Methodology

Rendered from the engine's METHODOLOGY.md at commit 6b351b02ca7b

Draft. This describes the method as designed. Measured accuracy figures will be added once the engine has run in production. Changes are listed at the end.

What we measure

For each sweep of London’s public traffic cameras we count:

Each sweep is tagged with the weather at that time: temperature, feels-like temperature and precipitation. Aggregating many sweeps gives the share of people wearing each item at each temperature, for example “at 12 °C, 71% wore a coat”.

We do not measure anything finer than these coarse attributes (sleeve length, colours, brands). At 352×288 pixels they are not reliable, and the product does not need them.

Pipeline

Step What happens Notes
Camera registry Download the current list of TfL JamCam cameras Refreshed every sweep; only cameras TfL lists as available are used (787 in a September 2026 test)
Fetch Download the latest still from each camera In memory only; one attempt per camera with a hard time limit; a failed camera is counted and skipped, never retried; only complete JPEG images are decoded
Detect YOLOX-m (Apache-2.0) on CPU via ONNX Runtime; classes person and umbrella About 190 ms per frame on a 4-core machine; chosen over YOLOX-s, which found about a quarter fewer people on the same frames
Classify Coarse attributes per person crop Method chosen in a later milestone; see Changelog
Aggregate Counts per sweep, joined to weather Published on the data branch as one JSON record per sweep (concatenates into JSON Lines)

Privacy

  1. Camera frames and person crops exist only in memory. They are never written to disk, logs, caches, CI artifacts, git or analytics services.
  2. No face detection, face recognition, re-identification, or tracking of anyone across frames.
  3. Only aggregate counts are published. The site never shows camera images or crops. To see a camera, follow the link to TfL’s own camera page.
  4. If a vision model is used for attribute labelling, it receives person crops only (never full frames), from a provider with data-processing terms, within a fixed monthly budget, and only the resulting labels are kept.
  5. Accuracy checks are done by hand, live, on a sample of current frames. A person views the crops in a window on their own computer; nothing is saved, and only the tallies and each box’s height in pixels are kept. Before launch at least 300 boxes are checked, across daylight, dusk and rain; after that, 100 a month and after every change to the detector or its thresholds. For one-off tests of automatic clothing labels, the same crops of single people may be sent, in memory, to an open-weights vision model at a hosting provider whose terms exclude storing, logging or training on them. The spot-check tool refuses to run in CI.

CI enforces rule 1 in two ways. A static check blocks image-writing calls in engine/. An end-to-end test runs a full sweep against a local fake camera server and checks that it creates no files except the aggregate output and leaves no image bytes in its working, home or temporary directories. Deliberate leaks in the test suite prove that these checks catch them. The detector’s runtime library (ONNX Runtime) has its built-in telemetry switched off, and a test checks that loading it writes nothing.

Sampling and known biases

Uncertainty and minimum sample

Validation

Results will be published here with dates and sample sizes.

Sources and attribution

Changelog