Behavior Detection System Development for Unwanted Actions

We design and deploy artificial intelligence systems: from prototype to production-ready solutions. Our team combines expertise in machine learning, data engineering and MLOps to make AI work not in the lab, but in real business.
Showing 1 of 1All 1564 services
Behavior Detection System Development for Unwanted Actions
Complex
~1-2 weeks
Frequently Asked Questions

AI Development Areas

AI Solution Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1251
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    956
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_logo-advance_0.webp
    B2B Advance company logo design
    646
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929

Behavior Detection System Development

A duty operator staring at 16 monitors with 4 cameras each—that's classic. After 20 minutes, attention fades; after an hour, they will miss a real fight. Automatic detection of unwanted behavior solves this problem. We develop systems that see not only 'what' but also 'how': poses, trajectories, context. The difficulty is that the boundary between normal and abnormal is blurred, and high recall requires addressing false positives. The system is built modularly: rule-based detectors for simple scenarios, skeleton analysis for falls and running, deep neural networks for aggression and vandalism. Each module cascades filters to keep precision at 82% and above. Assess automation possibilities for your facility—contact us for a preliminary analysis.

What Behavior Types Does the System Recognize?

Level 1 (rule-based): simple events—line crossing, point accumulation. No ML needed, low CPU. Configured in a day.

Level 2 (pose-based): events based on a human skeleton (MediaPipe / RTMPose). Analysis of joint angles and movement speed. Delivers 90% accuracy on falls without GPU.

Level 3 (video-based): deep video understanding via 3D CNN or Video Transformer. High accuracy, requires GPU. We use the KINETICS-400 dataset for pretraining.

How Does Aggression Detection Work?

A fight is not just two objects in frame—it's characteristic dynamics: sharp arm movements, sudden falls, increased movement speed. We use a 3D CNN trained on 400 classes from KINETICS. The model 'watches' 16 frames (0.5 s) and outputs aggression probability. In practice, precision=82%, recall=88%—better than 90% of operators.

import torch
import torch.nn as nn
from torchvision.models.video import r3d_18, R3D_18_Weights

class FightDetector:
    def __init__(self, model_path: str, threshold: float = 0.7):
        base = r3d_18(weights=R3D_18_Weights.KINETICS400_V1)
        base.fc = nn.Sequential(
            nn.Linear(512, 128),
            nn.GELU(),
            nn.Dropout(0.4),
            nn.Linear(128, 2)  # fight / no_fight
        )
        base.load_state_dict(torch.load(model_path))
        base.eval()
        self.model = base
        self.threshold = threshold

        # Sliding video window
        self.frame_buffer = []
        self.window_size = 16  # 16 frames = ~0.5 sec at 30fps

    def update(self, frame: np.ndarray) -> dict | None:
        """Update buffer and get result"""
        self.frame_buffer.append(frame)
        if len(self.frame_buffer) > self.window_size:
            self.frame_buffer.pop(0)

        if len(self.frame_buffer) == self.window_size:
            return self._classify_window()
        return None

    @torch.no_grad()
    def _classify_window(self) -> dict:
        # [T, H, W, C] → [1, C, T, H, W]
        clip = np.stack(self.frame_buffer)
        clip = torch.from_numpy(clip).float().permute(3, 0, 1, 2)
        clip = self._normalize(clip).unsqueeze(0)

        logits = self.model(clip)
        probs = torch.softmax(logits, dim=1).squeeze()
        fight_prob = float(probs[1])

        return {
            'fight_detected': fight_prob > self.threshold,
            'confidence': fight_prob
        }

What About False Positives?

The main pain of aggression detectors is false positives. Solution: temporal confirmation (N consecutive frames)—cuts 70% of random false positives; multi-evidence fusion (skeleton + video + context)—reduces errors in rooms with glare; human-in-the-loop—sends uncertain cases to the guard, and confirmed ones go to retraining. Ultimately we achieve precision=82% with recall=88% on fights. This saves up to 30% of the guard budget by reducing false alarms.

Technical detail: cascade filtering First level—rule-based (motion trigger), second—pose analysis (posture check), third—3D CNN (event verification). Each level filters out false positives, leaving only confirmed incidents.

Skeleton-based Behavior Analysis

Skeleton analysis enables detection of falls, running, suspicious lingering without costly 3D CNN. It only needs 5–15 FPS and a lightweight neural network. The code below processes trackers over 30 frames and returns the dominant behavior.

import numpy as np
from collections import deque

class BehaviorAnalyzer:
    def __init__(self, window_size: int = 30):
        self.track_history = {}  # track_id -> deque of (frame, keypoints)
        self.window = window_size

    def update(self, track_id: int, frame_num: int,
               keypoints: dict) -> dict:
        if track_id not in self.track_history:
            self.track_history[track_id] = deque(maxlen=self.window)
        self.track_history[track_id].append((frame_num, keypoints))

        if len(self.track_history[track_id]) < 10:
            return {'behavior': 'unknown'}

        return self._analyze(track_id)

    def _analyze(self, track_id: int) -> dict:
        history = list(self.track_history[track_id])
        keypoints_seq = [kp for _, kp in history]

        behaviors = {
            'fall': self._detect_fall(keypoints_seq),
            'running': self._detect_running(keypoints_seq),
            'crouching': self._detect_crouching(keypoints_seq[-1]),
            'loitering': self._detect_loitering(keypoints_seq)
        }

        dominant = max(behaviors, key=lambda k: behaviors[k])
        return {
            'behavior': dominant if behaviors[dominant] > 0.5 else 'normal',
            'scores': behaviors
        }

    def _detect_fall(self, seq: list) -> float:
        """Fall detection: sharp drop of center of mass"""
        hip_ys = []
        for kp in seq:
            if kp.get('left_hip') and kp.get('right_hip'):
                avg_hip_y = (kp['left_hip']['y'] + kp['right_hip']['y']) / 2
                hip_ys.append(avg_hip_y)

        if len(hip_ys) < 10:
            return 0.0

        # Normalized coordinates: y increases downwards
        max_drop = max(hip_ys[-5:]) - min(hip_ys[-15:-5]) if len(hip_ys) >= 15 else 0
        return min(1.0, max_drop / 0.3)  # 0.3 = 30% of frame height

    def _detect_loitering(self, seq: list) -> float:
        """Loitering detection: person stays in one place for a long time"""
        if len(seq) < 20:
            return 0.0
        positions = [(kp.get('nose', {}).get('x', 0.5),
                      kp.get('nose', {}).get('y', 0.5))
                     for kp in seq]
        positions = np.array(positions)
        spread = np.std(positions, axis=0).mean()
        return min(1.0, (0.05 - spread) / 0.05)  # < 5% spread = loitering

Rule-based vs Deep Learning: When to Choose What

For counters and line crossing, rule-based is faster and cheaper. For fights and vandalism, only deep learning works. Skeleton analysis (pose) is the sweet spot: gives 90% accuracy on falls without heavy GPU. In our practice, combining rule-based + pose saves up to 50% of the computing budget.

What's Included in the Work

  • Documentation: scenario specification, architecture diagram, alert API description.
  • Deliverables: Docker images with models, config repository, deployment instructions.
  • Integration: adaptation to VMS (Milestone, Genetec, TRASSIR) or RTSP streams.
  • Training: a session for operators and administrators (up to 4 hours).
  • Support: 3 months of warranty maintenance, model updates upon retraining.

Turnkey Implementation Process

  1. Analysis of scenarios and zones at the site (1–2 days).
  2. Collection and labeling of data (if retraining needed).
  3. Architecture selection: rule-based, pose, 3D CNN, or hybrid.
  4. Integration with existing video surveillance system.
  5. Cascade filtering and sensitivity tuning.
  6. Testing on historical recordings and launch 24/7.

Timelines start from 4 weeks for a basic solution. Order a pilot on two cameras and see results in two weeks.

Behavior Type Precision Recall
Fall 91% 94%
Running/Rushing 88% 92%
Aggression/Fight 82% 88%
Vandalism 79% 83%
Pickpocketing 74% 79%
Scale Timeline
2–3 event types, rule-based + pose 4–6 weeks
Full behavior analytics 9–14 weeks
High-precision system with training 14–22 weeks

Over 50 deployments in retail, logistics, and offices—our team has 5+ years of experience in Computer Vision. We'll assess your project free of charge; reach out to us.

How Distribution Shift Kills CV Model Metrics in Industry

On a production line, a camera is installed to control product quality. The model is trained on 10,000 labeled images—test accuracy mAP 0.84. Deployed to production, and in the first week it misses 30% of defects. Lighting on the line changes between shifts; distribution shift nullifies the metrics. This is a classic story with computer vision in industry, where pattern recognition fails without proper drift handling.

Our engineers, with experience from 60+ computer vision projects, know how to eliminate such scenarios. We guarantee stable model performance under real conditions.

Object Detection: YOLO, RT-DETR, and Everything in Between

YOLO is the standard for real-time detection. YOLOv8 and YOLOv11 from Ultralytics are the most used versions in production: simple API, active community, built-in validation, and export to ONNX/TensorRT. For tasks with high accuracy requirements and less critical latency, RT-DETR, a transformer-based architecture without NMS, gives better mAP on COCO at comparable speed to YOLOv8l.

Architecture mAP on COCO (val2017) FPS (A10G, FP16) Deployment Complexity
YOLOv8n 37.3 700+ Low (ONNX/TensorRT)
YOLOv8m 50.2 250 Low
RT-DETR-L 53.0 140 Medium (requires PyTorch)
Mask R-CNN 38.2 (bbox) 30 High

A typical mistake when training a detector: dataset of 8000 images, 3 classes, fine-tune YOLOv8m—F1 0.73 on validation. Look at confusion matrix—one class is almost never detected. Cause: imbalance 1:23. Solution: oversampling rare class, focal loss for objectness, augmentations (Mosaic, MixUp disabled for rare class as they "blur" it). Transfer learning is mandatory: pretrained on COCO weights reduces data requirement by 10 times. Fine-tuning on 500–2000 domain images yields a working model in 1–2 days on a single GPU.

For edge deployment: export to ONNX → TensorRT engine. YOLOv8n in TensorRT FP16 on Jetson AGX Orin gives 150+ FPS at P99 latency < 8 ms—3 times faster than ONNX Runtime without TensorRT. On server A10G: 700+ FPS for YOLOv8n in TensorRT INT8.

How Does Fine-Tuning YOLO Help in Pattern Recognition?

Suppose you need to find micro-defects on a metal surface—a task with high resolution and class imbalance. We use YOLOv8m pretrained on COCO and fine-tune on 2000 proprietary images. Apply augmentations Mosaic, MixUp, random perspective. After 200 epochs, mAP 0.5 reaches 0.93. Key techniques:

  • Focal loss for the objectness head—reduces contribution of easily classified examples.
  • Class-balanced sampling—equalizes representation of rare classes.
  • Test Time Augmentation (TTA)—increases recall by 5–7% through averaging over flips and scales.

Get a consultation on architecture selection for your task—contact us.

Segmentation: SAM, Mask R-CNN, and Instance Segmentation

SAM (Segment Anything Model) from Meta changed the approach to segmentation. SAM 2 works with video, supports object tracking across frames—for interactive object selection by point or bbox, it's the best out-of-the-box choice. For production instance segmentation without interactive prompting, Mask R-CNN or YOLOv8-seg are used. YOLOv8-seg trains like a regular detector with additional masks, convenient in the same pipelines. Semantic segmentation (each pixel is a class) uses SegFormer, DeepLabV3+. SegFormer-B5 provides a good balance of accuracy and speed for satellite imagery or medical segmentation.

Case study: cell segmentation on microscopic images. Dataset of 400 images with manual annotation. Training Mask R-CNN on ResNet-50 backbone gave IoU 0.61—poor. Problem: objects (cells) overlap; standard NMS kills overlapping predictions. Solution: switch to cellpose (specialized architecture for biomedical tasks) + soft-NMS. IoU increased to 0.79.

OCR: When Tesseract Fails

Tesseract is a starting point for simple tasks: printed text, good lighting, straight layout. As soon as there are handwritten elements, non-standard fonts, perspective distortions, or multi-column layouts, Tesseract degrades quickly.

PaddleOCR is a production-grade solution: text block detection + recognition + structural analysis. Works out of the box for 80+ languages, including Russian. Supports tables and complex document structures. TrOCR (Microsoft) is a transformer OCR with strong results on handwritten text. For Russian handwritten text, fine-tuning is needed: the base model is trained mostly on Latin script.

What to Do When Tesseract Cannot Handle Pattern Recognition on Documents?

For tasks like "extract data from invoices/contracts/passports," we use LayoutLMv3 or Donut—these models understand document layout, not just text. Integration via Hugging Face Transformers, fine-tuning on 200–500 annotated documents. Typical pipeline:

  1. Preprocessing: deskew, denoising, binarization via OpenCV.
  2. Text block detection: PaddleOCR detection or CRAFT.
  3. Recognition: PaddleOCR recognition or TrOCR.
  4. Post-processing: normalization, validation via regex or LLM for structured fields.

For documents with fixed structure, template matching + OCR by coordinates is often more reliable than an end-to-end solution.

Face Recognition: Identification and Verification

Face recognition = detection + alignment + embedding + matching. Each stage matters.

Detection: RetinaFace or InsightFace for accurate face localization and keypoints. MTCNN is older but reliable. Embedding: ArcFace (InsightFace) is state-of-the-art for face recognition embeddings. Models iresnet50/iresnet100 pretrained on MS1MV3 (5M identities). Embedding vector 512 float32, comparison by cosine similarity. Threshold tuning: decision threshold is a critical parameter. At threshold 0.6, typical FPR on LFW benchmark is 0.001, TPR is 0.985. In production, threshold must be calibrated to the real distribution: people in masks, with changed appearance, different lighting conditions. Liveness detection is mandatory: MiniFASNet—lightweight model on CPU; FaceX-Zoo contains several pretrained liveness detectors.

Video Analytics

Video is a sequence of frames plus a temporal dimension. A naive approach—detecting on every frame—is expensive.

Tracking: ByteTrack and BoT-SORT are the standard for multi-object tracking. They work on top of any detector, adding persistent IDs to objects across frames—enabling object counting, motion tracking, velocity.

Optimization: not every frame needs processing. For static scenes, detect every 5–10 frames, with tracking in between. For event detection (person entering a zone), background subtraction (OpenCV MOG2) serves as a lightweight pre-filter before neural detection. Action recognition: SlowFast, VideoMAE for action classification. Heavy models—for production use ONNX export + TensorRT or offline processing.

How to Measure Pattern Recognition Model Quality in Production?

Quality monitoring is key to MLOps. We track:

  • Prediction confidence distribution.
  • Share of low-confidence predictions (indicator of OOD data).
  • Drift of input images via feature distribution (embeddings from backbone).

A drop in average confidence from 0.87 to 0.71 over a week is an early signal of distribution shift. NVIDIA Triton Inference Server recommends tracking these metrics via Prometheus. Our certified engineers set up monitoring and guarantee SLA for inference quality.

Deployment of CV Models

For online inference, we use Triton Inference Server (NVIDIA)—production standard for serving CV models. Supports TensorRT, ONNX, PyTorch, dynamic batching, multiple instances. REST and gRPC API. We guarantee stable operation under load.

Edge deployment: ONNX Runtime on ARM/x86 CPU. TensorFlow Lite for mobile devices. OpenVINO for Intel CPU/GPU/VPU—gives 2–3× speedup on Intel hardware compared to ONNX Runtime. After deployment, we hand over the model with documentation and train personnel.

What Is Included in the Work

Stage Content Estimated Time
Analysis Technical specification, architecture selection, data evaluation 3–5 days
Labeling Image collection, annotation (up to 5000 objects) 1–3 weeks
Training Model fine-tuning, validation on test set 1–2 weeks
Optimization Export to ONNX/TensorRT/OpenVINO, testing on target hardware 1–2 weeks
Integration REST/gRPC API, integration with existing infrastructure 1–2 weeks
Deployment Deployment on server or edge device, load testing 1 week
Documentation and training Instructions, staff training, handover of code and model 3–5 days
Support Technical support for 3 months after launch

Deadlines and Cost

A prototype detector on existing data takes 1–2 weeks. Production system with optimization for target hardware takes 4–8 weeks. Full cycle including data labeling (1000–5000 images) takes 2–4 months. Cost is calculated individually for each task. Typical savings from implementing a quality control system can be significant per production line.

We have been in the market for over 5 years and completed 60+ computer vision projects. We will evaluate your project end-to-end—request a consultation to get a quote and technical proposal.