EXFILSENSE
03 / MODEL REPORTS

Five versions, one frozen threshold each

Every figure below is read from that version's index.json at the moment you load this page — not from the documentation, which can lag behind a retrain.

Model Unit Thr. PRF1ROC Rows
LSTM host · host_v1 entity 0.947 0.9115 0.8047 0.8548 0.9322 1 548 open
Random Forest dns · dns_v1 0.4 0.9978 0.9997 0.9988 0.9999 26 245 open
Random Forest host · host_v1 entity 0.367409241717 0.9060 0.8281 0.8653 0.9349 1 548 open
XGBoost dns · dns_v1 0.78 0.9985 0.9990 0.9987 1.0000 26 245 open
XGBoost host · host_v1 entity 0.79492521286 0.9464 0.8281 0.8833 0.9390 1 548 open

Thresholds are selected on VALIDATION and frozen; evaluation applies them and never re-selects. A threshold is shown at the precision the artifact carries — hover any figure for the stored value.

Version Runs Figures Trials Features Attribution Devices Index generated
lstm · host_v1 15 6 not produced cpu, gpu 2026-08-10 20:49 UTC
random-forest · dns_v1 3 6 12 7 produced cpu 2026-08-11 10:46 UTC
random-forest · host_v1 9 9 produced cpu 2026-08-10 19:36 UTC
xgboost · dns_v1 10 6 produced cpu, gpu 2026-08-10 19:43 UTC
xgboost · host_v1 9 9 produced cpu, gpu 2026-08-10 19:52 UTC

Every count is read from that version's index.json. Trials and features are blank where the version's generator recorded no search and no preprocessing block — a blank is the absence of a record, not a zero that was measured.