A user-visible internet shutdown is the end of a process, not the start of one. By the time domains stop loading and users notice, the routing and filtering infrastructure behind the shutdown has often already moved — routes withdrawn, DPI boxes switched on, blocking spreading to new networks. The pre-shutdown network signal detector asks a narrow, falsifiable question: can we see those technical precursors in our own evidence stream before the blocking becomes visible to users?
We build a per-country composite "pre-shutdown signal score" from three precursor signals, computed daily over the trailing 90 days:
http-blocking-tcp-reset and
related signal types) measured against a trailing 7-day mean. When a
deep-packet-inspection box is switched on, the connection resets show
up here before any blockpage does.
The composite is a weighted sum (0.5 BGP, 0.3 TLS, 0.2 new-ASN), then z-scored within each country over its own 90-day history so every country sits on a comparable scale. A score of z ≥ 1.5 is called "signal up."
The back-test. We took every confirmed shutdown in
the window — 2,240 evaluable events (incident_type
in censorship / mixed / disruption, severity critical) — and for
each one asked: did the composite cross z ≥ 1.5 at any point in the
72 hours before the shutdown timestamp?
522 of 2,240 did — a 23.3% true-positive rate,
with a median lead time of 31.3 hours (mean 39.9h).
When the precursor exists, it tends to exist a day or more out.
The honest other side. A lead signal is only useful
if it doesn't fire constantly. Of 585 country-days where the composite
fired, 180 had no shutdown in the following 72 hours — a
30.8% false-positive rate. So the detector is real
but partial: it catches under a quarter of shutdowns and, when it
fires, is wrong about a third of the time. It clears our promote-floor
(≥ 3 historical shutdowns with ≥ 1h lead — we got 522) and
ships as "promoted": true, but "promoted" here means the
signal is genuine and worth exposing, not that it is a reliable
standalone trigger.
Why it only catches a quarter. The ceiling is structural, and we state it in every API response. Many shutdowns are sudden: a government issues an order, an operator flips a switch, and there is no measurable technical run-up at all — the detector cannot warn on those because there is nothing to see. IODA's BGP feed also carries a roughly 6-hour ingest lag, so any precursor with a real lead time shorter than ~6h is invisible to this back-test even when it physically exists. And the back-test crosses days, not hours, so reported lead times are day-resolution.
What this is, what this isn't. It is a supporting early-warning signal — a per-country composite that, when elevated, raises the prior that a shutdown is coming and can feed into the broader forecast stack alongside the 7-day shutdown forecast and the pre-protest GDELT correlator. It is NOT a standalone predictor: an elevated composite reflects raised BGP / TLS / new-ASN anomaly activity, which frequently resolves with no shutdown at all. The leaderboard surfaces which countries are elevated today; the per-country endpoint returns the full 90-day daily series so a journalist or analyst can see exactly what drove the score. Every response carries the caveats inline — signal up is not the same as shutdown imminent.