arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Jev-IDS:用于网络入侵检测的System One模型

Jev-IDS: System One Models for Network Intrusion Detection

Paulo Severo, Silvio E. Quincozes, Amanda Dias

arXiv 2610.01079首次发表:更新:

发表机构

Federal University of Pampa (UNIPAMPA)(潘帕联邦大学(UNIPAMPA))

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出JEV-IDS,一种基于Jev System One模型的开放通用网络入侵检测系统,在标签稀缺下检测零日入侵,较GPT-5.6 Luna更快更便宜,且新攻击召回率更高,误报更少。

AI 中文摘要

基于机器学习的网络入侵检测系统(IDS)依赖大量标注数据集和特定任务的训练,而大语言模型(LLM)检测虽可直接分析流记录,但推理成本和延迟更高,且输出约束较少。本文提出JEV-IDS,一种基于Jev System One模型(SOM)的开放实验性通用NIDS,旨在标签稀缺情况下检测零日入侵。JEV-IDS将每个流序列化为一个请求,并向JEV提出两个问题:一个二元攻击概率和一个有限选择的流量类别。我们的结果表明,在k=1时,JEV比GPT-5.6 Luna快4.8倍,便宜3.8倍,新攻击召回率高出1.5倍;同时,其误报比低数据随机森林少15倍。在300流NSL-KDD试点划分的5400个决策中,JEV取得了F1分数0.859、精确率0.941、召回率0.790和新攻击召回率0.838。将k增加到2时,其F1分数降至0.839。

英文摘要

Machine-learning Network Intrusion Detection Systems (IDS) depend on substantial labeled datasets and task-specific training, whereas Large Language Models (LLMs) detection can analyze flow records directly but incurs higher inference cost and latency, with less constrained outputs. This paper presents JEV-IDS, an open experimental general NIDS based on the Jev System One Model (SOM) to detect zero day intrusions Under label scarcity. JEV-IDS serializes one flow per request and asks JEV two questions: a binary attack probability and a finite-choice traffic category. Our results show that, at k=1, JEV was 4.8 times faster and 3.8 times cheaper than GPT-5.6 Luna, with 1.5 times higher novel-attack recall; it also produced 15 times fewer false alarms than a low-data Random Forest. Across 5,400 decisions on a 300-flow NSL-KDD pilot split, JEV achieved F1-Score 0.859, precision 0.941, recall 0.790, and novel-attack recall 0.838. Increasing k to 2 reduced its F1-Score to 0.839.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑