Vessel trajectory anomaly detection method based on data fusion

WO2026174759A1PCT designated stage Publication Date: 2026-08-27HAINAN NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/119934
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-09
Publication Date
2026-08-27

Smart Images

  • Figure CN2025119934_27082026_PF_FP_ABST
    Figure CN2025119934_27082026_PF_FP_ABST
Patent Text Reader

Abstract

A vessel trajectory anomaly detection method based on data fusion. The method comprises: first, acquiring multi-source heterogeneous data of a vessel trajectory and performing preprocessing to generate a vessel trajectory dataset in a unified format; performing spatio-temporal clustering analysis on the vessel trajectory dataset, extracting a vessel interaction behavior dataset, and calculating dynamic interaction parameters therein; on the basis of the dynamic interaction parameters, detecting potential illegal transshipment behaviors to form an anomalous behavior candidate set; in a vessel-dense area, further analyzing the anomalous behavior candidate set to distinguish normal berthing from suspicious gathering behaviors to form an anomalous gathering behavior subset; in view of the anomalous gathering behavior subset and the dynamic interaction parameters, calculating a gathering duration and the number of vessels, so as to form an anomalous behavior confirmation set; and if the gathering duration in the anomalous behavior confirmation set exceeds a preset threshold, determining a final anomalous behavior. Thus, the detection accuracy and efficiency of illegal transshipment behaviors can be improved, thereby providing reliable technical support for maritime traffic supervision.
Need to check novelty before this filing date? Find Prior Art

Description

A method for detecting anomalies in ship tracks based on data fusion Technical Field

[0001] This invention belongs to the field of ship track monitoring and anomaly detection technology, and particularly relates to a ship track anomaly detection method based on data fusion. Background Technology

[0002] Anomaly detection in ship tracking is a crucial research area for ensuring maritime safety and oversight, with wide applications in maritime law enforcement, port management, and maritime traffic safety. Its core objective is to analyze ship movement trajectories to promptly detect unusual activities such as illegal transshipment and smuggling, thereby maintaining maritime order and security.

[0003] Currently, methods for detecting anomalies in ship tracks largely rely on a single data source or simple trajectory analysis. While these methods can provide basic monitoring capabilities to some extent, they have significant limitations. Many existing solutions struggle to effectively integrate multi-source heterogeneous data, such as radar, satellite, and Automatic Identification System (AIS) data. Because these data come from different sources and have varying formats, information is underutilized, failing to fully leverage the advantages of each data source.

[0004] Furthermore, existing methods often fail to balance real-time performance and accuracy when dealing with complex scenarios. Particularly in densely populated shipping areas, current technologies struggle to accurately distinguish between normal navigation and abnormal aggregation behavior. For instance, multiple vessels approaching each other within a short period and maintaining low-speed parallel navigation for an extended time may indicate illegal transshipment, a behavior that current technologies often cannot accurately identify.

[0005] To address the aforementioned problems in existing technologies, there is an urgent need to propose a method for detecting ship track anomalies based on data fusion. Summary of the Invention

[0006] To address the aforementioned technical problems, this invention provides a method for detecting anomalies in ship tracks based on data fusion, comprising the following steps:

[0007] Acquire multi-source heterogeneous data of ship tracks and preprocess them to generate a ship track dataset in a unified format;

[0008] Spatiotemporal clustering analysis was performed on the ship trajectory dataset to extract the ship interaction behavior dataset;

[0009] Calculate the dynamic interaction parameters in the ship interaction behavior dataset;

[0010] Based on dynamic interactive parameters, potential illegal copying behavior is detected, and a candidate set of abnormal behaviors is formed.

[0011] In areas with high vessel density, further analysis of the candidate set of abnormal behavior is conducted to distinguish between normal berthing and suspicious clustering behavior, forming a subset of abnormal clustering behavior.

[0012] By combining a subset of abnormal clustering behaviors and dynamic interaction parameters, the clustering duration and the number of ships are calculated to form an abnormal behavior confirmation set;

[0013] If the duration of the confirmed abnormal behavior cluster exceeds a preset threshold, an abnormal flight track report is generated to determine the final abnormal behavior.

[0014] Optionally, the process of acquiring multi-source heterogeneous ship trajectory data and preprocessing it to generate a ship trajectory dataset in a unified format includes:

[0015] The initial multi-source dataset is obtained by collecting ship navigation trajectory data based on radar, satellite and automatic identification system, and performing preliminary cleaning.

[0016] The initial multi-source dataset is format-converted and time-synchronized to generate a time-synchronized dataset.

[0017] Based on the time synchronization dataset, if there are missing values, the missing data is filled in using an interpolation algorithm to generate a complete time synchronization dataset.

[0018] Based on the complete time synchronization dataset, the position, speed, and heading information of the ships are extracted to generate a preliminary ship trajectory dataset;

[0019] Based on the initial ship trajectory dataset, anomaly detection and cleaning were performed using a clustering algorithm to obtain an optimized ship trajectory dataset.

[0020] Based on the optimized ship trajectory dataset, data compression technology is used for storage optimization to generate the final unified format ship trajectory dataset.

[0021] Optionally, the process of performing spatiotemporal clustering analysis on the ship trajectory dataset to extract the ship interaction behavior dataset includes:

[0022] Based on a unified format ship trajectory dataset, a spatiotemporal clustering algorithm is used to group the data, generating a set of grouped trajectory data.

[0023] Based on the grouped trajectory data set, the trajectory shape features of each group of ships are extracted to generate a trajectory shape feature set;

[0024] Based on the trajectory shape feature set, the velocity change pattern is determined using velocity pattern analysis.

[0025] Based on the velocity change pattern, if there are outliers, they are filtered using an anomaly detection algorithm to obtain the filtered velocity change pattern.

[0026] Based on the filtered velocity change patterns and trajectory shape feature sets, ship interaction behaviors are extracted to generate a set of ship interaction behaviors.

[0027] Based on the set of ship interaction behaviors, a behavior pattern recognition method is used to analyze and determine the ship interaction behavior patterns.

[0028] Based on the ship interaction behavior patterns, the data is classified and stored using a data grouping structure to obtain a classified ship interaction behavior dataset.

[0029] Optionally, the process of calculating dynamic interaction parameters in the ship interaction behavior dataset includes:

[0030] Based on the ship interaction behavior dataset, the trajectory pairing method is used to group the ships and determine the ship pairing set.

[0031] Based on the ship pairing set, the spatial relationship of each ship pair in the time series is calculated to obtain the trajectory spacing set;

[0032] Based on the trajectory spacing set, if the spacing is less than a preset threshold, the relative position is calculated using vector analysis to obtain a dynamic feature set;

[0033] Based on the dynamic feature set, the speed difference and heading consistency of each pair of ships are extracted to generate a navigation state parameter set;

[0034] Based on the set of navigation state parameters, the K-means clustering algorithm is used for classification to determine the set of interaction behavior patterns;

[0035] Based on the set of interaction behavior patterns, analyze the dynamic feature changes in the time series to obtain a behavior pattern classification set;

[0036] Based on the behavioral pattern classification set, a dynamic interaction parameter set for ship interaction is generated.

[0037] Optionally, the process of detecting potential unauthorized copying behavior based on dynamic interaction parameters and forming a candidate set of abnormal behaviors includes:

[0038] Based on the dynamic interaction parameter set, trajectory data of ships whose distance and speed are below preset thresholds are obtained, and an isolated forest algorithm is used to obtain a candidate set of abnormal behaviors;

[0039] Based on the candidate set of abnormal behaviors, the time series of each pair of ships is obtained, and the relative position change of the trajectory data is calculated to obtain the position change set.

[0040] Based on the set of location changes, if the relative location change is consistently below a preset threshold, then a set of potential abnormal dwelling behaviors is determined through time series analysis.

[0041] Based on the abnormal dwell behavior set, the navigation state of each pair of ships is extracted, and the fluctuation characteristics of speed and heading are calculated to obtain the state fluctuation set;

[0042] Based on the set of state fluctuations, the K-means clustering algorithm is used to classify the abnormal behavior patterns to obtain a set of abnormal behavior patterns.

[0043] Based on the abnormal behavior pattern set, obtain trajectory data within the time window, calculate the interaction frequency between ships, and obtain the interaction frequency set.

[0044] Based on the interaction frequency set, if the interaction frequency of a certain pair of ships is higher than a preset threshold, it is determined through quantitative analysis to be a potential illegal re-transfer behavior, thus obtaining the final abnormal behavior candidate set.

[0045] Optionally, in areas with high vessel density, further analysis of the candidate set of abnormal behavior is conducted to distinguish between normal berthing and suspicious clustering behavior, forming a subset of abnormal clustering behavior. This process includes:

[0046] Based on the candidate set of abnormal behaviors in densely populated areas of ships, the geometric features of each trajectory are calculated to obtain the trajectory geometric feature set;

[0047] Based on the trajectory geometric feature set, density clustering algorithm is used to classify the trajectories, distinguishing between normal berthing behavior and suspicious clustering behavior, and obtaining a preliminary behavior classification set;

[0048] Based on the suspicious clustering behaviors in the preliminary behavior classification set, the trajectory point density of each pair of ships is extracted, the point density distribution characteristics are calculated, and the density distribution feature set is obtained.

[0049] Based on the density distribution feature set, if the point density is consistently higher than a preset threshold, it is determined to be an abnormal clustering behavior through time series analysis, and a subset of abnormal clustering behaviors is obtained.

[0050] Based on the subset of abnormal clustering behavior, obtain the interaction time window for each pair of ships, calculate the trajectory overlap within the time window, and obtain the trajectory overlap set.

[0051] Based on the trajectory overlap set, if the trajectory overlap is higher than a preset threshold, then through quantitative analysis, the abnormal interaction patterns between ships are determined, and the abnormal interaction pattern set is obtained.

[0052] Based on the abnormal interaction pattern set, the navigation state features of the ship are extracted, and the support vector machine algorithm is used to classify the state features to obtain the final abnormal clustering behavior subset.

[0053] Optionally, the process of combining a subset of anomalous clustering behaviors and dynamic interaction parameters to calculate the clustering duration and number of ships, forming an anomalous behavior confirmation set, includes:

[0054] Based on the subset of abnormal clustering behavior, obtain the dynamic interaction parameters of each pair of ships, calculate the interaction frequency and interaction distance, and obtain the interaction feature set;

[0055] Based on the interaction feature set, if the interaction frequency is higher than a preset threshold, the continuity of the interaction is determined through time series analysis to obtain a continuous interaction set.

[0056] Based on the continuous interaction set, the trajectory point density of each pair of ships is extracted, the density distribution characteristics are calculated, and a density feature set is obtained.

[0057] Based on the density feature set, if the point density distribution is consistently higher than a preset threshold, the K-means clustering algorithm is used to classify high-density interaction behaviors and obtain a high-density interaction subset.

[0058] Based on the high-density interaction subset, the navigation state characteristics of the ship are obtained, the state change frequency is calculated, and the state change set is obtained.

[0059] Based on the set of state changes, abnormal interaction patterns between ships are determined through quantitative analysis, resulting in a set of abnormal interaction patterns.

[0060] Based on the set of abnormal interaction patterns, a decision tree algorithm is used to classify the severity of abnormal interaction patterns and obtain an abnormal behavior confirmation set.

[0061] The present invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the method.

[0062] The present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method.

[0063] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method.

[0064] Compared with the prior art, the present invention has the following advantages and technical effects:

[0065] This invention discloses a method that addresses the challenge of accurately distinguishing between normal berthing and suspicious gathering behavior in maritime vessel activity monitoring. By integrating radar, satellite, and automatic identification system (AIS) data, combined with spatiotemporal data preprocessing, cluster analysis, and anomaly detection techniques, it achieves precise identification of vessel interaction behavior. First, this invention standardizes and synchronizes multi-source heterogeneous data to generate a unified format vessel trajectory dataset. Then, a spatiotemporal clustering algorithm is used to extract trajectory geometric features and speed change patterns, calculating distances, speed differences, and heading consistency between trajectories to form a dynamic interaction parameter set. For vessel behavior in dense areas, this invention utilizes a density clustering algorithm to distinguish between normal and suspicious gatherings, and integrates the dynamic interaction parameters to calculate the gathering duration and number of vessels, generating an abnormal behavior confirmation set. If the gathering time exceeds a threshold, an abnormal trajectory report is generated through a trajectory reconstruction module. This invention significantly improves the detection accuracy and efficiency of illegal transshipment, providing reliable technical support for maritime traffic supervision. Attached Figure Description

[0066] The accompanying drawings, which form part of this application, are used to provide a further understanding of this application. The illustrative embodiments and descriptions of this application are used to explain this application and do not constitute an undue limitation of this application. In the drawings:

[0067] Figure 1 is a schematic diagram of the method flow according to an embodiment of the present invention;

[0068] Figure 2 is a schematic diagram of the process for generating an interactive behavior dataset according to an embodiment of the present invention;

[0069] Figure 3 is a schematic diagram of the process for obtaining the final set of abnormal aggregation behaviors according to an embodiment of the present invention. Detailed Implementation

[0070] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. This application will now be described in detail with reference to the accompanying drawings and embodiments.

[0071] It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.

[0072] Example 1

[0073] This embodiment provides a method for detecting ship track anomalies based on data fusion, including the following steps:

[0074] Acquire multi-source heterogeneous data of ship tracks and preprocess them to generate a ship track dataset in a unified format;

[0075] Spatiotemporal clustering analysis was performed on the ship trajectory dataset to extract the ship interaction behavior dataset;

[0076] Calculate the dynamic interaction parameters in the ship interaction behavior dataset;

[0077] Based on dynamic interactive parameters, potential illegal copying behavior is detected, and a candidate set of abnormal behaviors is formed.

[0078] In areas with high vessel density, further analysis of the candidate set of abnormal behavior is conducted to distinguish between normal berthing and suspicious clustering behavior, forming a subset of abnormal clustering behavior.

[0079] By combining a subset of abnormal clustering behaviors and dynamic interaction parameters, the clustering duration and the number of ships are calculated to form an abnormal behavior confirmation set;

[0080] If the duration of the confirmed abnormal behavior cluster exceeds a preset threshold, an abnormal flight track report is generated to determine the final abnormal behavior.

[0081] As shown in Figure 1, as a feasible implementation method, the specific steps include:

[0082] S101. Acquire ship navigation trajectory data based on radar, satellite, and automatic identification systems, and standardize and synchronize multi-source heterogeneous data to obtain a ship trajectory dataset in a unified format:

[0083] Multi-source data on ship navigation is acquired using radar, satellites, and automatic identification systems (AIS). This data is collected and preliminarily cleaned to obtain an initial multi-source dataset. The initial dataset is then format-converted to generate a standardized data structure. A time synchronization algorithm is used to timestamp-align the standardized data structure, resulting in a time-synchronized dataset. If missing values ​​exist in the time-synchronized dataset, interpolation algorithms are used to fill in the missing data, generating a complete time-synchronized dataset. Based on the complete time-synchronized dataset, ship position, speed, and heading information are extracted to generate a preliminary ship trajectory dataset. Anomaly detection and cleaning are performed on the preliminary ship trajectory dataset using clustering algorithms, resulting in an optimized ship trajectory dataset. Finally, data compression techniques are used to optimize storage of the optimized ship trajectory dataset, generating the final, uniformly formatted ship trajectory dataset.

[0084] In one possible implementation, multi-source data acquisition can be achieved through a dedicated data interface module when acquiring radar, satellite, and automatic identification system data.

[0085] For example, radar data can be acquired through shore-based radar stations, containing the real-time position and speed of ships; satellite data can be captured using synthetic aperture radar to capture information over a wide area of ​​sea; and automatic identification systems (AIS) provide dynamic data such as ship identity and heading. The initial cleaning stage requires removing duplicate or invalid data, such as abnormal latitude and longitude values ​​from the AIS. After cleaning, an initial multi-source dataset is generated, containing fields such as timestamps, latitude and longitude, and speed.

[0086] Specifically, the process of converting the initial multi-source dataset into a uniform format includes:

[0087] For example, radar data may be stored in polar coordinates and needs to be converted to latitude and longitude format; satellite data has different resolutions and requires projection transformation. Standardized data structures typically include a unified time format such as UTC and a geographic coordinate system such as WGS84 to ensure consistency in subsequent processing.

[0088] For example, time synchronization algorithms can employ timestamp alignment methods based on linear interpolation. Assuming radar data updates every 10 seconds and automatic identification system data updates every 6 seconds, a time synchronization algorithm aligns all data to a uniform time interval, such as every 5 seconds, ensuring the continuity of the time-synchronized dataset. If the dataset contains missing values, such as missing satellite data at a certain time point, these can be estimated using a linear interpolation algorithm.

[0089] For example, if a ship's position at time t1 is 120.5°E, 30.2°N, and at time t3 it is 120.7°E, 30.3°N, but time t2 is missing, then the interpolated estimated position at t2 is 120.6°E, 30.25°N. A complete time-synchronized dataset can improve the accuracy of trajectory analysis.

[0090] In one embodiment, when extracting ship position, speed, and heading information, a preliminary ship trajectory dataset can be generated based on a time-synchronized dataset.

[0091] For example, a ship records 10 location points within 5 minutes, with a speed ranging from 10 to 15 knots and a heading varying from 0 to 360°. The trajectory dataset is stored in tabular form, containing time, latitude, longitude, speed, and heading fields. Clustering algorithms such as DBSCAN can be used for anomaly detection, identifying points deviating from the normal course.

[0092] For example, if a point suddenly jumps to a location 100 kilometers away, which is obviously abnormal, clustering can be used to remove such points and generate an optimized ship trajectory dataset, thereby improving the reliability of the trajectory.

[0093] Specifically, data compression technology can employ trajectory simplification algorithms such as the Douglas-Puk algorithm to retain key points and reduce storage requirements.

[0094] For example, the original trajectory contains 1000 points, which are compressed to retain 200 key points, reducing the data volume by 80% while still preserving the main features of the trajectory. The final unified format ship trajectory dataset is stored in a standardized JSON or CSV format for easy subsequent analysis and sharing.

[0095] It should be noted that the advantage of the above method lies in improving data processing efficiency and trajectory accuracy.

[0096] For example, time synchronization and interpolation algorithms ensure data continuity, clustering algorithms improve trajectory quality, and compression techniques reduce storage costs. These technologies collectively support efficient ship monitoring and route optimization, applicable to scenarios such as port management and maritime safety.

[0097] S102. The ship trajectory dataset is grouped using a spatiotemporal clustering algorithm. The trajectory geometric features and speed change patterns of each group of ships are extracted to obtain the ship interaction behavior dataset.

[0098] As shown in Figure 2, a spatiotemporal clustering algorithm is used to group the ship trajectory dataset, generating a grouped trajectory data set. Based on the grouped trajectory data sets, the trajectory shape features of each group of ships are extracted, generating a trajectory shape feature set. A speed pattern analysis method is used to process each group of ship data in the trajectory shape feature set to determine the speed variation pattern. If outliers are found in the speed variation pattern, an anomaly detection algorithm is used to filter them, resulting in a filtered speed variation pattern. Based on the filtered speed variation pattern and the trajectory shape feature set, ship interaction behaviors are extracted, generating a ship interaction behavior set. A behavior pattern recognition method is used to analyze the ship interaction behavior set to determine the ship interaction behavior patterns. The ship interaction behavior patterns are then classified and stored using a data grouping structure, resulting in a classified interaction behavior dataset.

[0099] In one possible implementation, spatiotemporal clustering algorithms can be used to group ship trajectory datasets. These algorithms combine temporal and spatial dimensions to group trajectory points based on similarity.

[0100] For example, an extended version of the DBSCAN algorithm, considering the ship's latitude, longitude, and timestamp, sets a spatial radius of 2 kilometers and a time window of 10 minutes to generate trajectory groups. Assuming there are 1000 ship trajectories in a certain sea area, they are clustered into 50 groups, each representing a set of ships sailing within a specific time and area. The grouped trajectory data sets retain key information such as time and location, facilitating subsequent analysis.

[0101] For example, when extracting trajectory shape features, the trajectory geometry of each group of ships can be analyzed.

[0102] In one embodiment, a shape feature set is generated by calculating the curvature, turning angle, and path length of the trajectory.

[0103] Specifically, a set of ship trajectories comprises 10 paths, each consisting of 100 location points. The average curvature and turning angle distribution of each trajectory are calculated to form a feature set. Curvature reflects the smoothness of the course, turning angle indicates changes in heading, and length quantifies the distance traveled. These features provide the foundation for subsequent speed analysis.

[0104] In one possible implementation, the velocity pattern analysis method can process the trajectory shape feature set to determine the velocity variation pattern.

[0105] For example, for a group of ships, analyze the trend of their speed changes between 5 and 20 knots. Suppose a ship's speed increases from 10 knots to 15 knots and then decreases to 8 knots within 30 minutes. Through time series analysis, extract the acceleration and deceleration patterns.

[0106] It should be noted that the speed variation pattern reflects the dynamic behavior of the ship, such as obstacle avoidance or berthing.

[0107] For example, anomaly detection algorithms can filter out anomalies in the pattern of speed changes.

[0108] In one embodiment, the Isolation Forest algorithm is used to identify abrupt speed changes. Suppose a ship is sailing steadily at around 10 knots, and suddenly records a speed of 30 knots, significantly deviating from the normal range; this can be marked as an anomaly and removed. The filtered speed change patterns are more accurate and reflect the true sailing status.

[0109] In one possible implementation, ship interaction behavior is extracted based on the filtered velocity change patterns and trajectory shape feature sets.

[0110] For example, analyzing the distance changes between two ships within the same time window can determine whether approaching or following behavior has occurred. Suppose that the distance between two ships decreases from 2 kilometers to 500 meters within 5 minutes, and their course tends to be the same; this can be considered an interactive behavior, generating a set of interactive behaviors.

[0111] For example, behavioral pattern recognition methods can analyze a set of ship interaction behaviors to determine the interaction patterns.

[0112] In one embodiment, a classification algorithm such as random forest is used to identify patterns such as following, driving side-by-side, or avoiding. Assuming that in a certain sea area, out of 10 sets of interaction behaviors, 8 sets are following patterns and 2 sets are avoiding patterns, this indicates that ships in the area mostly navigate in convoys. The classified interaction behavior dataset is stored in a structured format, such as JSON, containing interaction type, time, and location fields for easy querying and analysis.

[0113] In one possible implementation, the data grouping structure categorizes and stores interaction behavior patterns.

[0114] For example, following and avoidance behaviors can be stored as subsets based on interaction type and time period. Suppose a port generates 1000 interaction records daily; after classification, these can be divided into subsets such as following and avoidance, facilitating targeted analysis, such as optimizing route planning or monitoring potential collision risks.

[0115] S103. For the ship interaction behavior dataset, calculate the distance, speed difference, and heading consistency between trajectories to obtain the dynamic interaction parameter set:

[0116] The ship interaction behavior dataset is grouped using a trajectory pairing method. For each pair of ships, the trajectory coordinates are matched to determine a ship pairing set. Based on the ship pairing set, the spatial relationship between each pair of ships in the time series is calculated, resulting in a trajectory spacing set. If the spacing in the trajectory spacing set is less than a preset threshold, the relative position is calculated using vector analysis to obtain a dynamic feature set. Based on the dynamic feature set, the speed difference and heading consistency of each pair of ships are extracted to generate a navigation state parameter set. The K-means clustering algorithm is used to classify the navigation state parameter set to determine the interaction behavior pattern set. Based on the interaction behavior pattern set, the dynamic feature changes in the time series are analyzed to obtain a behavior pattern classification set. Using the behavior pattern classification set, a dynamic interaction parameter set for ship interactions is generated.

[0117] For example, trajectory pairing methods can be used to group and process ship interaction behavior datasets. The core of trajectory pairing lies in matching ship trajectory points through temporal and spatial dimensions to generate pair sets. Suppose a sea area has 500 ship trajectories, each containing timestamps and latitude / longitude information. Using trajectory pairing methods, based on a 5-minute time window and a 1-kilometer spatial distance, 200 ship pair sets can be generated. Each pair set contains the trajectory points of two ships within a specific time period, preserving both location and time information, providing a foundation for subsequent spatial relationship analysis.

[0118] In one possible implementation, when calculating the trajectory spacing set, the spatial distance between each pair of ships in the time series can be analyzed.

[0119] For example, the Euclidean distance between two ships is calculated from their trajectory point sequences over a 10-minute period, generating a distance set. Suppose the distance between paired ships gradually decreases from 2 kilometers to 300 meters, indicating that the two ships may be approaching each other. If a preset distance threshold of 500 meters is set, this pair is marked as a potential interaction object. The distance set provides data support for dynamic feature extraction.

[0120] Specifically, vector analysis methods can be used to calculate relative positions and generate dynamic feature sets.

[0121] For example, using the latitude and longitude coordinates of two ships, the relative vector between them can be calculated, including distance and direction information. Suppose that the relative position of a paired ship shifts from due east to northeast within 5 minutes, indicating a course adjustment. The dynamic feature set records these changes, facilitating the analysis of navigation intentions.

[0122] For example, when extracting speed differences and heading consistency, navigation state parameters can be calculated based on a dynamic feature set. Suppose that in a pair of ships, one ship has a speed of 12 knots and the other 15 knots, a speed difference of 3 knots; simultaneously, the angle between their headings decreases from 30 degrees to 5 degrees, indicating that their headings are converging. These parameters form a navigation state parameter set, reflecting the dynamic relationship between the ships.

[0123] In one possible implementation, the K-means clustering algorithm classifies the set of navigation state parameters to generate a set of interaction behavior patterns.

[0124] For example, using speed differences and course consistency as features, clustering can categorize patterns into three types: following, parallel, and avoidance. Suppose that in a certain sea area, out of 100 pairs, 60 are following patterns, 30 are parallel patterns, and 10 are avoidance patterns, indicating that convoy navigation is prevalent in the area. The clustering results provide structured data for behavioral pattern analysis.

[0125] Specifically, analyzing the dynamic changes in time series data can generate behavioral pattern classification sets.

[0126] For example, the spacing between pairings in a certain following pattern decreased from 1 kilometer to 400 meters within 20 minutes, while the heading consistency remained within 10 degrees, indicating stable following behavior. The classification sets are stored in time-series format, including interaction types and feature changes, facilitating subsequent queries.

[0127] For example, a dynamic set of interaction parameters can be generated based on a behavioral pattern classification set, containing the interaction characteristics of each pair of ships. Suppose that the interaction parameters for a pair include a distance of 400 meters, a speed difference of 2 knots, and a heading angle of 5 degrees, indicating stable parallel navigation. These parameters can be used to optimize route planning or monitor collision risks, improving navigation efficiency and safety.

[0128] S104. If multiple ships in the dynamic interaction parameter set are within a preset time window and their distance and speed are both less than a threshold, then the anomaly detection algorithm will determine them as potential illegal re-entry behaviors, resulting in an abnormal behavior candidate set:

[0129] Trajectory data of ships whose distance and speed are below preset thresholds are obtained from a dynamic interaction parameter set. An isolated forest algorithm is used to obtain a candidate set of abnormal behaviors. For each pair of ships in the candidate set, time series data is obtained, and the relative position changes of the trajectory data are calculated to obtain a position change set. If the relative position changes in the position change set are consistently below a preset threshold, a potential abnormal loitering behavior set is determined through time series analysis. Based on the abnormal loitering behavior set, the navigation state of each pair of ships is extracted, and the fluctuation characteristics of speed and heading are calculated to obtain a state fluctuation set. The K-means clustering algorithm is used to classify the state fluctuation set to obtain an abnormal behavior pattern set. For the abnormal behavior pattern set, trajectory data within a time window is obtained, and the interaction frequency between ships is calculated to obtain an interaction frequency set. If the interaction frequency of a pair of ships in the interaction frequency set is higher than a preset threshold, quantitative analysis is used to determine it as potential illegal re-entry behavior, resulting in the final candidate set of abnormal behaviors.

[0130] For example, when processing dynamic interaction parameter sets, trajectory data where the ship's distance and speed are below a certain standard can be filtered out by setting thresholds. Suppose that in a certain sea area, the preset distance threshold is 500 meters and the speed threshold is 5 knots in the dynamic interaction parameter set, resulting in 100 paired trajectory data points after filtering. These data reflect the approach behavior of ships within a specific time window and may involve anomalies. The Isolation Forest algorithm can be used to detect candidate sets of anomalous behavior. Its principle is to randomly segment data points and identify those that are easily isolated as anomalies.

[0131] For example, in 100 pairs, the Isolation Forest algorithm identified 10 pairs whose trajectory data deviated from the normal pattern. These pairs of ships may have abnormal navigation behavior, such as approaching at low speed for a long time.

[0132] Specifically, for the candidate set of abnormal behavior, time-series data for each pair of ships can be extracted to analyze changes in their relative positions. For example, if the relative position change of a pair of ships is consistently less than 100 meters within 10 minutes, it indicates that the two ships may be maintaining close proximity and remaining stationary or moving slowly. Through time-series analysis, the continuity of position changes is calculated. If the change amplitude consistently falls below a threshold, such as 100 meters, it can be identified as potential abnormal stationary behavior.

[0133] For example, if two ships in a certain sea area change positions by only 50 meters within 30 minutes, with no significant adjustment in course and a speed of less than 2 knots, this may indicate that the ships are making abnormal stops or interactions.

[0134] In one possible implementation, the abnormal stopping behavior set can be further used to extract navigation status and calculate the fluctuation characteristics of speed and heading. Assuming a paired vessel's speed fluctuation range is 0.5 to 1.5 knots and its heading fluctuation angle is less than 10 degrees, this indicates a stable but abnormal navigation status, potentially involving illegal transshipment or anchoring. The K-means clustering algorithm can classify the set of state fluctuations to generate a set of abnormal behavior patterns.

[0135] For example, after clustering, abnormal behavior is categorized into three types: stationary, slow following, and abnormal parallelism. A pair of ships with a speed fluctuation of 0.8 knots and a heading fluctuation of 5 degrees is classified as stationary, indicating a possible abnormal stop.

[0136] For example, for a set of abnormal behavior patterns, the frequency of interactions within a time window can be analyzed. Suppose that within one hour, the interaction frequency of a paired vessel reaches 5 times, exceeding a preset threshold of 3 times, indicating frequent proximity behavior. Through vector analysis, the directional changes in the relative positions between the vessels are calculated. If the direction remains stable and the distance is less than 300 meters, it can be identified as potential illegal transshipment.

[0137] For example, if a paired vessel repeatedly approaches within 200 meters of another vessel within 20 minutes, maintaining a consistent course and interacting six times, this matches the characteristics of illegal transshipment. These analytical results form the final candidate set of abnormal behaviors, providing data support for subsequent monitoring and decision-making, and contributing to improved navigation safety and regulatory efficiency.

[0138] S105. In densely populated areas of ships, extract trajectory geometric features from the candidate set of abnormal behaviors, and use density clustering algorithm to distinguish between normal berthing and suspicious clustering behaviors to obtain a subset of abnormal clustering behaviors:

[0139] As shown in Figure 3, trajectory data of candidate abnormal behaviors are obtained from densely populated areas of ships. The geometric features of each trajectory are calculated to obtain a trajectory geometric feature set. Based on the trajectory geometric feature set, a density clustering algorithm is used to classify the trajectories, distinguishing between normal berthing behavior and suspicious clustering behavior, resulting in a preliminary behavior classification set. For suspicious clustering behavior in the preliminary behavior classification set, the trajectory point density of each pair of ships is extracted, and the point density distribution characteristics are calculated to obtain a density distribution feature set. If the point density in the density distribution feature set is consistently higher than a preset threshold, it is determined to be abnormal clustering behavior through time series analysis, resulting in an abnormal clustering behavior subset. Based on the abnormal clustering behavior subset, the interaction time window of each pair of ships is obtained, and the trajectory overlap within the time window is calculated to obtain a trajectory overlap set. For the trajectory overlap set, if the trajectory overlap is higher than a preset threshold, the abnormal interaction pattern between ships is determined through quantitative analysis, resulting in an abnormal interaction pattern set. Based on the abnormal interaction pattern set, the navigation state features of the ships are extracted, and the state features are classified using a support vector machine algorithm to obtain the final abnormal clustering behavior set.

[0140] For example, when acquiring trajectory data in densely populated areas, real-time position, speed, and heading information can be collected through an Automatic Identification System (AIS) to generate a dynamic trajectory dataset containing multiple vessels. The calculation of the trajectory's geometric features allows for analysis of curvature, turning angles, and path length. Suppose a vessel in a certain sea area exhibits multiple sharp turns within one hour, with significant curvature changes and a path length of 10 nautical miles, while a normal berthing trajectory is typically smoother with lower curvature. These geometric features can be derived by calculating the angle changes between trajectory points and the path smoothness, reflecting whether the vessel deviates from its normal navigation pattern.

[0141] In one possible implementation, a density clustering algorithm such as DBSCAN is used to classify the trajectories. Based on the trajectory geometric feature set, a neighborhood radius of 300 meters and a minimum number of points of 5 are set to classify normal berthing behavior and suspicious clustering behavior. Normal berthing trajectories typically exhibit a unidirectional straight line or a slight curve, while suspicious clustering trajectories show that the trajectory points of multiple ships overlap densely within a small area.

[0142] For example, if the trajectory points of three ships frequently appear within a 500-meter radius in a certain area, a clustering algorithm classifies this as suspicious clustering behavior, forming a preliminary behavior classification set. Based on the point density distribution characteristics of suspicious clustering behavior, the distribution density of trajectory points per unit area can be calculated. Assuming the trajectory point density in a certain area is 20 per square kilometer, exceeding a preset threshold of 10, time-series analysis is used to observe whether the density remains consistently high within 30 minutes. If it consistently exceeds the threshold, it can be determined as abnormal clustering behavior.

[0143] For example, if the trajectory points of a pair of ships are concentrated within a 200-meter range within 20 minutes, with a density of 25 points per square kilometer, it indicates that there may be abnormal stops or interactions.

[0144] In one possible implementation, the trajectory overlap within an interaction time window is calculated for a subset of anomalous clustering behaviors. Trajectory overlap can be determined by comparing the spatial overlap ratio of the trajectory points of two ships. Assuming that the trajectory overlap of a pair of ships reaches 80% within 15 minutes, exceeding a preset threshold of 60%, vector analysis is used to check the directional consistency of the relative positions between the ships. If the directional change is less than 5 degrees, it indicates the existence of an anomalous interaction pattern.

[0145] For example, if two ships have an 85% overlap in their trajectories and maintain the same course within 10 minutes, it suggests possible abnormal following behavior.

[0146] For example, for a set of abnormal interaction patterns, navigation state features such as speed fluctuations and heading stability are extracted. Assuming a pair of ships has speed fluctuations ranging from 0.3 to 1.2 knots and heading changes of less than 8 degrees, a support vector machine (SVM) algorithm is used to classify these features. The SVM constructs a high-dimensional classification plane, dividing the state features into two categories: normal navigation and abnormal clustering.

[0147] For example, a pair of ships exhibiting a speed fluctuation of 0.5 knots and a heading change of only 3 degrees is classified as an anomalous clustering behavior, ultimately forming an anomalous clustering behavior set. These analyses help identify potential illegal activities and improve regulatory efficiency.

[0148] S106. Based on the subset of abnormal aggregation behaviors, and by fusing the dynamic interaction parameter set, calculate the aggregation duration and the number of ships to obtain the abnormal behavior confirmation set:

[0149] The dynamic interaction parameters of each pair of ships are obtained from the subset of abnormal clustering behaviors. The interaction frequency and interaction distance are calculated to obtain an interaction feature set. For the interaction feature set, if the interaction frequency is higher than a preset threshold, the persistence of the interaction is determined through time series analysis to obtain a persistent interaction set. Based on the persistent interaction set, the trajectory point density of each pair of ships is extracted, and the density distribution characteristics are calculated to obtain a density feature set. For the density feature set, if the point density distribution is consistently higher than a preset threshold, the K-means clustering algorithm is used to classify high-density interaction behaviors to obtain a high-density interaction subset. Based on the high-density interaction subset, the navigation state characteristics of the ships are obtained, and the state change frequency is calculated to obtain a state change set. For the state change set, abnormal interaction patterns between ships are determined through vector analysis to obtain an abnormal interaction pattern set. Based on the abnormal interaction pattern set, the severity of abnormal interaction patterns is classified using a decision tree algorithm to obtain an abnormal behavior confirmation set.

[0150] For example, when analyzing anomalous clustering behavior in densely populated areas of ships, dynamic interaction parameters for each pair of ships can be extracted from a subset of anomalous clustering behavior. The focus is on calculating interaction frequency and interaction distance to construct an interaction feature set. Interaction frequency refers to the number of times ships approach each other per unit time, while interaction distance measures the spatial proximity of ship trajectory points. Assuming two ships in a certain sea area approach each other 5 times within 30 minutes, with an average interaction distance of 200 meters, these parameters can be calculated using data from the Automatic Identification System (AIS) to generate a feature set containing interaction frequency and distance. This helps in capturing the dynamic relationships between ships.

[0151] In one possible implementation, for an interaction feature set, if the interaction frequency exceeds a preset threshold, such as four times per hour, the persistence of the interaction can be determined through time series analysis. Time series analysis focuses on the temporal distribution of interaction events; continuous interaction refers to the repeated occurrence of proximity behavior over a period of time. For example, if two ships approach each other four times within one hour, with each interaction lasting more than five minutes, this can be categorized as a continuous interaction set. This analysis can effectively filter out abnormally frequent interaction behaviors.

[0152] Specifically, for a continuous interaction set, the trajectory point density of each pair of ships can be extracted, and the density distribution characteristics can be calculated to form a density feature set. Trajectory point density refers to the number of trajectory points per unit area, reflecting the degree of ship aggregation.

[0153] For example, the trajectory points of two ships within a certain area are concentrated within a 300-meter range, with a density of 15 per square kilometer, exceeding the threshold of 10. By analyzing the spatiotemporal changes in density distribution, abnormal clustering areas can be identified.

[0154] For example, for a density feature set, if the point density consistently exceeds a threshold, K-means clustering can be used to classify high-density interaction behaviors. K-means clustering identifies high-density interaction subsets by dividing data points into different clusters. Suppose that the trajectory point density of three pairs of ships in a certain sea area is all above the threshold; after clustering, two clusters are formed, one of which shows a significantly higher density and can be classified as a high-density interaction subset. This method can accurately distinguish different interaction patterns.

[0155] In one possible implementation, based on a high-density interaction subset, the ship's navigation state features, such as the frequency of speed changes and the number of course adjustments, can be extracted to form a state change set.

[0156] For example, if a pair of ships changes speed three times and adjusts course twice within 20 minutes, it indicates unstable status. By statistically analyzing the frequency of status changes, the degree of abnormality in ship behavior can be quantified.

[0157] Specifically, for a set of state changes, vector analysis can be used to determine abnormal interaction patterns between ships. Quantitative analysis examines the directional consistency of the relative positions and headings between ships.

[0158] For example, if two ships maintain a course difference of less than 5 degrees within 15 minutes and their trajectory points overlap by 70%, this can be categorized as an anomalous interaction pattern. This analysis can reveal potential anomalous following or cooperative behavior.

[0159] For example, for a set of abnormal interaction patterns, a decision tree algorithm can be used to classify the severity of these patterns. The decision tree categorizes abnormal behavior into mild, moderate, and severe levels based on feature conditions. For instance, a pair of ships exhibiting high interaction frequency, strong course consistency, and minimal speed fluctuations might be classified as exhibiting severe abnormal behavior, forming an abnormal behavior confirmation set. This classification can provide a prioritization basis for regulatory oversight.

[0160] In one possible implementation, the combination of the above methods forms a complete analysis chain from dynamic interaction to final classification, progressively filtering out high-risk abnormal behaviors. Feature extraction and classification at each step support each other, ensuring the rigor and reliability of the analysis and providing effective support for behavioral regulation in densely populated shipping areas.

[0161] S107. If the duration of the confirmed abnormal behavior clustering exceeds a preset threshold, an abnormal trajectory report is generated through the trajectory reconstruction module to determine the final abnormal behavior:

[0162] For example, when analyzing anomaly behavior confirmation sets in densely populated areas, if the aggregation duration exceeds a preset threshold, such as 2 hours, an anomaly track report can be generated to determine the final anomaly behavior. The core of the trajectory reconstruction module lies in integrating data from the Automatic Identification System (AIS) and combining temporal and spatial characteristics to reconstruct the complete navigation path of the vessel.

[0163] For example, if two ships in a certain sea area continuously approach each other for 3 hours, and their trajectory points show that the distance between them is always less than 300 meters, the trajectory reconstruction module can extract the latitude and longitude sequence of each ship from the time series data to generate a continuous track map. This track map can clearly show the movement path and interaction behavior of the ships, making it easier to analyze the spatiotemporal characteristics of abnormal clustering.

[0164] Specifically, when generating a track report, the trajectory reconstruction module extracts key parameters from the abnormal behavior confirmation set, such as the ship's speed, heading changes, and track point density.

[0165] For example, if a pair of ships adjusts their course six times within 2.5 hours, and their speed decreases from 10 knots to 5 knots, with trajectory points concentrated within a 200-meter range (a density of 12 points per square kilometer), the module will integrate these parameters into a dynamic trajectory on a timeline, marking the start and end times and geographical extent of the anomalous clustering. This method can visually present anomalous points in ship behavior, such as prolonged low-speed lingering or frequent course adjustments, providing a basis for subsequent analysis.

[0166] In one possible implementation, the trajectory reconstruction method would combine spatial interpolation techniques to fill in missing points in the data of the automatic identification system.

[0167] For example, if a vessel experiences a signal interruption for 30 minutes, the module can calculate the possible intermediate position using the speed and heading of the preceding and following trajectory points, generating a smooth track curve. Assuming the calculation shows the vessel maintained a close proximity of within 200 meters during the interruption, its anomalous clustering behavior can be further confirmed. This interpolation method improves the completeness of track reports and reduces the impact of missing data on the analysis.

[0168] For example, in generating abnormal track reports, the module also analyzes the relative motion characteristics between ships, such as relative speed and track overlap ratio.

[0169] Specifically, if two vessels maintain a relative speed of less than 2 knots for one hour and their tracks overlap by 60%, coordinated navigation behavior can be inferred. Track reports will mark these characteristics as high-risk points and, combined with the duration of the overlap, generate a detailed description of the abnormal behavior, such as "Two vessels coordinated at low speeds for 2.3 hours in a certain sea area, with highly overlapping tracks." This description provides clear evidence of abnormal behavior for regulatory purposes.

[0170] In one possible implementation, the track report would also incorporate environmental factors, such as currents and wind direction in the sea area, to validate the plausibility of the unusual behavior.

[0171] For example, in a sea area with a current speed of 3 knots and wind direction opposite to the ship's course, the trajectory reconstruction module can analyze whether the ship has adjusted its navigation status due to environmental factors. If the report shows that the ship maintains an abnormal approach despite adverse conditions, its abnormal behavior can be further confirmed. This comprehensive analysis improves the reliability of trajectory reports and provides multi-dimensional support for regulatory decisions.

[0172] For example, in the application of abnormal navigation reports, regulatory authorities can use the temporal and spatial characteristics of the reports to quickly locate high-risk areas. Suppose a report shows that three pairs of vessels repeatedly approached each other in a certain sea area within two hours, with a trajectory point density consistently exceeding 10 per square kilometer. Regulatory personnel can prioritize investigating whether there is illegal activity in that area. This trajectory reconstruction-based analysis can effectively improve the accuracy and efficiency of abnormal behavior identification.

[0173] Example 2

[0174] This embodiment also discloses a computer device, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the method described in Embodiment 1.

[0175] Example 3

[0176] This embodiment also discloses a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the method described in Embodiment 1.

[0177] Example 4

[0178] This embodiment also discloses a computer program product, including a computer program that, when executed by a processor, implements the steps of the method described in Embodiment 1.

[0179] The above are merely preferred embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

A method for detecting anomalies in ship tracks based on data fusion, characterized in that, Includes the following steps: Acquire multi-source heterogeneous data of ship tracks and preprocess them to generate a ship track dataset in a unified format; Spatiotemporal clustering analysis was performed on the ship trajectory dataset to extract the ship interaction behavior dataset; Calculate the dynamic interaction parameters in the ship interaction behavior dataset; Based on dynamic interactive parameters, potential illegal copying behavior is detected, and a candidate set of abnormal behaviors is formed. In areas with high vessel density, further analysis of the candidate set of abnormal behavior is conducted to distinguish between normal berthing and suspicious clustering behavior, forming a subset of abnormal clustering behavior. By combining a subset of abnormal clustering behaviors and dynamic interaction parameters, the clustering duration and the number of ships are calculated to form an abnormal behavior confirmation set; If the duration of the confirmed abnormal behavior cluster exceeds a preset threshold, an abnormal flight track report is generated to determine the final abnormal behavior. The method according to claim 1, characterized in that, The process of acquiring multi-source heterogeneous ship trajectory data and preprocessing it to generate a ship trajectory dataset in a unified format includes: The initial multi-source dataset is obtained by collecting ship navigation trajectory data based on radar, satellite and automatic identification system, and performing preliminary cleaning. The initial multi-source dataset is format-converted and time-synchronized to generate a time-synchronized dataset. Based on the time synchronization dataset, if there are missing values, the missing data is filled in using an interpolation algorithm to generate a complete time synchronization dataset. Based on the complete time synchronization dataset, the position, speed, and heading information of the ships are extracted to generate a preliminary ship trajectory dataset; Based on the initial ship trajectory dataset, anomaly detection and cleaning were performed using a clustering algorithm to obtain an optimized ship trajectory dataset. Based on the optimized ship trajectory dataset, data compression technology is used for storage optimization to generate the final unified format ship trajectory dataset. The method according to claim 1, characterized in that, The process of performing spatiotemporal clustering analysis on ship trajectory datasets to extract ship interaction behavior datasets includes: Based on a unified format ship trajectory dataset, a spatiotemporal clustering algorithm is used to group the data, generating a set of grouped trajectory data. Based on the grouped trajectory data set, the trajectory shape features of each group of ships are extracted to generate a trajectory shape feature set; Based on the trajectory shape feature set, the velocity change pattern is determined using velocity pattern analysis. Based on the velocity change pattern, if there are outliers, they are filtered using an anomaly detection algorithm to obtain the filtered velocity change pattern. Based on the filtered velocity change patterns and trajectory shape feature sets, ship interaction behaviors are extracted to generate a set of ship interaction behaviors. Based on the set of ship interaction behaviors, a behavior pattern recognition method is used to analyze and determine the ship interaction behavior patterns. Based on the ship interaction behavior patterns, the data is classified and stored using a data grouping structure to obtain a classified ship interaction behavior dataset. The method according to claim 1, characterized in that, The process of calculating dynamic interaction parameters in a ship interaction behavior dataset includes: Based on the ship interaction behavior dataset, the trajectory pairing method is used to group the ships and determine the ship pairing set. Based on the ship pairing set, the spatial relationship of each ship pair in the time series is calculated to obtain the trajectory spacing set; Based on the trajectory spacing set, if the spacing is less than a preset threshold, the relative position is calculated using vector analysis to obtain a dynamic feature set; Based on the dynamic feature set, the speed difference and heading consistency of each pair of ships are extracted to generate a navigation state parameter set; Based on the set of navigation state parameters, the K-means clustering algorithm is used for classification to determine the set of interaction behavior patterns; Based on the set of interaction behavior patterns, analyze the dynamic feature changes in the time series to obtain a behavior pattern classification set; Based on the behavioral pattern classification set, a dynamic interaction parameter set for ship interaction is generated. The method according to claim 1, characterized in that, The process of detecting potential unauthorized copying behavior and forming a candidate set of abnormal behaviors based on dynamic interaction parameters includes: Based on the dynamic interaction parameter set, trajectory data of ships whose distance and speed are below preset thresholds are obtained, and an isolated forest algorithm is used to obtain a candidate set of abnormal behaviors; Based on the candidate set of abnormal behaviors, the time series of each pair of ships is obtained, and the relative position change of the trajectory data is calculated to obtain the position change set. Based on the set of location changes, if the relative location change is consistently below a preset threshold, then a set of potential abnormal dwelling behaviors is determined through time series analysis. Based on the abnormal dwell behavior set, the navigation state of each pair of ships is extracted, and the fluctuation characteristics of speed and heading are calculated to obtain the state fluctuation set; Based on the set of state fluctuations, the K-means clustering algorithm is used to classify the abnormal behavior patterns to obtain a set of abnormal behavior patterns. Based on the abnormal behavior pattern set, obtain trajectory data within the time window, calculate the interaction frequency between ships, and obtain the interaction frequency set. Based on the interaction frequency set, if the interaction frequency of a certain pair of ships is higher than a preset threshold, it is determined through quantitative analysis to be a potential illegal re-transfer behavior, thus obtaining the final abnormal behavior candidate set. The method according to claim 1, characterized in that, In areas with high vessel density, further analysis of the candidate set of abnormal behavior, distinguishing between normal berthing and suspicious clustering behavior, and forming a subset of abnormal clustering behavior includes: Based on the candidate set of abnormal behaviors in densely populated areas of ships, the geometric features of each trajectory are calculated to obtain the trajectory geometric feature set; Based on the trajectory geometric feature set, density clustering algorithm is used to classify the trajectories, distinguishing between normal berthing behavior and suspicious clustering behavior, and obtaining a preliminary behavior classification set; Based on the suspicious clustering behaviors in the preliminary behavior classification set, the trajectory point density of each pair of ships is extracted, the point density distribution characteristics are calculated, and the density distribution feature set is obtained. Based on the density distribution feature set, if the point density is consistently higher than a preset threshold, it is determined to be an abnormal clustering behavior through time series analysis, and a subset of abnormal clustering behaviors is obtained. Based on the subset of abnormal clustering behavior, obtain the interaction time window for each pair of ships, calculate the trajectory overlap within the time window, and obtain the trajectory overlap set. Based on the trajectory overlap set, if the trajectory overlap is higher than a preset threshold, then through quantitative analysis, the abnormal interaction patterns between ships are determined, and the abnormal interaction pattern set is obtained. Based on the abnormal interaction pattern set, the navigation state features of the ship are extracted, and the support vector machine algorithm is used to classify the state features to obtain the final abnormal clustering behavior subset. The method according to claim 1, characterized in that, The process of combining a subset of anomalous clustering behaviors and dynamic interaction parameters to calculate the clustering duration and number of ships, and forming an anomalous behavior confirmation set, includes: Based on the subset of abnormal clustering behavior, obtain the dynamic interaction parameters of each pair of ships, calculate the interaction frequency and interaction distance, and obtain the interaction feature set; Based on the interaction feature set, if the interaction frequency is higher than a preset threshold, the continuity of the interaction is determined through time series analysis to obtain a continuous interaction set. Based on the continuous interaction set, the trajectory point density of each pair of ships is extracted, the density distribution characteristics are calculated, and a density feature set is obtained. Based on the density feature set, if the point density distribution is consistently higher than a preset threshold, the K-means clustering algorithm is used to classify high-density interaction behaviors and obtain a high-density interaction subset. Based on the high-density interaction subset, the navigation state characteristics of the ship are obtained, the state change frequency is calculated, and the state change set is obtained. Based on the set of state changes, abnormal interaction patterns between ships are determined through quantitative analysis, resulting in a set of abnormal interaction patterns. Based on the set of abnormal interaction patterns, a decision tree algorithm is used to classify the severity of abnormal interaction patterns and obtain an abnormal behavior confirmation set. A computer device includes a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the steps of the method according to any one of claims 1-7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the steps of the method according to any one of claims 1-7. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program implements the steps of the method according to any one of claims 1-7.