 1022, .... 102N, it should be understood that a single briefing summary may (alternatively or additionally) be generated for multiple cameras 102i, 1022, .... 102N, as will be described further below.

[0100] A date / time range estimation module 226 is configured to determine the period of interest for which the briefing summary is to be generated. The period of interest may be determined inany suitable manner. In one embodiment, the period of interest may be determined based on input received from the user. For example, a user may provide an input (e.g., using any suitable input means, such as a GUI) indicating the period of interest for which a briefing summary is requested. The data summary request received at the summary unit 210 may comprise the user input indicative of the period of interest. In another embodiment, the period of interest corresponds to the time since the user’s last (i.e., previous) shift and the period of interest is determined (e g., autonomously by the date / time range estimation module 226) based on a user’s profile with the system 100. The user profile may be indicative of data related to the user’s login into the system 100, on the user’s shift pattern, on calendar information for the user, on underlying data trends from the user, and the like. The user profile may be further indicative of user preferences and configuration with the system 100, as well as user personalization defined through any suitable algorithm.

[0101] In other embodiments, the generation of the briefing summary by the summary unit 210 may be automatically triggered by the event information unit 106 at login. In this case, the date / time range estimation module 226 may be configured to automatically determine when the last login for the user occurred and set the period of interest accordingly. The date / time range estimation module 226 may also be configured to automatically determine the period of interest based on the data (e.g., alarm data or other data acquired by the security system 100 for the monitored location) that is to be summarized. In yet other embodiments, rule(s) defining the period for which data is to be summarized may be predefined and pre-programmed into the event information unit 106. Examples of rules defining the period of interest include, but are not limited to, the timeframe spanning the last 24 hours, the timeframe since the user’s last login into the system 100, the timeframe spanning the last two days if the present day (on which the data summary request is received) is a Monday, or the timeframe spanning the last three days if the present date is the day following a public holiday. The predefined rule(s) may, for instance, be stored in the memory 114. The date / time range estimation module 226 may then be configured to retrieve the predefined rule(s) from the memory 114 and to determine the period of interest based on the retrieved rule(s).

[0102] In some embodiments, the summary unit 210 is configured to summarize alarm data, and more particularly enriched alarm data generated by the alarm enrichment unit 208. In this case, the estimated period of interest may be provided to an enriched alarms retrieval module 228, which may be configured to query the enriched alarms database 224 to obtain the enriched alarm data for the estimated period of interest. It should however be understood that the summaryunit 210 may be configured to generate briefing summaries for any suitable event-related data (other than the alarm-related data) which is acquired by the system 100. In particular, the summary unit 210 may be configured to generate a briefing summary in relation to any suitable event of interest that is indicative of an unusual activity at the monitored location (even if the event of interest did not trigger an alarm). Examples of such events include, but are not limited to, the detection of a crowd, the detection of an increasing number of people coming into the monitored site, orthe detection of a faulty device 101 (e.g., a camera that stops recording a video feed). The summary unit 210 may therefore be configured to generate a briefing summary based on any suitable event-related data including, but not limited to, alarm-related data (as described herein), video stream data (e.g. data related to camera events such as object detection and movement detection), access control data (e.g., badge reads, device logs, etc.), and loT device data (e.g., data acquired by air quality sensors, data indicative of light turning on out of hours, etc.).

[0103] The estimated period of interest determined by the date / time range estimation module 226 is further provided to a detected object(s) / event(s) retrieval module 230, which is configured to identify a plurality of events that occurred at the monitored location during the period of interest. The detected object(s) / event(s) retrieval module 230 may then output a list of all events (e.g., alarm-related events or any other suitable events) detected during the period of interest, along with the timestamp for each event. For this purpose, the detected object(s) / event(s) retrieval module 230 may be configured to communicate with the unification search API module 216 in order to identify (e.g., based on the event occurrence records) object(s) and / or event(s) that were detected during the estimated period of interest. The objects and / or events may be detected by one device 101 (e.g., one camera 102i , 1022, ... , 102N) or multiple devices 101 (e.g., multiple cameras 102i , 1022, .... 102N). The object(s) and / or event(s) may also be detected within a predetermined range (e.g., radius or distance) of the location of a given device 101. The unification search API module 216 is then configured to provide the event-related data (e.g., enriched alarm data) associated with detected object(s) and / or event(s) to the summary unit 210 (e.g., to the detected object(s) / event(s) retrieval module 230) for generation of the briefing summary.

[0104] Although reference is made herein to the unification search API module 216 being used to search for detected object(s) and / or event(s) within the data (e.g., video analytics metadata that accompanies video files) that is stored in the system 100, it should be understood that, in other embodiments where no pre-processed events are available (i.e. stored in the system 100), analytics may be performed on on-the-fly to detect object(s) and / or event(s). The analytics may include object detection and object classification. For example, the analytics may comprise avehicle make and model identification or person detection with clothing color or accessory detection. These on-the-fly analytics may apply when a camera as in 102i, 1022, ... , 102N only provides motion detection events but provides no identification of the types of objects which have caused the motion detection.

[0105] In one embodiment, the detected object(s) / event(s) retrieval module 230 is further configured to communicate with a times series obtention module 232 and with a media data obtention module 234. The times series obtention module 232 is configured to obtain, from the event analysis module 218, an aggregated dataset indicative of the events detected during the period of interest. It should however be understood that, in other embodiments, the times series obtention module 232 may be omitted and no aggregate dataset may be provided (i.e., the raw event data obtained at the detected object(s) / event(s) retrieval module 230 may be used to generate the briefing summary). When an aggregated dataset is used, such dataset may be obtained in any suitable manner and provided in any suitable format. In one embodiment, the times series obtention module 232 may be configured to provide the aggregated dataset as a time series for all events detected during the period of interest. In one embodiment, the time series is indicative of the level of occupancy at the monitored location, during the estimated period of interest. As used herein, the term “occupancy” (or “activity”) refers to the use of a given area or space at the monitored location and may include the number of occupants in the given area or space over a given period of time. In particular, the occupancy relates to events captured on any device configured to count objects such as humans, vehicles, and the like. The counting performed by such devices may be used to approximate given objects at a given time, thus providing information about the level of occupancy. In other embodiments, the occupancy may also include the trajectory of occupants, the presence state, or the like.

[0106] In one embodiment, the times series obtention module 232 is configured to separate the estimated period of interest into a number of subperiods (or time windows) such that the time series represents a count of object(s) and / or event(s) detected during each subperiod. Any suitable subperiod may apply and the object(s) and / or event(s) may be detected (and the count provided) using any suitable device or means configured to provide a measure of occupancy in a given area. Examples include, but are not limited to, forensic cameras and access control devices. For instance, the time series may indicate the number of people going through the entrance of a building (e.g., based on the number of badges scanned at the entrance) every thirty (30) minutes.

[0107] By way of a non-limiting example, the time series may be structured as follows (for a single camera 102i , 1022, ••• , 102N):{‘2024-02-15 06:00 AM’: 0, ‘2024-02-15 06:30 AM’: 0, ‘2024-02-15 07:00 AM’: 0, ‘2024-02-15 07:30 AM’: 0, ‘2024-02-15 08:00 AM’: 138, ‘2024-02-15 08:30 AM’: 527, ... }

[0108] The media data obtention module 234 is configured to obtain media data related to the event(s) and / or object(s) detected by the detected object(s) / event(s) retrieval module 230. The media data may be retrieved from memory (e.g., from one or more event occurrence records stored in the memory 114), received directly from the electronic devices 101 , or obtained in any other suitable manner. In one embodiment, the media data is a video feed captured by a video camera. It should however be understood that any other suitable media data may apply. For example, the summary unit 210 may be configured to obtain other media data including, but not limited to, data acquired by components of access control systems (e.g., access card readers), audio microphones (e.g., audio data), door stations, intercoms, sensors, license plate recognition (LPR) devices, Internet of Things (loT) devices, and the like.

[0109] In one embodiment, the media data obtention module 234 is configured to determine, given an alarm for instance, which events should be considered in the briefing summary. In particular, the media data obtention module 234 may be configured to obtain, from a video scene API module 236, frames for activity clusters detected during the estimated period of interest. For this purpose, the media data obtention module 234 may be configured to group the detected object(s) and / or event(s) retrieved by the detected object(s) / event(s) retrieval module 230 into clusters based on the activity associated with the detected object(s) and / or event(s). The activity clusters may then be provided to the video scene API module 236 which obtains (e.g., retrieves from the data source(s) 108) media data, such as one or more video feeds, for the event(s) associated with each activity cluster. The media data obtention module 234 may then obtain, based on the retrieved data (e.g., the video feeds), a frame for each activity cluster. The frames are then used to generate the briefing summary.

[0110] In one embodiment, the occupancy time series obtained by the time series obtention module 232 and the media data (e.g., clustered events frames) obtained by the media data obtention module 234, along with the enriched alarm data retrieved from the enriched alarms database 224, are sent to a conversion module 238. The conversion module 238 then providesthe enriched alarm data, the occupancy time series, and the clustered events frames to the LLM module 222 for generation of the briefing summary.

[0111] In one embodiment, the conversion module 238 is configured to obtain contextual information about the device(s) 101 which detected the object(s) / event(s) that occurred during the estimated period of interest. For example, the conversion module 238 may be configured to obtain information about the type of the device(s) 101 (e.g., “video camera”), the location within the monitored site (e.g., “lobby”, “tradeshow”, “door number 1 ”) where the media data was captured, the geolocation (e.g., GPS coordinates) of the device(s) 101 , and / or the status (e.g., online, offline, etc.) of the device(s) 101. The information about the device(s) 101 may be obtained based on any suitable data or parameter related to the device(s) 101 including, but not limited to, the configuration of the device(s) 101 and the configuration (e.g., topological information) of the monitored site where the device(s) 101 are deployed. The information about the device(s) 101 may alternatively or additionally be obtained based on the media data. The information may be obtained per device 101 and / or per area of the monitored site.

[0112] Once obtained, the information about the device(s) 101 may be used to generate (e.g., using the LLM module 222) device descriptions, which are subsequently used to generate the briefing summary. In some embodiments, the device descriptions may be generated automatically (e.g., during enrolment of the device(s) 101) and updated on a periodic basis (e.g., every three (3) or six (6) months or at any other suitable time interval), as part of the maintenance of the device(s) 101. As used herein, the term “device description” refers to a textual description including, but not limited to, a type of device, a location of the device, and / or an orientation of the device. A non-limiting example of device description is: “East-facing PTZ camera in the front lobby".

[0113] The LLM module 222 is configured to generate a second textual description (i.e., the briefing summary) summarizing the data received from the conversion module 238. In one embodiment, the second description is based on the enriched alarm data (and on the device description if available) and provides a concise summary of the alarms triggered during the time period of interest (e.g., since the user’s last shift). In this case, the LLM module 222 is configured to generate a summary of the descriptions of the scenes that occurred during and at least one of before and after triggering of the alarm (as obtained from the enriched alarm data). For events other than alarms, the LLM module 222 is configured to generate a summary of the various descriptions of the different scenes depicted in the media data received from the conversionmodule 238. The LLM module 222 may be configured to generate the briefing summary for all events (e.g., triggered alarms) that occurred at the monitored location or fora subset ofthe events. The LLM module 222 may be further configured to generate the briefing summary for data acquired by a single electronic device 101 or for data acquired by multiple electronic device(s) 101 (e.g., a subset of video cameras) deployed at the monitored location. When the briefing summary is generated for a single electronic device 101 , the electronic device 101 is selected based on any suitable criteria. In one embodiment, the electronic device 101 is selected based on a level of interest associated therewith, where the briefing summary may, for instance, be generated for one (or more) predefined camera(s) as in 102i, 1022, .... 102N considered to be highly sensitive. The briefing summary may alternatively be generated for all devices 101 and the results may be compiled together, optionally returning the results to the LLM module 222 to summarize. The briefing summary may also be generated for all devices 101 and only the most interesting summaries may be output (e.g., presented to a user via their client device 110), for instance by filtering for certain types of events and / or alarms, or by returning the list of devices 101 to the LLM module 222 with system prompt instructions defining the manner in which to select interest ones of the devices 101. Other embodiments may apply.

[0114] In some embodiments, the summary unit 210 may be configured to aggregate the data acquired by the multiple electronic device(s) 101 in order to generate a briefing summary for multiple devices 101. For this purpose, in a first phase, the summary unit 210 (i.e., the LLM module 222) may be configured to generate a briefing summary (referred to herein as an “individual device report”) for each electronic device 101. Each individual device report may be generated in the manner described herein above (e.g., based on the enriched alarm data, the occupancy time series, the clustered events frames, the device descriptions if available, or any other suitable event-related data). Each individual device report is indicative of the event(s) detected based on the media data acquired by a respective electronic device 101 . The individual device repots may be stored (e.g., in the memory 114, in one or more of the data sources 108, etc.), either permanently or temporarily, for subsequent use. In a second phase, the summary unit 210 may be configured to generate one or more further summaries (each referred to herein as a “device report summary”) of the individual device reports. The device report summaries may be used to facilitate user interactions. In particular, the summary unit 210 may be configured to generate, based on a given grouping (also referred to herein as a “clustering”) of the electronic device(s) 101 , a device report summary of the individual device reports generated (in the firstphase) for the device(s) 101 at each layer of the grouping. The overall briefing summary is then generated based on the device report summaries and output to the user.

[0115] In some embodiments, the grouping of the electronic device(s) 101 may be defined by the user and provided as an input to the summary unit 210. In other embodiments, the summary unit 210 may be configured to determine the grouping of the electronic device(s) 101 based on any suitable parameters) and using any suitable technique and to output the grouping as determined to the user (e.g., via the display 126 on their client device 1 10) for validation purposes. For example, the electronic device(s) 101 may be grouped according to the level of interest associated therewith. Electronic device(s) 101 that are deemed of interest (e.g., have a level of interest above a predetermined threshold) may form a first group based on which the briefing summary is generated, while electronic device(s) 101 deemed not to be of interest may form a second group which is not considered to generate the briefing summary. The summary unit 210 may be configured to identify, based on one or more parameters, selected ones of the electronic device(s) 101 that are deemed to be of interest. Any suitable parameter may be used including, but not limited to, the configuration of the monitored location (e.g., topological data, as described further below), the configuration of the device(s) 101 , and the user’s profile. For example, device(s) 101 of interest may be determined based on the type of information that a given user is seeking to obtain a briefing summary for (e.g., based on user preferences or search history, as indicated in the user’s profile). In another example, device(s) 101 which monitor high value asset(s) or are positioned at given locations or within given areas of the monitored site (e.g., at entry or exit points), as indicated in the location topological information, may be deemed to be of interest. In order to generate the briefing summary for multiple electronic device(s) 101 , the summary unit 210 may be further configured to filter the data (e.g., alarm data) generated by the electronic device(s) 101 based on whether the data is of relevance and / or indicative of unexpected trends (making the data and associated electronic device(s) 101 of interest). For example, alarm data indicative of unusual events (e.g., group formation or sudden egress) may be deemed of interest and used to generate the briefing summary. In other embodiments, the summary unit 210 may be configured to retrieve (e.g., from memory) previously generated briefing summaries and to determine based thereon relevant data (i.e., data of interest) to be used to generate the current briefing summary.

[0116] In another embodiment, the summary unit 210 may be configured to group (or cluster) the electronic device(s) 101 based on the contextual information obtained from the conversion module 238. The contextual information used by the summary unit 210 may include, but is notlimited to, the name(s) (or unique identifier(s)) of the device(s) 101 , the type(s) of the device(s) 101 , the location within the monitored site where media data was captured, the geolocation (e.g., GPS coordinates) of the device(s) 101 , and topological information associated with the device(s) 101 . In some embodiments, the topological information is pre-defined by the user and is indicative of the configuration (e.g., layout) of the monitored site where the device(s) 101 are deployed, and of the relationships between the device(s) 101. The summary unit 210 may be configured to generate the grouping of device(s) 101 based on the topological information, if available from the conversion module 238. Otherwise, if no topological information is available, the summary unit 210 may be configured to use a combination of other available device information (e.g., as obtained by the conversion module 238) in order to identify one or more groups of device(s) 101 that are within a predetermined distance (i.e., in close proximity) of one another. For example, if the available contextual information comprises the geolocation (e.g., GPS coordinates) of the device(s) 101 , the summary unit 210 may be configured to identify the group(s) of device(s) 101 based on the GPS coordinates. In other words, the device(s) 101 may be grouped based on their geolocation. In another example, if the available contextual information comprises the names (or identifiers) of the device(s) 101 , the summary unit 210 may be configured to group the device(s) 101 based on their names (or identifiers). Other embodiments may apply.

[0117] In one embodiment, the grouping of the device(s) 101 is hierarchical and comprises multiple grouping categories (also referred to herein as “layers”) arranged based on the contextual information associated with the device(s) 101. For example, the layers may be arranged according to the device topological information, with each layer corresponding to a given hierarchy level of the device topology and having one or more subsets (or sub-groups) of device(s) 101 associated therewith. An example of layers determined based on the device topological information includes, but is not limited to, a “Site” layer (grouping all devices 101 deployed at the monitored site into a same subset), a “Building” layer (grouping the device(s) 101 into one or more subsets, according to the building(s) within the monitored site the device(s) 101 are located in), a “Floor” layer (grouping the device(s) 101 into one or more subsets, according to the floor(s) within their given building the device(s) 101 are located in), and a “Room” layer (grouping the device(s) 101 into one or more subsets, according to the room(s) within their given floor the device(s) 101 are located in). It should be understood that other groupings may apply.

[0118] Once determined, the hierarchical grouping of the device(s) 101 may be represented in any suitable manner and this representation may be stored (e.g., in the memory 114, in one or more of the data sources 108, etc.) for subsequent use. For example, the grouping may berepresented as a tree-like structure. The tree may comprise multiple vertices (or nodes) each indicative of a subset of device(s) 101 at a given layer. The vertices may include one or more parent vertices (i.e. vertices provided at a given layer of the tree and from which stem one or more vertices, or “children” vertices, provided at the next layer), one or more children vertices stemming from the parent vertices, a root vertex (i.e. a vertex having no parent vertex and having only one or more children vertices), and one or more terminal leaves (i.e. vertices having no child vertex and having only one or more parent vertices). Each terminal leaf may store the names (or identifiers) of the device(s) 101 associated with the corresponding grouping.

[0119] Fig. 2C illustrates an example embodiment of a tree 250, continuing with the previous example in which the grouping is based on topological information. The tree 250 comprises a “Site” layer 252a, a “Building” layer 252b, a “Floor” layer 252c, and a “Room” layer 252d. A “Site” vertex 254 is provided at the “Site” layer 252a, one or more “Building” vertices as in 256a, 256b (labelled “Building 1 ” and “Building 2”) are provided at the “Building” layer 252b (with each “Building” vertex 256a, 256b representing a given building of the monitored site), one or more “Floor” vertices 258a, 258b (labelled “Floor 1 ” and “Floor 2”) are provided at the “Floor” layer 252c (with each “Floor” vertex representing a given floor of a given building), and one or more “Room” vertices as in 260a, 260b (labelled “Room 1 ” and “Room 2”) are provided at the “Room” layer 252d (with each “Room” vertex 260a, 260b representing a given room of a given floor). The “Site” vertex 254 serves as the root vertex of the tree 250 and the “Room” vertices 260a, 260b serve as the terminal leafs of the tree 250, with each “Room” vertex 260a, 260b storing the names of the device(s) 101 located in the corresponding room. The “Building” vertices 256a, 256b are children vertices of the “Site” vertex254 and are parent vertices to the “Floor” vertices 258a, 258b. The “Floor” vertices 258a, 258b are thus children vertices to the “Building” vertices 256a, 256b and are parent vertices to the “Room” vertices 260a, 260b. It should however be understood that the tree-like representation is for illustrative purposes only and any other suitable representation (e.g., a diagram, graph or the like) of the hierarchical grouping may apply.

[0120] Still referring to Fig. 2C, the summary unit 210 may be configured to generate the overall briefing summary by iteratively combining the individual device reports according to the hierarchical grouping of the device(s) 101 , referencing the supporting information combined at each step as described further below. As used herein, the term “supporting information” refers to the individual device report which has been generated for each individual device 101 that is part of the corresponding grouping of device(s) 101. For example, if an alarm or event is part of the overall briefing summary, the summary unit 210 is configured to provide a link to the particularcamera as in 102i, 1022 102N that the alarm or event originated from. In this manner, the overall briefing summary may be made transparent to the user and available for inspection. In one embodiment and continuing with the previous example illustrated in Fig. 2C, the summary unit 210 may first combine the individual device reports of the device(s) 101 associated with each “Building” vertex 256a, 256b to a generate a first device report summary. The summary unit 210 may then combine the individual device reports of the device(s) 101 associated with each “Floor” vertex 258a, 258b stemming from each “Building” vertex 256a, 256b to generate a second device report summary. The summary unit 210 may finally combine the individual device reports of the device(s) 101 associated with each “Room” vertex 260a, 260b stemming from each “Floor” vertex 258a, 258b to generate a third device report summary. The summary unit 210 combines the first, second, and third device report summaries to obtain the final briefing summary. This results in a briefing summary comprising multiple statements, each statement being indicative of the type of electronic device(s) 101 (e.g., cameras, access control devices, etc.) provided at a given layer (e.g., at the entire “Building 1 ” layer, at the “Floor 1 ” layer of “Building 2”, at the “Floor 2” layer of “Building 2”, etc.) and their number, the number of alarm(s) triggered (if any) at the given layer, a description of detected event(s) (e.g., triggered alarm(s)), and a description of all device activities for the given layer.

[0121] Although reference is made herein to the summary unit 210 being configured to generate intermediate device report summaries (e.g., the first, second, and third device report summaries) at each combination step, it should be understood that this is for illustrative purposes only and that, in other embodiments, the summary unit 210 may not be configured to generate such intermedia device report summaries. For example, a user may configure the summary unit 210 such that summarization at each layer of the device grouping is not required.

[0122] An example briefing summary 270 is provided in Fig. 2D. The example briefing summary 270 is divided into one or more categories 272a, 272b, each category 272a, 272b corresponding to a layer of the device grouping and containing one or more statements 274. In the example of Fig. 2D, the briefing summary 270 comprises the “Building" category 272a (corresponding to the “Building” layer described herein) and the “Floor” category 272b (corresponding to the “Floor” layer described herein), and corresponding statements 274. Examples statements 274 for the “Building 1" category 272a are : “5 Cameras”, “Two access Control Devices”, and “3 Alarms - Camera went offline, crowd detected”. It should however be understood that the example briefing summary 270 shown in Fig. 2D is for illustrative purposes only and that other embodiments may apply.

[0123] In some embodiments, the LLM module 222 may be configured to generate the briefing summary for a limited number (e.g., between two (2) and four (4)) of layers of the grouping, rather than for the totality of layers (e.g., forsake of conciseness). Continuing with the previous example, the LLM module 222 of the summary unit 210 may, for instance, be configured to generate the briefing summary based on the device report summaries generated for device(s) 101 at the “Building” and “Floor” layers only (as shown in Fig. 2D), and to disregard the device report summaries generated at the “Room” layer.

[0124] In one embodiment, each statement of the briefing summary has a reference associated therewith, the reference being used to link the statement to the individual device reports associated with the following layer (i.e., at the next level of detail in the device grouping), as discussed herein above with reference to the supporting information. The user may interact with the reference via the GUI presented on their client device 1 10 (e.g., hover over, select, or click on the reference, using any suitable input means, such as the I / O device(s) 124) in order to be provided with additional information regarding the briefing summary. Furthermore, by interacting with any reference as in 276 associated with the briefing summary as in 270, the user can be provided with supporting evidence used to generate the briefing summary. This is due to the fact that the briefing summary was generated in an iterative manner (as described above), with individual device reports (serving as supporting evidence) being combined at each layer based on the overall device grouping. Continuing with the example of Fig. 2D, a reference 276 is illustratively associated with the “7 Cameras” statement 274 (see “Building 2” category 272a and "Floor 1 " category 272b), where this statement 274 indicates that seven (7) cameras are provided at the monitored location and located in the first floor of the second building. By clicking on the reference 276, the user may be provided with information associated with the “Room” layer, i.e., information indicative of the specific rooms in which the seven (7) cameras are located.

[0125] The briefing summary generated based on the device grouping (as described herein above) may be refined by a user prompting the LLM module 222 with one or more narrowing questions. It should also be understood that, although reference is made herein to the summary unit 210 being configured to generate the briefing summary based on device grouping(s), in other embodiments, the summary unit 210 may be configured to generate the briefing summary based on data acquired by all device(s) 101 (i.e. without generating device report summaries at each layer of the device grouping) and the briefing summary may be refined by the user prompting the LLM module 222 with narrowing question(s). Any suitable narrowing question(s) or prompt(s) may apply. For example, the user may prompt the LLM module 222 about specific data, electronicdevice(s) 101 , event(s) of interest, location(s) within the monitored site, and the like. Examples of questions used to prompt the LLM module 222 include, but are not limited to: “Show me all the alarms”, “Tell me more about the crowd detected in Building 1”, and “Which cameras are in Building 1 ?”. When a device grouping is used to generate the briefing summary for multiple electronic device(s) 101 , the user may also prompt the LLM module 222 to request an alternative grouping of device(s) 101. The LLM module 222 may then be trained to generate a response based on the user’s prompts (i.e., questions and / or requests). In some embodiments, when a question is with regards to specific device(s) 101 , event(s) of interest, location(s) within the monitored site (e.g., “Which cameras are in Building 1?”), the LLM module 222 may be trained to generate a response to the question using the individual device reports for each device 101 and the device report summaries generated at each layer. When a request for a different grouping of device(s) 101 is received from a user, the summary unit 210 may be configured to generate the new device grouping and to generate (e.g., using the trained LLM module 222) a new briefing summary according to the new device grouping.

[0126] In some embodiments, the LLM module 222 is also configured to generate, based on the occupancy time series, a third textual description (also referred to herein as a “trend summary”) summarizing the trends associated with the events having occurred during the time period of interest. This may in turn provide the user with an understanding of the occupancy at the monitored location. The description(s) generated by the summary unit 210 (i.e., the briefing summary and, optionally, the trend summary) may then be output (e.g., to a user) via any suitable means (e.g., rendering the summary on the display 26 of the client device 110, via a user interface). The generated descriptions may be further stored (in any suitable format or data structure) by the conversion module 238 in an overview database 240 for subsequent access. While the enriched alarms database 224 and the overview database 240 are shown as separate entities, it should be understood that this is for illustrative purposes and that a single database may be used.

[0127] Referring now to Fig. 3A, the descriptions generated by the event information unit 106 are retrieved (e.g., from the enriched alarms database 224 and the overview database 240) for presentation on a GUI rendered on the display 126 of the client device 110. Fig. 3A illustrates an example embodiment of such a GUI 300, which may be one application amongst many in a surveillance software platform. The GUI 300 is interactive and configured to receive input from a user and to display output to the user. The GUI 300 renders on a landing page thereof the briefing summary generated by the summary unit (reference 210 of Fig. 2) for the time period of interest.As previously noted, the time period of interest may vary depending to the application. For example, the briefing summary may be generated to span a time period since the user’s last login into the system 100. In the illustrated embodiment, the briefing summary spans a time period ranging from March 5, 2024, at 13:53 CET to March 6, 2024, at 13:53 CET. Other embodiments may apply.

[0128] The GUI 300 comprises several regions 302, 304, 306, 308, and 310, in which various information is displayed. It should be understood that the different regions 302, 304, 306, 308, and 310 may be arranged in any suitable manner on the GUI 300. Region 302 (titled “Alarms”) displays text that summarizes the alarms triggered during the time period of interest, as generated by the summary unit 210 in the manner described above. It can be seen that, in the illustrated embodiment, three (3) alarms were triggered during the period of interest, namely a first alarm (indicative of motion outside of regular hours) was triggered ed at 9:31 PM on March 5, 2024, a second alarm (indicative of motion outside of regular hours) was triggered at 8:01 AM on March 6, 2024, and a third alarm (indicative of detection of a crowd) was triggered at 10:54 AM on March 6, 2024. For each alarm, a sentence provides an explanation of what the alarm relates to.

[0129] Region 304 (titled “Overview") displays text that summarizes the trends in the level of occupancy at the monitored location during the time period of interest, as generated by the summary unit 210 in the manner described above. It can be seen that, in the illustrated embodiment, the time period of interest is separated in four (4) subperiods for which the level of occupancy is summarized, namely afternoon to early evening (2 PM - 7 PM), late evening to night (7 PM - 12 AM), early to late morning (12 AM - 12 PM), and early to mid-afternoon (12 PM - 2 PM). It should however be understood that any suitable subperiods other than the ones illustrated may apply. A sentence summarizes the level of occupancy for each subperiod. Although shown in a bullet format and in chronological order of occurrence of the alarms and events, it should be understood that the descriptions may be presented in the regions 302, 304 in any other suitable format (e.g., in a table format).

[0130] Region 306 provides a timeline of the triggered alarms and the detected events for the period of interest, as summarized in regions 302 and 304 of the GUI 300. A plot 312 is displayed in region 306, the plot 312 providing an indication of the level of occupancy summarized in region 304 of the GUI 300. The plot 312 indicates the number of detected events (vertical or y axis) as a function of time (horizonal or x axis). In the illustrated example, it can be seen that the level of occupancy for March 5, 2024, is consistent between 2 PM and 7 PM with a notable increasearound 4:30 PM, decreases (to nearly zero) after 7 PM, and increases again the next day (March 6, 2024) starting at 7:30 AM with peaks around 10 AM and 12 AM. This corresponds to the textual description displayed in region 304 of the GUI 300.

[0131] Region 306 may further display the number of events occurring at a given point time. This may be achieved by the user interacting with (e.g., hovering over, selecting, or clicking on, using a suitable input device such as a mouse, touchscreen, keyboard, or the like) any data point on the plot 312. As a result, a pop-up element 314 detailing the number of events detected at the time corresponding to the selected data point, as well as the corresponding timestamp, is at least partly overlaid (i.e., superimposed) on the plot 312. In one embodiment, the pop-up element 314 is a text box element having a substantially rectangular shape. It should however be understood that the pop-up element 314 is not limited to a text box element and may have any suitable shape and size. In the illustrated example, the pop-up element 314 is displayed upon the user interacting with the data point on the plot 312 corresponding to 17:59:30 CET on March 5, 2024, the pop-up element 314 indicating that a total of 23 events occurred at that time. In one embodiment, in addition to the pop-up element 314 being displayed in response to the user interacting with a specific data point, the video feed 318 displayed in region 308 (described further below) displays video captured at the specific data point. In this manner, the user can inspect the event(s) having taken place at that specific time. Continuing with the previous example, interaction with the point on the plot 312 corresponding to 17:59:30 CET on March 5, 2024, would result in the video feed 318 displaying video captured at 17:59:30 CET.

[0132] One or more interface elements as in 3161, 3162, 3163, each indicative of a given one of the alarms being triggered, are placed at a position corresponding to a time of occurrence of the alarms. For example, interface element 3161 corresponds to the first triggered alarm listed in region 302 and is placed at a position corresponding to 9:31 PM, interface element 3162 corresponds to the second triggered alarm listed in region 302 and is placed at a position corresponding to 8:01 AM, and interface element 3163 corresponds to the third triggered alarm listed in region 302 and is placed at a position corresponding to 10:54 AM. It should be understood that any suitable interface element 316i, 3162, 316s, such as icons providing a graphical representation of the event, may be used. It should also be understood that, while three (3) interface elements 316i, 3162, 316a are shown in Fig. 3A, the number of interface elements 316i, 3162, 316s may vary depending on the number of alarms triggered.

[0133] Region 308 displays a video feed 318 corresponding to video captured by a given camera 102i, 1022, ... , 102N at the time that a given one of the alarms listed in region 302 and displayed in the timeline presented in region 306 was triggered. In one embodiment, the video feed 318 corresponding to the first triggered alarm is automatically displayed in region 308, except when the video feed 318 jumps to a specific point in time selected by the user (as described above with reference to Fig. 3A). In the illustrated embodiment, region 308 displays the video feed 318 associated with the first alarm (indicated by interface element 3161 in region 306) triggered at 9:31 PM on March 5, 2024, along with the corresponding timestamp.

[0134] A video timeline 320 associated with the video feed 318 may be displayed in region 308 to indicate a current play time of the video feed 318. As understood by those skilled in the art, the video timeline 320 may be displayed in any suitable format. In one embodiment, the video timeline 320 comprises a plurality of repeating major units sub-divided into a plurality of repeating minor units, the major units representing a first time increment (or interval) (e.g., five (5) seconds) and the minor units representing a second time increment (or interval) (e.g., one (1) second) smaller than the first time increment. Other embodiments may apply. A video feed control panel (not shown) may also be displayed in region 308, at any suitable location. The control panel may allow a user to perform (e.g., by interacting with corresponding control icons) control functions associated with the video feed 318 including, but not limited to, pausing or playing, fast- forwarding, rewinding, or saving (e.g., for later viewing or editing) the video feed 318.

[0135] A status 322 of the video feed 318 may also be displayed in region 308. In the illustrated embodiment, the status 322 of the video feed 318 is indicated as “Live”, meaning that the video feed 318 is displayed on the GUI 300 in real-time, as the video is being captured by a given camera 102i , 1022, ... , 102N. It should be understood that, in other embodiments, the video feed may have a status 322 indicated as “Pre-recorded”, meaning that the video feed 318 was previously recorded by the given camera 1021 , 1022, .... 102N and has been retrieved by the event information unit (reference 106 in Fig. 1) from memory (reference 114 in Fig. 1) and / or from the data source(s) (reference 108 in Fig. 1) for display on the GUI 300 after the video has been captured. It should be understood that additional relevant information may be displayed in region 308 including, but not limited to, information indicative of a source of (e.g., the camera 102i , 1022, ... , 102N having captured the video feed 312) being displayed.

[0136] With continued reference to Fig. 3A, region 310 displays a floorplan of the monitored location, the floorplan being indicative of the location of the camera 102i, 1022, .... 102N havingcaptured the video feed 318. Although a floorplan displaying an icon 324 representative of a single camera 102i , 1022, .... 102N is shown in Fig. 3A, it should be understood that the floorplan may alternatively display multiple icons as in 324 where multiple cameras 102i , 1022, ... , 102N are considered.

[0137] Referring now to Fig. 3B in addition to Fig. 3A, there is illustrated a pop-up window 330 that is displayed to provide additional details (i.e., enriched alarm data) about a specific alarm (referred to herein as an “alarm of interest”) as well as information about events detected (e.g., by a camera 102i , 1022, .... 102N) around the time the alarm of interest was triggered. In particular, the pop-up window 330 provides detailed information regarding an alarm of interest selected among the alarms listed in region 302 and displayed in the timeline presented in region 306. In the illustrated example, the pop-up window 330 provides details regarding the second triggered alarm for which a summary was provided in region 302. In other words, the pop-up window 330 expands on the information provided in region 302 in order to allow the user to investigate specifics of the alarm of interest.

[0138] In one embodiment, the pop-up window 330 is displayed in response to the user selecting the alarm of interest by interacting with (e.g., depressing or selecting, using a suitable input device such as a mouse orthe like) the corresponding interface element 3161, 3162, or 3163displayed in region 306. The pop-up window 330 is at least partially superimposed on regions 302, 304, 306, 308, and 310 of the GUI 300.

[0139] As can be seen in Fig. 3B, in the illustrated embodiment, the pop-up window 330 comprises a first region 332, a second region 334, and a third region 336. Region 332 provides an indication of the name and / or type of alarm (e.g ., “Out of hours motion detected event” in the example of Fig. 3B), the time at which the alarm of interest was triggered (e.g., “6 Mar 2024, 08:01 GET” in the example of Fig. 3B) as well as a summary (e.g., a sentence-based description presented in any suitable format, including, but not limited to, in a bullet format) of event(s) that occurred before the triggering of the alarm of interest, at the time of the alarm of interest was triggered, and after the triggering of the alarm of interest. The summary displayed in region 332 corresponds to the enriched alarm data generated by the alarm enrichment unit (reference 208 in Fig. 2) for the alarm of interest. An image 338 captured at the time the alarm of interest was triggered is also displayed in region 332 in order to provide the user with a snapshot of the scene at the time the alarm of interest was triggered.

[0140] Region 334 displays a video feed (along with the corresponding timestamp, timeline, and video status) captured by a camera 102i, 1022, ... , 102N at the time the alarm of interest was triggered. The video feed may be a live or a pre-recorded video feed. The video feed displayed in region 334 spans a time period ranging from a predetermined time period (e.g., a few minutes or seconds) before to a predetermined time period after the triggering of the alarm of interest. In this manner, the user may view scenes corresponding to the description presented in the region 332. For instance, Fig. 3B illustrates an example in which the video feed displayed in region 334 shows a scene recorded afterthe triggering of the alarm, namely a person in a green shirt walking by a cleaning cart. This corresponds to the “After the alarm” description displayed in region 332 of the GUI 300.

[0141] Region 336 displays a plurality of thumbnails 340 representative of events detected around the time the alarm of interest was triggered. Each thumbnail 340 corresponds to an image captured by the camera 102i, 1022 102N, upon detecting the occurrence of an event at a given point in time around the time at which the alarm of interest was triggered. For example, the first thumbnail 340 of Fig. 3B presents an image captured at 7:59:57 AM GET, i.e., two (2) seconds before 8:01 AM CET which is the time at which the alarm of interest was triggered. This first thumbnail 340 shows a person with a backpack walking down a carpeted hallway, which corresponds to the “Before the alarm” description displayed in region 332. Furthermore, region 336 may display an indication of any other alarm(s) that may have been triggered during the period of interest (e.g., before or after the alarm of interest). In the example illustrated in Fig. 3B, the mention “No alarms in the last hour” is indicated in region 336, indicating no alarms other than the alarm of interest were triggered.

[0142] With reference to FIG. 4A, there is illustrated a flowchart of an example method 400 for providing alarm-related information in a security system, such as the system 100 of Fig. 1 . The method 400 may be performed by the event information unit 106, and more particularly the alarm enrichment unit 208 thereof, as described herein above with reference to Fig. 2A. Step 402 comprises obtaining at least one alarm indication associated with one or more alarms triggered at a monitored location. Obtaining the alarm indication may comprise receiving, via a user interface, a query for information related to the one or more alarms. Obtaining the alarm indication may alternatively comprise receiving at least one alarm signal from the security system.

[0143] Step 404 comprises obtaining media data related to the one or more alarms, the media data captured, during a period of interest, by at least one media device deployed at the monitoredlocation. The media data may be received directly from the at least one media device. The media data may alternatively be obtained based on the querying of at least one database (e.g., the data source(s) 108 of Fig. 1) having a plurality of event occurrence records stored therein. In particular, the method 400 may comprise querying the at least one database with the alarm indication, identifying, based on the querying, at least one event occurrence record related to the one or more triggered alarms, and obtaining, from the at least one event occurrence record, alarm data associated with the one or more alarms. The alarm data may comprise the media data. The alarm data may also comprise a listing of the triggered alarms and a triggering time of each alarm. In some embodiments, obtaining the alarm data comprises obtaining (e.g., retrieving from the at least one database) first alarm data associated with an entirety of the triggered alarms, and filtering the first alarm data to obtain second alarm data associated with a subset of the triggered alarms. The filtering may be based on any suitable criteria (e.g., provided by the user), as described herein above.

[0144] Step 406 comprises executing at least one machine learning model to obtain a textual description of at least one event captured in the media data and step 408 comprises outputting the textual description. In one embodiment, the machine learning model is a LLM (e.g., the LLM module 222 of Fig. 2) trained to receive visual content, identify one or more objects within the visual content, and generate output describing the one or more objects. Step 406 may comprise providing to the machine learning model at least one first image depicting at least one first event (identified, based on the querying above, as having occurred at a triggering time of the one or more alarms), and obtaining a first textual description of the at least one first event. Step 406 may also comprise providing to the machine learning model at least one second image depicting at least one second event (identified, based on the querying, as having occurred a first time period before the triggering time of the one or more alarms), and obtaining a second textual description of the at least one second event. Step 406 may further comprise providing to the machine learning model at least one third image depicting at least one third event (identified, based on the querying, as having occurred a second time period after the triggering time of the one or more alarms), and obtaining a third textual description of the at least one third event. The at least one first, second, and third events correspond to the neighbour events described above with reference to Fig. 2. Each of the at least one first, second, and third images may be a frame from a video feed captured by the cameras 102i, 1022, .... 102N of Fig. 1 for the corresponding neighbour event.

[0145] The method 400 may further comprise associating the first textual description and at least one of the second and the third textual description with the alarm data to create an enrichedalarm dataset. The enriched alarm dataset may comprise, for each triggered alarm, a name of the alarm, a timestamp indicative of the triggering time of the alarm, the first textual description, and the at least one of the second and the third textual description.

[0146] In some embodiments, the machine learning model is trained to receive textual content and to summarize the textual content such that the method 400 may also comprise providing the first, second, and / or third textual description to the machine learning model, obtaining a summary of the first, second, and / or third textual description from the machine learning model, and outputting the summary via any suitable means (e.g., rendering the summary on a display of a client device, via a user interface). The summary corresponds to the briefing summary generated by the summary unit 210, as described herein above with reference to Fig. 2. It should be understood that the summary may be created by a different machine learning model than the one executed at step 406.

[0147] With reference to FIG. 4B, there is illustrated a flowchart of an example method 410 for summarizing data in a security system, such as the system 100 of Fig. 1. The method 410 may be performed by the event information unit 106, and more particularly the summary unit 210 thereof, as described herein above with reference to Fig. 2B. Step 412 comprises obtaining a data summary request (e.g., automatically at login or based on a user request), in the manner described above with reference to Fig. 2A and 2B. Step 414 comprises determining a period of interest associated with the data summary request. In some embodiments, obtaining the data summary request at step 412 comprises receiving (e.g., via a user interface) user input indicative of the period of interest, and the period of interest is determined at step 414 based on the user input. In other embodiments, determining the period of interest at step 414 comprises retrieving from memory at least one rule indicative of the period of interest, as described herein above.

[0148] Step 416 comprises identifying a plurality of events that occurred at the monitored location during the period of interest. In some embodiments, identifying the plurality of events at step 416 comprises obtaining an aggregated dataset indicative of the plurality of events. The aggregated dataset may comprise a time series indicative of a count of the plurality of events, as described above. In some embodiments, the time series is provided to the machine learning model and a textual description of one or more trends associated with the plurality of events is obtained from the machine learning model. In other embodiments, identifying the plurality of events at step 416 comprises obtaining a list of the plurality of events and a timestamp for each event.

[0149] Step 418 comprises obtaining media data related to the plurality of events, the media data acquired by the at least one media device during the period of interest. In some embodiments, the plurality of events are grouped into one or more activity clusters and the media data is obtained at step 418 based on the activity cluster(s). Obtaining the media data in this case may comprise obtaining a video frame for each activity cluster. In some embodiments obtaining the media data at step 418 comprises retrieving the media data from at least one database. In other embodiments obtaining the media data at step 418 comprises receiving the media data from the at least one media device.

[0150] Step 420 comprises executing at least one machine learning model to obtain, based on the media data, a plurality of textual descriptions of the plurality of events. In some embodiments, the media data comprises images depicting first, second, and / or third events that respectively occurred during, before, and / or after the triggering time of one or more alarms, as described above, and step 420 comprises executing a LLM (e.g., the LLM module 222 of Fig. 2) to obtain first, second, and / or third descriptions of the events. The machine learning model used at step 420 is trained to receive visual content, identify one or more objects within the visual content, and generate output describing the one or more objects.

[0151] Step 422 comprises executing a machine learning model to generate at least one summary based on the textual descriptions obtained at step 420. The same machine learning model or different machine learning models may be executed at steps 420 and 422. The machine learning model used at step 422 is trained to receive textual content and to summarize the textual content.

[0152] Although steps 420 and 422 are illustrated herein as being separate, it should be understood that both steps may be performed at once (e.g., by the LLM module 222 in one pass). In particular, the machine learning model may be provided with the media data related to the plurality of events (as obtained at step 418), and, optionally, a system prompt / instructions on how to summarize the data, and executed to generate a summary based on the media data.

[0153] Step 424 comprises outputting the at least one summary via any suitable means (e.g., rendering the summary on a display of a client device, via a user interface). The at least one summary corresponds to the briefing summary generated by the summary unit 210, as described herein above with reference to Fig. 2, and may comprise one or more briefing summaries. Indeed, in one embodiment, the at least one summary is a single briefing summary generated for a singleelectronic device (reference 101 in Fig. 1) based on the media data acquired by the electronic device. In another embodiment, the at least one summary comprises multiple individual briefing summaries generated for multiple electronic devices, and an overall briefing summary generated based on the individual briefing summaries (in the manner described herein above).

[0154] With reference to FIG. 5, there is illustrated a schematic diagram of an example computing device 500. As depicted, the computing device 500 includes at least one processing unit 510, a memory 520, and program instructions 530 stored within the memory 520, as well as input and output interfaces (I / O interfaces) 502 and 504, respectively. For simplicity, only one computing device 500 is shown; the various computing devices described herein may be embodied by one or more implementations of the computing device 500, which may be the same or different types of devices. The components of the computing device 500 may be connected in various ways including directly coupled, indirectly coupled via a network, and distributed over a wide geographic area and connected via a network, for instance via a cloud computing implementation.

[0155] The I / O interfaces 502, 504 may include one or more media interfaces, via which removable media or other data sources may be coupled, one or more network interfaces, or any other suitable type of interface. The I / O interfaces 502, 504 of the computing device 500 may additionally, in some embodiments, provide interconnection functionality to one or more input devices, such as a keyboard, mouse, camera, touch screen and a microphone, or with one or more output devices such as a display screen and a speaker, for instance devices via which a user may interact with a server. In embodiments in which the I / O interfaces 502, 504 include one or more network interfaces, the network interface(s) of the computing device 500 may enable the computing device 500 to communicate with other components, to exchange data with other components, to access and connect to network resources, to serve applications, and perform other computing applications by connecting to a network (or multiple networks) capable of carrying data including the Internet, Ethernet, plain old telephone service (POTS) line, public switch telephone network (PSTN), integrated services digital network (ISDN), digital subscriber line (DSL), coaxial cable, fiber optics, satellite, mobile, wireless (e.g. Wi-Fi, WiMAX), SS7 signaling network, fixed line, local area network, wide area network, and others, including any combination of these.

[0156] The processing unit 510 may be, for example, any type of general-purpose microprocessor or microcontroller, a digital signal processing (DSP) processor, an integratedcircuit, a field programmable gate array (FPGA), a reconfigurable processor, a programmable read-only memory (PROM), or any combination thereof. The processing unit 510 may be configured for executing the instructions 530 stored within the memory 520. The memory 520 may include a suitable combination of any type of computer memory that is located either internally or externally such as, for example, random-access memory (RAM), read-only memory (ROM), compact disc read-only memory (CDROM), electro-optical memory, magneto-optical memory, erasable programmable read-only memory (EPROM), and electrically erasable programmable read-only memory (EEPROM), Ferroelectric RAM (FRAM) or the like.

[0157] In certain embodiments, the computing device 500 is operable to register and authenticate users (using a login, unique identifier, and password for example) prior to providing access to applications, a local network, network resources, other networks, and network security devices. The computing device 500 may serve one user or multiple users.

[0158] For example, and without limitation, the computing device 500 may be a server, network appliance, set-top box, embedded device, computer expansion module, personal computer, laptop, personal data assistant, cellular telephone, smartphone device, UMPC tablets, video display terminal, gaming console, electronic reading device, and wireless hypermedia device or any other computing device capable of being configured to carry out the methods and / or implementing the systems described herein.

[0159] The embodiments of the methods, systems, devices, and computer-readable media described herein may be implemented in a combination of both hardware and software. These embodiments may be implemented on programmable computers, each computer including at least one processor, a data storage system (including volatile memory or non-volatile memory or other data storage elements or a combination thereof), and at least one communication interface.

[0160] Program code is applied to input data to perform the functions described herein and to generate output information. The output information is applied to one or more output devices. In some embodiments, the communication interface may be a network communication interface. In embodiments in which elements may be combined, the communication interface may be a software communication interface, such as those for inter-process communication. In still other embodiments, there may be a combination of communication interfaces implemented as hardware, software, and combination thereof.

[0161] Throughout the foregoing discussion, numerous references have been made regarding servers, services, interfaces, portals, platforms, or other systems formed from computing devices. It should be appreciated that the use of such terms is deemed to represent one or more computing devices having at least one processor configured to execute software instructions stored on a computer readable tangible, non-transitory medium. For example, a server can include one or more computers operating as a web server, database server, or other type of computer server in a manner to fulfill described roles, responsibilities, or functions.

[0162] The foregoing discussion provides many example embodiments. Although each embodiment represents a single combination of inventive elements, other examples may include all possible combinations of the disclosed elements. Thus, if one embodiment comprises elements A, B, and C, and a second embodiment comprises elements B and D, other remaining combinations of A, B, C, or D, may also be used.

[0163] The terms “connected” or “coupled to”, as well as any similar terms, may include both direct coupling (in which two elements that are coupled to each other contact each other) and indirect coupling (in which at least one additional element is located between the two elements).

[0164] The use of numerical ranges by endpoints in the present disclosure should be understood as including all numbers within that range (e.g., 1 to 5 includes 1 , 1 .25, 2, 2.5, 3, 3.69, 4, 4.33, 5, etc.). Where a range of values is qualified as being “greater than”, “less than”, etc., of a particular value, that value may or may not be included within the range, as appropriate.

[0165] Any direction or orientation described in the present disclosure, including but not limited to “top”, “bottom", “left”, “right”, “upper”, “lower”, “above”, below”, as well as other directions and orientations, are described herein for clarity, and should be understood in reference to the drawings. These and other similar terms should not be understood as limiting of an actual device or system or of use of the device or system. Many of the devices, articles, or systems described in the present disclosure may be used in a number of suitable directions and orientations.

[0166] Any citation to references in this disclosure and during the prosecution thereof is made out of an abundance of caution. No citation should be construed as an admission that the cited reference qualifies as prior art or comes from an area that is analogous or directly applicable to the present teachings.

[0167] To aid the Patent Office, as well as any readers of any patent issued from this application, in interpreting the claims appended hereto, it is noted that none of the appended claims or elements of the appended claims, as pending or as granted, are intended to invoke 35 U.S.C. 1 12(f) unless the words “means for” or “step for” are explicitly used in the particular claim or claim or claim element.

[0168] The technical solution of embodiments may be in the form of a software product. The software product may be stored in a non-volatile or non-transitory computer-readable storage medium, which can be a compact disk read-only memory (CD-ROM), a USB flash disk, or a removable hard disk. The software product includes a number of instructions that enable a computer device (personal computer, server, or network device) to execute the methods provided by the embodiments.

[0169] The embodiments described herein are implemented by physical computer hardware, including computing devices, servers, receivers, transmitters, processors, memory, displays, and networks. The embodiments described herein provide useful physical machines and particularly configured computer hardware arrangements. The embodiments described herein are directed to electronic machines and methods implemented by electronic machines adapted for processing and transforming electromagnetic signals which represent various types of information. The embodiments described herein pervasively and integrally relate to machines, and their uses; and at least some of the embodiments described herein have no meaning or practical applicability outside their use with computer hardware, machines, and various hardware components. Substituting the physical hardware particularly configured to implement various acts for nonphysical hardware, using mental steps for example, may substantially affect the way the embodiments work. Such computer hardware limitations are clearly essential elements of the embodiments described herein, and they cannot be omitted or substituted for mental means without having a material effect on the operation and structure of the embodiments described herein. The computer hardware is essential to implement the various embodiments described herein and is not merely used to perform steps expeditiously and in an efficient manner.

[0170] Although the embodiments have been described in detail, it should be understood that various changes, substitutions, and alterations can be made herein without departing from the scope as defined by the appended claims.

[0171] Moreover, the scope of the present application is not intended to be limited to the particular embodiments of the process, machine, manufacture, composition of matter, means, methods and steps described in the specification. As one of ordinary skill in the art will readily appreciate from the disclosure of the present invention, processes, machines, manufacture, compositions of matter, means, methods, or steps, presently existing or later to be developed, that perform substantially the same function or achieve substantially the same result as the corresponding embodiments described herein may be utilized. Accordingly, the examples described above and illustrated herein are intended to be examples only, and the appended claims are intended to include within their scope such processes, machines, manufacture, compositions of matter, means, methods, or steps.

[0172] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the relevant technical field, unless explicitly defined otherwise herein. All references to a / an / the element, apparatus, component, means, step, etc., are to be interpreted openly as referring to at least one instance ofthe element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated. The use of “first”, “second”, etc. for different features / components of the present disclosure are only intended to distinguish the features / components from other similar features / components and not to impart any order or hierarchy to the features / components.

Claims

1 . A method for providing alarm-related information in a security system comprising at least one media device deployed at a monitored location, the method comprising: obtaining at least one alarm indication associated with one or more alarms triggered at the monitored location; obtaining media data related to the one or more alarms, the media data acquired by the at least one media device during a period of interest; executing at least one machine learning model to obtain a textual description of at least one event captured in the media data; and outputting the textual description.

2. The method of claim 1 , wherein obtaining the at least one alarm indication comprises receiving, via a user interface, at least one query for information related to the one or more alarms.

3. The method of claim 1 , wherein obtaining the at least one alarm indication comprises receiving at least one alarm signal from the security system.

4. The method of claim 1 , further comprising: querying at least one database with the at least one alarm indication, the at least one database having a plurality of event occurrence records stored therein; identifying, based on the querying, at least one event occurrence record related to the one or more alarms triggered at the monitored location; and obtaining, from the at least one event occurrence record, alarm data associated with the one or more alarms.

5. The method of claim 4, wherein obtaining the alarm data comprises obtaining first alarm data associated with an entirety of the one or more alarms triggered at the monitored location, and filtering the first alarm data to obtain second alarm data associated with a subset of the one or more alarms.

6. The method of claim 4, wherein the alarm data comprises at least one of a listing of the one or more alarms and a triggering time of each of the one or more alarms.

7. The method of claim 4, wherein the alarm data comprises the media data.

8. The method of claim 1 , wherein obtaining the media data comprises receiving the media data from the at least one media device.

9. The method of claim 1 , wherein the at least one machine learning model is a large language model (LLM), the LLM trained to receive visual content, to identify one or more objects within the visual content, and to generate a textual output describing the one or more objects.

10. The method of claim 4, further comprising identifying, based on the querying, at least one first event that occurred at a triggering time of the one or more alarms.

11. The method of claim 10, wherein obtaining the media data comprises obtaining at least one first image depicting the at least one first event, further wherein executing the at least one machine learning model comprises providing the at least one first image to the at least one machine learning model, and obtaining a first textual description of the at least one first event from the at least one machine learning model.

12. The method of claim 11 , further comprising identifying, based on the querying, at least one second event that occurred a first time period before the triggering time of the one or more alarms.

13. The method of claim 12, wherein obtaining the media data comprises obtaining at least one second image depicting the at least one second event, further wherein executing the at least one machine learning model comprises providing the at least one second image to the at least one machine learning model, and obtaining a second textual description of the at least one second event from the at least one machine learning model.

14. The method of claim 13, further comprising identifying, based on the querying, at least one third event that occurred a second time period after the triggering time of the one or more alarms.

15. The method of claim 14, wherein obtaining the media data comprises obtaining at least one third image depicting the at least one third event, further wherein executing the at least one machine learning model comprises providing the at least one third image to the at least one machine learning model, and obtaining a third textual description of the at least one third event from the at least one machine learning model.

16. The method of claim 15, further comprising associating the first textual description and at least one of the second textual description and the third textual description with the alarm data to create an enriched alarm dataset.

17. The method of claim 16, wherein the enriched alarm dataset comprises, for each of the one or more alarms, a name of the alarm, a timestamp indicative of a triggering time of the alarm,the first textual description, and the at least one of the second textual description and the third textual description.

18. The method of claim 15, wherein the at least one machine learning model is trained to receive textual content and to summarize the textual content, further comprising: providing at least one of the first textual description, the second textual description, and the third textual description to the at least one machine learning model; obtaining, from the at least one machine learning model, a summary of the at least one of the first textual description, the second textual description, and the third textual description; and outputting the summary.

19. A system for providing alarm-related information in a security system comprising at least one media device deployed at a monitored location, the system comprising: a processing unit; and a non-transitory computer-readable medium having stored thereon program instructions executable by the processing unit for: obtaining at least one alarm indication associated with one or more alarms triggered at the monitored location; obtaining media data related to the one or more alarms, the media data acquired by the at least one media device during a period of interest; executing at least one machine learning model to obtain a textual description of at least one event captured in the media data; and outputting the textual description.

20. A non-transitory computer-readable medium having stored thereon program instructions executable by a processor for: obtaining at least one alarm indication associated with one or more alarms triggered at a monitored location; obtaining media data related to the one or more alarms, the media data acquired during a period of interest by at least one media device deployed at the monitored location; executing at least one machine learning model to obtain a textual description of at least one event captured in the media data; and outputting the textual description.21 . A method for summarizing data in a security system comprising at least one media device deployed at a monitored location, the method comprising: obtaining a data summary request; determining a period of interest associated with the data summary request; identifying a plurality of events that occurred at the monitored location during the period of interest; obtaining media data related to the plurality of events, the media data acquired by the at least one media device during the period of interest; executing at least one machine learning model to obtain, based on the media data, a plurality of textual descriptions of the plurality of events; executing the at least one machine learning model to generate at least one summary based on the plurality of textual descriptions; and outputting the at least one summary.

22. The method of claim 21 , wherein obtaining the data summary request comprises receiving user input indicative of the period of interest.

23. The method of claim 21 , wherein determining the period of interest comprises retrieving from memory at least one rule indicative of the period of interest.

24. The method of claim 21 , wherein identifying the plurality of events comprises obtaining an aggregated dataset indicative of the plurality of events.

25. The method of claim 24, wherein the aggregated dataset comprises a time series indicative of a count of the plurality of events.

26. The method of claim 25, further comprising providing the time series to the at least one machine learning model and obtaining, from the at least one machine learning model a textual description of one or more trends associated with the plurality of events.

27. The method of claim 21 , wherein identifying the plurality of events comprises obtaining a list of the plurality of events and a timestamp for each event.

28. The method of claim 21 , further comprising grouping the plurality of events into one or more activity clusters, wherein the media data is obtained based on the one or more activity clusters.

29. The method of claim 28, wherein obtaining the media data comprises obtaining a video frame for each of the one or more activity clusters.

30. The method of claim 21 , wherein obtaining the media data comprises retrieving the media data from at least one database.31 . The method of claim 21 , wherein obtaining the media data comprises receiving the media data from the at least one media device.

32. The method of claim 21 , wherein obtaining the media data comprises obtaining images depicting at least one first event, at least one second event, and / or at least one third event that respectively occurred during, before, and / or after a triggering time of one or more alarms, further wherein executing the at least one machine learning model to obtain the plurality of textual descriptions of the plurality of events comprises executing a large language model (LLM) to obtain a first description of the at least one first event, a second description of the at least one second event, and / or a third description of the at least one third event.

33. The method of claim 21 , wherein the at least one media device comprises a plurality of media devices, and further wherein the at least one machine learning model is executed to generate the at least one summary comprising a plurality of first summaries, each first summary generated based on the media data acquired by a respective one of the plurality of media devices.

34. The method of claim 33, further comprising: determining a grouping of the plurality of media devices; and executing the at least one machine learning model to combine, based on the grouping, the plurality of first summaries into a second summary.

35. The method of claim 34, wherein the grouping comprises a plurality of grouping levels each having at least one subset of the plurality of media devices associated therewith, further wherein the at least one machine learning model is executed to combine, for each of the plurality of grouping levels, the first summaries associated with the at least one subset of devices into a third summary, thereby obtaining a plurality of third summaries, and to iteratively combine the plurality of third summaries into the second summary.

36. The method of claim 34, further comprising receiving user input indicative of the grouping of the plurality of media devices.

37. The method of claim 34, further comprising identifying a level of interest associated with each media device, wherein the grouping is determined based on the level of interest.

38. The method of claim 37, wherein the level of interest is identified based on topological data indicative of a configuration of the monitored location having the plurality of media devices deployed thereat.

39. The method of claim 37, wherein the level of interest associated with each media device is identified based on at least one of an identifier, a type, a configuration, and a geolocation of the media device.

40. The method of claim 37, wherein the level of interest associated with each media device is identified based on the media data acquired by the media device.41 . A system for summarizing data in a security system comprising at least one media device deployed at a monitored location, the system comprising: a processing unit; and a non-transitory computer-readable medium having stored thereon program instructions executable by the processing unit for: obtaining a data summary request; determining a period of interest associated with the data summary request; identifying a plurality of events that occurred at the monitored location during the period of interest; obtaining media data related to the plurality of events, the media data acquired by the at least one media device during the period of interest; executing at least one machine learning model to obtain, based on the media data, a plurality of textual descriptions of the plurality of events; executing the at least one machine learning model to generate at least one summary based on the plurality of textual descriptions; and outputting the at least one summary.

42. A non-transitory computer-readable medium having stored thereon program instructions executable by a processor for: obtaining a data summary request; determining a period of interest associated with the data summary request; identifying a plurality of events that occurred at a monitored location during the period of interest; obtaining media data related to the plurality of events, the media data acquired during the period of interest by at least one media device deployed at the monitored location;executing at least one machine learning model to obtain, based on the media data, a plurality of textual descriptions of the plurality of events; executing the at least one machine learning model to generate at least one summary based on the plurality of textual descriptions; and outputting the at least one summary.

Citation Information

Patent Citations

  • Cascade alarm method and device for hydropower station operation management

    CN116704714A

  • Alarm log analysis method and system based on large language model

    CN117544397A

  • Premises security system with dynamic risk evaluation

    US20230021850A1