Energy consumption anomaly detection is the process of automatically catching deviations from “normal” in a facility’s electricity, natural gas, water and compressed air consumption data. By the time the monthly bill arrives, the damage is done: a machine running after hours, a base load creeping up silently or a failed power factor correction panel can generate cost for weeks without anyone noticing. Continuously monitored consumption data, on the other hand, makes these deviations visible within hours. In this article we explain how anomaly detection works with energy monitoring data and walk through the six most common “catch” scenarios seen in industrial facilities — for each one, what the data looks like, the likely root cause and the action to take.
What Is Anomaly Detection in Energy Data?
An anomaly is a meaningful deviation of a consumption point from its own historical behaviour. The key word is “own”: a consumption profile that is perfectly normal for a CNC line may be highly abnormal for a chiller. Anomaly detection therefore relies not on absolute numbers but on a reference profile built for each measurement point. The precondition for building that reference is continuous measurement at panel, line and machine level; we explained how that infrastructure is set up step by step in our guide on what energy monitoring is and how it works.
The value of anomaly detection lies in catching problems before the bill does. A monthly invoice compresses the entire facility’s consumption into a single figure and hides every deviation inside it. Time-stamped consumption data, by contrast, has the resolution to raise questions like “why was Hall B drawing 40 kW at 2 a.m. last night?”. A deviation that is not measured cannot be managed; a deviation that is measured is, in most cases, a loss that can be closed with a few hours of maintenance work.
How Are Anomalies Caught With Monitoring Data?
In practice, three basic methods are used together:
- Threshold alerts: Upper and lower limits are defined for each measurement point; when consumption, power, reactive ratio or flow crosses those limits, the system generates an automatic alert. This is the easiest method to set up and forms the first line of defence for critical lines.
- Profile comparison: Each point’s typical daily load curve (hourly profile) serves as the reference. When today’s curve deviates from the reference beyond a set margin, an anomaly is flagged. This catches the “shape distortions” that fixed thresholds cannot see.
- Day-type and shift-based comparison: Like is compared with like: this Tuesday with last Tuesday, tonight’s night shift with previous night shifts, this weekend with previous weekends. This is how natural fluctuation driven by production tempo is separated from genuine deviation.
Turning raw data into meaningful alerts happens in the software layer, where charts, comparison views and alarm rules are defined. We covered what that layer does in our article on energy monitoring software.
6 Typical Anomaly Scenarios: What the Data Says and What to Do
The scenarios below are not cases from a specific plant; they are recurring patterns encountered again and again across industrial facilities. For each one we summarise what the data looks like, the likely root cause and the action to take.
1. Equipment Running After Hours or at Weekends
What the data looks like: During hours when production has stopped, consumption is expected to fall close to zero — yet a flat plateau appears on a particular panel or line. In a typical example, the line is shut down on Friday evening, but the consumption curve stays flat in the 15–30 kW band until Monday morning.
Likely root cause: Ventilation fans, lighting groups, conveyors or hydraulic power units left on, or machines idling. Sometimes an error in the automation sequence keeps equipment in standby while it appears “off”.
Action: Define low-threshold alarms per panel for non-working hours; identify which line produces the plateau and add it to the shutdown checklist. In most facilities this is where anomaly detection pays for itself fastest, because the loss repeats reliably every single week.
2. An Unexpectedly Rising Base Load
What the data looks like: The base load is the floor consumption a facility draws even with no production running, read from the lowest hourly values at night. In a typical example, a night-time floor that has held steady around 80 kW climbs gradually to 95–100 kW over a few weeks. It is hard to notice on a daily chart, but the slope becomes obvious when weekly night minimums are placed side by side.
Likely root cause: A new piece of equipment left permanently on, a heater with a failed thermostat, a pump that has started running continuously, ageing cooling systems, or growing HVAC load due to insulation loss. A rising base load usually signals an accumulation of small losses rather than one large fault.
Action: Trend the night minimum weekly and set an alert on any climb above the reference value. Then locate the source by drilling down through the sub-metering hierarchy panel by panel. Tracking the base load regularly also prevents the savings achieved through an energy audit from eroding over time; we explored that relationship in our article on continuous monitoring after an energy audit.
3. Failed Power Factor Correction: A Silently Rising Reactive Ratio
What the data looks like: Active consumption stays normal while the inductive or capacitive reactive energy ratio rises day by day. In a typical example, the ratio sits in the 5–10 percent band for weeks, then settles into the 15–20 percent band within days after one capacitor stage drops out. Since nothing changes in production, nobody on the floor notices — the problem only surfaces on the bill once the penalty limit is exceeded.
Likely root cause: Capacitors reaching end of life, blown fuses, failed contactors or a mis-configured reactive power control relay.
Action: Set an alert threshold on the reactive-to-active ratio well below the penalty limit — for example at half of it. That way, a compensation fault triggers a maintenance work order before it turns into a penalty on the invoice. Where reactive penalties do not apply, the same rising ratio still points to equipment faults and unnecessary network loading, so the rule is worth having in any facility.
4. Rising Specific Consumption at the Same Output: A Sign of Efficiency Loss
What the data looks like: Total consumption looks normal on its own; but when consumption is tracked together with production output, energy per unit produced (specific consumption) trends upward. In a typical example, a line producing the same product at the same pace sees its kWh-per-unit figure rise 8–10 percent over a few months.
Likely root cause: Worn bearings and belts, fouled heat exchangers and filters, drifting process temperature setpoints, frequent idling or increased mechanical friction. A climbing specific consumption is very often the first footprint of an approaching failure in the energy data.
Action: Define specific consumption as a performance indicator for critical lines and trigger a maintenance check whenever it leaves its reference band. This approach turns energy monitoring into a data source for predictive maintenance: the machine is caught while becoming inefficient, before it stops.
5. Steadily Rising Consumption on the Compressed Air Line: A Leak Signature
What the data looks like: Compressor running time and consumption during non-production hours grow gradually over the weeks; more and more energy is needed just to hold line pressure. This pattern most likely points to leaks accumulating in the distribution network.
Action: Set a trend alert on night and weekend compressor consumption, and schedule a leak survey when the trend rises. We have covered how leaks are located and what they cost in detail in our article on compressed air leak detection and energy costs, so we will not repeat it here — the key point for anomaly detection is that this signal can be read from the electricity data as well.
6. Night Flow on the Water or Natural Gas Line: A Leak Indicator
What the data looks like: During night hours when consumption should be zero, the water meter shows a constant low flow, or the gas meter shows an unbroken flow while process equipment is off. In a typical example, water consumption never reaches zero between 1 a.m. and 5 a.m. and repeats the same floor value every night.
Likely root cause: A leak in an underground line, passing valves and float valves, overflowing tanks; on the gas side, valves that do not fully close or standing pilot flames. Water leaks in hidden lines can run for months and carry a structural damage risk on top of the cost.
Action: Define a “non-zero flow during night hours” rule on water and gas meters. It is one of the simplest anomaly rules to set up and one of the most reliable: if there is no legitimate explanation for night flow, there is very probably a leak.
How Should Alerts Be Configured?
The most common trap in anomaly detection is generating so many irrelevant alarms that the team starts ignoring them. A healthy alert design follows these principles:
- Few but meaningful alarms: Define alarms on critical, actionable points — not on every measurement point. An alarm with no response attached is just noise.
- Time-of-day sensitive thresholds: Use separate thresholds for working and non-working hours; a power level that is normal by day is an alarm condition by night.
- Duration conditions: Make the alarm condition “threshold exceeded for a sustained period” (for example 15–30 minutes) rather than an instantaneous spike. This prevents natural events such as motor inrush currents from turning into false alarms.
- Escalation: Route the first alert to the site supervisor, unresolved alarms to the maintenance manager, and persistent deviations to the energy manager.
- Regular review: Do not leave thresholds static; update them as the production pattern changes.
AI and Automatic Profile Learning in Anomaly Detection
Thresholds and profile comparisons can be configured by hand, but in a facility with hundreds of measurement points, manually defining a reference for each one is impractical. In the modern approach, the software learns each point’s typical behaviour from its own history: it computes the expected consumption band by day type, shift and season, and flags a deviation whenever the actual value leaves that band. The advantage of these machine-learning-based methods is that they also catch deviations nobody was looking for — a fixed threshold only answers the questions someone anticipated, while a learned profile can say “this point does not look like itself today”. When fed with production data, the system can also distinguish whether a consumption increase comes from higher output or from a genuine anomaly.
Anomaly Detection With the ATS Energy Monitoring System
The ATS Energy Monitoring System, developed by Atasayın Enerji at Teknopark Istanbul, monitors electricity, natural gas, water and compressed air consumption in real time on a single platform, compares it against historical profiles and generates automatic alerts on threshold violations. Every scenario in this article — from after-hours consumption to night-time water flow — can be tracked through monitoring and alarm rules configured in ATS. Used by industrial companies such as Beko, Cargill and Gedik, the system also converts consumption data into its carbon emission equivalent, providing the foundation for sustainability reporting. You can explore the full portfolio on our products page.
Frequently Asked Questions
How much historical data is needed for energy consumption anomaly detection?
A few days of data is enough for simple threshold alerts. Profile comparison and day-type benchmarking need at least 3–4 weeks, and a reliable reference that also covers seasonal effects requires a few months. Since the system starts accumulating data from the moment it is installed, its detection capability strengthens over time.
What is the difference between anomaly detection and a classic alarm?
A classic alarm reports the crossing of a fixed, predefined threshold. Anomaly detection looks for deviation from the point’s own historical behaviour; even if no threshold is crossed, it can say “this line does not normally consume this much at this hour”. The two are complementary, not alternatives.
How can false alarms be reduced?
Adding a duration condition (the threshold must be exceeded for a sustained period), defining separate thresholds for working and non-working hours, limiting alarms to actionable points, and updating thresholds as the production pattern changes all significantly reduce the false alarm rate.
Which quantities should be monitored for anomaly detection?
For electricity: active power, consumption, reactive ratio and power factor. For water and natural gas: flow rate and meter index. For compressed air: compressor consumption and line pressure. Adding context data such as production output makes specific consumption trackable as well.
Is anomaly detection worthwhile for small and medium-sized facilities?
Yes. Scenarios such as after-hours consumption, night-time water flow and power factor correction faults are independent of facility size and generate recurring losses in small plants too. It is entirely feasible to start with a handful of critical measurement points and expand the system over time.
To see which anomalies are hiding in your facility’s consumption data and to design a monitoring and alert setup that fits your operation, get in touch with the Atasayın team — we will assess your existing infrastructure and prepare a site-specific roadmap together.