ShadowCore-v2
ShadowCore-v2
Symbolic Network Risk Intelligence
Overview
ShadowCore-v2 is an 83.92M parameter hybrid neural architecture designed for symbolic network risk classification.
The model analyzes fixed-length sequences of network events and predicts a risk score between 0 and 9, representing increasing levels of network instability, degradation, and failure severity.
ShadowCore-v2 is the successor to ShadowCore-v1 and introduces a significantly expanded token vocabulary, a larger output space, and richer representation of network behavior while maintaining greater than 90% training accuracy.
Developed by BRSX-Labs.
Highlights
83.92M Parameters
CNN + GRU + Transformer + Mamba-like Hybrid Architecture
11 Symbolic Network Event Tokens
10 Risk Classes (0-9)
Context Length: 64 Tokens
Global Sequence-Level Classification
Supports Recovery-Aware Risk Estimation
What's New in ShadowCore-v2
Expanded Vocabulary
ShadowCore-v1 used only four symbolic events:
ShadowCore-v2 expands the vocabulary to eleven network events:
1 U
2 D
3 +
4 -
5 J
6 R
7 L
8 T
9 C
10 H
11 F
This allows the model to represent more realistic network conditions and failure scenarios.
Expanded Output Space
ShadowCore-v1:
ShadowCore-v2:
This enables finer anomaly severity estimation and more granular decision making.
Improved Network Awareness
ShadowCore-v2 introduces explicit representation of:
Packet Loss
Retransmissions
Jitter
Connection Resets
Timeouts
Recovery Events
Traffic Bursts
which were not available in ShadowCore-v1.
Token Definitions
1 U = Upload Increase
2 D = Download Increase
3
4 + = Latency Increase
5 - = Latency Decrease
6
7 J = Jitter
8 R = Retransmission
9 L = Packet Loss
10
11 T = Timeout
12 C = Connection Reset
13
14 H = Recovery
15 F = Flow Burst
Token Interpretation
1 Low Risk
2
3 H = Recovery
4 U = Upload Increase
5 D = Download Increase
6 - = Latency Decrease
7
8 Moderate Risk
9
10 + = Latency Increase
11 F = Flow Burst
12
13 High Risk
14
15 J = Jitter
16 R = Retransmission
17
18 Critical Risk
19
20 L = Packet Loss
21 T = Timeout
22 C = Connection Reset
Actual predictions depend on the entire sequence and not on individual token presence.
Risk Scale
1 0 = Healthy
2
3 1 = Normal Operation
4
5 2 = Minor Variation
6
7 3 = Low Risk Anomaly
8
9 4 = Moderate Risk
10
11 5 = Elevated Risk
12
13 6 = Significant Risk
14
15 7 = Severe Risk
16
17 8 = Critical Risk
18
19 9 = Extreme Risk / Failure State
Architecture
ShadowCore-v2 uses four specialized experts operating in parallel.
1 Input
2 ↓
3 Embedding
4 ↓
5 ┌───────────────┐
6 │ CNN Expert │
7 ├───────────────┤
8 │ GRU Expert │
9 ├───────────────┤
10 │ Transformer │
11 ├───────────────┤
12 │ Mamba Expert │
13 └───────────────┘
14 ↓
15 Fusion
16 ↓
17 Global Pooling
18 ↓
19 Classifier
20 ↓
21 Risk Score
Embedding Layer
1 Vocabulary Size : 11
2 Dimension : 512
All symbolic tokens are projected into a shared embedding space before expert processing.
CNN Expert
Purpose:
Local pattern extraction
Burst detection
Short-term event relationships
Configuration:
1 Blocks : 7
2 Channels : 960
3 Kernel : 3
GRU Expert
Purpose:
Sequential modeling
Temporal event tracking
Configuration:
1 Hidden Size : 960
2 Layers : 4
Transformer Expert
Purpose:
Long-range dependencies
Global context understanding
Configuration:
1 Layers : 6
2 Heads : 8
3 Feedforward : 2048
4 Dropout : 0.1
Mamba-like Expert
Purpose:
Efficient state-space sequence modeling
Long-context compression
Configuration:
1 Layers : 10
2 State Dim : 1408
Fusion Layer
Outputs from all experts are concatenated and fused.
1 CNN
2 +
3 GRU
4 +
5 Transformer
6 +
7 Mamba
8 ↓
9 Linear Fusion
10 ↓
11 LayerNorm
12 ↓
13 GELU
Classification Head
1 Global Mean Pooling
2 ↓
3 Linear(512)
4 ↓
5 GELU
6 ↓
7 Linear(10)
Final output:
Model Size
1 Total Parameters
2
3 83.92 Million
Training Configuration
1 Optimizer : AdamW
2 Learning Rate : 1e-4
3
4 Batch Size : 64
5
6 Epochs : 4
7
8 Gradient Clip : 1.0
9
10 Checkpoint
11 Every 1000 Steps
Sequence Format
Input length must be exactly 64 tokens.
Example:
UUUDDUUUDDUUUUDDHHHHUUUDD++JJRRLLTTUUUDDUUUDDUUUUDDHHHHUUUDD
Benchmark Summary
ShadowCore-v2 maintains greater than 90% training accuracy despite:
1 Vocabulary Expansion
2
3 4 Tokens
4 ↓
5 11 Tokens
6
7 Output Expansion
8
9 3 Classes
10 ↓
11 10 Classes
Observed training results:
1 Epoch 1 ≈ 90%
2
3 Epoch 2 ≈ 92%
4
5 Epoch 3 ≈ 92%
6
7 Epoch 4 ≈ 92-93%
This indicates that the architecture successfully scales to a larger symbolic event space without major degradation in training performance.
Behavioral Evaluation
Observed behavior during manual testing suggests that the model:
Differentiates Timeout and Connection Reset events.
Detects increasing failure density.
Uses intermediate risk levels instead of binary decisions.
Recognizes Recovery patterns.
Reacts to escalating anomaly accumulation.
Produces stable risk estimates for normal traffic sequences.
Example observations:
1 Healthy Traffic
2 → Low Risk
3
4 Timeout + Recovery
5 → Reduced Risk
6
7 Connection Reset Dominated
8 → Critical Risk
9
10 Mixed Jitter / Loss / Retransmission
11 → Medium-High Risk
Intended Use
ShadowCore-v2 is intended for:
Network anomaly research
Symbolic traffic classification
Risk scoring experiments
Cybersecurity research
Educational projects
Sequence classification studies
Limitations
Fixed context length of 64 tokens.
Requires symbolic event encoding.
Not intended as a production IDS/IPS replacement.
Training accuracy is not equivalent to real-world deployment performance.
Requires domain-specific token generation pipelines.
Citation
1 ShadowCore-v2
2
3 83.92M Parameter Hybrid CNN-GRU-Transformer-Mamba
4 Architecture for Symbolic Network Risk Classification
5
6 Developed by BRSX-Labs
7 2026