Blind PIDS Intrusion Testing Protocol for Site Acceptance

A practical protocol for blind intrusion trials on installed PIDS, covering frozen configurations, randomized tests, ground truth, alarm verification, failures, and controlled retesting.

AI Overview

A defensible blind PIDS acceptance block freezes the installed configuration, separates test roles, randomizes approved trials, captures independent ground truth, tests the complete alarm workflow, and preserves failures through controlled retesting.

A blind PIDS intrusion test determines whether an installed perimeter intrusion detection system can detect, present, and support verification of agreed threat actions without operators or maintainers knowing exactly when and where each trial will occur.

The acceptance block needs a frozen configuration, controlled threat methods, randomized assignments, independent ground truth, predefined validity rules, and an auditable evidence chain. Retuning during the block contaminates comparisons and should trigger a controlled stop, new baseline, or separately documented retest.

This protocol supplements the broader perimeter detection acceptance and witness criteria. It does not recreate the complete factory acceptance, site acceptance, documentation, training, resilience, or handover process.

What a Blind PIDS Trial Must Prove

  1. The agreed intrusion action is sensed under the approved installed condition.

  2. The system generates the expected alarm or event without test-team coaching.

  3. The control room receives an intelligible perimeter zone through the normal path.

  4. Event transport and presentation remain within the project timing requirement.

  5. The operator can access a useful verification view for the affected sector.

  6. The operator assesses, classifies, and escalates the event through the approved workflow.

  7. Source logs, field evidence, and operator records can be reconciled after the trial.

The NPSA PIDS guidance describes perimeter detection as an early-warning layer whose alarms require control-room verification, commonly through video. It also frames commissioning as a balance between detection and unwanted alarms. The test should therefore evaluate the operational chain, not only whether a sensor processor changes state.

Authorized team conducting a blind PIDS field trial
An independent controller records a randomized perimeter trial while an authorized actor executes the approved method.

Product Evaluation Is Not Site Acceptance

Manufacturer qualification, product standards, and site acceptance answer different questions. A product evaluation considers a defined product and deployment configuration under its evaluation method. NPSA notes that barrier-mounted systems are evaluated with a supplied barrier and defined core and peripheral components.

IEC 61757-3-2 specifies terminology, characteristics, and test methods for certain distributed fiber-optic acoustic and vibration interrogation units. It does not define acceptance of a complete site security workflow.

Engineering inference: even when an interrogator or PIDS product has been evaluated, the installed result still depends on the fence or ground condition, sensor route, configuration, zones, communications, alarm management, cameras, lighting, operator interface, and response procedure. Blind site trials test that deployed configuration. For meter-level error and chainage, use the separate fiber PIDS localization-accuracy guide.

Freeze the Configuration Before Testing

Create a signed baseline before the first blind acceptance block. Record the hardware, firmware, software, sensing route, zone boundaries, filtering, sensitivity, classification, persistence, integrations, camera associations, time sources, workstations, barrier condition, active exclusions, known defects, test-plan revision, and approved threat methods.

The Sandia test and evaluation methodology treats configuration management as the discipline that keeps requirements, physical configuration, settings, documentation, and test activity consistent. It also supports recording settings before sustained performance collection.

Do not change sensitivity, zones, camera mapping, firmware, alarm rules, or event suppression during the active block. If a safety-critical repair is unavoidable, stop, preserve the affected evidence, assess which trials remain valid, approve a new baseline, and restart only under documented control.

Separate Test Roles and Information

Blindness depends on information control, not literal concealment from normal work. Operators may know that an authorized test window exists, but they should not receive the trial time, sector, or method.

Responsibility Matrix

  • Test director: owns the randomized schedule, validity decisions, safety coordination, and master evidence register; must not coach operators.

  • Intrusion team: receives only the assigned location, method, start window, and safety limits; must not improvise a stronger action after a miss.

  • Control-room operator: works through normal alarms and procedures without advance trial details; records assessment and action.

  • System maintainer: protects the frozen baseline and records interventions; must not retune or suppress faults during the block.

  • Owner witness: observes evidence, deviations, and acceptance decisions without directing individual trials unless explicitly assigned.

  • Safety controller: holds stop authority and tracks hazards and personnel while disclosing only the information operations needs.

  • Evidence custodian: indexes source logs, video, photographs, screenshots, and field records without altering timestamps or content.

Small teams may combine compatible roles, but the person executing an intrusion should not be the sole person deciding whether that same trial passed.

Randomize the Trial Schedule

Build the schedule before execution from the approved test matrix. Randomize eligible trial order, sector, approved method, authorized start window, direction of approach, and representative transitions where practical. Include predefined no-event observation windows when the plan needs them.

Randomization must not override safety restrictions or the statistical plan. Trial counts, distribution, exclusions, and decision rules belong in the approved plan before results are visible. This article does not prescribe a universal sample size. The narrow lesson from the NIST pass-fail testing paper is that confidence and pass/fail requirements must be defined rather than reconstructed after the outcome.

Control the Threat Methods

Each trial should use a repeatable, authorized action tied to the operational requirement. Depending on the installed technology, that may include approved climbing, cutting, lifting, digging, crawling, walking, or vehicle-approach simulations.

  • Define the starting condition, approach path, test apparatus, and permitted contact with the barrier or detection area.

  • Specify the observable start and completion markers used for ground-truth timing.

  • Set safety limits, abort conditions, restoration needs, and inspection responsibilities.

  • List the procedural errors and environmental events that make a trial invalid.

  • Require field photographs or video sufficient to confirm execution without relying on the PIDS record.

Do not let a tester make a missed trial progressively more aggressive until an alarm appears. That changes the method and destroys comparability. Fence-mounted scenarios should use the approved records for welded-mesh fiber PIDS or chain-link fiber PIDS when selecting representative locations.

Establish Independent Ground Truth

Ground truth is the authoritative record of what physically happened, where it happened, and when. Collect it independently from the PIDS event record using synchronized field video, a controlled timestamp marker, the test-director log, a physical route reference, intrusion-team confirmation, environmental observations, photographs, and witness notes as appropriate.

Secure the field result before comparing it with PIDS, integration-platform, camera, or operator records. This prevents the displayed alarm from silently redefining where or when the test supposedly occurred.

Independent ground-truth station for blind PIDS testing
Randomized trial controls, synchronized field equipment, route evidence, and protected test records establish ground truth.

Trial Record Template

  • Identity: unique trial ID, approved test-plan revision, and signed configuration-baseline reference.

  • Schedule: authorized window plus actual ground-truth start and end timestamps.

  • Execution: physical sector, approved threat-method identifier, test actor, safety clearance, and deviations.

  • Conditions: weather, vegetation, traffic, nearby work, barrier state, and other relevant environmental facts.

  • PIDS outcome: alarm, no alarm, or indeterminate; presented zone; received-event time; and source-log reference.

  • Verification outcome: camera association, image usability, operator classification, action, and response timestamp.

  • Validity: valid or invalid with the pre-approved reason, plus pass, fail, or controlled-retest disposition.

  • Evidence: field video, photographs, event exports, screenshots, operator notes, witness record, and custody location.

Define Valid and Invalid Trials Before Execution

Invalidity is reserved for a predefined condition that prevents fair execution or reliable observation. Examples include a safety stop, incorrect method, ground-truth failure, loss of required time synchronization, unplanned maintenance, masking site work, execution outside the window, or advance disclosure to an operator.

A missed detection is not automatically invalid. Neither is a wrong zone, unusable camera view, delayed presentation, or operator error when those functions are in scope. Keep invalid trials in the evidence register with their reason; deleting them creates an incomplete audit trail.

Assess the Complete Alarm and Verification Sequence

  • Sensor detection and classification

  • Event transport through the integration path

  • Alarm presentation and zone identification

  • Camera association and image usability

  • Operator recognition and classification

  • Escalation or response initiation

Separate these outcomes so the failure domain remains visible. A sensor can detect while an integration rule suppresses the event. An alarm can arrive while the selected camera shows the wrong sector. An operator can receive correct information but classify it incorrectly. The camera alarm-verification guide covers the video layer; use the PIDS latency and response-time budget when timing is a formal acceptance requirement.

Control-room operators verifying an unannounced perimeter test alarm
Operators assess an unexpected perimeter event through mapped camera views while response evidence is recorded.

Handle Failures Without Contaminating the Block

  1. Secure every source record and record the failure against the frozen baseline.

  2. Continue only when the approved plan and safety conditions permit it.

  3. Do not retune the system during the active acceptance block.

  4. Classify the failure domain after the block and approve corrective action through change control.

  5. Define the bounded retest scope, sign a new baseline, and preserve the original result.

A corrected retest does not erase the first failure. The final package should show the original result, diagnosis, corrective action, configuration change, and subsequent outcome.

Go or No-Go Checklist

  • Approved test plan, controlled threat procedures, and operational requirement are available.

  • The configuration baseline is signed and relevant settings are frozen.

  • Pass, fail, invalid-trial, exclusion, and retest rules are approved.

  • Trial distribution and statistical decision requirements are frozen.

  • Roles, information boundaries, safety controls, communications, and stop authority are assigned.

  • Time synchronization and independent ground-truth equipment have been checked.

  • PIDS, integration, camera, and operator logs can be preserved and reconciled.

  • Known defects, excluded areas, and operational constraints are documented.

  • Evidence naming, custody, retention, and witness procedures are active.

  • No unapproved tuning or maintenance is scheduled during the block.

If a critical control is missing, postpone the block rather than generate evidence that cannot support acceptance.

Implementation Note

Use blind testing after installation checks and functional commissioning have produced a stable candidate configuration. A fiber PIDS proof of concept reduces design risk earlier, but it does not replace testing the final integrated site.

For critical-infrastructure perimeter security, preserve the approved matrix, baseline, raw exports, field evidence, operator records, deviations, failures, corrective actions, and retest package under document control. Review how FortSense 4 supports the zone and verification workflow, then request a project review before freezing the site protocol.

Source and Scope Controls

Calculate the frozen trial count and failure boundary with the PIDS probability-of-detection sample-size guide before randomizing the blind acceptance block.

For protected-area testing, extend this blind-test method with the nuclear-facility PIDS design guide.

Freeze the system before the blind acceptance block

Bring the signed baseline, threat procedures, role matrix, randomized trial plan, safety controls, ground-truth method, validity rules, alarm workflow, and evidence register into the test readiness review.

Request a blind-test design review

FAQ

Frequently Asked Questions

Operators and relevant maintainers do not know the exact trial time, location, or method. A test director controls the randomized schedule while the test actor receives only the assignment needed for safe execution.

They may need to know that an authorized test window exists for safety and operations. They should not receive details that allow them to anticipate individual trials.

Not during the active acceptance block. Preserve the failure, investigate after the block, approve any change, establish a new baseline, and run a controlled retest.

Not when correct zone presentation is an acceptance requirement. The trial may expose a workflow failure even though the sensor generated an alarm.

No. Failed trials are acceptance evidence. Invalid trials should remain in the register with the approved reason they were excluded from the decision calculation.

There is no universal number. Freeze the matrix, decision rule, and confidence method before testing based on site requirements, threat methods, perimeter conditions, and the applicable statistical plan.

No. Blind testing is one controlled part of site acceptance. Installation inspection, functional checks, documentation, resilience testing, training, and handover still apply.