Quantifying Precursor Lead Time
The value of a precursor detector is the lead time it buys; Kronos measures lead-time distributions and designs actuation around the time available.
Lead time as the figure of merit
A precursor is only useful if it fires early enough to act. Kronos characterizes each detector by its lead-time distribution: given a developing event, how long before the hard threshold does the detector cross its alarm level? This is measured on simulated and (post-FOAK) real events, per failure class.
- Magnet-quench precursors: seconds to tens of seconds of lead time
- Locked-mode / disruption precursors (breeder): milliseconds to hundreds of ms
- Plug-density collapse (burner): tens of ms as the ambipolar potential erodes
- Divertor thermal excursions: hundreds of ms to seconds
Matching action to time available
Lead time dictates which response is feasible. Seconds allow a graceful, MPC-planned ramp-down that preserves the magnet and the pulse. Tens of milliseconds allow only a pre-computed safe maneuver, so Kronos precomputes disruption-avoidance and plug-recovery trajectories that MPC can trigger instantly rather than plan on the spot. Below the time even that needs, only the L1 hardware failsafe can act, and it does, independently.
This is why the layering is strict. Each layer owns a time regime: the microsecond hardware failsafe for the fastest events, precomputed L3 maneuvers for the millisecond regime, planned MPC ramp-downs for the second regime. The anomaly ensemble's job is to push detection as early as possible in each regime so the response can be as gentle as possible.
Reporting honestly
Kronos reports lead time with its uncertainty, and a precursor that historically fires with too little margin is treated as a protection input, not an avoidance input, feeding the failsafe logic rather than promising an avoidance the timing cannot support. Overstating lead time would be the most dangerous error, so it is validated conservatively.