PARALLAX DETECTION PIPELINE
Live simulation — select an account archetype and watch 15 detectors classify behavior in real time
REAL-WORLD VALIDATION
Evaluated against the Los Alamos National Laboratory Unified Host and Network Dataset — 16.9M real authentication events, 87 known-compromised users
$ cat findings.txt
T2-006 Behavioral Shift is the engine. Compromised users show sharp behavioral changes in peak 4-hour windows (mean 0.71 vs normal 0.43). Delta +0.29 — drives most of the separation. This is the cross-domain signal: lateral movement in auth logs manifests as sudden behavioral shift, the same pattern that catches account takeover on AI platforms.
T1-009 Host Fan-Out delivers the second-strongest signal (+0.13 delta). Compromised users access more distinct hosts in their peak windows (mean 0.79 vs normal 0.66) — lateral movement leaves a destination diversity signature.
7 of 12 detectors were anti-correlated in v2 — they scored normal users higher than compromised. Designed for AI platform abuse, they penalized the wrong group on auth data. v3 zeroed all 10 non-contributing detectors and redistributed weight to the 5 correctly-oriented signals. AUC jumped from 0.48 to 0.68.
The approach that worked: diagnose which signals are noise, silence them, amplify what remains. Subtraction beat addition.
| Threshold | TP | FP | FN | TN | Precision | Recall | F1 |
|---|---|---|---|---|---|---|---|
| 0.25 | 72 | 324 | 15 | 89 | 18.2% | 82.8% | 0.298 |
| 0.35 | 71 | 309 | 16 | 104 | 18.7% | 81.6% | 0.304 |
| 0.45 | 69 | 273 | 18 | 140 | 20.2% | 79.3% | 0.322 |
| 0.55 | 62 | 204 | 25 | 209 | 23.3% | 71.3% | 0.351 |
| 0.77 | 42 | 44 | 45 | 369 | 48.8% | 48.3% | 0.486 |
| Detector | Weight | Delta | Role |
|---|---|---|---|
| T2-006 Behavioral Shift | 0.30 | +0.29 | Primary — cross-domain signal |
| T1-009 Host Fan-Out | 0.25 | +0.13 | Lateral movement signature |
| T1-008 Concurrent Sessions | 0.20 | +0.05 | Parallel access patterns |
| T1-007 Error Pattern | 0.15 | +0.01 | Auth failure signatures |
| T1-004 Session Anomaly | 0.10 | +0.04 | Session structure deviation |