Evidence

It starts level with the rule set. Then it learns.

The OWASP Core Rule Set is the standard defence for web applications. We put Senua AI against it on the same traffic, with nothing tuned on either side.

Out of the box: already ahead

Senua AI learned normal traffic only; the rule set ran as it ships. On the same 30,532 requests:

66.9%

of attacking sources stopped by Senua AI, against 64.7% for the rule set

CSIC 2010, the same 30,532 requests

Half

the genuine visitors wrongly blocked: 1 in 18,000, against 2

CSIC 2010

The chance of that lead being luck is under one in ten thousand.

After learning: 2.4 times the rule set

A rule set does not learn. Senua AI learns the causal pattern behind every attack an analyst confirms. On attacks it was never given, at the same false-block rate as the rule set (2 in 18,000), it blocked 67.4% of attacking requests. The rule set blocked 28.0%, and turned up a single notch it blocks every genuine visitor as well. There is no usable setting between.

CSIC 2010 public dataset; OWASP Core Rule Set on ModSecurity v3, official image, paranoia level 1, nothing changed. The attacks in this dataset are generated from templates, so the learning result shows the engine recognising new instances of attack types it has seen. The inline defence showcase has the full comparison and the files to rerun it.