October 2, 2026
As AI makes sophisticated cyber capabilities faster, more scalable, and increasingly accessible, organizations face a new generation of network attacks that can rapidly outpace human-led defenses. An advanced AI model is reportedly capable of breaching some of the U.S. government’s most sensitive classified systems in a matter of hours (Kuntz & Williams, 2026). Many threat-detection systems still rely on manual retraining and analysis, along with fixed thresholds that lose effectiveness as threats evolve. In response, Merit is collaborating with Michigan students and faculty to develop more adaptive defenses capable of detecting and responding to AI-accelerated attacks at the speed they emerge.
At Grand Valley State University (GVSU), for example, student Collins Karani has developed an agentic AI-powered threat detection and response prototype as part of his master’s work, under the guidance of Dr. Mostafa El-Said, Professor and Chair of Computer Science. A cybersecurity engineer with more than four years of enterprise experience, Karani specializes in AI-powered intrusion detection, darknet traffic analysis, and secure network infrastructure.
Karani used unsolicited internet traffic, also known as darknet data, from Merit Network’s INDNT Network Telescope to test and train his prototype. Darknet traffic contains very little legitimate activity, making malicious behavior easier to identify without the usual background noise. Because many attacks behave similarly whether they target unused or active addresses, the system learns common patterns in TCP flags, ports, and packet structures. This enables it to recognize attack behavior instead of relying on the configuration of one specific network. Using authentic internet traffic also strengthens the prototype’s feature extraction and model training.
The prototype developed by Karani essentially acts as a small security team. The training agent studies historical traffic and trains five machine-learning models to recognize nine categories of suspicious activity. The streaming agent examines new traffic using the trained models and asks the policy engine to consider what to allow, record, investigate, flag, or block. The threat-intelligence and firewall agents then identify and rank potentially dangerous behavior and sources. A feedback loop closes the process by evaluating the team’s choices and saving the information for future retraining.
Network defenders need tools that can learn and adapt just as quickly. New approaches to threat-detection software focus on tools that use a feedback loop to support retraining, measure effectiveness, and recalibrate automatically. Instead of requiring people to repeatedly update the software as threats change, the tool learns from the attacks it encounters, evaluates whether its response works, adjusts its approach, and becomes more effective over time.
Karani keeps it simple: “Train, detect, decide, prioritize, respond, evaluate, and learn again.”
The evaluation results:
97.1% recall: The prototype detected about 97 out of every 100 attacks in the evaluation. It also achieved 96.6% overall classification accuracy, within the 93.6% to 98.3% range reported by the systems in Karani’s literature review. Those studies used different data and methods, so the figures are useful context rather than a direct ranking.
98.7% autonomy: The prototype made nearly all evaluated decisions without human intervention; 1.3% required human review. The reviewed systems did not report a directly comparable measure of autonomy.
0.8% autonomous-blocking false-positive rate: Fewer than one in 100 autonomous decisions to block activity were incorrect. This measures blocking decisions specifically, so it cannot be directly compared with the general false-positive rates reported for other systems.
GVSU’s capstone model allows students to apply what they learn to an open research problem, moving away from predetermined classroom exercises and instead reinforcing experience with the real-life research process. In this example, developing an autonomous intrusion-detection system for corporate use functioned as an open-ended challenge and created momentum for continued research. “Our goal is not just to build something that is going to work in a classroom sandbox,” says El-Said. With Merit’s telescope data providing authentic telemetry of internet traffic, the collaboration establishes an educational sequence that future researchers can replicate: take classic classroom knowledge and research techniques, utilize synthetic data to its finite end, introduce fresh, real traffic data, build and evaluate an evolved prototype, and begin an unexplored course with brand-new research and deployment questions that extend beyond earlier efforts.
The next step for Karani is to move the prototype beyond the research environment, testing it with diverse datasets and real operational traffic to determine whether it can respond safely and reliably at scale. Any organization can participate, further strengthening a common model while protecting sensitive data. What began as a graduate research question can ultimately help shape a more adaptive approach to network defense, one that continues learning as the threats it confronts continue to change.