SHADE · Methods & evidence

How SHADE works.

Sparse Hybrid Anomaly Detection Engine produces one timestamp-level anomaly score from a time series and its declared known-normal prefix.

SHADE anomaly score rising around a detected event
01 · SHADE methodology

Three signal spaces. Five expert views. One score.

SHADE preserves time, frequency, and structural information as separate representations, brings them into a shared temporal context, and fuses five complementary evidence sources at every timestamp.

InputTime series + anomaly-free reference prefixComplete offline sequence · one or more channels
Tri-space representation
Raw + robust features

Time space

Raw values, robust standardization, and multiscale local patches expose amplitude shifts, abrupt transitions, and waveform distortion.

Global + local spectra

Frequency space

Compact Fourier summaries and timestamp-aligned local energy preserve persistent rhythms, missing cycles, and short spectral changes.

Whitened dependencies

Structural space

Regularized whitening exposes changes in cross-channel coordination, including faults that remain subtle in each channel alone.

Shared local + long-memory context
Temporal intelligenceConvolution + scalar and matrix memoryLocal behavior and long-range dependencies share one contextual representation.
Five timestamp-level evidence sources
Evidence 01Time reconstruction
Evidence 02Frequency reconstruction
Evidence 03Short + medium forecasting
Evidence 04Latent discord
Evidence 05Structural innovation
Calibrated multi-scale fusion
Sparse-channel aggregationMean, top fractions, and attention
Empirical tail calibrationReference-prefix surprise
Multi-scale temporal supportPoint and extended events
Dense anomaly rankingOne score for every timestamp
02 · Real inference example

One MSL series.
Fifty-five real channels.

The display uses five channels chosen by variance within the label-free normal prefix. Every line and score comes from the saved official-driver artifact.

Series002_MSL_id_1_Sensor_tr_500_1st_900.csv
1,827 timestamps55 channelsNormal prefix: 500VUS-PR: 0.996524Peak: 1.0 at timestamp 906
Channel 5Channel 49Channel 11Channel 39Channel 47
Known-normal prefix boundaryLabeled event
Selected channels
SHADE score
1.00.50.0
0Timestamp1826
What the chart shows: SHADE scored 1,827 timestamps using a 500-point known-normal prefix. The optional gold overlay marks the evaluator’s event at timestamps 900–910. All 11 event timestamps rank among the score’s top 20 values, and the full-resolution view includes every timestamp.
Scoring · Offline, reference-calibratedEvidence · 5 of 55 channels shownRun · July 27, 2026
03 · Benchmark performance

Strong results across 530 time-series files.

Across single-channel and multichannel tracks, SHADE delivers a mean VUS-PR above 0.65 while producing the same clear, timestamp-aligned score for every series.

TSB-AD performance snapshotJuly 27, 2026
TrackSeriesMean VUS-PR ↑Median VUS-PR ↑MinimumMaximum
TSB-AD-U3500.65114008520.74729978590.00086713271.0000000000
TSB-AD-M1800.65059424650.74513431510.01209103140.9999662246

530 community-submission evaluation series, with one metric row per series and arithmetic means across rows. Values are reproduced exactly from the paper.

04 · Score aggregation

Strong evidence stays visible.

SHADE carries distinct anomaly hypotheses through scoring, then combines them in ways that preserve localized faults, comparable confidence, and the right temporal support.

Channel aware

Sparse-channel aggregation

Mean, top-5%, top-20%, and attention summaries keep a fault affecting one or a few channels from disappearing inside a full-channel average.

Reference aware

Empirical calibration 

Reference-prefix score distributions translate unlike residuals into comparable tail surprise without imposing a parametric distribution.

Duration aware

Multi-scale temporal support

Identity, short, medium, and long supports preserve sharp point anomalies while building sustained evidence for extended events.