July 2026Unreviewed
NetInjectBench: Benchmarking Indirect Prompt Injection in Tool-Using Large Language Model Agents for Network Operations
Ruksat Khan Shayoni, Muhammad Faraz Shoaib, S M Asif Hossain, M. F. Mridha
Abstract
Tool-using large language model (LLM) agents are attractive for network operations, but tickets, alerts, logs, runbooks, and ChatOps messages can carry indirect prompt injections. We present NetInjectBench, a 130-scenario benchmark that separates untrusted artifact text, trusted policy metadata, and evaluation labels for network-operation tool use. The sample contains 40 benign, 40 weak-attack, 40 strong-attack, and 10 approved high-impact change scenarios; each is evaluated with Qwen2.5-7B, Lla
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
OWASP Top 10 for Agentic Applications
- ASI02Tool Misuse & Exploitation
MITRE ATLAS
- AML.T0051LLM Prompt Injection
- AML.T0053AI Agent Tool Invocation
Suggested from the entry's categories.
Cite
@misc{shayoni2026netinjectbench,
title = {{NetInjectBench: Benchmarking Indirect Prompt Injection in Tool-Using Large Language Model Agents for Network Operations}},
author = {Ruksat Khan Shayoni and Muhammad Faraz Shoaib and S M Asif Hossain and M. F. Mridha},
year = {2026},
month = jul,
eprint = {2607.10490},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2607.10490}
}