<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" version="2.0">
    <channel>
        
        <title>
            <![CDATA[ Reetain Raina - freeCodeCamp.org ]]>
        </title>
        <description>
            <![CDATA[ Browse thousands of programming tutorials written by experts. Learn Web Development, Data Science, DevOps, Security, and get developer career advice. ]]>
        </description>
        <link>https://www.freecodecamp.org/news/</link>
        <image>
            <url>https://cdn.freecodecamp.org/universal/favicons/favicon.png</url>
            <title>
                <![CDATA[ Reetain Raina - freeCodeCamp.org ]]>
            </title>
            <link>https://www.freecodecamp.org/news/</link>
        </image>
        <generator>Eleventy</generator>
        <lastBuildDate>Mon, 21 Sep 2026 05:09:18 +0000</lastBuildDate>
        <atom:link href="https://www.freecodecamp.org/news/author/reetain/rss.xml" rel="self" type="application/rss+xml" />
        <ttl>60</ttl>
        
            <item>
                <title>
                    <![CDATA[ Apple Watch’s New VO2 Max Test: How It Measures Your Cardiorespiratory Fitness ]]>
                </title>
                <description>
                    <![CDATA[ Your Apple Watch can tell you how fast you're moving, how your heart responds to exercise, and how your workout changes over time. But one of its more interesting fitness metrics is something it can't ]]>
                </description>
                <link>https://www.freecodecamp.org/news/apple-watch-vo2-max-test-cardiorespiratory-fitness/</link>
                <guid isPermaLink="false">6aa476cb322207896c23ef21</guid>
                
                    <category>
                        <![CDATA[ apple watch ]]>
                    </category>
                
                    <category>
                        <![CDATA[ VO2 Max ]]>
                    </category>
                
                    <category>
                        <![CDATA[ Wearable Technology ]]>
                    </category>
                
                    <category>
                        <![CDATA[ Health Tech  ]]>
                    </category>
                
                    <category>
                        <![CDATA[ Apple Health ]]>
                    </category>
                
                    <category>
                        <![CDATA[ Heart Rate Monitoring ]]>
                    </category>
                
                    <category>
                        <![CDATA[ Exercise Science ]]>
                    </category>
                
                <dc:creator>
                    <![CDATA[ Reetain Raina ]]>
                </dc:creator>
                <pubDate>Fri, 11 Sep 2026 21:46:51 +0000</pubDate>
                <media:content url="https://cdn.hashnode.com/uploads/covers/5e1e335a7a1d3fcc59028c64/63ffe5f1-2569-4684-8119-dcad13568ac9.png" medium="image" />
                <content:encoded>
                    <![CDATA[ <p>Your Apple Watch can tell you how fast you're moving, how your heart responds to exercise, and how your workout changes over time. But one of its more interesting fitness metrics is something it can't directly measure: VO2 max.</p>
<p>VO2 max represents the maximum amount of oxygen your body can use during intense exercise. It's widely used to assess cardiorespiratory fitness.</p>
<p>But unlike a laboratory test, an Apple Watch doesn't measure the oxygen you breathe in or out. Instead, it estimates VO2 max by combining data from sensors with information about your body and physical activity.</p>
<p>That raises an interesting question: How can a device sitting on your wrist estimate something happening deep inside your cardiovascular and respiratory systems?</p>
<p>With Apple Watch Series 12 and Apple Watch Ultra 4 introducing newer health-sensing capabilities alongside Apple's new at-home VO2 max assessment experience, understanding that number requires looking at more than just the result on the screen.</p>
<h3 id="heading-what-well-cover">What We'll Cover:</h3>
<ul>
<li><p><a href="#heading-what-exactly-is-vo2-max-and-why-does-it-matter">What Exactly Is VO2 Max and Why Does It Matter?</a></p>
</li>
<li><p><a href="#heading-the-original-vo2-max-test-was-not-designed-for-your-wrist">The Original VO2 Max Test Was Not Designed for Your Wrist</a></p>
</li>
<li><p><a href="#heading-so-how-does-a-watch-estimate-something-it-cant-directly-measure">So How Does a Watch Estimate Something It Can't Directly Measure?</a></p>
</li>
<li><p><a href="#heading-meet-the-new-apple-watch-vo2-max-experience">Meet the New Apple Watch VO2 Max Experience</a></p>
</li>
<li><p><a href="#heading-apple-watch-series-12-why-better-heart-rate-data-matters">Apple Watch Series 12: Why Better Heart-Rate Data Matters</a></p>
</li>
<li><p><a href="#heading-apple-watch-ultra-4-why-gps-can-add-important-context">Apple Watch Ultra 4: Why GPS Can Add Important Context</a></p>
</li>
<li><p><a href="#heading-what-happens-when-you-stop-moving-but-your-workout-keeps-running">What Happens When You Stop Moving but Your Workout Keeps Running?</a></p>
</li>
<li><p><a href="#heading-why-vo2-max-isnt-just-a-speed-versus-heart-rate-equation">Why VO2 Max Isn't Just a Speed-versus-Heart-Rate Equation</a></p>
</li>
<li><p><a href="#heading-but-how-accurate-is-the-apple-watchs-vo2-max-estimate">But How Accurate is the Apple Watch's VO2 Max Estimate?</a></p>
</li>
<li><p><a href="#heading-wrapping-up">Wrapping Up</a></p>
</li>
</ul>
<h2 id="heading-what-exactly-is-vo2-max-and-why-does-it-matter">What Exactly Is VO2 Max and Why Does It Matter?</h2>
<p>To decipher what your watch tells you, it's important to first understand the science of the metric. VO2 max essentially refers to the maximum volume of oxygen that can be used by the body while working at high intensities.</p>
<p>It's important for the body to continuously have oxygen available so that it can produce energy. Whether you're walking, jogging, cycling, or running, your body needs several biological systems to coordinate flawlessly.</p>
<p>The first step is for the lungs to bring oxygen to the body. After that, our heart pumps oxygen-rich blood very fast through the veins. The vital oxygen goes directly to the body muscles where it's used to produce the energy needed for the body's activity. The efficiency of the whole process is expressed by the VO2 max.</p>
<p>It's often presented using mL/kg/min, which just translates to milliliters of oxygen consumed per kilogram of body weight per minute. You can view VO2max as a rather crude estimate of how well your body is able to consume oxygen in situations of very high energy demand.</p>
<p>Due to the link between cardiorespiratory fitness and various health outcomes, VO2max is often used in exercise physiology and health literature.</p>
<h2 id="heading-the-original-vo2-max-test-was-not-designed-for-your-wrist">The Original VO2 Max Test Was Not Designed for Your Wrist</h2>
<h3 id="heading-the-lab-version">The Lab Version</h3>
<p>Traditionally, to determine exact VO2 max, physicians would apply a relatively strenuous method. For example, the test subject would run on the treadmill or perform strenuous exercise on the stationary bike. At the same time, they'd be wearing the mask, which would be tightly attached to a metabolic analyzer. As the exercise got more intense, the test subject would start breathing harder and harder.</p>
<p>At the same time, the subject would need to exert themself until they reached their peak level or total exhaustion. While exercising, the complex equipment would precisely measure the amount of oxygen that entered into their body and the quantity of carbon dioxide being released. This detailed measurement of their breathing is why lab testing is the traditional/preferred method of determining VO2 max.</p>
<p>But herein lies a huge practical issue: though the lab method is quite precise, it's not something you'd randomly do (or easily be able to do) after work on a Tuesday night, for example. This practical problem is partly why wearables have come into play.</p>
<h2 id="heading-so-how-does-a-watch-estimate-something-it-cant-directly-measure">So How Does a Watch Estimate Something It Can't Directly Measure?</h2>
<p>Again, note that an Apple Watch doesn't measure your metabolism via a direct test, like measuring cardiorespiratory function using a lab breathing mask. The device calculates cardiorespiratory fitness by utilizing complicated mathematical equations involving your physiological and workout data.</p>
<p>Apple openly admits that cardiorespiratory fitness is measured by VO2 max and workouts. In calculating, Apple takes into account a number of parameters, including age, gender, weight, height, medications that might influence heart rate, and a great deal of sensor data.</p>
<p>In other words, the watch focuses on one basic principle: how hard your heart is working compared to the effort you're producing physically.</p>
<p>Let's take two people running at the same brisk pace. Person A has a rather low heart rate while keeping this pace, showing that their cardiovascular system works effectively. Person B has a significantly higher heart rate while maintaining the same pace.</p>
<p>Over time, it's possible for an advanced algorithm to figure out the differences in their cardiorespiratory fitness. The algorithm uses relationships between all those data points. And while the exact calculation method isn't public, the physiological concept behind it is pretty clear.</p>
<h2 id="heading-meet-the-new-apple-watch-vo2-max-experience">Meet the New Apple Watch VO2 Max Experience</h2>
<p>The hardware updates released in late 2026 came with significant improvements in interacting with and interpreting these metrics.</p>
<p>In particular, the newly designed Health feature actively supports at-home measurements, giving users the option to take an accurate and guided test to evaluate their VO2 max. According to Apple, you can perform this evaluation using either the Apple Watch Series 12, Apple Watch Ultra 4, AirPods Pro, or any other compatible heart rate sensor device.</p>
<h3 id="heading-this-is-more-than-just-looking-at-your-workout-history">This Is More Than Just Looking at Your Workout History</h3>
<p>Previously, only VO2 max estimation from certain background outdoor exercises was allowed, like outdoor walking, outdoor running, and hiking. In other words, the software would just passively monitor your activity while you were doing something in real life.</p>
<p>Now, the newly designed Health experience brings you closer to a more accurate clinical-like assessment of VO2 max. In contrast to passive measurement based on random monitoring by your Apple Watch, the current version of the application lets you conduct a guided at-home physical test to evaluate your VO2 max.</p>
<h2 id="heading-apple-watch-series-12-why-better-heart-rate-data-matters">Apple Watch Series 12: Why Better Heart-Rate Data Matters</h2>
<p>To ensure that these figures are accurate, the quality of the raw data should be high. The latest generation of the <a href="https://wearablexp.com/smart-watches/apple-watch-series-12/">Apple Watch Series 12</a> is equipped with Apple's innovative <strong>Health Sensing System</strong> that provides heart rate and HRV (heart rate variability) monitoring at significantly higher frequencies. In fact, <em>heart rate background measurements are made every 5 seconds</em>. According to Apple, this advanced sensing system gives the most accurate heart-rate sensing ever seen on a wearable device.</p>
<h3 id="heading-heart-rate-is-one-of-the-most-important-pieces-of-the-puzzle">Heart Rate Is One of the Most Important Pieces of the Puzzle</h3>
<p>When you undergo any kind of strenuous exercise, your muscles need more energy than usual. This means your body needs more oxygen, so your heart tends to work harder and faster to respond to that.</p>
<p>But heart rate by itself doesn't just magically reveal your VO2 max. The device needs to analyze your heart rate <strong>along with</strong> the precise details of your physical activities, how intensely you exercise, your pace of running, and other health information. Then it can really help in estimating your cardiorespiratory fitness.</p>
<p>Bear in mind that the optical heart-rate monitor doesn't literally detect the oxygen flow in your muscles. Rather, it gives one of the key physiological inputs used by the complex estimation model to crunch its numbers.</p>
<h2 id="heading-apple-watch-ultra-4-why-gps-can-add-important-context">Apple Watch Ultra 4: Why GPS Can Add Important Context</h2>
<p>Although the Series 12 enhances biological sensing, the Apple Watch Ultra 4 prioritizes high spatial precision. In fact, Apple advertises that the Ultra 4 features very precise GPS functions that are specifically designed for tough sporting and outdoor pursuits. Indeed, VO2 max is listed amongst its premium running exercise metrics.</p>
<h3 id="heading-movement-data-gives-heart-rate-a-story">Movement Data Gives Heart Rate a Story</h3>
<p>The fact of the matter is that your heart rate alone doesn't indicate what you're doing physically. Your heart rate may be 150 beats per minute because you're jogging uphill, sprinting along a flat surface, exercising in extreme summer temperatures, climbing several flights of stairs, or even engaging in a completely different physiological response altogether such as being stressed out.</p>
<p>Movement and location-specific data about workouts can help fill in this information gap. This is because the watch can match up your heart rate with all sorts of analysis related to your pace, total distance traveled, drastic change in movement, workout time, and, more importantly, your geographical location.</p>
<h2 id="heading-what-happens-when-you-stop-moving-but-your-workout-keeps-running">What Happens When You Stop Moving but Your Workout Keeps Running?</h2>
<p>When your run comes to a sudden halt, your legs stop moving, but your heart hasn't received the memo yet. The watch on your wrist continues actively collecting workout information. The internal motion sensors can detect major, sudden changes in your movement, while GPS-equipped models effortlessly record the immediate drop in your pace and your stationary location during the outdoor activity. Meanwhile, your heart rate may easily remain elevated even after your physical movement slows down or stops entirely.</p>
<p>Rapid changes in movement and cardiovascular effort can create incredibly complicated physiological data. A person's running pace may suddenly drop to zero while their heart rate remains high simply because the human cardiovascular system doesn't instantly return to its resting baseline levels.</p>
<p>This means that estimation algorithms continuously need to interpret those changing signals and accurately determine which specific parts of the recorded activity actually provide useful, stable information about your cardiorespiratory fitness.</p>
<p>Because Apple doesn't publicly provide the complete proprietary algorithm, we can't definitively claim that an unexpected pause automatically produces a lower VO2 max score. The software is likely designed to filter out these brief, noisy anomalies, but it highlights exactly why interpreting wearable data is such a difficult engineering challenge.</p>
<h2 id="heading-why-vo2-max-isnt-just-a-speed-versus-heart-rate-equation">Why VO2 Max Isn't Just a Speed-versus-Heart-Rate Equation</h2>
<p>While comparing your pace with your heart rate would help you understand the idea generally, the real science behind VO2 max estimation is much more complex.</p>
<p>The way that Apple employs in its VO2 max estimation process is highly dependent on several individual and environmental factors that could have a huge impact on your heart rate response. Some of those factors include your age, your biological gender, your body weight, your actual height, the heart rate-affecting medicines you are taking daily, the particular type of exercise, the level of your effort and the quality of the sensor readings.</p>
<p>The <a href="https://support.apple.com/en-in/108790">official support documentation provided by Apple</a> states that your watch is capable of estimating your VO2 max in a range of 14-65 mL/kg/min, ensuring it covers a broad spectrum of human fitness levels.</p>
<h2 id="heading-but-how-accurate-is-the-apple-watchs-vo2-max-estimate">But How Accurate is the Apple Watch's VO2 Max Estimate?</h2>
<p>This is where the marketing promises meet peer-reviewed scientific reality. The research regarding wearable accuracy is nuanced and we can't simply declare that the watch accurately measures VO2 max without looking closely at the data.</p>
<h3 id="heading-what-scientific-studies-say-about-apple-watch-vo2-max">What Scientific Studies Say About Apple Watch VO2 Max</h3>
<p>A <a href="https://journals.plos.org/plosone/article?id=10.1371/journal.pone.0323741">2025 validation study published in PLOS ONE</a> compared Apple Watch VO2 max estimates directly with indirect calorimetry (the strict lab standard). The researchers found that the Apple Watch actually underestimated VO2 max on average and reported a mean absolute percentage error of approximately 13%.</p>
<p>The study thoughtfully concluded that these estimates still require refinement before true clinical implementation, although the watch may remain practically useful as a more accessible alternative to conventional lab testing.</p>
<p>In other words, the watch was useful for producing a convenient estimate, but individual results could differ meaningfully from the exact value measured by a doctor in a lab.</p>
<p>Also, a 2024 validation study evaluating the older Apple Watch Series 7 also compared wearable estimates with laboratory testing using a metabolic gas analyzer. The researchers found notable differences between the predicted and laboratory-measured values.</p>
<p>This doesn't mean the Apple Watch is useless. But again, it means that a we shouldn't treat a convenient wearable estimate as identical to a rigorous laboratory measurement.</p>
<p>A more recent <a href="https://www.researchgate.net/publication/403583901_Accuracy_of_VO2_max_Estimates_from_Apple_Watch_Series_10">2026 study evaluating the Apple Watch Series 10</a> echoed these precise findings, noting that the watch underestimated VO2 max overall compared with indirect calorimetry and showed meaningful variability at the individual user level.</p>
<p>The authors suggested that wearable estimates may still hold great value in research or broad population-level contexts but require further longitudinal validation for individual measurement reliability.</p>
<h2 id="heading-wrapping-up">Wrapping Up</h2>
<p>Apple Watch Series 12 and Ultra 4 make VO2 max easier to assess by combining heart-rate, movement, and other health data to estimate cardiorespiratory fitness. While the new at-home assessment offers a more structured way to get that estimate, the watch still can't directly measure oxygen consumption like a lab test can.</p>
<p>The number, then, is best understood as an estimate, but an interesting one that shows how sensors, physiology, and algorithms can work together to reveal more about your fitness.</p>
 ]]>
                </content:encoded>
            </item>
        
            <item>
                <title>
                    <![CDATA[ How AI Is Changing Patching and What Devs Need to Know About Exposure Management ]]>
                </title>
                <description>
                    <![CDATA[ When a vulnerability scanner reports 23 vulnerabilities in your application, of which 4 are critical, 7 are high, and the remaining 12 are medium, at first glance the answer seems clear: start patchin ]]>
                </description>
                <link>https://www.freecodecamp.org/news/how-ai-is-breaking-traditional-patch-management/</link>
                <guid isPermaLink="false">6a9aefa26eac286787fb7078</guid>
                
                    <category>
                        <![CDATA[ Artificial Intelligence ]]>
                    </category>
                
                    <category>
                        <![CDATA[ cybersecurity ]]>
                    </category>
                
                    <category>
                        <![CDATA[ Vulnerability management ]]>
                    </category>
                
                    <category>
                        <![CDATA[ Patch management ]]>
                    </category>
                
                    <category>
                        <![CDATA[ DevSecOps ]]>
                    </category>
                
                    <category>
                        <![CDATA[ software security ]]>
                    </category>
                
                    <category>
                        <![CDATA[ Exposure Management ]]>
                    </category>
                
                <dc:creator>
                    <![CDATA[ Reetain Raina ]]>
                </dc:creator>
                <pubDate>Fri, 04 Sep 2026 16:19:46 +0000</pubDate>
                <media:content url="https://cdn.hashnode.com/uploads/covers/5e1e335a7a1d3fcc59028c64/ce5b87e6-1941-493c-a2c9-7822138160d6.png" medium="image" />
                <content:encoded>
                    <![CDATA[ <p>When a vulnerability scanner reports 23 vulnerabilities in your application, of which 4 are critical, 7 are high, and the remaining 12 are medium, at first glance the answer seems clear: start patching. But which one should you fix first?</p>
<p>This has always been an issue in vulnerability management. While a security team might find out about the vulnerable dependency, fixing it may not always be possible at once. Developers need to ensure that the vulnerable code is in use and perform all necessary checks before releasing the fix into production.</p>
<p>Recently, though, there have been some solid advancements in the use of AI for discovering software vulnerabilities and exploits. This <a href="https://dl.acm.org/doi/10.1145/3708522">research</a>, for example, details some of the findings and the path forward.</p>
<p>But how will this really help the development community? We need to fix things more quickly, but more importantly, we need to be able to figure out which vulnerabilities actually matter and which ones need attention first.</p>
<p>In this article, we'll examine what the classic patching process looks like, how AI is decreasing the amount of time security teams have to react, and why it's not always reasonable just to address vulnerabilities by their severity score.</p>
<p>We'll also discuss exposure management and the difference between it and traditional vulnerability management. Then we'll cover how developers can analyze dependencies, code reachability, and Software Bill of Materials (SBOMs) to figure out the actual vulnerabilities in their applications.</p>
<h3 id="heading-what-well-cover">What We'll Cover:</h3>
<ul>
<li><p><a href="#heading-patching-vs-exposure-management-whats-the-difference">Patching vs. Exposure Management: What's the Difference?</a></p>
<ul>
<li><p><a href="#heading-what-is-patching">What Is Patching?</a></p>
</li>
<li><p><a href="#heading-what-is-exposure-management">What Is Exposure Management?</a></p>
</li>
</ul>
</li>
<li><p><a href="#heading-the-old-patch-management-workflow-was-built-around-time">The Old Patch Management Workflow Was Built Around Time</a></p>
</li>
<li><p><a href="#heading-ai-is-shrinking-the-time-between-found-and-exploited">AI Is Shrinking the Time Between "Found" and "Exploited"</a></p>
</li>
<li><p><a href="#heading-why-patch-everything-doesnt-work-at-scale">Why "Patch Everything" Doesn't Work at Scale</a></p>
</li>
<li><p><a href="#heading-exposure-management-moving-from-flaw-counts-to-contextual-risk">Exposure Management: Moving from Flaw Counts to Contextual Risk</a></p>
</li>
<li><p><a href="#heading-the-dependency-tree-as-an-attack-surface">The Dependency Tree as an Attack Surface</a></p>
</li>
<li><p><a href="#heading-practical-takeaways-for-developers">Practical Takeaways for Developers</a></p>
<ul>
<li><p><a href="#heading-audit-transitive-dependencies">Audit Transitive Dependencies</a></p>
</li>
<li><p><a href="#heading-check-code-reachability">Check Code Reachability</a></p>
</li>
<li><p><a href="#heading-generate-an-sbom-in-cicd">Generate an SBOM in CI/CD</a></p>
</li>
<li><p><a href="#heading-use-compensating-controls-when-a-patch-isnt-ready">Use Compensating Controls When a Patch Isn't Ready</a></p>
</li>
<li><p><a href="#heading-apply-least-privilege-at-runtime">Apply Least Privilege at Runtime</a></p>
</li>
</ul>
</li>
<li><p><a href="#heading-wrap-up">Wrap Up</a></p>
</li>
</ul>
<h2 id="heading-patching-vs-exposure-management-whats-the-difference">Patching vs. Exposure Management: What's the Difference?</h2>
<p>Before we look at how AI is changing vulnerability response, it helps to understand two important concepts: patching and exposure management.</p>
<h3 id="heading-what-is-patching">What Is Patching?</h3>
<p>Patching is a process of updating software to address an existing issue, including a security vulnerability, bug, or a stability problem. This may involve upgrading a library with a known vulnerability, applying a security update for your operating system, or using a new release of an application with a vulnerability fixed.</p>
<p>For instance, if your application uses a particular library with a known security vulnerability, you can upgrade the library once the patched version is available. After that, you'll need to test the update, ensure that the application still operates as intended, and release the upgraded version into production.</p>
<p>So patching isn't only about installing the latest version of the package in question. A dependency update can break an API, some functionality, or even other dependent packages. That's why teams typically use patch management strategies when identifying vulnerabilities, updating decision-making, testing, deploying, and verifying that the patches work.</p>
<h3 id="heading-what-is-exposure-management">What Is Exposure Management?</h3>
<p>While vulnerability management is concerned mainly with identifying vulnerabilities, exposure management focuses more broadly on whether those vulnerabilities can actually provide a realistic route for an attack.</p>
<p>For example, a vulnerable library, limited in use to a development system, poses less immediate threat than a similarly vulnerable library used in an internet-facing system that's capable of accessing the database.</p>
<p>Some aspects to consider include accessibility via network, asset exposure, vulnerable code paths, identity and access controls, cloud environments, and the sensitivity of systems and data.</p>
<p>Simply put, vulnerability management is concerned with the discovery and tracking of vulnerabilities, whereas exposure management is focused on determining which of those vulnerabilities pose a true or larger risk.</p>
<h2 id="heading-the-old-patch-management-workflow-was-built-around-time">The Old Patch Management Workflow Was Built Around Time</h2>
<p>The classic process of vulnerability mitigation depended on step-by-step actions.</p>
<ol>
<li><p>CVE discovered</p>
</li>
<li><p>Security team assesses the severity</p>
</li>
<li><p>Maintainer releases an upstream patch</p>
</li>
<li><p>Developer updates the dependency</p>
</li>
<li><p>CI/CD pipeline runs regression tests</p>
</li>
<li><p>Production deployment</p>
</li>
<li><p>Remediation verified</p>
</li>
</ol>
<p>The process wasn't flawed by nature, but it operated under the unspoken premise that the defenders were granted enough room to operate through each step.</p>
<p>Let's take a dependency vulnerability example for practice. If the automated scanner detects a vulnerability within a popular utility package such as <strong>lodash</strong>, engineers don't immediately bump the dependency version in the production environment. They need to confirm if the application code leverages the vulnerable function, check the presence of breaking API changes after the upgrade, and run build validation through integration tests.</p>
<p>Each security patch is essentially a change to the code and needs to be safely pushed through the development and deployment cycle.</p>
<h2 id="heading-ai-is-shrinking-the-time-between-found-and-exploited">AI Is Shrinking the Time Between "Found" and "Exploited"</h2>
<p>The buffer between vulnerability discovery and exploitation that used to exist is being eliminated. This is because automated programs can scan through codebases, generate proofs of concept, and discover edge cases.</p>
<p>Modern AI systems help researchers and would-be attackers alike perform tasks like static binary analysis, detecting vulnerabilities, creating exploit payloads, and finding logical issues in complicated software designs.</p>
<p>Programs such as <a href="https://www.darpa.mil/news/2024/ai-cyber-challenge-cybersecurity">DARPA’s Artificial Intelligence Cyber Challenge</a> (AIxCC) show how AI systems can be used to automatically find and patch vulnerabilities in complex open-source software. During the 2024 semifinal competition, autonomous Cyber Reasoning Systems were tested against projects based on real-world software such as Jenkins, the Linux kernel, Nginx, SQLite3, and Apache Tika. The systems discovered 22 unique synthetic vulnerabilities and successfully patched 15 of them. They also identified one real-world bug in SQLite3, which was responsibly disclosed.</p>
<p>In the context of a real development process, certain tasks in the patching process can be performed by AI. The AI could perform code analysis and dependency analysis in order to detect potential vulnerabilities. It could also help trace the usage of vulnerable functions, recommend changes in code and dependencies, and generate tests to make sure that the suggested patch doesn’t break the existing functionality. The security team could also use AI for pattern detection.</p>
<p>As AI tools get better at assessing software and detecting vulnerabilities, the window of time between vulnerability detection and its mitigation becomes smaller and more important. This change in paradigm also affects how security professionals approach <a href="https://www.axonius.com/blog/from-vulnpocalypse-to-patchmageddon-security-ops-in-the-ai-era">AI and exposure management</a>, especially as the exploit window gets smaller and vulnerabilities need proper prioritization.</p>
<p>AI can also support exposure management by connecting vulnerability information with the environment in which the vulnerable software is running. For example, an AI-assisted security system could correlate a vulnerable dependency with an internet-facing application, its network connections, cloud permissions, and the data or services it can access. This helps security teams move from simply asking whether a vulnerability exists to asking <strong>what an attacker could realistically reach through it</strong>.</p>
<h2 id="heading-why-patch-everything-doesnt-work-at-scale">Why "Patch Everything" Doesn't Work at Scale</h2>
<p>When an organization-wide scanner generates a list of 500 vulnerabilities spread across multiple microservices, reacting to each one with urgency starts to seem impossible. Developers can suffer from alert fatigue and get overwhelmed pretty easily.</p>
<p>The <a href="https://nvd.nist.gov/vuln-metrics/cvss">Common Vulnerability Scoring System</a> (CVSS) is a standardized framework used to describe the severity of a vulnerability. CVSS v3.1 uses the following severity ranges:</p>
<table style="min-width:50px"><colgroup><col style="min-width:25px"><col style="min-width:25px"></colgroup><tbody><tr><td><p><strong>CVSS Score&nbsp;</strong></p></td><td><p><strong>Severity&nbsp;</strong></p></td></tr><tr><td><p>0.0&nbsp;</p></td><td><p>None&nbsp;</p></td></tr><tr><td><p>0.1–3.9&nbsp;</p></td><td><p>Low&nbsp;</p></td></tr><tr><td><p>4.0–6.9&nbsp;</p></td><td><p>Medium&nbsp;</p></td></tr><tr><td><p>7.0–8.9&nbsp;</p></td><td><p>High&nbsp;</p></td></tr><tr><td><p>9.0–10.0&nbsp;</p></td><td><p>Critical&nbsp;</p></td></tr></tbody></table>

<p>CVSS is useful because it provides both developers and security teams with a common language that describes the severity of a vulnerability. Nevertheless, the rating describes the vulnerability but not the environment where this vulnerability appears. In other words, CVSS doesn't tell you if the functionality used by the vulnerability is really used by your application or if the affected system is exposed to the Internet.</p>
<p>To see why CVSS alone isn't always enough, let's say we have two hypothetical vulnerabilities in an organization's environment:</p>
<ul>
<li><p><strong>Vulnerability A:</strong> This critical remote code execution vulnerability is part of an isolated testing harness or development-only dependency that's never included in the production environment and doesn't have any external network accessibility.</p>
</li>
<li><p><strong>Vulnerability B:</strong> A high-severity input validation vulnerability is found in an internet-facing API gateway that processes malicious user input and has access to a backend database with customer information.</p>
</li>
</ul>
<p>Looking at just the CVSS score would require the team to focus on Vulnerability A before Vulnerability B. But it's clear that Vulnerability B poses the greater threat to operations. Security studies show us that very few vulnerabilities get exploited once they're known. Telemetry data from the <a href="https://www.runzero.com/resources/kevology/">CISA KEV Catalog</a> clearly indicates that attackers focus on a subset of vulnerabilities that have a real path of exploitation.</p>
<p>In reality, teams must consider the CVSS score in addition to many contextual factors when deciding what to fix. A particular vulnerability might have a higher priority if the following conditions are true:</p>
<ul>
<li><p>it has an impact on an internet-facing production system,</p>
</li>
<li><p>there's a known exploit for the vulnerability,</p>
</li>
<li><p>there's sensitive information exposed,</p>
</li>
<li><p>it impacts an important business function,</p>
</li>
<li><p>or it offers an attacker a means of gaining access to other privileged systems.</p>
</li>
</ul>
<p>But vulnerabilities that occur only in development or are inaccessible for some reason likely don't need to be fixed immediately.</p>
<p>The most appropriate method for determining the importance of vulnerabilities is asking some straightforward questions: Is the vulnerable system accessible? Is the vulnerable code accessible? Is there any exploit for this vulnerability? What privileges does the affected service have? What will an attacker be able to access after exploiting the vulnerability?</p>
<p>Assigning the same level of priority to all alerts wastes engineering efforts on vulnerabilities that might pose no or little risk at all.</p>
<h2 id="heading-exposure-management-moving-from-flaw-counts-to-contextual-risk">Exposure Management: Moving from Flaw Counts to Contextual Risk</h2>
<p>Exposure management shifts focus from simply cataloging static vulnerabilities to evaluating an organization's actual operational risk posture.</p>
<p>Instead of asking "How many CVEs exist in our repositories?", exposure management asks "Which vulnerable components, misconfigurations, and reachable network paths create exploitable risk across our running assets?"</p>
<p>The difference becomes easier to see when you look at what each approach focuses on:</p>
<table style="min-width:75px"><colgroup><col style="min-width:25px"><col style="min-width:25px"><col style="min-width:25px"></colgroup><tbody><tr><td><p><strong>Dimension&nbsp;</strong></p></td><td><p><strong>Traditional Vulnerability Management&nbsp;</strong></p></td><td><p><strong>Exposure Management&nbsp;</strong></p></td></tr><tr><td><p>Primary Question&nbsp;</p></td><td><p>What software bugs and CVEs exist?&nbsp;</p></td><td><p>What paths can an attacker exploit to access critical assets?&nbsp;</p></td></tr><tr><td><p>Data Scope&nbsp;</p></td><td><p>Isolated dependency scans and static vulnerability databases&nbsp;</p></td><td><p>Code repositories, cloud runtime, network routing and IAM permissions&nbsp;</p></td></tr><tr><td><p>Prioritization Metric&nbsp;</p></td><td><p>CVSS base scores and static severity ratings&nbsp;</p></td><td><p>Reachability, exploitability, asset sensitivity and environment context&nbsp;</p></td></tr><tr><td><p>Primary Action&nbsp;</p></td><td><p>Upstream package upgrades and direct software patches&nbsp;</p></td><td><p>Risk-based triage: network isolation, configuration changes, or targeted patching&nbsp;</p></td></tr></tbody></table>

<p>When there are 10,000 cloud assets managed by an engineering environment and 1,000 vulnerable libraries found through dependency scanners, the combined numbers don't represent the actual security situation. In order to focus on the right level of risks, you should have some knowledge about the context within which each of these vulnerabilities exists.</p>
<ul>
<li><p>Is the container exposed to the internet or is it hidden behind the internal load balancer?</p>
</li>
<li><p>Is the code actually invoking the risky symbol or library function?</p>
</li>
<li><p>What are the identity permissions, cloud roles, and databases that are accessible through the vulnerable service?</p>
</li>
</ul>
<p>Having an understanding of this denominator (total numbers of assets that should receive a specific patch) helps teams identify the exposures that are actually threats so that engineering time is spent on solving the problems that impact production data.</p>
<h2 id="heading-the-dependency-tree-as-an-attack-surface">The Dependency Tree as an Attack Surface</h2>
<p>Modern software delivery depends on multi-layered packages such as npm, PyPI, Maven, NuGet, base operating system layer packages, GitHub Actions, and third-party APIs. The application logic is written by developers, but the final runtime software contains numerous levels of packages:</p>
<p>Your Application Logic → Direct Dependency (Declared in manifest) → Transitive Dependency (Pulled in automatically) → Underlying OS System Packages → Base Container Image / Cloud Runtime.</p>
<p>If a vulnerability is three levels down in the transitive dependencies and the transitive dependency is unmaintained, but can be accessed via external inputs, then that's an essential part of your application's attack surface.</p>
<p>That's why software development teams have started to use Software Bill of Materials (SBOMs). An SBOM is an inventory of software components that constitute the software or application. Depending on the technology used to create the SBOM, different information can be available including component name, version, dependencies and package ID.</p>
<p>It's helpful in cases where a new vulnerability has been identified. For example, if a vulnerability is discovered in a specific version of lodash, the security team can use its SBOMs to identify which applications or container images contain the affected version. They'll then be able to investigate if there's an exploitable exposure.</p>
<p>An SBOM alone doesn't provide security for the application. Its significance lies in increasing visibility to developers and security personnel regarding what is present in their applications.</p>
<h2 id="heading-practical-takeaways-for-developers">Practical Takeaways for Developers</h2>
<p>These principles will be relevant once you integrate them into your team's routine development process. There are some practical ways you and your team can employ these best practices and strategies:</p>
<h3 id="heading-audit-transitive-dependencies">Audit Transitive Dependencies</h3>
<p>The first thing to do is to verify what dependencies are included in your application. This is very useful when it comes to transitive dependencies, because these dependencies may have been automatically added when installing some other package directly.</p>
<p>For Node.js applications, the command <code>npm ls</code> will display the dependency tree. Python programmers may use <code>pipdeptree</code>, while Java programs created using Maven can use the <code>mvn dependency:tree</code> command. These commands can help you understand the origins of packages and the direct dependency that introduced a vulnerable transitive dependency into your project.</p>
<h3 id="heading-check-code-reachability">Check Code Reachability</h3>
<p>Finding a weak point in a dependency doesn't automatically imply that you're using it within your application. Don't take every vulnerability report as a critical production blocker. Instead, you should investigate if the impacted functionality is actually accessible from your application.</p>
<p>Suppose you find a vulnerability in a certain library function. In this case, you need to look through your codebase for any usage of this function and figure out if there's any possibility of passing user-controlled data to it. You may use either the search function provided by your IDE or command-line utilities such as grep.</p>
<p>An unused or inaccessible from the outside function reduces the urgency of the finding. But it doesn't automatically imply that you should ignore it.</p>
<h3 id="heading-generate-an-sbom-in-cicd">Generate an SBOM in CI/CD</h3>
<p>You can also produce a Software Bill of Materials using your <strong>CI/CD pipeline</strong>. Creating an SBOM will help you identify the components used in the software and make it easier to identify affected components once a vulnerability is found.</p>
<p>For instance, using Syft, you can generate an SBOM from a container image by executing the command: <code>syft my-app:latest -o cyclonedx-json &gt; sbom.json</code>.</p>
<p>This will create a CycloneDX JSON file with information on the components within the container image. This SBOM will then be stored along with the build artifacts. Once a new vulnerability is identified in a particular package version, it becomes easy for the security team to know which applications and container images contain this particular component.</p>
<h3 id="heading-use-compensating-controls-when-a-patch-isnt-ready">Use Compensating Controls When a Patch Isn't Ready</h3>
<p>Sometimes there may be no patch available or it may be too risky to implement it straight away since doing so might introduce breaking changes that need further testing. In such cases, you can use compensatory controls to lessen the exposure of the application until it's patched properly.</p>
<p>Depending on the environment, this may involve limiting the network access to the vulnerable component, isolating the workload from sensitive resources, disabling the feature that has been compromised, or minimizing the privileges of the application.</p>
<p>These controls don't take the place of the security patch but only minimize the risk of exploitation until a patch is implemented.</p>
<h3 id="heading-apply-least-privilege-at-runtime">Apply Least Privilege at Runtime</h3>
<p>Lastly, restrict the amount of access your applications have at run time. When a compromise is made due to exploitation, it prevents the spread of that breach to other applications or systems.</p>
<p>When deploying container-based applications, you can leverage read-only filesystems, as well as remove capabilities that aren't required in Linux. For instance, Docker provides the option to use <code>--read-only</code> and <code>--cap-drop=ALL</code> when running containers.</p>
<p>Cloud applications also need to adopt the same concept by ensuring the use of IAM permissions, giving access only to what the application requires.</p>
<p><strong>The goal is simple:</strong> if one element has been breached, the attacker should be able to gain access to as few components of the environment around it as possible.</p>
<p>The future of software security doesn't rely on how fast organizations can update their packages without knowing the underlying reasons for doing so. With vulnerability detection becoming more efficient through automation, effective mitigation relies on knowledge about the relationship between the source code, its dependencies, and infrastructure at runtime.</p>
<p>The purpose here isn't just finding new vulnerabilities but recognizing the ones that pose real risks to the application.</p>
<h2 id="heading-wrap-up">Wrap Up</h2>
<p>While artificial intelligence is helping teams detect vulnerabilities quicker, modern applications keep becoming increasingly dependent on numerous software layers. This doesn't mean that patching becomes unnecessary. It means that all vulnerabilities don't require the same immediate attention.</p>
<p>Developers also still need to look at where those vulnerabilities exist, whether they're reachable by attackers, and what they could affect. As the time between vulnerability detection and exploitation continues to change, understanding exposure becomes just as important as the patch itself.</p>
 ]]>
                </content:encoded>
            </item>
        
            <item>
                <title>
                    <![CDATA[ How Sensors Collect, Process, and Track Data in Wearable Devices ]]>
                </title>
                <description>
                    <![CDATA[ A smartwatch can tell you that your heart rate is 78 beats per minute, that you've walked 6,421 steps, or that you slept for 7 hours last night. All of these numbers appear simple on the screen, but b ]]>
                </description>
                <link>https://www.freecodecamp.org/news/how-sensors-collect-process-and-track-data-in-wearables/</link>
                <guid isPermaLink="false">6a887ddeb55a70d585eec152</guid>
                
                    <category>
                        <![CDATA[ Wearables ]]>
                    </category>
                
                    <category>
                        <![CDATA[ sensors ]]>
                    </category>
                
                    <category>
                        <![CDATA[ iot ]]>
                    </category>
                
                    <category>
                        <![CDATA[ Machine Learning ]]>
                    </category>
                
                <dc:creator>
                    <![CDATA[ Reetain Raina ]]>
                </dc:creator>
                <pubDate>Fri, 21 Aug 2026 16:33:34 +0000</pubDate>
                <media:content url="https://cdn.hashnode.com/uploads/covers/5e1e335a7a1d3fcc59028c64/e0ee25a6-436d-48d6-abca-9519b531707a.png" medium="image" />
                <content:encoded>
                    <![CDATA[ <p>A smartwatch can tell you that your heart rate is 78 beats per minute, that you've walked 6,421 steps, or that you slept for 7 hours last night. All of these numbers appear simple on the screen, but behind each one is a surprisingly long chain of measurements and calculations.</p>
<p>Your watch doesn't actually see a "step" or directly measure "sleep." Instead, tiny sensors continuously detect things such as movement, changes in blood flow, electrical activity, and temperature. Those signals are converted into digital data, processed to remove noise, and analyzed by algorithms that look for meaningful patterns.</p>
<p>This process happens quietly in the background. Every movement of your wrist can become a stream of numbers. A change in reflected light can become a heart-rate reading. Several different signals can be combined to estimate what you were doing or how your body was responding.</p>
<p>By the time that information reaches the screen, the original signal has already gone through several layers of processing, turning something the sensor can detect into something you can understand.</p>
<h3 id="heading-what-well-cover"><a href="#heading-what-well-cover">What We'll Cover:</a></h3>
<ul>
<li><p><a href="#heading-what-is-a-wearable-sensor-actually-measuring">What Is a Wearable Sensor Actually Measuring?</a></p>
</li>
<li><p><a href="#heading-the-tiny-sensors-doing-all-the-work">The Tiny Sensors Doing All the Work</a></p>
<ul>
<li><p><a href="#heading-accelerometer">Accelerometer</a></p>
</li>
<li><p><a href="#heading-gyroscope">Gyroscope</a></p>
</li>
<li><p><a href="#heading-photoplethysmography-ppg">Photoplethysmography (PPG)</a></p>
</li>
<li><p><a href="#heading-electrocardiogram-ecg">Electrocardiogram (ECG)</a></p>
</li>
<li><p><a href="#heading-temperature-sensor">Temperature Sensor</a></p>
</li>
</ul>
</li>
<li><p><a href="#heading-how-a-physical-signal-becomes-data">How a Physical Signal Becomes Data</a></p>
</li>
<li><p><a href="#heading-raw-sensor-data-is-messier-than-it-looks">Raw Sensor Data Is Messier Than It Looks</a></p>
</li>
<li><p><a href="#heading-how-algorithms-turn-messy-signals-into-useful-information">How Algorithms Turn Messy Signals Into Useful Information</a></p>
<ul>
<li><p><a href="#heading-digital-filtering">Digital Filtering</a></p>
</li>
<li><p><a href="#heading-feature-extraction">Feature Extraction</a></p>
</li>
<li><p><a href="#heading-metric-calculation">Metric Calculation</a></p>
</li>
<li><p><a href="#heading-why-wearables-combine-multiple-sensors">Why Wearables Combine Multiple Sensors</a></p>
</li>
</ul>
</li>
<li><p><a href="#heading-where-does-all-this-data-go">Where Does All This Data Go?</a></p>
</li>
<li><p><a href="#heading-a-sensor-can-be-accurate-and-the-final-result-can-still-be-wrong">A Sensor Can Be Accurate and the Final Result Can Still Be Wrong</a></p>
</li>
<li><p><a href="#heading-wrap-up">Wrap Up</a></p>
</li>
</ul>
<p>When you check your daily summary, there's a fundamental gap between what the user interface displays and what the underlying hardware actually captured.</p>
<p>Consumer health trackers don't observe abstract concepts like "recovery" or "cardio strain." Instead, they observe physical, mechanical, and optical properties occurring right at the surface of your skin.</p>
<table style="min-width:463px"><colgroup><col style="min-width:25px"><col style="width:438px"></colgroup><tbody><tr><td><p><strong>Wearable Metric</strong></p></td><td><p><strong>What's Actually Measured</strong></p></td></tr><tr><td><p>Steps</p></td><td><p>Dynamic multi-axis acceleration and periodic inertial forces</p></td></tr><tr><td><p>Heart Rate</p></td><td><p>Changes in blood volume altering light absorption or micro-voltages</p></td></tr><tr><td><p>SpO₂</p></td><td><p>Differential absorption ratio of red versus infrared light</p></td></tr><tr><td><p>Skin Temperature</p></td><td><p>Conductive heat transfer at the device chassis interface</p></td></tr><tr><td><p>Sleep Stages</p></td><td><p>Autonomic nervous system correlates via movement and pulse variability</p></td></tr><tr><td><p>Stress Score</p></td><td><p>Statistical fluctuations in time intervals between consecutive heartbeats</p></td></tr></tbody></table>

<p>The sensor’s sole job is to capture raw physical reality without bias, while software carries the burden of interpretation. Because biological signals are dynamic and influenced by countless environmental variables, converting physical values into physiological insights requires comprehensive mathematical modeling.</p>
<p>A comprehensive review in <a href="https://www.nature.com/articles/s41746-019-0111-3">Nature Digital Medicine on wearable sensing and analytics</a> highlights that wearable health tracking is fundamentally a signal-processing challenge rather than a simple hardware readout.</p>
<h2 id="heading-the-tiny-sensors-doing-all-the-work">The Tiny Sensors Doing All the Work</h2>
<p>To capture physical signals accurately within a compact form factor, modern wearables rely on a cluster of miniaturized electromechanical and optical modules.</p>
<h3 id="heading-accelerometer">Accelerometer</h3>
<p>The accelerometer detects linear acceleration and inertial forces across three spatial axes (X, Y and Z). Built using Micro-Electro-Mechanical Systems (MEMS), it contains microscopic suspended masses that deflect during movement, altering local electrical capacitance.</p>
<p>When you walk, your arm swings in a predictable, periodic pattern. The accelerometer records these repetitive acceleration peaks, allowing software to distinguish rhythmic locomotion from random gestures like typing or drinking water.</p>
<h3 id="heading-gyroscope">Gyroscope</h3>
<p>While the accelerometer detects linear movement and gravity, the gyroscope measures angular velocity and rotational motion. It monitors how quickly and along which axis the device rotates in space.</p>
<p>By pairing a gyroscope with an accelerometer, the device can accurately determine its spatial orientation, ensuring that a simple wrist roll to view the screen isn't mistakenly categorized as an exercise rep or a walking stride.</p>
<h3 id="heading-photoplethysmography-ppg">Photoplethysmography (PPG)</h3>
<p>PPG sensors use light to monitor changes in microvascular blood volume. Green light-emitting diodes (LEDs) illuminate the capillary bed beneath the skin, while adjacent photodetectors measure the light reflected back.</p>
<p>Because hemoglobin naturally absorbs green light, each ventricular contraction of the heart expands arterial volume, briefly increasing light absorption and lowering the reflected signal. The time between these reflection dips corresponds directly to individual pulse events.</p>
<h3 id="heading-electrocardiogram-ecg">Electrocardiogram (ECG)</h3>
<p>While PPG relies on optical reflection, an ECG sensor detects the direct bioelectrical impulses driving the cardiac muscle.</p>
<p>When the heart beats, electrical currents spread across the myocardium, creating subtle voltage fluctuations across your body. By placing a finger on a dedicated case electrode while the back of the watch rests against your wrist, you complete a circuit that lets differential amplifiers measure the heart's depolarization and repolarization waves directly.</p>
<h3 id="heading-temperature-sensor">Temperature Sensor</h3>
<p>Wearable temperature sensors employ thermistors or dedicated resistance temperature detectors (RTDs) resting against the skin surface.</p>
<p>It's worth noting that peripheral skin temperature isn't identical to core body temperature. Skin temperature fluctuates significantly based on ambient air, blood vessel dilation, and peripheral blood circulation. This makes it most valuable for identifying relative baseline deviations, such as sleep-phase cooling or early illness markers, rather than absolute clinical readings.</p>
<p>Comprehensive engineering overviews, such as this <a href="https://ieeexplore.ieee.org/document/8806989">IEEE review of wearable physiological sensors</a>, emphasize that these diverse hardware components must operate in close harmony to continuously reconstruct a clear picture of bodily activity.</p>
<h2 id="heading-how-a-physical-signal-becomes-data">How a Physical Signal Becomes Data</h2>
<p>Before computational logic can make sense of physical phenomena, continuous analog events must be converted into discrete numerical data.</p>
<p>When an optical photodiode detects fluctuating light levels, it outputs a continuous, smooth electrical voltage. Computers, however, can't compute infinite continuous curves. They operate exclusively on discrete numbers. This transition is handled by an <strong>Analog-to-Digital Converter</strong> (ADC).</p>
<p>The ADC periodically samples the continuous voltage wave and quantizes it into a discrete digital value:</p>
<ul>
<li><p><strong>Sampling Rate:</strong> Expressed in Hertz (Hz), this defines how many times per second the ADC records a value.</p>
<p>Fast, electrically complex signals like ECG require sampling rates of 250 Hz to 500 Hz to capture sharp wave morphology without losing critical cardiac peaks. Conversely, skin temperature changes slowly and can be accurately tracked at a fraction of a single Hertz (such as one sample every few seconds), preserving battery life and system storage.</p>
</li>
<li><p><strong>Resolution:</strong> Typically measured in bits (such as 12-bit, 16-bit or 24-bit depth), resolution determines how finely the converter quantizes the electrical signal. A higher bit-depth allows the system to resolve tiny physiological variations, such as shallow pulse signals on darker skin tones or during cold weather, without the waveform clipping or flattening.</p>
</li>
</ul>
<p>As explored in signal processing literature on <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC9599646/">wearable biometric data acquisition</a>, selecting appropriate sampling frequencies and quantization ranges balances the need for high signal fidelity with power consumption constraints.</p>
<h2 id="heading-raw-sensor-data-is-messier-than-it-looks">Raw Sensor Data Is Messier Than It Looks</h2>
<p>In controlled clinical environments, diagnostic tools are firmly attached to stationary patients. Consumer wearables, by contrast, must gather physiological data during dynamic, everyday movements. Consequently, raw sensor output rarely resembles textbook physiological waveforms.</p>
<p>Everyday wear introduces severe real-world interference:</p>
<ul>
<li><p><strong>Motion Artifacts:</strong> When you run, type, or grip objects, muscle contractions and sudden impacts physically rattle the device, creating massive inertial spikes that obscure subtle cardiac pulses.</p>
</li>
<li><p><strong>Sensor Displacement:</strong> A loose strap causes the device chassis to bounce against the epidermis, changing the optical path length between the LEDs and the photodetector, which introduces sharp baseline drifts.</p>
</li>
<li><p><strong>Environmental &amp; Physiological Noise:</strong> Ambient sunlight leaking beneath the device edges can overwhelm sensitive photodiodes, while cold environments trigger peripheral vasoconstriction, drastically reducing blood volume in the wrist capillaries.</p>
</li>
</ul>
<p>Because of this constant interference, wearable firmware includes automated Signal Quality Indices (SQIs). Before handing raw data to downstream algorithms, the system evaluates <strong>signal-to-noise ratios</strong> (SNR). If a specific data window is completely distorted by motion, the algorithm flags it as unreliable and discards it rather than generating an inaccurate reading. The dynamics of real-time artifact suppression are thoroughly analyzed in <a href="https://www.mdpi.com/1424-8220/22/1/141">wearable artifact removal research</a>.</p>
<h2 id="heading-how-algorithms-turn-messy-signals-into-useful-information">How Algorithms Turn Messy Signals Into Useful Information</h2>
<p>Once the signal is digitized and validated for basic quality, deterministic digital signal processing and algorithmic modeling convert the raw numerical stream into actionable human metrics.</p>
<h3 id="heading-digital-filtering">Digital Filtering</h3>
<p>Raw data first passes through digital bandpass filters configured to discard frequencies that fall outside the bounds of human physiology.</p>
<p>For an optical heart-rate signal, an algorithm suppresses frequencies below 0.5 Hz (30 BPM) and above 4.0 Hz (240 BPM), filtering out slow baseline drift and high-frequency electrical hum.</p>
<h3 id="heading-feature-extraction">Feature Extraction</h3>
<p>Instead of continuously processing thousands of raw digital samples, the software extracts concise statistical and morphological markers:</p>
<ul>
<li><p>Peak-to-Peak Intervals (△ t): The precise time duration between consecutive pulse crests.</p>
</li>
<li><p>Signal Variance: The degree of dispersion in acceleration values across a rolling 5-second window.</p>
</li>
<li><p>Dominant Frequency: The primary harmonic component identified through Fast Fourier Transforms (FFT).</p>
</li>
</ul>
<h3 id="heading-metric-calculation">Metric Calculation</h3>
<p>For heart rate, the algorithm identifies valid systolic peaks, measures the inter-beat interval, eliminates mathematical outliers and computes the instantaneous beats per minute (60 / △ t).</p>
<p>For step detection, the algorithm processes 3-axis accelerometer arrays:</p>
<p>The software monitors this composite acceleration value for rhythmic threshold crossings and frequency signatures typical of a human gait, ignoring non-cyclical vibrations like riding a car over a bumpy road.</p>
<p>Machine learning classifiers, trained on large labeled movement datasets, help classify these feature profiles into specific activities such as cycling, swimming or sleeping.</p>
<h3 id="heading-why-wearables-combine-multiple-sensors">Why Wearables Combine Multiple Sensors</h3>
<p>A single physical sensor often lacks the context needed to accurately understand what your body is doing. To resolve ambiguity, devices use Sensor Fusion, combining data from multiple distinct sensors to generate more accurate inferences than any single sensor could provide alone.</p>
<p>Consider a sudden rise in heart rate from 65 BPM to 145 BPM:</p>
<ul>
<li><p>If the accelerometer detects no concurrent body movement, the algorithm may interpret the event as psychological stress, caffeine intake, or a cardiac anomaly.</p>
</li>
<li><p>If the accelerometer simultaneously registers a sustained, high-cadence rhythmic movement signature, the system identifies the elevated heart rate as a normal physiological response to running.</p>
</li>
</ul>
<p>By pairing optical, thermal, and inertial data points simultaneously, the system constructs a detailed picture of the user's metabolic state.</p>
<p>As detailed in the <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC8708785/">Biomedical Engineering survey on multimodal sensor fusion</a>, combining complementary sensor streams helps eliminate false positives and balances out individual hardware limitations.</p>
<h2 id="heading-where-does-all-this-data-go">Where Does All This Data Go?</h2>
<p>The data pipeline extends beyond the physical device on your wrist. Processing tasks are distributed across local hardware, your paired mobile phone and remote cloud infrastructure.</p>
<ul>
<li><p><strong>On the Wearable (Edge Computing):</strong> Time-sensitive tasks run directly on low-power microcontrollers embedded inside the wearable. Filtering raw voltages, detecting steps and monitoring safety alerts (such as fall detection) happen locally, ensuring low latency, lower power consumption and better privacy.</p>
</li>
<li><p><strong>On the Smartphone:</strong> Because smartphones have faster multi-core processors and larger batteries, they handle heavy machine learning tasks, data visualization and the fusion of GPS traces with wrist kinematics.</p>
</li>
<li><p><strong>In the Cloud:</strong> Aggregated summaries are periodically uploaded to remote data centers for long-term historical tracking, deep longitudinal comparisons and training the next generation of algorithmic models across anonymized populations.</p>
</li>
</ul>
<h2 id="heading-a-sensor-can-be-accurate-and-the-final-result-can-still-be-wrong">A Sensor Can Be Accurate and the Final Result Can Still Be Wrong</h2>
<p>A common misconception is that an inaccurate health metric points directly to a broken sensor. In reality, a physical sensor can function with micro-voltage precision while the final displayed metric remains fundamentally incorrect.</p>
<p>There's a distinct difference between direct <strong>physical measurement</strong> and <strong>algorithmic estimation</strong>:</p>
<ul>
<li><p>The photodiode may accurately record light absorption.</p>
</li>
<li><p>The ADC may convert those currents into digital samples without losing precision.</p>
</li>
<li><p>Yet, if the user experiences severe vascular constriction from cold air or if an unpredictable arm movement mimics a pulse frequency, the peak-detection logic may latch onto the wrong frequency peak.</p>
</li>
</ul>
<p>A metric can fail at multiple points along the pipeline: poor contact mechanics, edge-case physiology that falls outside the training dataset, or mathematical assumptions that break down during specific sports. Recognizing that wearables provide informed physiological estimations rather than direct clinical measurements is key to interpreting everyday health data properly.</p>
<h2 id="heading-wrap-up">Wrap Up</h2>
<p>Wearable data goes through much more than a sensor before it becomes the numbers you see on your screen. Sensors capture physical signals, hardware converts them into digital data, and algorithms filter, combine, and interpret those signals to produce useful metrics.</p>
<p>Understanding this process also makes one thing clear: wearable measurements aren't always direct readings. They're often estimates built from several layers of sensing and computation. The better we understand that pipeline, the better we can understand what our wearable data is actually telling us.</p>
 ]]>
                </content:encoded>
            </item>
        
            <item>
                <title>
                    <![CDATA[ How an ECG on a Wrist Wearable Works and How It Compares to a Clinical Test ]]>
                </title>
                <description>
                    <![CDATA[ For decades, recording an electrocardiogram (ECG) meant visiting a hospital or clinic. The doctors would place multiple electrodes on your chest and limbs to capture your heart's electrical activity.  ]]>
                </description>
                <link>https://www.freecodecamp.org/news/how-smartwatch-ecg-works/</link>
                <guid isPermaLink="false">6a74c6e11a7e8d7040b2949f</guid>
                
                    <category>
                        <![CDATA[ embedded systems ]]>
                    </category>
                
                    <category>
                        <![CDATA[ Internet of Things ]]>
                    </category>
                
                    <category>
                        <![CDATA[ Wearable Technology ]]>
                    </category>
                
                    <category>
                        <![CDATA[ Health Tech  ]]>
                    </category>
                
                    <category>
                        <![CDATA[ Digital Signal Processing ]]>
                    </category>
                
                <dc:creator>
                    <![CDATA[ Reetain Raina ]]>
                </dc:creator>
                <pubDate>Thu, 06 Aug 2026 17:39:45 +0000</pubDate>
                <media:content url="https://cdn.hashnode.com/uploads/covers/5e1e335a7a1d3fcc59028c64/c283c6cc-f094-47bd-83dd-c7361536a73f.png" medium="image" />
                <content:encoded>
                    <![CDATA[ <p>For decades, recording an electrocardiogram (ECG) meant visiting a hospital or clinic. The doctors would place multiple electrodes on your chest and limbs to capture your heart's electrical activity.</p>
<p>Today, many wrist wearables can perform a simplified version of the same test. They record a single-lead ECG in about 30 seconds using just two small electrodes built into the device.</p>
<p>Despite this convenience, a smartwatch isn't replacing the large ECG machines used in hospitals. Instead, it solves a different problem. A clinical ECG is designed for diagnosing a wide range of heart conditions, while a wrist wearable focuses on capturing enough electrical information to monitor heart rhythm and identify certain abnormalities, such as atrial fibrillation (AFib).</p>
<p>Multiple <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC9795256/?">studies</a> have shown that modern single-lead smartwatch ECGs can detect AFib with high accuracy under appropriate conditions, but they're intended to complement, not replace, a standard 12-lead ECG.</p>
<p>That raises an interesting question: how can two tiny metal contacts on a smartwatch detect electrical signals generated deep inside your heart?</p>
<p>The answer combines biology, electronics, embedded systems, and digital signal processing. Let's break it down.</p>
<h2 id="heading-table-of-contents">Table of Contents</h2>
<ul>
<li><p><a href="#heading-your-heart-is-an-electrical-system-before-its-a-mechanical-one">Your Heart Is an Electrical System Before It's a Mechanical One</a></p>
</li>
<li><p><a href="#heading-how-a-wrist-wearable-captures-that-electrical-signal">How a Wrist Wearable Captures That Electrical Signal</a></p>
</li>
<li><p><a href="#heading-from-analog-waveform-to-a-digital-ecg-waveform">From Analog Waveform to a Digital ECG Waveform</a></p>
</li>
<li><p><a href="#heading-why-wrist-wearables-use-a-single-lead-ecg">Why Wrist Wearables Use a Single-Lead ECG</a></p>
</li>
<li><p><a href="#heading-clinical-ecg-vs-wrist-ecg-whats-the-difference">Clinical ECG vs Wrist ECG: What’s the difference</a></p>
</li>
<li><p><a href="#heading-where-smartwatch-ecg-performs-surprisingly-well">Where Smartwatch ECG Performs Surprisingly Well</a></p>
</li>
<li><p><a href="#heading-why-consumer-ecg-still-has-important-limitations">Why Consumer ECG Still Has Important Limitations</a></p>
</li>
<li><p><a href="#heading-the-engineering-challenges-behind-wrist-ecg">The Engineering Challenges Behind Wrist ECG</a></p>
</li>
<li><p><a href="#heading-the-future-of-wearable-ecg">The Future of Wearable ECG</a></p>
</li>
<li><p><a href="#heading-wrap-up">Wrap Up</a></p>
</li>
</ul>
<h2 id="heading-your-heart-is-an-electrical-system-before-its-a-mechanical-one"><strong>Your Heart Is an Electrical System Before It's a Mechanical One</strong></h2>
<p>Before your heart can pump a single drop of blood, it has to fire an electrical impulse. You can think of the heart as a synchronized electrical circuit where every mechanical beat starts with a precisely timed waveform pulse.</p>
<p>This sequence begins in the <strong>sinoatrial</strong> (SA) node which is the heart's natural pacemaker, located in the upper right chamber. The SA node fires a tiny waveform spike that spreads across the atria, causing them to contract and push blood down.</p>
<p>Next, the signal hits the <strong>atrioventricular</strong> (AV) node, which acts like an intentional delay gate to let the ventricles fill completely.</p>
<p>Finally, the pulse surges through specialized conductive pathways into the ventricles, triggering a powerful contraction that circulates blood through your body. Because human tissues and fluids are electrically conductive, these microscopic waveform shifts ripple outward until they reach the surface of your skin.</p>
<h2 id="heading-how-a-wrist-wearable-captures-that-electrical-signal"><strong>How a Wrist Wearable Captures That Electrical Signal</strong></h2>
<p>Capturing a biological signal from two isolated points on the skin surface is a tricky hardware problem. A typical smartwatch solves this using two main metal electrodes: one integrated into the back crystal touching the wrist and another built into the side crown or outer frame.</p>
<p>When you touch the side crown with a finger from your opposite hand, your body completes a continuous electrical path. This loop spans across your arms, shoulders, and chest cavity. The watch measures the electrical potential difference between these two distinct contact points.</p>
<p>But this biological signal is vanishingly small, typically between <strong>0.5 and 2 millivolts</strong>. Because it travels across long paths of skin and muscle, it arrives heavily contaminated by ambient noise, static electricity, and electromagnetic interference from nearby appliances.</p>
<p>To manage this, the wearable routes the raw micro-wave into an <strong>Analog Front End</strong> (AFE). The AFE uses high-impedance instrumentation amplifiers and differential sensing to boost the heart signal by orders of magnitude while stripping away common-mode noise before the data ever reaches a digital processor.</p>
<h2 id="heading-from-analog-waveform-to-a-digital-ecg-waveform"><strong>From Analog Waveform to a Digital ECG Waveform</strong></h2>
<p>Once the Analog Front End cleans and amplifies the microscopic waveform, software algorithms step in to transform raw analog input into the sharp line graph you see on your screen.</p>
<p>First, an <strong>Analog-to-Digital Converter</strong> (ADC) samples the analog waveform hundreds of times per second, converting continuous waves into a high-resolution stream of digital data.</p>
<p>Next, <strong>Digital Signal Processing</strong> (DSP) algorithms strip out environmental noise. A high-pass filter eliminates low-frequency baseline wander caused by chest breathing. A low-pass filter cuts high-frequency noise from micro-tremors in your hand muscles.</p>
<p>Finally, a dedicated notch filter cancels out the persistent <strong>50 Hz or 60 Hz</strong> hum emitted by power grids and wall outlets.</p>
<p>After filtering, specialized software algorithms analyze the clean waveform. Using precise peak-detection routines, the firmware identifies the <strong>QRS</strong> complex, specifically the tall <strong>R-peak</strong> that marks ventricular contraction. By calculating the exact time intervals between successive R-peaks, the device determines instantaneous heart rate and flags irregular beats.</p>
<p>The smartwatch isn't just recording waveforms, it's continuously scrubbing and interpreting data before drawing the final waveform.</p>
<h2 id="heading-why-wrist-wearables-use-a-single-lead-ecg"><strong>Why Wrist Wearables Use a Single-Lead ECG</strong></h2>
<p>In clinical cardiology, an ECG measurement is defined by a "lead," which represents a specific spatial view of the heart's electrical vector between two reference points.</p>
<p>Because a smartwatch only features two distinct contact locations, it can only measure a single vector across the upper body. In standard <strong>12-lead nomenclature</strong>, the path going from the right arm to the left arm is classified as <strong>Lead I</strong>.</p>
<p>A Lead I configuration tracks the primary horizontal electrical axis of the heart. This single perspective provides clear timing intervals between heartbeats, making it remarkably effective for calculating heart rate and evaluating basic rhythm regularity.</p>
<p>But because Lead I only views the heart along a single plane, it can't detect localized structural issues occurring on the inferior or posterior walls of the heart muscle.</p>
<h2 id="heading-clinical-ecg-vs-wrist-ecg-whats-the-difference"><strong>Clinical ECG vs Wrist ECG: What’s the difference</strong></h2>
<p>While both technologies measure bioelectric waveform, their implementation targets fundamentally different monitoring requirements:</p>
<table style="min-width:75px"><colgroup><col style="min-width:25px"><col style="min-width:25px"><col style="min-width:25px"></colgroup><tbody><tr><td><p><strong>Feature / Metric&nbsp;</strong></p></td><td><p><strong>Wrist Wearable ECG&nbsp;</strong></p></td><td><p><strong>Clinical ECG&nbsp;</strong></p></td></tr><tr><td><p>Lead Count&nbsp;</p></td><td><p>Single Lead (Lead I equivalent)&nbsp;</p></td><td><p>12 Leads (derived from 10 physical electrodes)&nbsp;</p></td></tr><tr><td><p>Duration&nbsp;</p></td><td><p>On-demand 30-second snapshot&nbsp;</p></td><td><p>Continuous recording / diagnostic strip&nbsp;</p></td></tr><tr><td><p>Primary Focus&nbsp;</p></td><td><p>Ambulatory rhythm and AFib detection&nbsp;</p></td><td><p>Comprehensive cardiac diagnostic assessment&nbsp;</p></td></tr><tr><td><p>Signal Source&nbsp;</p></td><td><p>Dry metal contacts on extremities&nbsp;</p></td><td><p>Conductive wet gel electrodes on chest &amp; limbs&nbsp;</p></td></tr><tr><td><p>Environment&nbsp;</p></td><td><p>Real-world / Uncontrolled home setting&nbsp;</p></td><td><p>Controlled hospital or clinical environment&nbsp;</p></td></tr><tr><td><p>Primary Output&nbsp;</p></td><td><p>Basic rhythm status &amp; interval data&nbsp;</p></td><td><p>3D multi-angle vector analysis&nbsp;</p></td></tr></tbody></table>

<p>A hospital ECG views the heart from <strong>12 unique electrical angles</strong> simultaneously, mapping vectors across 3 dimensions. A smartwatch, by contrast, observes only one horizontal plane. This core structural difference explains why cardiologists rely on 12-lead systems for full clinical diagnoses.</p>
<h2 id="heading-where-smartwatch-ecg-performs-surprisingly-well"><strong>Where Smartwatch ECG Performs Surprisingly Well</strong></h2>
<p>Despite being limited to a single lead, smartwatch ECGs excel in scenarios where traditional clinical equipment struggles: capturing sporadic, intermittent events in everyday life.</p>
<p>Conditions like AFib often occur unpredictably in short bursts. A patient might experience palpitations at home, yet present a perfectly normal rhythm by the time they reach a clinic for a formal standard test.</p>
<p>A comprehensive <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC12096014/">meta-analysis on smartwatch ECG diagnostic accuracy</a> showed that consumer smartwatch algorithms achieve high sensitivity and specificity for detecting AFib when evaluated against clinical reference standards.</p>
<p>Capturing an irregular rhythm moment in real-time on a wrist device provides actionable, timestamped data that clinicians can later review to guide further diagnostic testing.</p>
<h2 id="heading-why-consumer-ecg-still-has-important-limitations"><strong>Why Consumer ECG Still Has Important Limitations</strong></h2>
<p>Understanding wearable ECG engineering also means acknowledging the hardware limitations inherent to consumer form factors.</p>
<p>Firstly, dry metal electrodes lack the conductive gel used in clinical settings, creating higher skin-electrode impedance. Factors like dry skin, excessive sweat, loose strap fit, or wrist tattoos can degrade the signal-to-noise ratio.</p>
<p>Secondly, micro-movements introduce <strong>motion artifacts</strong>, waveform spikes created by flexing muscles that can mimic or obscure true cardiac signals.</p>
<p>Most importantly, because a single lead can't evaluate vector changes across the entire <strong>myocardium</strong>, a wearable can't detect acute heart attacks, silent ischemia, or complex ventricular arrhythmias. A clean smartwatch reading simply confirms a stable rhythm along Lead I. It's never a complete clean bill of health.</p>
<h2 id="heading-the-engineering-challenges-behind-wrist-ecg"><strong>The Engineering Challenges Behind Wrist ECG</strong></h2>
<p>Building a functional ECG into a watch involves navigating severe hardware and software trade-offs. Engineers must balance signal sensitivity against power consumption, battery constraints, and physical footprint.</p>
<p>The primary engineering challenges include:</p>
<ul>
<li><p><strong>Ultra-low-power AFE design:</strong> The sensing circuitry must remain accurate while drawing minimal microamps from a tiny battery.</p>
</li>
<li><p><strong>Real-time adaptive filtering:</strong> Embedded processors must run digital bandpass and notch filters on incoming data without causing system latency.</p>
</li>
<li><p><strong>Motion artifact cancellation:</strong> Algorithms must differentiate between true cardiac electrical waves and electromyographic signals generated by flexing arm muscles.</p>
</li>
<li><p><strong>On-device machine learning:</strong> Lightweight classification models must run locally on microcontroller hardware to classify rhythms securely without relying entirely on cloud processing.</p>
</li>
</ul>
<p>Ultimately, the hardest engineering problem isn't detecting bioelectricity, it's separating a faint cardiac signal from the noisy environment of a moving human wrist.</p>
<h2 id="heading-the-future-of-wearable-ecg"><strong>The Future of Wearable ECG</strong></h2>
<p>As embedded systems continue to evolve, wearable cardiac monitoring is moving toward multi-sensor fusion. Future devices are pairing single-lead ECG data with <strong>optical Photoplethysmography (PPG)</strong>, wrist temperature sensors, and continuous accelerometers.</p>
<p>By combining optical blood volume shifts (PPG) with electrical timing (ECG), devices can calculate Pulse Transit Time (PTT) to estimate blood pressure non-invasively.</p>
<p>Simultaneously, edge-AI chips are becoming efficient enough to perform continuous, low-power background rhythm monitoring, notifying users the moment an anomaly is detected rather than relying solely on manual 30-second tests.</p>
<h2 id="heading-wrap-up"><strong>Wrap Up</strong></h2>
<p>Wearable ECG is a good example of how solving a real-world problem often requires expertise from multiple engineering disciplines. A feature that appears as a simple 30-second test on a smartwatch depends on analog circuit design, embedded firmware, digital signal processing, and intelligent algorithms working together to produce reliable results.</p>
<p>As wearable devices continue to become more capable, understanding the engineering behind features like ECG becomes just as important as understanding what they measure. It shows that building modern health technology isn't just about adding new sensors, it's about designing systems that can turn tiny, noisy biological signals into information that people can trust.</p>
 ]]>
                </content:encoded>
            </item>
        
    </channel>
</rss>
