🧠
Cognitum/Behavioral Profilerv0.9.0
🧠
Security

Behavioral Profiler

Builds behavioral baselines and scores anomalies based on deviation from learned routine patterns over time.

eventsanomaly_score · routine_deviation · profile_update hardwareESP32-S3 inputCSI presence, motion
Anomaly score
β€”
current Β· threshold 0.50
Anomalies Β· 24h
β€”
peak score β€”
Profile samples
β€”
rev β€”
Baseline coverage
β€”
168 bins Β· β€” days
Deviations Β· 24h
β€”
routine_deviation
Live anomaly score
Rolling 5-minute window Β· threshold 0.50
History →
β€”
β€”
0.00 – 0.20  normal
0.20 – 0.40  notable
0.40 – 0.60  elevated
0.60 – 1.00  critical
Today's routine (24h)
Hourly activity vs baseline Β· solid = observed, dashed = expected
Baseline →
Anomaly score Β· last 24h
288 samples Β· 5-minute bins
Recent events
Last 8 emitted from the cog
All events →
Sensor inputs
CSI presence + motion Β· ESP32-S3
streaming
Sample rate
5 Hz
Frame size
64 Γ— 1 CSI
Buffer
3.2 KB
Uptime
β€”

Baseline

Learned routine patterns over a rolling 7-day window. Each cell is the expected occupancy/activity intensity for that hour of day, derived from CSI presence and motion samples. Anomaly scoring compares fresh observations against these baselines.

Bins filled
β€”
of 168 (7d Γ— 24h)
Total samples
β€”
profile rev β€”
Baseline age
β€”
since first sample
Hottest hour
β€”
β€”
Learned baseline Β· hour Γ— day
Mean activity intensity (0–1). Brighter = more occupied.
0.01.0 Hover a cell for value
Hourly activity profile
Averaged across all weekdays
Per-weekday intensity
Mean baseline activity per day
Learning progress
Profile samples ingested Β· last 12 days

Anomalies

Continuous anomaly scoring against the learned baseline. Each score is a normalized deviation (0–1) emitted every 5 minutes as anomaly_score. Crossings of the threshold escalate to routine_deviation events.

Above threshold Β· 24h
β€”
samples > 0.50
Peak score Β· 24h
β€”
β€”
Mean score Β· 24h
β€”
288 samples
Deviation events Β· 24h
β€”
routine_deviation
Anomaly score history
β€”
Score distribution
Bin counts Β· last 24h
p50 β€” p90 β€” p99 β€” max β€”
By time-of-day
Average score per hour Β· 24h window
Detected anomalies
β€”
Open event stream →
TimestampScoreSeverityCellDetail

Event stream

Raw events emitted by the behavioral-profiler cog. Three event types are produced: anomaly_score (continuous scoring), routine_deviation (threshold crossings & cluster shifts), profile_update (baseline retrain / sample ingestion).

Events Β· session
β€”
all types
anomaly_score
β€”
scoring emissions
routine_deviation
β€”
cluster shifts
profile_update
β€”
baseline writes
Event timeline
Density across the session
anomaly deviation profile
Live stream
β€”

Profile

Current state of the resident profile model β€” feature weights, cluster centroids, retraining cadence, and detection sensitivity. Tune sensitivity below to trade between false positives and missed anomalies.

Routine clusters
5 latent clusters Β· k-means over 168-bin profile
active
Feature weights
Contribution to anomaly_score
Detection sensitivity
Threshold & smoothing
0.50

Crossings above this value emit a routine_deviation event.

5 min
Above threshold
β€”
Predicted alerts/day
β€”
Estimated FP rate
β€”
Latency-to-alert
β€”
Profile updates Β· last 14 days
profile_update events per day
🧠
Security

Behavioral Profiler

Behavioral anomaly scoring from routine pattern deviation

versionv0.9.0 size26 KB difficultyHard
Description
What this cog does

Builds behavioral baselines and scores anomalies based on deviation from learned routine patterns over time.

Activity is binned into a 7-day Γ— 24-hour grid built from CSI presence and motion samples. After a warm-up period the cog continuously scores incoming observations against the learned baseline, emitting an anomaly_score every 5 minutes and an escalated routine_deviation event whenever the score crosses a configurable threshold.

Manifest
cog.toml fields
ID
behavioral-profiler
Category
Security
Version
v0.9.0
Size
26 KB
Difficulty
Hard
License
Apache-2.0
Events
Topics emitted on the cog bus
topicanomaly_scoreContinuous scoring Β· payload includes score, cell, z-score, contributing features5m
topicroutine_deviationThreshold crossing or cluster shift Β· payload includes cluster, delta, durationedge
topicprofile_updateBaseline retrain Β· payload includes samples, rev, retrain_window15m
Hardware & Input
Device + sensor channels
Hardware
ESP32-S3
Flash
β‰₯ 4 MB
PSRAM
β‰₯ 2 MB
RTOS
ESP-IDF 5.x
Input channels
csi_presence csi_breathing motion_pir motion_accel
Source
Repository path
cognitum-one/cogs/src/cogs/behavioral-profiler
commita3f9b21 Β· main
buildesp-idf 5.1.4 Β· target esp32s3
hashsha256:b8c7…f1a4
Dependencies
Runtime cogs + capabilities
NameKindRequired
csi-presencecogrequired
motion-sensorcogrequired
nv-storagecapabilityrequired
brain-miniserviceoptional
Quickstart
Deploy this cog to a paired seed
$ cogctl install behavioral-profiler --seed seed-living-room
$ cogctl tail behavioral-profiler --follow
[profile_update]    samples=14210  rev=0.9.0+212  retrain_window=7d
[anomaly_score]     score=0.18     cell=Mon/19:30  z=0.4Οƒ
[routine_deviation] cluster=evening_peak  delta=+0.27  duration_short