Technical resource · Updated September 2026
Anomaly detection on industrial machines: how it works, why impulsive machines are a special case, and where we stand
A complete guide without the marketing: what "detecting an anomaly" from vibration really means, why fixed thresholds are not enough, why presses, cappers and needle looms break the classic methods — and what VBOX4AI does in the field today, what is being validated and what we do not promise.
1. What anomaly detection is — and what it is not
Anomaly detection answers one question only: is this machine behaving differently from usual? It does not say which component is failing, nor when. It says that something has changed, and it says so early — often long before the vibration level crosses a standard threshold.
It is the first step on a four-level ladder, and mixing the levels up is the most common cause of wrong expectations:
| Level | Question it answers | What it takes |
|---|---|---|
| Standard threshold e.g. ISO 20816-3 | Is the vibration acceptable for this machine class? | Power, support type, one RMS velocity value |
| Anomaly detection | Is the machine behaving differently from its normal? | A baseline learned on the individual machine, for each operating regime |
| Diagnosis | Which component is involved, and what kind of fault? | Adequate bandwidth, rigid mounting, machine kinematics, history |
| Prognosis (RUL) | How long until failure? | Real run-to-failure histories, on many identical machines |
Most of the practical value sits in the first two levels: knowing straight away that a machine has changed lets someone go and look before it stops. Prognosis, on the other hand, needs run-to-failure datasets that almost no company owns — which is why we are wary of anyone promising it "out of the box", and why we do not promise it either.
2. Why fixed thresholds fall short
ISO 20816-3 (which replaced ISO 10816-3 in 2022) defines four severity zones — A, B, C, D — based on RMS vibration velocity, machine power and support type. It is a valuable tool and VBOX4AI applies it from the first minute. But it has three structural limits:
- It covers a precise scope: rotating machines above 15 kW, between 120 and 30,000 rpm, measured on the bearing housings in steady state. A press, a capper or a reciprocating machine is out of scope.
- It is an absolute threshold: a machine that has run at 1.2 mm/s all its life and moves to 2.5 mm/s has doubled, yet stays in the "acceptable" zone. The standard itself suggests setting alarms relative to the individual machine's baseline, not to the zone boundaries.
- It ignores context: the same value can be normal at one speed or with one product and abnormal with another.
3. The learned baseline: each machine's "normal"
The answer to the limits of fixed thresholds is to learn the normal behaviour of each individual machine and measure how far it drifts. It sounds simple; the details make the difference between a system that works and one that is ignored after a month of false alarms. These are the principles VBOX4AI is built on:
One baseline per regime, not per machine
A line running idle, loaded or with different formats has several "normals". The system recognises the regime and compares each measurement with the right baseline.
Context is modelled, not ignored
Speed, cadence and load explain most of the variation. The system estimates what the measurement should be in that context and analyses only the residual.
A spike is not an alarm
An anomaly must persist over several consecutive windows before it becomes a notification. This is the most effective filter against false alarms.
New does not silently become normal
If a never-seen regime appears, the system flags it to the operator instead of absorbing it: otherwise a stable fault would be "learned" as the new normal within minutes.
The sensor checks itself
A loose, saturated or disconnected sensor produces "abnormal" signals that have nothing to do with the machine. These events have a separate alarm class.
History is never rewritten
Each recalibration creates a new linked event; acquired data is never overwritten. You can always reconstruct why an alarm was raised.
The baseline starts at go-live: from day one the system flags obvious deviations; typically after about two weeks of real operation it covers the usual regimes and works at full sensitivity, and from then on it keeps refining in service.
4. The processing chain, step by step
The work is split between the sensor, mounted on the machine, and the platform. The order of the steps is not a detail: each one assumes the previous one has been done.
- SensorContinuous three-axis acquisition at a high sampling rate, with anti-aliasing filtering.
- SensorSignal quality check: saturation, flat signal, lost samples.
- SensorFeature extraction every 10 seconds: RMS velocity per axis, kurtosis, crest factor, energy per frequency band, spectral shape.
- PlatformState and regime: running or stopped, production cadence, operating regime.
- PlatformContext normalisation: the share of variation explained by speed, cadence and load is removed.
- PlatformAnomaly score on the residual, with several complementary detectors: statistical deviations, slow cumulative drifts, joint changes of several features.
- PlatformTemporal consistency: the deviation must persist.
- PlatformHypotheses: which axes and bands are involved, to guide the maintenance technician.
- OutputNotification in the dashboard, in the J4BOX MES or in the customer's own system.
Why features and not the raw signal? Because they cut network traffic by orders of magnitude and make it possible to work on modest industrial networks. The raw signal is still acquired on demand — for instance in sessions where the operator labels machine states, or for a deeper diagnostic look.
5. Impulsive machines: why they are a special case
Almost all the literature on vibration monitoring — and almost every product on the market — was designed for rotating machines in steady state: motors, pumps, fans, gearboxes. The signal is continuous and repetitive, and averages computed over a window are stable. A large share of the installed machine base, however, does not work that way.
What breaks in the classic methods
- RMS depends on cadence. If the machine slows down, fewer impacts fall into the window and RMS drops — without anything having improved. If it speeds up, RMS rises — without anything having got worse.
- Kurtosis and crest factor are high by nature. They are the classic bearing-damage indicators precisely because they react to impacts; on a press they are always "in alarm" and therefore say nothing.
- The spectrum is dominated by cycle harmonics. A comb of lines at the working frequency and its multiples covers the content you are looking for.
- Standards do not cover the case. ISO 20816-3 is written for rotating machines in steady state; for presses, cappers and cyclic machines there is no table of reference values to rely on.
How we approach them
Our approach starts from one observation: the cycle is the natural unit of an impulsive machine, not the time window.
- Cadence is derived from vibration. Using autocorrelation and harmonic analysis, the system estimates cycles per minute without an encoder or a PLC connection. It is also production data in its own right: cycle counts, stops, slowdowns.
- The window adapts to the machine. It must contain at least three complete cycles: a machine at 10 cycles/min needs windows of at least 18 seconds, one at 120 cycles/min needs only a few. A fixed window, the same for everyone, is wrong by definition.
- Features are normalised for cadence and regime, so that a slowdown is not mistaken for an improvement, nor a speed-up for a fault.
- Cycle is compared with cycle. By aligning the impacts, the system builds the machine's typical cycle and measures how far each new cycle departs from it: impact timing, energy of each phase, impacts that appear or disappear.
What shows up well, and what remains hard
Shows up well
- Loose fastenings and foundations
- Mechanical play and wear that shift impact timing
- Abnormal impacts appearing in one phase of the cycle
- Cadence changes, micro-stops, manual/automatic transitions
- Continuously rotating parts of the machine (main motor, flywheel), measured at the right point
Remains hard
- Machines that change format or product very often: each format is a regime to learn
- Frequent manual operator interventions during the cycle
- Bearing defects on parts buried in impact noise
- Very slow machines with few cycles per minute: they need long windows and more time for the baseline
6. Bearings and high frequency: why the sensor matters
Bearing defects first show up as small repeated impacts that excite high-frequency resonances — typically between 1 and 6 kHz and beyond. They are recognised with envelope analysis: the high band is isolated, its envelope extracted, and the bearing's characteristic frequencies are searched for (outer race, inner race, rolling elements, cage).
This requires two conditions no algorithm can make up for:
- Sensor bandwidth. The new VBOX4AI generation measures up to 6.3 kHz on three axes. Low-end MEMS sensors, limited to a few hundred hertz, cannot see these phenomena.
- Rigid mounting. A magnetic base strongly attenuates frequencies above 1–2 kHz, exactly where bearings live. For bearing diagnosis, stud mounting is mandatory. We cover this in detail in the resource on the limits of vibration analysis.
7. Current status of VBOX4AI
Separating what works today from what is in progress is, for us, part of the product. This is the situation as of September 2026:
| Function | Status | Notes |
|---|---|---|
| Running/stopped state and production cadence from vibration | Live | In the field on complex-cycle machines, without encoder or PLC. |
| Machine state recognition (e.g. automatic/manual) | Live | On a nonwoven line: ~97% on a single window, 99.8–100% on the consolidated state with a 3-window vote. Validated on a still limited number of sessions. |
| ISO 20816-3 zone evaluation | Live | Active from go-live, with the zones of the configured machine class. |
| Sensor diagnostics | Live | Saturation, flat signal, data loss: separate alarm class. |
| Anomaly detection with per-regime baseline — rotating machines | In validation | Verification with induced faults on a test bench: imbalance, misalignment, looseness, damaged bearings. |
| Cycle-based anomaly detection — impulsive machines | In validation | In the field on real machines; a controlled-fault campaign on a second machine family is planned for Q1 2027. |
| Bearing diagnosis with envelope analysis | In development | Requires the new-generation sensor and stud mounting. |
| Fleet learning across identical machines | In development | Initial baseline shared across machines of the same model: designed for machine builders. |
| Remaining useful life (RUL) | Not offered | It needs run-to-failure histories that do not reliably exist today. |
8. How we validate it
In anomaly detection it is easy to get brilliant numbers that do not hold up in the field. The rules we set ourselves:
- Split by session and by machine. Test data is never mixed sample by sample with training data: consecutive windows look alike, and mixing them artificially inflates accuracy.
- Metrics suited to time series. We use VUS-PR, the metric recommended by the TSB-AD benchmark (NeurIPS 2024), instead of point accuracy that rewards flagging everything.
- Real faults, induced in a controlled way. On a dedicated test bench — motor with inverter, imbalance disc, slotted plate for misalignment, supports with replaceable bearings — each fault is repeated at several speeds and intensities.
- Accuracy on the consolidated state. What matters in the field is the state that reaches the maintenance technician, after temporal confirmation, not the single 10-second window. We report both numbers.
We will publish the campaign results on this page as they become available.
Frequently asked questions
How long before anomaly detection works?
It starts at go-live, about 20 minutes after installation. From day one it flags obvious deviations; typically after about two weeks of real operation the baseline covers the machine's usual regimes and detection works at full sensitivity.
Does it work on presses, cappers and other impulsive machines?
Yes, but with a different approach from rotating machines: cadence is derived from vibration, the analysis window always contains several complete cycles and the comparison is made cycle by cycle. On these machines anomaly detection is currently in field validation, and we state it as such.
Do I need a failure history for the machine?
No. Anomaly detection learns the normal behaviour of the individual machine and flags when it departs from it: it does not need examples of faults. Failure histories would be needed to estimate remaining useful life, which is exactly why we do not offer it.
How are false alarms avoided?
With three measures: a separate baseline for each operating regime, normalisation for speed and cadence, and temporal confirmation — a deviation must persist over several consecutive windows before it becomes a notification. Problems with the sensor itself have a separate alarm class.
ISO thresholds or anomaly detection — which is better?
Both, because they answer different questions. ISO 20816-3 says whether the vibration level is acceptable for that machine class; anomaly detection says whether the machine has changed from its normal, often long before the level leaves the acceptable zone. VBOX4AI activates both together.
Do I need to connect to the machine's PLC?
No. State, cadence and cycles are derived from vibration. A PLC or MES connection remains possible to enrich the context or write notifications into existing systems, but it is not a prerequisite.