• Title/Summary/Keyword: Abnormal Behavior Detection

Search Result 131, Processing Time 0.029 seconds

Unsupervised Motion Learning for Abnormal Behavior Detection in Visual Surveillance (영상감시시스템에서 움직임의 비교사학습을 통한 비정상행동탐지)

  • Jeong, Ha-Wook;Chang, Hyung-Jin;Choi, Jin-Young
    • Journal of the Institute of Electronics Engineers of Korea SC
    • /
    • v.48 no.5
    • /
    • pp.45-51
    • /
    • 2011
  • In this paper, we propose an unsupervised learning method for modeling motion trajectory patterns effectively. In our approach, observations of an object on a trajectory are treated as words in a document for latent dirichlet allocation algorithm which is used for clustering words on the topic in natural language process. This allows clustering topics (e.g. go straight, turn left, turn right) effectively in complex scenes, such as crossroads. After this procedure, we learn patterns of word sequences in each cluster using Baum-Welch algorithm used to find the unknown parameters in a hidden markov model. Evaluation of abnormality can be done using forward algorithm by comparing learned sequence and input sequence. Results of experiments show that modeling of semantic region is robust against noise in various scene.

Using Image Visualization Based Malware Detection Techniques for Customer Churn Prediction in Online Games (악성코드의 이미지 시각화 탐지 기법을 적용한 온라인 게임상에서의 이탈 유저 탐지 모델)

  • Yim, Ha-bin;Kim, Huy-kang;Kim, Seung-joo
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.27 no.6
    • /
    • pp.1431-1439
    • /
    • 2017
  • In the security field, log analysis is important to detect malware or abnormal behavior. Recently, image visualization techniques for malware dectection becomes to a major part of security. These techniques can also be used in online games. Users can leave a game when they felt bad experience from game bot, automatic hunting programs, malicious code, etc. This churning can damage online game's profit and longevity of service if game operators cannot detect this kind of events in time. In this paper, we propose a new technique of PNG image conversion based churn prediction to improve the efficiency of data analysis for the first. By using this log compression technique, we can reduce the size of log files by 52,849 times smaller and increase the analysis speed without features analysis. Second, we apply data mining technique to predict user's churn with a real dataset from Blade & Soul developed by NCSoft. As a result, we can identify potential churners with a high accuracy of 97%.

Time Series Analysis of Agricultural Reservoir Water Level Data for Abnormal Behavior Detection (농업용 저수지 이상거동 탐지를 위한 시계열 수위자료 특성 분석)

  • Lee, Sung Hack;Lee, Sang Hyun;Hong, Min Ki;Cho, Jin Young
    • Proceedings of the Korea Water Resources Association Conference
    • /
    • 2015.05a
    • /
    • pp.275-275
    • /
    • 2015
  • 최근 기후변화에 따른 극한 강우사상의 증가로 인하여 농업용 저수지의 재해 위험도가 증가하고 있는 추세이며, 사고가 발생할 때 마다 파손/붕괴된 시설물을 보수하는 대응형 유지관리체계에서 벗어나 기반시설의 성능과 생애주기 등을 고려하여 재해 발생을 사전에 예보 및 경보를 알릴 수 있는 예방적 관리체계로의 전환이 필요하다. 한국농어촌공사는 전국 1,500개 저수지에서 10분 단위 수위자료를 측정하고 있으며, 이를 분석하여 재해예방에 활용할 수 있는 기반이 조성되어 있으나 이에 대한 관리가 이루어지지 않고 있고 수집된 자료를 활용하여 재해 징후를 분석할 수 있는 재해 예방적 분석기술이 마련되어 있지 않은 실정이다. 본 연구에서는 농업용 저수지 수위자료를 이용한 저수지 이상거동을 판별하기 위하여 전국 34개 한국농어촌공사 관할 저수의 시계열 수위자료의 특성(Feature)을 분석하고자 한다. 시계열 자료의 시계열 특성을 분석하기 위하여 한국농어촌공사 관할의 전국 34개 저수지를 선정하여 분석을 실시하였다. 대상저수지는 지역별, 저수용량, 안정등급, 붕괴발생, 1개 지사관할 저수지로 각각 구분하여 선정하였으며, 각 저수지의 수위 측정기간(최소 5개년)에 대한 자료를 수집하였다. 농업용 저수지의 시계열 수위 자료의 특성을 분석하기 위하여 자료의 전처리를 수행하였다. 자료의 전처리는 시계열 수위자료의 잡음 특성, 기상자료 관련 변동특성 등 분류(Classification)에 영향을 미치는 노이즈 요소를 제거하는 과정이다. 전처리과정을 거친 자료는 특징(Feature) 추출 과정을 거치게 되고, 추출된 특징의 적합성에 따라 분류 알고리듬 성능에 많은 영향을 미친다. 따라서 시계열 자료의 특성을 파악하고 특징을 추출하는 것은 이상치 탐지에 있어 매우 중요한 과정이다. 본 연구에서는 시계열 자료 특징 추출 방법으로 물리적인 한계치, 확률적인 문턱값(Threshold), 시계열 패턴, 주변 저수지와의 시계열 상관분석 등을 적용하였으며, 이를 데이터베이스로 구축하여 이후 분류알고리듬 학습에 적용하여 정상치와 이상치를 판별하는데 이용될 수 있도록 하였다. 따라서 본 연구에서 제시되는 농업용 저수지의 시계열 특성은 다양한 분류알고리듬에 적용할 수 있으며, 이를 통하여 저수지 이상거동 판별을 위한 최적을 분류알고리듬의 선택에 도움이 될 것이다.

  • PDF

Classification Performance Improvement of UNSW-NB15 Dataset Based on Feature Selection (특징선택 기법에 기반한 UNSW-NB15 데이터셋의 분류 성능 개선)

  • Lee, Dae-Bum;Seo, Jae-Hyun
    • Journal of the Korea Convergence Society
    • /
    • v.10 no.5
    • /
    • pp.35-42
    • /
    • 2019
  • Recently, as the Internet and various wearable devices have appeared, Internet technology has contributed to obtaining more convenient information and doing business. However, as the internet is used in various parts, the attack surface points that are exposed to attacks are increasing, Attempts to invade networks aimed at taking unfair advantage, such as cyber terrorism, are also increasing. In this paper, we propose a feature selection method to improve the classification performance of the class to classify the abnormal behavior in the network traffic. The UNSW-NB15 dataset has a rare class imbalance problem with relatively few instances compared to other classes, and an undersampling method is used to eliminate it. We use the SVM, k-NN, and decision tree algorithms and extract a subset of combinations with superior detection accuracy and RMSE through training and verification. The subset has recall values of more than 98% through the wrapper based experiments and the DT_PSO showed the best performance.

Deep Learning-based Pet Monitoring System and Activity Recognition device

  • Kim, Jinah;Kim, Hyungju;Park, Chan;Moon, Nammee
    • Journal of the Korea Society of Computer and Information
    • /
    • v.27 no.2
    • /
    • pp.25-32
    • /
    • 2022
  • In this paper, we propose a pet monitoring system based on deep learning using an activity recognition device. The system consists of a pet's activity recognition device, a pet owner's smart device, and a server. Accelerometer and gyroscope data were collected from an Arduino-based activity recognition device, and the number of steps was calculated. The collected data is pre-processed and the amount of activity is measured by recognizing the activity in five types (sitting, standing, lying, walking, running) through a deep learning model that hybridizes CNN and LSTM. Finally, monitoring of changes in the activity, such as daily and weekly briefing charts, is provided on the pet owner's smart device. As a result of the performance evaluation, it was confirmed that specific activity recognition and activity measurement of pets were possible. Abnormal behavior detection of pets and expansion of health care services can be expected through data accumulation in the future.

Optimization of Pose Estimation Model based on Genetic Algorithms for Anomaly Detection in Unmanned Stores (무인점포 이상행동 인식을 위한 유전 알고리즘 기반 자세 추정 모델 최적화)

  • Sang-Hyeop Lee;Jang-Sik Park
    • Journal of the Korean Society of Industry Convergence
    • /
    • v.26 no.1
    • /
    • pp.113-119
    • /
    • 2023
  • In this paper, we propose an optimization of a pose estimation deep learning model for recognition of abnormal behavior in unmanned stores using radio frequencies. The radio frequency use millimeter wave in the 30 GHz to 300 GHz band. Due to the short wavelength and strong straightness, it is a frequency with less grayness and less interference due to radio absorption on the object. A millimeter wave radar is used to solve the problem of personal information infringement that may occur in conventional CCTV image-based pose estimation. Deep learning-based pose estimation models generally use convolution neural networks. The convolution neural network is a combination of convolution layers and pooling layers of different types, and there are many cases of convolution filter size, number, and convolution operations, and more cases of combining components. Therefore, it is difficult to find the structure and components of the optimal posture estimation model for input data. Compared with conventional millimeter wave-based posture estimation studies, it is possible to explore the structure and components of the optimal posture estimation model for input data using genetic algorithms, and the performance of optimizing the proposed posture estimation model is excellent. Data are collected for actual unmanned stores, and point cloud data and three-dimensional keypoint information of Kinect Azure are collected using millimeter wave radar for collapse and property damage occurring in unmanned stores. As a result of the experiment, it was confirmed that the error was moored compared to the conventional posture estimation model.

Research on Core Technology for Information Security Based on Artificial Intelligence (인공지능 기반 정보보호핵심원천기술 연구)

  • Sang-Jun Lee;MIN KYUNG IL;Nam Sang Do;LIM JOON SUNG;Keunhee Han;Hyun Wook Han
    • The Journal of Bigdata
    • /
    • v.6 no.2
    • /
    • pp.99-108
    • /
    • 2021
  • Recently, unexpected and more advanced cyber medical treat attacks are on the rise. However, in responding to various patterns of cyber medical threat attack, rule-based security methodologies such as physical blocking and replacement of medical devices have the limitations such as lack of the man-power and high cost. As a way to solve the problems, the medical community is also paying attention to artificial intelligence technology that enables security threat detection and prediction by self-learning the past abnormal behaviors. In this study, there has collecting and learning the medical information data from integrated Medical-Information-Systems of the medical center and introduce the research methodology which is to develop the AI-based Net-Working Behavior Adaptive Information data. By doing this study, we will introduce all technological matters of rule-based security programs and discuss strategies to activate artificial intelligence technology in the medical information business with the various restrictions.

Study on Factors for Passenger Risk in Railway Vehicle (철도차량내 승객 위험요소 선정 연구)

  • Park, Won-Hee;Park, Sung-Joon;Kim, Hyo-Jin;Kim, HanSaem;Oh, Sechan
    • Journal of the Society of Disaster Information
    • /
    • v.17 no.4
    • /
    • pp.733-746
    • /
    • 2021
  • Purpose: This study was conducted for the purpose of selecting important events from among various events that may pose a risk to railway passengers. For this purpose, opinions of various railroad vehicle passengers and railway operator workers were investigated and analyzed. Method: The survey was conducted on 1,000 men and women in their 20s and 60s and 429 workers at 11 company across the country. A survey was conducted on the dangerous situations that may occur in subways, general railroads and high-speed rail vehicles targeting passengers. For railway operator workers, the questionnaire is limited to subway vehicles. Result: Among the passenger risk factors(abnormal behavior and dangerous situations) selected based on the frequency and importance of occurrence of passenger risk factors, the main risk factors are selected 'car door jamming', 'sexual harassment', 'intoxicating behavior', 'fighting' /assault', 'wandering around', and 'not wearing a mask'. Conclusion: The major risk factors affecting passengers were selected by surveying passengers and railway operators. we plan to develop a CCTV detection system with AI technology that can quickly and continuously detect the major risk factors of railway vehicles selected as a result of this study.

Security Credential Management & Pilot Policy of U.S. Government in Intelligent Transport Environment (지능형 교통 환경에서 미국정부의 보안인증관리 & Pilot 정책)

  • Hong, Jin-Keun
    • Journal of Convergence for Information Technology
    • /
    • v.9 no.9
    • /
    • pp.13-19
    • /
    • 2019
  • This paper analyzed the SCMS and pilot policy, which is pursued by the U.S. government in connected vehicles. SCMS ensures authentication, integrity, privacy and interoperability. The SCMS Support Committee of U.S. government has established the National Unit SCMS and is responsible for system-wide control. Of course, it introduces security policy, procedures and training programs making. In this paper, the need for SCMS to be applied to C-ITS was discussed. The structure of the SCMS was analyzed and the U.S. government's filot policy for connected vehicles was discussed. The discussion of the need for SCMS highlighted the importance of the role and responsibilities of SCMS between vehicles and vehicles. The security certificate management system looked at the structure and analyzed the type of certificate used in the vehicle or road side unit (RSU). The functions and characteristics of the certificates were reviewed. In addition, the functions of basic safety messages were analyzed with consideration of the detection and warning functions of abnormal behavior in SCMS. Finally, the status of the pilot project for connected vehicles currently being pursued by the U.S. government was analyzed. In addition to the environment used for the test, the relevant messages were also discussed. We also looked at some of the issues that arise in the course of the pilot project.

A SURVEY OF INTRAFAMILIAL CHILD SEXUAL ABUSE BY PHYSICIANS' REPORTS (의사들의 보고에 의한 근친간 아동성학대 연구)

  • Hong, Kang-E;Kang, Byung-Goo;Kwack, Young-Sook
    • Journal of the Korean Academy of Child and Adolescent Psychiatry
    • /
    • v.9 no.2
    • /
    • pp.138-147
    • /
    • 1998
  • Authors surveyed intrafamilial child sexual abuse in the children under 15years old in clinical. We sent the semi-structured child sexual abuse questionnaires to 7055 board certified pediatrics, obstetrics and gynecology, family medicine and emergency medicine. Total respondents were 1205. The results from these respondents were as follows. 1) The numbers of respondents who have had the experience of treating victims of intrafamilial child sexual abuses were 157(13.0% of total respondents). 2) Among the perpetrators, 58(36.9%) were siblings and 32(20.4%) 26(16.6%) were step-fathers, and respectively. The most common age bracket was 10s(39.5%), and the next was 40s and 50s (33.7%) Almost all(98.7%) of the perpetrators were male. 3) The mean age of victims was $12.1{\pm}3.3$ years old, and all of the victims were female, and the number of victims who had previous mental or physical handicaps and behavior problems were 5(3.2%) and 8(5.1%) respectively. 4) The ways by which intrafamilial child sexual abuses were found were abnormal behaviors 45(28.7%), victim's own report 40(25.5%), pregnancy 18(11.5%), pain complaint 13(8.3%), other person's report 13(8.3%), and detection during examination 12(7.6%). 5) Time lags between intrafamilial child sexual abuses and hospital visits were after 1 month 97(61.8%), from 1 day to 1 week 29(18.5%), within 1 day 21(13.4%), and from 1 week to 1 month 10(6.4%). 6) Physical complications were perineal wound 93(59.2%), hymen rupture 90(57.3%), pregnancy 68(43.3%), wound of other part of body 11(7.0%), and sexually transmitted disease 4(4.5%). 7) Treatment for victims were discharge 92(58.6%), admission, operation or transfer to a bigger hospital 25(15.9%), psychiatry consult 19(12.1%), report to police(10.9%) and social work consult 3(1.9%). These results suggest that considerable numbers of physicians have had the experience of treating victims of intrafamilial child sexual abuses, and intrafamilial child sexual abuses are the major medical as well as social issue in children in Korea.

  • PDF