๐ฅ Roast My Pick ยท SIH26153
AI based Network Attack Forecasting from Network Traffic Data
National Technical Research Organisation (NTRO)
Good pick. Genuinely. Now sit down, because the judges are going to try anyway โ and this is what they will try.
Strong pick. The forecasting-over-classification framing is genuinely fresh and the data is handed to you โ commit to predicting the next stage rather than relabelling flows, and define clearly what a correct forecast means, because that is where the concept proves itself. Roughly 70โ160 teams are expected to go here.
The receipts
Every red flag on this statement, in full. These are the four places it bites.
Exhibit A
Public IDS datasets have discrete labelled attacks but limited genuine multi-stage campaign structure, so the temporal progression you learn may be thinner than the framing implies
It gets worse
Forecasting future attack states is much harder to validate than classifying past ones, and you must define honestly what a correct forecast even means
Still reading?
Lab-dataset attack sequences are cleaner than real ones, so forecast accuracy will look better than it would deploy
And the finisher
The world-model framing is ambitious, and a submission that quietly reduces to a sequence classifier has not delivered the forecasting the description asks for
The damage report
Every score this statement earned, and what each one actually costs you.
Feasibility
4/5Actually buildable, which on this slate is rarer than it sounds. Do not squander it on scope.
The datasets are named and public โ CIC-IDS and UNSW-NB15 contain labelled multi-stage attack sequences โ and sequence and graph models over network telemetry are well-supported, so the whole thing is buildable, with the framing as forecasting rather than classification the genuinely novel and interesting twist.
Innovation scope
4/5There is something genuinely new here. Do not bury it under another dashboard.
The world-model framing โ learning state transitions to predict progression rather than classifying flows โ is genuinely open and current, and how you represent state and forecast the next stage is the real intellectual contribution.
Clarity
4/5The ask is unambiguous, which quietly removes your favourite excuse.
The description is specific about the approach โ state representation, sequence or graph models, next-stage probability, MITRE ATT&CK mapping, explainability โ so the deliverable is well defined even though it points at an ambitious concept.
Acceptance potential
4/5Strong footing before you have written a line. Try not to waste it.
A strong pick โ the data is named and public, the forecasting-over-classification framing is genuinely fresh in a field crowded with binary IDS projects, and the MITRE ATT&CK mapping plus explainability make it exactly the kind of predictive-defence work NTRO is signalling it wants.
Effort
HeavyHeavy. Somebody on this team is not sleeping in week three. Pick who, on purpose.
State representation, the temporal or graph model, the forecasting head, the ATT&CK mapping and the explainability layer are focused, well-bounded work on data that already exists.
Demo-ability
MediumDemoable, if you rehearse it. Nobody rehearses it.
Forecasting the next attack stage before it happens is a genuinely compelling story, but it needs the multi-stage attack context explained before a judge appreciates that a prediction, not a detection, is being shown.
The demo they will have already seen
Somewhere around 70โ160 teams are heading here, and the description is doing the choosing for most of them. They will read the same brief, reach the same architecture, and build a version of the same demo you are planning. Being correct is the floor. If your five minutes could be swapped with the team before you and nobody in the room would notice, you have not picked badly โ you have built predictably, which costs exactly the same and hurts more.
What survives
The ground worth standing on when the questions start.
- The datasets are named and public, and CIC-IDS and UNSW-NB15 genuinely contain the multi-stage attack sequences the forecasting depends on
- Framing this as forecasting rather than classification is a real conceptual differentiator in a field saturated with binary intrusion detectors
- MITRE ATT&CK mapping gives your predictions a standard, defender-legible vocabulary that makes the output immediately actionable
Nothing here is fatal. It is just the list of places this statement pushes back, and you now get to push there first.
The framing is a joke. The findings are not โ they are the same analysis on the statement page, and every line above is attached to a score or a fact in the record. It is one opinion with its reasoning attached, so argue with it before you trust it.