Metering Bypass (node)

Single-node metering-bypass suspicion score (0-100) with patterns, formulas, evidence confidence, legal readiness and a field-visit checklist.

The Metering Bypass report performs a formalised analysis of a single metering node over a selected period, with the goal of detecting signs of possible under-metering, substitution of the measuring channel, incorrect sensor behaviour or other events that require attention from the metering service. It relies on the same standards that govern gas metering: ISO 5167 (orifice plates), ISO 6976 (calorific value), EN 12405-1 (electronic gas-volume conversion), OIML R 137 (gas meters), OIML R 140 (measuring systems for gaseous fuel) and EN 1359 (diaphragm meters).

Report purpose

Report header

Report header. The first thing the reader sees: the node identifier, the device identifier, the corrector type, the covered period, the generation time, the final suspicion score and its textual severity. The score on its own proves nothing — it is a composite indicator that must always be read together with the six neighbouring indicators (see the investigation summary below).

The report is not a formal statement of violation. It does not establish the fact of theft, does not replace a field inspection and is not a legal opinion. Its job is to describe suspicious patterns mathematically and metrologically, show the confidence of the sources, set the inspection priority and give the field crew a clear list of what to check on site.

The report answers the following questions:

  • are there Q≈0 periods in the hourly archive that look atypical;
  • was the pressure channel P stuck at a substitution or near-constant value;
  • did the temperature T change while the pressure stayed still;
  • was there a sharp recovery of Q and P after a zero period;
  • are there matches with the abnormal-events archive;
  • are there direct device signals: physical access, parameter change, reset, clock change;
  • how complete are the data sources;
  • can the suspicion be considered confirmed;
  • is a field visit needed and at what priority;
  • what potential scale of unmetered volume requires verification;
  • which alternative hypotheses must be ruled out before any conclusion about tampering.

Target audience

RoleWhat they get from the report
Head of the metering serviceoverall suspicion level, evidence confidence, legal readiness, field-visit priority
Metrologistcheck of the Q/P/T channels, the P_const regime, applicability of the physical model, passport gaps
Telemetry engineerlink with the sessions archive, completeness of sources, suspicious gaps
Field crewtop windows for inspection and the inspection checklist
Compliance servicelist of suspicious patterns, device events and alternative hypotheses
Billing analystindicative exposure volume as the scale of the potential blind spot
Utility-company lawyerbase for preparing a formal act once hard evidence is confirmed

What the report must NOT do

The report must not:

  • automatically accuse a consumer of metering bypass;
  • call the computed exposure a confirmed loss;
  • treat zero flow as a violation without checking the operating regime;
  • treat a stuck sensor as proof of tampering;
  • apply Gay-Lussac’s law without checking its physical applicability;
  • treat P=100 kPa as illegal without the passport and the P_const regime;
  • raise legal readiness based on an AI comment alone;
  • form a conclusion about tampering when the hourly archive is missing;
  • replace a field act with an automatic score.

Key terms

TermMeaning
Qhourly gas flow, m³/h
Ppressure, kPa
Tgas temperature, °C
Q≈0flow below the near-zero threshold
P_defaultpressure close to a substitution value: e.g. 100, 101.325, 103, 105 or 0 kPa
P_stuckpressure barely changes during the period
zero-flow runa continuous period where flow is near zero
recoverysharp return of flow and/or pressure after a zero period
eventa detected window of a suspicious pattern
severitystrength of the indicator: low / medium / high / high_plus
pattern scoremathematical suspicion score based on archive patterns (0..100)
event scorescore based on direct or classified device events (0..100)
final scoreoverall suspicion score, max(pattern, event)
evidence confidencecompleteness of the evidence base
legal readinessreadiness for a legally meaningful conclusion
field priorityfield-visit priority P0..P3
exposureestimated potentially unmetered volume, not a proven loss
hard evidencedirect proof: housing breach, parameter change, archive reset, confirmed device event, formal act

Overall report logic

The overall logic of the report is built in several layers:

It is essential that the report separates:

  1. statistical pattern in the hourly archive;
  2. device event in the corrector log;
  3. source confidence;
  4. legal readiness;
  5. field inspection.

Each of the five layers is evaluated independently. A high score on one of them does not raise the readiness for action on another. For example, score=100 with no device events and no field visit may stay partial on legal readiness and P1 on field priority.

Input data

Mandatory data

SourcePurpose
Hourly archive Q/P/Tmain source for pattern search
Analysis periodwindow bounds
Node and device identifierslinking the result to a specific object

Without the hourly archive the report can only show absence of data, and must not build a full suspicion conclusion.

Desirable data

SourcePurpose
Communication-sessions archivecheck whether the node was online during events
Abnormal-events archivesearch for hard evidence: housing breach, reset, parameter_change
Corrector passportcheck legality of P_const, Qmin/Qmax, pulse weight
Field inspectionconfirmation of seals, pipework layout, actual regime
Corrector display photorecord of Q/P/T/V, date, time, regime
External-meter readingsreconciliation of the accumulated volume

Minimum reliable period

A period shorter than 30 days automatically downgrades the evidence-base confidence by one level: high → medium, medium → low. A reasonable minimum is 90 days; the recommended period is 366 days (one year gives seasonality for all patterns).

Evidence map

Evidence map

Evidence map. Which data sources were used for scoring and how complete they are. The more green “OK” marks, the higher the confidence in the evidence. Each source has a weight in the evidence-confidence formula, and a partial or missing status lowers the resulting percentage.

SourceStatusWeight in evidence
Hourly archive Q/P/Tok / partial / missing3
Communication-sessions archiveok / partial / missing2
Abnormal-events archiveok / partial / missing3
Corrector passportok / partial / missing1
Field inspectionok / partial / missing3

Source confidence formula

Let:

  • w_i — weight of the source;
  • s_i — source status coefficient.

Statuses:

si={1,statusi=ok0.5,statusi=partial0,statusi=missings_i = \begin{cases} 1, & status_i = ok \\ 0.5, & status_i = partial \\ 0, & status_i = missing \end{cases}

Then the overall source-confidence percentage is:

EvidenceSourcePct=(wi×si)wi×100%EvidenceSourcePct = \frac{\sum (w_i \times s_i)}{\sum w_i} \times 100\%

Evidence confidence interpretation

EvidenceSourcePctEvidence confidence
≥ 70%high
35–70%medium
< 35%low

Zero-flow period

Most signs in the report start with the search for periods where the flow is near zero.

Near-zero threshold

Baseline threshold:

Qnearzero=0.5  m3/hQ_{nearzero} = 0.5 \; m³/h

An hour is considered zero if:

QhQnearzeroQ_h \le Q_{nearzero}

Minimum duration

A zero period becomes a candidate for analysis if it lasts at least:

Hzero_run6  hoursH_{zero\_run} \ge 6 \; hours

That is:

text
Q≈0 continuously for 6 hours or more

Why exactly 6 hours

The 6-hour threshold avoids reacting to short operational pauses, random idle periods or single zero points. For a bypass or substitution pattern, what matters is not isolated zeros but a steady window in which the flow is absent while the other channels behave suspiciously.

Empirically, 6 hours covers most real “night shutdown → morning restart with substitution” patterns without false positives on lunch breaks or short planned stops at industrial sites.

Substitution pressure P_default

One of the key indicators is pressure close to typical substitution values.

Substitution values

GroupValues
Atmospheric / contractual100.0, 101.325, 103.0, 105.0 kPa
Zero / disconnected sensor0.0 kPa

Tolerance

For atmospheric and contractual values:

Toleranceatm=0.5  kPaTolerance_{atm} = 0.5 \; kPa

For the zero value:

Tolerancezero=0.3  kPaTolerance_{zero} = 0.3 \; kPa

Closeness formula

Pressure is considered close to the substitution value if:

PmeanPdefaultTolerance|P_{mean} - P_{default}| \le Tolerance

where:

  • P_mean — average pressure inside the zero window;
  • P_default — one of the substitution values.

Important limitation

P_default is not proof of violation on its own. It may be:

  • a legal P_const regime;
  • a device setting used when the sensor is absent;
  • an emergency fallback value;
  • a consequence of sensor disconnection;
  • a particular feature of the corrector model.

That is why the passport is required for any conclusion:

text
Check: is P_const allowed, what value of P_const is set, why it was applied.

Stuck pressure channel P_stuck

Standard deviation of pressure

Within the zero window, the standard deviation of pressure is computed:

σP=1n1i=1n(PiP)2\sigma_P = \sqrt{ \frac{1}{n-1} \sum_{i=1}^{n} (P_i - \overline{P})^2 }

The pressure channel is considered stuck if:

σP<0.1  kPa\sigma_P < 0.1 \; kPa

Temperature change

For the physical check, the temperature in the window must change noticeably:

ΔT=max(Ti)min(Ti)\Delta T = max(T_i) - min(T_i)

Condition:

ΔT1C\Delta T \ge 1^\circ C

If the temperature barely changed, it is impossible to say with confidence whether P should have changed.

Gay-Lussac law check

Physical formula

For a closed volume of gas with a constant amount of substance:

PTK=const\frac{P}{T_K} = const

where:

TK=TC+273.15T_K = T_C + 273.15

Given initial values:

Pexpected,i=P1×TK,iTK,1P_{expected,i} = P_1 \times \frac{T_{K,i}}{T_{K,1}}

Expected pressure change:

ΔPexpected=max(Pexpected,i)min(Pexpected,i)\Delta P_{expected} = max(P_{expected,i}) - min(P_{expected,i})

Comparison with the actual change

Actual pressure variability is assessed via the standard deviation or the range:

Pstd=σPP_{std} = \sigma_P

or:

ΔPactual=max(Pi)min(Pi)\Delta P_{actual} = max(P_i) - min(P_i)

If:

ΔPexpectedΔPactual\Delta P_{expected} \gg \Delta P_{actual}

and at the same time:

σP<0.1  kPa\sigma_P < 0.1 \; kPa

then the pressure channel is treated as suspiciously stuck.

Divergence coefficient

For the report explanation the following ratio can be used:

KGL=ΔPexpectedmax(σP,ε)K_{GL} = \frac{\Delta P_{expected}}{max(\sigma_P, \varepsilon)}

where ε is a small constant to guard against division by zero.

If K_GL is large, the report states that the expected pressure change is many times greater than the actual variability.

Important physical limitation

Gay-Lussac’s law is applicable only to a closed volume of gas.

It is not applicable or only partly applicable if:

  • the node is connected to the grid;
  • the pressure is maintained by a regulator;
  • the upstream/downstream is open;
  • the pressure is gauge, not absolute;
  • the passport specifies a P_const regime;
  • the volume is not isolated;
  • the pressure sensor rounds or filters values.

Catalogue of detected patterns

Methodology table

Methodology table. All nine indicators the report can search for, with their formal condition, severity level (low / medium / high / very_high) and a clickable “triggered in this report” mark. The table immediately shows which indicators triggered on the given node, and lets you jump straight to the event card.

Substitution of P with a default value

Formal condition:

Q0  for  H6hQ \approx 0 \; for \; H \ge 6h

and:

σP<0.1  kPa\sigma_P < 0.1 \; kPa

and:

PmeanPdefaultP_{mean} \in P_{default}

and:

ΔT1C\Delta T \ge 1^\circ C

Meaning: pressure sits at a typical substitution value during a long zero-flow period. This may indicate substitution of the pressure channel, but may also be a legal P_const regime.

Stuck pressure channel P (Gay-Lussac violation)

Formal condition:

Q0  for  H6hQ \approx 0 \; for \; H \ge 6h σP<0.1  kPa\sigma_P < 0.1 \; kPa ΔT1C\Delta T \ge 1^\circ C

and the Gay-Lussac model shows that the expected pressure change should be noticeable.

Meaning: temperature changes but pressure is almost still. This may indicate a stuck pressure channel, the P_const regime, a grid regulator or substitution of the measuring channel.

Synchronous Q+P jump after a zero period

Formal condition:

There is a zero period:

Q0  for  H6hQ \approx 0 \; for \; H \ge 6h

and after it ends, within a window of:

±2  hours\pm 2 \; hours

the following is recorded:

Qrecovery10  m3/hQ_{recovery} \ge 10 \; m³/h

and:

ΔPrecovery20  kPa\Delta P_{recovery} \ge 20 \; kPa

Meaning: after a long zero, both flow and pressure are restored simultaneously. This may indicate that metering has resumed after a regime switch, but may also be a normal technological start-up.

Gap in the archive with successful communication sessions

Formal condition:

There is a gap in the hourly archive:

Hgap24hH_{gap} \ge 24h

and in the same window there were successful communication sessions:

FailRatio<30%FailRatio < 30\%

Meaning: the node was online, but the hourly archive was not delivered or recorded. This looks more like a delivery, export, parsing or integration issue than a physical bypass of metering.

Too-flat Q and P (plateau)

Formal condition:

The period lasts:

H24hH \ge 24h

flow is non-zero:

Q>1  m3/h\overline{Q} > 1 \; m³/h

flow is too flat:

σQQ<0.02\frac{\sigma_Q}{\overline{Q}} < 0.02

pressure is almost stuck:

σP<1  kPa\sigma_P < 1 \; kPa

Meaning: a very flat curve can be normal for some technological processes, but it can also indicate a synthetic or substituted profile.

Night Q=0 at warm temperature

Formal condition:

In night hours:

02:00hour05:0002:00 \le hour \le 05:00

flow equals zero:

Q0Q \approx 0

temperature is above the threshold:

T>15CT > 15^\circ C

and this happens on at least 5 nights.

Meaning: weak indicator. For schools, offices, seasonal sites and residential buildings, zero night-time flow can be the norm.

Pressure jumps without flow

Formal condition:

At least 3 occurrences:

ΔPh30  kPa|\Delta P_h| \ge 30 \; kPa

with:

Qh<5  m3/hQ_h < 5 \; m³/h

Meaning: strong pressure jumps with no matching flow may point to a sensor fault, a telemetry artefact or a manual channel edit.

Long run of identical Q values

Formal condition:

The flow stays identical for:

H48hH \ge 48h

within:

QiQrun0.001  m3/h|Q_i - Q_{run}| \le 0.001 \; m³/h

Meaning: natural flow normally has noise and variability. Long-running identity may indicate a constant, a transmission error or a disconnected flow sensor.

Recoveries only during business hours

Formal condition:

There are at least 3 recovery events, and the share of recoveries during business hours is:

Sharebusiness70%Share_{business} \ge 70\%

Business hours:

09:00hour<17:0009:00 \le hour < 17:00

and the day of the week is a weekday.

Meaning: if metering recovery often happens only during business hours, this may indicate manual maintenance, operator visits or regime actions. But it is not proof of tampering.

Data-quality pre-filters

Before interpreting tampering patterns, the report must rule out obvious artefacts.

Physically impossible pressure

If:

P>500  kPaP > 500 \; kPa

for a low- or medium-pressure node, this may be a telemetry artefact.

Such points must not inflate suspicion.

Flow spike

A flow spike can be treated as an artefact if:

Qh>20×median(Q)Q_h > 20 \times median(Q)

and at the same time:

Qh>1000  m3/hQ_h > 1000 \; m³/h

Such a point may be a totalizer dump, a transmission error or an archive reset.

Broken P sensor

If the pressure channel is stuck for:

HPstuck168hH_{Pstuck} \ge 168h

then P-dependent tampering detectors must be turned off or marked as non-evidential.

This means:

text
Issue: metrological reliability of the P sensor.
Not a conclusion: proof of bypass.

Network node where Gay-Lussac is not applicable

If:

median(P)<10  kPamedian(P) < 10 \; kPa

and:

σP<2  kPa\sigma_P < 2 \; kPa

and the sensor is not deemed broken, the node may be a low-pressure grid object where pressure is held by a regulator.

In that case GL-dependent indicators must be downgraded or excluded from scoring.

Severity levels and probability weights

Every triggered indicator is assigned a strength level.

SeverityProbability weight p_i
info0.00
low0.10
medium0.30
high0.50
high_plus0.65

These values are not the probability of a legal violation. They are internal weights for combining independent indicators.

Composite suspicion score

Why not a simple sum

If we simply summed all indicators, a node with many weak events would receive an excessively high score. Therefore a multiplicative logic of independent signals is used.

Formula

For each event the weight p_i is taken according to its severity.

Probability that none of the indicators points to suspicion:

Pnone=i=1n(1pi)P_{none} = \prod_{i=1}^{n}(1 - p_i)

Then the combined estimate is:

Pcombined=1i=1n(1pi)P_{combined} = 1 - \prod_{i=1}^{n}(1 - p_i)

Score:

SuspicionScore=100×PcombinedSuspicionScore = 100 \times P_{combined}

or, expanded:

SuspicionScore=100×(1i=1n(1pi))SuspicionScore = 100 \times \left(1 - \prod_{i=1}^{n}(1 - p_i)\right)

Example

Suppose there are two events:

  • medium: p=0.30;
  • low: p=0.10.

Then:

Pcombined=1(10.30)(10.10)P_{combined} = 1 - (1-0.30)(1-0.10) Pcombined=10.70×0.90=0.37P_{combined} = 1 - 0.70 \times 0.90 = 0.37 SuspicionScore=37SuspicionScore = 37

Events excluded from the score

Some events may appear in the report but not participate in the score:

  • informational events;
  • events with non-applicable physics;
  • events suppressed by a quality gate;
  • grid GL events;
  • events explained by a broken sensor.

Severity cap

Even if the score comes out high, the final textual level must not be inflated when all the events are weak.

Cap matrix

Composition of eventsMaximum level
has high_plusvery_high
has highhigh
has 2 or more mediumhigh
has 1 mediummedium
only lowmedium
only infolow / no suspicion

Why the cap is needed

The cap protects the report from a situation in which many weak events produce a very high mathematical score while the evidential value of each event remains low.

Example:

text
Score = 100
But there are no high/high_plus events.
Final level: medium.

Event score — device events

The report takes into account not only the Q/P/T statistics but also the device events.

Device-event classes

ClassMeaning
physicalphysical access, housing breach, clock change, access events
substitutionindications of substitution or change of the measuring regime
metrologymetrological deviations
system_errorsystem errors of the device
commcommunication events
otherother events

Why the event score can dominate

Device events can be more reliable than statistical heuristics. For example:

  • housing breach;
  • parameter change;
  • reset;
  • archive reset;
  • date/time change;
  • password/default access;
  • parameter_change.

If such events exist, the final score may be driven by them even when the statistical score is lower.

Important limitation

Not every device event is direct proof of tampering.

For example:

  • metrological deviations may be regular;
  • abnormal-event summaries require decoding;
  • repeated RAISE/CLEAR must be grouped;
  • “flow = 0” may be normal operation.

Final score and Root Cause Matrix

Final score and hypothesis matrix

Final score and hypothesis matrix. The block shows which of the two layers (statistical pattern or event score) drove the final score, and immediately offers a root-cause matrix with alternative hypotheses. All hypotheses except “bypass” are checked on site. The final root cause is set only after the field visit and decoding of the abnormal-events log.

The final score must take both layers into account:

text
statistical pattern score
device event score

One of the principles:

FinalScore=max(PatternScore,EventScore)FinalScore = max(PatternScore, EventScore)

If EventScore is higher, the report must explain:

text
The final score is driven by direct or classified device events.
The statistical detector gave a lower score.

If PatternScore is higher, the report must explain:

text
The final score is driven by a repeated Q/P/T pattern.
Direct device signals are insufficient.

Evidence confidence

Evidence confidence reflects not the strength of suspicion but the completeness of the evidence base.

Formula

The source map is used:

SourceWeight
Hourly archive3
Sessions2
Device events3
Passport1
Field visit3

Source status:

si={1,ok0.5,partial0,missings_i = \begin{cases} 1, & ok \\ 0.5, & partial \\ 0, & missing \end{cases}

Overall percentage:

EvidenceConfidencePct=wisiwi×100%EvidenceConfidencePct = \frac{\sum w_i s_i}{\sum w_i} \times 100\%

Levels

PercentageLevel
≥ 70%high
35–70%medium
< 35%low

Important interpretation

  • Suspicion score answers: how strong the pattern is.
  • Evidence confidence answers: whether sources are sufficient for a confident conclusion.
  • Legal readiness answers: whether a legally meaningful conclusion can be made.

These are three different scales, and one cannot be derived from another.

Investigation summary: seven scales

Investigation summary

Investigation summary. Right under the report header — seven indicators that are read together, not separately. For example, Pattern Score = 100 with Evidence Confidence = 58% and Confirmed Tampering = ”—” means: mathematically the node looks very suspicious, but there is not yet enough evidence for a formal act — a field visit is needed.

Each of the seven scales has its own meaning, formula and sources:

ScaleWhat it showsSource
Pattern Suspicionstrength of the mathematical indicatorshourly archive
Evidence Confidencecompleteness of the evidence basesource map
Confirmed Tamperingfact of tampering (juridical)field act + hard events
Legal Readinessreadiness for legal actionconfidence + hard events
Field Priorityvisit urgencyscore + confidence + recency
Metrology Reliabilityreliability of physical assumptionspassport + sensors
Data Integrity Riskintegrity of sourcesarchives + sessions

Legal readiness is the assessment of whether the conclusion is ready for a legally meaningful action.

Possible statuses

StatusMeaning
not_readynot enough evidence
partialstrong indicators exist, but confirmation is needed
readyenough evidence for a formal act or formal action

Conditions for not_ready

text
statistical patterns only
and no field visit
and no hard device evidence
and the passport is incomplete

Conditions for partial

text
there are substitution events
or evidence confidence is high
or there is a field visit but some sources are missing

Conditions for ready

ready is possible only if the evidence base is sufficient. Examples:

  • a hard physical event in the device log;
  • confirmed housing breach;
  • confirmed parameter change;
  • field visit + device events;
  • formal photo documentation;
  • proven illegal P_const / parameter_change.

Field priority

Field priority defines the urgency of the visit.

Possible levels

PriorityMeaning
P0urgent, today / 24–48 hours
P1visit within a week
P2planned check
P3monitoring

Matrix

ConditionPriority
physical event in the last 7 daysP0
physical event older than 7 daysP1
score ≥ 70 and confidence medium/highP0
score ≥ 70 and confidence lowP1
score 50–70P1
score 30–50P2
score < 30P3

Why score 100 can be P1

If the score is high but:

  • few events;
  • no high / high_plus;
  • confidence is medium;
  • no field visit;
  • the passport is incomplete;
  • there is no hard evidence;

then the visit may be P1, not P0.

Metrology reliability

Metrology reliability shows how correct the physical and metrological assumptions are.

What reduces reliability

  • passport not confirmed;
  • P_const unknown;
  • pulse weight unknown;
  • Qmin/Qmax unknown;
  • P≈100 kPa repeats without explanation;
  • the P channel is stuck;
  • the T channel is stuck;
  • pressure type unknown: absolute or gauge;
  • Gay-Lussac is applied to a non-closed grid node.

Levels

LevelMeaning
highpassport and channels confirmed, no substantial metrological limitations
mediumthere are passport gaps or isolated anomalies
lowthe physical model is not applicable or the sensors are clearly degraded

Data integrity risk

Data integrity risk shows how complete the investigation data is.

What raises the risk

  • partial sessions archive;
  • missing device-events log;
  • incomplete hourly archive;
  • gaps with successful sessions;
  • contradictions between sources;
  • timestamp from the future;
  • incomplete event decoding;
  • raw logs unavailable.

Levels

LevelCondition
lowsources complete and consistent
mediumsome sources partial/missing
highthere are data-integrity events or serious contradictions

Root Cause Matrix — typical hypotheses

The Root Cause Matrix exists so that the report does not collapse into a single accusation.

Typical hypotheses

HypothesisWhat may support itWhat may refute it
Legal P_constP near default, passport allows the regimepassport does not confirm P_const
P sensor stucklow std(P), repeatabilityP changes normally outside the window
Metering bypassQ=0 + P default + recovery + hard evidenceno field proof, no device evidence
Planned downtimeQ=0 in line with the site’s regimeP_default / recovery atypical
Archive / parser errorgaps, repeated patterns, sessions mismatchraw device logs confirm reality
Downstream valve closedQ=0 with operating Pno confirmation of valve position
Grid regulatorP stable at low pressurethe site is not a grid node
Seasonal shutdownsite profile allows downtimeconsumption was due under contract

Hypothesis statuses

StatusMeaning
not_checkednot checked
possiblepossible
unlikelyunlikely
likelylikely
confirmedconfirmed

The final root cause is set only after a field visit and decoding of the abnormal-events log.

Potential exposure-volume estimate

Potential exposure-volume estimate

Potential exposure-volume estimate. Not a theft volume, but a scale estimate for prioritising the check. The three numbers (low / expected / high) form a ±30% range around the expected value. The baseline is computed as the median of non-zero flows for the same hour of week outside events. Without a field inspection, all numbers remain a heuristic.

Exposure is a computation of the scale of potentially unmetered consumption in suspicious windows.

Baseline

For each hour a baseline is built from historical non-event data.

The median of non-zero flows is used for the same combination:

text
hour of day + day of week

Formula:

Baselineh,d=median(Q    hour=h,  weekday=d,  Q>0,  outside  events)Baseline_{h,d} = median(Q \; | \; hour=h,\; weekday=d,\; Q>0,\; outside\; events)

Hour exposure

For each hour of a suspicious window:

Exposuret=max(0,BaselinetQt)Exposure_t = max(0, Baseline_t - Q_t)

Upper cap

To avoid overestimation, the hourly exposure is capped at the historical P95:

Exposuret=min(Exposuret,QP95)Exposure_t = min(Exposure_t, Q_{P95})

If Qmax is known, the cap can be tightened:

Exposuret=min(Exposuret,QP95,Qmax)Exposure_t = min(Exposure_t, Q_{P95}, Q_{max})

Deduplication

If suspicious windows overlap, the same hour is counted only once:

SuspiciousHours=unique(hours  inside  all  suspicious  windows)SuspiciousHours = unique(hours \; inside \; all \; suspicious \; windows)

Total expected exposure

Exposureexpected=tSuspiciousHoursExposuretExposure_{expected} = \sum_{t \in SuspiciousHours} Exposure_t

Uncertainty range

For the indicative range, ±30% is used:

Exposurelow=0.7×ExposureexpectedExposure_{low} = 0.7 \times Exposure_{expected} Exposurehigh=1.3×ExposureexpectedExposure_{high} = 1.3 \times Exposure_{expected}

Exposure evidence weight

Exposure has low or medium evidence weight until there is:

  • a field visit;
  • external-meter readings;
  • confirmation of the site’s regime;
  • confirmation that Q should indeed have been >0;
  • verification of the passport parameters.

Correlation with the abnormal-events archive

Events by groups

Events by groups. Each suspicious-pattern window expands into a full card: detailed values, correlation with the abnormal-events log (device events within ±24h), the list of alternative hypotheses and the hourly archive of this window. A strong correlation (parameter_change / reset inside the window) is a hard-evidence candidate.

The correlation shows whether device events sit near a suspicious window.

Correlation window

For each event the following window is used:

[event_start24h,  event_end+24h][event\_start - 24h,\; event\_end + 24h]

What counts as a match

A match is any device event that falls inside the window.

Examples:

  • abnormal-events summary;
  • a single abnormal event;
  • parameter_change — change of a device parameter;
  • reset — reset;
  • cover_open — housing breach;
  • clock_change — clock change;
  • archive_reset — archive reset.

Interpretation

ResultMeaning
no matchesthe device log does not confirm the window
only summariesweak correlation
parameter_change / resetstrong correlation
cover / magnet / physicalhard-evidence candidate
log is emptyconfirmation is impossible

AI commentary

AI commentary

AI commentary. An auxiliary text for the operator: one block explains the device events, the other formulates a methodology summary. The disclaimer at the top stresses that AI does not participate in scoring and does not replace a field inspection.

AI commentary is an auxiliary text.

What AI can do

  • briefly explain the issue;
  • list the main risks;
  • formulate hypotheses;
  • suggest the order of checks;
  • produce a clear conclusion for the operator.

What AI cannot do

AI cannot:

  • change the score;
  • change legal readiness;
  • confirm tampering;
  • replace the device log;
  • replace the passport;
  • replace a field visit;
  • create evidence.

Required disclaimer

text
The AI commentary does not participate in the calculation of Legal Readiness, Evidence Confidence or Pattern Score and is not part of the evidence base.

Field-crew inspection checklist

Field-visit checklist

Field-visit checklist. The minimum set of photos and measurements needed to draft the act. Printed or opened on a tablet before the visit. Tied to the detected indicators: if the P_default pattern triggered — the P_const regime item is mandatory; if the archive-gap pattern triggered — the abnormal-events log item is mandatory.

The checklist must be tied to the detected indicators.

General items

  • meter seals;
  • corrector seals;
  • pulse cable / reed / encoder;
  • pressure sensor;
  • temperature sensor;
  • bypass line;
  • valve positions upstream and downstream of the meter;
  • P_const regime;
  • abnormal-events log;
  • cumulative volume on the meter and the corrector;
  • corrector display photo;
  • pipework layout;
  • contractual regime of the site.

Required photos

  • corrector display: Q, P, T, V;
  • corrector date and time;
  • P_const regime;
  • meter serial number;
  • corrector serial number;
  • seals;
  • P sensor;
  • T sensor;
  • pulse cable;
  • bypass and valves;
  • overall view of the node.

What to measure

  • actual pressure with a reference manometer;
  • actual temperature;
  • cumulative volume;
  • external-meter readings;
  • presence of pulses;
  • power-supply status;
  • communication parameters;
  • Qmin/Qmax per passport;
  • pulse weight.

Q/P chart and suspicious windows

Flow and pressure chart

Q/P chart. The main visualisation. The blue line is the hourly flow, the orange one is the pressure. Red and yellow hatched zones mark windows of the triggered patterns: on hover, the exact hour values are shown. The double chart lets you see the whole period at once and not miss long-term trends.

Chart tooltip

Chart tooltip. Hovering over any point shows the exact hourly values of Q and P. This is needed for hypothesis checks: e.g. to learn the pressure value inside a suspicious window or to compare flow against the baseline.

What to look for on the chart

  • long horizontal segments of P (plateau → P_stuck);
  • drops of Q to zero (zero-flow periods);
  • simultaneous jumps of Q and P (recovery);
  • pressure jumps without flow;
  • a perfectly flat Q with a non-zero mean (synthetic profile);
  • discontinuities in time (gap in the archive).

What cannot be interpreted alone

  • a single zero hour;
  • a one-off P spike;
  • any anomaly without checking the abnormal-events log and the passport.

Node summary and hourly distribution

Node summary

Node summary. A single glance at the “raw fabric”: how many events, how diverse the indicators, total duration, period coverage. The “when they started” histogram is useful for spotting regime patterns: events only at night or only during business hours are diagnostically important (see the “recoveries only during business hours” pattern).

Summary metrics

MetricWhat it shows
Total eventstotal number of detected patterns
Unique typeshow many distinct detectors triggered
Durationtotal duration of all windows (with deduplication)
Coverageshare of the period covered by suspicious windows
Levelsbreakdown by low/medium/high/high_plus
Most severename and severity of the strongest indicator

Hourly distribution

The “when they started” histogram uses colour coding:

  • night (00–05) — blue;
  • morning (06–08) — light blue;
  • day (09–17) — orange;
  • evening (18–23) — violet.

Concentration in one colour is a strong diagnostic signal (e.g. all events during business hours → manual maintenance).

Top-5 windows for field inspection

Top-5 windows for the crew

Top-5 windows for the crew. If the crew is time-limited — start with these 5 windows. The full list is below in the “all events by groups” section. The “what to check” column is assembled automatically from the triggered indicators: for zero_flow_p_default it is the P_const regime, for gap_with_clean_sessions it is the abnormal-events log and an archive-parser check.

Top-5 selection algorithm

text
1. filter events with severity >= medium
2. sort by weight (high_plus > high > medium > low)
3. within each weight — by time descending
4. keep the first 5
5. assemble the checklist union from the triggered indicators

”What to check” column

Triggered indicatorMandatory items
zero_flow_p_defaultseals, passport P_const, abnormal-events log
zero_flow_p_stuckP sensor, passport, display photo
zero_flow_recoveryvalve positions, abnormal events, recovery time
gap_with_clean_sessionssessions archive, parser, raw logs
plateau_q_ppulse cable, encoder, passport Qmin/Qmax

How to read the upper block

Pattern suspicion

Answers the question:

How strong are the mathematical indicators of suspicion?

Does not answer the question:

Is tampering proven?

Evidence confidence

Answers the question:

How complete is the evidence base?

Is not equal to suspicion score.

Confirmed tampering

Must stay NOT CONFIRMED if there is no hard evidence or field act.

Shows whether one can proceed to a legally meaningful action.

Field priority

Shows how urgently a field visit is needed.

Metrology reliability

Shows whether the physical and metrological assumptions can be trusted.

Data integrity risk

Shows how complete and consistent the data sources are.

Common interpretation mistakes

Mistake: score 100 = proof

Wrong. A score of 100 may be the result of a strong statistical pattern or event score. Proof requires sources.

Mistake: P=100 kPa = illegal substitution

Wrong. It may be a P_const or default value allowed by the passport.

Mistake: Gay-Lussac violated = tampering

Wrong. The model applies only to a closed volume.

Mistake: Q=0 with P>0 = bypass

Wrong. It may be downtime, a closed valve or a technological regime.

Mistake: exposure = loss

Wrong. Exposure is a scale estimate for the check.

Mistake: AI wrote “suspicion” = proven

Wrong. The AI commentary is only an explanation.

Mistake: “not triggered” = “no problem”

Wrong. An indicator may have been suppressed by a quality gate, disabled because of a stuck sensor or simply not applicable to the node type. Read the limitations section carefully.

Minimum criteria for a complete report

The report is considered methodologically complete if it contains:

  • analysis period;
  • node card;
  • pattern suspicion score;
  • evidence confidence;
  • confirmed tampering status;
  • legal readiness;
  • field priority;
  • data-source map;
  • list of detected patterns;
  • formal condition for each pattern;
  • severity and cap logic;
  • event score or an explanation of its absence;
  • root cause matrix;
  • exposure estimate;
  • correlation with device events;
  • AI disclaimer;
  • field-visit checklist;
  • methodology with formulas and thresholds;
  • statement of limitations and alternative hypotheses.

A correct final verdict must be neutral:

text
The node shows indicators that require verification: long Q≈0 periods,
a stuck pressure channel and/or matches with device events.
This is not standalone proof of tampering.
For the final verdict, the P_const passport, the abnormal-events log,
seals, the pulse cable, the corrector readings and the actual node layout must be checked.

If evidence confidence is high:

text
The presence of direct device events raises the evidence weight, but the final qualification
must take into account the decoding of the codes, passport parameters and the results of the field inspection.

If evidence confidence is low:

text
The detected indicators are heuristic in nature and are used only for planning the check.
  • Metering Bypass (fleet) — the same assessment across the whole fleet at once, without the proceedings blocks.
  • Suspicious Nodes — the main fleet-level tool for detecting bypass.
  • Consumption Analytics — a general node breakdown with the event log; recommended to run before or together with this report.
  • Passport Audit — a check of passport completeness, without which legal readiness cannot be ready.

Related topics

Last updated on

Was this page helpful?