Deterministic by Design
Cryptographically Verifiable
Geometric Anomaly Detection
Triaxis GDI -- Geometric Deterministic Intelligence

Find known and unknown anomalies in your data through geometric measurement.

GDI is Geometric Deterministic Intelligence: anomaly detection by measuring where points sit in mathematical space -- not by fitting another statistical or neural model to your problem.

Normal behavior clusters. Anomalies sit away from that cluster. The distance and angle from a baseline are facts about the data, not estimates. Same input, same output, every run.

14 public datasets, identical code, zero per-dataset configuration, CPU-only -- completed back-to-back in 156 seconds. The geometry was always in the data. GDI measures it.

Measured on public benchmarks
Commodity CPU, no GPU, no training labels
14
Public benchmark datasets
156s
Back-to-back CPU run (same code)
97.6%
Best F1 (ESC-50)
Zero Config
No retuning between datasets
59,515/sec
Peak throughput (Household Power)

Anomaly detection through measurement

GDI does not watch an AI system from the outside. It analyzes the vectors your data already forms -- and surfaces both the rare events you expect and the novel deviations you have not seen before.

Known unknowns

The anomalies you know matter but are hard to catch: fraud at fractions of a percent, intrusions buried in normal traffic, rare failures in industrial telemetry. GDI refines detection when events are rare so alerts stay actionable.

Unknown unknowns

Patterns you have never labeled and cannot sign in advance. Because detection is geometric -- not a fixed classifier -- novel points that sit far from the established baseline surface without retraining or new rules.

Measurement, not modeling

Most systems fit millions of parameters and approximate patterns. GDI measures distances and angles in the space your data already occupies -- like using a ruler, not training another model.

The explanation is the detection

When a point is flagged, the reason is the measurement itself: how far it sits from the baseline, and which features drove that distance. No separate interpretability layer.

Any vector, automatically routed

Raw numerical telemetry or embeddings from another system. You send data; GDI selects the right geometric measurement for its dimensionality and shape.

Outputs compose upward

Anomaly scores, drift, and attributions are themselves vectors. The same engine can analyze those outputs to reveal fleet-wide or enterprise-wide patterns no single stream shows alone.

Deterministic, reproducible results
No labeled training data
Baseline adapts to slow drift
Runs air-gapped on commodity CPU

Three common deployment paths

GDI on your data

Run geometric detection on telemetry, transactions, sensors, or logs expressed as vectors. Standalone product -- no Atum required.

GDI on embeddings

Embeddings translate complex objects into geometry; GDI measures that geometry. Useful for LLM output drift, hallucination signals, and any domain where an embedding model already exists.

GDI with Atum

Neural systems generate and reason; geometric systems detect, classify, and explain. Use both when you need provable models and continuous measurement on the same streams.

Natural partner to neural AI

GDI does not replace generative or reasoning systems. Embeddings can translate a domain into geometry; geometric measurement can flag drift, degradation, and hallucination in those outputs. Triaxis Atum extends that partnership when a workload needs deterministic, provable inference underneath.

Explore Triaxis Atum

How teams apply geometric detection

The same measurement engine supports operational screening, population analytics, and compliance review -- without separate products or domain-specific models.

Operations

Continuous geometric screening

Every vector in the stream is measured against the baseline -- not a sampled subset of the traffic.

Alerts you can verify

Each flag reports the measurements behind it: which features deviated, by how much, and from what baseline.

Multiple anomaly modes together

Sudden spikes, slow drift, and structural shifts can surface in parallel instead of fighting over one threshold.

Analytics

Batch attribution summaries

See which features drive anomalies across a population, not just point by point.

Drift measurement

Track how the geometry of your data shifts over time while the baseline adapts to legitimate slow change.

Composed fleet patterns

Feed anomaly scores from many sources back into the same engine to find correlations invisible locally.

Compliance

Air-gap deployable

Single Docker container, no GPU, no external dependencies -- runs inside your perimeter.

Auditable measurements

Every detection is a reproducible geometric fact about the data, not an opaque model score.

Deterministic by construction

Same input produces the same output -- suitable for regulated review and replay.

Named datasets, measured F1 scores

Performance is dataset-dependent -- so we publish the datasets, not a vague range. GDI is unsupervised on every run below: no training labels, no per-dataset retuning.

14 public datasets, identical code, zero per-dataset configuration, CPU-only -- completed back-to-back in 156 seconds.

ESC-50 Audio Anomaly
97.6%
Environmental sound / security audio / 512D / 1,200 samples

Near-supervised F1 on CLAP embeddings with no training labels.

Tennessee Eastman Process
93.0%
Industrial chemical fault detection / 52D / 13,000 samples

Matches supervised deep learning without labeled fault data.

Beijing Air Quality
90.8%
Environmental / smart city sensors / 12D / 70,000 samples

96.3% recall on hazardous air events at very high throughput.

Household Power Consumption
90.6%
Smart grid / IoT telemetry / 7D / 175,000 samples

Peak throughput benchmark -- one CPU, massive meter fleets.

CERT Insider Threat
89.7%
User behavior analytics / 768D / 1,171 samples

Near-perfect precision for SOC workflows on behavioral embeddings.

Smart Grid Stability
84.0%
Power grid simulation / 12D / 6,000 samples

Instability detection for grid modernization workloads.

DatasetDomainDimsF1PrecisionThroughputContext
ESC-50 Audio AnomalyEnvironmental sound / security audio512D97.6%97.3%1,242/secTop performer
Tennessee Eastman ProcessIndustrial chemical fault detection52D93.0%98.3%6,239/secTop performer
Beijing Air QualityEnvironmental / smart city sensors12D90.8%86.0%67,299/secTop performer
Household Power ConsumptionSmart grid / IoT telemetry7D90.6%99.2%59,515/secTop performer
CERT Insider ThreatUser behavior analytics768D89.7%100.0%1,051/secCompetitive
HaluEval LLM HallucinationLLM output monitoring384D83.2%89.4%2,359/secTop performer
FI-2010 High-Frequency TradingMarket microstructure40D80.4%99.1%27,859/secCompetitive
Elliptic Bitcoin AMLBlockchain compliance166D80.9%75.3%4,390/secCompetitive
Smart Grid StabilityPower grid simulation12D84.0%77.0%16,388/secCompetitive
NSL-KDD Network IntrusionExplainable network IDS41D78.6%85.5%22,622/secStrong
NASA Turbofan EnginePredictive maintenance24D78.6%68.4%16,889/secStrong
CICIDS-2017 Network AttacksModern network security76D79.4%67.3%9,085/secStrong
CTU-13 Botnet DetectionNetwork PCAP / intrusion384D72.0%69.6%1,713/secStrong
Credit Card FraudExtreme imbalance fraud29D36.0%40.0%36,551/secDataset-dependent

Hard datasets stay in the table on purpose. Credit card fraud at 36% F1 is still the best unsupervised result on that benchmark -- useful as a fast screen, not a claim of universal 90%+ F1. Ask us for the domain closest to your data.

See geometric detection on your own data.

Send vectors. Get measurements. No labeled training data, no GPU, and no domain-specific model to rebuild for each new source.