Docs / ANALYSIS ENGINES
ANALYSIS ENGINES
Neural Network Engine
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
The Neural Network Engine is the on-device neural-network layer that runs as a deterministic fallback after rule-based detectors have done what they can. It answers four specific questions: "is this block doing crypto, and if so what kind?" , "what algorithm is this unknown function call?" , "are these two usages part of the same operation?" , and "which plan items should be tackled first?" The Neural Network Engine runs entirely on-device. No source code, no findings, no scan data ever leaves your machine. Network features (model-update checks) are gated behind explicit user consent and transmit only the current model version string.
Models
| Model | Job |
|---|---|
| Block Classifier | Classifies a code block into one of: PASSWORD_HASHING, INTEGRITY, TRANSPORT, DATA_AT_REST, AUTHENTICATION, KEY_EXCHANGE, RANDOM, CUSTOM_IMPL. |
| Algorithm Resolver | Resolves an unknown function call to one of ~150 canonical algorithm classes. |
| Relation Predictor | Predicts whether two nearby crypto usages are part of the same logical operation (e.g. "generate key + encrypt with it"). |
| Plan Prioritizer | Scalar priority score for re-ordering plan items by predicted impact. |
When It Runs
The Neural Network Engine is consulted only after rule-based detectors complete - it never overrides a high-confidence rule-based finding. Predictions below the per-model confidence threshold are discarded silently to avoid noise. Scanner consults the Block Classifier + Algorithm Resolver during analysis when a call site can't be resolved through static rules alone. Context Engine consults the Relation Predictor to merge findings that belong to the same logical operation. Planner consults the Plan Prioritizer to re-order plan items within each severity bucket. This is not selectable per run - there is no --reprioritize-with-nn switch - and it applies whenever the engine is present with a trained model; when either is missing the planner keeps its rule-based ordering. Dependency edges are resolved first either way, so a re-order never moves an item ahead of something it depends on.
Files
Architecture fingerprint. Each .kxnn carries an architecture fingerprint covering vocabulary and topology. Loading is refused if the fingerprint doesn't match the engine's expected configuration - this protects against model substitution attacks.
| File | Purpose |
|---|---|
| .kxnn | Encrypted, signed weight file. One per model. |
| .kxnn.sig | Detached cryptographic signature. Verified on load; load is refused on mismatch. |