The Ceiling Is the Calibration Set’s Maximum: Quantized Time-Series Scores that Cannot Fire
Feodor Shevlyakov ⋅ Dmitriy Donskoy ⋅ Aleksandr Kovalenko ⋅ Ilya Makarov
Abstract
Streaming time-series anomaly detectors are developed in float and deployed quantized by a vendor toolchain onto edge hardware. On an RK3568 NPU the fully-on-NPU export of a convolutional-autoencoder detector is born dead: it detects none of the fifty catalogued HAI 21.03 attacks, at a measured false-alarm rate of exactly zero. Nothing crashes, and the label-free signal the failure moves is the false-alarm rate, which it lowers. The cause is an identity. The toolchain sets a tensor's range from its calibration set, and a squared-residual score is non-negative, so the largest value the exported score can represent is exactly that draw's maximum. A threshold above it cannot be reached at any calibration size. We verify the identity on eighty sealed vendor conversions spanning a $256\times$ range of calibration size, eight of them executed on the NPU, and across five toolchains whose min/max observers all return that maximum, the worst disagreement $5.1\times10^{-7}$. We do not find an impossibility: calibrating the score head on the block that set the threshold (free, and still on the accelerator) matches our recommended architectural fix, 656 detections against 657, across eighteen simulated cells. The lattice failure is decidable before deployment, from the ceiling the export contains and the threshold the deployment inherits.
Chat is not available.
Successful Page Load