Russian Researchers Develop Hybrid Neural Network Architecture for Cyberattack Detection
Researchers at the National Research Nuclear University MEPhI have developed TA-BN-ODE, a hybrid artificial intelligence architecture designed to detect cyberattacks.

Unlike conventional security systems that either analyze isolated events or inspect networks at scheduled intervals, the new architecture tracks sequences of attacker activity in continuous time, from microseconds to months. The system combines neural ordinary differential equations, spatiotemporal models, Bayesian inference, and a large language model. Together, these components enable it to estimate the probability of cyber threats, prioritize alerts, and identify previously unseen attack techniques.
Protecting Critical Infrastructure
TA-BN-ODE achieved a 99% attack detection rate. For zero-day attacks, it reached 87.6% detection accuracy compared with roughly 42% for signature-based systems. The model requires just 9.2 MB of RAM and processes more than 12 million events per second with latency below 0.1 seconds.
The technology could serve as the foundation for Russian intrusion detection systems, SIEM platforms, and SOC solutions while strengthening the cyber resilience of critical infrastructure, government agencies, financial institutions, telecommunications providers, and industrial enterprises. For end users, that could translate into a lower risk of data breaches, service disruptions, and fraud. More broadly, the technology advances a proactive approach to cyber defense by identifying previously unknown attack scenarios rather than relying solely on known signatures.

Demand for Compact Real-Time Models
The developers plan to integrate the architecture into enterprise SOC environments. Its ability to process millions of events while estimating threat probabilities could reduce false positives and ease the workload on security analysts. Primary application areas include protecting government information systems, energy facilities, industrial and transportation infrastructure, banking and payment services, communications networks, cloud environments, data centers, and IoT deployments.
The technology comes at a time when cyberattacks are becoming increasingly sophisticated. According to Positive Technologies, the number of successful cyberattacks worldwide increased by 18% in 2023, driven in part by the growing exploitation of zero-day vulnerabilities. Russian SOC operators are already handling large-scale data streams. For example, Solar Group analyzes incidents across approximately 300 organizations in multiple industries, creating demand for compact, high-performance models capable of operating in real time.
The architecture could eventually be exported as software modules for intrusion detection systems, IoT security platforms, and national SOC deployments in countries seeking greater technological sovereignty. Before that becomes possible, however, the prototype will need to mature into a certified commercial product, undergo validation on live network traffic, and demonstrate compatibility with widely deployed cybersecurity platforms.

Growing Interest From Major Industry Players
In 2022, Russian researchers introduced a neural network model capable of detecting cybersecurity incidents affecting critical infrastructure in real time. That marked another step in the development of Russian machine learning-based security technologies. A year later, Sber and the Russian Academy of Sciences agreed to conduct joint research in artificial intelligence and cybersecurity, including work on high-speed attack detection methods. The partnership highlighted growing interest among major organizations in these technologies.
By 2024, the increasing complexity of cyber threats had become even more apparent. Solar JSOC reported a higher share of critical attacks and malware-related incidents across a sample of approximately 300 organizations. Positive Technologies also documented continued growth. During the fourth quarter of 2024, the total number of incidents rose by 13%, while malware was involved in 66% of successful attacks.
Against that backdrop, Russian developers continued integrating machine learning into cyber threat management systems throughout 2026 to improve anomaly detection and attack forecasting. The MEPhI architecture advances that direction by analyzing not only individual events but also the temporal logic connecting an attack's entire sequence of actions.

Testing on Live Infrastructure
TA-BN-ODE can be viewed as a promising intelligent intrusion detection system. Its distinguishing feature is the ability to analyze cyberattacks as long-running processes rather than as collections of unrelated events. That approach is particularly effective against sophisticated targeted attacks, which often unfold gradually and remain undetected by conventional security tools for extended periods.
According to experts, the next stage will involve testing the system on operational infrastructure and adapting it for sector-specific use cases. If its performance is confirmed under real-world conditions, the model could become the analytical core of future Russian SIEM, NDR, and SOC platforms. Looking ahead, systems of this kind are expected to work alongside human analysts by automatically identifying attack chains, assessing risk, and recommending response priorities.









































