July 2026Unreviewed
Just Testing, Move Along: Evasion of LLM-based System Log Interpretation by Prompt Injection
Max Landauer, Florian Skopik, Markus Wurzenberger, Franciszek Górski, Mateusz Krzysztoń
Abstract
Large Language Models (LLMs) are increasingly integrated into Security Operations Center (SOC) workflows, where they support analysts in tasks such as the interpretation of system logs. However, the ability of LLMs to directly process untrusted textual input also introduces new attack surfaces. In particular, attackers can inject contextual information or explicit instructions into log entries in order to influence how malicious activity is interpreted by the model. Despite the growing adoption
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{landauer2026just,
title = {{Just Testing, Move Along: Evasion of LLM-based System Log Interpretation by Prompt Injection}},
author = {Max Landauer and Florian Skopik and Markus Wurzenberger and Franciszek Górski and Mateusz Krzysztoń},
year = {2026},
month = jul,
eprint = {2607.24174},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2607.24174}
}