Jev-IDS Catches Network Attacks 4.8x Faster Than GPT-5.6 Luna
A new intrusion detection prototype swaps text-generating LLMs for a typed-output model, cutting cost and latency while catching more zero-day attacks.
- Jev-IDS uses TypeSafe AI's Jev, a System One Model that returns typed probabilities instead of text, for flow-based intrusion detection.
- On NSL-KDD it hit F1 0.859, precision 0.941, and novel-attack recall 0.838 with just one labeled example per category.
- It ran 4.8x faster and 3.8x cheaper than GPT-5.6 Luna, with 1.5x higher recall on unseen attacks.
- It generated 15x fewer false alarms than a Random Forest trained on the same scarce labels.
- The LLM still edges it on in-distribution F1 (0.880 vs 0.856), but loses on zero-day recall and efficiency.
- Full MIT-licensed code and reproducible benchmarks are available at github.com/jev-ids/jev-ids.
Jev-IDS uses typed probabilities to detect network attacks
Jev-IDS is an open-source intrusion-detection prototype that returns structured probabilities for each network flow. Its fixed output schema avoids the token generation, parsing, and validation required by free-form large language model responses. An accompanying arXiv paper reports lower latency and cost, along with stronger recall on attack families excluded from the model’s examples.
Those results make Jev-IDS a candidate for early-stage traffic triage, where false alarms, per-flow cost, and response time determine how much telemetry a system can process. The current evidence comes from a small benchmark on an established but dated dataset, so it does not establish production or line-rate performance.
Why typed output changes the pipeline
Conventional network intrusion detection systems often use supervised classifiers trained on labeled flows. Their performance can deteriorate when traffic differs from the training data, while collecting and labeling representative attacks requires substantial work. General-purpose LLMs can classify flows from a few examples, but each response incurs generation latency and may contain text that downstream software must parse and validate.
TypeSafe AI describes Jev as the first System One Model, or SOM, in a family built for typed probabilistic decisions. The caller defines each question and its valid answer shape in advance. Jev then returns probabilities and predefined values without generating an explanation.
One flow in, two typed answers out
Every Jev-IDS request places a single serialized network flow into the model state with its column names, instructions, five traffic-category descriptions, and labeled examples. The number of examples per category is controlled by
This story is for Pro members
You've reached the end of the free preview. Upgrade to AlphaSignal Pro to read the full article - and everything else behind the paywall.