control//fault diagnosis//change detection//CUSUM

CUSUM is a sequential change-detection test that adds up how far each sample of a residual exceeds a small allowance and raises an alarm when the running total passes a limit, and it is used to catch small persistent shifts that an instantaneous threshold never sees: a bearing running half a degree hotter than its model predicts, a sensor bias creeping in over days, a GPS position dragged slowly by a spoofer. E. S. Page proposed it in 1954 for quality control, and it fits in any PLC or flight controller, at three operations per sample.


CUSUM is a sequential change-detection test that adds up how far each sample of a residual exceeds a small allowance and raises an alarm when the running total passes a limit, and it is used to catch small persistent shifts that an instantaneous threshold never sees: a bearing running half a degree hotter than its model predicts, a sensor bias creeping in over days, a GPS position dragged slowly by a spoofer. E. S. Page proposed it in 1954 for quality control, and it fits in any PLC or flight controller, at three operations per sample.

The recursion is

gk=max⁡(0,  gk−1+rk−ν),alarm if gk>h.g_k=\max\bigl(0,\; g_{k-1}+r_k-\nu\bigr),\qquad \text{alarm if } g_k>h .gk​=max(0,gk−1​+rk​−ν),alarm if gk​>h.

Here rkr_krk​ is the residual normalized by its noise, gkg_kgk​ the accumulated evidence, ν\nuν the slack (what is tolerated without suspicion, typically half the jump μ1\mu_1μ1​ worth detecting) and hhh the limit. On a healthy signal each sample subtracts ν\nuν on average and the max⁡(0,⋅)\max(0,\cdot)max(0,⋅) stops the total from sinking, so gkg_kgk​ lives near zero. Once the residual shifts to a mean μ1>ν\mu_1>\nuμ1​>ν, gkg_kgk​ climbs by about μ1−ν\mu_1-\nuμ1​−ν per sample and crosses hhh after roughly h/(μ1−ν)h/(\mu_1-\nu)h/(μ1​−ν) samples. The threshold is the cashier who notices only when a 500-euro note is missing; the CUSUM is the accountant who writes down every cent.

false alarms per hour97.2 mean delay, thresholdat least 26.7 s mean delay, CUSUM14.1 s At 10 Hz, with a drift of 0.20 °C per minute from 60 s in noise of σ = 0.30 °C and a threshold at 3.0 σ, both detectors raise 97.2 false alarms per hour; the threshold sees the fault after at least 26.7 s on average, the CUSUM after 14.1 s.

Start with a large jump and both detectors fire almost together; then shrink the drift until the trace looks like noise and watch the threshold arrive late or never while the CUSUM, tuned to the same false alarms per hour, still finds it. Press for a new trial a few times: the delay is a random variable.

Accumulated evidence sees what no single sample shows.

A shift of half a standard deviation never crosses a 3σ3\sigma3σ threshold however long it lasts; the CUSUM adds it up and alarms within a predictable number of samples, at a false-alarm rate fixed by hhh.

With Gaussian noise and ν=μ1/2\nu=\mu_1/2ν=μ1​/2 the increment rk−νr_k-\nurk​−ν is, up to a scale factor, the log-likelihood ratio between the mean has jumped and it has not, so the total is a running sum of evidence (likelihood function).

Watching both directions takes two CUSUMs, one per sign. The slack comes from the smallest fault worth catching; the limit is calibrated on real healthy data until the false alarms per hour are acceptable, never taken from a formula that assumes white Gaussian residuals (detection threshold).

Tuned for one jump size, it is slow for much smaller ones, and for much larger ones a plain threshold would have been as fast; a residual with autocorrelation spends long runs on one side and looks like a jump. The trade between its delay and its false alarms is laid out in change detection.