The approach, which the authors say has never before been applied to intrusion detection, transforms raw network traffic data into grayscale images and then analyzes those images the way a vision model would analyze a photograph.

The core insight behind the work is that network intrusion data, despite arriving as tables of numbers, contains patterns that can be made visible.

Network traffic is notoriously lopsided: in a typical dataset, normal connections vastly outnumber malicious ones, which can bias classifiers toward simply labeling everything as safe.

The experimental evidence spans three benchmarks that have anchored intrusion detection research for years.

All three datasets, while canonical, are laboratory benchmarks; real network traffic is noisier, more diverse, and subject to distribution drift as new services and protocols appear.