A new experimental intrusion detection system claims to catch unknown network attacks using a fraction of the compute a comparable AI approach would need.
JEV-IDS runs on what its creators call the Jev System One Model. Instead of training on huge banks of labeled attack data like traditional machine-learning detectors, it looks at one network flow record at a time and answers two questions: is this traffic malicious, and what category does it fall into. On a 300-flow slice of the aging NSL-KDD benchmark, across 5,400 total decisions, it posted an F1 score of 0.859, 94.1% precision, and recall of 79% on known attacks that climbed to 83.8% on attacks it had never seen before. The paper also reports JEV generating 15 times fewer false alarms than a Random Forest model trained on limited data.
The bigger claim is speed and cost: the authors say JEV ran 4.8 times faster and 3.8 times cheaper than a system they call "GPT-5.6 Luna," with 1.5 times better recall on novel attacks. That name doesn't correspond to any publicly confirmed OpenAI release, so treat it as the paper's own benchmark label rather than a verified head-to-head against a known commercial model.
Zero-day detection without heavy labeling is a real pain point for security teams, and a lighter, cheaper model that flags new attack patterns would be worth watching. But every number here comes from one paper's own test harness, on one small, decades-old dataset slice. That's a promising lab result, not proof it holds up against live traffic.