Search NASA⌕ Search

SEARCH · Search NASA

Results for “Anomaly detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

Detection of Anomalies in the UV/Vis Reflectances from the Ozone Monitoring Instrument

Various instrumental or geophysical artifacts, such as saturation, stray light, or obstruction of light (either coming from the instrument or related to solar eclipses), negatively impact satellite measured ultraviolet and visible Earthshine radiance spectra and downstream retrievals of atmospheric and surface properties derived from these spectra. In addition, excessive noise such as from cosmic ray impacts, prevalent within the South Atlantic Anomaly, can also degrade satellite radiance measurements. Saturation specifically pertains to observations of very bright surfaces such as sun glint over open water or thick clouds. When saturation occurs, additional photoelectric charge generated at the saturated pixel may overflow to pixels adjacent to a saturated area and be reflected as a distorted image in the final sensor output.When these effects cannot be corrected to an acceptable level for science quality retrievals, flagging of the affected pixels is indicated. Here, we introduce a straightforward detection method that is based on the correlation, r, between the observed Earthshine radiance and solar irradiance spectraover a 10 nm-spectral range; our Decorrelation Index (DI for brevity) is simply defined as DI=1-r. DI increases with anomalous additive effects or excessive noise in either radiances, the most likely cause indata from theOzone Monitoring Instrument (OMI),or irradiances. DI is relatively straight-forward to use and interpret and can be 20computed for different wavelength intervals. We developed a set of DIs for two spectral channelsof the OMI, a hyperspectral pushbroom imaging spectrometer. For each OMI spatial measurement, we define 14 wavelength-dependent DIs within the OMI visible channel (350-498 nm) and 6 DIs in its ultraviolet 2 (UV2) channel (310-370 nm). As defined, DIs reflect a continuous range of deviations of observed spectra from the reference irradiance spectrum that are complementary to the binary Saturation Possibility Warning (SPW) flags currently provided for each individual spectral/spatial pixel in the OMI radiance data set. Smaller values of DI are also caused by a number of geophysical factors; this allows one to obtain interesting physical results on the global distribution of spectral variations.

Space sensor↗

Integrated System Health Management: Foundational Concepts, Approach, and Implementation

A sound basis to guide the community in the conception and implementation of ISHM (Integrated System Health Management) capability in operational systems was provided. The concept of "ISHM Model of a System" and a related architecture defined as a unique Data, Information, and Knowledge (DIaK) architecture were described. The ISHM architecture is independent of the typical system architecture, which is based on grouping physical elements that are assembled to make up a subsystem, and subsystems combine to form systems, etc. It was emphasized that ISHM capability needs to be implemented first at a low functional capability level (FCL), or limited ability to detect anomalies, diagnose, determine consequences, etc. As algorithms and tools to augment or improve the FCL are identified, they should be incorporated into the system. This means that the architecture, DIaK management, and software, must be modular and standards-based, in order to enable systematic augmentation of FCL (no ad-hoc modifications). A set of technologies (and tools) needed to implement ISHM were described. One essential tool is a software environment to create the ISHM Model. The software environment encapsulates DIaK, and an infrastructure to focus DIaK on determining health (detect anomalies, determine causes, determine effects, and provide integrated awareness of the system to the operator). The environment includes gateways to communicate in accordance to standards, specially the IEEE 1451.1 Standard for Smart Sensors and Actuators.

Figueroa, Fernando↗

Model-agnostic search for dijet resonances with anomalous jet substructure in proton–proton collisions at $\sqrt{s}$ = 13 TeV

This paper presents a model-agnostic search for narrow resonances in the dijet final state in the mass range 1.8-6 TeV. The signal is assumed to produce jets with substructure atypical of jets initiated by light quarks or gluons, with minimal additional assumptions. Search regions are obtained by utilizing multivariate machine-learning methods to select jets with anomalous substructure. A collection of complementary anomaly detection methods - based on unsupervised, weakly supervised, and semisupervised algorithms - are used in order to maximize the sensitivity to unknown new physics signatures. These algorithms are applied to data corresponding to an integrated luminosity of 138 fb -1 , recorded by the CMS experiment at the LHC, at a center-of-mass energy of 13 TeV. No significant excesses above background expectations are seen. Exclusion limits are derived on the production cross section of benchmark signal models varying in resonance mass, jet mass, and jet substructure. Many of these signatures have not been previously sought, making several of the limits reported on the corresponding benchmark models the first ever. When compared to benchmark inclusive and substructure-based search strategies, the anomaly detection methods are found to significantly enhance the sensitivity to a variety of models.

72 PHYSICS OF ELEMENTARY PARTICLES AND FIELDS↗

MetaPoL: Immersive VR based Indoor Patterns of Life (PoL) and Anomalies Data Generation for Insider Threat Modeling in Nuclear Security

Insider threats are perhaps the most serious challenges that nuclear and radiological security systems face. Insiders pose such a great threat due to their access, authority, and knowledge, granting them opportunities to bypass dedicated nuclear and radiological security elements. For example, in one of the latest major insider threat incidents to nuclear security, the Doel-4 nuclear powerplant in Belgium suffered a shutdown, the threat of nuclear materials diversion, and long-term loss of tens of millions of dollars. Seven years of investigation concluded that it was an inside job and attempted sabotage. In this regard, there is an immediate need for R&D and technology integration in the domain of modeling indoor Patterns-of-Life (PoL) and anomaly detection. This can be achieved by using datasets of facility users’ mobility and activity, which can support the design of algorithms for insider threat modeling and detection. However, due to classification, privacy, sensitivity, and safety protocols, such datasets from real physical nuclear reactor facilities are not only hard to share, but also not always feasible to deploy and collect. Aiming to find an alternate solution, our proposed demonstration work - MetaPoL, is the first-ever (for the application space) immersive VR (virtual reality) environment of a real-world secure facility and allows users to move-and-stay through the designed indoor physical layout and also encounter NPCs (non-player characters) that emulate other facility users. In the MetaPoL an interactive user performs realistic spatio-temporal movement, dwelling and activities using a Meta Quest Pro VR headset, and that generates high-frequency (in time) high-resolution (in space) indoor spatial-temporal datasets that are valuable for PoL modeling and anomaly detection research specifically for insider threat modeling and detection mission. Such generated realistic, rich in context, and mission specific datasets can boost AI/Machine Learning based research for modeling and detecting insider threats in nuclear security and nonproliferation.

Gunaratne, Chathika↗

Evaluation of In-Situ AM Process Monitoring Techniques and Potential for Detecting Process Anomalies and Undesirable Microstructures

The US Department of Energy’s Advanced Materials and Manufacturing Technologies (AMMT) program is pursuing rapid qualification of new materials for fabrication of nuclear relevant components using advanced manufacturing techniques. Particular interest is placed on code-qualifying stainless steel (SS) 316H processed by laser powder bed fusion (LPBF) additive manufacturing. A paradigm that incorporates data from in-situ sensing during the printing, ex-situ characterization, and advanced artificial intelligence–based models was established under the Transformation Challenge Reactor (TCR) program to develop a pedigree for each fabricated component that could be tracked from the feedstock to the component’s release for application. Under the TCR program, the Peregrine software was developed as a tool for incorporating the vast amounts of in-situ and ex-situ characterization data collected; all data stored on a rapidly growing digital platform. The digital platform allows for users to link site-specific process anomalies to the macro- and microstructure. The platform will eventually be able to predict component performance, which will be crucial to qualifying materials and components in risk-averse industries such as those supporting and building nuclear reactors. Current in-situ process monitoring techniques that are already integrated with software like Peregrine are advantageous for identifying process anomalies including powder spatter, component edge swelling, recoating-build interactions, and so on. However, additional data are required to fully predict the resulting microstructures needed for identifying relationships to component performance. The rapid cooling rates observed in LPBF are some of the highest of any bulk manufacturing process, resulting in heterogenous microstructures and typically causing anisotropy in mechanical properties. Moreover, evolved residual thermal stresses are high, which can cause severe defects such as delamination or cracking. Therefore, other in-situ monitoring methods are warranted for exploration to measure and map the thermal history, and potentially the stress state, of each build. This report summarizes different in-situ monitoring strategies proposed for LPBF with a focus on the more developed sensor systems. Novel capabilities for measuring melt pool temperatures are also addressed to better inform modeling efforts.

36 MATERIALS SCIENCE↗

Usage of Fault Detection Isolation & Recovery (FDIR) in Constellation (CxP) Launch Operations

This paper will explore the usage of Fault Detection Isolation & Recovery (FDIR) in the Constellation Exploration Program (CxP), in particular Launch Operations at Kennedy Space Center (KSC). NASA's Exploration Technology Development Program (ETDP) is currently funding a project that is developing a prototype FDIR to demonstrate the feasibility of incorporating FDIR into the CxP Ground Operations Launch Control System (LCS). An architecture that supports multiple FDIR tools has been formulated that will support integration into the CxP Ground Operation's Launch Control System (LCS). In addition, tools have been selected that provide fault detection, fault isolation, and anomaly detection along with integration between Flight and Ground elements.

Ferrell, Rob↗

Detecting Risk and Anomalies in Airplane Dynamics Through Entropic Analysis of Time Series Data

Despite recent efforts to move away from traditional threshold exceedance detection methods for aircraft state monitoring, modern aircraft still rely on safety thresholds to communicate to pilots the identification of an anomaly in the aircraft when a threshold is surpassed. Current anomaly detection methods mainly depend on uninterpretable machine learning models to learn complex patterns and relationships contained in the time series data of aircraft. Although these methods are capable of identifying known anomalies, their deficiency in interpretability presents a challenge when translating them to different aircraft. To overcome this deficiency, entropic analysis of aircraft dynamics seeks to characterize the complexity, or lack thereof, of the aircraft dynamics prior to the development of a risk scenario. This complexity characterization provides a more straightforward summary of state changes in the dynamics of flight variables. To build a foundation for entropic analysis, we analyzed the complexity of unstable approaches, an anomalous event present in many of today’s aviation accidents. The analysis revealed a statistically significant difference in the complexity distribution of flight variables under a stable approach versus an unstable approach. These differences in complexity were especially notable minutes before an approach was identified as unstable. Moreover, the multiscale entropic analysis revealed the presence of signal complexity at multiple time scales across multiple time windows before landing. By capturing state changes and corrections in the aircraft dynamics using entropy, advanced, yet still interpretable, sensor systems based on entropic frameworks from this study can be constructed in the future using classical machine learning approaches.

Risk detection↗

Artificial intelligence techniques for ground test monitoring of rocket engines

An expert system is being developed which can detect anomalies in Space Shuttle Main Engine (SSME) sensor data significantly earlier than the redline algorithm currently in use. The training of such an expert system focuses on two approaches which are based on low frequency and high frequency analyses of sensor data. Both approaches are being tested on data from SSME tests and their results compared with the findings of NASA and Rocketdyne experts. Prototype implementations have detected the presence of anomalies earlier than the redline algorithms that are in use currently. It therefore appears that these approaches have the potential of detecting anomalies early eneough to shut down the engine or take other corrective action before severe damage to the engine occurs.

Ali, Moonis↗

Spatio-temporal multivariate cluster evolution analysis for detecting and tracking climate impacts

Recent years have seen a growing concern about climate change and its impacts. While Earth System Models (ESMs) can be invaluable tools for studying the impacts of climate change, the complex coupling processes encoded in ESMs and the large amounts of data produced by these models, together with the high internal variability of the Earth system, can obscure important source-to-impact relationships. Here, this paper presents a novel and efficient unsupervised data-driven approach for detecting statistically-significant impacts and tracing spatio-temporal source-impact pathways in the climate through a unique combination of ideas from anomaly detection, clustering and Natural Language Processing (NLP). Using as an exemplar the 1991 eruption of Mount Pinatubo in the Philippines, we demonstrate that the proposed approach is capable of detecting known post-eruption impacts/events. We additionally describe a methodology for extracting meaningful sequences of post-eruption impacts/events by using NLP to efficiently mine frequent multivariate cluster evolutions, which can be used to confirm or discover the chain of physical processes between a climate source and its impact(s).

Anomaly detection↗

EV SALaD 2023 Demonstration: Best Practices and Mitigations for Protecting EVSE Infrastructure

The Electric Vehicle Secure Architecture Laboratory Demonstration (EV SALaD) program is a demonstration of cybersecurity best practices for high-power electric vehicle (EV) charging infrastructure led by Idaho National Laboratory (INL), in collaboration with other DOE National Laboratories participating in the EVs at Scale Consortium.a Sandia National Laboratories (SNL) and Pacific Northwest National Laboratory (PNNL) participated in the first 2-year (FY22-23) demonstration cycle for EV SALaD. This report documents the FY23 demonstration, the second in a series of demonstrations and collaborations in deploying and operating cybersecure EV charging infrastructure. It includes a summary of improvements from the FY22 demonstration, technical analysis of the FY23 demonstration, how the research demonstrates cyber-physical and cybersecurity best practices for high-power EV charging infrastructure, and related impacts to national and energy security. For EV SALaD, the FY22 demonstration focused on the detection, ranking, and prioritization of anomalous events for high-power EV charging. The FY23 demonstration additionally included the demonstration of cybersecurity best practices, which included protection and mitigation solutions to prevent, respond, and recover from anomalous events. During the demonstrations, the multi-lab EV SALaD team conducted a Test Effect Payload (TEP)b evaluation on extreme fast charger (XFC) hardware equipped with Cerberus, a detection and response solution, to demonstrate anomaly detection and mitigation cybersecurity best practices against cyber-enabled events.

33 ADVANCED PROPULSION SYSTEMS↗

Application of Data Cubes for Improving Detection of Water Cycle Extreme Events

As part of an ongoing NASA-funded project to remove a longstanding barrier to accessing NASA data (i.e., accessing archived time-step array data as point-time series), for the hydrology and other point-time series-oriented communities, "data cubes" are created from which time series files (aka "data rods") are generated on-the-fly and made available as Web services from the Goddard Earth Sciences Data and Information Services Center (GES DISC). Data cubes are data as archived rearranged into spatio-temporal matrices, which allow for easy access to the data, both spatially and temporally. A data cube is a specific case of the general optimal strategy of reorganizing data to match the desired means of access. The gain from such reorganization is greater the larger the data set. As a use case of our project, we are leveraging existing software to explore the application of the data cubes concept to machine learning, for the purpose of detecting water cycle extreme events, a specific case of anomaly detection, requiring time series data. We investigate the use of support vector machines (SVM) for anomaly classification. We show an example of detection of water cycle extreme events, using data from the Tropical Rainfall Measuring Mission (TRMM).

water cycle extreme events↗

System for Anomaly and Failure Detection (SAFD) system development

The System for Anomaly and Failure Detection (SAFD) algorithm was developed as an improvement over the current redline system used in the Space Shuttle Main Engine Controller (SSMEC). Simulation tests and execution against previous hot fire tests demonstrated that the SAFD algorithm can detect engine failures as much as tens of seconds before the redline system recognized the failure. Although the current algorithm only operates during steady state conditions (engine not throttling), work is underway to expand the algorithm to work during transient conditions. This task assignment originally specified developing a platform for executing the algorithm during hot fire tests at Technology Test Bed (TTB) and installing the SAFD algorithm on that platform. Two units were built and installed in the Hardware Simulation Lab and at the TTB in December 1991. Since that time, the task primarily entailed improvement and maintenance of the systems, additional testing to prove the feasibility of the algorithm, and support of hot fire testing. This document addresses the work done since the last report of June 1992. The work on the System for Anomaly and Failure Detection during this period included improving the platform and the algorithm, testing the algorithm against previous test data and in the Hardware Simulation Lab, installing other algorithms on the system, providing support for operations at the Technology Test Bed, and providing routine maintenance.

Oreilly, D.↗

Towards Reliable Evaluation of Anomaly-Based Intrusion Detection Performance

This report describes the results of research into the effects of environment-induced noise on the evaluation process for anomaly detectors in the cyber security domain. This research was conducted during a 10-week summer internship program from the 19th of August, 2012 to the 23rd of August, 2012 at the Jet Propulsion Laboratory in Pasadena, California. The research performed lies within the larger context of the Los Angeles Department of Water and Power (LADWP) Smart Grid cyber security project, a Department of Energy (DoE) funded effort involving the Jet Propulsion Laboratory, California Institute of Technology and the University of Southern California/ Information Sciences Institute. The results of the present effort constitute an important contribution towards building more rigorous evaluation paradigms for anomaly-based intrusion detectors in complex cyber physical systems such as the Smart Grid. Anomaly detection is a key strategy for cyber intrusion detection and operates by identifying deviations from profiles of nominal behavior and are thus conceptually appealing for detecting "novel" attacks. Evaluating the performance of such a detector requires assessing: (a) how well it captures the model of nominal behavior, and (b) how well it detects attacks (deviations from normality). Current evaluation methods produce results that give insufficient insight into the operation of a detector, inevitably resulting in a significantly poor characterization of a detectors performance. In this work, we first describe a preliminary taxonomy of key evaluation constructs that are necessary for establishing rigor in the evaluation regime of an anomaly detector. We then focus on clarifying the impact of the operational environment on the manifestation of attacks in monitored data. We show how dynamic and evolving environments can introduce high variability into the data stream perturbing detector performance. Prior research has focused on understanding the impact of this variability in training data for anomaly detectors, but has ignored variability in the attack signal that will necessarily affect the evaluation results for such detectors. We posit that current evaluation strategies implicitly assume that attacks always manifest in a stable manner; we show that this assumption is wrong. We describe a simple experiment to demonstrate the effects of environmental noise on the manifestation of attacks in data and introduce the notion of attack manifestation stability. Finally, we argue that conclusions about detector performance will be unreliable and incomplete if the stability of attack manifestation is not accounted for in the evaluation strategy.

cyber defense↗