A KAN-native network detection engine. The core heads are unsupervised — trained on benign traffic only, with no attack labels — and every alert traces back to the signal that produced it.
A Kolmogorov–Arnold Network places learnable functions on the edges. You read the contribution directly — you are not approximating a black box after the fact with a second model.
The autoencoder heads learn the manifold of normal behaviour and flag deviation. No attack labels — because labelling cannot keep pace with activity nobody has seen yet.
Two heads are plain rules, not models. Punycode distance and RFC1918/Bogon checks do not need a network, and pretending otherwise would only add uncertainty.
Each head learns a different near-orthogonal projection of normal. Something that hides inside normal in one view separates in another.
Three carry measured detection evidence; three are explicitly limited to deterministic or evaluation-only roles. In August 2026 we re-measured every contested performance number on real traffic, with re-runnable scripts — the table below is what survived.
H1 is the head a DNS-tunnelling story would lean on, and right now we cannot show that it detects tunnelling. On a synthetic positive control it stayed silent. Until we have a real tunnel capture to measure against, we make no tunnel detection claim at all — and we would rather you read that here than discover it in a proof of concept.
A co-located appliance fed by a passive tap or by the flow and DNS logs you already produce. Nothing installed on endpoints. Inference runs on CPU.
Those first two numbers describe two different regimes and do not hold simultaneously — single-event latency on one thread is not the batched figure. We print them apart on purpose.
The engine runs end to end in our lab stack against a Juniper-format syslog pipeline. That is an internal demonstration on our own data. It is not third-party validation, and we do not present it as one.
An NDR test plan (v1.3) was submitted into the JSEL process on 29 May 2026. Execution is pending. No result exists yet, so none is quoted here — and the plan's target numbers are not achievements.
Six MITRE ATT&CK techniques at the DNS layer are in scope in the current baseline. The wider roadmap adds TLS metadata, flow analytics and graph-based lateral-movement heads in later phases.
A research partnership with the University of Szeged is in progress, aimed at the label-free direction — because supervised labelling does not scale against activity that has not been seen before.
Tell us what your DNS and flow telemetry looks like, and we will tell you where HYDRA would help today and where it would not.