Skip to content
Saharsh Engineering Log
Engineering log

Retrospective note

Written from project notes after the fact.

An anomaly is not a diagnosis

Detecting that behaviour changed and explaining why are different problems, and merging them produces confident causes the evidence does not support.

DwellMetryFault ReasoningUncertainty

Problem

An anomaly detector answers one question: does behaviour differ from a validated reference? It has no information about cause. The temptation is to attach the most plausible explanation to the detection and present the pair as a finding, which reads as a diagnosis regardless of how it is worded.

Decision

I separated the layers. Detection reports deviation and stops. A distinct reasoning layer ranks candidate explanations by weighted supporting evidence against contradicting evidence, and its output is an explanation with its evidence attached rather than a confirmed component fault.

Test / evidence

Two rules did most of the work. Grouping: increased runtime and increased daily energy largely reflect the same underlying behaviour, so counting them separately exaggerates support for whatever they both point at. And missing evidence contributes nothing in either direction — an unknown filter-maintenance date is not evidence that the filter is blocked.

Result

A valid conclusion can be "possible explanation" rather than "confirmed fault". Safety rules sit outside the ranking entirely, and a safety engine reacts only to evidence it receives: no triggered warning is not proof that a home is safe.