LOCAL AI · BEHAVIORAL SECURITY · SHADOW MODE

Your WAF sees requests.
JevSec sees behavior.

JevSec is a self-hosted behavioral security triage layer that groups activity across requests, combines deterministic evidence with local Qwen3-4B decisions, and surfaces structured findings for human review.

Self-hostedLocal Qwen3-4BNo auto-blockingMIT licensed
Latest semi-real test
39 vs 30
anomalous windows detected by Hybrid vs static rules
26.90%Hybrid recall
97.50%Precision
0.95%Observed FPR
1 / 105Normal false reviews
Evidence first

More review coverage, with the caveats left visible.

On a deterministic held-out CSIC replay sample, JevSec Hybrid detected 39 anomalous windows versus 30 for the static-rule baseline. That is a 30% relative increase in detections on this sample, with one additional false review among 105 normal windows.

JevSec benchmark showing 20.69 percent recall for static rules, 23.45 percent for local Qwen3, and 26.90 percent for JevSec Hybrid
250held-out windows
145anomalous
105normal
+50%relative recall on 1-anomaly subgroup
Different layer, different job

Keep the WAF. Add behavioral context beside it.

Traditional WAF

Request-level enforcement

Strong at known request syntax, exploit indicators, anomaly rules and immediate enforcement decisions.

  • SQLi / XSS / traversal signatures
  • Request anomaly scoring
  • Inline allow / block
+
JevSec

Cross-request review context

Aggregates short behavior windows and highlights sequence, frequency, context and rule/model disagreement.

  • Behavior windows
  • Local Qwen3-4B
  • Human-review oriented findings
Nginx / JSONL→privacy-aware normalization→behavior windows→rules + Qwen3-4B→review findings
Built for local evaluation

Privacy-aware by design.

01

Local model

Current decision provider is Qwen3-4B through a local Jev-compatible service.

02

Whitelisted context

Cookies, Authorization values, passwords and API keys are not retained for model context.

03

Shadow mode first

JevSec does not automatically ban IPs, alter firewall state or block requests.

04

Reproducible evaluation

Fixed seeds, validation-only threshold fitting, held-out reporting and explicit failure analysis.

No benchmark theater

The current model is not production-proven.

AUROC remains weak.

Current semi-real risk-score AUROC is 0.473 for Qwen3-4B and 0.454 for Hybrid. The current gain is incremental review coverage, not strong global risk ranking.

The data is semi-real.

CSIC 2010 is an experimental dataset. Replay IPs, timestamps and response codes are evaluation scaffolding, not original production observations.

It is not a WAF replacement.

Request-level exploit syntax remains squarely in the domain of mature WAFs. JevSec is a complementary behavioral review layer.

Research Alpha

Run it, break the assumptions, challenge the benchmark.

The most useful feedback right now is about false positives, missing behavior classes, sequence design and fair evaluation.