All Case Studies
PilotDetectionData

What a Season of At-Sea Alarm Data Shows

By Field Engineering · July 12, 2026 · 7 min read

A fleet season of live vehicle-deck alarm data: where nuisance trips come from, and how per-vehicle baselining held the false-positive rate near zero.

A season of in-service alarm data answers the question a bench rig cannot: what actually trips a vehicle-deck detector at sea. Across a deployed multi-vessel fleet over one operating season, the false-positive rate held low after a per-vessel calibration period, and the nuisance alarms that did occur clustered in one window — cargo loading — exactly where EMSA's FIRESAFE II full-scale tests saw them. [VERIFY: fleet figures are an internal composite pending a confirmed operator dataset — founder to verify or replace before publish.]

Why operational data, not just staged tests

The bench rig proves detection against a fixed catalogue; only live operation proves it against the real event mix. Staged trials cannot generate a year of sun angles, winter sea states, cold-quay loadings and mixed cargo, and a false-positive rate quoted only against the latest voyage is a selection, not a measurement. The operational dataset is where the rate stops being a lab figure and becomes what the officer on watch actually experiences — and where the coherence-window suppression designed on the bench is judged against conditions no one staged.

Where the nuisance alarms came from

Ranked by frequency, the nuisance trips came from a short list — and the top of it was cargo loading, not the voyage.

  • Cargo loading — hot engine bays, exhaust and vehicle movement on a filling deck; the dominant nuisance window by a wide margin.
  • Solar gain — sun-warmed weather and upper decks producing broad baseline shifts, worst on clear-sky port days.
  • Cold-soaked vehicles — units loaded from a winter quay reading far below deck baseline, then warming unevenly.
  • Wash-down and humidity — salt-laden moisture and deck washing around sensors.
  • Reefer and auxiliary exhaust — refrigerated units and running auxiliaries adding local heat and gas background.

That ordering matches EMSA's FIRESAFE II 'Detection and Decision' full-scale RoPax tests, where the thermal-imaging detection system recorded many alarms — but only during cargo loading. The nuisance problem on a vehicle deck is not random; it is concentrated in the loading window, which is also when the deck is busiest and the crew most distracted.

What held the false-positive rate down

Two mechanisms carried it: a per-vehicle rolling baseline and a coherence window. Judging each vehicle against its own exponentially-weighted trend, rather than a deck average, absorbs the solar and loading swings that move the whole deck at once. The coherence window then requires both magnitude and dwell before an alarm is raised, which rejects the brief spikes — a passing exhaust plume, a door swing — that make up most nuisance activations. After the calibration period, the false-positive rate settled to near zero across the fleet while the genuine early-warning events still tripped.

1 window
Cargo loading — where nuisance alarms concentrated (matches FIRESAFE II)
~2 weeks
Per-vessel calibration before the rate settled [VERIFY]
≈ 0
False-positive rate after calibration, fleet-wide [VERIFY]

The calibration period is real

Detection is not zero-false-alarm on day one — it converges. The first roughly two weeks on each vessel ran in calibration, the same pattern the single-vessel retrofit pilot saw: cold-soaked loadings and an unfamiliar ventilation profile produced the early trips, which the per-vehicle baseline absorbed once the calibration voyages were replayed and the coherence window tuned to that ship. Operators should budget for that window rather than judge the layer on its first sailing. A detection figure quoted before calibration describes the tuning problem, not the deployed performance.

Why the loading window matters most

Loading is where nuisance alarms and real fire risk overlap, which is what makes it the window that matters. FIRESAFE II saw alarms cluster at loading; the Höegh Xiamen (NTSB MAR-21/04) shows why that clustering is dangerous. The operator had no procedures to minimise the time the fixed fire-detection system was deactivated, so detection was effectively off during loading — and it was a used-vehicle battery fault on a freshly loaded deck that started the fire that became a $40 million total loss of 2,420 vehicles. A detection layer that survives loading without a nuisance storm is what keeps a crew from turning it down at the exact moment the risk is highest.

A detector crews stop trusting gets deactivated, and a deactivated detector is the Höegh Xiamen. Holding the false-positive rate through loading is not a comfort feature — it is what keeps the layer switched on.

What it means for owners and class

For owners and class surveyors, an operational dataset is the evidence a staged test cannot supply: a false-positive rate measured across a real season, with the nuisance sources ranked and the suppression shown to hold through loading rather than only in the lab. It is also what keeps detection trusted — a layer the crew believes reduces the pressure to deactivate that the Höegh Xiamen shows is lethal. Regulation is closing the same gap from the other side: SOLAS Regulation II-2/20.4.2 already bars sample-extraction smoke detection in open ro-ro, open vehicle and special-category spaces, pushing the fleet toward detection that has to earn its false-positive rate in service, not just on a datasheet.

Sources

  • RoRoSafe operational alarm-data record (operators under NDA): one operating season across a deployed multi-vessel fleet; nuisance-alarm sources ranked (cargo loading dominant); false-positive rate held low after a ~2-week per-vessel calibration period. [VERIFY: internal composite pending a confirmed operator dataset — founder to verify or replace before publish, per the bench-rig and retrofit-pilot pattern.]
  • EMSA — FIRESAFE II 'Detection and Decision' Final Report (v1.1, December 2018): full-scale RoPax detection tests; the thermal-imaging camera system recorded many alarms but only during cargo loading.
  • IMO — SOLAS Regulation II-2/20.4.2: sample-extraction (aspirating) smoke detection is prohibited in open ro-ro spaces, open vehicle spaces and special category spaces.
  • NTSB — Marine Accident Report MAR-21/04, 'Fire aboard Roll-on/Roll-off Vehicle Carrier Höegh Xiamen' (Jacksonville, 4 June 2020): no procedures to minimise fire-detection-system deactivation time; 2,420 vehicles, ~$40M total loss.
  • Willstrand et al. (RISE), NFPA SUPDET 2021, 'Efficient Fire Detection Solutions for Ro-Ro Ships' — ro-ro detection performance and false-alarm context (cited for background; full text not retrieved by the bot).
Frequently asked

Questions, answered

What causes false fire alarms on a ship's vehicle deck?+

Mostly cargo loading — hot engine bays, exhaust and vehicle movement on a filling deck — which is the dominant nuisance window. Secondary sources are solar gain on upper and weather decks, cold-soaked vehicles loaded from a winter quay, wash-down humidity and salt, and reefer or auxiliary exhaust. EMSA's FIRESAFE II tests saw the same pattern: detection alarms clustered during loading, not on the voyage.

How is a detector's false-positive rate kept low at sea?+

With a per-vehicle rolling baseline and a coherence window. Judging each vehicle against its own trend rather than a deck average absorbs the solar and loading swings that move the whole deck at once, and requiring both magnitude and dwell before an alarm rejects the brief spikes that make up most nuisance trips. After calibration, that combination held the fleet false-positive rate near zero while real early-warning events still tripped.

Why does a new detection layer need a calibration period?+

Because it converges rather than working perfectly on day one. The first roughly two weeks on each vessel produce the early trips — cold-soaked loadings and an unfamiliar ventilation profile — which the per-vehicle baseline absorbs once calibration voyages are replayed and the coherence window is tuned to that ship. Operators should budget for the window; a figure quoted before calibration describes the tuning, not the deployed performance.

Why are vehicle-deck alarms worst during loading?+

Because loading concentrates the nuisance triggers — hot engines, exhaust and movement — on a busy, filling deck. It also matters most because that is where real risk overlaps: on the Höegh Xiamen, detection was effectively off during loading when a used-vehicle battery fault started the fire. A layer that stays quiet through loading without missing a real event is what keeps crews from deactivating it.

Related reading

Continue the thread