PAPER

Jev-IDS: System One Models for Network Intrusion Detection

LLM Other LLM ML Semi-SL Other ML
基于机器学习的网络入侵检测系统(IDS)依赖于大量带标签的数据集,并需针对特定任务进行训练;而大型语言模型(LLM)驱动的检测方法虽可直接分析网络流记录,但推理开销与延迟更高,且输出缺乏明确约束。本文提出JEV-IDS——一种基于Jev系统单模型(SOM)构建的开源、通用型实验性网络入侵检测系统,旨在标签数据极度匮乏的条件下实现对零日攻击的有效检测。JEV-IDS将每条网络流序列化为一次独立请求,并向JEV模型提出两个问题:一是判断该流是否为攻击的二分类概率,二是从预定义有限类别集中判定其所属的流量类型。实验结果表明,在参数k=1时,JEV的推理速度是GPT-5.6 Luna的4.8倍,单位推理成本仅为后者的1/3.8,且对新型攻击的召回率高出1.5倍;同时,其误报率较低数据场景下的随机森林模型降低了15倍。在NSL-KDD数据集的一个300条流构成的试点子集上共作出5400次检测决策,JEV取得了F1值0.859、精确率0.941、召回率0.790、以及新型攻击召回率0.838的综合性能;当k提升至2时,其F1值略微下降至0.839。
Machine-learning Network Intrusion Detection Systems (IDS) depend on substantial labeled datasets and task-specific training, whereas Large Language Models (LLMs) detection can analyze flow records directly but incurs higher inference cost and latency, with less constrained outputs. This paper presents JEV-IDS, an open experimental general NIDS based on the Jev System One Model (SOM) to detect zero day intrusions Under label scarcity. JEV-IDS serializes one flow per request and asks JEV two questions: a binary attack probability and a finite-choice traffic category. Our results show that, at k=1, JEV was 4.8 times faster and 3.8 times cheaper than GPT-5.6 Luna, with 1.5 times higher novel-attack recall; it also produced 15 times fewer false alarms than a low-data Random Forest. Across 5,400 decisions on a 300-flow NSL-KDD pilot split, JEV achieved F1-Score 0.859, precision 0.941, recall 0.790, and novel-attack recall 0.838. Increasing k to 2 reduced its F1-Score to 0.839.
许愿