Voidly already runs CenDTect-style DBSCAN per (country, day) and surfaces it at /v1/anomaly/dbscan/{cc} — AUC 0.65 against labeled incidents, promoted as a second-opinion signal. That axis asks: which days look weird per country?

This finding ships the other axis: which DOMAINS are changing how they're blocked across the world? The implementation uses HDBSCAN (McInnes et al. 2017, arXiv:1705.07321), which gives variable-density clustering — much better suited than DBSCAN's single-eps assumption to a small/medium per-domain matrix where measurement counts span from 10 (niche domains) to 1,800 (claude.ai).

The build

First-run results (week ending 2026-05-20)

Verification

We re-queried the evidence table for each top-10 drift domain over the last 14 days and asked: are these actually being blocked, or is the drift noise? Result: 10 / 10 top-drift domains have critical or warning evidence in 18-27 countries over the last 14 days. 4 / 10 also appear in our curated incidents table by name (tiktok, openai, twitter, facebook). The unsupervised drift signal is genuinely tracking real blocking activity.

Honest caveats

Live at

GET /v1/anomaly/domain-drift/leaderboard?limit=20 — top-N drift domains, sorted by L2 distance with new/dropped domains at the top
GET /v1/anomaly/domain-drift/{domain} — single-domain detail (cluster this/last week, drift score, raw method-share, per-country block geometry)
GET /v1/anomaly/domain-drift/info — sidecar metadata (algorithm, paper, params, run stats)

Refresh cadence: weekly Sunday 04:00 UTC, after the 02:00 retrain and the ~02:30 temporal holdout. State JSON + sidecar are written by scripts/run-hdbscan-domain-drift.py and the Flask endpoint hot-reloads on file-mtime change.