Papers
Topics
Authors
Recent
Search
2000 character limit reached

Detectability of Subtle Anomalies in Dynamical Systems via Log-Likelihood Ratio

Published 13 Apr 2026 in eess.SY | (2604.11631v1)

Abstract: Industrial control applications require detecting system anomalies as accurately and quickly as possible to enable prompt maintenance. In this context, it is common to consider several possible plant models, each linked to a different anomaly. The log-likelihood ratio method can then be used to identify the most accurate model and thereby classify which anomaly, if any, has occurred. Although the method has been applied to a wide variety of systems, there is no formal analysis of what makes anomalies more or less prone to detection. In this paper, we investigate a real-time anomaly detector based on the log-likelihood ratio and provide a theoretical characterization of its error rate when it is applied to linear Gaussian systems. We showcase the performance of this algorithm and the characterization obtained, and demonstrate how the latter can be leveraged for observer design.

Summary

  • The paper presents a closed-form analytical characterization of the cumulative log-likelihood ratio method for detecting subtle anomalies in linear Gaussian systems.
  • It quantifies detection error rates using a Fisher information metric and assesses the impact of temporal correlation on effective sample size.
  • It demonstrates practical applications in an inverted double pendulum and observer design, highlighting trade-offs between innovation variance and anomaly detectability.

Detectability of Subtle Anomalies in Dynamical Systems via Log-Likelihood Ratio

Introduction

The identification of subtle system anomalies in industrial and safety-critical systems demands detection mechanisms with quantified sensitivity and reliability. "Detectability of Subtle Anomalies in Dynamical Systems via Log-Likelihood Ratio" (2604.11631) rigorously analyzes the statistical performance of cumulative log-likelihood ratio (LLR) methods for anomaly detection in linear Gaussian dynamical systems. The work provides closed-form analytical characterizations of detection error rates, establishes connections to Fisher information, and demonstrates implications for both anomaly detection and observer design.

Problem Formulation and LLR-Based Anomaly Detection

The detection paradigm centers on discrete-time linear systems with additive, zero-mean Gaussian process and measurement noise, modeled as

xk+1=Axk+wk,yk=Cxk+vkx_{k+1} = Ax_k + w_k, \qquad y_k = Cx_k + v_k

with wkN(0,Q)w_k \sim \mathcal{N}(0,Q), vkN(0,R)v_k \sim \mathcal{N}(0,R). The actual system differs from the nominal model Π\Pi_* by small parametric deviations. These deviations are parameterized by weights γ\gamma, so that the real system is a linear combination of the nominal model and deviation directions.

Detection is formalized as model discrimination between hypothesized systems Πα\Pi_\alpha and Πβ\Pi_\beta, with the cumulative log-likelihood ratio (LLR) statistic employed to decide which hypothesis better explains an observed measurement sequence. For hypotheses characterized by deviations α\alpha and β\beta,

L({yk}k=1Nα,β)=12(NlogΣβΣα+k=1Nyk(Σβ1Σα1)yk)\mathcal{L}(\{y_k\}_{k=1}^N \mid \alpha, \beta) = \frac{1}{2} \Big( N \log \frac{|\Sigma_\beta|}{|\Sigma_\alpha|} + \sum_{k=1}^N y_k^\top(\Sigma_\beta^{-1} - \Sigma_\alpha^{-1}) y_k \Big)

where wkN(0,Q)w_k \sim \mathcal{N}(0,Q)0, wkN(0,Q)w_k \sim \mathcal{N}(0,Q)1 are the implied steady-state output covariances.

Statistical Characterization of the LLR and Analytical Bounds

By leveraging the asymptotic normality of the LLR, the mean and variance of the test statistic can be computed in closed form under both the null and alternative system hypotheses. The key theoretical contribution is the quadratic approximation for the distribution's mean and variance as functions of the deviation parameters and a Fisher information-weighted metric wkN(0,Q)w_k \sim \mathcal{N}(0,Q)2, where

wkN(0,Q)w_k \sim \mathcal{N}(0,Q)3

resulting in

wkN(0,Q)w_k \sim \mathcal{N}(0,Q)4

where wkN(0,Q)w_k \sim \mathcal{N}(0,Q)5 is the true deviation. The expression directly yields the error probability for the LLR-based test, quantifying the exponential decay of false positive rates as a function of information content and the number of observations. Figure 1

Figure 1: 2000 Monte-Carlo sample paths of the cumulative log-likelihood ratio for the stabilized inverted double pendulum; lower panel shows empirical and theoretical error rates with shaded confidence bounds.

This analytical quantification enables evaluating the minimal number of measurements required for a prescribed detection confidence, explicitly reveals the influence of deviation directionality and magnitude, and allows practical deployment through data-driven or model-based estimation of wkN(0,Q)w_k \sim \mathcal{N}(0,Q)6.

Effects of Temporal Correlation and Adjusted Detection Thresholds

While the analytical derivations take i.i.d. measurements as their starting point, the work carefully addresses the colored nature of measurement noise in dynamical systems. Through detailed analysis, it is shown that temporal correlation inflates the variance of the LLR, reducing effective sample size and slowing convergence of error rates. The authors develop a heuristic correction, where the effective standard deviation is adjusted according to the largest closed-loop eigenvalue, yielding adjusted theoretical bounds.

Practical Application: Double Pendulum and Observer Design

The efficacy and implications of the proposed methodology are demonstrated in two salient case studies:

  1. Deviation Detection in an Inverted Double Pendulum: Multiple subtle fault modes (friction and process noise increases) are defined. The metric wkN(0,Q)w_k \sim \mathcal{N}(0,Q)7 is computed, quantifying which deviations are intrinsically more detectable and highlighting nontrivial interactions (off-diagonal entries) where distinct faults produce highly correlated changes in the measurement covariance, complicating discrimination. Figure 2

    Figure 2: Contour maps of wkN(0,Q)w_k \sim \mathcal{N}(0,Q)8 and the Fisher information metric wkN(0,Q)w_k \sim \mathcal{N}(0,Q)9 for different observer gains, delineating the detectability/accuracy trade-off and regions of instability.

  2. Observer Gain Selection for Enhanced Detectability: The LLR detectability metric is used as a performance functional for observer design. It is demonstrated that the classical Kalman filter generally does not maximize anomaly detectability; indeed, there is a tension between minimizing innovation variance (Kalman criterion) and maximizing the Fisher information (detection criterion). By sweeping observer gains, the authors show maximized detectability and innovation variance are reached by distinct gain settings. Figure 3

    Figure 3: Experimental and theoretical error rates for three observer strategies (no observer, Kalman, and Fisher-optimal), demonstrating the theoretical predictions and highlighting observer impact on detection sensitivity.

Implications and Future Directions

The closed-form characterization of LLR-based anomaly detection sensitivity enables:

  • Formal detectability assessment for any hypothesized deviation class, providing guarantees on minimal detectable effect sizes and sample complexity.
  • Quantitative, insight-driven observer design not limited by the traditional minimum-variance framework.
  • Systematic trade-off analysis between observer-induced decorrelation (beneficial for standard inference assumptions, but potentially detrimental to deviation distinguishability) and detectability.

From a theoretical perspective, the explicit connection to Fisher information and the covariance structure of the measurement process strengthens the bridge between statistical decision theory, control, and fault diagnosis. Practically, the results facilitate data-driven calibration of detection thresholds in industrial settings and motivate new frameworks for adaptive observer reconfiguration where detectability is dynamically optimized.

Potential future extensions involve generalizing the approach to non-autonomous systems, addressing input-dependent settings, and scaling up observer design for large-scale or distributed architectures.

Conclusion

This work establishes a rigorous analytical framework for anomaly detectability in stochastic dynamical systems using the cumulative log-likelihood ratio. The provided methodology delivers actionable, theoretically justified guarantees on detection performance and facilitates observer and system architecture co-design for enhanced anomaly sensitivity. This contributes a foundational toolset for robust, quantifiable anomaly detection in engineered systems.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.