Zero-Shot Anomaly Detectors Publish Their Own Accept Region
James Shin ⋅ Chenhui Shao
Abstract
A residual anomaly detector has power over a channel only if its estimate of that channel is formed without reading it. But "formed without reading $x_i$" means "computable before $x_i$ exists," by anyone holding the model and the remaining inputs. The independence that gives the test its power is what makes its answer precomputable. Neither the attack nor the property is ours: the attack belongs to Murguia and Ruths (2017), Zizzo et al. (2020), and Erba and Tippenhauer (2023), and the property is what self-supervised denoising calls $\mathcal{J}$-invariance, wanted there for the opposite reason. What we add is a measurement. We autodifferentiate $\partial \hat{x}_i / \partial x_i$ on a public time series foundation model and find it is set by how the model is called, not by its architecture: the same weights read 0.274 or exactly 0. On a published detector over public TimesFM weights, matched Gaussian and replay forgeries alarm on 87.5–90.0% and 94.2–95.8% of steps, while the precomputed substitution, written to every channel the score couples, scores exactly zero, and holds at zero for 320 steps while the forged stream departs the true process by at least four orders of magnitude. We report no F1, use no anomaly labels, and fix no threshold for the central claim; we claim nothing about downstream consequences.
Chat is not available.
Successful Page Load