If nobody assesses the alarm, there is no detection. Everything useful about perimeter intrusion detection follows from that one sentence — including why catching the approach beats catching the breach.
Sandia National Laboratories, in its physical protection systems guidance, puts it without decoration: “detection cannot and does not occur without assessment. If the adversary opens an alarmed door, and no one assesses the alarm, there is no detection.”
Read that as an audit instruction. Every perimeter intrusion detection alert your site raised last night that nobody looked at contributed exactly nothing to your security posture. Not a reduced amount. Nothing. The sensor fired, the log filled, and by the framework's own definition no detection took place.
Which means the first thing to fix isn't the fence line. It's what the word detection is being used to mean.
Detection Is Sensing Plus Assessment
A physical protection system does three things: detect, delay, respond. Sensors and barriers get the budget, but the three are a chain, and the chain has a specific arithmetic that most perimeter procurement skips.
Detection is sensing plus assessment. A sensor produces a signal; assessment turns that signal into knowledge that something real is happening. Skip the second half and the first half has no value, because nothing downstream — no delay, no response — is ever triggered by an alarm nobody read.
The measurement vocabulary matters too, because two terms get used interchangeably and mean different things. Nuisance alarm rate covers all alarms from non-intrusion causes — the bird, the branch, the headlight sweep. False alarm rate is narrower: alarms from unknown sources, a subset of NAR. And probability of detection isn't a marketing percentage but a lower confidence bound: thirty successful test trials support a PD of 0.9 at 95% confidence, because thirty trials is not enough evidence to claim more.
Those definitions connect in a way worth internalising. A high nuisance alarm rate doesn't just annoy people — it actively degrades probability of detection through what the report calls cry-wolf syndrome. Your PD is not a property of the sensor. It's a property of the sensor and the human together, and the human's half is destroyed by noise.
Once detection is defined properly, the reason to detect early becomes arithmetic rather than instinct.
The Race You Are Actually Running
The framework's core inequality is simple: the time your system needs — assess the alarm, decide, deploy a response — must be less than the adversary's remaining task time from the moment detection occurs. Everything else is detail.
That single relationship explains why a fence-mounted sensor, on its own, is a weak instrument. It sits at what the guidance calls the critical detection point — the last layer before the target. Detection there starts the response clock at the latest possible moment, with the smallest remaining task time on the other side of the inequality. It's not that the sensor is bad. It's that it's positioned to give you the least possible warning.
Detect the approach instead and nothing about the response force changes — you have simply moved the start of the clock earlier and made the same inequality much easier to satisfy. That's all a predictive perimeter really is. Not prophecy. Earlier position on the same timeline.
Which raises the fair question of whether there is anything out there to catch before the fence.
The Approach Phase Is Real
There is. In the UNC Charlotte survey of 422 incarcerated burglars, planning was common but short: among burglaries that were planned in advance, 49% took place within 24 hours of the target being selected, and 16% involved one to three days. Longer horizons existed but were the minority.
So the reconnaissance window is not a security-industry invention — but it is measured in hours and days, not weeks. A perimeter that only compares tonight against tonight will miss it. One that can ask whether this vehicle was also here yesterday afternoon is looking at the right timescale, and that is a data-retention and query problem as much as a detection one.
The trouble starts when vendors describe what they claim to see during that window.
You Cannot Detect Intent — and Nor Can Anyone Else
The pitch for predictive perimeter security usually promises recognition of hostile reconnaissance: someone loitering with intent, casing the site, behaving suspiciously. The evidence base for that capability is weak, and it has been reviewed properly. Zoe Marchment and Paul Gill at CREST screened 7,033 studies on the human ability to recognise suspicious activity and hostile reconnaissance, and found accuracy sitting around chance level — with no meaningful difference between experienced CCTV operators and untrained observers.
Their central point is the one to carry into any procurement conversation: establishing non-verbal indicators of hostile intent that hold up across different contexts is genuinely difficult. Not unsolved-for-now difficult. Difficult in a way that has resisted a large literature.
This is where the honest reframe lives. If trained humans cannot reliably distinguish reconnaissance from a person waiting for a lift, a model trained on somebody else's footage and evaluated by its own vendor has not solved it either. Intent is not a visible property. Treat any claim to detect it as a claim requiring evidence you have not been shown.
Fortunately, the thing that actually works never needed intent at all.
Detect Rule Violations, Not Intentions
Effective perimeter detection replaces an unanswerable question with several answerable ones. Not “is this person a threat” but “is anyone in the substation compound between midnight and 5 a.m.” The second question has a definite answer, can be tested, and produces a measurable PD and NAR on your specific site.
| What you'd like to detect | Why it fails | What to detect instead |
|---|---|---|
| Hostile intent | Not observable; human accuracy sits near chance | A person inside a zone that should be empty |
| Suspicious behaviour | No stable cross-context definition exists | Dwell beyond a set threshold in a defined area |
| Someone casing the site | Requires inferring a plan from a single view | The same vehicle appearing on separate days |
| A person who will return later | Prediction about the future, untestable today | Direction of travel across a line, at an hour with no legitimate traffic |
None of the right-hand column requires inferring anything about a person's mind. Each is an observable fact about a place and a time, which is why each can be walk-tested, tuned and measured — and why it produces an alert an operator can adjudicate in seconds rather than one asking them to read a stranger's motives.
It also fits what the burglary data actually says. Someone whose target selection happened yesterday afternoon shows up as the same vehicle on two days, or as a person on a service road at an hour with no legitimate traffic. You do not need to know why they were there. You need to know that they were, and to have someone look while they still are.
Which turns the design problem into a handful of concrete decisions.
Designing Perimeter Intrusion Detection That Earns Its Alerts
- Layer outward from the asset. Outer zones for awareness, inner zones for alarm, with different rules and different urgency. Detection at the critical detection point should be your last line, not your only one.
- Work with the cameras you have. Perimeter projects almost never start from an empty field, and you're never greenfield — the existing estate sets what detection zones are even possible before any rule gets written.
- Tune the nuisance alarm rate per camera, not per system. In most estates a small number of views generate most of the noise — a tree, a road, a security light. Fixing those individually protects the PD of every other camera by protecting the operator's willingness to look.
- Measure PD by walk-testing, and state the confidence. Thirty successful trials support 0.9 at 95% confidence. Run the tests, in the dark and in the rain, and record what you actually achieved rather than what the datasheet claimed.
- Budget the assessment, not just the sensor. An alert nobody can adjudicate is not detection, so alerts per hour has to fit inside the operator capacity you actually have. That constraint is the subject of the operator-to-camera ratio, and it caps how aggressive your rules can be.
- Keep the assessment path live. Assessment means watching, now, not opening a clip afterwards. If pulling up the alerting camera costs several seconds, the approach window you worked to buy is being spent at the moment it matters.
- Retain enough to ask about yesterday. Cross-day questions are where the approach phase becomes visible, and they need retention plus a way to search it. A system that can only answer questions about the last hour cannot see reconnaissance at the timescale the data says it happens.
That last one is a bigger commitment than it sounds. Holding days of footage across every perimeter camera so you can ask cross-day questions is exactly where recording at scale meets the compliance trap — retention long enough to be useful, governed well enough to be defensible.
All of which rests on video infrastructure that can carry live assessment and archive in the same system.
Build, Buy, or Deploy
- Build on open source. go2rtc or MediaMTX for ingest and low-latency delivery, with your own detection rules and retention on top. You own the tuning loop entirely, which matters because NAR tuning is site-specific and never finished. Right when perimeter monitoring is core to your product.
- Use a managed cloud relay. Fast to a working live view, but per-stream costs scale with camera count, and cross-day retention in somebody else's cloud is a cost and governance question before it is a technical one.
- Deploy a commercial platform. A full media stack — ingest, sub-second live view for assessment, recording and retention — on-premise or as a managed cloud deployment under a flat license. Samvyo is one such option: based on SFU architecture, with the media path, TURN and recording under your control, which matters for a site whose archive is also its evidence. Where it doesn't fit: a small site with no monitored response, where a recording system and a good fence are the honest answer.
Three routes, one test — can somebody assess the alert while it is still true?
The Bottom Line
Perimeter intrusion detection is not a sensor problem. Detection, by the definition the discipline actually uses, does not occur until somebody assesses the alarm — so an unassessed alert contributes nothing, and a high nuisance alarm rate degrades detection by destroying the operator's willingness to look. The case for catching the approach rather than the breach is arithmetic: your assess-decide-respond time has to fit inside the adversary's remaining task time, and a fence-mounted sensor starts that clock at the worst possible moment. Just don't buy intent detection to do it. A review of 7,033 studies puts human recognition of hostile reconnaissance at around chance, so build rules about places and times instead, measure their PD on your own site, and make sure someone can watch while the alert is still true.
What's Next?
Whether you can afford to adjudicate the alerts your rules generate is the subject of the operator-to-camera ratio, which is where perimeter design meets monitoring economics.
For what happens after assessment, and how much delay a response can absorb, see Talk-Down at Ten Seconds Is Theater.
And the live path that assessment depends on starts with getting RTSP cameras into a browser.
Frequently Asked Questions
What is perimeter intrusion detection?
A system that senses unauthorised approach or entry at a site boundary and enables assessment of what triggered it. The important nuance from physical-protection doctrine is that sensing alone isn't detection — Sandia's guidance states that detection does not occur without assessment, so an alarm nobody evaluates provides no detection at all.
What's the difference between nuisance alarm rate and false alarm rate?
Nuisance alarm rate covers all alarms from non-intrusion causes with known sources — animals, weather, vegetation, vehicle lights. False alarm rate is narrower, covering alarms whose source is unknown, and is a subset of NAR. Both matter because a high nuisance rate degrades detection through cry-wolf desensitisation.
What probability of detection should I specify?
Specify it with a confidence level or the number is meaningless. PD is a lower confidence bound derived from testing: thirty successful trials support PD of 0.9 at 95% confidence. Walk-test on your own site, in poor conditions, and record what you achieved rather than trusting a datasheet figure.
Can AI detect someone casing a site before a break-in?
Be sceptical of that claim. A CREST review of 7,033 studies found human ability to recognise suspicious activity and hostile reconnaissance sits around chance level, with experienced CCTV operators no better than untrained observers, and no stable cross-context indicators of hostile intent. Detect observable rule violations — presence, dwell, direction, repeat appearance — rather than inferred intent.
How much warning does detecting the approach actually buy?
It changes which side of the inequality you're on. Response time must be shorter than the adversary's remaining task time from the moment of detection, and a fence-mounted sensor sits at the critical detection point — the last layer before the target — so it starts that clock with the least time remaining. Detecting further out extends the window without changing anything about the response force.
How long before a break-in does reconnaissance happen?
Often hours rather than weeks. In a survey of 422 incarcerated burglars, 49% of planned burglaries occurred within 24 hours of the target being selected and 16% involved one to three days of planning. That timescale means cross-day queries matter, which makes retention part of your detection design.
What video infrastructure does perimeter assessment need?
A live view an operator can open within seconds and stay on, plus retention long enough to ask cross-day questions. Samvyo is based on SFU architecture and delivers sub-second live view alongside recording, with the media path, TURN and recording under your control — which matters when the same archive serves both detection and evidence.