Skip to content
Search
paperSeptember 2026UnreviewedOpen access

Hive-AI: a defended multi-service honeypot framework for generative AI APIs

Sebastián Vargas Yáñez, Sergio Tobón

International Journal of Information Security

Abstract

Public Large Language Model (LLM) APIs draw attacker traffic that defenders cannot see. Probes hit at the semantic layer—past TLS, past Web Application Firewall rules—and conventional intrusion detection picks up almost none of it. No open-source honeypot framework today captures this traffic at scale, and the few LLM-honeypot prototypes that exist push captured logs straight into a downstream LLM analyzer, exposing the analysis pipeline to indirect prompt injection through attacker-controlled i

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@article{yanez2026hiveai,
  title = {{Hive-AI: a defended multi-service honeypot framework for generative AI APIs}},
  author = {Sebastián Vargas Yáñez and Sergio Tobón},
  year = {2026},
  month = sep,
  journal = {International Journal of Information Security},
  doi = {10.1007/s10207-026-01307-0},
  url = {https://www.semanticscholar.org/paper/33566699ae6da88b8b15e737037575861d87045c}
}