Neurosymbolic Networking
Contents
ExploreOn this page

Make Network Knowledge First-Class.

Neural components can learn patterns directly from the vast amounts of data generated by networks. Symbolic rules can express the physical principles and design decisions that govern networks. Our neurosymbolic approach combines the two.

Our common methodology

  1. 01DiscoverFind useful network knowledge
  2. 02CodifyExpress knowledge as rules
  3. 03EnforceUse rules to guide decisions

AI promises to automate network management.

Telemetry imputation

Recovers fine grained measurements from their coarse counterparts.

Four coarse measurements become four windows of fine-grained measurements. In the failure state, the middle windows violate the observed totals.coarse → fine-grainedimpossible given the input✓ totals match the measurements

+ less measurement overhead + better debugging and history

Congestion control

Adapts sending rates to changing network conditions.

Sage sending rate and a dashed BBR reference after a bandwidth drop. The failure example recovers slowly even after bandwidth returns.tracks the available bandwidthSageBBRProtectedOriginal

+ higher throughput, lower latency + less manual tuning

Traffic classification

Identify applications from traffic metadata.

Encrypted traffic classified as a video call. Two small packet delays incorrectly change the label to web browsing; knowledge-guided training restores the video-call label for this illustrative perturbed flow.Video callWeb browsing

+ no payload inspection + QoS and anomaly detection

One methodology, three application areas

Discover, codify, enforce

Generation, testing, and control share a common methodology. We discover network knowledge, codify it as explicit rules, and enforce those rules when decisions are made.

Generation

e.g., for telemetry imputation and synthetic data generation

  1. 01 Discover

    Measurements, traces, and domain knowledge reveal constraints on valid network data.

  2. 02 Codify

    Express constraints as explicit rules, learned from data or supplied by experts.

  3. 03 Enforce

    Guide training and reconstruction with constraints. LeJIT masks invalid next tokens during generation.

Control

e.g., RL based network control and LLM token generation

  1. 01 Discover

    Identify domain requirements and conditions where neural decisions need correction.

  2. 02 Codify

    Express requirements and corrective behavior as rules over outputs, actions, and network state.

  3. 03 Enforce

    LeJIT filters token choices during inference. ReGuard corrects risky controller actions.

Testing & robustification

e.g., for traffic classification, network modeling, and abstraction refinement

  1. 01 Discover

    Search for realizable attacks, avoidable controller failures, and counterexamples to proposed network rules.

  2. 02 Codify

    ReGuard learns protection rules from counterfactual comparisons. TypoNet validates a symbolic model against network evidence. PANTS encodes feasible packet changes.

  3. 03 Enforce

    Verify network behavior with a solver, retrain on realizable attacks, and correct risky controller actions during deployment.

01

Logic-guided Generation

Generated network data should follow the same rules as the network it represents.

LeJIT: a case for Just-In-Time knowledge infusion

A language model learns statistical patterns in network data. LeJIT uses a logical solver to exclude choices that would violate explicit requirements, while leaving the language model to choose among the valid options.

LeJIT · HotNets 2025

The LLM generates. LeJIT filters.

LeJIT masks invalid next tokens using rules and an SMT solver. The LLM selects an allowed token and continues generating.CapacityTotalsBurstsNetwork rulesSMT solverLLMCandidatesLeJITNext token2Selected bythe LLM270819Generated tokens2Propose → mask → select → repeat
CandidatesMasked outAllowed choices

LeJIT masks invalid tokens before the LLM chooses its next token. The SMT solver uses the rules and the output so far to update the mask as generation continues.

Inspired by the token-masking sequence in the LeJIT HotNets slides. Token choices illustrate the mechanism; the page does not run an LLM or an SMT solver.

Zoom2Net: a case for knowledge-augmented training

Coarse measurements can hide short traffic bursts. Zoom2Net learns correlations among network signals to reconstruct fine detail. Explicit constraints keep the reconstructed telemetry consistent with measurements and operational knowledge.

Zoom2Net · SIGCOMM 2024

Recover detail between measurements

Observe. Each window averages 20, but an average cannot reveal when a burst occurred. Correlated measurements provide additional clues.Traffic per intervalObserved average0204060???Window 1Total: 100Window 2Total: 100Window 3Total: 100Coarse averages leave the detail unknown

Coarse averages hide when traffic arrives inside each observation window.

An illustrative reconstruction inspired by the Zoom2Net slides and Figures 1 and 6. Several detailed histories can match the same coarse measurements.

02

Logic-guided Testing

Network tests need realistic inputs and checkable expectations about behavior.

Autogram: Invariant Discovery for Networked Systems

Autogram discovers checkable relationships in network telemetry. An LLM uses counter names and metadata to propose a grammar of possible relationships. A deterministic search checks those candidates with logic and statistics, allowing for measurement noise. The resulting invariants give network tests explicit conditions to check.

Autogram · HotNets 2026, to appear 

A grammar determines which rules can be found

The grammar defines which relationships Autogram can express. A known flow-conservation rule lies outside a grammar limited to pairwise comparisons.Relations the solver can decideGrammar ΓKnown invariantStart with comparisonst ::= xr ::= t ≈ t | t ≤ tFlow conservationXYZout(X) ≈ e(X,Y) + e(X,Z)CandidateAccepted★ Known

The grammar defines the relationships Autogram can express.

Autogram Figure 1, redrawn as an expanding search space. Candidate positions and the abbreviated grammar illustrate expressibility; they are not experimental results.

Metadata proposes the search. Measurements decide.

Counter names and metadata go to the LLM, which proposes a typed grammar. Network measurements go directly to the evaluator.Counter names& metadataLLMΓDeterministic search and evaluationCandidatesx = xx < xout ≈ Σ egressSolver⊢?Statistical testResidualsNetworktelemetrySynthetic calibration dataCandidates await evaluationA proposed relation still needs evidence

Counter names and metadata go to the LLM, which proposes a typed grammar.

Autogram Figure 2. Measurements enter the statistical evaluator; synthetic calibration data sets the generic thresholds. The residual plot is illustrative.

PANTS

Adversarial search can propose input features that fool a network classifier, yet correspond to impossible traffic. PANTS combines that search with a solver that constructs realizable packets. It then checks whether those packets still fool the classifier.

PANTS · USENIX Security 2025

From a difficult input to a real test

Extract features. The classifier sees features extracted from packets, such as their average spacing. A test must account for the relationship between those features and real packets.OriginalpacketsFeatureextractionNetworkclassifierPacket spacing becomes a classifier inputPacket arrival times10 ms220 ms340 ms460 msThe classifier uses measurements,not the raw timing story.

The classifier sees features extracted from packets, such as their average spacing.

A simplified reconstruction of PANTS Figure 4. The timing example uses an illustrative 20 ms per-packet delay budget.

Could an attacker make this change?

Packets on a shared 0 to 100 millisecond axis. Original: 0, 20, 40, 60. Candidate: 0, 10, 35, 60.Arrival time (ms)020406080100OriginalCandidate102203404601+02-103-54+0Delay relative to original (ms)

An attacker restricted to delaying packets cannot make them arrive earlier.

No Hyperscaler? No Problem. Your Students also Break (and Fix) Networks

Student debugging sessions provide realistic tests for AI network operators. The mini-Internet records how students configure networks, encounter faults, and repair them. Commands are abstracted into symbolic actions and matched against templates to reveal recurring diagnostic patterns. Replaying the faults creates benchmarks for AI diagnosis, while runbooks derived from the patterns guide AI agents toward a fix.

Read the paper · HotNets 2026 

Different commands reveal the same procedure

Two students configure equivalent hosts with different addresses, command spellings, and operation orders. Both finish with a successful ping.Two students configure a hostStudent Aip addr add 55.200.0.1/24dev 55-S2ip route add defaultvia 55.102.0.2ip addr showip rping 55.102.0.2Student Bip address add 24.200.0.11/24dev 24-S2ifconfigip route add defaultvia 24.200.0.254ip route list defaultping group24.ATLrouterSame goal: configure, inspect, connectHostGatewayping ✓

Two students configure equivalent hosts through different command sequences.

Figure 1, redrawn as a command-to-pattern walkthrough. The final view aligns the unordered commands for comparison; the successful probe remains the anchor. Hover or focus on commands to see their mapping.

03

Logic-guided Control

Explicit rules turn observed behavior into knowledge that can guide future decisions.

NetNomos: a case for automated rule learning

Network knowledge is scattered across standards, measurements, and operator experience. NetNomos learns candidate rules directly from data, filters them for meaning, and enforces them during generation.

NetNomos · NSDI 2026

Learn rules from observations

Define grammar Γ. The grammar defines typed signals, comparisons, logical connectives, and time windows. It gives NetNomos an expressive but bounded search space.Grammar ΓCore productionsτ ∈ {time, size, id, flag, count}vτ ∈ V, k ∈ {0, …, K − 1}p ::= (ℓτ ⋈ rτ), ⋈ ∈ {<, ≤, =, ≠, ≥, >}φ ::= [¬]p ((∨ | ∧ | ⇒) [¬]p)*Q ::= ε | ∀W | ∀W ∃vkC ::= Q : φA concrete window: K = 5CongestiontK > 0BW/2tt+1t+2t+3t+4∃ 0 ≤ k < 5 : It+k ≥ BW/2

A network-specific grammar defines the ingredients and structure of candidate rules.

The grammar and evidence-set search from NetNomos, redrawn from slides 16–20. A rule that fits observations still needs a check for semantic meaning.

Which clauses cover every observation?

A rule combines selected clauses with “or.” Try removing one clause, or adding the redundant condition.

Sample 1B ✓
Sample 2A ✓
Sample 3A ✓
Sample 4B ✓
Sample 5B ✓

A or B covers every observation, and neither clause is redundant.

ReGuard: a case for rule-protected RL controllers

A poor outcome does not always mean the controller made a poor decision. ReGuard searches for conditions where better decisions could have achieved more. It turns those counterfactual examples into rules that correct recurring mistakes during deployment.

ReGuard · NSDI 2027, to appear

Discover, explain, protect, refine

Discover. The outer search changes network conditions; the inner search finds a strong reference for the same conditions. The performance gap directs the search toward avoidable failures.Test both controllers on the same bottleneckPensieve · 1850 KbpsRL controllerBottleneckVideo trafficBufferReference · 750 KbpsReference policyBottleneckVideo trafficBufferNetwork search ↻ Better reference ↻

The outer search changes network conditions; the inner search finds a strong reference for the same conditions.

Bitrate choices and the 750 Kbps rule follow ReGuard slides 12–13. Network scenes illustrate the failure mechanisms.

ReGuard corrects risky controller actions.

Pensieve requests an oversized video chunk on a bottleneck link. Protection on.Sparse bandwidth and a low playback bufferPensieve · 1850 KbpsRL controllerBottleneckVideo trafficBufferProtected · 300 KbpsRL controllerBottleneckVideo trafficBuffer1850 → 300 Kbps

A low playback buffer, slow downloads, and a large next chunk call for a lower bitrate.

Pensieve bitrates follow ReGuard slides 12–13. The Sage curves and network scenes are schematic. Hover over or focus on a diagram element for details.

TypoNet: Let AI Agents Translate Networks, Not Reason About Them

TypoNet translates network records into a reusable symbolic model. An AI agent proposes logical rules, and another AI agent challenges them with independent network evidence. A solver uses the checked rules to answer operational questions. A separate emulation loop adds knowledge for tasks such as root-cause analysis.

TypoNet · Preprint, July 2026 

Translate once. Ask the solver many questions.

Operators and AI agents face a large collection of configurations, topology records, and routing state. Re-reading those artifacts makes each new question expensive.Reason from raw recordsABCAIagent?Query a symbolic modelABCTranslateLogical rulesProposedSolverRepeated questions re-read the same artifacts

Operators and AI agents face a large collection of configurations, topology records, and routing state.

TypoNet Figure 1. Solver answers follow from the current symbolic model; agreement with the real network depends on the evidence used to validate it.

Counterexamples turn proposed rules into checked knowledge.

The Constructor AI agent builds rules from source-of-truth records. The Detractor AI agent checks them against snapshots, known invariants, and operator procedures.Foundation loopConstructorDetractorRoute ⇒ forwardProposedABCSnapshots · invariants · proceduresSpecialization loopConstructorDetractorFault → symptomsProposedABCEmulated network · inject & restoreFoundation theory under constructionBuild behavior from facts and check every layer

The Constructor AI agent proposes a rule, and the Detractor AI agent checks it against independent evidence.

TypoNet Figure 2. The forwarding rule and three-router topology are simplified examples. The foundation uses recorded evidence; task specialization uses controlled experiments in an emulated network.

Looking ahead

The research agenda

Network AI needs knowledge it can inspect, update, and use at the right moment.

Discover meaningful rules

Distinguish recurring relationships from coincidences and express richer behavior over time.

Make reasoning efficient

Integrate learning and constraint enforcement so that explicit knowledge can guide decisions under tight latency requirements.

Keep protection useful

Find new failures and update the rules as networks and workloads change.

Further reading

Papers & resources

The papers behind the demos provide the full methods and experimental results. For related work from other groups, see the community reading list.

  1. ReGuard · NSDI 2027, to appear

    Worst-Case Discovery and Runtime Protection for RL-Based Network Controllers 

    Hongyu Hè, Minhao Jin, and Maria Apostolaki

    Preprint 
  2. Autogram · HotNets 2026, to appear

    Invariant Discovery for Networked Systems 

    Hongyu Hè, Alexander Krentsel, Sylvia Ratnasamy, and Maria Apostolaki

    Preprint 
  3. Student debugging traces · HotNets 2026

    No Hyperscaler? No Problem. Your Students also Break (and Fix) Networks 

    Constantine Doumanidis, Hongyu Hè, and Maria Apostolaki

    Student debugging traces and AI testing
  4. TypoNet · Preprint, July 2026

    Let AI Agents Translate Networks, Not Reason About Them 

    Hongyu Hè and Maria Apostolaki

    Preprint 
  5. NetNomos · NSDI 2026

    Making Logic a First-Class Citizen in Generative ML for Networking 

    Hongyu Hè, Minhao Jin, and Maria Apostolaki

    Talk & publication  Code 
  6. LeJIT · HotNets 2025

    Just-in-Time Logic Enforcement: A new paradigm of combining statistical and symbolic reasoning for network management 

    Hongyu Hè and Maria Apostolaki

    Talk  Code 
  7. PANTS · USENIX Security 2025

    Robustifying ML-powered Network Classifiers with PANTS 

    Minhao Jin and Maria Apostolaki

    Talk & publication  Code  Artifact 
  8. Zoom2Net · SIGCOMM 2024

    Zoom2Net: Constrained Network Telemetry Imputation 

    Fengchen Gong, Divya Raghunathan, Aarti Gupta, and Maria Apostolaki

    Publication  Code 
Download BibTeX

From the community

Community reading list

Related work connects learning, domain knowledge, and formal reasoning across networked systems and AI applications. Contributions from all research groups are welcome, including your own work.

Join the conversation

Help shape neurosymbolic networking

Have network data, an application that needs better guarantees, or a question current methods cannot answer? Share it with the community.

Share data or an application

Bring a dataset, workload, or deployment challenge. Tell us what the network does and what AI needs to get right.

Share a use case

Bring a question

Point out a failure case, a missing constraint, or a research question. Concrete examples help connect ideas to practical problems.

Start a discussion

Submissions open as public GitHub issues and require a GitHub account. For restricted data, share a description and a contact route rather than uploading the data.

Who we are

People

Research Support

This work is supported by the U.S. National Science Foundation and the Office of Naval Research.