An iota of signal in a flood of noise: a stateful detector improves synthetic intrusion detection from 13% to 92%
Kevin Vaillancourt
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
Events viewed in isolation do not carry enough signal to cross the threshold into a security event; the accumulation of events does. The detector averages an entity’s past events and scores the average beside the current event. On synthetic campaigns calibrated to the timing and phase structure of Hugging Face’s 108-hour incident, with false alarms capped at 5%, detection within 120 hours rises from 13% without memory to 92% with it. Controls show the advantage depends on ordered evidence staying attached to the same entity; breaking that removes most of the gain. The evaluation uses four benign entities per attacker; an earlier attackers-only result of 59% was an entity-age artifact and was replaced. Rdet, the share of predictive information attributable to history rather than the current event, is a diagnostic for whether history holds exploitable signal. These rates are properties of the synthetic generator, not measurements of Hugging Face telemetry
Reviews
The problem is well-chosen and timely, but CUSUM ties the detector at both windows, so the contribution is closer to "stateful beats stateless" than a new method. Table 4 on entity keying is the genuinely novel piece and deserves to be the headline.
Calibration is honest, with the full detection/false-alarm curve rather than a single favourable point. The repo backs every table with a named script. Capped by being entirely synthetic on a generator the author wrote.
Scope discipline is unusually good; the abstract's number needs the per-event-signal caveat that Table 5 shows is essential; the Discussion is thin; limitations are restated four times in near-identical wording.
Cite this project
@misc{vaillancourt2026iota,
title = {{An iota of signal in a flood of noise: a stateful detector improves synthetic intrusion detection from 13\% to 92\%}},
author = {Kevin Vaillancourt},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/an-iota-of-signal-in-a-flood-of-noise-a-stateful-detector-improves-synthetic-intrusion-detection-from-13-to-92-e3wk}},
url = {https://apartresearch.com/sprints/projects/an-iota-of-signal-in-a-flood-of-noise-a-stateful-detector-improves-synthetic-intrusion-detection-from-13-to-92-e3wk}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …