Intrusion Detection Video Analytics – AI-Powered with <1 False Alarm/HR

We design and deploy artificial intelligence systems: from prototype to production-ready solutions. Our team combines expertise in machine learning, data engineering and MLOps to make AI work not in the lab, but in real business.
Showing 1 of 1All 1564 services
Intrusion Detection Video Analytics – AI-Powered with <1 False Alarm/HR
Medium
~5 days
Frequently Asked Questions

AI Development Areas

AI Solution Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1251
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    957
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_logo-advance_0.webp
    B2B Advance company logo design
    646
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929

Imagine a bank server room, 3:00 AM. The camera detects motion – the system triggers an alarm, security dispatches a team, but it's just a plastic bag falling off a shelf. On a site with 20 cameras, up to 30% of all alarms are false. Operators get used to ignoring warnings, and a real intrusion goes unnoticed. Each false alarm carries potential liability or administrative fines. We solve this with a two-tier detection architecture that filters out 90% of empty frames while achieving recall >95% with <1 false alarm per hour per camera. Below are the technical details.

How does the two-tier architecture filter out 90% of empty frames?

The first tier is a motion pre-filter based on the MOG2 background subtractor. It's faster than a neural network – latency <5 ms per frame. If the motion level is below a threshold (0.001), the frame is skipped: no ML inference is triggered. This saves GPU resources – load drops by a factor of 3–5. The second tier is YOLO detection with zone-based filtering.

import cv2
import numpy as np
from ultralytics import YOLO

class IntrusionDetector:
    def __init__(self, model_path: str, zone_polygon: list,
                 sensitivity: str = 'medium'):
        self.detector = YOLO(model_path)
        self.zone = np.array(zone_polygon, dtype=np.int32)
        self.bg_subtractor = cv2.createBackgroundSubtractorMOG2(
            history=500,
            varThreshold=16,
            detectShadows=True
        )
        self.conf_thresholds = {'low': 0.7, 'medium': 0.5, 'high': 0.3}
        self.conf = self.conf_thresholds[sensitivity]
        self.confirmed_tracks = {}
        self.confirmation_frames = 3

    def detect(self, frame: np.ndarray) -> dict:
        result = {'intrusion_detected': False, 'intruders': [], 'motion_level': 0.0}
        fg_mask = self.bg_subtractor.apply(frame)
        fg_mask[fg_mask == 127] = 0
        motion_level = float(fg_mask.sum()) / (frame.shape[0] * frame.shape[1])
        result['motion_level'] = motion_level
        if motion_level < 0.001:
            return result
        detections = self.detector(frame, conf=self.conf, classes=[0,2,3,5,7])
        for box in detections[0].boxes:
            x1,y1,x2,y2 = map(int, box.xyxy[0])
            cx,cy = (x1+x2)//2, (y1+y2)//2
            in_zone = cv2.pointPolygonTest(self.zone, (float(cx),float(cy)), False) >=0
            if in_zone:
                result['intruders'].append({
                    'class': self.detector.model.names[int(box.cls)],
                    'confidence': float(box.conf),
                    'bbox': [x1,y1,x2,y2],
                    'center': (cx,cy)
                })
        if result['intruders']:
            result['intrusion_detected'] = True
        return result

This approach runs the neural network only on frames with motion. In practice, it reduces GPU load from 100% to 20–30%, which is especially important when processing 8–16 cameras in parallel on a single server.

Why does area filtering and frame confirmation keep false alarms below 1 per hour?

False alarms are usually caused by small animals, falling leaves, or shadows. We apply two filters. First, a minimum bounding box area (2000 pixels): objects smaller than this are not considered intrusions. Second, confirmation over 3 consecutive frames: if the object disappears on the next frame, the alarm is not raised.

class FalsePositiveFilter:
    def __init__(self):
        self.event_buffer = []
        self.cooldown_seconds = 30

    def should_trigger_alarm(self, intrusion_event: dict, current_time: float) -> bool:
        for intruder in intrusion_event.get('intruders', []):
            x1,y1,x2,y2 = intruder['bbox']
            area = (x2-x1)*(y2-y1)
            if area < 2000:
                return False
        if self.event_buffer:
            last_event_time = self.event_buffer[-1]
            if current_time - last_event_time < self.cooldown_seconds:
                return False
        self.event_buffer.append(current_time)
        self.event_buffer = self.event_buffer[-10:]
        return True

This combination yields a consistently low false alarm rate – less than 1 per hour per camera while maintaining recall >95%.

Multi-zone configuration with schedules and whitelists

Each zone is defined by a polygon with parameters: alert_level (warning/critical), schedule (always/after_hours), and a list of allowed_persons. For example, a server room can be configured as critical, active only during off-hours, and ignore authorized staff.

zones_config = {
    'perimeter': {
        'polygon': [[0,300],[1920,300],[1920,1080],[0,1080]],
        'alert_level': 'warning',
        'schedule': 'always'
    },
    'server_room': {
        'polygon': [[500,200],[900,200],[900,600],[500,600]],
        'alert_level': 'critical',
        'schedule': 'after_hours',
        'allowed_persons': ['id_001', 'id_002']
    }
}

Such flexibility lets you tailor the system to any scenario – from a low-priority perimeter to critical zones with employee whitelists.

Low-light operation: IR and thermal cameras

Standard RGB cameras are unsuitable for detection in complete darkness. The solution is to use IR illuminators (850/940 nm) with a model fine-tuned on IR frames, or thermal cameras (FLIR, Axis). Combining RGB and thermal channels yields the best results: detection rate 90–94% at zero lux.

Metric Typical Value
Detection Rate (recall) 95–98%
False Alarm Rate < 2 per hour (good conditions)
Latency to alarm < 2 seconds
Low-light operation (IR) 90–94% DR
Scale Deployment timeline
1–4 cameras, simple zones 2–3 weeks
8–20 cameras, complex zones + schedules 4–7 weeks
50+ cameras, PSIM integration 10–16 weeks

What's included

  • Documentation: architecture diagram, zone configuration files, operator manual.
  • Access to: code repository, metrics dashboard, REST API for integration.
  • Training: 2-hour webinar for security and administrative staff.
  • Support: 3 months of free maintenance with incident response within 24 hours.

Deployment process: from audit to support

  1. Site analysis. On-site engineer visit, measuring illumination, camera placements, creating zone maps.
  2. Design. Choosing architecture (single-server vs distributed), preparing configurations.
  3. Development. Customizing YOLOv8 model on your footage (RGB, IR, thermal). Adding data augmentation: night, fog, rain.
  4. Integration. Connecting to existing video surveillance and PSIM systems.
  5. Testing. Running scenarios: real intrusions, noise, measuring recall and false alarm rate.
  6. Documentation and training. Operator manual, handover of code and configurations.
  7. Support. 3 months of free maintenance with incident response within 24 hours.

At each stage you receive a report and a demo of results.

Example cost savings calculation With 10 false alarms per day, an operator spends 5 minutes per check – 30 hours per month. At an operator salary of $1200/month, savings from reduced false alarms exceed $4,500/year. For a 20-camera system, the deployment pays for itself in 4–6 months.

Ensuring stable accuracy: tracking and data augmentation

To prevent losing targets during temporary occlusions, we use object tracking based on the SORT algorithm. Additionally, each model is trained with augmentation: night frames, fog, rain, glare. This guarantees stable operation in any weather and lighting conditions. Our team has 5+ years of experience in Computer Vision and has delivered over 30 video analytics projects of varying complexity.

Get a consultation for your site – our engineers will find the optimal solution. Order a pilot project on 2 cameras and see the technology in action. Contact us for a detailed audit.

How Distribution Shift Kills CV Model Metrics in Industry

On a production line, a camera is installed to control product quality. The model is trained on 10,000 labeled images—test accuracy mAP 0.84. Deployed to production, and in the first week it misses 30% of defects. Lighting on the line changes between shifts; distribution shift nullifies the metrics. This is a classic story with computer vision in industry, where pattern recognition fails without proper drift handling.

Our engineers, with experience from 60+ computer vision projects, know how to eliminate such scenarios. We guarantee stable model performance under real conditions.

Object Detection: YOLO, RT-DETR, and Everything in Between

YOLO is the standard for real-time detection. YOLOv8 and YOLOv11 from Ultralytics are the most used versions in production: simple API, active community, built-in validation, and export to ONNX/TensorRT. For tasks with high accuracy requirements and less critical latency, RT-DETR, a transformer-based architecture without NMS, gives better mAP on COCO at comparable speed to YOLOv8l.

Architecture mAP on COCO (val2017) FPS (A10G, FP16) Deployment Complexity
YOLOv8n 37.3 700+ Low (ONNX/TensorRT)
YOLOv8m 50.2 250 Low
RT-DETR-L 53.0 140 Medium (requires PyTorch)
Mask R-CNN 38.2 (bbox) 30 High

A typical mistake when training a detector: dataset of 8000 images, 3 classes, fine-tune YOLOv8m—F1 0.73 on validation. Look at confusion matrix—one class is almost never detected. Cause: imbalance 1:23. Solution: oversampling rare class, focal loss for objectness, augmentations (Mosaic, MixUp disabled for rare class as they "blur" it). Transfer learning is mandatory: pretrained on COCO weights reduces data requirement by 10 times. Fine-tuning on 500–2000 domain images yields a working model in 1–2 days on a single GPU.

For edge deployment: export to ONNX → TensorRT engine. YOLOv8n in TensorRT FP16 on Jetson AGX Orin gives 150+ FPS at P99 latency < 8 ms—3 times faster than ONNX Runtime without TensorRT. On server A10G: 700+ FPS for YOLOv8n in TensorRT INT8.

How Does Fine-Tuning YOLO Help in Pattern Recognition?

Suppose you need to find micro-defects on a metal surface—a task with high resolution and class imbalance. We use YOLOv8m pretrained on COCO and fine-tune on 2000 proprietary images. Apply augmentations Mosaic, MixUp, random perspective. After 200 epochs, mAP 0.5 reaches 0.93. Key techniques:

  • Focal loss for the objectness head—reduces contribution of easily classified examples.
  • Class-balanced sampling—equalizes representation of rare classes.
  • Test Time Augmentation (TTA)—increases recall by 5–7% through averaging over flips and scales.

Get a consultation on architecture selection for your task—contact us.

Segmentation: SAM, Mask R-CNN, and Instance Segmentation

SAM (Segment Anything Model) from Meta changed the approach to segmentation. SAM 2 works with video, supports object tracking across frames—for interactive object selection by point or bbox, it's the best out-of-the-box choice. For production instance segmentation without interactive prompting, Mask R-CNN or YOLOv8-seg are used. YOLOv8-seg trains like a regular detector with additional masks, convenient in the same pipelines. Semantic segmentation (each pixel is a class) uses SegFormer, DeepLabV3+. SegFormer-B5 provides a good balance of accuracy and speed for satellite imagery or medical segmentation.

Case study: cell segmentation on microscopic images. Dataset of 400 images with manual annotation. Training Mask R-CNN on ResNet-50 backbone gave IoU 0.61—poor. Problem: objects (cells) overlap; standard NMS kills overlapping predictions. Solution: switch to cellpose (specialized architecture for biomedical tasks) + soft-NMS. IoU increased to 0.79.

OCR: When Tesseract Fails

Tesseract is a starting point for simple tasks: printed text, good lighting, straight layout. As soon as there are handwritten elements, non-standard fonts, perspective distortions, or multi-column layouts, Tesseract degrades quickly.

PaddleOCR is a production-grade solution: text block detection + recognition + structural analysis. Works out of the box for 80+ languages, including Russian. Supports tables and complex document structures. TrOCR (Microsoft) is a transformer OCR with strong results on handwritten text. For Russian handwritten text, fine-tuning is needed: the base model is trained mostly on Latin script.

What to Do When Tesseract Cannot Handle Pattern Recognition on Documents?

For tasks like "extract data from invoices/contracts/passports," we use LayoutLMv3 or Donut—these models understand document layout, not just text. Integration via Hugging Face Transformers, fine-tuning on 200–500 annotated documents. Typical pipeline:

  1. Preprocessing: deskew, denoising, binarization via OpenCV.
  2. Text block detection: PaddleOCR detection or CRAFT.
  3. Recognition: PaddleOCR recognition or TrOCR.
  4. Post-processing: normalization, validation via regex or LLM for structured fields.

For documents with fixed structure, template matching + OCR by coordinates is often more reliable than an end-to-end solution.

Face Recognition: Identification and Verification

Face recognition = detection + alignment + embedding + matching. Each stage matters.

Detection: RetinaFace or InsightFace for accurate face localization and keypoints. MTCNN is older but reliable. Embedding: ArcFace (InsightFace) is state-of-the-art for face recognition embeddings. Models iresnet50/iresnet100 pretrained on MS1MV3 (5M identities). Embedding vector 512 float32, comparison by cosine similarity. Threshold tuning: decision threshold is a critical parameter. At threshold 0.6, typical FPR on LFW benchmark is 0.001, TPR is 0.985. In production, threshold must be calibrated to the real distribution: people in masks, with changed appearance, different lighting conditions. Liveness detection is mandatory: MiniFASNet—lightweight model on CPU; FaceX-Zoo contains several pretrained liveness detectors.

Video Analytics

Video is a sequence of frames plus a temporal dimension. A naive approach—detecting on every frame—is expensive.

Tracking: ByteTrack and BoT-SORT are the standard for multi-object tracking. They work on top of any detector, adding persistent IDs to objects across frames—enabling object counting, motion tracking, velocity.

Optimization: not every frame needs processing. For static scenes, detect every 5–10 frames, with tracking in between. For event detection (person entering a zone), background subtraction (OpenCV MOG2) serves as a lightweight pre-filter before neural detection. Action recognition: SlowFast, VideoMAE for action classification. Heavy models—for production use ONNX export + TensorRT or offline processing.

How to Measure Pattern Recognition Model Quality in Production?

Quality monitoring is key to MLOps. We track:

  • Prediction confidence distribution.
  • Share of low-confidence predictions (indicator of OOD data).
  • Drift of input images via feature distribution (embeddings from backbone).

A drop in average confidence from 0.87 to 0.71 over a week is an early signal of distribution shift. NVIDIA Triton Inference Server recommends tracking these metrics via Prometheus. Our certified engineers set up monitoring and guarantee SLA for inference quality.

Deployment of CV Models

For online inference, we use Triton Inference Server (NVIDIA)—production standard for serving CV models. Supports TensorRT, ONNX, PyTorch, dynamic batching, multiple instances. REST and gRPC API. We guarantee stable operation under load.

Edge deployment: ONNX Runtime on ARM/x86 CPU. TensorFlow Lite for mobile devices. OpenVINO for Intel CPU/GPU/VPU—gives 2–3× speedup on Intel hardware compared to ONNX Runtime. After deployment, we hand over the model with documentation and train personnel.

What Is Included in the Work

Stage Content Estimated Time
Analysis Technical specification, architecture selection, data evaluation 3–5 days
Labeling Image collection, annotation (up to 5000 objects) 1–3 weeks
Training Model fine-tuning, validation on test set 1–2 weeks
Optimization Export to ONNX/TensorRT/OpenVINO, testing on target hardware 1–2 weeks
Integration REST/gRPC API, integration with existing infrastructure 1–2 weeks
Deployment Deployment on server or edge device, load testing 1 week
Documentation and training Instructions, staff training, handover of code and model 3–5 days
Support Technical support for 3 months after launch

Deadlines and Cost

A prototype detector on existing data takes 1–2 weeks. Production system with optimization for target hardware takes 4–8 weeks. Full cycle including data labeling (1000–5000 images) takes 2–4 months. Cost is calculated individually for each task. Typical savings from implementing a quality control system can be significant per production line.

We have been in the market for over 5 years and completed 60+ computer vision projects. We will evaluate your project end-to-end—request a consultation to get a quote and technical proposal.