You are on page 1of 5

Detecting an Abrupt Change of Finite Duration

Blaise Kevin Guepie, Lionel Fillatre and Igor Nikiforov

ICD - LM2S - Universite de Technologie de Troyes (UTI) - UMR STMR - CNRS

Troyes, France

Abstract-This paper addresses the detection of a suddenly

arriving signal of finite duration. In contrast to the traditional
abrupt change detection framework where the post-change pe
riod is assumed to be infinitely long, the detection of a suddenly
arriving short signal should be done before it disappears. Hence,
the maximum delay for detection should be upper bounded
and the traditional quickest change detection criterion is com
promised. The new proposed optimality criterion promotes the
maximization of the signal detection probability provided that
the detection delay and the false alarm rate are upper bounded.

A suboptimal detection algorithm based on a window limited

cumulative sum test with a variable threshold is offered. The
proposed method is analyzed theoretically and by simulation
in case of Gaussian observations. A finite variable threshold is

necessary to optimize the proposed algorithm which outperforms

the conventional CUSUM test. It is shown that the resulting

algorithm coincides with the finite moving average one.



In many industrial applications, it is desirable to detect

the situations where the input data contains, in addition to
noise, a suddenly arrived signal of finite duration (anomaly).
This detection problem can be thought of as a two-sided
change: the observations are obeying the distribution FOa
before an unknown but non random change time ns, next, the
observations are obeying the distribution Fo, and, finally, they
are switching back to FOa after the duration nd. It is assumed
that the duration nd and the distribution parameters ()o and ()l
are known. This situation is modeled as





1::; n < ns or n :::: ns + nd,

ns::; n < ns + nd,


where the observations {Yn} n>l are assumed independent.

When monitoring continuous process like drinking water
distribution [1] or large-scale IF networks [2], the detection
delay should be upper bounded whatever the anomaly dura
tion. For such safety critical applications, the latent detection,
i.e. the detection which occurs after signal disappearance or
with the detection delay greater than a prescribed value, is
considered as a missed detection. The pre-change period is
arbitrary long (several days or several months), hence the
number of observations is not upper bounded and, the de
veloped approaches based on burst transient detection (see [3]
for example) are not applicable. Indeed, as it follows from
the literature, the proposed theory of burst signal detection
and developed tests are mainly applicable to off-line detection
This work is supported by French National Agency (ANR) through ANR
CSOSG Program (Project ANR-08-SECU-0 13-02).

978-1-4673-5051-8/12/$31.00 2012


(only exclusion is [4], [5], [6]). Furthermore, it must be noted

that the nature of the transient signal described in this paper is
different than the burst-like signals described in [7]. Typically,
this paper considers a sequential detection of a constant mean
signal of finite duration.
The contribution of the paper is threefold. Firstly, a Vari
able Threshold Window Limited CUmulative SUM (VTWL
CUSUM) test is proposed to sequentially detect a change of
finite duration. A finite variable threshold allows us to optimize
the proposed algorithm. Secondly, the performance of this
VTWL CUSUM is evaluated with an original criterion of
optimality which considers any latent detection as a missed
one. The goal is to maximize the conditional probability of
detection provided that the false alarm rate for a given period
is upper bounded. It is shown that the optimal VTWL CUSUM
test is reduced to the Finite Moving Average (FMA) algorithm.
Moreover, the proposed test outperforms the conventional
CUSUM test in case of a change in the mean of a Gaussian
The paper is organized as follows. Section II discusses the
previous results proposed in the literature. A new optimality
criterion for detecting a finite change is proposed in section III.
The VTWL CUSUM test is described in section IV and its
performances are studied in Section V. Section VI is devoted
to : i) the comparison of the developed theoretical bounds
with the results of Monte Carlo simulation; ii) the comparison
of the proposed test with the conventional CUSUM. Some
conclusions are drawn in section VII.


The traditional sequential change detection problem consists

of the quickest detection of abrupt changes under assumption
that the post-change period is infinitely long. Some results
and references can be found in book [8] and survey [9].
The two main classes of quickest detection problems are the
Bayesian (where the change time ns is random) and the
non-Bayesian (where the change time ns is unknown but
non random) approaches. The first optimality results for the
Bayesian approach were obtained in [10], [11]. More recent
results can be found in [12]. The optimality results for the
non-Bayesian approach were obtained in [13]. Non-asymptotic
aspects of optimality for non-Bayesian algorithms (CUSUM
type) were investigated in [14], [15]. The asymptotic minimax
optimality of the CUSUM algorithm in the case of dependent
random processes was obtained in [16] and recently in [17]
for stochastic-dynamic systems.


Asilomar 2012

Unfortunately, the traditional quickest detection criterion,

i.e. the mean detection delay against the mean time before a
false alarm is meaningless in the problem which is addressed
here, i.e the detection of finite duration signal. There are
several proposed techniques for this kind of signal detection
which can be broadly divided into three classes.
The first class investigates a non-Bayesian approach, i.e.
it is assumed that the signal onset time is unknown but non
random. Standard solutions are based on the CUSUM test [5],
[6], [3] and, more generally, the Generalized Likelihood Ratio
Test (GLRT) [IS]. The algorithm given in [3] proposes a
variable threshold procedure. Its main argument is the fact that
a short and strong signal is best served by a low threshold,
while a long and weak requires a high one. In contrast to [3],
we propose a window limited threshold variable CUSUM
algorithm in order to optimize the detection of a suddenly
arriving signal with a known duration.
The detection algorithms of the second class are based
on some preliminary data transformation with the consequent
application of CUSUM-type or GLR-type algorithms to off
line detection. This class contains Nuttall's frequency domain
"power-law" detector [19], [20] and some detectors based on
linear transformations [21], [22] as the Gabor [23] or the
wavelet transformation.
The last class investigates Bayesian approaches which are
based on a prior distribution imposed over some portions of
the signal parameter space [24], [25], [4], [26] or some Hidden
Markov Model assumptions [7].
Unfortunately, almost all available results from the litera
ture are applicable to off-line detection on finite observation
intervals. The case of sequential detection has received less
attention in recent years.


shown in [13] that the CUSUM algorithm, suggested by [27]

and recalled hereafter
f (Y )
log o, i (3)
T= inf n2:1: max 51: 2:
, 51:
foa (y.)
where fei is the density of FOi' is asymptotically optimal in
the sense of criterion (2). In papers [12], [17], [2S] some
alternative performance criteria have been established instead
of (2) and new approaches to optimal detection of permanent
abrupt changes in stochastic systems has been developed.
The disadvantage of (2) and other above mentioned criteria
for detecting a change of finite duration consists of the
existence of the right "tail" of the detection delay distribution.
Strictly speaking, a small mean delay for detection does not
necessarily lead to a small probability of missed detection.
Next, for safety critical applications, it is more convenient
to consider the probability of false alarm, initially proposed
in [17],
suplP'o (:::; T < + moJ:::;
where is the false alarm rate during a specially chosen period
ma.. lim inf ma / I log I > Plol but log ma = o ( I log I) as
-+ 0, instead of Lorden's constraint lEo (T) 2: THere, P10 =
( l
lE1 og IIe" (YYl denotes the Kullback-Letbler between foo and




The criterion of reliable detection promoting a small probability of missed detection which consists to minimize
sup IP'ns (T - ns + 1 > nd)
subject to a given level of false alarm has been proposed
in [6]. Let us assume that the acceptable detection delay nd
al as -+ and 0 > 0.
satisfies the equality nd = (1 + 0) Ilog
It has been pointed out in [6] based on the results of [17],
[2S] that in such a case the probability of missed detection for
the CUSUM algorithm is asymptotically negligible. Unfortu
nately, to establish that the CUSUM algorithm asymptotically
minimizes the probability (5) as -+ subject to constraint
(4), the speed of convergence of the above probability to zero
-+ should be known. In addition, for safety critical
applications, the conditional probability of missed detection
can be a more adequate criterion. It can be shown that

A change detection procedure is completely defined by its

stopping time T at which the change is declared. Let Fns be
the distribution of the observations Yl,Y2,... ,Yns,Yns+l,. . .
Fo, .
Foo and Yns,Yns+l,'"
where Yl,Y2,'" ,Yns-l
Let lEns (resp. lEo) and IP'ns (resp. 1P'0) be the expectation and
probability w.r.t. the distribution Fns (resp. Fo = Foo). The
quantity of interest is the delay for detection Dd = T - ns + l.
The change should be detected with the delay Dd :::; nd. If the
change is detected with the delay Dd > nd then this detection sup IP'ns (T-ns+l>nd):::; sup IP'ns (T-ns+1>nd I T2:ns) '
is assumed to be missed. Hence, the usage of traditional
criterion involving the mini
quickest detection criterion such as the minimization of
mization of the "worst case" probability of missed detection
sup esssuplEns (T - ns + l) + I Y1,""Yns-l
is used in the paper :
subject to lEo (T) 2: I > 0,
sup IP'ns (T - ns + 1>nd I T2: ns)
inf ifD; , (T) = nsL
where (x) + = max(O, x) and esssup denotes the essential
among all stopping times T E Ca satisfYing
supremum t, is compromised. An asymptotic lower bound for
the "worst case" mean delay for detection (2) in the class
Ca = SUPlP'o (:::; T < + ma)
K"f = {T: lEo (T) 2: I} is given in [13] when nd = 00. It is
where the integer L :::; nd denotes the length of the starting
esssup{ xt, t E T} is the essential supremum of {XdtET if : 1)
period necessary to the sequential algorithm to be operational
IP'(Y :::: Xt)
1 for every t E T; 2) if for a random variable Z such that
(see the next section).
IP'(Z :::: Xt)
1 for every t E T this fact implies that IP'(Z :::: Y)


:::; a} ,







Seeking for simplicity, a change in the mean of a Gaussian

distribution is considered in the rest of the paper:
if 1::; n < ns or n ;::: ns + nd,
if ns::; n < ns + nd,


where 81 > 0 is a known constant and CT 2 is the known

variance. The goal of this section is to optimize the statistic
performances of the VTWL CUSUM with respect to the
optimality criterion (6). Starting from now on, it is assumed
that L = nd.


A. Probability of Missed Detection


This subsection gives the relation between the sequence

of thresholds {h(n)}l<n<L and the probability of missed
detection. It follows fro-m (6) that


ns L


The exact calculation of iF; (TWL) is complicated, let us find

an upper bound for iF; (Twd. A short calculation yields to



iF;, (Twd ::;lP'ns



Let us start with an intuitive introduction of the VTWL

CUSUM test (see Fig. 1). This figure illustrates the behavior
of the cumulative sum {Sl}n>1 log likelihood ratio (LLR)
defined in (3). It is obvious that before the change point ns
and after ns + nd - 1, the mean drift of the LLR is negative
and between ns and ns + nd- 1 (including boundary points),
it is positive. The rationalities of the VTWL CUSUM test
are based on the criterion of optimality (6) which considers
any latent detection as a missed one. Hence, it is proposed
to use the following algorithm based only L last observations
Yn-L+l,, Yn:
TWL= inf n ;::: L:



{Sk'-h(n-k+ 1)}

max {Sf +n -l

0) ::; lP'ns ( S*s+ns -l


h(L + ns -k)}

h(L)) = lP'1 (sf



where sf is a Gaussian variable with mean /Ls,l = L

standard deviation CTs = VI. Thereby, one obtains

L---------'------'''----'T, cw-------50


Fig. I. Motivation of the VTWL CUSUM in the case of transient change


I TWL;::: ns).

iF;, (Twd = sup lP'ns (TWL - ns + 1> L

;:::o }


where {h(n)}l<n<L is a sequence of thresholds. It is assumed

that during the- starting period 1 ::; n < L (the preheating
period), the algorithm is not operational. It is easy to show
that the VTWL CUSUM is a generalization of the snapshot
test (L = 1). If the thresholds are constant, L = 00 and
the preheating period is omitted, then the VTWL CUSUM
coincides with the conventional CUSUM test. The role of
tuning parameters h(1),... ,h(L) and L, is to optimize the
performances of the VTWL CUSUM test.


(r.WL ) < <I> h(L) - /LS,l






where <I> (x) = Joo k exp

du is the Cumulative
Distribution Function (CDF) of the standard normal distribu

Probability of False Alarm

This subsection establishes a relation between the sequence

{h(n)}l<n<L and the worst case probability of false alarm

lP'fa (TwL; m) = a for a given period ma:.

Let Vc = lP'o( ::; TWL < + ma:) for all
show that

VL = supVf = suplP'o( ::; TWL



;::: L. We firstly

+ ma:).


Let Uf = lP'o (TWL = ) for L. A short calculation shows

that { Ue }fL is a non-increasing sequence. It is clear that
Vc =



lP'O (TWL = t).


Hence, one easily gets




lP'O (TWL = t)

Uf - UHma

;::: O.

- 2::= lP'O (TWL = t)


v:;O, <1>-1 ( (1 - o:)l/ma ) - .

The probability of missed detection lP';, (TFMA) of the FMA

Thus {Vi:}e?:L is a non-increasing sequence. It follows that

where the threshold is h =

lP'fa (TwL; maJ= VL=maxVi:=maxlP'o(:S TWL < + ma,).




Because the direct calculation oflP'fa (TwL; met) is complicated,

it is propose to use an upper bound instead. It follows that



VL =

( [n {

VL:S 1-




{Sk'-h(n-k +l)}<O

=H(h(I),... ,h(L)). (11)


By remarking that for any couples of natural numbers kl:S nl

and k2 :S n2, COY (S,' ,S:) 2 0, the last inequality is an
application of Lemma 1 from [29].


+ + + + +

95% confidence intervals

Upper-bound given in (9)
Monte-Carlo simulation

- -- --

C. Optimization of VTWL CUSUM


The goal of this subsection is to determine how to choose

the sequence of tuning parameters { h ( n ) }l<n<L for opti
mizing the VTWL CUSUM algorithm with- respect to the
optimality criterion (6). It follows from (9) and (11) that the
bound of the worst probability of missed detection lP';, (Twd
only depends of h(L) and the bound of the worst probability of
false alarm suplP'o(:S TWL < + met) during a given period



,:-5 ----": ----:-----'-------:

Threshold h 6

Fig. 2. The estimated probability of missed detection JiD; (TFMA) of the

FMA test and its upper bound approximation as functions o f the threshold h.

algorithm is shown in Fig. 2 as a function of h. This probability

is estimated from a 105-repetition Monte Carlo simulation. It
is compared with an upper bound for lP';, (TFMA) given by (9).
The worst case probability of false alarm as a function of the


met is function of the parameters h(I),... ,h(L). Moreover

the choice of first L - 1 arguments of the function

1 0'

(Xl,... ,XL-l,h) >-----+ H(Xl,... ,XL-I,h)


is independent from the choice of the value h = h(L). It is

easy to see from (11) that the bound H(XI,... ,XL-I,h) is
a non-increasing function of Xl,... ,XL-I. Hence, indepen
dently from the value h, the optimal choice for the arguments
XI,... ,XL-I is given by Xn ---+ +00 for n = 1, ... ,L-l.
The passage to the limit leads to the following function

lim H(Xl,... ,XL-l,h) = H(h) = 1-[lP'o (Sf < h)ra

Xn --++cx:>

Hence, the optimization of the VTWL CUSUM test is sum
marized as follows: i) determinin the threshold h which is
the solution of the equation h = H-I ( 0: ) and ii) calculating
the worst probability of missed detection lP';, (TWL) by using


This section is firstly devoted to the comparison of the pro

posed theoretical results established in section V with Monte
Carlo simulations. Secondly, the proposed test is compared
with the conventional CUSUM test.
Let us consider the following parameters (motivated by
the detection of drinking water contamination) : L = 6,
met = 12, (J = 1, &1 = 2 for the first part. As it follows
from subsection V-C, the optimized VTWL CUSUM test is
reduced to the following FMA algorithm :
TFMA = inf {n 2 L: S-L+I 2 h},


10.3 '--------'---------'---'
Thrshold h 6

Fig. 3. The estimated worst case probability of false alarm and its upper
bound h >-+ ii (h) as functions of the threshold h.

threshold h is shown in Fig. 3. Here, the results of a 105_

repetition Monte Carlo simulation is compared with the upper
bound for lP'fa (TFMA; met) given in (12).
It follows from Fig. 2 and 3 that both bounds are close to the
results of Monte Carlo simulation for the values of threshold h
relevant in practice. These experiments confirm that the quality
of upper bounds is acceptable for practical applications.
Let us finally compare the FMA test with the conventional
CUSUM test. The CUSUM test is established to be optimal
optimal according to the quickest change detection criterion




00 0 0

CUSUM test
FMA test
Upper-bound given in (9)


0 0


Worst case probability of false alarm Q

Fig. 4. The probability of missed detection li';, (T) as a function of the

worst case probability of false alann a for the FMA and CUSUM tests.

(2) with infinite post-change period [13], [14], [15], [17], [28].
It is also widely used for the problem of finite transient change
detection [5], [6], [3]. For this reason the CUSUM test is a
good competitor for the algorithm proposed in the paper. Fig. 4
shows the probability of missed detection lP';, (T) as a function
of the worst case false alarm probability lP'ra (T; ma) a for
both competitors obtained by using a lOS-repetition Monte
Carlo simulation. The theoretical upper bound is also shown
for the FMA test. The simulation parameters are the same as
previously. It can be concluded that the FMA test outperforms
the conventional CUSUM. In fact, the better performance of
the FMA test shows that it is relevant to take into account only
L last observations to improve the detection performance.



The paper investigates the problem of sequential abrupt

change detection in the case of finite post-change period.
The proposed optimality criterion minimizes the "worst case"
probability of missed detection provided that a false alarm rate
is upper bounded. A suboptimal variable threshold window
limited CUSUM test is proposed. Its statistical performances
have been theoretically studied and verified by using Monte
Carlo simulations. It is shown that the optimization of this
procedure leads to a finite moving average test. Finally, the
proposed solution has been compared with the conventional
CUSUM test. It is shown that the proposed test outperforms
the CUSUM test for detecting abrupt changes of finite duration
in Gaussian case.
[ I] P. Castro and M. Neves, "Chlorine decay in water distribution system,
case study - Lousada Network," Electronic Journal oj Environmental,
Agricultural and Food chemistry, vol. 2, no. 2, pp. 261-266, 2003.
[2] P. Casas, S. Vaton, L. Fillatre, and T. Nikiforov, "Optimal volume
anomaly detection and isolation in large-scale IP networks using coarse
grained measurements," Computer Networks, vol. 54, no. 11, pp. 17501766, 2010.

[3] Z. J. Wang and P. Willett, "A variable threshold page procedure for
detection of transient signals," IEEE Trans. Signal Processing, vol. 53,
no. I I, pp. 4397-4402, 2005.
[4] Y. Repin, "Detection of a signal with unknown moments of appearance
and disappearance," Problemy Peredachi Informatsii, vol. 27, no. 2, pp.
61-72, 1991.
[5] C. Han, P. Willett, and D. Abraham, "Some methods to evaluate the
performance of Page's test as used to detect transient signals," IEEE
Trans. Signal Processing, vol. 47, no. 8, pp. 2112-2127, aug 1999.
[6] B. Bakhache and I. Nikiforov, "Reliable detection of faults in measure
ment systems," International Journal oj Adaptive Control and Signal
Processing, vol. 14, no. 7, pp. 683-700, November 2000.
[7] B. Chen and P. Willett, "Detection of hidden markov model transient
signals," IEEE Trans. Aerosp. Electron. Syst., vol. 36, no. 4, pp. 12531268, 2000.
[8] M. Basseville and T. Y. Nikiforov, Detection ojAbrupt Changes: Theory
and Application.
Prentice Hall, www.irisa.frlsisthem/kniga. 1993.
[9] T. L. Lai, "Sequential analysis
some classical problems and new
challenges (with discussion)," Statistica Sinica, vol. 11, pp. 303-408,
[10] A. N. Shiryaev, 'The detection of spontaneous effects," Soviet Mathe
matics - Doklady, vol. 2, pp. 740-743, 1961, translation from Doklady
Akademii Nauk SSSR, 138:799-801, 1961.
[ I I] --, "On optimum methods in quickest detection problems," Theory
oj Probability and its Applications, vol. 8, no. I, pp. 22-46, 1963.
[12] M. Pollak, "Optimal detection of a change in distribution," Annals oj
Statistics, vol. 13, no. I, pp. 206-227, Mar. 1985.
[13] G. Lorden, "Procedures for reacting to a change in distribution," The
Annals oj Mathematical Statistics, vol. 42, no. 6, pp. 1897-1908, 1971.
[14] G. Moustakides, "Optimal stopping times for detecting changes in
distribution," Annals ojStatistics, vol. 14, no. 4, pp. 1379-1387, 1986.
[15] Y. Ritov, "Decision theoretic optimality of the CUSUM procedure,"
Annals oJStatistics, vol. 18, no. 3, pp. 1464-1469, Sep. 1990.
[16] R. K. Bansal and P. Papantoni-Kazakos, "An algorithm for detecting a
change in a stochastic process," IEEE Trans. Inform. Theory, vol. 32,
no. 2, pp. 227-235, Mar. 1986.
[17] T. L. Lai, "Information bounds and quick detection of parameter changes
in stochastic systems," IEEE Trans. Inform. Theory, vol. 44, no. 7, pp.
2917-2929, November 1998.
[18] c. Han, P. Willett, B. Chen, and D. Abraham, "A detection optimal min
max test for transient signals," IEEE Trans. InJorm. Theory, vol. 44,
no. 2, pp. 866-869, mar 1998.
[19] A. Nuttall, "Near-optimum detection perfonnance of power-law proces
sors for random signals of unknown locations, structure, extent, and
arbitrary strengths," OTIC Document, Tech. Rep., 1996.
[20] Z. Wang and P. Willett, "All-purpose and plug-in power-law detectors
for transient signals," IEEE Trans. Signal Processing, vol. 49, no. I I,
pp. 2454-2466, nov 2001
[21] B. Friedlander and B. Porat, "Performance analysis of transient detectors
based on a class of linear data transforms," IEEE Trans. Inform. Theory,
vol. 38, no. 2, pp. 665-673, March 1992.
[22] M. Frisch and H. Messer, "The use of the wavelet transform in the
detection of an unknown transient signal," IEEE Trans. Inform. Theory,
vol. 38, no. 2, pp. 892-897, mar 1992.
[23] B. Friedlander and B. Porat, "Detection of transient signals by the gabor
representation," IEEE Trans. Acoust., Speech, Signal Processing, vol. 37,
no. 2, pp. 169-180, 1989.
[24] R. Streit and P. Willett, "Detection of random transient signals via
hyperparameter estimation," IEEE Trans. Signal Processing, vol. 47,
no. 7, pp. 1823-1834, jul 1999.
[25] A. Tartakovskii, "Detection of signals with random moments of appear
ance and disappearance," Problemy Peredachi InJormatsii, vol. 24, no. 2,
pp. 39-50, 1988.
[26] A. P. Trifonov, A. Y. Zakharov, and E. Y. Pronyaev, "Adaptive detection
of a stochastic signal under parametric a priori uncertainty," Prob/.
Inf Transm., vol. 38, pp. 203-217, July 2002. [Online]. Available:
[27] E. S. Page, "Continuous inspection schemes," Biometrika, vol. 41, no.
1-2, pp. 100-114, Jun. 1954.
[28] T. L. Lai and J. Z. Shan, "Efficient recursive algorithms for detection of
abrupt changes in signals and control systems," IEEE Trans. Automat.
Contr., vol. 44, no. 5, pp. 952-966, May 1999.
[29] T. L. Lai, "Control charts based on weighted sums," Annals oJStatistics,
vol. 2, no. I, pp. 134-147, 1974.