Harbormaster: Evidence-Gated, Replay-Safe Maritime Anomaly Detection on AWS

📅 2026-09-30
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the unreliability, poor traceability, and post-failure irrecoverability of maritime anomaly detection caused by falsified or missing AIS data by proposing an AWS-based, production-grade system. Methodologically, it ensures attributability and replay safety through upfront physical validation and idempotent projection storage. A novel LSN guard mechanism is introduced with formal proofs guaranteeing the safety of arbitrary prefix and suffix replays of change logs. Furthermore, a progressive model deployment pipeline integrating shadow comparison and burn-rate checks is established. Experimental results demonstrate that the system achieves a 99.99% request success rate within a bounded window and a P95 latency of 142 ms. Under high concurrency, consumer lag ultimately converges to zero, validating its high availability and robust recoverability.
📝 Abstract
Ships broadcast their positions through the Automatic Identification System (AIS), and those reports can be false or missing. An operator who acts on an anomaly alert needs that alert to be attributable, reviewable, and recoverable after a failure. This paper describes Harbormaster, a production-shaped system on AWS that follows three rules. Physics checks run on every report before any learned model runs. The DynamoDB read store is an idempotent projection of PostgreSQL, and a guard on the log sequence number (LSN) of each change protects every write to it. A candidate model must pass a holdout gate and a shadow comparison before a canary gives it traffic, and a burn-rate check guards each canary step. The paper proves that replaying any prefix or suffix of the change log leaves each projected key at the value of its highest applied LSN. It also notes effects this result does not cover, such as repeated cache invalidations and repeated audit rows. In a bounded AWS window, a one-hour soak returned 35,999 HTTP 200 responses to 36,000 requests, with a 95th-percentile (p95) client latency of 142.751 ms. In a separate bounded AWS run of 900 s, the stream path received a burst of 400 records/s, and its consumer lag later drained to zero. Every number in the paper carries a label that says where it was measured, and the paper lists the parts of the design that were never built.
Problem

Research questions and friction points this paper is trying to address.

Maritime Anomaly Detection
Automatic Identification System
Replay Safety
System Reliability
Innovation

Methods, ideas, or system contributions that make the work stand out.

Maritime Anomaly Detection
Replay Safety
Idempotent Projection
Evidence-Gated Pipeline
Canary Deployment
🔎 Similar Papers
No similar papers found.