Skip to content
Search
paperJuly 2026Unreviewed

NetInjectBench: Benchmarking Indirect Prompt Injection in Tool-Using Large Language Model Agents for Network Operations

Ruksat Khan Shayoni, Muhammad Faraz Shoaib, S M Asif Hossain, M. F. Mridha

Abstract

Tool-using large language model (LLM) agents are attractive for network operations, but tickets, alerts, logs, runbooks, and ChatOps messages can carry indirect prompt injections. We present NetInjectBench, a 130-scenario benchmark that separates untrusted artifact text, trusted policy metadata, and evaluation labels for network-operation tool use. The sample contains 40 benign, 40 weak-attack, 40 strong-attack, and 10 approved high-impact change scenarios; each is evaluated with Qwen2.5-7B, Lla

Categories

Framework mappings

OWASP Top 10 for Agentic Applications
  • ASI02Tool Misuse & Exploitation
MITRE ATLAS
  • AML.T0051LLM Prompt Injection
  • AML.T0053AI Agent Tool Invocation

Suggested from the entry's categories.

Cite

@misc{shayoni2026netinjectbench,
  title = {{NetInjectBench: Benchmarking Indirect Prompt Injection in Tool-Using Large Language Model Agents for Network Operations}},
  author = {Ruksat Khan Shayoni and Muhammad Faraz Shoaib and S M Asif Hossain and M. F. Mridha},
  year = {2026},
  month = jul,
  eprint = {2607.10490},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2607.10490}
}