Telemetry imputation
Recovers fine grained measurements from their coarse counterparts.
+ less measurement overhead + better debugging and history
Neural components can learn patterns directly from the vast amounts of data generated by networks. Symbolic rules can express the physical principles and design decisions that govern networks. Our neurosymbolic approach combines the two.
Our common methodology
AI promises to automate network management.
Recovers fine grained measurements from their coarse counterparts.
+ less measurement overhead + better debugging and history
Adapts sending rates to changing network conditions.
+ higher throughput, lower latency + less manual tuning
Identify applications from traffic metadata.
+ no payload inspection + QoS and anomaly detection
One methodology, three application areas
Generation, testing, and control share a common methodology. We discover network knowledge, codify it as explicit rules, and enforce those rules when decisions are made.
e.g., for telemetry imputation and synthetic data generation
Measurements, traces, and domain knowledge reveal constraints on valid network data.
Express constraints as explicit rules, learned from data or supplied by experts.
Guide training and reconstruction with constraints. LeJIT masks invalid next tokens during generation.
e.g., RL based network control and LLM token generation
Identify domain requirements and conditions where neural decisions need correction.
Express requirements and corrective behavior as rules over outputs, actions, and network state.
LeJIT filters token choices during inference. ReGuard corrects risky controller actions.
e.g., for traffic classification, network modeling, and abstraction refinement
Search for realizable attacks, avoidable controller failures, and counterexamples to proposed network rules.
ReGuard learns protection rules from counterfactual comparisons. TypoNet validates a symbolic model against network evidence. PANTS encodes feasible packet changes.
Verify network behavior with a solver, retrain on realizable attacks, and correct risky controller actions during deployment.
01
Generated network data should follow the same rules as the network it represents.
A language model learns statistical patterns in network data. LeJIT uses a logical solver to exclude choices that would violate explicit requirements, while leaving the language model to choose among the valid options.
LeJIT · HotNets 2025The LLM generates. LeJIT filters.
LeJIT masks invalid tokens before the LLM chooses its next token. The SMT solver uses the rules and the output so far to update the mask as generation continues.
Coarse measurements can hide short traffic bursts. Zoom2Net learns correlations among network signals to reconstruct fine detail. Explicit constraints keep the reconstructed telemetry consistent with measurements and operational knowledge.
Zoom2Net · SIGCOMM 2024Recover detail between measurements
Coarse averages hide when traffic arrives inside each observation window.
02
Network tests need realistic inputs and checkable expectations about behavior.
Autogram discovers checkable relationships in network telemetry. An LLM uses counter names and metadata to propose a grammar of possible relationships. A deterministic search checks those candidates with logic and statistics, allowing for measurement noise. The resulting invariants give network tests explicit conditions to check.
Autogram · HotNets 2026, to appearA grammar determines which rules can be found
The grammar defines the relationships Autogram can express.
Metadata proposes the search. Measurements decide.
Counter names and metadata go to the LLM, which proposes a typed grammar.
Adversarial search can propose input features that fool a network classifier, yet correspond to impossible traffic. PANTS combines that search with a solver that constructs realizable packets. It then checks whether those packets still fool the classifier.
PANTS · USENIX Security 2025From a difficult input to a real test
The classifier sees features extracted from packets, such as their average spacing.
An attacker restricted to delaying packets cannot make them arrive earlier.
Student debugging sessions provide realistic tests for AI network operators. The mini-Internet records how students configure networks, encounter faults, and repair them. Commands are abstracted into symbolic actions and matched against templates to reveal recurring diagnostic patterns. Replaying the faults creates benchmarks for AI diagnosis, while runbooks derived from the patterns guide AI agents toward a fix.
Read the paper · HotNets 2026Different commands reveal the same procedure
Two students configure equivalent hosts through different command sequences.
03
Explicit rules turn observed behavior into knowledge that can guide future decisions.
Network knowledge is scattered across standards, measurements, and operator experience. NetNomos learns candidate rules directly from data, filters them for meaning, and enforces them during generation.
NetNomos · NSDI 2026Learn rules from observations
A network-specific grammar defines the ingredients and structure of candidate rules.
A rule combines selected clauses with “or.” Try removing one clause, or adding the redundant condition.
A or B covers every observation, and neither clause is redundant.
A poor outcome does not always mean the controller made a poor decision. ReGuard searches for conditions where better decisions could have achieved more. It turns those counterfactual examples into rules that correct recurring mistakes during deployment.
ReGuard · NSDI 2027, to appearDiscover, explain, protect, refine
The outer search changes network conditions; the inner search finds a strong reference for the same conditions.
A low playback buffer, slow downloads, and a large next chunk call for a lower bitrate.
Pensieve bitrates follow ReGuard slides 12–13. The Sage curves and network scenes are schematic. Hover over or focus on a diagram element for details.
TypoNet translates network records into a reusable symbolic model. An AI agent proposes logical rules, and another AI agent challenges them with independent network evidence. A solver uses the checked rules to answer operational questions. A separate emulation loop adds knowledge for tasks such as root-cause analysis.
TypoNet · Preprint, July 2026Translate once. Ask the solver many questions.
Operators and AI agents face a large collection of configurations, topology records, and routing state.
Counterexamples turn proposed rules into checked knowledge.
The Constructor AI agent proposes a rule, and the Detractor AI agent checks it against independent evidence.
Looking ahead
Network AI needs knowledge it can inspect, update, and use at the right moment.
Distinguish recurring relationships from coincidences and express richer behavior over time.
Integrate learning and constraint enforcement so that explicit knowledge can guide decisions under tight latency requirements.
Find new failures and update the rules as networks and workloads change.
Further reading
The papers behind the demos provide the full methods and experimental results. For related work from other groups, see the community reading list.
Hongyu Hè, Minhao Jin, and Maria Apostolaki
PreprintHongyu Hè, Alexander Krentsel, Sylvia Ratnasamy, and Maria Apostolaki
PreprintConstantine Doumanidis, Hongyu Hè, and Maria Apostolaki
Student debugging traces and AI testingHongyu Hè and Maria Apostolaki
PreprintHongyu Hè, Minhao Jin, and Maria Apostolaki
Talk & publication CodeHongyu Hè and Maria Apostolaki
Talk CodeMinhao Jin and Maria Apostolaki
Talk & publication Code ArtifactFengchen Gong, Divya Raghunathan, Aarti Gupta, and Maria Apostolaki
Publication CodeFrom the community
Related work connects learning, domain knowledge, and formal reasoning across networked systems and AI applications. Contributions from all research groups are welcome, including your own work.
Join the conversation
Have network data, an application that needs better guarantees, or a question current methods cannot answer? Share it with the community.
Bring a dataset, workload, or deployment challenge. Tell us what the network does and what AI needs to get right.
Share a use casePoint out a failure case, a missing constraint, or a research question. Concrete examples help connect ideas to practical problems.
Start a discussionSubmissions open as public GitHub issues and require a GitHub account. For restricted data, share a description and a contact route rather than uploading the data.
Who we are
This work is supported by the U.S. National Science Foundation and the Office of Naval Research.