Large Language Thing

Home/Concepts/The Apollo guidance computer and state estimation in public safety

The Apollo guidance computer and state estimation in public safety

On the axis of what a system may observe, continuous fused estimation is terminal. Kalman's formulation admits exactly three ingredients: a prior, a dynamics model, and…

The objection that should win

Here is the strongest case against everything that follows. Apollo's navigation worked because the target obeyed an equation. Two-body gravity, corrected for a few known perturbations, predicts a spacecraft's position to metres, days in advance, without looking at it. That is what let Stanley Schmidt's filter do anything useful with a handful of sextant sightings: the propagation step between sightings was almost exact, so the corrections only had to be small.

Public safety has no orbital mechanics. Crime does not obey a conservation law. A structure fire does not have a two-body approximation. Call volume on a Friday night in a city with a new stadium, a heatwave and a transit strike is not predictable from any dynamics model a duty officer could write down, still less one accurate enough to make continuous measurement look like correction rather than noise. Feed such a system every stream you like — incident reports, dispatch telemetry, gunshot sensors, radar-derived storm cells — and without a trustworthy model of how the state evolves between readings, you have not built an estimator. You have built a very expensive scanner.

This is not a weak objection. It is the correct one, and it deserves to be taken at full strength before any concession is offered back.

Why the objection is right, as far as it goes

A Kalman filter with a bad process model does not gracefully degrade. It actively misleads. If the propagation step assumes the world moves more smoothly than it does, the filter grows confident between updates and then treats the next real measurement as an outlier to be down-weighted rather than a correction to be absorbed. This is not hypothetical in public safety; it is the exact mechanism behind the characteristic failure of the field. A risk map built on last year's pattern is a process model. It says: burglary clusters in this ward on Thursday nights, ambulance demand peaks at this hour, wildfire risk follows this slope and this vegetation index. Resources — patrol cars, ambulances, brush engines — get staged against that model days or weeks in advance, because staging takes lead time and lead time requires a prediction.

The trouble is that the model is exact until it is not. A new licensing law changes Thursday night. A closed hospital shifts ambulance demand two miles west. A drought turns yesterday's moderate fire risk into tonight's extreme risk, and the vegetation index used to build the map was last recalculated in spring. None of this is noise in the statistical sense the filter assumes. It is a change in the dynamics themselves, and a filter — or a duty officer — that trusts the old model too much will read the first contradicting incident report as an anomaly rather than as the leading edge of a regime change.

So the objection stands at its strongest point: continuous intake does not save you if what you are propagating between observations is wrong. Kalman's mathematics has always known this. Divergence from covariance collapse — the filter becoming falsely confident and starting to reject the very measurements that would correct it — is a named failure mode, not a hypothetical one. More streams into a mis-specified estimator produce confident error faster than a static map would, because the confident estimator dismisses contradicting evidence instead of updating on it.

What survives the concession

Grant all of that. The conclusion that follows is not "abandon continuous intake" — it is "widen the prior and shorten the horizon over which any given model is trusted." Numerical weather prediction faces exactly this problem and has solved it the same way for decades: atmospheric dynamics are chaotic on any horizon beyond about ten days, so forecasters do not propagate one confident trajectory for a week and correct it once. They run ensembles of plausible states and reinitialise against fresh observation every six hours, because the model's own error growth is known and bounded, and the remedy is more frequent grounding in measurement, not less.

The same logic runs the other way in public safety. A risk map with no dynamics model worth trusting is not an argument for building the map once a year and running on it; it is an argument for treating the map as a prior with a short shelf-life, continuously pulled back towards the present by whatever is actually happening now. Weather feeds, gunshot detection triangulation, live dispatch telemetry, and the raw incident stream itself are not decoration on top of the risk map. They are the sextant sightings that stop the map's own drift from becoming policy. A duty officer staging units against last year's pattern while a live storm cell, three simultaneous structure fires and a stadium evacuation are all resolving on the same screen is dead reckoning with excellent initial conditions and no update — which is a Large Language Model's failure mode exactly, translated into shift work. The error is not that the initial map was bad. It is that nothing was allowed to contradict it in real time.

Apollo's actual answer to this

Apollo's engineers did not solve the "bad dynamics model" problem by trusting the model less in the abstract. They solved it by instrumenting the specific places where the model was known to be weak. The inertial platform drifted because gyros drift; there was no fixing that in the hardware available, so crews ran Program 52 star alignments to catch it directly, and ground Doppler tracking, accurate to a few tenths of a foot per second, caught what the sextant sightings missed between them. Mid-course burns of a few feet per second existed only because that continuous ground track kept exposing drift the onboard system could not see on its own.

The public safety equivalent is not a single better risk map. It is treating each stream as correcting a specific, named weakness in the prevailing model, with an explicit account of how much to trust it. Weather radar corrects the fire-risk model's assumption about wind and moisture, and it should be weighted accordingly and distrusted immediately if the model's category changes — a wind shift is not gentle correction, it is a new regime. Live dispatch telemetry corrects the assumption that demand follows the historical curve, and its weight should rise exactly when an anomaly starts recurring rather than appearing once. Sensor networks — gunshot detection, traffic loop counters, hospital bed availability feeds — each correct one narrow part of the prior, and none of them, on its own, replaces the prior. The prior is still doing most of the work, the way celestial mechanics did most of Apollo's work. The streams are there to catch the parts it gets wrong, and to say, with a number attached, how wrong.

The narrower claim

None of this rescues the idea that public safety has an exact dynamics model waiting to be found. It does not, and pretending otherwise produces exactly the over-confidence that collapses filters: a system, or a duty officer, that stops examining its own innovations because the map has worked well enough for long enough. The discipline that survives the objection is not a better model. It is the practice — mundane, procedural, borrowed wholesale from control theory — of tracking how far reality has strayed from prediction and treating that gap itself as the signal worth watching. An innovation sequence that starts looking structured rather than random is the same warning in a spacecraft and in an operations centre: the model has stopped fitting, before anyone has said so out loud.

A risk map that cannot be contradicted by tonight's incident feed is not a prior. It is a memory pretending to be a forecast.

What is terminal, on the narrow axis this lineage is about, is not the existence of a perfect process model for crime, fire and weather — there is none, and there may never be one. What is terminal is the recognition that no accumulation of historical pattern, however finely staged, substitutes for a live, weighted, provenance-tagged correction against what the streams are reporting right now. Apollo's crews could not out-predict gyro drift. They tracked it, continuously, and flew anyway. A duty officer cannot out-predict a heatwave, a transit strike and a stadium crowd landing on the same Friday. The map does not need to be exact. It needs to keep being checked.

Continue