Machine-learning Network Intrusion Detection Systems (IDS) depend on substantial labeled datasets and task-specific training, whereas Large Language Models (LLMs) detection can analyze flow records directly but incurs higher inference cost and latency, with less constrained outputs. This paper presents JEV-IDS, an open experimental general NIDS based on the Jev System One Model (SOM) to detect zero day intrusions Under label scarcity. JEV-IDS serializes one flow per request and asks JEV two questions: a binary attack probability and a finite-choice traffic category. Our results show that, at k=1, JEV was 4.8 times faster and 3.8 times cheaper than GPT-5.6 Luna, with 1.5 times higher novel-attack recall; it also produced 15 times fewer false alarms than a low-data Random Forest. Across 5,400 decisions on a 300-flow NSL-KDD pilot split, JEV achieved F1-Score 0.859, precision 0.941, recall 0.790, and novel-attack recall 0.838. Increasing k to 2 reduced its F1-Score to 0.839.
Figures & tables
Figure 1: Architecture of Jev-IDS . A target Flow is represented by its feature values in Card order and inserted into a Jev request together with the request instructions, column names, Category descriptions, and optional labeled Examples. Jev answers an intrusion-probability question and a Category question, from which Jev-IDS derives the corresponding detection outputs.
Flows
Normal
DoS
Probe
R2L
U2R
2,000
874
642
213
248
23
Table 1: Composition of the NSL-KDD evaluation set.
Detector
k
F1
Precision
Recall
Known recall
Novel recall
PR-AUC
ROC-AUC
Jev
0
0.782±0.005
0.972
0.654
0.665
0.622
0.940
0.925
1
0.856±0.025
0.953
0.778
0.790
0.747
0.952
0.950
2
0.846±0.009
0.949
0.763
0.772
0.738
0.949
0.944
4
0.856±0.015
0.944
0.784
0.803
0.731
0.959
0.959
8
0.854±0.017
0.942
0.783
0.805
0.721
0.964
0.962
Gemini 3.6 Flash
0
0.867±0.005
0.946
0.801
0.842
0.687
0.949
0.959
Table 2: Predictive results on the 2,000-Flow NSL-KDD evaluation set. F1 is reported as mean ± sample standard deviation across three Example seeds. The remaining metrics are seed means.
Subset
k
Pairs
Discordant
Jev correct
Gemini correct
Exact p
All Flows
0
6,000
833
213
620
<0.001
All Flows
1
6,000
508
195
313
<0.001
All Flows
2
6,000
515
199
316
<0.001
All Flows
4
6,000
506
178
328
<0.001
All Flows
8
6,000
472
159
313
<0.001
Known attacks
0
2,478
489
25
464
<0.001
Table 3: Paired comparison between Jev and Gemini 3.6 Flash. The “Jev correct” and “Gemini correct” columns report the correctly classified instances among discordant decisions.
k
Jev cost
Gemini cost
Cost ratio
Jev latency
Gemini latency
Latency ratio
0
US$43
US$1,068
25×
310 ms
2.24 s
7.2×
1
US$74
US$1,651
22×
315 ms
2.42 s
7.7×
2
US$106
US$2,409
23×
308 ms
2.65 s
8.6×
4
US$169
US$2,869
17×
322 ms
2.13 s
6.6×
8
US$295
US$3,035
10×
335 ms
1.99 s
5.9×
Table 4: Operational comparison between Jev and Gemini 3.6 Flash. Cost denotes the estimated list price per one million Flow decisions, and latency denotes the mean wall-clock duration of a successful model request. Ratios are Gemini/ Jev .