NeuralGrad: Multi-Scale Gradient Reactivity for Open-World Network Intrusion Detection
Abstract
Neural network-based intrusion detection systems achieve high accuracy on known attacks but fail to detect novel threats in real-world deployments. We address three fundamental challenges: (1) detecting out-of-distribution attacks from unseen families, (2) adapting to novel attacks from labeled examples, and (3) capturing multi-scale temporal patterns from packets to sessions. We propose **NeuralGrad**, a framework leveraging *gradient reactivity*, the structured response of network layers during inference, captured via intermediate activation gradients. Our contributions are (1) Gradient Reactivity Maps (GRM): A learned representation where in-distribution inputs produce low-rank gradient patterns while out-of-distribution inputs project far outside. We prove OOD separability unconditionally in the NTK regime and under testable regularity conditions generally. (2) Multi-Scale Dual-Stream Transformer: Hierarchical architecture with parallel temporal/spatial attention at packet, flow, and session scales. (3) Gradient-Space Prototypical Networks: Few-shot classification via gradient-space prototypes, exploiting higher ambient dimensionality than feature space. On 14.8M samples across eight datasets: 98.7% closed-world accuracy, 94.5% AUROC on novel attacks (+8.7% over prior work), 87.4% accuracy with 3 labeled examples (+29.8% over baselines), and 0.71 ms edge inference.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.