Pilot program / real-time anomaly detection

REFLEX

Multi-lane anomaly detection built for harsh, remote operations. REFLEX runs three independent detection lanes for every signal channel — a LightGBM hot-path detector, a neural network autoencoder, and a structured state-space sequence model — delivering orthogonal coverage and continuous adaptation entirely at the asset.

Self-training
Champion-challenger lanes continuously tune the live hot path.
Per-channel
Three independent model lanes for every instrumented signal.
Air-gapped
All three lanes run at the asset with no internet dependency.
REFLEX_MONITORING
000m
250m
500m
750m
Three-lane anomaly detection
Independent models / every signal channel
Edge live
LGBM
Champion / hot path
AE
Challenger / drift
SSM
Challenger / sequence
Hot path
Real time
Manifold
Adaptive
Sequence
Long range
Operational problem

One model cannot see every way a machine departs from normal.

An abrupt excursion, a slow drift away from learned behavior, and a change in a long temporal sequence are different anomaly classes. Static thresholds and single-model systems compress those distinctions, while fleet-wide baselines ignore the individual cadence, noise, and operating envelope of each signal.

System view

Three model architectures watch every signal from different angles.

  • A production-grade LightGBM detector serves the real-time hot path with fast, reliable gradient boosting.
  • A neural network autoencoder learns each signal's normal behavioral manifold and flags deviations from that representation.
  • A structured state-space sequence model captures long-range dependencies within individual signals and across user-defined correlation groups. Operators choose which channels belong together, enabling batched multi-signal analysis of cascading failures, correlated drift, cross-signal regime shifts, and other temporal anomalies that per-channel analysis cannot see.
  • The lanes run independently but are coupled through a champion-challenger dynamic: the autoencoder and state-space challengers probe the LightGBM champion for blind spots, feeding validated gaps back into its adaptation cycle.

How REFLEX works.

REFLEX places three complementary model architectures on every signal channel, while the state-space lane can also analyze operator-defined groups of related signals together. The LightGBM hot path serves as champion while the autoencoder and state-space lanes challenge its blind spots, creating orthogonal detection coverage and a structured self-tuning loop at the edge.

01

LightGBM hot-path lane

Production-grade gradient boosting serves live anomaly decisions in real time. This is the fast, reliable, battle-tested lane for identifying deviations in each channel as equipment operates.

02

Neural autoencoder lane

A neural network autoencoder learns the normal behavioral manifold of each signal. It catches subtle drift and complex pattern deviations that do not fit the learned representation and may escape a tree-based detector.

03

State-space sequence lane

A structured state-space model captures long-range temporal dependencies and sequential behavior within individual signals. Operators can also define correlation groups, allowing related signals to be analyzed together as batched units over time. This exposes cascading failures, correlated drift, and cross-channel regime shifts that per-channel analysis may not see.

04

Per-channel self-training

Every signal gets its own three-lane model set. The LightGBM hot-path detector is the production champion; the autoencoder and state-space lanes continuously challenge it, surfacing deviations it misses. Validated gaps feed its adaptation cycle, sharpening live detection without taking the hot path offline.

Edge deployment and operational governance.

REFLEX keeps the complete three-lane inference path beside the equipment, where it can operate fully air-gapped with no cloud dependency or required external data flow.

Edge runtimeLightGBM, autoencoder, and state-space inference all run on consumer-grade hardware physically near the asset. Core detection requires neither datacenter GPUs nor a cloud round trip.
Air-gapped by designREFLEX processes telemetry and runs anomaly detection while completely disconnected from the internet. With no cloud API calls, outbound data flows, or third-party servers required, the detection pipeline has no internet-facing attack surface and cannot be exposed by a cloud-side breach.
Data sovereigntyOperational telemetry, learned equipment behavior, and anomaly outputs remain inside the operator-controlled environment. Synchronization is governed by site policy rather than required for detection, so no vendor cloud needs to see asset data.
US-controlled model lifecycleREFLEX detection models are developed and deployed entirely on US-controlled infrastructure, providing a transparent model supply chain and supporting procurement review where controlled domestic technology is required.
User-defined correlation groupsOperators decide which related signals should be watched as a correlated system. The state-space lane analyzes each group together over time to surface cross-channel temporal anomalies while preserving per-channel coverage.
Model governanceEach detection lane retains a clear architectural role, each channel retains its own model context, and multi-signal analysis is limited to correlation groups explicitly defined by the operator.
SPARK handoffValidated anomaly context can move into SPARK for evidence-bound investigation across engineering documents, schematics, procedures, and incident history.
Validation status

Currently undergoing internal benchmarking.

The detection pipeline — three-lane architecture, channel-independent modeling, regime-aware baselines, continuous adaptation, and edge runtime — is in active internal benchmarking against real equipment telemetry.

Primary usersReliability engineers, maintenance supervisors, offshore operations teams, field engineers, and equipment owners accountable for asset availability.
Best fitSensor-rich equipment operating across distinct regimes where downtime, remote access, or delayed fault recognition carries material cost or safety exposure.
InputsSensor telemetry, timestamps, asset and channel identity, and operating-state context used to establish channel-independent, regime-aware behavior.
OutputsReal-time anomaly events with signal-channel and operating-regime context, system health evidence, and SPARK-ready incident packages for deeper investigation.

REFLEX screenshots.

Representative views from an early alpha build of the REFLEX operator workspace: fleet health, live signals, monitoring, diagnostics, correlation analysis, and model operations. Interface and workflows are subject to change as development continues.

REFLEX dashboard screenshot
REFLEX live sensors screenshot
REFLEX monitoring screenshot
REFLEX diagnostics screenshot
REFLEX correlations screenshot
REFLEX ML operations screenshot
Q3 pilot discussions open

Brief REFLEX against a real signal and operating envelope.

Q3 briefings are now open for Q4 pilot rollout. Bring one asset class, representative sensor history, known operating regimes, and the abnormal behavior your team needs to surface earlier. We will map the three-lane edge deployment, per-channel modeling scope, and validation criteria around that system.

Request REFLEX Briefing